# Skyvern > Skyvern is a browser agent that completes multi-step web workflows from natural-language goals using language models and computer vision. It runs as an AGPL-3.0 open-source server or a hosted cloud with a REST API and MCP server. - Canonical: https://www.anchorterminal.com/tools/skyvern - Markdown: https://www.anchorterminal.com/tools/skyvern.md (~8,800 tokens) - Slim: https://www.anchorterminal.com/tools/skyvern.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/skyvern.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 63.1/100 · rank #288 of 629 · #10 in Browser automation · not agent-ready · confidence medium** ## Assessment The hosted MCP server annotates every tool as read-only or destructive and can advertise a 29 or 32-tool subset in place of 114, and the API has a written six-month deprecation policy. Every key and OAuth token carries full organisation authority, with no read-only or scoped credential, and no request rate limits are documented. ## Facts | Field | Value | | --- | --- | | Vendor | Ikonomos Inc. (Skyvern) (https://www.skyvern.com) | | Kind | HTTP API | | Category | Browser automation (https://www.anchorterminal.com/categories/browser) | | Transport | HTTP, Streamable HTTP, stdio | | Endpoint | `https://api.skyvern.com/v1` | | Auth | OAuth or key · Self-serve. Sign up at app.skyvern.com and copy the organisation API key from Settings, sent as `x-api-key`. MCP clients can use OAuth 2.0 with browser sign-in, PKCE and dynamic client registration, with no client ID to configure. Both credentials carry full authority over the organisation. OAuth scopes are identity claims, and there are no read-only or per-endpoint keys (https://www.skyvern.com/docs/developers/api/authentication-and-permissions.md). | | Pricing | Freemium ($29 / mo) · Free with 5,000 one-time credits and 1 concurrent run, no card and no contract. Hobby $29 a month with 30,000 credits and 10 concurrent runs. Pro $149 with 150,000 credits and 25 concurrent runs. Enterprise is custom. Extra credits can be bought from the Billing page at a price that isn't published. The billing docs count one credit a browser action, while the pricing page puts 5,000 credits at about 170 actions. Self-hosting the AGPL-3.0 server is free with your own model keys (https://www.skyvern.com/pricing, https://www.skyvern.com/docs/cloud/account-settings/billing-usage.md, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs (llms-full.txt), llms.txt or the pricing page (checked 2026-10-08). | | Licence | AGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repository | | Tools exposed | 114 | | Packages | pypi: `skyvern`; npm: `@skyvern/client` | | MCP registry name | `io.github.Skyvern-AI/skyvern` | | Source | https://github.com/Skyvern-AI/skyvern | | Docs | https://www.skyvern.com/docs | | llms.txt | https://www.skyvern.com/docs/llms.txt | | Last release | 2026-10-01 | | GitHub stars | 23,155 (as of 2026-10-08) | | npm downloads / week | 3,193 | | PyPI downloads / week | 1,636 | | Graded surface | Skyvern Cloud, the REST API at https://api.skyvern.com/v1 and the hosted MCP server at https://api.skyvern.com/mcp. The same code is open source under AGPL-3.0 for self-hosting with your own model keys | | MCP server | Official. Hosted over streamable HTTP with OAuth or `x-api-key`, or local stdio with `python -m skyvern run mcp` against a self-hosted server. 114 tools at full scope, 29 `operate`, 60 `build`, 54 `browser`, 32 `lean`, chosen by /mcp/x/ or `X-Skyvern-Scope` | | Credentials | Organisation-wide API key in `x-api-key`, no expiry, rotated in Settings. OAuth 2.0 authorisation code with PKCE S256, dynamic client registration and rotating refresh tokens. OAuth scopes are identity claims only. No read-only or scoped credential | | Free tier | 5,000 credits once, 1 concurrent run, no card. The pricing page estimates about 170 actions and the billing docs about 200 | | Plans | Hobby $29 a month, 30,000 credits, 10 concurrent runs. Pro $149, 150,000 credits, 25 concurrent, residential proxies, TOTP and 1Password. Enterprise custom, 100 concurrent, HIPAA and the SOC 2 report | | Rate limits | Concurrent runs per plan are published. No request limits in the docs. Responses carry `ratelimit-policy: "submit-run";q=50;w=60`, and run submission can answer 503 with `Retry-After` | | Errors | Terminal run statuses include `completed`, `failed`, `terminated` and `timed_out`, with `failure_reason` and a caller-defined `error_code_mapping`. MCP results carry codes such as SELECTOR_NOT_FOUND with a hint | | SDKs | Python `skyvern` 1.0.55 (Python 3.11 to 3.14) and TypeScript `@skyvern/client` 1.0.55, both 1 October 2026, generated from the OpenAPI document | | Audit | GET /v1/audit-events/export, default window 90 days, JSON or CSV, up to 500 a page. Each run keeps a recording, screenshots, an action timeline and a HAR file | | Deprecations | At least six months' notice, 12 for a major version, `Deprecation` and `Sunset` headers, `deprecated` flags in the OpenAPI document. No /v1 endpoint is deprecated today | | Status | status.skyvern.com on Statuspage, three components. One incident in the 90 days to 8 October 2026, about 70 minutes of elevated run failures on 6 August | | Reuse terms | You are responsible for the target site's terms and for authorisation to automate it. Data may be sent to third-party model providers, and anonymised data may train models unless you opt out by email | | Capabilities | browser.control, browser.hosted, web.extract, automation.workflows, browser.debug | | Tags | official, hosted, open-source, freemium, no-card, mcp, oauth, openapi, llms-txt, python, typescript, status-page, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/skyvern.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 57 | 11.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 88 | 14.3 | | Agent ergonomics | 13% | 16.2 | 76 | 12.3 | | Security & auth | 14% | 17.5 | 59 | 10.3 | | Payments & pricing | 10% | 12.5 | 32 | 4.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 85 | 7.4 | | Transparency & trust (editorial 66, provenance 78) | 7% | 8.8 | 72 | 6.3 | | Negative events | up to −15 | up to −15 | 2026-06-30. A public issue reports non-blind SSRF from workflow `http_request` and file download blocks to loopback, private and metadata addresses in version 1.0.39, with a reproduction (https://github.com/Skyvern-AI/skyvern/issues/6915). The issue is still open on 8 October 2026 and no advisory is published, but the 1.0.55 source routes these requests through an SSRF-guarded resolver, so we deduct 3 and not more. We didn't reproduce it, and whether Skyvern Cloud was exposed isn't stated. | -3 | | **Total** | | | | **63.1 → B** | ### Why each score - Reliability 57: Graded as a hosted service, Skyvern Cloud at api.skyvern.com. status.skyvern.com is a Statuspage site with three components (API, web application, async workers), 90-day uptime bars and an incident feed back to March 2025 (20). The feed has one incident in the 90 days to 8 October 2026, marked major by Skyvern, on 6 August, when an upstream model provider rejected requests and task and workflow runs failed at elevated rates from about 21:20 UTC to 22:30, roughly 70 minutes. A 29-minute run of 503s on 3 July falls just outside the window (10). The pricing page gives concurrent runs per plan (1, 10, 25, 100) and API responses carry `ratelimit-policy: "submit-run";q=50;w=60`, but we found no documented request limits (8). The OpenAPI document describes 503 with `Retry-After` on run submission and 429 on two recipe endpoints, and the SDKs retry network errors and 5xx with backoff. `Idempotency-Key` exists only on POST /v1/agents, so retried run submissions rely on the 503 saying no run was created (9). The pricing FAQ mentions custom SLAs for Enterprise and nothing is published (0). `/v1` is declared stable (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 88: OpenAPI 3.1.0 at /docs/api-reference/openapi.json with 94 operations on 71 paths and 261 schemas, and MCP tools with typed parameters (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). The MCP server ships a routing table that says which tool to use for each kind of job, what each costs in model calls and what not to use it for, and tool docstrings repeat it. Many REST operations have one-line descriptions such as "Run a task" (16). Inputs are typed with enums and ranges, such as `limit` 1 to 500 on the audit export, but `skyvern_workflow_create` takes the whole definition as a JSON or YAML string and the spec marks `x-api-key` as optional on every operation (11). Code samples in Python, TypeScript and cURL and a full error-handling guide, while 422 is the only error documented on most operations, with 404 on 31 of 94 and 429 on two (11). `/v1` path versioning with a written compatibility policy and a weekly dated changelog (15). - Agent ergonomics 76: The full MCP surface is 114 tools by the docs' count (5). Scopes cut that to 29 (`operate`), 32 (`lean`), 54 (`browser`) or 60 (`build`) through a URL such as /mcp/x/lean or the `X-Skyvern-Scope` header, and page reads are size-capped and selector-scoped (9, so 14). List endpoints take `page` and `page_size`, with `status`, `search_key`, tag and date filters, and `max_steps` bounds a run (17). MCP results return codes such as SELECTOR_NOT_FOUND and SESSION_EXPIRED with a hint, runs report `status`, `failure_reason` and a caller-defined `error_code_mapping`, and the SDKs raise typed errors. HTTP error bodies are mostly unspecified (16). Every tool has readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source. `Idempotency-Key` covers agent creation only, not run submission (14). A task needs only a prompt, and official SDKs exist for Python and TypeScript (15). - Security & auth 59: An organisation-wide API key in the `x-api-key` header, revocable and rotated from Settings, or OAuth 2.0 with PKCE, dynamic client registration and rotating single-use refresh tokens. The docs say plainly that OAuth scopes are identity claims and that there are no read-only, per-endpoint or per-resource credentials, so we scored plain revocable keys. No secret travels in a URL (20). MCP tool scopes are documented as a usability filter and not a permission boundary. Separate organisations are the only isolation, Human Interaction blocks are listed for Enterprise, and `skyvern_act` rejects prompts that contain passwords (6). Web pages are untrusted content. Stored credentials reach the browser directly and appear to the model as placeholders, the May 2026 changelog records sanitising of page content in prompt templates, and one tool description says page content is data, not instructions. We found no guidance page on prompt injection (8). GET /v1/audit-events/export returns organisation audit events for a default 90 days as JSON or CSV, and each run keeps a recording, screenshots, an action timeline and a HAR file (14). The site claims SOC 2 Type II and HIPAA on Enterprise, with a trust centre that didn't render for us. SECURITY.md routes reports to GitHub private advisories and its supported-versions table still says 0.1.x. No security.txt and no bug bounty found. The webhook page warns that its verifier examples before August 2026 accepted any signature of the right length (11). - Payments & pricing 32: No x402, MPP or L402 in the docs, llms.txt or pricing page (0). Plan prices are public with credit allowances, Free 5,000 credits once, Hobby $29 for 30,000 a month, Pro $149 for 150,000, Enterprise custom. The price of extra credits isn't published, and the pages disagree on what a credit buys, one credit an action in the billing docs against about 170 or about 200 actions for 5,000 credits (12). The Free plan needs no card, per the pricing page (20). Signup is a browser flow, including `skyvern signup` from the CLI, so a person has to create the account (0). The open-source server is free to run under AGPL-3.0 with your own model keys, and we scored the hosted service because that is what the MCP and API docs point agents to. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 85: Version 1.0.55 on PyPI and npm on 1 October 2026, seven days before this check (30). Twelve weekly changelog entries since 13 July 2026, and PyPI releases 1.0.47, 1.0.48 and 1.0.55 in the same period (20). The repository had 200 commits between 16 September and 7 October and 48 open issues, several opened in the last fortnight. GitHub didn't show us the replies, and an issue of 8 September 2026 asks whether anyone watches the private advisory queue, so we scored this below full (14). Listed in the official MCP registry as io.github.Skyvern-AI/skyvern, active, but the entry is version 1.0.23 from 13 March 2026 and lists only the API-key header (13). CI runs pre-commit hooks, a migration check, pytest and pip smoke tests on Python 3.11 and 3.13, with a locked dependency file. We couldn't read whether the default branch passes (8). - Transparency & trust 72: The core is AGPL-3.0, an OSI licence, in a public repository. The README says anti-bot measures are in the managed cloud only (27). The privacy policy (last modified 1 October 2026) keeps data "as long as necessary" with deletion on request and no stated periods. The terms (27 February 2026) say data may go to third-party model providers such as OpenAI and Anthropic and that anonymised data may train models unless you opt out by email. Section 7.3 of the terms says the services aren't designed to comply with HIPAA, while the pricing page lists HIPAA compliance on Enterprise. No public DPA found (12). The deprecation policy promises at least six months' notice, 12 for a major version, a changelog entry, `Deprecation` and `Sunset` headers and `deprecated` flags in the spec (20). Model providers are named only as examples, artifact URLs point to Amazon S3, and no subprocessor list or data location statement was readable. The open-source server discloses PostHog usage telemetry in its README with `SKYVERN_TELEMETRY=false` to turn it off (7). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/skyvern.md (JSON https://www.anchorterminal.com/fixes/skyvern.json) ### What we couldn't check - unchecked: the trust centre at trust.skyvern.com is a JavaScript application that didn't render for our reader, so the SOC 2 Type II report, the HIPAA statement and any subprocessor list rest on the pricing and home pages - unchecked: reply times on GitHub issues and whether CI passes on the default branch. The GitHub API refused us for rate limits and the issue pages didn't show comments - unchecked: whether the SSRF reported in issue 6915 affected Skyvern Cloud, and which release added the SSRF-guarded resolver. The changelog doesn't mention it - What a credit buys. The billing docs say one credit a browser action, the pricing page says 5,000 credits is about 170 actions, the cost-control page about 200, and the pricing FAQ says credits depend on run complexity and duration - Whether the `ratelimit-policy` header (50 run submissions in 60 seconds) is the enforced limit on every plan. It isn't documented - Enterprise concurrency is 100 on the pricing page and unlimited in the billing docs - Whether the permissive webhook verifier examples before August 2026 merit a deduction. We recorded them in the security note and didn't deduct, because the page discloses the fault and we couldn't date the fix - The audit export says only organisation admins and full API keys may export, which implies a restricted key type that the authentication page says doesn't exist - firstReleased is left empty. PyPI's earliest file is 0.1.53 from 6 February 2025, and the repository is older ### Sources - home page: (seen 2026-10-08) - pricing: (seen 2026-10-08) - docs index: (seen 2026-10-08) - full docs text: (seen 2026-10-08) - authentication and permissions: (seen 2026-10-08) - versioning and deprecation: (seen 2026-10-08) - MCP server setup: (seen 2026-10-08) - OpenAPI document: (seen 2026-10-08) - error handling: (seen 2026-10-08) - SDK error handling and retries: (seen 2026-10-08) - webhooks and signature verification: (seen 2026-10-08) - cost control: (seen 2026-10-08) - billing and usage: (seen 2026-10-08) - changelog: (seen 2026-10-08) - status page: (seen 2026-10-08) - incident feed: (seen 2026-10-08) - OAuth protected-resource metadata: (seen 2026-10-08) - API response headers, unauthenticated request: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - trust centre (didn't render): (seen 2026-10-08) - security.txt (404): (seen 2026-10-08) - repository at v1.0.55, licence, MCP tool source, CI workflows, SECURITY.md: (seen 2026-10-08) - open issues list: (seen 2026-10-08) - SSRF issue: (seen 2026-10-08) - advisory queue issue: (seen 2026-10-08) - published advisories (none): (seen 2026-10-08) - OSV records for the PyPI package: (seen 2026-10-08) - MCP registry search: (seen 2026-10-08) - Python package on PyPI: (seen 2026-10-08) - TypeScript SDK on npm: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 78/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Ikonomos Inc. | 20/20 | | Domain age | skyvern.com, registered 2023-10-16 (2 years) | 7/15 | | Endpoint on the vendor's domain | api.skyvern.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 | | Status page | status.skyvern.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms (last modified 27 February 2026) and privacy policy (last modified 1 October 2026) name Ikonomos Inc., doing business as Skyvern, with Delaware law governing the terms. The API and the hosted MCP server answer at api.skyvern.com. OAuth is issued through clerk.skyvern.com, backed by Clerk. www.skyvern.com/.well-known/security.txt and api.skyvern.com/.well-known/security.txt both return 404. SECURITY.md in the repository sends reports to GitHub private advisories. RDAP for skyvern.com gives a registration date of 2023-10-16. docs.skyvern.com redirects to www.skyvern.com/docs. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.skyvern.com/terms), read 2026-10-08, dated 2026-02-27, states 6 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "We may use anonymized or aggregated data for service improvement and model training; and" - To know. Says access can be ended without notice or for any reason. "We may terminate or suspend your access to the Services immediately, without prior notice or liability, for any reason, including if you breach these Terms." - To know. Requires arbitration or waives class actions. "Dispute Resolution: Disputes are governed by Delaware law and subject to binding arbitration." - Gives the date it was last updated. Last updated 2026-02-27. - Names the governing law or courts. The law of the State of Delaware. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Changes are posted, with no other notice named. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The customer alone is responsible for complying with the terms and acceptable use policies of any third-party website it accesses through the service. "You are solely responsible for compliance with the terms of service, acceptable use policies, and other agreements of any third-party websites you access through the Services." - Also in the text (2026-10-08). A claim must be started within one year of the cause of action arising or it is permanently barred. "Any cause of action or claim you may have arising out of or relating to these Terms or the Services must be commenced within one (1) year after the cause of action accrues; otherwise, such cause of action or claim is permanently barred." - Also in the text (2026-10-08). Customer data may be sent to and processed by third-party LLM providers, with OpenAI and Anthropic named as examples. "Your data may be transmitted to and processed by third-party LLM providers (such as OpenAI and Anthropic);" **Privacy policy** (https://www.skyvern.com/privacy), read 2026-10-08, dated 2026-10-01, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "To train and improve our machine learning models using anonymized data." - Gives the date it was last updated. Last updated 2026-10-01. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Screenshots of automation sessions are sent to LLM providers including OpenAI, Anthropic, Google Gemini, Azure OpenAI and AWS Bedrock. "We send screenshots to LLM providers (including OpenAI, Anthropic, Google Gemini, Azure OpenAI, and AWS Bedrock) for AI-powered visual analysis and automation processing." - Also in the text (2026-10-08). Connecting the Google Drive integration grants Skyvern full access to the files in the customer's Google Drive, which it says it uses only for uploads and folder lookups. "connecting this integration grants Skyvern full access to the files in your Google Drive; we use that access only for the uploads and folder lookups described here, and do not read, modify, or delete your other Drive content." - Also in the text (2026-10-08). Automation tasks are performed through residential proxy networks. "Proxy Network Providers: We use residential proxy networks to perform automation tasks." ## Live (updated 2026-10-08 17:36 UTC) - Right now: up, HTTP 404, 266 ms, checked 2026-10-08 17:36 UTC (get on `https://api.skyvern.com/v1`) - Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 266 ms · p95 395 ms - Vendor status page: none, All Systems Operational - github `Skyvern-AI/skyvern` v1.0.55, released 2026-10-01 - npm `@skyvern/client` 1.0.55 - pypi `skyvern` 1.0.55, released 2026-10-01 - security.txt: none - Always current: https://www.anchorterminal.com/api/v1/live/skyvern.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Hobby plan | $29 | per month (plan) | 30,000 credits, 10 concurrent runs | | Pro plan | $149 | per month (plan) | 150,000 credits, 25 concurrent runs | | Skyvern SMS number, Pro plan | $10 | per month (plan) | per number, for SMS 2FA codes | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Every MCP tool carries readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source - Hosted MCP scopes cut the advertised tools from 114 to 29 (`operate`) or 32 (`lean`) by URL or `X-Skyvern-Scope` header - Written deprecation policy with six months' notice, 12 for a major version, and `Deprecation` and `Sunset` response headers - OpenAPI 3.1.0 with 94 operations, llms.txt, Markdown twins of every docs page and a weekly dated changelog - Stored passwords, cards and TOTP secrets are injected into the browser and replaced by placeholders in prompts, recordings and logs, per the docs ## Weaknesses - Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys - No request rate limits in the docs. Responses carry `ratelimit-policy: "submit-run";q=50;w=60`, and only plan concurrency is published - What a credit buys is stated three ways (one credit an action, 5,000 credits for about 170 or about 200 actions, by run complexity) - An SSRF report against 1.0.39 from 30 June 2026 is still open with no advisory, though 1.0.55 source has SSRF guards - Retention is "as long as necessary", anonymised data may train models unless you opt out by email, and no subprocessor list was readable ## Before you call it (notes for agents) 1. Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send `X-Skyvern-Scope`, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions 2. Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows 3. Never pass passwords to `skyvern_act` or `skyvern_type`. Store them as credentials and call `skyvern_login` 4. Set `max_steps` on tasks, or `x-max-steps-override` on agent runs, to cap credits. A run that reaches the cap ends as `timed_out` 5. On 503 from POST /v1/run/agents, wait `Retry-After` seconds. No run was created, so resubmitting is safe ## Connect Install: ```bash pip install skyvern ``` First request: ```bash curl -X POST "https://api.skyvern.com/v1/run/tasks" -H "x-api-key: YOUR_API_KEY" -H "Content-Type: application/json" -d '{ "url": "https://example.com", "prompt": "Extract the pricing table" }' ``` Claude Code: ```bash claude mcp add --transport http skyvern https://api.skyvern.com/mcp/ --scope user ``` MCP client configuration: ```json { "mcpServers": { "Skyvern": { "headers": { "x-api-key": "YOUR_SKYVERN_API_KEY" }, "type": "streamable-http", "url": "https://api.skyvern.com/mcp/" } } } ``` Through letme (picks today, calling later): https://letme.dev/skyvern. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Browser Use | BB | 77.9 | 16 | browser.control, browser.hosted, web.extract | yes | https://www.anchorterminal.com/tools/browser-use.md | | Browserless | BB | 70.4 | 128 | browser.control, browser.hosted, browser.debug | no | https://www.anchorterminal.com/tools/browserless.md | | Steel | BB | 70.4 | 129 | browser.control, browser.hosted, browser.debug | yes | https://www.anchorterminal.com/tools/steel.md | | Anchor Browser | B | 67.3 | 196 | browser.control, browser.hosted, browser.debug | no | https://www.anchorterminal.com/tools/anchor-browser.md | | Hyperbrowser | B | 66.9 | 205 | browser.control, browser.hosted, web.extract | yes | https://www.anchorterminal.com/tools/hyperbrowser.md | | Notte | B | 63.2 | 285 | browser.control, browser.hosted, web.extract | no | https://www.anchorterminal.com/tools/notte.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The hosted MCP server at https://api.skyvern.com/mcp accepts OAuth or `x-api-key`, and scopes `operate`, `build`, `browser` and `lean` narrow the advertised tools without narrowing permissions (source: ) - Every MCP tool is registered with readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in skyvern/cli/mcp_tools/__init__.py at v1.0.55 (source: ) - The deprecation policy promises at least six months' notice, 12 months for a major version, and `Deprecation` and `Sunset` headers (source: ) - One incident in the 90 days to 8 October 2026, elevated task and workflow failures for about 70 minutes on 6 August after an upstream model provider rejected requests (source: ) - A public issue of 30 June 2026 reports SSRF from workflow HTTP and download blocks in 1.0.39. It is still open, and the 1.0.55 source has an SSRF-guarded resolver (source: ) - The webhook docs warn that verifier examples published before August 2026 accepted any signature of the right length (source: ) - The MCP registry entry is version 1.0.23 from 13 March 2026, while PyPI and npm are at 1.0.55 from 1 October 2026 (source: ) ## Compare - [Airtop vs Skyvern](https://www.anchorterminal.com/compare/airtop-vs-skyvern.md): C 55.3 vs B 63.1 - [Anchor Browser vs Skyvern](https://www.anchorterminal.com/compare/anchor-browser-vs-skyvern.md): B 67.3 vs B 63.1 - [Browser Use vs Skyvern](https://www.anchorterminal.com/compare/browser-use-vs-skyvern.md): BB 77.9 vs B 63.1 - [Browserless vs Skyvern](https://www.anchorterminal.com/compare/browserless-vs-skyvern.md): BB 70.4 vs B 63.1 - [Chrome DevTools MCP vs Skyvern](https://www.anchorterminal.com/compare/chrome-devtools-mcp-vs-skyvern.md): BB 77 vs B 63.1 - [Hyperbrowser vs Skyvern](https://www.anchorterminal.com/compare/hyperbrowser-vs-skyvern.md): B 66.9 vs B 63.1 - [Notte vs Skyvern](https://www.anchorterminal.com/compare/notte-vs-skyvern.md): B 63.2 vs B 63.1 - [Playwright MCP vs Skyvern](https://www.anchorterminal.com/compare/playwright-mcp-vs-skyvern.md): B 67.6 vs B 63.1 - [Puppeteer (archived MCP reference server) vs Skyvern](https://www.anchorterminal.com/compare/puppeteer-reference-server-archived-vs-skyvern.md): F 30.6 vs B 63.1 - [Skyvern vs Steel](https://www.anchorterminal.com/compare/skyvern-vs-steel.md): B 63.1 vs BB 70.4 - [Browserbase vs Skyvern](https://www.anchorterminal.com/compare/browserbase-vs-skyvern.md): BB 76.2 vs B 63.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on skyvern.com or one of its subdomains, or the README of github.com/Skyvern-AI/skyvern. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "skyvern", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Skyvern on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Skyvern on Anchor Terminal](https://www.anchorterminal.com/badges/skyvern.svg)](https://www.anchorterminal.com/tools/skyvern) ``` Plain link: ```html Skyvern on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Skyvern is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/skyvern-dark.png - Light: https://www.anchorterminal.com/assets/share/skyvern-light.png