Sprout Social API

by Sprout Social, Inc. HTTP API in Social media posting APIs

Hosted

Sprout Social, Inc. · sproutsocial.com since 2009 · status page · who's behind it

Sprout Social is a social media management suite. Its REST API reads profile and post analytics, inbox messages, listening topics and cases for connected profiles, and creates draft posts with media, on plans that include API access.

Good for Reporting agents that pull profile, post, inbox, listening and case data for a company that already pays for Sprout Social, and for drafting posts a person will approve.

Is this your product? Claim this listing or verify it

Assessment. The API reads analytics, inbox messages, listening topics and cases across the main networks, with OAuth client credentials, field selection and a dated changelog. It creates draft posts only, so a person must publish them in Sprout. Access needs the Advanced plan at $399 per seat a month, and no OpenAPI file or SDK was found.

Facts

Transport
HTTP
Endpoint
https://api.sproutsocial.com
Auth
OAuth or key
Pricing
Paid · $399 / seat-mo
x402
No
Licence
Proprietary service under the Sprout Social Developer Terms and Terms of Service
llms.txt
not found
Last release
Endpoints
20 documented operations under https://api.sproutsocial.com/v1. Eight metadata reads, profile and post analytics, inbox messages, listening topic messages and metrics, cases, create and retrieve publishing post, and four media upload calls
Networks
Analytics for X, Facebook, Instagram, LinkedIn, YouTube, Pinterest, Threads, TikTok and Bluesky. Draft posts for Instagram Business and Creator, Facebook Pages, Threads, X, LinkedIn Pages and personal profiles, YouTube, TikTok, Pinterest and Google My Business
Writes
Draft posts and media uploads only. No reply, tag, case update, delete or direct publish call is documented
Credentials
OAuth 2.0 from identity.sproutsocial.com (client credentials for machine-to-machine, or a user-based flow with redirect URIs), or an API token created on the API page of Settings. Both go in the Authorization: Bearer header
Plan gate
The pricing page lists the Sprout API on Advanced ($399 per seat a month) and Enterprise. A user needs the API Permissions permission, and the account must accept the API terms in settings
Rate limits
60 requests a minute and 250,000 a month. 429 means too fast or the monthly allowance is used up
Paging
Profiles 1,000 results a page, posts 50, messages and cases limit up to 100 with page_cursor (next page only). 10,000 results at most by page number
Versioning
MAJOR.MINOR. The path carries the major version, and X-Sprout-API-Version and X-Sprout-Server-Version response headers carry the rest. X-Sprout-Request-ID on every response
Status
www.sproutsocialstatus.com on Atlassian Statuspage, with components for the web application and the API. Six incidents between 20 July and 25 September 2026, four of them traced to Meta, Reddit or Threads and two to Sprout's Trellis assistant
Hosting
AWS us-east-1 (primary) and us-west-2 (secondary), with Google Cloud us-central1 for disaster recovery and backup, all in the United States
Certifications
SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 per the trust centre. Vulnerability disclosure programme on Bugcrowd
Tableau
A Tableau web data connector at https://api.sproutsocial.com/tableau/ takes the same API token

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OAuth 2.0 client credentials issue short-lived JWT access tokens, and named API tokens can be invalidated in settings
  • Rate limits are published as 60 requests a minute and 250,000 a month
  • Messages and post requests take a fields list and return only guid when it is omitted, with limit up to 100 and cursor paging
  • The status page has a separate Sprout Social API component, and no incident in the 90 days to 9 October 2026 named it
  • SOC 2 Type 2, ISO 27001 and ISO 27701 are listed on the trust centre, with a vulnerability disclosure programme on Bugcrowd

Weaknesses

  • Posts can be created only as drafts (is_draft: true), so the API cannot publish or schedule a post without a person in Sprout
  • API access is listed on the Advanced plan at $399 per seat a month and on Enterprise, with no per-call price
  • No OpenAPI file, SDK or MCP server was found in the reviewed documentation
  • No idempotency key on post creation, and no Retry-After header documented for 429 responses
  • The Developer Terms of 9 May 2024 forbid monitoring the API's availability or performance for benchmarking, and combining the API with software Sprout Social has not authorised. Recorded as a fact with no deduction. It matters before any probe is run

Before you call it notes for agents

  1. Call GET /v1/metadata/client first for the customer ID, then GET /v1/<customer ID>/metadata/customer for profile and group IDs. Every other path needs them
  2. Send is_draft: true on POST /v1/<customer ID>/publishing/posts. Tell the user the draft waits in the Sprout calendar for a person to publish
  3. Name the fields you want on messages and posts requests. Without the list only guid comes back
  4. Stay under 60 requests a minute and 250,000 a month, and back off on 429 on your own because no Retry-After is documented
  5. Check the response when a draft names several profiles. A profile that cannot take the attached media is dropped with no error

Who's behind it provenance 85/100

  • Legal entity namedSprout Social, Inc.20/20
  • Domain agesproutsocial.com, registered 2009-09-22 (17 years)15/15
  • Endpoint on the vendor's domainapi.sproutsocial.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagewww.sproutsocialstatus.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2024-05-09, states 6 of 7, 3 to know

TL;DR Dated 2024-05-09. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking and cut-off without notice or for any reason.

Restricts automated accesscosts points
access, store, display, or facilitate the transfer of any content available in the Sprout Social Services obtained through the following methods: scraping, crawling, spidering or using any other technology or software to access such content outside of the APIs

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Restricts benchmarking or competitive usecosts points
monitor the availability, performance, or functionality of the APIs or the Sprout Social Services for competitive or performance analysis, including for benchmarking purposes;

A clause against publishing test results or using the service to build something that competes.

Says access can be ended without notice or for any reason
We may immediately terminate or suspend these Terms, any rights granted herein, and/or your licenses or access granted under these Terms, in our sole discretion with or without cause, and with or without notice to you.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated Last updated 2024-05-09
Last updated: May 9, 2024

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of Illinois
These Terms will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of Illinois, U.S.A., without reference to its choice of law rules and not including the provisions of the 1980 U.N.

Says where a dispute would be heard and under whose law.

States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
TO THE FULLEST EXTENT PERMITTED UNDER APPLICABLE LAW, IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD PARTY UNDER ANY TORT, CONTRACT, NEGLIGENCE, STRICT LIABILITY, OR OTHER LEGAL OR EQUITABLE THEORY FOR (a) ANY LOST PROFITS, LOST OR CORRUPTED DATA, COMPUTER FAILURE OR MALFUNCTION, INTERRUPTION OF BUSINESS, OR OTH…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Sprout Social may, in its sole discretion, suspend, limit, or terminate access to the Beta Features at any time.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Changes are posted, with no other notice named
You acknowledge and agree that we have the right, in our sole discretion, to modify these Terms from time to time by posting the revised version on our website or communicating it to you through your Sprout Social account.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
IF YOU DO NOT HAVE AUTHORITY TO ACCEPT THESE TERMS OR YOU DO NOT AGREE WITH THESE TERMS, YOU MAY NOT ACCESS OR USE THE SPROUT SOCIAL SERVICES OR APIS.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Sprout Social's total liability under the developer terms is capped at 500 US dollars.
ANY DAMAGES, IN THE AGGREGATE, IN EXCESS OF $500 U.S. DOLLARS EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGES AND WHETHER OR NOT SUCH LOSS OR DAMAGES ARE FORESEEABLE.

Noted by a second reader on 2026-10-08.

A developer that caches API data must refresh the cache at least every 24 hours.
If You cache Data, You must refresh the cache at least every 24 hours.

Noted by a second reader on 2026-10-08.

Every API request must be identified as coming from the developer's application in the way Sprout Social specifies, and in a way that is clear to the application's users.
You must also identify each request coming from Your Application as originating from Your Application in the manner specified by Sprout Social (for example, using a required Header value) and in a manner that is obvious to Your Users.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 6,048 words

Privacy policy dated 2026-09-16, states 8 of 8, 1 to know

TL;DR Dated 2026-09-16. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
For instance, we incorporate the Facebook pixel on our Services and may share your email address with Facebook as part of our use of Facebook Custom Audiences.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-09-16
Last updated: September 16, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This privacy policy (“Privacy Policy”) explains who we are, how we collect, share and use information about you and how you can exercise your privacy rights.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 12 months
Consumers who are California, Colorado, or Virginia residents have the right to request that we delete the personal information we have collected about them (subject to certain exemptions) and the right to know certain information about our data practices in the preceding 12 months.

Says when data sent to the service is deleted.

Says who else receives the data
In connection with the provision of the Services to our customers, Sprout Social may act as a "data processor" or "service provider" under applicable data protection laws.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
To opt out of us using your data for Matched Ads and other audience matching, please click the “Do Not Sell or Share My Personal Information” link.

A plain statement either way.

Says what rights people have over their data
This privacy policy (“Privacy Policy”) explains who we are, how we collect, share and use information about you and how you can exercise your privacy rights.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@sproutsocial.com
You may submit a request to opt out by clicking “Do Not Sell or Share My Personal Information”, by calling our toll-free number at (866) 878-3231, or by emailing us at privacy@sproutsocial.com.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses and the Data Privacy Framework
These include our use of European Commission-approved Standard Contractual Clauses (along with the UK Addendum, where appropriate) and, as applicable, our commitment (and commitments made by third party transferees) to honor the principles set forth in the Data Privacy Frameworks (defined below), to the extent each su…

The countries data goes to and the safeguard used.

Sprout Social states that it is a data broker under Texas law for its Influencer Marketing platform.
With respect to the operation of the Influencer Marketing platform, Sprout Social is a data broker under Texas law.

Noted by a second reader on 2026-10-08.

Sprout Social may use artificial intelligence and machine learning to generate insights about creators, such as estimated audience demographics.
We may also generate insights about creators using artificial intelligence and machine learning, such as estimated audience demographics, engagement analysis, and content categorization.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 11,464 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Sprout Social Developer Terms (last updated 9 May 2024) are the agreement the API docs link, between the developer and Sprout Social, Inc. They sit on top of the Terms of Service (effective 9 May 2025) at https://sproutsocial.com/legal/terms/.

The Terms of Service give the notice address as Sprout Social, Inc., 131 S. Dearborn Suite 700, Chicago, Illinois 60603.

The privacy policy (last updated 16 September 2026) says it applies to the websites and services, app.sproutsocial.com among them, and that Sprout Social is a data processor for customer data.

https://sproutsocial.com/.well-known/security.txt answered 404. Reports go through the Bugcrowd programme named in the Responsible Disclosure Policy.

The API answers at api.sproutsocial.com and tokens come from identity.sproutsocial.com.

RDAP for sproutsocial.com gives a registration date of 2009-09-22 and GoDaddy Corporate Domains, LLC as registrar.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 404 · 247 ms · 1 minute ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h258 msget
p95 24h316 msopen endpoint

Probed every five minutes at https://api.sproutsocial.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 2 minutes ago

Pages we watch

PageKindLast checkedLast changed
api.sproutsocial.com/docs/changelogchangelog6 hours ago · 200no change seen
sproutsocial.com/pricingpricing6 hours ago · 200no change seen
sproutsocial.com/legal/privacy-policyprivacy6 hours ago · 200no change seen
sproutsocial.com/legal/api-terms-of-serviceterms6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/sprout-social.json

Notable

  • Create Publishing Post accepts only drafts, and a post read back by publishing_post_id always shows delivery_status: PENDING, even after it was published source
  • The API leaves out paid (ad account) data, listening data from X, message-level listening data from Reddit, and review data from Yelp, Trustpilot, Tripadvisor and Glassdoor source
  • X data needs a separate Sprout API X Content End User Licence Agreement accepted in settings before the API returns it source
  • Uploaded media is kept for 24 hours unless a post uses it. Single uploads take up to 50 MiB, and larger files go in parts of 5 MiB source
  • Responses are capped at 10,000 results with page numbers, and cursor paging is documented for larger sets source
  • The Developer Terms require cached data to be refreshed at least every 24 hours and a user's data deleted within 30 days of a deletion request source
  • The changelog runs from an initial release in November 2020 to an entry of 6 October 2026 source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 14.2
Hosted lines. A public status page on Atlassian Statuspage with a separate Sprout Social API component and incident history (20). The history feed shows six incidents in the 90 days to 9 October 2026. Four were traced to Meta, Reddit or Threads, two were on Sprout's Trellis assistant (one a 22-minute outage on 6 August), and one on 20 July was platform performance trouble resolved in about two hours with no severity stated. None named the API component, so we read the record as minor incidents only (20). Rate limits are published as 60 requests a minute and 250,000 a month (15). 429 is documented with the advice to slow down, and the media upload section advises exponential back-off on 5xx, but no Retry-After header or idempotency key for post creation was found (6). No SLA was found in the Terms of Service or Developer Terms. The security page gives 99.9 per cent uptime as an internal target (0). The API is not labelled beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 8.3
No OpenAPI file or other machine-readable description was found in the docs (0). The site's llms.txt lists marketing articles and no API page, and the docs are one HTML page with no Markdown twin (2). Each endpoint group states its purpose and has a Limitations section, and the overview lists what the API does not include (14). Request keys are tabulated with example values, limits and a few enumerations such as media_type, but filters are strings in a small expression syntax such as created_time.in(...) (9). Every endpoint has an example request and response, and a status code table gives a corrective action for each code. The error body is one free-text string (11). Versioning is MAJOR.MINOR with version response headers, and the changelog is dated from November 2020 to 6 October 2026 (15).
Agent ergonomics 13%16.2 9.6
Messages and posts requests take a fields list and return only guid without it, and analytics requests name their metrics (20). Paging by page number or page_cursor, limit up to 100, filters and sort are documented, with a 10,000 result cap on numbered pages (18). The status code table tells the caller what to do for each code and every response carries X-Sprout-Request-ID, but there are no machine-readable error codes (11). No idempotency key was found. Post creation is draft-only, which limits the harm of a repeated call, and media parts are numbered so a part can be resent (5). No SDK was found, and every call needs a customer ID looked up first (5).
Security & auth 14%17.5 10.7
OAuth 2.0 client credentials issue short-lived JWT access tokens, a user-based flow is available, and API tokens are named and can be invalidated. The only scope documented is organization_id, so a credential is not limited to reading or to one endpoint group. Credentials travel in the Authorization header only (22). No read-only credential is documented. The API can write only draft posts and media, the app has approval workflows, and API access can be limited to IP ranges per the product security page (12). The messages and listening endpoints return text written by the public, and no guidance on untrusted content was found (2). The app has a customer-facing audit trail of over fifty events. Whether API calls appear in it was not established (8). Responsible Disclosure Policy with a Bugcrowd vulnerability disclosure programme, SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 on the trust centre. No security.txt and no paid bounty stated (17).
Payments & pricing 10%12.5 2.5
No x402 or other machine payment protocol (0). Plan prices are public and the API is listed on Advanced at $399 per seat a month, with no per-call price (10). A 30-day trial needs no credit card, but whether it includes API access was not established, so half marks (10). A person has to sign up, hold the API Permissions permission and accept the API terms in settings (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 3.3
The newest changelog entry is dated 6 October 2026 (30). It is the only dated entry in the 90 days to 9 October 2026. The two before it are 15 June and 10 June (0). A public changelog, a help centre and a community site are linked. The Developer Terms say they entitle the developer to no support for the API (8). No official SDK was found (0). No package to assess (0).
Transparency & trusteditorial 55, provenance 85 7%8.8 6.1
Closed service with published Developer Terms (9 May 2024) and Terms of Service (9 May 2025) from Sprout Social, Inc. (15). The privacy policy of 16 September 2026 covers the services and states the processor role, the Terms of Service allow account content to be removed within 30 days of termination, and the docs say uploaded media is kept for 24 hours. The policy gives no retention periods, and the DPA is a PDF we did not read (20). The changelog carries dated notices of removed metrics, most of them forced by Meta. The Developer Terms promise only reasonable efforts, when possible, to give notice that a version will stop being supported (8). Hosting is disclosed to the cloud region, all in the United States. The privacy policy lists service providers by category, and a named sub-processor list was not found on the pages read (12).
Negative events≤15None recorded0
Total54.7 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 18 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Sprout Social API, or have the agent fetch /fixes/sprout-social.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Sprout Social API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/sprout-social, the October 2026 research run, assessed 9 October 2026. Grade C, 54.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Sprout Social API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 20 out of 100, up to 10 more on the total

Why it scored 20: No x402 or other machine payment protocol (0). Plan prices are public and the API is listed on Advanced at $399 per seat a month, with no per-call price (10). A 30-day trial needs no credit card, but whether it includes API access was not established, so half marks (10). A person has to sign up, hold the API Permissions permission and accept the API terms in settings (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Schema & documentation, 51 out of 100, up to 8 more on the total

Why it scored 51: No OpenAPI file or other machine-readable description was found in the docs (0). The site's llms.txt lists marketing articles and no API page, and the docs are one HTML page with no Markdown twin (2). Each endpoint group states its purpose and has a Limitations section, and the overview lists what the API does not include (14). Request keys are tabulated with example values, limits and a few enumerations such as `media_type`, but filters are strings in a small expression syntax such as `created_time.in(...)` (9). Every endpoint has an example request and response, and a status code table gives a corrective action for each code. The error body is one free-text string (11). Versioning is MAJOR.MINOR with version response headers, and the changelog is dated from November 2020 to 6 October 2026 (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 3. Security & auth, 61 out of 100, up to 6.8 more on the total

Why it scored 61: OAuth 2.0 client credentials issue short-lived JWT access tokens, a user-based flow is available, and API tokens are named and can be invalidated. The only scope documented is `organization_id`, so a credential is not limited to reading or to one endpoint group. Credentials travel in the Authorization header only (22). No read-only credential is documented. The API can write only draft posts and media, the app has approval workflows, and API access can be limited to IP ranges per the product security page (12). The messages and listening endpoints return text written by the public, and no guidance on untrusted content was found (2). The app has a customer-facing audit trail of over fifty events. Whether API calls appear in it was not established (8). Responsible Disclosure Policy with a Bugcrowd vulnerability disclosure programme, SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 on the trust centre. No security.txt and no paid bounty stated (17).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Agent ergonomics, 59 out of 100, up to 6.7 more on the total

Why it scored 59: Messages and posts requests take a `fields` list and return only `guid` without it, and analytics requests name their metrics (20). Paging by page number or `page_cursor`, `limit` up to 100, filters and sort are documented, with a 10,000 result cap on numbered pages (18). The status code table tells the caller what to do for each code and every response carries `X-Sprout-Request-ID`, but there are no machine-readable error codes (11). No idempotency key was found. Post creation is draft-only, which limits the harm of a repeated call, and media parts are numbered so a part can be resent (5). No SDK was found, and every call needs a customer ID looked up first (5).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Reliability, 71 out of 100, up to 5.8 more on the total

Why it scored 71: Hosted lines. A public status page on Atlassian Statuspage with a separate Sprout Social API component and incident history (20). The history feed shows six incidents in the 90 days to 9 October 2026. Four were traced to Meta, Reddit or Threads, two were on Sprout's Trellis assistant (one a 22-minute outage on 6 August), and one on 20 July was platform performance trouble resolved in about two hours with no severity stated. None named the API component, so we read the record as minor incidents only (20). Rate limits are published as 60 requests a minute and 250,000 a month (15). 429 is documented with the advice to slow down, and the media upload section advises exponential back-off on 5xx, but no `Retry-After` header or idempotency key for post creation was found (6). No SLA was found in the Terms of Service or Developer Terms. The security page gives 99.9 per cent uptime as an internal target (0). The API is not labelled beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Maintenance & community, 38 out of 100, up to 5.4 more on the total

Why it scored 38: The newest changelog entry is dated 6 October 2026 (30). It is the only dated entry in the 90 days to 9 October 2026. The two before it are 15 June and 10 June (0). A public changelog, a help centre and a community site are linked. The Developer Terms say they entitle the developer to no support for the API (8). No official SDK was found (0). No package to assess (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 70 out of 100, up to 2.6 more on the total

Made of editorial 55, provenance 85.

Why it scored 70: Closed service with published Developer Terms (9 May 2024) and Terms of Service (9 May 2025) from Sprout Social, Inc. (15). The privacy policy of 16 September 2026 covers the services and states the processor role, the Terms of Service allow account content to be removed within 30 days of termination, and the docs say uploaded media is kept for 24 hours. The policy gives no retention periods, and the DPA is a PDF we did not read (20). The changelog carries dated notices of removed metrics, most of them forced by Meta. The Developer Terms promise only reasonable efforts, when possible, to give notice that a version will stop being supported (8). Hosting is disclosed to the cloud region, all in the United States. The privacy policy lists service providers by category, and a named sub-processor list was not found on the pages read (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- security.txt: not found (0 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: whether the 30-day trial includes API access. The pricing page lists the API on Advanced and the docs send readers to sales or support, so Payments takes half marks for the trial
- unchecked: the Data Processing Addendum (a PDF on media.sproutsocial.com) and the Customer Trust Portal at trust.sproutsocial.com, so a named sub-processor list and retention periods may exist that we did not read
- unchecked: the Bugcrowd programme page, so whether rewards are paid is not established
- unchecked: the help centre at support.sproutsocial.com, which the docs link for plan requirements, media limits and audit trail details
- unchecked: whether API calls are recorded in the audit trail
- The status feed gives no severity for the 20 July 2026 performance incident (09:46 to 11:39 CDT). Read as a major outage it would lower Reliability by 10
- The lead was right about the interface. One correction, the API creates draft posts only and cannot publish, so `social.post` and `social.schedule` are left out of the capabilities
- The Developer Terms forbid monitoring the API's availability, performance or functionality for benchmarking (section 3s), combining the API with software not authorised by Sprout Social (3l) and testing the vulnerability of its systems (3o). No deduction taken. The owner should read these before any probe is run
- The docs name no MCP server, SDK or OpenAPI file. We did not search beyond the pages the docs and the main site link

## Weaknesses

- Posts can be created only as drafts (`is_draft: true`), so the API cannot publish or schedule a post without a person in Sprout
- API access is listed on the Advanced plan at $399 per seat a month and on Enterprise, with no per-call price
- No OpenAPI file, SDK or MCP server was found in the reviewed documentation
- No idempotency key on post creation, and no `Retry-After` header documented for 429 responses
- The Developer Terms of 9 May 2024 forbid monitoring the API's availability or performance for benchmarking, and combining the API with software Sprout Social has not authorised. Recorded as a fact with no deduction. It matters before any probe is run

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Call `GET /v1/metadata/client` first for the customer ID, then `GET /v1/<customer ID>/metadata/customer` for profile and group IDs. Every other path needs them
- Send `is_draft: true` on `POST /v1/<customer ID>/publishing/posts`. Tell the user the draft waits in the Sprout calendar for a person to publish
- Name the `fields` you want on messages and posts requests. Without the list only `guid` comes back
- Stay under 60 requests a minute and 250,000 a month, and back off on 429 on your own because no `Retry-After` is documented
- Check the response when a draft names several profiles. A profile that cannot take the attached media is dropped with no error

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: whether the 30-day trial includes API access. The pricing page lists the API on Advanced and the docs send readers to sales or support, so Payments takes half marks for the trial
  • unchecked: the Data Processing Addendum (a PDF on media.sproutsocial.com) and the Customer Trust Portal at trust.sproutsocial.com, so a named sub-processor list and retention periods may exist that we did not read
  • unchecked: the Bugcrowd programme page, so whether rewards are paid is not established
  • unchecked: the help centre at support.sproutsocial.com, which the docs link for plan requirements, media limits and audit trail details
  • unchecked: whether API calls are recorded in the audit trail
  • The status feed gives no severity for the 20 July 2026 performance incident (09:46 to 11:39 CDT). Read as a major outage it would lower Reliability by 10
  • The lead was right about the interface. One correction, the API creates draft posts only and cannot publish, so social.post and social.schedule are left out of the capabilities
  • The Developer Terms forbid monitoring the API's availability, performance or functionality for benchmarking (section 3s), combining the API with software not authorised by Sprout Social (3l) and testing the vulnerability of its systems (3o). No deduction taken. The owner should read these before any probe is run
  • The docs name no MCP server, SDK or OpenAPI file. We did not search beyond the pages the docs and the main site link

Sources 18

  1. API documentation (one page) api.sproutsocial.com · seen 2026-10-09
  2. API changelog api.sproutsocial.com · seen 2026-10-09
  3. pricing sproutsocial.com · seen 2026-10-09
  4. Sprout Social Developer Terms, last updated 9 May 2024 sproutsocial.com · seen 2026-10-09
  5. Terms of Service, effective 9 May 2025 sproutsocial.com · seen 2026-10-09
  6. privacy policy, last updated 16 September 2026 sproutsocial.com · seen 2026-10-09
  7. security centre sproutsocial.com · seen 2026-10-09
  8. product security page for the Sprout application sproutsocial.com · seen 2026-10-09
  9. trust centre (certifications) sproutsocial.com · seen 2026-10-09
  10. Responsible Disclosure Policy sproutsocial.com · seen 2026-10-09
  11. status page sproutsocialstatus.com · seen 2026-10-09
  12. status history feed linked from the status page (25 incidents, 5 December 2025 to 25 September 2026) sproutsocialstatus.com · seen 2026-10-09
  13. llms.txt (marketing articles only) sproutsocial.com · seen 2026-10-09
  14. security.txt (answered 404) sproutsocial.com · seen 2026-10-09
  15. robots.txt for sproutsocial.com (200, no disallow rules) sproutsocial.com · seen 2026-10-09
  16. robots.txt for api.sproutsocial.com (answered 404, so no rules published) api.sproutsocial.com · seen 2026-10-09
  17. robots.txt for the status host (200, disallows /api/ and /embed/, neither read) sproutsocialstatus.com · seen 2026-10-09
  18. RDAP record for sproutsocial.com (the registry's robots.txt answered 400) rdap.verisign.com · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid $399 / seat-mo The Sprout API is listed on the Advanced plan at $399 per seat a month and on Enterprise (custom price). Standard is $199 and Professional $299 per seat a month, without the API. The page shows these prices beside an annual billing note. A 30-day trial needs no credit card. Whether the trial includes API access was not established, and there is no sandbox or per-call price (https://sproutsocial.com/pricing/, checked 2026-10-09).

Prices

ItemPriceUnitNote
Advanced$399per seat per monthCheapest plan that lists the Sprout API. Price shown beside an annual billing note
Professional$299per seat per monthNo API access listed
Standard$199per seat per monthNo API access listed

Compared across listings on the price index.

Recent changes

  • Sprout Social API status page: minor → none source
  • Sprout Social API status page: none → minor source
  • Latest release

Follow them as a feed at /feeds/tools/sprout-social.xml, or this listing's score history at history.json.

Connect

First request

curl https://api.sproutsocial.com/v1/metadata/client -H "Authorization: Bearer $TOKEN" -H "Accept: application/json"

Through letme picks today, calling later

GET https://letme.dev/sprout-social

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Zernio (formerly Late) API + MCP ZernioB67.5social.analytics social.comments social.media-uploadno
bundle.social BUNDLE SP. Z O.O.C60.1social.analytics social.comments social.media-uploadno
Upload-Post API + MCP Upload-PostC58.7social.analytics social.comments social.media-uploadno
Ayrshare API + MCP AyrshareC57.2social.analytics social.comments social.media-uploadno
Blotato Blotato Inc.D46.1social.analytics social.comments social.media-uploadno
OneUp API + MCP OneUpF24.4social.analytics social.comments social.media-uploadno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Sprout Social API on Anchor Terminal, C, 54.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/sprout-social"><img src="https://www.anchorterminal.com/badges/sprout-social.svg" alt="Sprout Social API on Anchor Terminal" height="20"></a>
    [![Sprout Social API on Anchor Terminal](https://www.anchorterminal.com/badges/sprout-social.svg)](https://www.anchorterminal.com/tools/sprout-social)

    It counts on a page on sproutsocial.com or one of its subdomains.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "sprout-social", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.