Skyvern
by Ikonomos Inc. (Skyvern) HTTP API in Browser automation
Hosted Local
Ikonomos Inc. · skyvern.com since 2023 · status page · who's behind it
Skyvern is a browser agent that completes multi-step web workflows from natural-language goals using language models and computer vision. It runs as an AGPL-3.0 open-source server or a hosted cloud with a REST API and MCP server.
Good for Agents that must finish a multi-step job on sites with logins, 2FA and forms, where stored credentials, saved workflows and cached scripts matter more than raw browser time.
Is this your product? Claim this listing or verify it
Assessment. The hosted MCP server annotates every tool as read-only or destructive and can advertise a 29 or 32-tool subset in place of 114, and the API has a written six-month deprecation policy. Every key and OAuth token carries full organisation authority, with no read-only or scoped credential, and no request rate limits are documented.
Facts
- Transport
- HTTP, Streamable HTTP, stdio
- Endpoint
https://api.skyvern.com/v1- Auth
- OAuth or key
- Pricing
- Freemium · $29 / mo
- x402
- No
- Licence
- AGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repository
- Tools exposed
- 114
- Packages
pypiskyvernnpm@skyvern/client- MCP registry
io.github.Skyvern-AI/skyvern- llms.txt
- published
- Last release
- GitHub stars
- 23k
- npm / week
- 3.2k
- PyPI / week
- 1.6k
- Graded surface
- Skyvern Cloud, the REST API at https://api.skyvern.com/v1 and the hosted MCP server at https://api.skyvern.com/mcp. The same code is open source under AGPL-3.0 for self-hosting with your own model keys
- MCP server
- Official. Hosted over streamable HTTP with OAuth or
x-api-key, or local stdio withpython -m skyvern run mcpagainst a self-hosted server. 114 tools at full scope, 29operate, 60build, 54browser, 32lean, chosen by /mcp/x/<scope> orX-Skyvern-Scope - Credentials
- Organisation-wide API key in
x-api-key, no expiry, rotated in Settings. OAuth 2.0 authorisation code with PKCE S256, dynamic client registration and rotating refresh tokens. OAuth scopes are identity claims only. No read-only or scoped credential - Free tier
- 5,000 credits once, 1 concurrent run, no card. The pricing page estimates about 170 actions and the billing docs about 200
- Plans
- Hobby $29 a month, 30,000 credits, 10 concurrent runs. Pro $149, 150,000 credits, 25 concurrent, residential proxies, TOTP and 1Password. Enterprise custom, 100 concurrent, HIPAA and the SOC 2 report
- Rate limits
- Concurrent runs per plan are published. No request limits in the docs. Responses carry
ratelimit-policy: "submit-run";q=50;w=60, and run submission can answer 503 withRetry-After - Errors
- Terminal run statuses include
completed,failed,terminatedandtimed_out, withfailure_reasonand a caller-definederror_code_mapping. MCP results carry codes such as SELECTOR_NOT_FOUND with a hint - SDKs
- Python
skyvern1.0.55 (Python 3.11 to 3.14) and TypeScript@skyvern/client1.0.55, both 1 October 2026, generated from the OpenAPI document - Audit
- GET /v1/audit-events/export, default window 90 days, JSON or CSV, up to 500 a page. Each run keeps a recording, screenshots, an action timeline and a HAR file
- Deprecations
- At least six months' notice, 12 for a major version,
DeprecationandSunsetheaders,deprecatedflags in the OpenAPI document. No /v1 endpoint is deprecated today - Status
- status.skyvern.com on Statuspage, three components. One incident in the 90 days to 8 October 2026, about 70 minutes of elevated run failures on 6 August
- Reuse terms
- You are responsible for the target site's terms and for authorisation to automate it. Data may be sent to third-party model providers, and anonymised data may train models unless you opt out by email
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Every MCP tool carries readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source
- Hosted MCP scopes cut the advertised tools from 114 to 29 (
operate) or 32 (lean) by URL orX-Skyvern-Scopeheader - Written deprecation policy with six months' notice, 12 for a major version, and
DeprecationandSunsetresponse headers - OpenAPI 3.1.0 with 94 operations, llms.txt, Markdown twins of every docs page and a weekly dated changelog
- Stored passwords, cards and TOTP secrets are injected into the browser and replaced by placeholders in prompts, recordings and logs, per the docs
Weaknesses
- Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys
- No request rate limits in the docs. Responses carry
ratelimit-policy: "submit-run";q=50;w=60, and only plan concurrency is published - What a credit buys is stated three ways (one credit an action, 5,000 credits for about 170 or about 200 actions, by run complexity)
- An SSRF report against 1.0.39 from 30 June 2026 is still open with no advisory, though 1.0.55 source has SSRF guards
- Retention is "as long as necessary", anonymised data may train models unless you opt out by email, and no subprocessor list was readable
Before you call it notes for agents
- Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send
X-Skyvern-Scope, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions - Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows
- Never pass passwords to
skyvern_actorskyvern_type. Store them as credentials and callskyvern_login - Set
max_stepson tasks, orx-max-steps-overrideon agent runs, to cap credits. A run that reaches the cap ends astimed_out - On 503 from POST /v1/run/agents, wait
Retry-Afterseconds. No run was created, so resubmitting is safe
Who's behind it provenance 78/100
- Legal entity namedIkonomos Inc.20/20
- Domain ageskyvern.com, registered 2023-10-16 (2 years)7/15
- Endpoint on the vendor's domainapi.skyvern.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects9.1/10
- Privacy policyread, states 7 of the 8 things a reader expects, and has 1 clause that costs points7.3/10
- Status pagestatus.skyvern.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-02-27, states 6 of 7, 3 to know
TL;DR Dated 2026-02-27. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, model training with an opt-out, cut-off without notice or for any reason and arbitration or a class action waiver.
Says it may use customer content to train or improve models, and gives an opt-out
We may use anonymized or aggregated data for service improvement and model training; and
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says access can be ended without notice or for any reason
We may terminate or suspend your access to the Services immediately, without prior notice or liability, for any reason, including if you breach these Terms.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
Dispute Resolution: Disputes are governed by Delaware law and subject to binding arbitration.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-02-27
Last Modified: 27 February, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Delaware
These Terms and any dispute arising out of or relating to these Terms or the Services shall be governed by and construed in accordance with the laws of the State of Delaware, without giving effect to any choice or conflict of law provision or rule.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
Limitation of Liability: Our liability is limited to the fees you paid in the prior 12 months.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
We may modify, suspend, or discontinue any aspect of the Services at any time.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Changes are posted, with no other notice named
Your continued use of the Services following the posting of revised Terms constitutes your acceptance of such changes.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you do not agree to these Terms, you must not access or use the Services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The customer alone is responsible for complying with the terms and acceptable use policies of any third-party website it accesses through the service.
You are solely responsible for compliance with the terms of service, acceptable use policies, and other agreements of any third-party websites you access through the Services.
Noted by a second reader on 2026-10-08.
A claim must be started within one year of the cause of action arising or it is permanently barred.
Any cause of action or claim you may have arising out of or relating to these Terms or the Services must be commenced within one (1) year after the cause of action accrues; otherwise, such cause of action or claim is permanently barred.
Noted by a second reader on 2026-10-08.
Customer data may be sent to and processed by third-party LLM providers, with OpenAI and Anthropic named as examples.
Your data may be transmitted to and processed by third-party LLM providers (such as OpenAI and Anthropic);
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,039 words
Privacy policy dated 2026-10-01, states 7 of 8, 1 to know
TL;DR Dated 2026-10-01. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, model training with no opt-out found.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
To train and improve our machine learning models using anonymized data.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Gives the date it was last updated Last updated 2026-10-01
Last Modified: 1 October, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This policy describes the types of information we may collect from you or that you may provide when you use our website skyvern.com (our "Website") and our AI-powered browser automation platform and services (collectively, the "Services"), and our practices for collecting, using, maintaining, protecting, and disclosin…
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain Google user data only as long as needed to provide the feature, which includes keeping it in the workflow run results you can view in Skyvern (see Data Retention below, including how to request deletion).
Says when data sent to the service is deleted.
Says who else receives the data
From third parties, including business-information providers, visitor-identification partners, and public professional sources such as company websites and professional profiles.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Residents of certain states under 13, 16, or 18 years of age may have additional rights regarding the collection and sale of their personal information.
A plain statement either way.
Says what rights people have over their data
This disclosure does not limit your rights under applicable privacy laws.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
To ask questions or comment about this privacy policy and our privacy practices, contact us at:
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Screenshots of automation sessions are sent to LLM providers including OpenAI, Anthropic, Google Gemini, Azure OpenAI and AWS Bedrock.
We send screenshots to LLM providers (including OpenAI, Anthropic, Google Gemini, Azure OpenAI, and AWS Bedrock) for AI-powered visual analysis and automation processing.
Noted by a second reader on 2026-10-08.
Connecting the Google Drive integration grants Skyvern full access to the files in the customer's Google Drive, which it says it uses only for uploads and folder lookups.
connecting this integration grants Skyvern full access to the files in your Google Drive; we use that access only for the uploads and folder lookups described here, and do not read, modify, or delete your other Drive content.
Noted by a second reader on 2026-10-08.
Automation tasks are performed through residential proxy networks.
Proxy Network Providers: We use residential proxy networks to perform automation tasks.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,903 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms (last modified 27 February 2026) and privacy policy (last modified 1 October 2026) name Ikonomos Inc., doing business as Skyvern, with Delaware law governing the terms.
The API and the hosted MCP server answer at api.skyvern.com. OAuth is issued through clerk.skyvern.com, backed by Clerk.
www.skyvern.com/.well-known/security.txt and api.skyvern.com/.well-known/security.txt both return 404. SECURITY.md in the repository sends reports to GitHub private advisories.
RDAP for skyvern.com gives a registration date of 2023-10-16.
docs.skyvern.com redirects to www.skyvern.com/docs.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.skyvern.com/v1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- github
Skyvern-AI/skyvernv1.0.55, released 2026-10-01 - npm
@skyvern/client1.0.55 - pypi
skyvern1.0.55, released 2026-10-01 - GitHub stars 23k
- npm downloads a week 3.2k
- PyPI downloads a week 1.6k
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/skyvern.json
Notable
- The hosted MCP server at https://api.skyvern.com/mcp accepts OAuth or
x-api-key, and scopesoperate,build,browserandleannarrow the advertised tools without narrowing permissions source - Every MCP tool is registered with readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in skyvern/cli/mcp_tools/__init__.py at v1.0.55 source
- The deprecation policy promises at least six months' notice, 12 months for a major version, and
DeprecationandSunsetheaders source - One incident in the 90 days to 8 October 2026, elevated task and workflow failures for about 70 minutes on 6 August after an upstream model provider rejected requests source
- A public issue of 30 June 2026 reports SSRF from workflow HTTP and download blocks in 1.0.39. It is still open, and the 1.0.55 source has an SSRF-guarded resolver source
- The webhook docs warn that verifier examples published before August 2026 accepted any signature of the right length source
- The MCP registry entry is version 1.0.23 from 13 March 2026, while PyPI and npm are at 1.0.55 from 1 October 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 11.4 | |
Graded as a hosted service, Skyvern Cloud at api.skyvern.com. status.skyvern.com is a Statuspage site with three components (API, web application, async workers), 90-day uptime bars and an incident feed back to March 2025 (20). The feed has one incident in the 90 days to 8 October 2026, marked major by Skyvern, on 6 August, when an upstream model provider rejected requests and task and workflow runs failed at elevated rates from about 21:20 UTC to 22:30, roughly 70 minutes. A 29-minute run of 503s on 3 July falls just outside the window (10). The pricing page gives concurrent runs per plan (1, 10, 25, 100) and API responses carry ratelimit-policy: "submit-run";q=50;w=60, but we found no documented request limits (8). The OpenAPI document describes 503 with Retry-After on run submission and 429 on two recipe endpoints, and the SDKs retry network errors and 5xx with backoff. Idempotency-Key exists only on POST /v1/agents, so retried run submissions rely on the 503 saying no run was created (9). The pricing FAQ mentions custom SLAs for Enterprise and nothing is published (0). /v1 is declared stable (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.3 | |
OpenAPI 3.1.0 at /docs/api-reference/openapi.json with 94 operations on 71 paths and 261 schemas, and MCP tools with typed parameters (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). The MCP server ships a routing table that says which tool to use for each kind of job, what each costs in model calls and what not to use it for, and tool docstrings repeat it. Many REST operations have one-line descriptions such as "Run a task" (16). Inputs are typed with enums and ranges, such as limit 1 to 500 on the audit export, but skyvern_workflow_create takes the whole definition as a JSON or YAML string and the spec marks x-api-key as optional on every operation (11). Code samples in Python, TypeScript and cURL and a full error-handling guide, while 422 is the only error documented on most operations, with 404 on 31 of 94 and 429 on two (11). /v1 path versioning with a written compatibility policy and a weekly dated changelog (15). | |||
| Agent ergonomics | 13%16.2 | 12.3 | |
The full MCP surface is 114 tools by the docs' count (5). Scopes cut that to 29 (operate), 32 (lean), 54 (browser) or 60 (build) through a URL such as /mcp/x/lean or the X-Skyvern-Scope header, and page reads are size-capped and selector-scoped (9, so 14). List endpoints take page and page_size, with status, search_key, tag and date filters, and max_steps bounds a run (17). MCP results return codes such as SELECTOR_NOT_FOUND and SESSION_EXPIRED with a hint, runs report status, failure_reason and a caller-defined error_code_mapping, and the SDKs raise typed errors. HTTP error bodies are mostly unspecified (16). Every tool has readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source. Idempotency-Key covers agent creation only, not run submission (14). A task needs only a prompt, and official SDKs exist for Python and TypeScript (15). | |||
| Security & auth | 14%17.5 | 10.3 | |
An organisation-wide API key in the x-api-key header, revocable and rotated from Settings, or OAuth 2.0 with PKCE, dynamic client registration and rotating single-use refresh tokens. The docs say plainly that OAuth scopes are identity claims and that there are no read-only, per-endpoint or per-resource credentials, so we scored plain revocable keys. No secret travels in a URL (20). MCP tool scopes are documented as a usability filter and not a permission boundary. Separate organisations are the only isolation, Human Interaction blocks are listed for Enterprise, and skyvern_act rejects prompts that contain passwords (6). Web pages are untrusted content. Stored credentials reach the browser directly and appear to the model as placeholders, the May 2026 changelog records sanitising of page content in prompt templates, and one tool description says page content is data, not instructions. We found no guidance page on prompt injection (8). GET /v1/audit-events/export returns organisation audit events for a default 90 days as JSON or CSV, and each run keeps a recording, screenshots, an action timeline and a HAR file (14). The site claims SOC 2 Type II and HIPAA on Enterprise, with a trust centre that didn't render for us. SECURITY.md routes reports to GitHub private advisories and its supported-versions table still says 0.1.x. No security.txt and no bug bounty found. The webhook page warns that its verifier examples before August 2026 accepted any signature of the right length (11). | |||
| Payments & pricing | 10%12.5 | 4.0 | |
No x402, MPP or L402 in the docs, llms.txt or pricing page (0). Plan prices are public with credit allowances, Free 5,000 credits once, Hobby $29 for 30,000 a month, Pro $149 for 150,000, Enterprise custom. The price of extra credits isn't published, and the pages disagree on what a credit buys, one credit an action in the billing docs against about 170 or about 200 actions for 5,000 credits (12). The Free plan needs no card, per the pricing page (20). Signup is a browser flow, including skyvern signup from the CLI, so a person has to create the account (0). The open-source server is free to run under AGPL-3.0 with your own model keys, and we scored the hosted service because that is what the MCP and API docs point agents to. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.4 | |
| Version 1.0.55 on PyPI and npm on 1 October 2026, seven days before this check (30). Twelve weekly changelog entries since 13 July 2026, and PyPI releases 1.0.47, 1.0.48 and 1.0.55 in the same period (20). The repository had 200 commits between 16 September and 7 October and 48 open issues, several opened in the last fortnight. GitHub didn't show us the replies, and an issue of 8 September 2026 asks whether anyone watches the private advisory queue, so we scored this below full (14). Listed in the official MCP registry as io.github.Skyvern-AI/skyvern, active, but the entry is version 1.0.23 from 13 March 2026 and lists only the API-key header (13). CI runs pre-commit hooks, a migration check, pytest and pip smoke tests on Python 3.11 and 3.13, with a locked dependency file. We couldn't read whether the default branch passes (8). | |||
| Transparency & trusteditorial 66, provenance 78 | 7%8.8 | 6.3 | |
The core is AGPL-3.0, an OSI licence, in a public repository. The README says anti-bot measures are in the managed cloud only (27). The privacy policy (last modified 1 October 2026) keeps data "as long as necessary" with deletion on request and no stated periods. The terms (27 February 2026) say data may go to third-party model providers such as OpenAI and Anthropic and that anonymised data may train models unless you opt out by email. Section 7.3 of the terms says the services aren't designed to comply with HIPAA, while the pricing page lists HIPAA compliance on Enterprise. No public DPA found (12). The deprecation policy promises at least six months' notice, 12 for a major version, a changelog entry, Deprecation and Sunset headers and deprecated flags in the spec (20). Model providers are named only as examples, artifact URLs point to Amazon S3, and no subprocessor list or data location statement was readable. The open-source server discloses PostHog usage telemetry in its README with SKYVERN_TELEMETRY=false to turn it off (7). | |||
| Negative events | ≤15 |
| -3 |
| Total | 63.1 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 21 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Skyvern, or have the agent fetch /fixes/skyvern.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Skyvern From Anchor Terminal's listing at https://www.anchorterminal.com/tools/skyvern, the October 2026 research run, assessed 8 October 2026. Grade B, 63.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Skyvern: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 57 out of 100, up to 8.6 more on the total Why it scored 57: Graded as a hosted service, Skyvern Cloud at api.skyvern.com. status.skyvern.com is a Statuspage site with three components (API, web application, async workers), 90-day uptime bars and an incident feed back to March 2025 (20). The feed has one incident in the 90 days to 8 October 2026, marked major by Skyvern, on 6 August, when an upstream model provider rejected requests and task and workflow runs failed at elevated rates from about 21:20 UTC to 22:30, roughly 70 minutes. A 29-minute run of 503s on 3 July falls just outside the window (10). The pricing page gives concurrent runs per plan (1, 10, 25, 100) and API responses carry `ratelimit-policy: "submit-run";q=50;w=60`, but we found no documented request limits (8). The OpenAPI document describes 503 with `Retry-After` on run submission and 429 on two recipe endpoints, and the SDKs retry network errors and 5xx with backoff. `Idempotency-Key` exists only on POST /v1/agents, so retried run submissions rely on the 503 saying no run was created (9). The pricing FAQ mentions custom SLAs for Enterprise and nothing is published (0). `/v1` is declared stable (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 32 out of 100, up to 8.5 more on the total Why it scored 32: No x402, MPP or L402 in the docs, llms.txt or pricing page (0). Plan prices are public with credit allowances, Free 5,000 credits once, Hobby $29 for 30,000 a month, Pro $149 for 150,000, Enterprise custom. The price of extra credits isn't published, and the pages disagree on what a credit buys, one credit an action in the billing docs against about 170 or about 200 actions for 5,000 credits (12). The Free plan needs no card, per the pricing page (20). Signup is a browser flow, including `skyvern signup` from the CLI, so a person has to create the account (0). The open-source server is free to run under AGPL-3.0 with your own model keys, and we scored the hosted service because that is what the MCP and API docs point agents to. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 59 out of 100, up to 7.2 more on the total Why it scored 59: An organisation-wide API key in the `x-api-key` header, revocable and rotated from Settings, or OAuth 2.0 with PKCE, dynamic client registration and rotating single-use refresh tokens. The docs say plainly that OAuth scopes are identity claims and that there are no read-only, per-endpoint or per-resource credentials, so we scored plain revocable keys. No secret travels in a URL (20). MCP tool scopes are documented as a usability filter and not a permission boundary. Separate organisations are the only isolation, Human Interaction blocks are listed for Enterprise, and `skyvern_act` rejects prompts that contain passwords (6). Web pages are untrusted content. Stored credentials reach the browser directly and appear to the model as placeholders, the May 2026 changelog records sanitising of page content in prompt templates, and one tool description says page content is data, not instructions. We found no guidance page on prompt injection (8). GET /v1/audit-events/export returns organisation audit events for a default 90 days as JSON or CSV, and each run keeps a recording, screenshots, an action timeline and a HAR file (14). The site claims SOC 2 Type II and HIPAA on Enterprise, with a trust centre that didn't render for us. SECURITY.md routes reports to GitHub private advisories and its supported-versions table still says 0.1.x. No security.txt and no bug bounty found. The webhook page warns that its verifier examples before August 2026 accepted any signature of the right length (11). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 76 out of 100, up to 3.9 more on the total Why it scored 76: The full MCP surface is 114 tools by the docs' count (5). Scopes cut that to 29 (`operate`), 32 (`lean`), 54 (`browser`) or 60 (`build`) through a URL such as /mcp/x/lean or the `X-Skyvern-Scope` header, and page reads are size-capped and selector-scoped (9, so 14). List endpoints take `page` and `page_size`, with `status`, `search_key`, tag and date filters, and `max_steps` bounds a run (17). MCP results return codes such as SELECTOR_NOT_FOUND and SESSION_EXPIRED with a hint, runs report `status`, `failure_reason` and a caller-defined `error_code_mapping`, and the SDKs raise typed errors. HTTP error bodies are mostly unspecified (16). Every tool has readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source. `Idempotency-Key` covers agent creation only, not run submission (14). A task needs only a prompt, and official SDKs exist for Python and TypeScript (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Transparency & trust, 72 out of 100, up to 2.5 more on the total Made of editorial 66, provenance 78. Why it scored 72: The core is AGPL-3.0, an OSI licence, in a public repository. The README says anti-bot measures are in the managed cloud only (27). The privacy policy (last modified 1 October 2026) keeps data "as long as necessary" with deletion on request and no stated periods. The terms (27 February 2026) say data may go to third-party model providers such as OpenAI and Anthropic and that anonymised data may train models unless you opt out by email. Section 7.3 of the terms says the services aren't designed to comply with HIPAA, while the pricing page lists HIPAA compliance on Enterprise. No public DPA found (12). The deprecation policy promises at least six months' notice, 12 for a major version, a changelog entry, `Deprecation` and `Sunset` headers and `deprecated` flags in the spec (20). Model providers are named only as examples, artifact URLs point to Amazon S3, and no subprocessor list or data location statement was readable. The open-source server discloses PostHog usage telemetry in its README with `SKYVERN_TELEMETRY=false` to turn it off (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: skyvern.com, registered 2023-10-16 (2 years) (7 of 15) - Terms of service: read, states 6 of the 7 things a reader expects (9.1 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects, and has 1 clause that costs points (7.3 of 10) - security.txt: not found (0 of 10) ## 6. Schema & documentation, 88 out of 100, up to 2 more on the total Why it scored 88: OpenAPI 3.1.0 at /docs/api-reference/openapi.json with 94 operations on 71 paths and 261 schemas, and MCP tools with typed parameters (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). The MCP server ships a routing table that says which tool to use for each kind of job, what each costs in model calls and what not to use it for, and tool docstrings repeat it. Many REST operations have one-line descriptions such as "Run a task" (16). Inputs are typed with enums and ranges, such as `limit` 1 to 500 on the audit export, but `skyvern_workflow_create` takes the whole definition as a JSON or YAML string and the spec marks `x-api-key` as optional on every operation (11). Code samples in Python, TypeScript and cURL and a full error-handling guide, while 422 is the only error documented on most operations, with 404 on 31 of 94 and 429 on two (11). `/v1` path versioning with a written compatibility policy and a weekly dated changelog (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Maintenance & community, 85 out of 100, up to 1.3 more on the total Why it scored 85: Version 1.0.55 on PyPI and npm on 1 October 2026, seven days before this check (30). Twelve weekly changelog entries since 13 July 2026, and PyPI releases 1.0.47, 1.0.48 and 1.0.55 in the same period (20). The repository had 200 commits between 16 September and 7 October and 48 open issues, several opened in the last fortnight. GitHub didn't show us the replies, and an issue of 8 September 2026 asks whether anyone watches the private advisory queue, so we scored this below full (14). Listed in the official MCP registry as io.github.Skyvern-AI/skyvern, active, but the entry is version 1.0.23 from 13 March 2026 and lists only the API-key header (13). CI runs pre-commit hooks, a migration check, pytest and pip smoke tests on Python 3.11 and 3.13, with a locked dependency file. We couldn't read whether the default branch passes (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 2026-06-30. A public issue reports non-blind SSRF from workflow `http_request` and file download blocks to loopback, private and metadata addresses in version 1.0.39, with a reproduction (https://github.com/Skyvern-AI/skyvern/issues/6915). The issue is still open on 8 October 2026 and no advisory is published, but the 1.0.55 source routes these requests through an SSRF-guarded resolver, so we deduct 3 and not more. We didn't reproduce it, and whether Skyvern Cloud was exposed isn't stated. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the trust centre at trust.skyvern.com is a JavaScript application that didn't render for our reader, so the SOC 2 Type II report, the HIPAA statement and any subprocessor list rest on the pricing and home pages - unchecked: reply times on GitHub issues and whether CI passes on the default branch. The GitHub API refused us for rate limits and the issue pages didn't show comments - unchecked: whether the SSRF reported in issue 6915 affected Skyvern Cloud, and which release added the SSRF-guarded resolver. The changelog doesn't mention it - What a credit buys. The billing docs say one credit a browser action, the pricing page says 5,000 credits is about 170 actions, the cost-control page about 200, and the pricing FAQ says credits depend on run complexity and duration - Whether the `ratelimit-policy` header (50 run submissions in 60 seconds) is the enforced limit on every plan. It isn't documented - Enterprise concurrency is 100 on the pricing page and unlimited in the billing docs - Whether the permissive webhook verifier examples before August 2026 merit a deduction. We recorded them in the security note and didn't deduct, because the page discloses the fault and we couldn't date the fix - The audit export says only organisation admins and full API keys may export, which implies a restricted key type that the authentication page says doesn't exist - firstReleased is left empty. PyPI's earliest file is 0.1.53 from 6 February 2025, and the repository is older ## Weaknesses - Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys - No request rate limits in the docs. Responses carry `ratelimit-policy: "submit-run";q=50;w=60`, and only plan concurrency is published - What a credit buys is stated three ways (one credit an action, 5,000 credits for about 170 or about 200 actions, by run complexity) - An SSRF report against 1.0.39 from 30 June 2026 is still open with no advisory, though 1.0.55 source has SSRF guards - Retention is "as long as necessary", anonymised data may train models unless you opt out by email, and no subprocessor list was readable ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send `X-Skyvern-Scope`, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions - Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows - Never pass passwords to `skyvern_act` or `skyvern_type`. Store them as credentials and call `skyvern_login` - Set `max_steps` on tasks, or `x-max-steps-override` on agent runs, to cap credits. A run that reaches the cap ends as `timed_out` - On 503 from POST /v1/run/agents, wait `Retry-After` seconds. No run was created, so resubmitting is safe ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the trust centre at trust.skyvern.com is a JavaScript application that didn't render for our reader, so the SOC 2 Type II report, the HIPAA statement and any subprocessor list rest on the pricing and home pages
- unchecked: reply times on GitHub issues and whether CI passes on the default branch. The GitHub API refused us for rate limits and the issue pages didn't show comments
- unchecked: whether the SSRF reported in issue 6915 affected Skyvern Cloud, and which release added the SSRF-guarded resolver. The changelog doesn't mention it
- What a credit buys. The billing docs say one credit a browser action, the pricing page says 5,000 credits is about 170 actions, the cost-control page about 200, and the pricing FAQ says credits depend on run complexity and duration
- Whether the
ratelimit-policyheader (50 run submissions in 60 seconds) is the enforced limit on every plan. It isn't documented - Enterprise concurrency is 100 on the pricing page and unlimited in the billing docs
- Whether the permissive webhook verifier examples before August 2026 merit a deduction. We recorded them in the security note and didn't deduct, because the page discloses the fault and we couldn't date the fix
- The audit export says only organisation admins and full API keys may export, which implies a restricted key type that the authentication page says doesn't exist
- firstReleased is left empty. PyPI's earliest file is 0.1.53 from 6 February 2025, and the repository is older
Sources 32
- home page skyvern.com · seen 2026-10-08
- pricing skyvern.com · seen 2026-10-08
- docs index skyvern.com · seen 2026-10-08
- full docs text skyvern.com · seen 2026-10-08
- authentication and permissions skyvern.com · seen 2026-10-08
- versioning and deprecation skyvern.com · seen 2026-10-08
- MCP server setup skyvern.com · seen 2026-10-08
- OpenAPI document skyvern.com · seen 2026-10-08
- error handling skyvern.com · seen 2026-10-08
- SDK error handling and retries skyvern.com · seen 2026-10-08
- webhooks and signature verification skyvern.com · seen 2026-10-08
- cost control skyvern.com · seen 2026-10-08
- billing and usage skyvern.com · seen 2026-10-08
- changelog skyvern.com · seen 2026-10-08
- status page status.skyvern.com · seen 2026-10-08
- incident feed status.skyvern.com · seen 2026-10-08
- OAuth protected-resource metadata api.skyvern.com · seen 2026-10-08
- API response headers, unauthenticated request api.skyvern.com · seen 2026-10-08
- privacy policy skyvern.com · seen 2026-10-08
- terms of service skyvern.com · seen 2026-10-08
- trust centre (didn't render) trust.skyvern.com · seen 2026-10-08
- security.txt (404) skyvern.com · seen 2026-10-08
- repository at v1.0.55, licence, MCP tool source, CI workflows, SECURITY.md github.com · seen 2026-10-08
- open issues list github.com · seen 2026-10-08
- SSRF issue github.com · seen 2026-10-08
- advisory queue issue github.com · seen 2026-10-08
- published advisories (none) github.com · seen 2026-10-08
- OSV records for the PyPI package api.osv.dev · seen 2026-10-08
- MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- Python package on PyPI pypi.org · seen 2026-10-08
- TypeScript SDK on npm registry.npmjs.org · seen 2026-10-08
- domain registration rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $29 / mo Free with 5,000 one-time credits and 1 concurrent run, no card and no contract. Hobby $29 a month with 30,000 credits and 10 concurrent runs. Pro $149 with 150,000 credits and 25 concurrent runs. Enterprise is custom. Extra credits can be bought from the Billing page at a price that isn't published. The billing docs count one credit a browser action, while the pricing page puts 5,000 credits at about 170 actions. Self-hosting the AGPL-3.0 server is free with your own model keys (https://www.skyvern.com/pricing, https://www.skyvern.com/docs/cloud/account-settings/billing-usage.md, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Hobby plan | $29 | per month (plan) | 30,000 credits, 10 concurrent runs |
| Pro plan | $149 | per month (plan) | 150,000 credits, 25 concurrent runs |
| Skyvern SMS number, Pro plan | $10 | per month (plan) | per number, for SMS 2FA codes |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/skyvern.xml, or this listing's score history at history.json.
Connect
Install
pip install skyvern
First request
curl -X POST "https://api.skyvern.com/v1/run/tasks" -H "x-api-key: YOUR_API_KEY" -H "Content-Type: application/json" -d '{ "url": "https://example.com", "prompt": "Extract the pricing table" }'
Claude Code
claude mcp add --transport http skyvern https://api.skyvern.com/mcp/ --scope user
MCP client configuration
{
"mcpServers": {
"Skyvern": {
"headers": {
"x-api-key": "YOUR_SKYVERN_API_KEY"
},
"type": "streamable-http",
"url": "https://api.skyvern.com/mcp/"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/skyvern
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Browser Use BBBrowserless BBSteel BBHyperbrowser BChrome DevTools MCP BBBrowserbase BB
Head to head Browser Use vs Skyvern · Browserless vs Skyvern · Chrome DevTools MCP vs Skyvern · Hyperbrowser vs Skyvern · Playwright MCP vs Skyvern · Puppeteer (archived MCP reference server) vs Skyvern · Skyvern vs Steel · Browserbase vs Skyvern
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Browser Use Browser Use | BB | 77.9 | browser.control browser.hosted web.extract | ✓ |
| Browserless browserless.io, Inc. | BB | 70.4 | browser.control browser.hosted browser.debug | no |
| Steel Nen Labs, Inc. | BB | 70.4 | browser.control browser.hosted browser.debug | ✓ |
| Hyperbrowser S2 Labs Inc. | B | 66.9 | browser.control browser.hosted web.extract | ✓ |
| Chrome DevTools MCP Google (Chrome DevTools team) | BB | 77 | browser.control browser.debug | no |
| Browserbase Browserbase | BB | 76.2 | browser.hosted browser.control | ✓ |
Machine-readable
- JSON
/api/v1/tools/skyvern.json· historyhistory.json· badge/badges/skyvern.svg· changes feed/feeds/tools/skyvern.xml - Markdown
/tools/skyvern.md· slim/tools/skyvern.min.md(or sendAccept: text/markdown) - Fix list
/fixes/skyvern.md·/fixes/skyvern.json - From a terminal
anchor tool skyvern --md(the CLI) · over MCPget_tool {"slug": "skyvern"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/skyvern"><img src="https://www.anchorterminal.com/badges/skyvern.svg" alt="Skyvern on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/skyvern)<a href="https://www.anchorterminal.com/tools/skyvern">Skyvern on Anchor Terminal</a>It counts on a page on skyvern.com or one of its subdomains, or the README of github.com/Skyvern-AI/skyvern.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "skyvern", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
