Wrike
by Wrike, Inc. HTTP API in Project & task management
Hosted
Wrike, Inc. · wrike.com since 2005 · status page · who's behind it
Wrike is a hosted work management platform for tasks, projects, folders, approvals and request forms. Agents reach it through REST API v4 and an official remote MCP server at mcp.wrike.com/v2 with 29 documented tools.
Good for Teams already on Wrike that want an assistant to find work, create tasks and projects from notes, update status in bulk, comment and check approvals.
Is this your product? Claim this listing or verify it
Assessment. The official MCP server has 29 documented tools for search, task and project creation, bulk updates, comments and approvals, and it works on every plan including Free. Permanent access tokens never expire and carry the user's full access, and no SLA, official SDK or deprecation policy was found in the reviewed documentation.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://www.wrike.com/api/v4- Auth
- OAuth or key
- Pricing
- Freemium · $10 / seat-mo
- x402
- No
- Licence
- Proprietary service under Wrike's terms. The agent skills repository on GitHub is MIT
- Tools exposed
- 29
- llms.txt
- published
- Last release
- Surfaces
- REST API v4 at https://<host>/api/v4 (www.wrike.com, app-eu.wrike.com, app-us2.wrike.com) and the remote MCP server v2 at https://mcp.wrike.com/v2 (Streamable HTTP)
- MCP tools
- 29 documented. Read: search_spaces, get_items_children, get_my_inbox, search_items, search_users, get_users, get_item_details, get_item_comments, search_blueprints, search_requestforms, get_requestform, prefill_requestform, get_async_job, recommend_resources (Wrike Labs, Pinnacle and Apex), search_workflows, search_customitemtypes, search_item_customfields, get_approvals, search_approvals. Write: create_task_item, create_project_folder_item, create_item_from_blueprint, submit_requestform, update_items, create_item_comment, prepare_attachment_upload, add_attachments_to_item, add_whiteboard_to_item, remove_whiteboard_from_item
- Credentials
- OAuth 2.0 authorisation code flow with a client ID and secret from an API app, one-hour access tokens and refresh tokens. Permanent access tokens never expire, are shown once and can be revoked in the app console
- Scopes
- Default, wsReadOnly, wsReadWrite, amReadOnlyWorkflow, amReadWriteWorkflow, amReadOnlyInvitation, amReadWriteInvitation, amReadOnlyGroup, amReadWriteGroup, amReadOnlyUser, amReadWriteUser, plus amReadOnlyAccessRole and dataExportFull on some methods
- Rate limits
- About 400 requests a minute per IP or access token, answered with 429 too_many_requests. A second 429, rate_limit_exceeded, comes from overload protection
- Pagination
pageSizeup to 1,000 withnextPageToken, alimitparameter, sort fields, date and assignee filters, and afieldsarray for optional data- Errors
- JSON body with
erroranderrorDescription. 11 documented codes across 400, 401, 403, 404, 429 and 500 - Batch
- POST /batch schedules up to 100 independent operations as an async job with per-operation results
- Webhooks
- Account, folder and space webhooks with event filtering, optional HMAC SHA-256 signing, up to 3 delivery attempts and automatic suspension
- Free tier
- Free plan at $0 with the API and MCP server, 2 GB of storage per account. 14-day trial of paid plans with no card
- Audit
- MCP actions appear in the activity stream under the authenticated user. User audit reports are on Pinnacle and Apex only
- Certifications
- SOC 2 Type II, ISO 27001, 27017, 27018 and 27701 per the trust centre at security.wrike.com
- Status
- status.wrike.com, Wrike's own page, a dated timeline of incidents and maintenance back to 2024 with no per-component view
- Sub-processors
- List updated 2 July 2026 with locations. Hosting on AWS, Google Cloud and Microsoft Azure in the US or EU by region. AI processing by Microsoft Azure OpenAI, Google, Anthropic and OpenAI
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Official remote MCP server at https://mcp.wrike.com/v2 over Streamable HTTP, with 29 documented tools and no delete tool
- REST API v4 and the MCP server are included on every plan, Free among them, and the 14-day trial needs no card
- OpenAPI 3.0.1 definitions on each of 244 reference pages, plus llms.txt and Markdown copies of the docs
- OAuth 2.0 authorisation code flow with read-only and read-write scopes and one-hour access tokens
- SOC 2 Type II and ISO 27001, 27017, 27018 and 27701 named on the trust centre, and a valid security.txt
Weaknesses
- A permanent access token never expires and reaches everything its user can, and it is the documented route for clients that need dynamic client registration
- The API accepts the access token as an
access_tokenquery parameter as a documented option - No SLA, idempotency keys or Retry-After header found in the reviewed documentation
- No official SDK, and the official MCP registry lists only a third-party Wrike server (ai.waystation/wrike)
- The status page is a single timeline with no API or MCP component, and user audit reports are limited to Pinnacle and Apex
Before you call it notes for agents
- Build API URLs from the
hostvalue returned by /oauth2/token. Accounts live on www.wrike.com, app-eu.wrike.com or app-us2.wrike.com, and the wrong host answers 401. - Use https://mcp.wrike.com/v2 only. The older /app/mcp/stream and /app/mcp/sse URLs serve the v1 tool set.
- Call
search_workflowsbefore setting a status, becauseupdate_itemsandsearch_itemstake custom status ids. - Stay under about 400 requests a minute per token or IP and back off exponentially on 429. Use POST /batch for up to 100 operations.
- Page task lists with
pageSize(up to 1,000) andnextPageToken, and request optional data throughfields.
Who's behind it provenance 94/100
- Legal entity namedWrike, Inc.20/20
- Domain agewrike.com, registered 2005-10-15 (20 years)15/15
- Endpoint on the vendor's domainwww.wrike.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 3 clauses that cost points4/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.wrike.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2025-04-08, states 7 of 7, 4 to know
TL;DR Dated 2025-04-08. States all 7 things a reader expects. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice and cut-off without notice or for any reason.
Restricts automated accesscosts points
access or search the Service by any means other than Wrike’s publicly supported interfaces (e.g., “scraping”)
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
if Customer is a Wrike competitor, use the Service directly or indirectly for competitive benchmarking or other competitive analysis
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
for legal or regulatory reasons or for any other reasons as Wrike deems necessary, at its sole discretion, without notice.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Wrike may, with or without prior notice, immediately terminate the Agreement, Customer’s Account, Subscriptions and/or corresponding Subscription Term, and/or access to the Service and/or Add-Ons.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated Last updated 2025-04-08
Last revised: April 8, 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
…any disputes arising out of or related hereto shall be governed by and construed in accordance with the laws of the State of California, without giving effect to its conflicts of laws rules, the United Nations Convention on the International Sale of Goods, or the Uniform Computer Information Transactions Act.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $100
…UNLESS SUCH EXCLUSION OF LIABILITY IS NOT ENFORCEABLE UNDER APPLICABLE LAW IN WHICH CASE WRIKE’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO A FREE TRIAL SERVICE OR FREE CUSTOMER ACCOUNT, OR ANY CUSTOMER DATA INCLUDED THEREIN, IS $100 USD.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Wrike may ask Customer to remediate such violation and, if Customer fails to comply with such request, Wrike may suspend or terminate the User’s access to the Service and/or suspend Customer’s access to the Service pursuant to Section 8.8.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
When material changes to the Terms of Service are made, Wrike will provide Customer with notice as appropriate under the circumstances, e.g., by displaying a prominent notice to the Account Owner within the Service or by sending Customer an email.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Customer may not receive notice or confirmation from Wrike that a Free Trial Service has ended or that a Converted Paid-For Service has begun.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Fees may include Service-level changes as requested by Customer.
Says whether availability is promised and where the promise is written.
Prompts and generated content from Wrike AI are stored temporarily by Microsoft Azure OpenAI Service for abuse monitoring.
For the avoidance of doubt, Customer is aware and accepts that, in connection with Customer’s use of Wrike AI, the Azure OpenAI Service will temporarily store all prompts and generated content to monitor for and prevent abusive or harmful uses or outputs of the Azure OpenAI Service.
Noted by a second reader on 2026-10-08.
Export of customer data may be unavailable or limited after an account is deactivated or converted to a free account.
Customer may not be able, or may have limited ability, to export Customer Data after deactivation of its Customer Account or conversion to a Free Customer Account
Noted by a second reader on 2026-10-08.
Subscriptions renew automatically at the then-current rates unless the customer gives written notice before the term ends.
The Subscription will automatically renew for successive Subscription Terms at Wrike’s then-current rates unless Customer provides written notice of its intent not to renew such Subscription prior to the expiration of the then-current Subscription Term.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 9,571 words
Privacy policy dated 2026-06-01, states 8 of 8, 1 to know
TL;DR Dated 2026-06-01. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
Ad Targeting: We and our advertising partners use these cookies mainly to build a profile of your interests and show you relevant ads on other websites and deliver other online or offline marketing to you.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-06-01
Last updated June 1, 2026.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
When we collect personal data via AI-enabled tools or automated systems, we ensure such collection is limited to what is necessary for the specified purpose.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 10 years
Following contract termination, we retain core account records (such as invoices, signed contracts, and payment history) for 10 years to comply with statutory tax and commercial record-keeping obligations.
Says when data sent to the service is deleted.
Says who else receives the data
…participant has actively consented to the recording, and to use AI-enabled tools and related service providers in connection with those videoconferences and emails to assist with
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
To learn more about interest-based advertising, including certain additional opt-out options for the targeting of interest-based ads by some of our current ad service partners, visit aboutads.info/choices, youradchoices.ca or youronlinechoices.eu from each of your browsers on each of your devices.
A plain statement either way.
Says what rights people have over their data
The right to restrict the processing of personal data where the accuracy of the data is contested or the processing is unlawful;
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Gives an email address, hidden from our reader by the page
You also can contact us at [email protected] to perform the portion of the "sale" or "sharing" opt-out process in which you provide us with contact information.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
Residents of the European Economic Area, the UK, and Switzerland also have certain rights under the Data Privacy Framework, as described in the “International Data Transfers” section below.
The countries data goes to and the safeguard used.
Emails exchanged with Wrike sales staff, including third-party replies, may be processed with AI tools.
Sales representatives’ emails and related correspondence, including complete email chains and third-party responses to Wrike communications, may be processed using AI-enabled tools for the purposes described in this Privacy Policy.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,534 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms name Wrike, Inc. or its affiliate on the order, with a principal office at 550 West B Street, Floor 4, PMB 2305, San Diego, CA 92101, and apply to orders effective on or after 8 April 2025.
The API answers on wrike.com hosts (www, app-eu, app-us2) and the MCP server at mcp.wrike.com.
www.wrike.com/.well-known/security.txt names a report form and appsec@team.wrike.com and expires on 10 October 2026, two days after this check.
RDAP for wrike.com gives a registration date of 2005-10-15.
status.wrike.com/history redirects to a 404 page. The timeline is read from status.wrike.com/json, the feed the page itself loads.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://www.wrike.com/api/v4. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- GitHub stars 0
- security.txt valid, expires 2026-10-10T11:59:00Z · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/wrike.json
Notable
- MCP v2 is served at https://mcp.wrike.com/v2 over Streamable HTTP only, with OAuth 2.0 through an OAuth app an admin creates, or a permanent access token sent as a Bearer header source
- The tools page lists 29 tools marked Read or Write, among them search_items, get_item_details (up to five items), create_task_item, update_items (up to 20 items) and create_item_comment, with no delete tool source
- The comparison table lists Open RESTful API and MCP Server on every plan from Free to Apex source
- API errors list 429 too_many_requests at 400 requests per minute per IP or access token, and the FAQ advises exponential backoff source
- An async Batch API takes up to 100 operations in one request, announced 30 December 2025 source
- Webhooks can be signed with a shared secret (X-Hook-Signature, HMAC SHA-256), are retried up to 3 times and are suspended after failures source
- Wrike publishes five agent skills for the MCP server under MIT at https://github.com/wrike/agent-skills
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.6 | |
Graded on the hosted lines for REST API v4 and the MCP server. status.wrike.com is Wrike's own page with a dated timeline back to 2024 but no per-component history and no API or MCP entry (15 of 20). In the 90 days to 8 October 2026 it shows three incidents, a 7-minute workspace loading problem on the EU data centre on 5 October, the mobile apps unreachable from 09:19 to 15:59 UTC on 12 September while web and desktop kept working, and an attachment upload fault for some users on 12 August. None names the API (20). The error reference gives 400 requests a minute per IP or access token (15). The FAQ advises exponential backoff on 429, with no Retry-After header and no idempotency keys for writes found (8 of 15). No SLA found in the terms, pricing or trust centre pages we read (0). API v4 is generally available and MCP v2 carries no beta label, though recommend_resources is a Wrike Labs tool (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.7 | |
Each of the 244 API reference pages embeds an OpenAPI 3.0.1 definition with a bearer security scheme, and a Postman collection is published. We found no single downloadable spec (22 of 25). llms.txt and Markdown copies of every docs page (10). API parameter descriptions are short, such as 'Title of task, required', and the MCP tools page gives one line per tool with a few limits stated, for example that prefill_requestform doesn't submit. The MCP tool schemas sit behind authentication and were not read (12 of 20). Enums for status, importance and sort fields and required flags, but structured values such as dates travel as JSON strings in query parameters (11 of 15). Curl and JSON examples in the guides and an error table of 11 codes, while reference responses are grouped as 2XX, 4XX and 5XX (10 of 15). A single v4 version and a dated changelog with sparse entries (13 of 15). | |||
| Agent ergonomics | 13%16.2 | 10.2 | |
29 MCP tools in a fixed set with no toolsets or read-only subset on the server (15 of 25). Task queries take pageSize up to 1,000, nextPageToken, sort fields, a fields array and filters for dates, assignees and status, and search_items filters by assignee, status, dates and importance (20). Errors return error and errorDescription from 11 documented codes, which name the fault but rarely the fix (14 of 20). No idempotency keys. The tools page marks each tool Read or Write, and whether the server sends readOnlyHint or destructiveHint was not checked. The async Batch API reports per-operation results (6 of 20). Creating a task needs only a title, but the FAQ says there is no official SDK (8 of 15). | |||
| Security & auth | 14%17.5 | 10.5 | |
OAuth 2.0 authorisation code flow with read-only and read-write scopes, one-hour access tokens and revocation. Permanent tokens never expire and reach everything their user can, and the docs point clients that need dynamic client registration to them. The docs also allow the token as an access_token query parameter, which costs 10 (20 of 30). The API has wsReadOnly, the MCP server inherits the user's permissions, has no delete tool and marks tools Read or Write, and client admins can restrict tools. No server-side read-only mode or confirmation step is documented (12 of 20). Comments, descriptions and inbox items written by other people reach the model, and no injection guidance was found (3 of 15). MCP actions appear in the activity stream under the user, and user audit reports are limited to Pinnacle and Apex (10 of 15). Valid security.txt with a report form, SOC 2 Type II and ISO 27001, 27017, 27018 and 27701 on the trust centre. No bug bounty or public advisories found (15 of 20). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices are public, Free $0, Team $10 and Business $25 a user a month, with Pinnacle and Apex quoted by sales. API calls aren't priced (10). The Free plan includes the API and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates the API app or token (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.5 | |
| The newest API changelog entries are dated 17 September 2026, and the MCP tools page was updated on 7 October 2026 (30). Three dated changelog entries in the 90 days to 8 October, on 28 July and two on 17 September (20). A public changelog, a developer community forum and a support form. We didn't check response times (10 of 15). No official SDK, and the official MCP registry lists only a third-party server, ai.waystation/wrike (0). No packages to assess. The MIT agent skills repository is published by CI and last changed on 7 October 2026 (3 of 10). | |||
| Transparency & trusteditorial 62, provenance 94 | 7%8.8 | 6.8 | |
| Closed service with terms naming Wrike, Inc., and MIT agent skills (15). The privacy policy of 1 June 2026 gives retention periods but excludes customer data, which falls under the terms and a published DPA. The terms say customer data isn't used to train Wrike AI models, deletion follows 'then-current practices', and inactive Free accounts are deleted after 180 days. The MCP docs say the server stores and caches nothing (22 of 30). No deprecation policy found. The FAQ records the v3 sunset on 30 June 2019, and one parameter is marked deprecated without a date (5 of 20). The sub-processor list, updated 2 July 2026, gives purposes and US or EU locations by region (20). | |||
| Negative events | ≤15 |
| -3 |
| Total | 60.1 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 16 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Wrike, or have the agent fetch /fixes/wrike.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Wrike From Anchor Terminal's listing at https://www.anchorterminal.com/tools/wrike, the October 2026 research run, assessed 8 October 2026. Grade C, 60.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Wrike: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices are public, Free $0, Team $10 and Business $25 a user a month, with Pinnacle and Apex quoted by sales. API calls aren't priced (10). The Free plan includes the API and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates the API app or token (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 60 out of 100, up to 7 more on the total Why it scored 60: OAuth 2.0 authorisation code flow with read-only and read-write scopes, one-hour access tokens and revocation. Permanent tokens never expire and reach everything their user can, and the docs point clients that need dynamic client registration to them. The docs also allow the token as an `access_token` query parameter, which costs 10 (20 of 30). The API has wsReadOnly, the MCP server inherits the user's permissions, has no delete tool and marks tools Read or Write, and client admins can restrict tools. No server-side read-only mode or confirmation step is documented (12 of 20). Comments, descriptions and inbox items written by other people reach the model, and no injection guidance was found (3 of 15). MCP actions appear in the activity stream under the user, and user audit reports are limited to Pinnacle and Apex (10 of 15). Valid security.txt with a report form, SOC 2 Type II and ISO 27001, 27017, 27018 and 27701 on the trust centre. No bug bounty or public advisories found (15 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Reliability, 68 out of 100, up to 6.4 more on the total Why it scored 68: Graded on the hosted lines for REST API v4 and the MCP server. status.wrike.com is Wrike's own page with a dated timeline back to 2024 but no per-component history and no API or MCP entry (15 of 20). In the 90 days to 8 October 2026 it shows three incidents, a 7-minute workspace loading problem on the EU data centre on 5 October, the mobile apps unreachable from 09:19 to 15:59 UTC on 12 September while web and desktop kept working, and an attachment upload fault for some users on 12 August. None names the API (20). The error reference gives 400 requests a minute per IP or access token (15). The FAQ advises exponential backoff on 429, with no Retry-After header and no idempotency keys for writes found (8 of 15). No SLA found in the terms, pricing or trust centre pages we read (0). API v4 is generally available and MCP v2 carries no beta label, though `recommend_resources` is a Wrike Labs tool (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Agent ergonomics, 63 out of 100, up to 6 more on the total Why it scored 63: 29 MCP tools in a fixed set with no toolsets or read-only subset on the server (15 of 25). Task queries take `pageSize` up to 1,000, `nextPageToken`, sort fields, a `fields` array and filters for dates, assignees and status, and `search_items` filters by assignee, status, dates and importance (20). Errors return `error` and `errorDescription` from 11 documented codes, which name the fault but rarely the fix (14 of 20). No idempotency keys. The tools page marks each tool Read or Write, and whether the server sends readOnlyHint or destructiveHint was not checked. The async Batch API reports per-operation results (6 of 20). Creating a task needs only a title, but the FAQ says there is no official SDK (8 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 78 out of 100, up to 3.6 more on the total Why it scored 78: Each of the 244 API reference pages embeds an OpenAPI 3.0.1 definition with a bearer security scheme, and a Postman collection is published. We found no single downloadable spec (22 of 25). llms.txt and Markdown copies of every docs page (10). API parameter descriptions are short, such as 'Title of task, required', and the MCP tools page gives one line per tool with a few limits stated, for example that `prefill_requestform` doesn't submit. The MCP tool schemas sit behind authentication and were not read (12 of 20). Enums for status, importance and sort fields and required flags, but structured values such as dates travel as JSON strings in query parameters (11 of 15). Curl and JSON examples in the guides and an error table of 11 codes, while reference responses are grouped as 2XX, 4XX and 5XX (10 of 15). A single v4 version and a dated changelog with sparse entries (13 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Maintenance & community, 63 out of 100, up to 3.2 more on the total Why it scored 63: The newest API changelog entries are dated 17 September 2026, and the MCP tools page was updated on 7 October 2026 (30). Three dated changelog entries in the 90 days to 8 October, on 28 July and two on 17 September (20). A public changelog, a developer community forum and a support form. We didn't check response times (10 of 15). No official SDK, and the official MCP registry lists only a third-party server, ai.waystation/wrike (0). No packages to assess. The MIT agent skills repository is published by CI and last changed on 7 October 2026 (3 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 78 out of 100, up to 1.9 more on the total Made of editorial 62, provenance 94. Why it scored 78: Closed service with terms naming Wrike, Inc., and MIT agent skills (15). The privacy policy of 1 June 2026 gives retention periods but excludes customer data, which falls under the terms and a published DPA. The terms say customer data isn't used to train Wrike AI models, deletion follows 'then-current practices', and inactive Free accounts are deleted after 180 days. The MCP docs say the server stores and caches nothing (22 of 30). No deprecation policy found. The FAQ records the v3 sunset on 30 June 2019, and one parameter is marked deprecated without a date (5 of 20). The sub-processor list, updated 2 July 2026, gives purposes and US or EU locations by region (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points (4 of 10) ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 17 September 2026. The API changelog says the task dependency endpoints 'now' need the TaskDatesAndDependenciesEdit right and reject callers without it with 403, with no earlier notice found. The change is documented with the action required, so the smallest deduction applies (https://developers.wrike.com/changelog/permission-checks-enforced-on-task-dependency-endpoints). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the MCP server's tool schemas and annotations (readOnlyHint, destructiveHint), because tools/list needs a Wrike account. The tool count of 29 is from the docs page. - unchecked: whether Wrike gave earlier notice by email of the 17 September 2026 permission change on dependency endpoints. - unchecked: the DPA and the information security addendum PDFs, and whether any enterprise contract carries an uptime SLA. - unchecked: response times on the developer community forum. - No single downloadable OpenAPI file was found. The definitions are embedded per reference page, so `openapi` is left empty. - The launch dates of MCP v1 and v2 were not found. A Wrike blog post on the MCP server is dated 6 October 2025. - security.txt expires on 10 October 2026 and will read as expired unless renewed. ## Weaknesses - A permanent access token never expires and reaches everything its user can, and it is the documented route for clients that need dynamic client registration - The API accepts the access token as an `access_token` query parameter as a documented option - No SLA, idempotency keys or Retry-After header found in the reviewed documentation - No official SDK, and the official MCP registry lists only a third-party Wrike server (ai.waystation/wrike) - The status page is a single timeline with no API or MCP component, and user audit reports are limited to Pinnacle and Apex ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Build API URLs from the `host` value returned by /oauth2/token. Accounts live on www.wrike.com, app-eu.wrike.com or app-us2.wrike.com, and the wrong host answers 401. - Use https://mcp.wrike.com/v2 only. The older /app/mcp/stream and /app/mcp/sse URLs serve the v1 tool set. - Call `search_workflows` before setting a status, because `update_items` and `search_items` take custom status ids. - Stay under about 400 requests a minute per token or IP and back off exponentially on 429. Use POST /batch for up to 100 operations. - Page task lists with `pageSize` (up to 1,000) and `nextPageToken`, and request optional data through `fields`. ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the MCP server's tool schemas and annotations (readOnlyHint, destructiveHint), because tools/list needs a Wrike account. The tool count of 29 is from the docs page.
- unchecked: whether Wrike gave earlier notice by email of the 17 September 2026 permission change on dependency endpoints.
- unchecked: the DPA and the information security addendum PDFs, and whether any enterprise contract carries an uptime SLA.
- unchecked: response times on the developer community forum.
- No single downloadable OpenAPI file was found. The definitions are embedded per reference page, so
openapiis left empty. - The launch dates of MCP v1 and v2 were not found. A Wrike blog post on the MCP server is dated 6 October 2025.
- security.txt expires on 10 October 2026 and will read as expired unless renewed.
Sources 25
- developer docs index (llms.txt) developers.wrike.com · seen 2026-10-08
- API v4 overview and scopes developers.wrike.com · seen 2026-10-08
- OAuth 2.0 and permanent tokens developers.wrike.com · seen 2026-10-08
- API errors and rate limit developers.wrike.com · seen 2026-10-08
- FAQ (plans, rate limit, SDKs) developers.wrike.com · seen 2026-10-08
- MCP server overview developers.wrike.com · seen 2026-10-08
- MCP tools developers.wrike.com · seen 2026-10-08
- MCP permanent token setup developers.wrike.com · seen 2026-10-08
- MCP setup for other clients developers.wrike.com · seen 2026-10-08
- Create Task reference with OpenAPI developers.wrike.com · seen 2026-10-08
- Query Tasks reference developers.wrike.com · seen 2026-10-08
- webhooks developers.wrike.com · seen 2026-10-08
- API changelog developers.wrike.com · seen 2026-10-08
- changelog entry on dependency permission checks developers.wrike.com · seen 2026-10-08
- status timeline feed status.wrike.com · seen 2026-10-08
- pricing wrike.com · seen 2026-10-08
- plan comparison table wrike.com · seen 2026-10-08
- help centre article on MCP help.wrike.com · seen 2026-10-08
- trust centre security.wrike.com · seen 2026-10-08
- security.txt wrike.com · seen 2026-10-08
- terms wrike.com · seen 2026-10-08
- privacy policy wrike.com · seen 2026-10-08
- sub-processors wrike.com · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- agent skills repository github.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $10 / seat-mo The API and the MCP server are included on every plan, and Wrike charges nothing per call. Free is $0, Team $10 a user a month (2 to 15 users), Business $25 a user a month (5 to 200 users), and Pinnacle and Apex are quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract. Some fields and tools depend on the plan (checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Free (API and MCP server included) | free | per seat per month | 2 GB of storage per account |
| Team | $10 | per seat per month | 2 to 15 users, as shown on 2026-10-08 |
| Business | $25 | per seat per month | 5 to 200 users, as shown on 2026-10-08 |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/wrike.xml, or this listing's score history at history.json.
Connect
First request
curl -X GET -H "Authorization: bearer $WRIKE_ACCESS_TOKEN" "https://www.wrike.com/api/v4/contacts?me=true"
MCP client configuration
{
"mcpServers": {
"wrike": {
"args": [
"mcp-remote",
"https://mcp.wrike.com/v2",
"--header",
"Authorization:Bearer YOUR_ACCESS_TOKEN"
],
"command": "npx"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/wrike
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
monday.com BBAsana BBTodoist BClickUp CRoma DComposio (API + MCP) BB
Head to head Asana vs Wrike · ClickUp vs Wrike · monday.com vs Wrike · Roma vs Wrike · Todoist vs Wrike
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| monday.com monday.com Ltd. | BB | 76.4 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Asana Asana, Inc. | BB | 70.1 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Todoist Doist | B | 66.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| ClickUp Mango Technologies, Inc. DBA ClickUp | C | 60.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Roma Milo Mode Inc. | D | 51.1 | tasks.create tasks.update projects.manage | no |
| Composio (API + MCP) Composio | BB | 75.1 | automation.webhooks | no |
Machine-readable
- JSON
/api/v1/tools/wrike.json· historyhistory.json· badge/badges/wrike.svg· changes feed/feeds/tools/wrike.xml - Markdown
/tools/wrike.md· slim/tools/wrike.min.md(or sendAccept: text/markdown) - Fix list
/fixes/wrike.md·/fixes/wrike.json - From a terminal
anchor tool wrike --md(the CLI) · over MCPget_tool {"slug": "wrike"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/wrike"><img src="https://www.anchorterminal.com/badges/wrike.svg" alt="Wrike on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/wrike)<a href="https://www.anchorterminal.com/tools/wrike">Wrike on Anchor Terminal</a>It counts on a page on wrike.com or one of its subdomains, or the README of github.com/wrike/agent-skills.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "wrike", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
