{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/basecamp.json",
        "name": "Basecamp",
        "score": 67.9,
        "shared": [
          "work.chat"
        ],
        "slug": "basecamp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/microsoft-teams.json",
        "name": "Microsoft Teams (Microsoft Graph)",
        "score": 62.2,
        "shared": [
          "work.chat"
        ],
        "slug": "microsoft-teams"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/clickup.json",
        "name": "ClickUp",
        "score": 60.9,
        "shared": [
          "work.chat"
        ],
        "slug": "clickup"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/slack-mcp.json",
        "name": "Slack MCP Server (official)",
        "score": 59.7,
        "shared": [
          "work.chat"
        ],
        "slug": "slack-mcp"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/outline.json",
        "name": "Outline",
        "score": 60.3,
        "shared": null,
        "slug": "outline"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/notion-mcp.json",
        "name": "Notion MCP",
        "score": 58.9,
        "shared": null,
        "slug": "notion-mcp"
      }
    ],
    "tool": {
      "slug": "zulip",
      "name": "Zulip",
      "vendor": "Kandra Labs, Inc.",
      "vendorUrl": "https://zulip.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Zulip is open-source team chat organised into channels and topics, from Kandra Labs, hosted as Zulip Cloud or self-hosted. Agents reach it through a REST API with bot accounts, an events queue and Python and JavaScript client libraries.",
      "url": "https://www.anchorterminal.com/tools/zulip",
      "markdownUrl": "https://www.anchorterminal.com/tools/zulip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zulip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zulip.json",
      "repo": "https://github.com/zulip/zulip",
      "license": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "zulip"
        },
        {
          "registry": "npm",
          "name": "zulip-js"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. Every user and every bot has one API key, sent with HTTP Basic authentication as the account's email and the key. A member creates a bot under Personal settings, Bots, unless an administrator has restricted bot creation, and copies its key or downloads a `zuliprc` file. Generating a new key invalidates the old one. Keys carry no scopes or expiry. What a key can do follows the account's role (owner, administrator, moderator, member, guest), its channel subscriptions and, for bots, the bot type. No OAuth for API clients. `POST /fetch_api_key` exchanges a user's password for the key.",
      "pricing": "freemium",
      "pricingNotes": "Zulip Cloud Free costs nothing and needs no card, with 10,000 messages of search history and 5 GB of files in total. Standard is $6.67 a user a month billed annually or $8 monthly, and Plus is $10 or $12 with a 10-user minimum (https://zulip.com/plans/). API calls are not charged, and the plan comparison lists REST API custom integrations. A self-hosted server is free, with paid plans from $3.50 a user a month for mobile notifications and support. An agent's owner can start on the Free plan or a demo organisation without a contract.",
      "priceSummary": "$6.67 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API documentation, the OpenAPI file or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 26014,
        "npmWeekly": 7094,
        "pypiWeekly": 157209,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://zulip.com/api/rest",
      "openapi": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "api-key",
        "openapi",
        "python",
        "javascript",
        "webhooks",
        "status-page"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.5,
        "grade": "C",
        "agentReady": false,
        "rank": 422,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 83,
            "points": 16.6,
            "reason": "Graded on the hosted Zulip Cloud API with the hosted lines. Status page at status.zulip.com on Statuspage with nine components (20). The history lists no incidents from June to 8 October 2026 and one minor incident on 21 May. The Static asset CDN component was marked degraded on the day with no incident posted (30). The API docs give 200 requests a minute per user as the default configuration and say limits can vary by server and over time (13). A 429 returns `RATE_LIMIT_HIT` with `retry-after`, and every response has `X-RateLimit-*` headers. No idempotency key on `POST /messages` and no retry guidance for writes (10). No SLA found (0). The API is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 82,
            "points": 13.33,
            "reason": "Public OpenAPI 3.0.1 file in the repository, 166 operations on 119 paths (25). No llms.txt. The docs are Markdown in the public repository and are served as HTML only (2). All 166 operations have a description, median 295 characters, many saying which clients an endpoint is for (16). 263 enums and 322 closed objects, but one `maxLength`, five minimums and several parameters that are JSON encoded inside form fields, such as `narrow` (11). 819 example values, curl, Python and JavaScript samples per endpoint, and a shared error page with codes (14). No version beyond `/api/v1`. Changes are tracked by feature level in a public API changelog with 499 entries and 975 inline change notes, none dated (14)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 68,
            "points": 11.05,
            "reason": "`GET /messages` sizes responses with `num_before`, `num_after` and `apply_markdown`, and `POST /register` with `fetch_event_types`. No field selection (15). Anchor-based paging with flags for more results, and `narrow` filters using the search operators (18). Errors carry a stable `code` and extra keys such as `var_name`, with `msg` translated. Many failures share `BAD_REQUEST` (17). No idempotency keys. `local_id` and `queue_id` on `POST /messages` serve local echo, and the docs tell clients to repeat `delete-topic` until `complete` is true (6). Three required parameters to send a message, official Python and JavaScript libraries, the Python one last tagged in September 2025 (12)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 42,
            "points": 7.35,
            "reason": "One revocable API key per account with no scopes or expiry, and no OAuth for API clients, read as plain revocable keys (20). Incoming webhook URLs carry the key as `api_key` in the query string as a documented option (less 10). Bots are separate accounts, an incoming webhook bot can only send, roles and channel permissions apply to bots, and administrators can restrict bot creation. No read-only key and no confirmation for deletes (12). Messages are other users' text and no prompt-injection guidance was found (2). The security page claims an audit log of administrative actions. No help article or per-call log for an operator was found (5). A disclosure policy, a private HackerOne programme, advisories published with CVE numbers and CodeQL in CI. No security.txt, SOC 2 or ISO 27001 found (13)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Prices are public per user a month, $6.67 to $12 on the cloud plans, with nothing per call (10). The Free cloud plan needs no card (20). A person creates the organisation and the bot in a browser, and no programmatic route to a first key was found (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 77,
            "points": 6.74,
            "reason": "Zulip Server 12.3 was released on 21 September 2026, 18 days before the check, and the main branch had a commit on 8 October (30). Two tagged releases since 11 July 2026, 12.2 and 12.3. The API changelog adds 13 undated feature levels for 13.0 and the cloud runs ahead of the tags, so half marks (10). The newest open issues were all updated between 1 and 8 October 2026, with about 1,200 issues and 874 pull requests open on a repository of 26,014 stars, and a public development community chat (20). Official Python and JavaScript libraries exist. The Python tag 0.9.1 dates from 30 September 2025 and the JavaScript repository's last commit from December 2025 (8). CI, CodeQL and zizmor workflows, and dependency updates in each maintenance release (9)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 76,
            "points": 6.65,
            "note": "editorial 77, provenance 74",
            "reason": "The server is open source under Apache 2.0 (30). Terms, a privacy policy, rules of use, a DPA and a GDPR page agree that Kandra Labs is processor for customer data. The privacy policy keeps personal data while an account is open and states no periods, and the DPA is a PDF we did not read (20). The release lifecycle keeps the API compatible with apps released in the last 12 months, and the changelog marks removals by feature level, 50 fields are marked deprecated, with no dates (13). Seven sub-processors are named with their roles, and the service is hosted in the United States. No country per sub-processor and no change log for the list (14)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`GET /messages` sizes responses with `num_before`, `num_after` and `apply_markdown`, and `POST /register` with `fetch_event_types`. No field selection (15). Anchor-based paging with flags for more results, and `narrow` filters using the search operators (18). Errors carry a stable `code` and extra keys such as `var_name`, with `msg` translated. Many failures share `BAD_REQUEST` (17). No idempotency keys. `local_id` and `queue_id` on `POST /messages` serve local echo, and the docs tell clients to repeat `delete-topic` until `complete` is true (6). Three required parameters to send a message, official Python and JavaScript libraries, the Python one last tagged in September 2025 (12).",
            "maintenance": "Zulip Server 12.3 was released on 21 September 2026, 18 days before the check, and the main branch had a commit on 8 October (30). Two tagged releases since 11 July 2026, 12.2 and 12.3. The API changelog adds 13 undated feature levels for 13.0 and the cloud runs ahead of the tags, so half marks (10). The newest open issues were all updated between 1 and 8 October 2026, with about 1,200 issues and 874 pull requests open on a repository of 26,014 stars, and a public development community chat (20). Official Python and JavaScript libraries exist. The Python tag 0.9.1 dates from 30 September 2025 and the JavaScript repository's last commit from December 2025 (8). CI, CodeQL and zizmor workflows, and dependency updates in each maintenance release (9).",
            "payments": "No x402, MPP or L402 (0). Prices are public per user a month, $6.67 to $12 on the cloud plans, with nothing per call (10). The Free cloud plan needs no card (20). A person creates the organisation and the bot in a browser, and no programmatic route to a first key was found (0).",
            "reliability": "Graded on the hosted Zulip Cloud API with the hosted lines. Status page at status.zulip.com on Statuspage with nine components (20). The history lists no incidents from June to 8 October 2026 and one minor incident on 21 May. The Static asset CDN component was marked degraded on the day with no incident posted (30). The API docs give 200 requests a minute per user as the default configuration and say limits can vary by server and over time (13). A 429 returns `RATE_LIMIT_HIT` with `retry-after`, and every response has `X-RateLimit-*` headers. No idempotency key on `POST /messages` and no retry guidance for writes (10). No SLA found (0). The API is generally available (10).",
            "schema": "Public OpenAPI 3.0.1 file in the repository, 166 operations on 119 paths (25). No llms.txt. The docs are Markdown in the public repository and are served as HTML only (2). All 166 operations have a description, median 295 characters, many saying which clients an endpoint is for (16). 263 enums and 322 closed objects, but one `maxLength`, five minimums and several parameters that are JSON encoded inside form fields, such as `narrow` (11). 819 example values, curl, Python and JavaScript samples per endpoint, and a shared error page with codes (14). No version beyond `/api/v1`. Changes are tracked by feature level in a public API changelog with 499 entries and 975 inline change notes, none dated (14).",
            "security": "One revocable API key per account with no scopes or expiry, and no OAuth for API clients, read as plain revocable keys (20). Incoming webhook URLs carry the key as `api_key` in the query string as a documented option (less 10). Bots are separate accounts, an incoming webhook bot can only send, roles and channel permissions apply to bots, and administrators can restrict bot creation. No read-only key and no confirmation for deletes (12). Messages are other users' text and no prompt-injection guidance was found (2). The security page claims an audit log of administrative actions. No help article or per-call log for an operator was found (5). A disclosure policy, a private HackerOne programme, advisories published with CVE numbers and CodeQL in CI. No security.txt, SOC 2 or ISO 27001 found (13).",
            "transparency": "The server is open source under Apache 2.0 (30). Terms, a privacy policy, rules of use, a DPA and a GDPR page agree that Kandra Labs is processor for customer data. The privacy policy keeps personal data while an account is open and states no periods, and the DPA is a PDF we did not read (20). The release lifecycle keeps the API compatible with apps released in the last 12 months, and the changelog marks removals by feature level, 50 fields are marked deprecated, with no dates (13). Seven sub-processors are named with their roles, and the service is hosted in the United States. No country per sub-processor and no change log for the list (14)."
          },
          "sources": [
            {
              "what": "REST API overview",
              "url": "https://zulip.com/api/rest",
              "seen": "2026-10-09"
            },
            {
              "what": "HTTP headers, authentication and rate limits",
              "url": "https://zulip.com/api/http-headers",
              "seen": "2026-10-09"
            },
            {
              "what": "error handling",
              "url": "https://zulip.com/api/rest-error-handling",
              "seen": "2026-10-09"
            },
            {
              "what": "API keys and zuliprc files",
              "url": "https://zulip.com/api/api-keys",
              "seen": "2026-10-09"
            },
            {
              "what": "client libraries",
              "url": "https://zulip.com/api/client-libraries",
              "seen": "2026-10-09"
            },
            {
              "what": "roles and permissions",
              "url": "https://zulip.com/api/roles-and-permissions",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI file, 166 operations",
              "url": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
              "seen": "2026-10-09"
            },
            {
              "what": "API changelog source",
              "url": "https://github.com/zulip/zulip/blob/main/api_docs/changelog.md",
              "seen": "2026-10-09"
            },
            {
              "what": "server changelog and advisories by release",
              "url": "https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md",
              "seen": "2026-10-09"
            },
            {
              "what": "release lifecycle",
              "url": "https://github.com/zulip/zulip/blob/main/docs/overview/release-lifecycle.md",
              "seen": "2026-10-09"
            },
            {
              "what": "bots overview",
              "url": "https://zulip.com/help/bots-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "incoming webhook URL format",
              "url": "https://github.com/zulip/zulip/blob/main/docs/webhooks/incoming-webhooks-overview.md",
              "seen": "2026-10-09"
            },
            {
              "what": "plans and pricing",
              "url": "https://zulip.com/plans/",
              "seen": "2026-10-09"
            },
            {
              "what": "security page",
              "url": "https://zulip.com/security/",
              "seen": "2026-10-09"
            },
            {
              "what": "security policy",
              "url": "https://github.com/zulip/zulip/blob/main/SECURITY.md",
              "seen": "2026-10-09"
            },
            {
              "what": "security advisories",
              "url": "https://github.com/zulip/zulip/security/advisories",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://status.zulip.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "status history",
              "url": "https://status.zulip.com/history",
              "seen": "2026-10-09"
            },
            {
              "what": "terms of service",
              "url": "https://zulip.com/policies/terms",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy",
              "url": "https://zulip.com/policies/privacy",
              "seen": "2026-10-09"
            },
            {
              "what": "rules of use",
              "url": "https://zulip.com/policies/rules",
              "seen": "2026-10-09"
            },
            {
              "what": "sub-processors",
              "url": "https://zulip.com/policies/subprocessors",
              "seen": "2026-10-09"
            },
            {
              "what": "GDPR compliance",
              "url": "https://zulip.com/help/gdpr-compliance",
              "seen": "2026-10-09"
            },
            {
              "what": "repository page, stars and open issues",
              "url": "https://github.com/zulip/zulip",
              "seen": "2026-10-09"
            },
            {
              "what": "open issues",
              "url": "https://github.com/zulip/zulip/issues",
              "seen": "2026-10-09"
            },
            {
              "what": "Python client repository and tags",
              "url": "https://github.com/zulip/python-zulip-api",
              "seen": "2026-10-09"
            },
            {
              "what": "npm registry, zulip-js",
              "url": "https://registry.npmjs.org/zulip-js/latest",
              "seen": "2026-10-09"
            },
            {
              "what": "npm downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/zulip-js",
              "seen": "2026-10-09"
            },
            {
              "what": "PyPI downloads",
              "url": "https://pypistats.org/api/packages/zulip/recent",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt, 404",
              "url": "https://zulip.com/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "llms.txt, 404",
              "url": "https://zulip.com/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "RDAP for zulip.com",
              "url": "https://rdap.verisign.com/com/v1/domain/zulip.com",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: the Data Processing Addendum, a PDF at zulip.com/static/images/policies/Zulip-Data-Processing-Addendum.pdf",
            "unchecked: the PyPI project page for `zulip`, which needs JavaScript. The version and date come from the repository tag 0.9.1",
            "unchecked: the rate limits Zulip Cloud applies. The 200 a minute figure is the documented default configuration",
            "unchecked: whether a bot counts as a paid user on Standard and Plus",
            "unchecked: the status API and uptime figures. status.zulip.com disallows `/api/` in robots.txt, so the history pages were read instead",
            "unchecked: severity ratings of the advisories, and whether a second page of advisories lists more than the changelog does",
            "The lead gave docs.zulip.com/api/rest. The API documentation read is at zulip.com/api/rest, and docs.zulip.com was not requested",
            "The lead named the vendor Zulip. The legal entity in the terms is Kandra Labs, Inc.",
            "No official MCP server was found in the help centre, API docs or server documentation",
            "No SLA, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a sales agreement",
            "The Rules of Use say not to permit any third party to access an account's credentials. How that applies to an agent run by a third party was not established",
            "The audit log named on the security page has no help article we could find, so what an organisation administrator can see on Zulip Cloud was not established"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-10 and 2026-09-21. GHSA-5r8f-gq2h-fcgp let a guest receive new messages from public channels it was not subscribed to by registering an event queue, fixed in 12.2. GHSA-42mq-rxcr-wj72 let a member forge the sender of a group direct message through the API, fixed in 12.3. Both are reachable with an ordinary API key. Fixed and published, so 2 points (https://github.com/zulip/zulip/security/advisories/GHSA-5r8f-gq2h-fcgp, https://github.com/zulip/zulip/security/advisories/GHSA-42mq-rxcr-wj72).",
          "2026-02-05 to 2026-09-21. Eleven further advisories in twelve months across releases 11.5, 11.6, 12.0, 12.2 and 12.3, among them CVE-2026-25742 (attachments still public after web-public access was disabled), CVE-2026-40300 (edit history exposing original content in the API) and GHSA-xw9h-9rcm-hx4m (OpenID Connect ignoring `email_verified`). All fixed and published by the vendor, so 2 points (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)."
        ],
        "verdict": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.",
        "bestFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
        "strengths": [
          "Public OpenAPI 3.0 file with 166 operations, all described, and curl, Python and JavaScript examples per endpoint",
          "Every API change is recorded against a numbered feature level that clients read from `GET /server_settings`",
          "status.zulip.com lists no incidents from 11 July to 8 October 2026 and one minor incident in May 2026",
          "Bot accounts come in three types, and an incoming webhook bot can only send messages",
          "The server is Apache 2.0, and the Free cloud plan needs no card"
        ],
        "weaknesses": [
          "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do",
          "Thirteen security advisories between February and September 2026, among them guests reading unsubscribed public channels and forged senders through the API",
          "`POST /messages` has no idempotency key, so a retried send can post twice",
          "Incoming webhook URLs carry the bot's key in the query string as `api_key`",
          "No SLA, SOC 2 or ISO 27001 statement, security.txt or llms.txt was found"
        ],
        "agentNotes": [
          "Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages",
          "Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1",
          "Read `code`, not `msg`, on errors. `msg` is translated into the account's language",
          "On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user",
          "Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.5
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 77
        },
        "provenanceScore": 74
      },
      "connect": {
        "install": "pip install zulip",
        "http": "curl -X POST https://your-org.zulipchat.com/api/v1/messages -u EMAIL_ADDRESS:API_KEY --data-urlencode type=stream --data-urlencode 'to=\"Denmark\"' --data-urlencode topic=Castle --data-urlencode 'content=Hello'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/zulip"
      },
      "notable": [
        "The REST API is the one the web, desktop and mobile apps use, and the docs say anything a user can do in Zulip can be done through it (https://zulip.com/api/rest)",
        "Bots are accounts of three types. Generic acts like a normal user, incoming webhook can only send messages, and outgoing webhook also receives mentions and direct messages by HTTP POST (https://zulip.com/help/bots-overview)",
        "All responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and the default configuration limits each user to 200 API requests a minute (https://zulip.com/api/http-headers)",
        "Zulip Server 12.3 of 21 September 2026 fixed four advisories and 12.2 of 10 August 2026 fixed five (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)",
        "The Rules of Use say a product that embeds Zulip as its chat backend must self-host, and that account credentials must not be shared with a third party (https://zulip.com/policies/rules)",
        "The security policy reports through security@zulip.com or a private HackerOne programme, and fixes are announced on the blog with CVE numbers (https://github.com/zulip/zulip/blob/main/SECURITY.md)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The REST API of the hosted Zulip Cloud service at https://\u003corganisation\u003e.zulipchat.com/api/v1. The same API ships in the self-hosted server"
        },
        {
          "label": "API",
          "value": "OpenAPI 3.0.1, 166 operations on 119 paths. Users (45 operations), channels (29), server and organisation settings (28), messages (20), drafts (8), invitations (6), real-time events (5), scheduled messages (4). Request bodies are form-encoded"
        },
        {
          "label": "Messages",
          "value": "`POST /messages` needs `type`, `to` and `content`, plus `topic` for a channel. `GET /messages` takes a `narrow` filter with the search operators, an `anchor`, `num_before` and `num_after`, up to 5,000 a request with 1,000 recommended"
        },
        {
          "label": "Events",
          "value": "`POST /register` opens an event queue and `GET /events` long-polls it. Outgoing webhook bots receive mentions and direct messages by HTTP POST instead"
        },
        {
          "label": "Credentials",
          "value": "One API key per user or bot over HTTP Basic. No scopes, expiry or OAuth. Regenerating the key revokes the old one. Bot types are generic, incoming webhook and outgoing webhook"
        },
        {
          "label": "Rate limits",
          "value": "200 API requests a minute per user in the default configuration, lower limits on login. `X-RateLimit-*` headers on every response. A 429 body has `code` `RATE_LIMIT_HIT` and `retry-after` in seconds"
        },
        {
          "label": "Errors",
          "value": "JSON with `result`, `msg` and a machine-readable `code` such as `INVALID_API_KEY`, `REQUEST_VARIABLE_MISSING` or `RATE_LIMIT_HIT`. Success responses list `ignored_parameters_unsupported`"
        },
        {
          "label": "Versioning",
          "value": "No version beyond `/api/v1`. Each change gets a feature level (513 on the main branch on 8 October 2026), returned as `zulip_feature_level` and listed in the API changelog"
        },
        {
          "label": "Client libraries",
          "value": "Official Python `zulip` 0.9.1 (tagged 30 September 2025) and JavaScript `zulip-js` 2.1.0. Eight user-maintained libraries are listed, among them Go, Java, C# and Ruby"
        },
        {
          "label": "Releases",
          "value": "Zulip Server 12.3 on 21 September 2026, 12.2 on 10 August, 12.1 on 26 June, 12.0 on 27 April. The cloud pages reported server version 12.0-1057 on the day"
        },
        {
          "label": "Status",
          "value": "status.zulip.com on Statuspage with nine components. No incidents from June to 8 October 2026, one minor incident on 21 May 2026"
        },
        {
          "label": "Sub-processors",
          "value": "Amazon Web Services, DigitalOcean, Google, Front, Sentry, Mailgun and Stripe. The privacy policy says the service is hosted in the United States"
        }
      ],
      "unitPrices": [
        {
          "item": "Zulip Cloud Standard",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly"
        },
        {
          "item": "Zulip Cloud Plus",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed annually, $12 billed monthly, 10 users minimum"
        },
        {
          "item": "Self-hosted Basic",
          "unit": "seat-month",
          "usd": 3.5,
          "note": "billed monthly, for a server the owner runs"
        },
        {
          "item": "Self-hosted Business",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly, 25 users minimum"
        }
      ],
      "provenance": {
        "legalEntity": "Kandra Labs, Inc.",
        "domain": "zulip.com",
        "domainRegistered": "2010-12-01",
        "endpointOnVendorDomain": false,
        "terms": "https://zulip.com/policies/terms",
        "privacy": "https://zulip.com/policies/privacy",
        "statusPage": "https://status.zulip.com",
        "changelog": "https://zulip.com/api/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service (effective 7 February 2022) are a contract with Kandra Labs, Inc., 584 Castro St #3175, San Francisco, CA 94114, and cover the websites, products, services and applications.",
          "Cloud organisations answer at https://\u003corganisation\u003e.zulipchat.com/api/v1, a second domain. zulip.com's own footer links its terms and privacy policy at zulipchat.com, and the OpenAPI file names the host.",
          "https://zulip.com/.well-known/security.txt returns 404. SECURITY.md in the repository gives security@zulip.com and a private HackerOne programme.",
          "The privacy policy is effective 1 January 2022. A Data Processing Addendum is published as a PDF and was not read.",
          "RDAP for zulip.com gives a registration date of 2010-12-01."
        ],
        "score": 74,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Kandra Labs, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "zulip.com, registered 2010-12-01 (15 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on zulip.com",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects",
            "points": 9.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.zulip.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://zulip.com/policies/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-02-07",
            "words": 7266,
            "points": 9.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective date: February 7, 2022. View change history.",
                "says": "Last updated 2022-02-07"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms are governed by and will be construed under the Federal Arbitration Act, applicable federal law, and the laws of the State of California, without regard to the conflicts of laws provisions thereof.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…(B) ANY SUBSTITUTE GOODS, SERVICES OR TECHNOLOGY, (C) ANY AMOUNT, IN THE AGGREGATE, IN EXCESS OF THE GREATER OF (I) ONE-HUNDRED ($100) DOLLARS OR (II) THE AMOUNTS PAID AND/OR PAYABLE BY YOU TO ZULIP IN CONNECTION WITH THE SERVICES IN THE TWELVE (12) MONTH PERIOD PRECEDING THIS APPLICABLE CLAIM OR (D) ANY MATTER BEYOND…",
                "says": "Capped at the greater of $100 and the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We will generally aim to provide such notice about changes to the Terms at least 14 days in advance of the new Terms taking effect.",
                "says": "Gives 14 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "IF YOU DO NOT AGREE TO ALL OF THE FOLLOWING, YOU MAY NOT USE OR ACCESS THE SERVICES IN ANY MANNER."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Zulip is also free to terminate (or suspend access to) your use of the Services or your account for any reason at our sole discretion, including your breach of these Terms."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "These Terms include information about future changes to these Terms, automatic renewals, limitations of liability, a class action waiver and resolution of disputes by arbitration instead of in court."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Effective date: February 7, 2022. View change history."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Use is limited to the user's own internal, personal use and may not be on behalf of or for the benefit of a third party.",
                "quote": "You will only use the Services for your own internal, personal use, and not on behalf of or for the benefit of any third party, and only in a manner that complies with all laws that apply to you."
              },
              {
                "date": "2026-10-08",
                "text": "Paid plans renew automatically for the same term at the then-current non-promotional rate unless auto-renewal is switched off in billing settings.",
                "quote": "Unless you opt out of auto-renewal, which can be done through your billing settings, any Paid Services you have signed up for will be automatically extended for successive renewal periods of the same duration as the subscription term originally selected, at the then-current non-promotional rate."
              },
              {
                "date": "2026-10-08",
                "text": "A user may opt out of the arbitration agreement by written notice postmarked within 30 days of first accepting the terms.",
                "quote": "You have the right to opt out of the provisions of this Arbitration Agreement by sending written notice of your decision to opt out to the following address: 584 Castro St #3175, San Francisco, CA 94114 postmarked within thirty (30) days of first accepting these Terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://zulip.com/policies/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-01-01",
            "words": 5228,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective date: January 1, 2022. View change history.",
                "says": "Last updated 2022-01-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This chart details the categories of Personal Data that we may collect and may have collected from or about you over the past 12 months."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We will only share your data with third parties to help make our Services a reality."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We will not sell your personal information to third parties.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you believe that a child under the age of thirteen (13) or below the minimum age of consent in their country may have provided us personal information, please contact us at privacy@zulip.com.",
                "says": "privacy@zulip.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "servers, and you authorize Zulip to transfer, store and process your information to and in the U.S., and possibly other countries."
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Effective date: January 1, 2022. View change history."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Messages sent to another user are not deleted when an account is deleted and stay associated with a Deleted User.",
                "quote": "Please note that we will not be able to delete messages or other content that you have sent to another Zulip user."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zulip.json",
      "live": {
        "slug": "zulip",
        "vendorStatus": {
          "page": "https://status.zulip.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-09T10:11:26.208588166Z"
        },
        "updatedAt": "2026-10-09T10:11:26.208588166Z"
      }
    },
    "verify": {
      "accepts": "a page on zulip.com or one of its subdomains, or the README of github.com/zulip/zulip",
      "badgeUrl": "https://www.anchorterminal.com/badges/zulip.svg",
      "body": {
        "slug": "zulip",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/zulip",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/zulip\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zulip.svg\" alt=\"Zulip on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Zulip on Anchor Terminal](https://www.anchorterminal.com/badges/zulip.svg)](https://www.anchorterminal.com/tools/zulip)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/zulip\"\u003eZulip on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/zulip",
    "json": "https://www.anchorterminal.com/tools/zulip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/zulip.md",
    "slim": "https://www.anchorterminal.com/tools/zulip.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 61.5/100 · rank #422 of 842 · #2 in Work \u0026 productivity · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Kandra Labs, Inc. (https://zulip.com) |\n| Kind | HTTP API |\n| Category | Work \u0026 productivity (https://www.anchorterminal.com/categories/productivity) |\n| Transport | HTTP |\n| Auth | API key · Self-serve. Every user and every bot has one API key, sent with HTTP Basic authentication as the account's email and the key. A member creates a bot under Personal settings, Bots, unless an administrator has restricted bot creation, and copies its key or downloads a `zuliprc` file. Generating a new key invalidates the old one. Keys carry no scopes or expiry. What a key can do follows the account's role (owner, administrator, moderator, member, guest), its channel subscriptions and, for bots, the bot type. No OAuth for API clients. `POST /fetch_api_key` exchanges a user's password for the key. |\n| Pricing | Freemium ($6.67 / seat-mo) · Zulip Cloud Free costs nothing and needs no card, with 10,000 messages of search history and 5 GB of files in total. Standard is $6.67 a user a month billed annually or $8 monthly, and Plus is $10 or $12 with a 10-user minimum (https://zulip.com/plans/). API calls are not charged, and the plan comparison lists REST API custom integrations. A self-hosted server is free, with paid plans from $3.50 a user a month for mobile notifications and support. An agent's owner can start on the Free plan or a demo organisation without a contract. |\n| x402 | No · No x402, MPP or L402 in the API documentation, the OpenAPI file or the pricing page (checked 2026-10-09). |\n| Licence | Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT |\n| Packages | pypi: `zulip`; npm: `zulip-js` |\n| Source | https://github.com/zulip/zulip |\n| Docs | https://zulip.com/api/rest |\n| llms.txt | not found |\n| Last release | 2026-09-21 |\n| GitHub stars | 26,014 (as of 2026-10-09) |\n| npm downloads / week | 7,094 |\n| PyPI downloads / week | 157,209 |\n| Surface graded | The REST API of the hosted Zulip Cloud service at https://\u003corganisation\u003e.zulipchat.com/api/v1. The same API ships in the self-hosted server |\n| API | OpenAPI 3.0.1, 166 operations on 119 paths. Users (45 operations), channels (29), server and organisation settings (28), messages (20), drafts (8), invitations (6), real-time events (5), scheduled messages (4). Request bodies are form-encoded |\n| Messages | `POST /messages` needs `type`, `to` and `content`, plus `topic` for a channel. `GET /messages` takes a `narrow` filter with the search operators, an `anchor`, `num_before` and `num_after`, up to 5,000 a request with 1,000 recommended |\n| Events | `POST /register` opens an event queue and `GET /events` long-polls it. Outgoing webhook bots receive mentions and direct messages by HTTP POST instead |\n| Credentials | One API key per user or bot over HTTP Basic. No scopes, expiry or OAuth. Regenerating the key revokes the old one. Bot types are generic, incoming webhook and outgoing webhook |\n| Rate limits | 200 API requests a minute per user in the default configuration, lower limits on login. `X-RateLimit-*` headers on every response. A 429 body has `code` `RATE_LIMIT_HIT` and `retry-after` in seconds |\n| Errors | JSON with `result`, `msg` and a machine-readable `code` such as `INVALID_API_KEY`, `REQUEST_VARIABLE_MISSING` or `RATE_LIMIT_HIT`. Success responses list `ignored_parameters_unsupported` |\n| Versioning | No version beyond `/api/v1`. Each change gets a feature level (513 on the main branch on 8 October 2026), returned as `zulip_feature_level` and listed in the API changelog |\n| Client libraries | Official Python `zulip` 0.9.1 (tagged 30 September 2025) and JavaScript `zulip-js` 2.1.0. Eight user-maintained libraries are listed, among them Go, Java, C# and Ruby |\n| Releases | Zulip Server 12.3 on 21 September 2026, 12.2 on 10 August, 12.1 on 26 June, 12.0 on 27 April. The cloud pages reported server version 12.0-1057 on the day |\n| Status | status.zulip.com on Statuspage with nine components. No incidents from June to 8 October 2026, one minor incident on 21 May 2026 |\n| Sub-processors | Amazon Web Services, DigitalOcean, Google, Front, Sentry, Mailgun and Stripe. The privacy policy says the service is hosted in the United States |\n| Capabilities | work.chat |\n| Tags | hosted, self-hosted, open-source, freemium, api-key, openapi, python, javascript, webhooks, status-page |\n| JSON | https://www.anchorterminal.com/api/v1/tools/zulip.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 83 | 16.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 82 | 13.3 |\n| Agent ergonomics | 13% | 16.2 | 68 | 11.1 |\n| Security \u0026 auth | 14% | 17.5 | 42 | 7.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 77 | 6.7 |\n| Transparency \u0026 trust (editorial 77, provenance 74) | 7% | 8.8 | 76 | 6.7 |\n| Negative events | up to −15 | up to −15 | 2026-08-10 and 2026-09-21. GHSA-5r8f-gq2h-fcgp let a guest receive new messages from public channels it was not subscribed to by registering an event queue, fixed in 12.2. GHSA-42mq-rxcr-wj72 let a member forge the sender of a group direct message through the API, fixed in 12.3. Both are reachable with an ordinary API key. Fixed and published, so 2 points (https://github.com/zulip/zulip/security/advisories/GHSA-5r8f-gq2h-fcgp, https://github.com/zulip/zulip/security/advisories/GHSA-42mq-rxcr-wj72). 2026-02-05 to 2026-09-21. Eleven further advisories in twelve months across releases 11.5, 11.6, 12.0, 12.2 and 12.3, among them CVE-2026-25742 (attachments still public after web-public access was disabled), CVE-2026-40300 (edit history exposing original content in the API) and GHSA-xw9h-9rcm-hx4m (OpenID Connect ignoring `email_verified`). All fixed and published by the vendor, so 2 points (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md).  | -4 |\n| **Total** | | | | **61.5 → C** |\n\n### Why each score\n\n- Reliability 83: Graded on the hosted Zulip Cloud API with the hosted lines. Status page at status.zulip.com on Statuspage with nine components (20). The history lists no incidents from June to 8 October 2026 and one minor incident on 21 May. The Static asset CDN component was marked degraded on the day with no incident posted (30). The API docs give 200 requests a minute per user as the default configuration and say limits can vary by server and over time (13). A 429 returns `RATE_LIMIT_HIT` with `retry-after`, and every response has `X-RateLimit-*` headers. No idempotency key on `POST /messages` and no retry guidance for writes (10). No SLA found (0). The API is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 82: Public OpenAPI 3.0.1 file in the repository, 166 operations on 119 paths (25). No llms.txt. The docs are Markdown in the public repository and are served as HTML only (2). All 166 operations have a description, median 295 characters, many saying which clients an endpoint is for (16). 263 enums and 322 closed objects, but one `maxLength`, five minimums and several parameters that are JSON encoded inside form fields, such as `narrow` (11). 819 example values, curl, Python and JavaScript samples per endpoint, and a shared error page with codes (14). No version beyond `/api/v1`. Changes are tracked by feature level in a public API changelog with 499 entries and 975 inline change notes, none dated (14).\n- Agent ergonomics 68: `GET /messages` sizes responses with `num_before`, `num_after` and `apply_markdown`, and `POST /register` with `fetch_event_types`. No field selection (15). Anchor-based paging with flags for more results, and `narrow` filters using the search operators (18). Errors carry a stable `code` and extra keys such as `var_name`, with `msg` translated. Many failures share `BAD_REQUEST` (17). No idempotency keys. `local_id` and `queue_id` on `POST /messages` serve local echo, and the docs tell clients to repeat `delete-topic` until `complete` is true (6). Three required parameters to send a message, official Python and JavaScript libraries, the Python one last tagged in September 2025 (12).\n- Security \u0026 auth 42: One revocable API key per account with no scopes or expiry, and no OAuth for API clients, read as plain revocable keys (20). Incoming webhook URLs carry the key as `api_key` in the query string as a documented option (less 10). Bots are separate accounts, an incoming webhook bot can only send, roles and channel permissions apply to bots, and administrators can restrict bot creation. No read-only key and no confirmation for deletes (12). Messages are other users' text and no prompt-injection guidance was found (2). The security page claims an audit log of administrative actions. No help article or per-call log for an operator was found (5). A disclosure policy, a private HackerOne programme, advisories published with CVE numbers and CodeQL in CI. No security.txt, SOC 2 or ISO 27001 found (13).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Prices are public per user a month, $6.67 to $12 on the cloud plans, with nothing per call (10). The Free cloud plan needs no card (20). A person creates the organisation and the bot in a browser, and no programmatic route to a first key was found (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 77: Zulip Server 12.3 was released on 21 September 2026, 18 days before the check, and the main branch had a commit on 8 October (30). Two tagged releases since 11 July 2026, 12.2 and 12.3. The API changelog adds 13 undated feature levels for 13.0 and the cloud runs ahead of the tags, so half marks (10). The newest open issues were all updated between 1 and 8 October 2026, with about 1,200 issues and 874 pull requests open on a repository of 26,014 stars, and a public development community chat (20). Official Python and JavaScript libraries exist. The Python tag 0.9.1 dates from 30 September 2025 and the JavaScript repository's last commit from December 2025 (8). CI, CodeQL and zizmor workflows, and dependency updates in each maintenance release (9).\n- Transparency \u0026 trust 76: The server is open source under Apache 2.0 (30). Terms, a privacy policy, rules of use, a DPA and a GDPR page agree that Kandra Labs is processor for customer data. The privacy policy keeps personal data while an account is open and states no periods, and the DPA is a PDF we did not read (20). The release lifecycle keeps the API compatible with apps released in the last 12 months, and the changelog marks removals by feature level, 50 fields are marked deprecated, with no dates (13). Seven sub-processors are named with their roles, and the service is hosted in the United States. No country per sub-processor and no change log for the list (14).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (24 items): https://www.anchorterminal.com/fixes/zulip.md (JSON https://www.anchorterminal.com/fixes/zulip.json)\n\n### What we couldn't check\n\n- unchecked: the Data Processing Addendum, a PDF at zulip.com/static/images/policies/Zulip-Data-Processing-Addendum.pdf\n- unchecked: the PyPI project page for `zulip`, which needs JavaScript. The version and date come from the repository tag 0.9.1\n- unchecked: the rate limits Zulip Cloud applies. The 200 a minute figure is the documented default configuration\n- unchecked: whether a bot counts as a paid user on Standard and Plus\n- unchecked: the status API and uptime figures. status.zulip.com disallows `/api/` in robots.txt, so the history pages were read instead\n- unchecked: severity ratings of the advisories, and whether a second page of advisories lists more than the changelog does\n- The lead gave docs.zulip.com/api/rest. The API documentation read is at zulip.com/api/rest, and docs.zulip.com was not requested\n- The lead named the vendor Zulip. The legal entity in the terms is Kandra Labs, Inc.\n- No official MCP server was found in the help centre, API docs or server documentation\n- No SLA, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a sales agreement\n- The Rules of Use say not to permit any third party to access an account's credentials. How that applies to an agent run by a third party was not established\n- The audit log named on the security page has no help article we could find, so what an organisation administrator can see on Zulip Cloud was not established\n\n### Sources\n\n- REST API overview: \u003chttps://zulip.com/api/rest\u003e (seen 2026-10-09)\n- HTTP headers, authentication and rate limits: \u003chttps://zulip.com/api/http-headers\u003e (seen 2026-10-09)\n- error handling: \u003chttps://zulip.com/api/rest-error-handling\u003e (seen 2026-10-09)\n- API keys and zuliprc files: \u003chttps://zulip.com/api/api-keys\u003e (seen 2026-10-09)\n- client libraries: \u003chttps://zulip.com/api/client-libraries\u003e (seen 2026-10-09)\n- roles and permissions: \u003chttps://zulip.com/api/roles-and-permissions\u003e (seen 2026-10-09)\n- OpenAPI file, 166 operations: \u003chttps://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml\u003e (seen 2026-10-09)\n- API changelog source: \u003chttps://github.com/zulip/zulip/blob/main/api_docs/changelog.md\u003e (seen 2026-10-09)\n- server changelog and advisories by release: \u003chttps://github.com/zulip/zulip/blob/main/docs/overview/changelog.md\u003e (seen 2026-10-09)\n- release lifecycle: \u003chttps://github.com/zulip/zulip/blob/main/docs/overview/release-lifecycle.md\u003e (seen 2026-10-09)\n- bots overview: \u003chttps://zulip.com/help/bots-overview\u003e (seen 2026-10-09)\n- incoming webhook URL format: \u003chttps://github.com/zulip/zulip/blob/main/docs/webhooks/incoming-webhooks-overview.md\u003e (seen 2026-10-09)\n- plans and pricing: \u003chttps://zulip.com/plans/\u003e (seen 2026-10-09)\n- security page: \u003chttps://zulip.com/security/\u003e (seen 2026-10-09)\n- security policy: \u003chttps://github.com/zulip/zulip/blob/main/SECURITY.md\u003e (seen 2026-10-09)\n- security advisories: \u003chttps://github.com/zulip/zulip/security/advisories\u003e (seen 2026-10-09)\n- status page: \u003chttps://status.zulip.com/\u003e (seen 2026-10-09)\n- status history: \u003chttps://status.zulip.com/history\u003e (seen 2026-10-09)\n- terms of service: \u003chttps://zulip.com/policies/terms\u003e (seen 2026-10-09)\n- privacy policy: \u003chttps://zulip.com/policies/privacy\u003e (seen 2026-10-09)\n- rules of use: \u003chttps://zulip.com/policies/rules\u003e (seen 2026-10-09)\n- sub-processors: \u003chttps://zulip.com/policies/subprocessors\u003e (seen 2026-10-09)\n- GDPR compliance: \u003chttps://zulip.com/help/gdpr-compliance\u003e (seen 2026-10-09)\n- repository page, stars and open issues: \u003chttps://github.com/zulip/zulip\u003e (seen 2026-10-09)\n- open issues: \u003chttps://github.com/zulip/zulip/issues\u003e (seen 2026-10-09)\n- Python client repository and tags: \u003chttps://github.com/zulip/python-zulip-api\u003e (seen 2026-10-09)\n- npm registry, zulip-js: \u003chttps://registry.npmjs.org/zulip-js/latest\u003e (seen 2026-10-09)\n- npm downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/zulip-js\u003e (seen 2026-10-09)\n- PyPI downloads: \u003chttps://pypistats.org/api/packages/zulip/recent\u003e (seen 2026-10-09)\n- security.txt, 404: \u003chttps://zulip.com/.well-known/security.txt\u003e (seen 2026-10-09)\n- llms.txt, 404: \u003chttps://zulip.com/llms.txt\u003e (seen 2026-10-09)\n- RDAP for zulip.com: \u003chttps://rdap.verisign.com/com/v1/domain/zulip.com\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 74/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Kandra Labs, Inc. | 20/20 |\n| Domain age | zulip.com, registered 2010-12-01 (15 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on zulip.com | 0/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.zulip.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Service (effective 7 February 2022) are a contract with Kandra Labs, Inc., 584 Castro St #3175, San Francisco, CA 94114, and cover the websites, products, services and applications.\n\nCloud organisations answer at https://\u003corganisation\u003e.zulipchat.com/api/v1, a second domain. zulip.com's own footer links its terms and privacy policy at zulipchat.com, and the OpenAPI file names the host.\n\nhttps://zulip.com/.well-known/security.txt returns 404. SECURITY.md in the repository gives security@zulip.com and a private HackerOne programme.\n\nThe privacy policy is effective 1 January 2022. A Data Processing Addendum is published as a PDF and was not read.\n\nRDAP for zulip.com gives a registration date of 2010-12-01.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://zulip.com/policies/terms), read 2026-10-08, dated 2022-02-07, states 6 of the 7 things a reader expects.\n\n- To know. Says access can be ended without notice or for any reason. \"Zulip is also free to terminate (or suspend access to) your use of the Services or your account for any reason at our sole discretion, including your breach of these Terms.\"\n- To know. Requires arbitration or waives class actions. \"These Terms include information about future changes to these Terms, automatic renewals, limitations of liability, a class action waiver and resolution of disputes by arbitration instead of in court.\"\n- To know. Has not been updated for three years or more. \"Effective date: February 7, 2022. View change history.\"\n- Gives the date it was last updated. Last updated 2022-02-07.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the greater of $100 and the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives 14 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Use is limited to the user's own internal, personal use and may not be on behalf of or for the benefit of a third party. \"You will only use the Services for your own internal, personal use, and not on behalf of or for the benefit of any third party, and only in a manner that complies with all laws that apply to you.\"\n- Also in the text (2026-10-08). Paid plans renew automatically for the same term at the then-current non-promotional rate unless auto-renewal is switched off in billing settings. \"Unless you opt out of auto-renewal, which can be done through your billing settings, any Paid Services you have signed up for will be automatically extended for successive renewal periods of the same duration as the subscription term originally selected, at the then-current non-promotional rate.\"\n- Also in the text (2026-10-08). A user may opt out of the arbitration agreement by written notice postmarked within 30 days of first accepting the terms. \"You have the right to opt out of the provisions of this Arbitration Agreement by sending written notice of your decision to opt out to the following address: 584 Castro St #3175, San Francisco, CA 94114 postmarked within thirty (30) days of first accepting these Terms.\"\n\n**Privacy policy** (https://zulip.com/policies/privacy), read 2026-10-08, dated 2022-01-01, states 8 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Effective date: January 1, 2022. View change history.\"\n- Gives the date it was last updated. Last updated 2022-01-01.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@zulip.com.\n- Also in the text (2026-10-08). Messages sent to another user are not deleted when an account is deleted and stay associated with a Deleted User. \"Please note that we will not be able to delete messages or other content that you have sent to another Zulip user.\"\n\n## Live (updated 2026-10-09 10:11 UTC)\n\n- Vendor status page: minor, Partially Degraded Service\n- Always current: https://www.anchorterminal.com/api/v1/live/zulip.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Zulip Cloud Standard | $6.67 | per seat per month | billed annually, $8 billed monthly |\n| Zulip Cloud Plus | $10 | per seat per month | billed annually, $12 billed monthly, 10 users minimum |\n| Self-hosted Basic | $3.50 | per seat per month | billed monthly, for a server the owner runs |\n| Self-hosted Business | $6.67 | per seat per month | billed annually, $8 billed monthly, 25 users minimum |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0 file with 166 operations, all described, and curl, Python and JavaScript examples per endpoint\n- Every API change is recorded against a numbered feature level that clients read from `GET /server_settings`\n- status.zulip.com lists no incidents from 11 July to 8 October 2026 and one minor incident in May 2026\n- Bot accounts come in three types, and an incoming webhook bot can only send messages\n- The server is Apache 2.0, and the Free cloud plan needs no card\n\n## Weaknesses\n\n- One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do\n- Thirteen security advisories between February and September 2026, among them guests reading unsubscribed public channels and forged senders through the API\n- `POST /messages` has no idempotency key, so a retried send can post twice\n- Incoming webhook URLs carry the bot's key in the query string as `api_key`\n- No SLA, SOC 2 or ISO 27001 statement, security.txt or llms.txt was found\n\n## Before you call it (notes for agents)\n\n1. Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages\n2. Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1\n3. Read `code`, not `msg`, on errors. `msg` is translated into the account's language\n4. On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user\n5. Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend\n\n## Connect\n\nInstall:\n\n```bash\npip install zulip\n```\n\nFirst request:\n\n```bash\ncurl -X POST https://your-org.zulipchat.com/api/v1/messages -u EMAIL_ADDRESS:API_KEY --data-urlencode type=stream --data-urlencode 'to=\"Denmark\"' --data-urlencode topic=Castle --data-urlencode 'content=Hello'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/zulip. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Basecamp | B | 67.9 | 220 | work.chat | no | https://www.anchorterminal.com/tools/basecamp.md |\n| Microsoft Teams (Microsoft Graph) | B | 62.2 | 399 | work.chat | no | https://www.anchorterminal.com/tools/microsoft-teams.md |\n| ClickUp | C | 60.9 | 442 | work.chat | no | https://www.anchorterminal.com/tools/clickup.md |\n| Slack MCP Server (official) | C | 59.7 | 489 | work.chat | no | https://www.anchorterminal.com/tools/slack-mcp.md |\n| Outline | C | 60.3 | 474 | same category (Work \u0026 productivity) | no | https://www.anchorterminal.com/tools/outline.md |\n| Notion MCP | C | 58.9 | 511 | same category (Work \u0026 productivity) | no | https://www.anchorterminal.com/tools/notion-mcp.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The REST API is the one the web, desktop and mobile apps use, and the docs say anything a user can do in Zulip can be done through it (source: \u003chttps://zulip.com/api/rest\u003e)\n- Bots are accounts of three types. Generic acts like a normal user, incoming webhook can only send messages, and outgoing webhook also receives mentions and direct messages by HTTP POST (source: \u003chttps://zulip.com/help/bots-overview\u003e)\n- All responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and the default configuration limits each user to 200 API requests a minute (source: \u003chttps://zulip.com/api/http-headers\u003e)\n- Zulip Server 12.3 of 21 September 2026 fixed four advisories and 12.2 of 10 August 2026 fixed five (source: \u003chttps://github.com/zulip/zulip/blob/main/docs/overview/changelog.md\u003e)\n- The Rules of Use say a product that embeds Zulip as its chat backend must self-host, and that account credentials must not be shared with a third party (source: \u003chttps://zulip.com/policies/rules\u003e)\n- The security policy reports through security@zulip.com or a private HackerOne programme, and fixes are announced on the blog with CVE numbers (source: \u003chttps://github.com/zulip/zulip/blob/main/SECURITY.md\u003e)\n\n## Compare\n\n- [Microsoft Teams (Microsoft Graph) vs Zulip](https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.md): B 62.2 vs C 61.5\n- [Slack MCP Server (official) vs Zulip](https://www.anchorterminal.com/compare/slack-mcp-vs-zulip.md): C 59.7 vs C 61.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on zulip.com or one of its subdomains, or the README of github.com/zulip/zulip. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"zulip\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zulip\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zulip.svg\" alt=\"Zulip on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Zulip on Anchor Terminal](https://www.anchorterminal.com/badges/zulip.svg)](https://www.anchorterminal.com/tools/zulip)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zulip\"\u003eZulip on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Zulip is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/zulip-dark.png\n- Light: https://www.anchorterminal.com/assets/share/zulip-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Work \u0026 productivity",
        "url": "https://www.anchorterminal.com/categories/productivity"
      },
      {
        "name": "Zulip",
        "url": ""
      }
    ],
    "description": "Zulip is open-source team chat organised into channels and topics, from Kandra Labs, hosted as Zulip Cloud or self-hosted. Agents reach it through a REST API with bot accounts, an events queue and Python and JavaScript client libraries.",
    "facts": [
      "rank #422 of 842",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Zulip",
    "image": "https://www.anchorterminal.com/assets/og/tools-zulip.png",
    "path": "/tools/zulip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Zulip review for AI agents, grade C (61.5/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/zulip"
  },
  "tokens": {
    "markdown": 7400,
    "slim": 1780
  },
  "version": 1
}
