Vercel Connect

by Vercel Inc. HTTP API in Agent auth & delegated access

Hosted

Vercel Inc. · vercel.com since 1999 · status page · who's behind it

Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user.

Good for Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.

Is this your product? Claim this listing or verify it

More from Vercel Inc. Vercel Sandbox (Sandboxes)

Assessment. Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.

Facts

Transport
HTTP
Endpoint
https://api.vercel.com
Auth
OAuth or key
Pricing
Freemium · $3 / 1k req
x402
No
Licence
Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0
Packages
npm @vercel/connect
llms.txt
published
Last release
GitHub stars
16k
npm / week
738k
Surface graded
The hosted Connect API at https://api.vercel.com (/v1/connect/token/{connector}, /v1/connect/authorize/{connector} and the connector management paths), reached through the @vercel/connect TypeScript SDK, the vercel connect CLI or plain HTTP
Token subjects
app (the service or bot), user (a named user, after consent), jwt-bearer (a federated subject from the customer's own identity provider) and token (exchange of an existing subject token)
Scoping
scopes, resources, authorizationDetails and audience are forwarded to the provider per request. installationId picks the tenant, and '*' asks for a cross-installation token where the connector supports it
Connectors
Managed by Vercel: Slack, GitHub, Linear, Microsoft, Microsoft Teams, Snowflake, Salesforce (beta) and Linq (beta). Customer managed: custom OAuth with the authorisation code flow with PKCE or client credentials, static API keys, and MCP servers discovered from their OAuth metadata
Rate limits
200 reads a minute per team (getToken, getTokenResponse, getConnectorMetadata, list), 50 writes a minute per team (revokeToken, create, attach, detach, update, remove), 6,000 a minute on the OAuth gateway and trigger endpoints. A 429 means waiting one minute
Errors
Typed SDK classes: UserAuthorizationRequiredError, ConnectorInstallationRequiredError, NoValidTokenError, ConnectorNotFoundError, ClientNotLinkedToProjectError, ClientNotEnabledForEnvironmentError
Audit
Observability tab per connector with five event types and correlation IDs. Retention 12 hours on Hobby, 3 days on Pro, 30 days on Enterprise. Drains on Pro and Enterprise. Connector changes appear in the team Activity Log
Triggers
Connect verifies provider webhook signatures, re-attests each event with an OIDC identity and forwards it to up to 3 project destinations per connector
Access control
Project links per environment, including Custom Environments. On Pro and Enterprise an owner can restrict connector management to Owners and the Connector Manager permission
SDK
@vercel/connect 2.4.1 (6 October 2026), Apache-2.0, one runtime dependency (@vercel/oidc), with adapters for AI SDK, MCP clients, eve, Chat SDK, Better Auth and Auth.js
Certifications
Vercel states SOC 2 Type 2 (Security, Confidentiality, Availability) and ISO 27001:2022. security.txt points to HackerOne and expires 28 September 2027
Status
Connect has been a component on www.vercel-status.com since 18 September 2026

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user
  • A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables
  • Public OpenAPI 3.0.3 document covers 13 Connect paths, including /v1/connect/token/{connector} and /v1/connect/authorize/{connector}
  • Token requests, completed authorisations and revocations are logged with tokenId and authorizationId, and can be sent to a drain on Pro and Enterprise
  • Rate limits are published with numbers, 200 reads and 50 writes a minute per team

Weaknesses

  • Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment
  • Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page
  • Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise
  • Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires
  • The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1

Before you call it notes for agents

  1. Call getToken at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry
  2. Pass scopes on every request. Since SDK 1.0.0 an omitted scopes defaults to ['*'], the connector's default scopes
  3. Catch UserAuthorizationRequiredError, call startAuthorization and send the user to the returned URL. Consent needs a person in a browser
  4. Outside Vercel, pass a Vercel access token as vercelToken. It can request only the app subject or its own user, not another user
  5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team

Who's behind it provenance 99/100

  • Legal entity namedVercel Inc.20/20
  • Domain agevercel.com, registered 1999-10-04 (27 years)15/15
  • Endpoint on the vendor's domainapi.vercel.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects10/10
  • Privacy policyread, states 7 of the 8 things a reader expects9.3/10
  • Status pagewww.vercel-status.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service dated 2026-06-01, states 7 of 7, 3 to know

TL;DR Dated 2026-06-01. States all 7 things a reader expects. To know before relying on it, model training with an opt-out, cut-off without notice or for any reason and arbitration or a class action waiver.

Says it may use customer content to train or improve models, and gives an opt-out
In addition, if you are on a Hobby plan or trial Pro plan, you agree that we may use Your Content to train our artificial intelligence ("AI") and machine learning models, and we may share Your Content with third parties for the purpose of developing and improving their products, including training and improving their…

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Says access can be ended without notice or for any reason
We may shut down and terminate projects or deployments using the Hobby plan without notice for any reason or no reason.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
You and Vercel agree that any Claim will be settled by final and binding arbitration, using the English language, administered by JAMS under its Streamlined Arbitration Rules and Procedures (the "JAMS Rules").

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-06-01
Last Updated June 1, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of California
This Agreement shall be governed by the laws of the State of California without regard to its conflict of laws provisions.

Says where a dispute would be heard and under whose law.

States a limit on its liability
IN THESE STATES, VERCEL'S LIABILITY WILL BE LIMITED TO THE GREATEST EXTENT PERMITTED BY LAW.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Subject to earlier termination as provided below, Vercel may terminate your account and this Agreement at any time by providing thirty (30) days prior notice to the administrative email address associated with your account.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
Vercel may change this Agreement from time to time by providing notice either by emailing the email address associated with your account or by posting a notice at https://vercel.com.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
If you do not have such authority, or if you do not agree with this Agreement, you must not accept this Agreement and may not use the Services.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Vercel's warranties, indemnities and SLA terms do not apply to Previews and Support Services are not provided for Previews.

Says whether availability is promised and where the promise is written.

A customer that lets its own or a third party's AI tools or agents access the service agrees to be legally bound by the actions those tools take on its behalf.
you authorize and agree to be legally bound by the actions taken on your behalf by those Third Party Tools

Noted by a second reader on 2026-10-08.

During the agreement Vercel may use the customer's trademarks, trade names and logos in its marketing materials and websites and name it as a customer.
During the term of this Agreement, you grant Vercel a non-exclusive, royalty-free, fully-paid up license to use and reproduce your trademarks, trade names and logos in Vercel's marketing materials and website(s) and to indicate that you are a Vercel customer.

Noted by a second reader on 2026-10-08.

The licence over customer content is sublicensable and transferable and covers improving the services and developing new products and services.
a worldwide, non-exclusive, royalty-free, fully paid, sublicensable and transferable license to use, copy, modify, adapt, reproduce, distribute, display, publish, store, perform, and create derivatives of Your Content to provide and improve the Services, develop new products and services

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 8,171 words

Privacy policy dated 2026-06-01, states 7 of 8, 2 to know

TL;DR Dated 2026-06-01. States 7 of the 8 things a reader expects, and we didn't find how long data is kept. To know before relying on it, model training with an opt-out and selling or sharing data for advertising.

Says it may use customer content to train or improve models, and gives an opt-out
Services, such as when we use your information to train the AI models

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Says it sells personal data or shares it for advertising
We engage with several partners, such as third-party advertising networks, integration service partners, event sponsors, and resellers. We may share information with them to provide and support our Services, and to conduct our Advertising and Marketing Activities.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-06-01
Last Updated June 1, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
The information that we collect depends on your interactions with us, the choices that you make, the products and features you use, your location, and applicable laws.

The basic statement a privacy policy exists to make.

Says how long data is kept

Not found in the text.

Says when data sent to the service is deleted.

Says who else receives the data
We receive information about Customers from third parties or Vercel partners that provide services or support our business operations.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
We advertise our Services through third parties, and may use cookies and other tracking technologies to support targeted advertising and serve relevant ads.

A plain statement either way.

Says what rights people have over their data
You have the right to withdraw consent where you have provided your consent for us to process your personal information.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@vercel.com
If you have questions about this Notice, please contact us at privacy@vercel.com or write to us:

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
To the extent required by applicable law, whenever we transfer your information, we take the appropriate steps to protect your information, including the use of standard contractual clauses or other appropriate legal mechanisms.

The countries data goes to and the safeguard used.

For Hobby and Pro plans, subject to team settings, Vercel may disclose de-identified information to AI business partners for training and improving their models.
we may disclose de-identified information (including de-identified AI Product Information) to AI business partners for their product improvement and development, including training and improving AI and machine learning models

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 7,867 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Terms of Service (last updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, and California law. The DPA calls Vercel Inc. a Delaware corporation.

Connect also has its own product terms at https://vercel.com/docs/connect/legal. The Terms of Service text we read does not mention Connect by name.

The Privacy Notice (effective 1 June 2026) says it does not apply to personal information Vercel processes as a processor for customers, which the DPA covers. The DPA (effective 31 March 2026) applies to Pro and Enterprise plans.

https://vercel.com/.well-known/security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.

RDAP gives vercel.com a registration date of 1999-10-04, long before Vercel, so the domain was bought later.

The API answers at api.vercel.com and the OpenAPI document at openapi.vercel.sh.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 09:03 UTC

Right nowUpHTTP 200 · 762 ms · 5 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h563 msget
p95 24h2.6 sopen endpoint

Probed every five minutes at https://api.vercel.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 1 minute ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/vercel-connect.json

Notable

  • Every token request is a POST to https://api.vercel.com/v1/connect/token/:connector with a Bearer OIDC or access token, and the connector uid is URL-encoded, so slack/acme-slack becomes slack%2Facme-slack source
  • Generally available on all plans since 25 August 2026, with RBAC for connectors, audit logs and token observability added at that release source
  • The catalogue page listed 1,083 services when we counted on 8 October 2026, 8 of them marked Managed, 882 with an API key method, 374 with MCP and 48 with OAuth. Salesforce and Linq are marked Beta source
  • The product terms forbid routing cardholder data, protected health information, GLBA non-public personal information or ITAR data through Connect without Vercel's written approval, and let Vercel add or remove third-party platforms without notice source
  • Revocation calls the provider's revocation endpoint where one exists. Otherwise Connect marks the token for deletion in its own store and the provider credential may keep working until it expires source
  • Project links decide which environments may request tokens but don't separate provider installations, so Vercel's docs advise one connector per environment for isolation source
  • Vercel's security bulletin for April 2026 says an attacker reached internal systems through an employee account and decrypted some customers' non-sensitive environment variables. Connect was not generally available then source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 12.6
Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.7
Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, authorizationDetails is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12).
Agent ergonomics 13%16.2 12.2
A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes limit, cursor, search, projectId and type (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8).
Security & auth 14%17.5 14.5
Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to ['*'], and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18).
Payments & pricing 10%12.5 5.0
No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.1
@vercel/connect 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6).
Transparency & trusteditorial 55, provenance 99 7%8.8 6.7
Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12).
Negative events≤15
  • April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident).
-3
Total68.8 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 18 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Vercel Connect, or have the agent fetch /fixes/vercel-connect.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Vercel Connect

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/vercel-connect, the October 2026 research run, assessed 8 October 2026. Grade B, 68.8 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Vercel Connect: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total

Why it scored 40: No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Reliability, 63 out of 100, up to 7.4 more on the total

Why it scored 63: Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 3. Agent ergonomics, 75 out of 100, up to 4.1 more on the total

Why it scored 75: A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes `limit`, `cursor`, `search`, `projectId` and `type` (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Security & auth, 83 out of 100, up to 3 more on the total

Why it scored 83: Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to `['*']`, and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Schema & documentation, 84 out of 100, up to 2.6 more on the total

Why it scored 84: Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, `authorizationDetails` is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 77 out of 100, up to 2 more on the total

Made of editorial 55, provenance 99.

Why it scored 77: Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)

## 7. Maintenance & community, 81 out of 100, up to 1.7 more on the total

Why it scored 81: `@vercel/connect` 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident).

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the entries of the subprocessor list on security.vercel.com, which is drawn by script. We saw only that the page has a Subprocessors section.
- unchecked: whether Hobby signup asks for a card. The Hobby plan page names none, and we did not open the signup flow.
- unchecked: CI status for packages/connect on the default branch of vercel/vercel, and issue replies there.
- Whether failed or cached token requests are billed. The pricing page defines a token request as a call that returns a provider token.
- How stored provider refresh tokens and API keys are encrypted and how long they are kept after a connector is deleted. Not found in the reviewed documentation.
- Whether a REST path for revocation is public. The docs say tokens can be revoked through the REST API, and the OpenAPI document has no Connect revoke path.
- The deduction of 3 for the April 2026 incident is a judgement call. The existing vercel-sandbox listing took none for the same bulletin.
- The 18 September 2026 status entry for KMS and Connect errors has no duration, so its length is unknown.
- The count of 1,083 catalogue services is ours, from the Markdown of /connect/browse. Vercel's own figure at launch was 100+ preset connectors.

## Weaknesses

- Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment
- Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page
- Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise
- Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires
- The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry
- Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes
- Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser
- Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user
- On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the entries of the subprocessor list on security.vercel.com, which is drawn by script. We saw only that the page has a Subprocessors section.
  • unchecked: whether Hobby signup asks for a card. The Hobby plan page names none, and we did not open the signup flow.
  • unchecked: CI status for packages/connect on the default branch of vercel/vercel, and issue replies there.
  • Whether failed or cached token requests are billed. The pricing page defines a token request as a call that returns a provider token.
  • How stored provider refresh tokens and API keys are encrypted and how long they are kept after a connector is deleted. Not found in the reviewed documentation.
  • Whether a REST path for revocation is public. The docs say tokens can be revoked through the REST API, and the OpenAPI document has no Connect revoke path.
  • The deduction of 3 for the April 2026 incident is a judgement call. The existing vercel-sandbox listing took none for the same bulletin.
  • The 18 September 2026 status entry for KMS and Connect errors has no duration, so its length is unknown.
  • The count of 1,083 catalogue services is ours, from the Markdown of /connect/browse. Vercel's own figure at launch was 100+ preset connectors.

Sources 27

  1. Connect docs overview vercel.com · seen 2026-10-08
  2. authentication and the HTTP token call vercel.com · seen 2026-10-08
  3. tokens, scoping, revocation and errors vercel.com · seen 2026-10-08
  4. rate limits vercel.com · seen 2026-10-08
  5. pricing vercel.com · seen 2026-10-08
  6. observability events and retention vercel.com · seen 2026-10-08
  7. SDK reference vercel.com · seen 2026-10-08
  8. Connect product terms vercel.com · seen 2026-10-08
  9. project links vercel.com · seen 2026-10-08
  10. general availability changelog entry vercel.com · seen 2026-10-08
  11. connector permissions changelog entry vercel.com · seen 2026-10-08
  12. connector catalogue vercel.com · seen 2026-10-08
  13. OpenAPI document openapi.vercel.sh · seen 2026-10-08
  14. status page incidents feed vercel-status.com · seen 2026-10-08
  15. status page components vercel-status.com · seen 2026-10-08
  16. npm registry, versions and dates registry.npmjs.org · seen 2026-10-08
  17. npm weekly downloads api.npmjs.org · seen 2026-10-08
  18. SDK source in the public repository (shallow clone) github.com · seen 2026-10-08
  19. Terms of Service vercel.com · seen 2026-10-08
  20. Privacy Notice vercel.com · seen 2026-10-08
  21. Data Processing Addendum vercel.com · seen 2026-10-08
  22. SLA vercel.com · seen 2026-10-08
  23. compliance page vercel.com · seen 2026-10-08
  24. security.txt vercel.com · seen 2026-10-08
  25. April 2026 security bulletin vercel.com · seen 2026-10-08
  26. Hobby plan vercel.com · seen 2026-10-08
  27. RDAP for vercel.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $3 / 1k req Billed per token request and per trigger. Hobby includes 500 token requests and 1,000 triggers a month at no extra charge, and Vercel's fair use guidelines limit Hobby to non-commercial, personal use. Pro is $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on top of the plan. Enterprise is negotiated. A trigger is counted once per destination, and once per event when no destination is set. The SDK's in-process cache means many provider calls in one invocation cost one token request (https://vercel.com/docs/connect/pricing, checked 2026-10-08).

Prices

ItemPriceUnitNote
Token request (Pro)$3per 1,000 requestsHobby includes 500 a month. Enterprise negotiated
Trigger, a forwarded provider webhook (Pro)$0.95per 1,000 requestsCounted per destination. Hobby includes 1,000 a month

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/vercel-connect.xml, or this listing's score history at history.json.

Connect

Install

pnpm add @vercel/connect

First request

curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \
  -H "Authorization: Bearer $VERCEL_OIDC_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"subject":{"type":"app"},"scopes":["chat:write"]}'

Through letme picks today, calling later

GET https://letme.dev/vercel-connect

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Descope Agentic Identity Hub DescopeA78.1auth.oauth auth.tokens auth.consent auth.auditno
Amazon Bedrock AgentCore Identity Amazon Web ServicesBB74.8auth.oauth auth.tokens auth.consent auth.auditno
Aembit Aembit, Inc.BB70.5auth.oauth auth.tokens auth.consent auth.auditno
Nango NangoB67.7auth.oauth auth.tokens auth.consent auth.auditno
Arcade.dev Arcade.devB66.9auth.oauth auth.tokens auth.consent auth.auditno
WorkOS Pipes and Agents WorkOSC59.9auth.oauth auth.tokens auth.consent auth.auditno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Vercel Connect on Anchor Terminal, B, 68.8/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/vercel-connect"><img src="https://www.anchorterminal.com/badges/vercel-connect.svg" alt="Vercel Connect on Anchor Terminal" height="20"></a>
    [![Vercel Connect on Anchor Terminal](https://www.anchorterminal.com/badges/vercel-connect.svg)](https://www.anchorterminal.com/tools/vercel-connect)

    It counts on a page on vercel.com or one of its subdomains, or the README of github.com/vercel/vercel.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "vercel-connect", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.