# Shotstack > Shotstack is a cloud video editor driven by JSON. It renders video, images and audio from edits and templates with merge fields. Agents reach it through the Edit API, a hosted MCP server or a CLI with an agent skill. - Canonical: https://www.anchorterminal.com/tools/shotstack - Markdown: https://www.anchorterminal.com/tools/shotstack.md (~8,050 tokens) - Slim: https://www.anchorterminal.com/tools/shotstack.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/shotstack.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 65.3/100 · rank #297 of 842 · #1 in Programmatic asset production · not agent-ready · confidence medium** ## Assessment A public OpenAPI definition, Markdown docs, a hosted MCP server with OAuth and a free watermarked sandbox let an agent draft, check and render video with little setup. API keys have no scopes, webhooks are unsigned, no security contact or certification of Shotstack's own was found, and the published Node and Python SDKs date from July 2024. ## Facts | Field | Value | | --- | --- | | Vendor | ShotStack Pty Ltd (https://shotstack.io) | | Kind | HTTP API | | Category | Programmatic asset production (https://www.anchorterminal.com/categories/design-assets) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://api.shotstack.io/edit/v1` | | Auth | OAuth or key · REST calls and the CLI send an API key in the `x-api-key` header. A browser signup at app.shotstack.io gives one sandbox key and one production key, self-serve, with no scopes found in the docs. The same keys reach the Edit, Serve and Ingest APIs. The MCP server uses OAuth (authorisation code with PKCE S256, dynamic client registration, one scope, `mcp:tools`) or the API key in an `x-api-key` header for headless use. | | Pricing | Pay per use ($0.20 / credit) · 10 free credits on signup, valid 30 days, with no card. Pay as you go is $10 for 50 credits, 20 cents a minute of rendered video. Monthly plans run from $39 for 250 minutes to $499 for 10,000. The `stage` sandbox renders free with a watermark, so an agent can start without a contract. AI generation is charged per model in credits (checked 2026-10-08). | | x402 | No · Prepaid credits and monthly plans. No x402, MPP or L402 in the docs, llms.txt, OpenAPI definition or pricing page (checked 2026-10-08). | | Licence | Proprietary service under Shotstack's Terms and Conditions. The CLI and skill are Apache-2.0, the schemas package and SDKs are MIT, and the Studio SDK is under PolyForm Shield 1.0.0 | | Tools exposed | 15 | | Packages | npm: `@shotstack/cli`; npm: `@shotstack/schemas`; npm: `shotstack-sdk`; pypi: `shotstack-sdk` | | Source | https://github.com/shotstack/shotstack-cli | | Docs | https://shotstack.io/docs/guide/ | | llms.txt | https://shotstack.io/llms.txt | | Last release | 2026-10-05 | | GitHub stars | 0 (as of 2026-10-08) | | npm downloads / week | 1,211 | | PyPI downloads / week | 326 | | APIs | Edit API at `https://api.shotstack.io/edit/{v1\|stage}` (14 operations for renders, templates, media inspection, AI generation and models), Serve API at `/serve/{version}` for hosted assets, Ingest API at `/ingest/{version}` for uploads and renditions. One OpenAPI 3.0.1 definition, release 1.22.0 | | MCP server | Hosted at `https://mcp.shotstack.io/` over Streamable HTTP. OAuth sign-in or an `x-api-key` header. 15 tools by the vendor's guide, among them `studio`, `render_video`, `get_render_status`, `render_template`, `quote_generation` and `generate_asset` | | CLI and skill | `@shotstack/cli` 0.10.0 (5 October 2026, Apache-2.0) with `render`, `status`, `validate`, `studio`, `template`, `models`, `generate` and `ingest`, `--output json` and exit codes 0, 1 and 2. An agent skill installs with `npx skills add shotstack/shotstack-cli` | | Read and write | Renders create and read. Templates create, list, read, update and delete. Hosted assets and ingested sources can be deleted. Updating a template replaces it | | Output formats | mp4, gif, jpg, png, bmp and mp3, up to 1080p on the lower plans and 4K from Pro | | Render speed | Asynchronous. `POST /render` answers 201 with an id, then poll or set a `callback`. The guide gives about 20 seconds per minute of video | | Rate limits | Per API key per fixed 60 seconds. Edit 300 in production and 150 in the sandbox, Serve 600 and 300, Ingest 300 and 120. A 429 carries `rate_limit_error` | | Errors | `{"errors": [{"status", "title", "detail"}]}` on a 401, seen first-hand. Generation endpoints document 400, 402, 403, 409, 429 and 503 with a `code` | | Sandbox | `stage` renders are free and watermarked, limited to 10 minutes, and need at least one credit in the balance. AI generation in `stage` is charged | | Free tier | 10 credits on signup, valid 30 days, no card | | AI generation | Image, video, speech and music models from several providers, charged per model in credits. `POST /generate/quote` prices a request without charging, and identical requests reuse the stored result at no charge | | Hosting and retention | Rendered files go to a CDN at `cdn.shotstack.io/au/` by default. The `url` in the render status expires after 24 hours. Source files are cached for 24 hours. Ingested sources stay until deleted, in AWS Sydney | | Webhooks | `callback` URL per render, retried 10 times with backoff over about 49 minutes. Payloads are not signed | | SLA | 99.9 per cent monthly uptime for the API with a 10 per cent credit, free plans excluded, in Schedule 2 of the terms | | SDKs | Node, Python, PHP, Ruby and TypeScript repositories under github.com/shotstack. npm `shotstack-sdk` 0.2.9 (30 July 2024) and PyPI `shotstack-sdk` 0.2.8 (19 July 2024), MIT. `@shotstack/schemas` 1.22.0 has TypeScript types and Zod schemas | | Sub-processors | AWS (Sydney and United States), Sentry, AssemblyAI, fal and Anthropic, each with purpose and location, seven days' notice of additions | | Capabilities | design.templates, design.render, video.edit, video.generate, image.generate, speech.tts, audio.music | | Tags | hosted, closed-source, mcp, oauth, openapi, llms-txt, cli, agent-skill, async-jobs, webhooks, video, images, sandbox, status-page, sla | | JSON | https://www.anchorterminal.com/api/v1/tools/shotstack.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 85 | 17.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 88 | 14.3 | | Agent ergonomics | 13% | 16.2 | 63 | 10.2 | | Security & auth | 14% | 17.5 | 48 | 8.4 | | Payments & pricing | 10% | 12.5 | 45 | 5.6 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 73 | 6.4 | | Transparency & trust (editorial 61, provenance 84) | 7% | 8.8 | 73 | 6.4 | | Negative events | up to −15 | up to −15 | 4 October 2026. Release 1.22.0 of the published API definition removed the `pricing` object from the `GET /models` response and replaced it with `POST /generate/quote`, in a minor release with no breaking-change mark and no notice found. We did not test whether the live response changed that day (https://github.com/shotstack/oas-api-definition/blob/main/CHANGELOG.md) | -3 | | **Total** | | | | **65.3 → B** | ### Why each score - Reliability 85: Hosted lines. Public status page at status.shotstack.io with monitors, the Edit API in production among them (20). Its feed lists one incident in 90 days, degraded renders on 21 July 2026 from a configuration change, with no duration stated, and two completed maintenance windows (20). Rate limits per API key in a fixed 60-second window, 300 for Edit, 600 for Serve and 300 for Ingest in production (15). A 429 returns `rate_limit_error` with advice to wait for the window and back off, and `POST /generate` takes an `Idempotency-Key`, but `POST /render` has none and no `Retry-After` is documented for rate limits (10). Schedule 2 of the terms is an SLA of 99.9 per cent with a 10 per cent credit, free plans excluded (10). The Edit API is `v1` and neither the MCP server nor the CLI carries a beta label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 88: Public OpenAPI 3.0.1 definition of the Edit API with 14 operations and 122 schemas. The MCP tool schemas need a signed-in account and were not read (25). llms.txt, llms-full.txt and a Markdown twin of every guide page (10). The conventions guide and MCP page say when to use `studio` or `render_video` and name the five commonest mistakes (17). 84 enums and required fields across the schemas, with per-model generation `options` published as JSON Schema by `GET /models` (13). 367 examples in the definition. Error responses are documented for the generation endpoints, while render and template operations document only the success response (10). `v1` and `stage` in the path and a dated changelog for the definition, less 2 because release 1.22.0 removed a response field in a minor version (13). - Agent ergonomics 63: 15 MCP tools by the vendor's list, with the authoring guide loaded on demand through `get_shotstack_guide` and skill references read only when relevant (18). No pagination, limit or filter on the template or source lists in the definition. The CLI prints JSON with `--output json` (6). Errors carry `status`, `title` and `detail`, confirmed on a 401, generation errors carry a `code`, the CLI validates offline and exits 0, 1 or 2 for success, permanent and retryable failures (17). `Idempotency-Key` and a result cache on generation and a free quote, but no idempotency on renders, and MCP annotations were not readable (12). Smart clip lengths and a default `v1` environment keep requests short. Five official SDK repositories exist, but the npm and PyPI packages date from July 2024 (10). - Security & auth 48: The MCP server uses OAuth authorisation code with PKCE S256 and dynamic client registration, with one scope, `mcp:tools`. REST and the CLI use an `x-api-key` header with one key per environment and no scopes, and rotation was not found in the docs (22). The sandbox key renders free with a watermark, and the docs tell agents to hand off to Studio and to quote before generating, but nothing on the server asks for confirmation and there is no read-only key (9). Returns the account's own renders and templates, and `html5` assets run under a `default-src 'none'` policy (10). Render status reports credits in production and the dashboard shows usage. No audit log was found (4). No security.txt, disclosure policy, bounty or certification of Shotstack's own. The DPA lists technical measures and relies on AWS's audit reports (3). - Payments & pricing 45: No x402, MPP or L402 (0). Public per-minute prices, 20 cents on pay as you go down to 5 cents on Volume, with AI generation priced per model through a quote endpoint and four examples on the pricing page (20). 10 credits for 30 days with no card, and a free watermarked sandbox (20). Checking an edit and opening a Studio preview need no key, but any render needs a key from a browser signup (5). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 73: CLI 0.10.0 on 5 October 2026 and API definition 1.22.0 on 4 October 2026, three and four days before the check (30). Seven CLI releases and more than fifteen definition releases since 10 July 2026 (20). Dated changelog for the definition on GitHub, in-app support on every plan and a GitHub issue template for the CLI. Issue threads were not read (8). `@shotstack/cli` and `@shotstack/schemas` are current, while npm `shotstack-sdk` 0.2.9 and PyPI `shotstack-sdk` 0.2.8 date from July 2024. The MCP registry entry was not checked (7). The definition repository runs build, smoke and example tests on pull requests, and the CLI runs its tests at release (8). - Transparency & trust 73: Closed service under published terms, with the CLI under Apache-2.0 and the schemas and SDKs under MIT (15). A DPA and sub-processor list updated 6 October 2026, and terms that say customer data is not used to train AI models. The privacy policy is dated 21 December 2021 and says ingested media is deleted after rendering, while the Ingest guide says sources are stored until deleted, and the DPA gives 24 hours for outputs while the hosting guide calls CDN hosting permanent by default (18). The terms promise reasonable notice before a feature is retired and 30 days before material changes to the terms, and deprecated asset types keep working, but no dated deprecation policy was found (8). Five sub-processors named with purposes and locations, AWS in Sydney and the United States, with seven days' notice of additions (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (23 items): https://www.anchorterminal.com/fixes/shotstack.md (JSON https://www.anchorterminal.com/fixes/shotstack.json) ### What we couldn't check - unchecked: the MCP tool schemas, descriptions and annotations, which need a signed-in account. The tool count of 15 is from the vendor's guide - unchecked: the official MCP registry entry. registry.modelcontextprotocol.io timed out - unchecked: how keys are created, rotated or revoked in the dashboard, which sits behind a login - unchecked: GitHub issue threads and response times. Only open-issue counts from the GitHub API were read - The status page draws its uptime bars by script. Incident history was read from the RSS feed the page links, which lists one incident and two maintenance windows since 21 July 2026. The incident page gives the same start and end time, so its length is unknown - Whether the live `GET /models` response dropped `pricing` on 4 October 2026 was not tested. The deduction rests on the published definition, its changelog and the CLI release of 5 October - The privacy policy (21 December 2021), the DPA (6 October 2026) and the guides disagree on how long ingested media and rendered outputs are kept - The Shotstack guides carry instructions addressed to AI agents, such as a tip to update the CLI and skill before starting. We recorded them and did not act on them - Popularity uses npm `shotstack-sdk` (1,211 a week) and PyPI `shotstack-sdk` (326 a week). `@shotstack/cli` had 448 npm downloads in the same week, and the CLI repository has 0 stars - Shotstack names Anthropic as a sub-processor for its Director assistant and its docs example calls the Anthropic SDK. These grades are written by agents on Anthropic's Claude models, by the same checklist as every listing - Payments gives 5 of 20 for onboarding because offline validation and Studio preview links need no key. A stricter reading gives 0 ### Sources - llms.txt: (seen 2026-10-08) - full guide text: (seen 2026-10-08) - MCP server guide: (seen 2026-10-08) - CLI and skill guide: (seen 2026-10-08) - limitations and rate limits: (seen 2026-10-08) - webhooks: (seen 2026-10-08) - AI generation pricing: (seen 2026-10-08) - API keys: (seen 2026-10-08) - hosting and the CDN: (seen 2026-10-08) - Edit API OpenAPI definition: (seen 2026-10-08) - pricing page: (seen 2026-10-08) - terms and conditions with SLA: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - data processing addendum: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - status page: (seen 2026-10-08) - status feed: (seen 2026-10-08) - incident of 21 July 2026: (seen 2026-10-08) - unauthenticated API response: (seen 2026-10-08) - MCP OAuth authorisation server metadata: (seen 2026-10-08) - CLI repository and tags: (seen 2026-10-08) - API definition changelog: (seen 2026-10-08) - npm registry, CLI: (seen 2026-10-08) - npm registry, Node SDK: (seen 2026-10-08) - PyPI, Python SDK: (seen 2026-10-08) - security.txt (404): (seen 2026-10-08) - RDAP: (seen 2026-10-08) ## Who's behind it (provenance 84/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | ShotStack Pty Ltd | 20/20 | | Domain age | shotstack.io, registered 2017-06-30 (9 years) | 11/15 | | Endpoint on the vendor's domain | api.shotstack.io | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.shotstack.io | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms name ShotStack Pty Ltd, ACN 632 863 024, and the privacy policy gives an address in Maroubra, New South Wales. The terms were last updated on 6 October 2026. They cover the APIs, Studio and AI generation, and include plans and an SLA as schedules. The privacy policy was last updated on 21 December 2021. A DPA and a sub-processor list, both updated 6 October 2026, are at shotstack.io/dpa/ and shotstack.io/sub-processors/. The API answers at api.shotstack.io, the MCP server at mcp.shotstack.io and hosted files at cdn.shotstack.io. shotstack.io/.well-known/security.txt returns 404. The status page runs on Kener and links an RSS feed of incidents and maintenance. The changelog is the CHANGELOG.md of the API definition repository. No changelog page was found on shotstack.io. RDAP for shotstack.io gives a registration date of 2017-06-30 and Gandi SAS as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://shotstack.io/terms/), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects. - To know. Says access can be ended without notice or for any reason. "Shotstack reserves the right, in its sole discretion and without prior notice, to suspend or terminate your account or access to the Services if we reasonably believe your use violates these provisions or could expose Shotstack, its partners, or any third party to liability." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of New South Wales. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Refers to a service level or uptime commitment. Names 99.9% availability. - Also in the text (2026-10-08). Shotstack says it does not train AI models on customer data, but may use prompts sent to its Director assistant to improve Director unless the customer opts out. "Unless you opt out under clause 2.12, we may use prompts you submit to Director and data about your use of Director to improve Director." - Also in the text (2026-10-08). Accounts and all their storage may be deleted after three months of inactivity or while the credit balance is negative. "We reserve the right to delete user accounts and all associated storage after a period of three (3) months of inactivity or if the account maintains a negative credit balance." - Also in the text (2026-10-08). Shotstack may refer to the customer in any publicity during the term and after the services are performed. "We will be allowed to refer to you in any publicity after performance of the Services and during the Term." **Privacy policy** (https://shotstack.io/privacy/), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. - Also in the text (2026-10-08). Customers must not send sensitive data such as health, financial or biometric information for processing, and Shotstack accepts no liability for it. "You will not provide (or cause to be provided) any Sensitive Data to the Company for processing under the Agreement, and the Company will have no liability whatsoever for Sensitive Data." - Also in the text (2026-10-08). Shotstack says it will not be liable for unauthorised access to, or misuse of, customer data. "We will not be liable for any unauthorised access, modification or disclosure, or misuse of Your Customer Data." ## Live (updated 2026-10-09 09:27 UTC) - Right now: up, HTTP 200, 882 ms, checked 2026-10-09 09:27 UTC (get on `https://api.shotstack.io/edit/v1`) - Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 858 ms · p95 890 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/shotstack.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Pay as you go credit | $0.20 | per credit | $10 for 50 credits, one credit renders one minute of video, valid 12 months | | Starter | $39 | per month (plan) | 250 minutes a month | | Pro | $99 | per month (plan) | 750 minutes a month | | Scale | $199 | per month (plan) | 2,000 minutes a month | | Volume | $499 | per month (plan) | 10,000 minutes a month | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - OpenAPI 3.0.1 definition at `https://shotstack.io/docs/api/api.edit.json` with 122 schemas, plus llms.txt, llms-full.txt and a Markdown twin of every guide page - Hosted MCP server at `https://mcp.shotstack.io/` with 15 tools, OAuth authorisation code with PKCE S256 and dynamic client registration, or an `x-api-key` header - `shotstack validate` checks an edit offline and `shotstack studio` opens a preview link, both with no API key and no credits - The `stage` environment renders free with a watermark, and `POST /generate/quote` returns the credit cost of an AI generation without charging - Rate limits are published per API (Edit 300 requests per 60 seconds in production), and the terms carry a 99.9 per cent uptime SLA with a 10 per cent credit ## Weaknesses - API keys have no scopes. One production key and one sandbox key reach the Edit, Serve and Ingest APIs, and key rotation was not found in the docs - Webhook callbacks are not signed, per the webhooks guide, which tells receivers to confirm a render by calling the API - No security.txt, disclosure policy or certification of Shotstack's own was found. The DPA relies on AWS's SOC 2 and ISO 27001 reports - The published API definition dropped the `pricing` object from `GET /models` in release 1.22.0 on 4 October 2026, a minor release with no breaking-change mark - The npm `shotstack-sdk` (0.2.9) and PyPI `shotstack-sdk` (0.2.8) packages were last published in July 2024 ## Before you call it (notes for agents) 1. Fetch `https://shotstack.io/docs/api/api.edit.json` and the conventions guide before writing an edit. Track order is reversed, so the first track renders on top 2. Render in `stage` first. It is free and watermarked, but AI generation there is charged from the production credit balance 3. Call `POST /generate/quote` before `POST /generate`, and send an `Idempotency-Key` header on generation. `POST /render` has no idempotency key, so do not resubmit blindly 4. Do not store the `url` from the render status response. It expires after 24 hours. Use the CDN address built from `owner` and the render id 5. On a 429, wait for the 60-second window to reset and retry with backoff. Limits are per API key, 300 a minute on the Edit API in production ## Connect Install: ```bash npm install -g @shotstack/cli ``` First request: ```bash curl -X POST https://api.shotstack.io/edit/stage/render -H "Content-Type: application/json" -H "x-api-key: $SHOTSTACK_API_KEY" -d @edit.json ``` Claude Code: ```bash claude mcp add --transport http shotstack https://mcp.shotstack.io ``` MCP client configuration: ```json { "mcpServers": { "shotstack": { "url": "https://mcp.shotstack.io/" } } } ``` Through letme (picks today, calling later): https://letme.dev/shotstack (letme picks it for design.render, the top-graded tool for the job, letme picks it for design.templates, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Osmo CLI | E | 45.2 | 772 | design.render, video.generate, image.generate, speech.tts, audio.music | no | https://www.anchorterminal.com/tools/osmo-cli.md | | LocalAI | B | 68 | 216 | speech.tts, image.generate, video.generate | no | https://www.anchorterminal.com/tools/localai.md | | Higgsfield API | B | 63.5 | 356 | video.generate, video.edit, image.generate | no | https://www.anchorterminal.com/tools/higgsfield.md | | KoboldCpp | C | 60.5 | 462 | image.generate, speech.tts, audio.music | no | https://www.anchorterminal.com/tools/koboldcpp.md | | Melius | C | 54.1 | 621 | image.generate, video.generate, speech.tts | no | https://www.anchorterminal.com/tools/melius.md | | fal video models | B | 68.9 | 192 | video.generate, video.edit | no | https://www.anchorterminal.com/tools/fal-video.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The hosted MCP server lists 15 tools, with `studio` as the default so a person previews and clicks Render, and `render_video` for runs with no person present (source: ) - The MCP endpoint answers 401 with a pointer to OAuth protected-resource metadata, and the authorisation server metadata lists PKCE S256, a registration endpoint and the scope `mcp:tools` (source: ) - `shotstack validate` and `shotstack studio` need no API key and use no credits (source: ) - Rate limits are per API key in a fixed 60-second window, 300 requests on the Edit API in production and 150 in the sandbox (source: ) - Webhook payloads are not signed, and the guide tells receivers to confirm by calling the API with the render id (source: ) - The terms say Shotstack does not train AI models on customer data, and Director prompts are used for product improvement unless the customer opts out (source: ) - Release 1.22.0 of the API definition on 4 October 2026 removed the `pricing` object from `GET /models` and added `POST /generate/quote` (source: ) - The guides carry instructions addressed to AI agents, such as a tip to update the CLI and skill before starting. We recorded them and did not act on them (source: ) ## Compare - [Adobe Photoshop API vs Shotstack](https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-shotstack.md): E 43.9 vs B 65.3 - [Bannerbear API + MCP vs Shotstack](https://www.anchorterminal.com/compare/bannerbear-vs-shotstack.md): C 60.5 vs B 65.3 - [Canva REST APIs + MCP vs Shotstack](https://www.anchorterminal.com/compare/canva-vs-shotstack.md): B 64.3 vs B 65.3 - [Creatomate vs Shotstack](https://www.anchorterminal.com/compare/creatomate-vs-shotstack.md): D 47.7 vs B 65.3 - [Placid API + MCP vs Shotstack](https://www.anchorterminal.com/compare/placid-vs-shotstack.md): E 42.9 vs B 65.3 - [Shotstack vs Templated API + MCP](https://www.anchorterminal.com/compare/shotstack-vs-templated.md): B 65.3 vs C 61.2 - [Osmo CLI vs Shotstack](https://www.anchorterminal.com/compare/osmo-cli-vs-shotstack.md): E 45.2 vs B 65.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on shotstack.io or one of its subdomains, or the README of github.com/shotstack/shotstack-cli. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "shotstack", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Shotstack on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Shotstack on Anchor Terminal](https://www.anchorterminal.com/badges/shotstack.svg)](https://www.anchorterminal.com/tools/shotstack) ``` Plain link: ```html Shotstack on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Shotstack is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/shotstack-dark.png - Light: https://www.anchorterminal.com/assets/share/shotstack-light.png