# Upstash QStash > Upstash QStash is a hosted HTTP message queue and scheduler. A caller publishes a request to its REST API, and QStash sends it to a public URL with retries, delays, cron schedules, FIFO queues and signed requests. - Canonical: https://www.anchorterminal.com/tools/upstash-qstash - Markdown: https://www.anchorterminal.com/tools/upstash-qstash.md (~6,800 tokens) - Slim: https://www.anchorterminal.com/tools/upstash-qstash.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/upstash-qstash.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 72.3/100 · rank #90 of 629 · #4 in Event delivery & webhooks · agent-ready · confidence medium** More from Upstash, listed separately because each is its own product: [Upstash Vector API + MCP](https://www.anchorterminal.com/tools/upstash-vector.md) (Retrieval & vector search). ## Assessment A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed. ## Facts | Field | Value | | --- | --- | | Vendor | Upstash (https://upstash.com/qstash) | | Kind | HTTP API | | Category | Event delivery & webhooks (https://www.anchorterminal.com/categories/webhooks) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://qstash.upstash.io/v2` | | Auth | OAuth or key · Self-serve. A person signs up at console.upstash.com and copies `QSTASH_TOKEN` for a region, sent as a Bearer token or, as a documented option, in a `qstash_token` query parameter. Each region has one full-access token and one read-only token, and resetting the token revokes the old one. The hosted MCP server uses OAuth with a per-client, revocable grant that can be read-only, or account email plus a Developer API key, which can be read-only and can expire. | | Pricing | Freemium ($0.05 / GB) · Free plan with 1,000 messages a day and no card. Pay as you go is $1 per 100,000 messages with 50 GB of bandwidth a month free, then $0.05 per GB. Fixed plans are $180 a month for 1M messages a day and $420 for 10M. Enterprise by quote. The pricing FAQ bills each delivery attempt, retries included, while the Markdown version of the page also says retries are free. The price of the Prod Pack add-on wasn't found (https://upstash.com/pricing/qstash). | | x402 | No · No x402, MPP or L402 in the QStash docs, the OpenAPI file or the pricing page (checked 2026-10-08). | | Licence | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT | | Tools exposed | 10 | | Packages | npm: `@upstash/qstash`; pypi: `qstash`; npm: `@upstash/mcp-server` | | MCP registry name | `io.github.upstash/mcp-server` | | Source | https://github.com/upstash/qstash-js | | Docs | https://upstash.com/docs/qstash/overall/getstarted | | llms.txt | https://upstash.com/docs/llms.txt | | Last release | 2026-09-29 | | GitHub stars | 269 (as of 2026-10-08) | | npm downloads / week | 816,190 | | PyPI downloads / week | 90,589 | | Surface graded | The QStash REST API at qstash.upstash.io/v2 (EU) and qstash-us-east-1.upstash.io/v2 (US), 43 operations. The hosted Upstash MCP server is a second route | | Free tier | 1,000 messages a day, 1 MB messages, 7-day maximum delay, 10 schedules, 10 queues, 3-day logs and dead letter queue, no card per the pricing page | | Delivery | At least once. 3 retries by default with delay min(86400, e^(2.5n)) seconds, a custom `Upstash-Retry-Delay` expression, and the destination's `Retry-After` honoured up to one day | | Ordering | FIFO within a named queue, where the next message waits for the current one to finish or fail. Plain publishes are unordered | | Deduplication | `Upstash-Deduplication-Id` or content-based, 10-minute window, 202 with the first message ID for a duplicate | | Schedules | Cron expressions in UTC or a named timezone on POST /v2/schedules, with pause and resume. 10 active on Free, 1,000 on pay as you go, then $0.01 each | | Signatures | HS256 JWT in `Upstash-Signature` with a SHA-256 body hash and a 5-minute lifetime. Current and next signing keys, rotated at POST /v2/keys/rotate | | Failed messages | Dead letter queue with single and bulk retry and delete, kept 3 days on Free, 7 on pay as you go, 30 days or 3 months on fixed plans. Failure callbacks to a URL | | Rate limits | None per second on publish, enqueue and batch. Management endpoints such as logs have a one-second burst limit reported in `Burst-RateLimit-*` headers, with no number published. Daily message caps by plan | | Logs | GET /v2/logs with a cursor, up to 100 entries a call and filters for state, URL, queue, schedule, label and date. Kept 3 to 14 days by plan | | MCP server | Hosted at mcp.upstash.com/mcp with OAuth or email plus API key. 10 QStash and Workflow tools with `?features=qstash_workflow`, 55 without. A read-only grant refuses every write. The stdio package `@upstash/mcp-server` also covers QStash | | Regions | EU (eu-central-1) and US (us-east-1), independent, with a console migration tool for schedules, URL groups and queues | | SLA | 99.99% monthly uptime with service credits, only with the Prod Pack add-on or an Enterprise plan | | SDKs | TypeScript `@upstash/qstash` 2.12.0 (29 September 2026) and Python `qstash` 3.4.0 (18 March 2026), both MIT | | Self-hosted | Not available. The service is closed source, and the local development server is for testing only | | Capabilities | events.queue, events.schedule, events.webhooks-send, events.webhooks-receive | | Tags | hosted, freemium, no-card, free-tier, openapi, mcp, llms-txt, closed-source, typescript, python, status-page | | JSON | https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 83 | 16.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 78 | 12.7 | | Agent ergonomics | 13% | 16.2 | 83 | 13.5 | | Security & auth | 14% | 17.5 | 61 | 10.7 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 77 | 6.7 | | Transparency & trust (editorial 62, provenance 100) | 7% | 8.8 | 81 | 7.1 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **72.3 → BB** | ### Why each score - Reliability 83: Graded on the hosted REST API. status.upstash.com is a Statuspage with a QStash component split into EU-CENTRAL-1 and US-EAST-1 and a full incident history (20). Two QStash incidents since 10 July 2026, both in us-east-1 and both short. Publish errors on 16 July were fixed within minutes, and a message persistence fault on 28 August ran from 22:20 to 22:33 UTC and was marked major (20 of 30). Publish, enqueue and batch have no per-second limit, daily message caps and parallelism are published per plan, but the burst limit on management endpoints has no published number (10 of 15). 429 responses carry `Burst-RateLimit-Reset`, the SDK raises typed rate-limit errors with a reset time, and deduplication IDs make a repeated publish safe (13 of 15). 99.99% SLA with the Prod Pack add-on or Enterprise (10). Generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 78: Public OpenAPI 3.1 file with 43 operations (25). llms.txt and a Markdown copy of every docs page (10). Each header parameter says what it does with formats and examples, and the docs point from queue parallelism to flow control, but few entries say when not to use an endpoint (14 of 20). Enums on method and message state, typed query parameters on logs, but most options are string headers, among them the flow-control value and retry-delay expression (10 of 15). curl, TypeScript and Python examples on each page and status codes per operation, with one error schema holding a single string and no error list (10 of 15). The path is versioned at /v2, but the docs changelog stops at February 2026 and the GitHub Discussions list that replaced it shows nothing released after March 2026 (9 of 15). - Agent ergonomics 83: Graded as an API. Publish returns only a message ID, logs take `count` up to 100, and there's no field selection. Through MCP, `?features=qstash_workflow` cuts 55 tools to 10 (17 of 25). Cursor pagination and filters for state, URL, queue, schedule, label and date on logs and the dead letter queue (20). Errors are an HTTP status plus one message string, such as `unable to authenticate: token is empty`, with typed SDK errors for rate limits and no code list (12 of 20). Deduplication IDs with a 10-minute window, 202 for a duplicate, `Upstash-Message-Id` for idempotent receivers, and read, write or destructive labels on MCP tools (20). One curl with a token publishes a message, with 3 retries by default. Official SDKs for TypeScript and Python, the Python one last released in March 2026 (14 of 15). - Security & auth 61: One full-access token and one read-only token per region, revoked by a reset, with two signing keys that rotate by API. No scopes per queue, destination or schedule (24 of 30). The token is accepted in a `qstash_token` query parameter as a documented option (less 10). Read-only token, read-only Developer API keys and MCP grants, and destructive labels on MCP tools, though the read-only token still reads message bodies (18 of 20). Logs and the dead letter queue return message bodies and endpoint responses. Field redaction is documented, and no prompt-injection guidance was found (5 of 15). Per-message logs by API, kept 3 to 14 days, and Prometheus and Datadog export on Prod Pack. No account audit log was found (10 of 15). Valid security.txt, a disclosure policy with safe harbour and rewards for critical findings, and SOC 2 Type 2 for QStash only with Prod Pack. ISO 27001 is in progress (14 of 20). - Payments & pricing 40: No x402, MPP or L402 (0). $1 per 100,000 messages and $0.05 per GB over 50 GB, published without login (20). Free plan with 1,000 messages a day and no card required per the pricing page (20). A person signs up in the browser and copies the token from the console. No keyless or programmatic route to a first QStash token was found (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 77: `@upstash/qstash` 2.12.0 reached npm on 29 September 2026 (30). Three releases in 90 days, 2.11.2 on 14 July, 2.11.3 on 22 July and 2.12.0 (20). Public changelog, Discord and email support, with the docs changelog last updated for February 2026 and GitHub issue replies not read (8 of 15). The TypeScript SDK is current, the Python SDK's last release is 3.4.0 on 18 March 2026, and the MCP server is in the official registry as io.github.upstash/mcp-server (11 of 15). CI and test workflows on both SDK repositories, and the TypeScript SDK replaced crypto-js with Web Crypto in September 2026 (8 of 10). - Transparency & trust 81: Closed service with published terms. The SDKs and MCP server are MIT, and the local development server has its own testing-only licence (18 of 30). DPA, privacy policy, subprocessor list and security measures are public, and log and dead letter retention is published per plan. The security measures PDF says SOC 2 Type II is in progress while the QStash page says it's held with Prod Pack, and the Markdown pricing page gives two answers on retry billing (22 of 30). No deprecation policy found. Queue parallelism is to be deprecated 'at some point' with no date (5 of 20). Subprocessors are listed with addresses, the two regions are named, and the stdio MCP server's telemetry is documented with `--disable-telemetry` (17 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (15 items): https://www.anchorterminal.com/fixes/upstash-qstash.md (JSON https://www.anchorterminal.com/fixes/upstash-qstash.json) ### What we couldn't check - Whether retries are billed. The pricing FAQ says each delivery attempt is a message, and the Markdown version of the same page also says retries are free - unchecked: the price of the Prod Pack add-on, which wasn't on the pricing page we read - unchecked: the numeric burst limit on management endpoints such as logs and the dead letter queue - unchecked: the hosted MCP server's QStash tool schemas, which aren't published. The stdio package's source is public and has a different tool list - unchecked: issue response times on the SDK repositories, because the GitHub API refused our requests and issues aren't in a clone - Whether the February 2026 change to the GET /v2/globalParallelism response was announced beforehand - Whether SOC 2 Type 2 is complete for QStash. The QStash page says yes with Prod Pack, the security measures PDF says in progress, and the compliance page names only Redis - The first release date is the npm package's creation date, 14 June 2022, not a vendor statement about the service ### Sources - getting started: (seen 2026-10-08) - pricing and limits: (seen 2026-10-08) - pricing, Markdown version: (seen 2026-10-08) - OpenAPI 3.1 file: (seen 2026-10-08) - docs index: (seen 2026-10-08) - authentication: (seen 2026-10-08) - read-only token: (seen 2026-10-08) - rate limit responses: (seen 2026-10-08) - retry behaviour: (seen 2026-10-08) - deduplication: (seen 2026-10-08) - at-least-once delivery: (seen 2026-10-08) - request signing: (seen 2026-10-08) - regions: (seen 2026-10-08) - webhook receiver guide: (seen 2026-10-08) - Prod Pack and Enterprise: (seen 2026-10-08) - uptime SLA: (seen 2026-10-08) - QStash changelog: (seen 2026-10-08) - released items in GitHub Discussions: (seen 2026-10-08) - MCP server docs: (seen 2026-10-08) - compliance page: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - vulnerability disclosure policy: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - subprocessor list: (seen 2026-10-08) - security measures: (seen 2026-10-08) - TypeScript SDK repository and tags: (seen 2026-10-08) - Python SDK repository and tags: (seen 2026-10-08) - MCP server repository: (seen 2026-10-08) - npm registry entry: (seen 2026-10-08) - PyPI entry: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - development server licence: (seen 2026-10-08) ## Who's behind it (provenance 100/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Upstash, Inc. | 20/20 | | Domain age | upstash.com, registered 2015-06-23 (11 years) | 15/15 | | Endpoint on the vendor's domain | qstash.upstash.io | 15/15 | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | status.upstash.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms of service (last updated April 2025) name Upstash, Inc., a Delaware corporation, and list upstash.io subdomains as Upstash-owned. The QStash API answers at qstash.upstash.io and qstash-us-east-1.upstash.io. upstash.com/.well-known/security.txt names security@upstash.com, expires on 29 September 2027 and links a vulnerability disclosure policy last updated in September 2026. RDAP for upstash.com gives a registration date of 2015-06-23. The docs changelog says changes moved to GitHub Discussions from October 2025. Its own last entry is February 2026. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://upstash.com/trust/terms.pdf), not read yet. **Privacy policy** (https://upstash.com/trust/privacy.pdf), not read yet. ## Live (updated 2026-10-08 18:22 UTC) - Right now: up, HTTP 401, 66 ms, checked 2026-10-08 18:20 UTC (get on `https://qstash.upstash.io/v2`, asks for auth) - Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 67 ms · p95 116 ms - Vendor status page: none, All Systems Operational - github `upstash/qstash-js` v2.12.0, released 2026-09-29 - npm `@upstash/mcp-server` 0.3.0 - npm `@upstash/qstash` 2.12.0 - pypi `qstash` 3.4.0, released 2026-03-18 - security.txt: valid, expires 2027-09-29T00:00:00.000Z - Always current: https://www.anchorterminal.com/api/v1/live/upstash-qstash.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Pay as you go message | $0. | per message | $1 per 100,000 messages. The pricing FAQ counts each delivery attempt as a message | | Bandwidth over 50 GB a month | $0.05 | per GB of traffic | pay as you go | | Fixed 1M plan | $180 | per month (plan) | 1M messages a day, 1 TB bandwidth, 50 MB messages | | Fixed 10M plan | $420 | per month (plan) | 10M messages a day, 5 TB bandwidth, 50 MB messages | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.1 file with 43 operations for messages, queues, schedules, URL groups, the dead letter queue, logs and signing keys - Retries default to 3 with exponential backoff capped at one day, and a destination's `Retry-After` header is honoured - `Upstash-Deduplication-Id` makes a repeated publish safe for 10 minutes, with 202 returned for a duplicate - Every request to the destination carries an HS256 JWT in `Upstash-Signature`, with two signing keys so rotation needs no downtime - Free plan of 1,000 messages a day with no card, then $1 per 100,000 messages ## Weaknesses - One full-access token and one read-only token per region. No per-queue or per-destination scopes were found - The token is accepted as a `qstash_token` query parameter, which the webhook receiver guide relies on - The Markdown pricing page says retries are free and, in its FAQ, that each retry is billed as a message - Two QStash incidents in us-east-1 in 90 days, on 16 July and 28 August 2026, both under 15 minutes - The docs changelog stops at February 2026, and the Python SDK last shipped on 18 March 2026 ## Before you call it (notes for agents) 1. Use the regional host that matches the token. `qstash.upstash.io` is the EU region, and US tokens work only on `qstash-us-east-1.upstash.io` 2. Send `Upstash-Deduplication-Id` on every publish so a retried request isn't queued twice. The window is 10 minutes 3. Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set `Upstash-Retries` deliberately 4. Give monitoring agents the read-only token, and set `Upstash-Redact-Fields` on publish, because that token still reads message bodies and headers 5. Make the destination idempotent on `Upstash-Message-Id`. Delivery is at least once, and duplicates can follow a server restart ## Connect Install: ```bash npm install @upstash/qstash ``` First request: ```bash curl -XPOST \ -H 'Authorization: Bearer ' \ -H "Content-type: application/json" \ -d '{ "hello": "world" }' \ 'https://qstash.upstash.io/v2/publish/https://' ``` Claude Code: ```bash claude mcp add --scope user --transport http upstash https://mcp.upstash.com/mcp ``` MCP client configuration: ```json { "mcpServers": { "upstash": { "url": "https://mcp.upstash.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/upstash-qstash (letme picks it for events.schedule, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Hookdeck | BB | 76.9 | 23 | events.webhooks-receive, events.queue, events.webhooks-send | no | https://www.anchorterminal.com/tools/hookdeck.md | | Ably | BB | 75 | 53 | events.webhooks-send, events.webhooks-receive, events.queue | no | https://www.anchorterminal.com/tools/ably.md | | Svix | BB | 74 | 66 | events.webhooks-send, events.webhooks-receive | no | https://www.anchorterminal.com/tools/svix.md | | Convoy | B | 62.2 | 308 | events.webhooks-send, events.webhooks-receive | no | https://www.anchorterminal.com/tools/convoy.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The REST API has a public OpenAPI 3.1 file with 43 operations and two servers, eu-central-1 and us-east-1 (source: ) - Publish, enqueue and batch have no per-second limit. Excess traffic is queued and sent within the plan's parallelism, from 10 on Free to 1,000 on Fixed 10M (source: ) - Each region has its own token, signing keys, resources and bill, and the unqualified host qstash.upstash.io is the EU region (source: ) - The read-only token can list logs, messages and schedules and can't publish or change anything, but it still reads message bodies unless fields are redacted (source: ) - The hosted MCP server at mcp.upstash.com/mcp has 10 QStash and Workflow tools out of 55, selected with `?features=qstash_workflow` and each labelled read, write or destructive (source: ) - The Markdown pricing page says retries are free near the top and says in its FAQ that each retry is billed as one more message (source: ) - A local development server runs in memory for tests under its own licence, which forbids production use (source: ) ## Compare - [Convoy vs Upstash QStash](https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.md): B 62.2 vs BB 72.3 - [Svix vs Upstash QStash](https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.md): BB 74 vs BB 72.3 - [Hookdeck vs Upstash QStash](https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.md): BB 76.9 vs BB 72.3 - [Ably vs Upstash QStash](https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.md): BB 75 vs BB 72.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on upstash.com or one of its subdomains, or the README of github.com/upstash/qstash-js. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "upstash-qstash", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Upstash QStash on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Upstash QStash on Anchor Terminal](https://www.anchorterminal.com/badges/upstash-qstash.svg)](https://www.anchorterminal.com/tools/upstash-qstash) ``` Plain link: ```html Upstash QStash on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Upstash QStash is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/upstash-qstash-dark.png - Light: https://www.anchorterminal.com/assets/share/upstash-qstash-light.png