# Shortcut (slim) > Shortcut is a hosted project tracker for software teams, with stories, epics, iterations, objectives and docs. Agents reach it through REST API v3 with a personal token, or the hosted MCP server at mcp.shortcut.com/mcp with OAuth. - Full: https://www.anchorterminal.com/tools/shortcut.md (~7,950 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/shortcut.json · canonical https://www.anchorterminal.com/tools/shortcut - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 60.2/100 · rank #411 of 722 · #9 in Project & task management · not agent-ready · confidence medium** Assessment: REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation. ## Facts - Kind: HTTP API · vendor: Shortcut Software Company · category: Project & task management · legal entity: Shortcut Software Company · provenance 88/100 - Endpoint: `https://api.app.shortcut.com` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: REST API v3 at https://api.app.shortcut.com/api/v3 (current), REST API v4 (alpha), outgoing webhooks v1, and the hosted MCP server at https://mcp.shortcut.com/mcp - API coverage: 143 operations on 85 paths in v3, among them stories (23), epics (17), objectives (9), documents (8), iterations (8), search (7), labels, files, custom fields, workflows and members - MCP server: Hosted, OAuth only. Stories can be retrieved, created and updated with comments and sub-tasks, epics and iterations retrieved and created, docs retrieved, created and updated, and objectives, teams, members and workflows read. The tool list needs an account and was not read - Credentials: Per-user API tokens in the `Shortcut-Token` header, read-only or read-write. OAuth authorisation code flow with PKCE and dynamic client registration for MCP - Scopes: read, write, story-write, comment-write, admin, plus openid for sign-in - Rate limits: 200 requests a minute, answered with 429. No Retry-After header is documented - Pagination: Search endpoints take `page_size` (1 to 250), a `next` token and `detail=slim`. Epics have a paginated list. Other v3 lists return every record. v4 adds cursors with `limit` 1 to 100 and a `fields` parameter - Errors: 400 schema mismatch, 404 resource does not exist and 422 unprocessable on every operation, 403 on 13. A live 401 returned JSON with `message` and `tag` - Webhooks: Story and epic create, update and delete events, with comments and tasks included. Registered by API at `/api/v3/integrations/webhook`, optional HMAC-SHA-256 signature in `Payload-Signature` - SDKs: `@shortcut/client` 3.4.1 for JavaScript and TypeScript (22 September 2026, MIT). `@shortcut/mcp` 0.25.0 is the last release of the archived local MCP server - Free tier: Free plan at $0 for up to 10 users with API and webhook access and the MCP server, 5 GB of storage. 14-day trial of paid plans with no card - Certifications: SOC 2 Type 2 for security, availability and confidentiality per the security page, report by email request. A BAA for HIPAA on Business and Enterprise - Status: status.shortcut.com on Statuspage, with components for API, Shortcut MCP, Web App, Search and integrations, and incidents back to March 2023 - Sub-processors: List updated 12 November 2025 with 33 providers and countries. Hosting on Amazon Web Services in the US. Anthropic is listed for Korey only - Prices: Free (API, webhooks and MCP server included) free per seat per month; Team, billed yearly $8.50 per seat per month; Business, billed yearly $12 per seat per month - Scores: Reliability 64, Performance pending, Schema & documentation 75, Agent ergonomics 57, Security & auth 54, Payments & pricing 30, Task success pending, Maintenance & community 73, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted lines for REST API v3 and the hosted MCP server. · Schema & documentation, Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 a… · Agent ergonomics, Graded on the API. · Security & auth, The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). · Transparency & trust, Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). - Sources: 30, open questions: 8, both in the full twin - Capabilities: tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks - JSON: https://www.anchorterminal.com/api/v1/tools/shortcut.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/shortcut.svg` or a link to https://www.anchorterminal.com/tools/shortcut from a page on shortcut.com or one of its subdomains, or the README of github.com/useshortcut/shortcut-client-js, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there. 2. Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected. 3. Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once. 4. Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented. 5. For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`. ## Connect ```bash npm install @shortcut/client ``` ```bash curl -X GET -H "Content-Type: application/json" -H "Shortcut-Token: $SHORTCUT_API_TOKEN" -L "https://api.app.shortcut.com/api/v3/categories" ``` ```bash claude mcp add --transport http shortcut https://mcp.shortcut.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/shortcut ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Teamwork.com | B | 65.9 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks | https://www.anchorterminal.com/tools/teamwork.min.md | | Wrike | C | 60.1 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks | https://www.anchorterminal.com/tools/wrike.min.md | | monday.com | BB | 76.4 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/monday.min.md | | Asana | BB | 70.1 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/asana.min.md | | Basecamp | B | 67.9 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/basecamp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)