{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "alation",
    "name": "Alation",
    "vendor": "Alation, Inc.",
    "vendorUrl": "https://www.alation.com",
    "kind": "http-api",
    "category": "company-knowledge",
    "summary": "Alation is a hosted data catalogue for tables, queries, BI reports, lineage and data quality. Agents reach it through REST APIs, a natural-language Aggregated Context API, a Python agent SDK and an MCP server on each cloud instance.",
    "url": "https://www.anchorterminal.com/tools/alation",
    "markdownUrl": "https://www.anchorterminal.com/tools/alation.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/alation.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/alation.json",
    "repo": "https://github.com/Alation/alation-ai-agent-sdk",
    "license": "Proprietary service under Alation's Master Cloud Software Licence and Services Agreement. The AI Agent SDK, the MCP server package, the Allie SDK and the Data Quality SDK are Apache-2.0",
    "transports": [
      "http",
      "streamable-http",
      "stdio"
    ],
    "packages": [
      {
        "registry": "pypi",
        "name": "alation-ai-agent-mcp"
      },
      {
        "registry": "pypi",
        "name": "alation-ai-agent-sdk"
      },
      {
        "registry": "pypi",
        "name": "allie-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access is granted inside a customer's Alation instance. On Alation Cloud Service a Server Admin registers an OAuth client application, which creates a system user with one Alation role, and the client exchanges its ID and secret for a JWT sent as a Bearer token. An authorisation code flow with refresh tokens covers user sign-in, and the remote MCP server needs a client that accepts a `client_id` and `client_secret`, since dynamic client registration is not supported. Any signed-in user can also create an API key pair, a refresh token (60 days by default) and an access token (24 hours) sent in a `TOKEN` header. Permissions follow the user's role, as listed in the APIs by Roles table.",
    "pricing": "paid",
    "pricingNotes": "No prices are published. www.alation.com/pricing redirects to a form for a sales call, and we found no trial or self-serve sign-up. Each cloud tenant gets a one-time allowance of 2,000 Aggregated Context API calls, with 429 responses from 2,400 calls until a paid tier is bought through the account manager (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer portal, the agent SDK source or the legal pages (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 16,
    "popularity": {
      "githubStars": 19,
      "npmWeekly": null,
      "pypiWeekly": 2087,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.alation.com/",
    "capabilities": [
      "data.catalogue",
      "knowledge.search",
      "data.lineage",
      "db.sql"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "enterprise",
      "official",
      "mcp",
      "oauth",
      "openapi",
      "python",
      "sales-led",
      "status-page",
      "sla",
      "soc2"
    ],
    "lastRelease": "2026-10-03",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.3,
      "grade": "C",
      "agentReady": false,
      "rank": 472,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 71,
        "maintenance": 71,
        "payments": 0,
        "reliability": 61,
        "schema": 78,
        "security": 63,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 61,
          "points": 12.2,
          "reason": "Hosted service, read on the hosted lines and graded on what an agent uses, the Alation Cloud Service REST APIs and the MCP server. A Statuspage at status.alationcloud.com with production and development components for nine regions (20). The history page lists four incidents between 10 August and 10 September 2026. US-East-1 lost connectivity for 2 hours 26 minutes on 10 September (marked critical), eu-west-1 was disrupted for 65 minutes on 10 August (major), a subset of customers had degraded availability for 56 minutes on 18 August (major), and Sydney was down for 19 minutes on 20 August (critical). Each was regional, and two ran over an hour. July was not on the page we read (5 of 30). The AI API has a two-tier token bucket with no numbers published. REST throttling is off by default and, when enabled, defaults to 20 requests a second for each API family. The Aggregated Context API has a one-time quota of 2,000 calls with enforcement at 2,400 (10 of 15). AI API 429s carry `Retry-After` and three `Ai-RateLimit` headers, REST 429s state the seconds to wait, and the SDK marks 429 and 500 as retryable. No idempotency keys were found (10 of 15). The MSA sets a 99.5 per cent monthly uptime target with service credits of 1 to 5 per cent (10). The Aggregated Context API has been generally available since 2025.1.5. The AI API page calls itself new and under highly active development, and the SDK and local MCP server are at 1.0.0rc3 (6 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Every API has an OpenAPI 3.0 definition, printed in the Markdown copy of each reference page and served by each instance under `/openapi/`. We found no single public file to download. The local MCP server's tools take typed parameters through FastMCP (22 of 25). No llms.txt on developer.alation.com, www.alation.com or docs.alation.com, but the developer portal serves a Markdown copy of each page at the same address with `.md` (6 of 10). MCP tool descriptions name use cases, counter-examples and the tool to call instead, and the API reference states purpose and availability for each operation (16 of 20). The `signature` parameter is a free-form JSON object, search `filters` is a JSON string, and the agent tools take one natural-language `message` (9 of 15). A table of six-digit error codes, request and response examples and recipes. The portal warns that its code generator builds a wrong URL for `filters` (13 of 15). Reference pages are versioned from v2024.1 to v2026.9.0-1 and paths carry v1 or v2, but the API release notes page we read holds only the 2026.7.2.0 entry (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "The local MCP server registers 16 tools and enables 8 by default, with `--enabled-tools` and `--disabled-tools` lists, and the README says the remote server lists only the tools the current user may call. Descriptions are long. On the Aggregated Context API a signature selects object types and fields, and field caps hold a table to its top 50 columns (22 of 25). REST paging uses `limit` and `skip` with an `X-Next-Page` header and a 1,000-object cap, and the AI API uses `limit` and `offset` up to 1,000. Parameter names differ between API families (17 of 20). Six-digit error codes with a published table, and the SDK returns `reason`, `resolution_hint`, `is_retryable` and `help_links` (17 of 20). No idempotency keys in the docs and no `readOnlyHint` or `destructiveHint` in the MCP source. Bulk writes run as jobs with a status endpoint (6 of 20). The catalogue search agent needs one parameter. The official SDKs (`alation-ai-agent-sdk`, `allie-sdk`, `alation-data-quality-sdk`) are all Python (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 63,
          "points": 11.03,
          "reason": "OAuth 2.0 client credentials on Alation Cloud Service. A Server Admin registers a client application, which creates a system user with one Alation role, and the admin can set token duration, revoke tokens, rotate the secret and rotate the signing key. An authorisation code flow with refresh tokens exists for user sign-in, without dynamic client registration. API keys are a refresh token (60 days) and an access token (24 hours) sent in a `TOKEN` header, revocable by an admin. Permissions follow roles, not scopes, and the refresh token endpoint takes a username and password (24 of 30). The APIs by Roles table maps each API to the roles that may call it, AI SQL execution allows reads only, and tools can be disabled. No confirmation step for writes was found (13 of 20). Tools return descriptions, documents and query text written by catalogue users, and we found no prompt-injection guidance (3 of 15). A Logging API, an API usage log, and SDK tool events sent to the customer's instance with tool name, parameters, duration and status. The source says parameters are not redacted (10 of 15). ISO 27001, 27701, 27017 and 27018, SOC 2 Type 2 with HIPAA, two penetration tests a year and a security@alation.com address. No security.txt, no bug bounty, and advisories need a Community login (13 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "Hosted service, so the hosted rubric applies. No x402, MPP or L402 (0). No published prices. www.alation.com/pricing redirects to a form for a 30-minute sales call (0). No free tier or trial for a new user. The 2,000 free Aggregated Context API calls are a one-time allowance inside a paying tenant (0). An agent needs a customer's Server Admin to register an OAuth client, or a user to create a token, after a sales contract (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "reason": "The status page shows the 2026.9.1.0 upgrade reaching US instances on 3 October 2026 (30). Upgrades to 2026.7.2, 2026.8.0, 2026.9.0 and 2026.9.1 appear between 1 August and 3 October (20). Closed service, scored on the 15-point scale. API release notes and a support policy with response targets by severity. On GitHub the agent SDK has two open issues, one from 10 September 2026 asking when 1.0 will ship and a bug from 7 November 2025 (8 of 15). `alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, `allie-sdk` 2.2.3 on 25 May 2026 and `alation-data-quality-sdk` 1.0.7 on 14 May 2026. No entry in the official MCP registry (6 of 15). The SDK repository runs Renovate and test workflows with actions pinned to commit SHAs, and its last commit is dated 4 August 2026 (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 65, provenance 86",
          "reason": "Closed service under the published Master Cloud Software Licence and Services Agreement of 10 April 2026. The agent SDK and MCP server are Apache-2.0 (15 of 30). The MSA deletes customer data within 30 days of termination, the Data Privacy Addendum promises breach notice without undue delay, and the AI Acceptable Use Policy bars training on customer data while keeping anonymised usage data and derived learnings. The Aggregated Context API guide says content is not shared with external model providers and also says the question and signature go to a language model routed through Amazon Bedrock (22 of 30). An end-of-support matrix for versions and connectors. The SDK gave three months' notice for removing `alation_context` in February 2026, and the tool was still in the source in August. No API deprecation policy with periods was found (10 of 20). A sub-processor list with locations, 30 days' notice of additions, and a table of model routing regions (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The local MCP server registers 16 tools and enables 8 by default, with `--enabled-tools` and `--disabled-tools` lists, and the README says the remote server lists only the tools the current user may call. Descriptions are long. On the Aggregated Context API a signature selects object types and fields, and field caps hold a table to its top 50 columns (22 of 25). REST paging uses `limit` and `skip` with an `X-Next-Page` header and a 1,000-object cap, and the AI API uses `limit` and `offset` up to 1,000. Parameter names differ between API families (17 of 20). Six-digit error codes with a published table, and the SDK returns `reason`, `resolution_hint`, `is_retryable` and `help_links` (17 of 20). No idempotency keys in the docs and no `readOnlyHint` or `destructiveHint` in the MCP source. Bulk writes run as jobs with a status endpoint (6 of 20). The catalogue search agent needs one parameter. The official SDKs (`alation-ai-agent-sdk`, `allie-sdk`, `alation-data-quality-sdk`) are all Python (9 of 15).",
          "maintenance": "The status page shows the 2026.9.1.0 upgrade reaching US instances on 3 October 2026 (30). Upgrades to 2026.7.2, 2026.8.0, 2026.9.0 and 2026.9.1 appear between 1 August and 3 October (20). Closed service, scored on the 15-point scale. API release notes and a support policy with response targets by severity. On GitHub the agent SDK has two open issues, one from 10 September 2026 asking when 1.0 will ship and a bug from 7 November 2025 (8 of 15). `alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, `allie-sdk` 2.2.3 on 25 May 2026 and `alation-data-quality-sdk` 1.0.7 on 14 May 2026. No entry in the official MCP registry (6 of 15). The SDK repository runs Renovate and test workflows with actions pinned to commit SHAs, and its last commit is dated 4 August 2026 (7 of 10).",
          "payments": "Hosted service, so the hosted rubric applies. No x402, MPP or L402 (0). No published prices. www.alation.com/pricing redirects to a form for a 30-minute sales call (0). No free tier or trial for a new user. The 2,000 free Aggregated Context API calls are a one-time allowance inside a paying tenant (0). An agent needs a customer's Server Admin to register an OAuth client, or a user to create a token, after a sales contract (0).",
          "reliability": "Hosted service, read on the hosted lines and graded on what an agent uses, the Alation Cloud Service REST APIs and the MCP server. A Statuspage at status.alationcloud.com with production and development components for nine regions (20). The history page lists four incidents between 10 August and 10 September 2026. US-East-1 lost connectivity for 2 hours 26 minutes on 10 September (marked critical), eu-west-1 was disrupted for 65 minutes on 10 August (major), a subset of customers had degraded availability for 56 minutes on 18 August (major), and Sydney was down for 19 minutes on 20 August (critical). Each was regional, and two ran over an hour. July was not on the page we read (5 of 30). The AI API has a two-tier token bucket with no numbers published. REST throttling is off by default and, when enabled, defaults to 20 requests a second for each API family. The Aggregated Context API has a one-time quota of 2,000 calls with enforcement at 2,400 (10 of 15). AI API 429s carry `Retry-After` and three `Ai-RateLimit` headers, REST 429s state the seconds to wait, and the SDK marks 429 and 500 as retryable. No idempotency keys were found (10 of 15). The MSA sets a 99.5 per cent monthly uptime target with service credits of 1 to 5 per cent (10). The Aggregated Context API has been generally available since 2025.1.5. The AI API page calls itself new and under highly active development, and the SDK and local MCP server are at 1.0.0rc3 (6 of 10).",
          "schema": "Every API has an OpenAPI 3.0 definition, printed in the Markdown copy of each reference page and served by each instance under `/openapi/`. We found no single public file to download. The local MCP server's tools take typed parameters through FastMCP (22 of 25). No llms.txt on developer.alation.com, www.alation.com or docs.alation.com, but the developer portal serves a Markdown copy of each page at the same address with `.md` (6 of 10). MCP tool descriptions name use cases, counter-examples and the tool to call instead, and the API reference states purpose and availability for each operation (16 of 20). The `signature` parameter is a free-form JSON object, search `filters` is a JSON string, and the agent tools take one natural-language `message` (9 of 15). A table of six-digit error codes, request and response examples and recipes. The portal warns that its code generator builds a wrong URL for `filters` (13 of 15). Reference pages are versioned from v2024.1 to v2026.9.0-1 and paths carry v1 or v2, but the API release notes page we read holds only the 2026.7.2.0 entry (12 of 15).",
          "security": "OAuth 2.0 client credentials on Alation Cloud Service. A Server Admin registers a client application, which creates a system user with one Alation role, and the admin can set token duration, revoke tokens, rotate the secret and rotate the signing key. An authorisation code flow with refresh tokens exists for user sign-in, without dynamic client registration. API keys are a refresh token (60 days) and an access token (24 hours) sent in a `TOKEN` header, revocable by an admin. Permissions follow roles, not scopes, and the refresh token endpoint takes a username and password (24 of 30). The APIs by Roles table maps each API to the roles that may call it, AI SQL execution allows reads only, and tools can be disabled. No confirmation step for writes was found (13 of 20). Tools return descriptions, documents and query text written by catalogue users, and we found no prompt-injection guidance (3 of 15). A Logging API, an API usage log, and SDK tool events sent to the customer's instance with tool name, parameters, duration and status. The source says parameters are not redacted (10 of 15). ISO 27001, 27701, 27017 and 27018, SOC 2 Type 2 with HIPAA, two penetration tests a year and a security@alation.com address. No security.txt, no bug bounty, and advisories need a Community login (13 of 20).",
          "transparency": "Closed service under the published Master Cloud Software Licence and Services Agreement of 10 April 2026. The agent SDK and MCP server are Apache-2.0 (15 of 30). The MSA deletes customer data within 30 days of termination, the Data Privacy Addendum promises breach notice without undue delay, and the AI Acceptable Use Policy bars training on customer data while keeping anonymised usage data and derived learnings. The Aggregated Context API guide says content is not shared with external model providers and also says the question and signature go to a language model routed through Amazon Bedrock (22 of 30). An end-of-support matrix for versions and connectors. The SDK gave three months' notice for removing `alation_context` in February 2026, and the tool was still in the source in August. No API deprecation policy with periods was found (10 of 20). A sub-processor list with locations, 30 days' notice of additions, and a table of model routing regions (18 of 20)."
        },
        "sources": [
          {
            "what": "developer portal home",
            "url": "https://developer.alation.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "API authentication guide",
            "url": "https://developer.alation.com/dev/docs/authentication-into-alation-apis",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth 2.0 client applications",
            "url": "https://docs.alation.com/en/latest/admins/AlationAPIs/AuthenticateAPICallsWithOAuth20.html",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth user authorisation endpoints",
            "url": "https://developer.alation.com/dev/reference/oauth-user-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Aggregated Context API guide, quota, privacy and regions",
            "url": "https://developer.alation.com/dev/docs/guide-to-aggregated-context-api-beta",
            "seen": "2026-10-08"
          },
          {
            "what": "Aggregated Context API reference with OpenAPI definition",
            "url": "https://developer.alation.com/dev/reference/getaggregatedcontext",
            "seen": "2026-10-08"
          },
          {
            "what": "Alation AI API overview, throttling and pagination",
            "url": "https://developer.alation.com/dev/reference/alation-ai-api-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "API throttling guide",
            "url": "https://developer.alation.com/dev/docs/api-throttling",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination guide",
            "url": "https://developer.alation.com/dev/docs/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI index",
            "url": "https://developer.alation.com/dev/docs/open-api-index",
            "seen": "2026-10-08"
          },
          {
            "what": "API error codes",
            "url": "https://developer.alation.com/dev/docs/api-error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "API release notes",
            "url": "https://developer.alation.com/dev/docs/running-api-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "AI Agent SDK repository, README, guides and source",
            "url": "https://github.com/Alation/alation-ai-agent-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "AI Agent SDK issues",
            "url": "https://github.com/Alation/alation-ai-agent-sdk/issues?q=is%3Aissue",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI alation-ai-agent-mcp",
            "url": "https://pypi.org/project/alation-ai-agent-mcp/",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI allie-sdk",
            "url": "https://pypi.org/project/allie-sdk/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.alationcloud.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.alationcloud.com/history",
            "seen": "2026-10-08"
          },
          {
            "what": "status page documentation",
            "url": "https://docs.alation.com/en/latest/cloud/StatusPage/index.html",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing address, which redirects to a sales form",
            "url": "https://www.alation.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Cloud Software Licence and Services Agreement with SLA",
            "url": "https://www.alation.com/legal/msa/",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Privacy Addendum",
            "url": "https://www.alation.com/legal/online-dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processor list",
            "url": "https://www.alation.com/legal/subprocessors/",
            "seen": "2026-10-08"
          },
          {
            "what": "AI Acceptable Use Policy",
            "url": "https://www.alation.com/legal/alation-ai-acceptable-use-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.alation.com/legal/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.alation.com/legal/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "support policy",
            "url": "https://www.alation.com/legal/support/",
            "seen": "2026-10-08"
          },
          {
            "what": "security notices index",
            "url": "https://docs.alation.com/en/latest/releases/fieldnotices/index.html",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=alation",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/alation.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the Alation Cloud Service documentation that moved to the Help Centre on 18 August 2026. help.alation.com showed our reader an error page, so the remote MCP server's set-up, its tool list and any audit log pages went unread.",
          "unchecked: the remote MCP server's tool schemas and annotations at `https://\u003cinstance\u003e/ai/mcp`, which need a customer instance.",
          "unchecked: status history before August 2026. The history page we read listed August, September and October, and robots.txt on status.alationcloud.com disallows the JSON API.",
          "unchecked: numeric limits for the AI API's two token-bucket tiers. The docs name the tiers and headers without numbers.",
          "unchecked: security advisories since March 2024, which sit behind an Alation Community login, and the SOC 2 and ISO documents, which go through a sales representative.",
          "unchecked: comment counts and reply dates on the two open GitHub issues.",
          "The API release notes page we read holds one entry, 2026.7.2.0 (updated 30 July 2026), while the portal's version menu runs to v2026.9.0-1. Later API notes were not found.",
          "The agent SDK README said in December 2025 that `alation_context` would be removed in February 2026. It was still in the source on 4 August 2026.",
          "firstReleased is left empty. The agent SDK first reached PyPI on 2 May 2025, and we did not establish the catalogue's own launch date.",
          "popularity.pypiWeekly is `allie-sdk` (2,087). `alation-ai-agent-sdk` had 113 downloads in the week and `alation-ai-agent-mcp` 93."
        ]
      },
      "negative": 0,
      "verdict": "Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.",
      "bestFor": "A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.",
      "strengths": [
        "OpenAPI 3.0 definitions for each API, shown on every reference page and served by each instance under `/openapi/`",
        "OAuth 2.0 client credentials tied to a system user with one Alation role, with token revocation, secret rotation and offline JWT verification",
        "The AI API answers 429 with `Retry-After` and three `Ai-RateLimit` headers, and the REST 429 body states the seconds to wait",
        "The local MCP server enables 8 of its 16 tools by default, with allow and deny lists, and the remote server lists only tools the user may call",
        "A 99.5 per cent monthly uptime target with service credits of 1 to 5 per cent in the published MSA"
      ],
      "weaknesses": [
        "No published price, trial or self-serve sign-up. The pricing address redirects to a sales form",
        "Four incidents between 10 August and 10 September 2026, two of them regional outages longer than an hour",
        "`alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, and a plain `pip install` still resolves to 0.12.0",
        "No guidance on prompt injection, although tools return catalogue descriptions, documents and query text written by users",
        "No `security.txt` and no bug bounty, and security advisories sit behind a Community login"
      ],
      "agentNotes": [
        "Ask a Server Admin to register an OAuth client application with the lowest role that fits. Only admins can create one, and the secret is shown once",
        "Pin `alation-ai-agent-mcp==1.0.0rc3`. An unpinned install resolves to 0.12.0, which predates the catalogue search agent",
        "Call `catalog_context_search_agent` for catalogue questions. `alation_context` is deprecated and its description tells models not to call it directly",
        "Watch `X-Entitlement-Usage` on Aggregated Context API responses. The 2,000 free calls never reset, and a quota 429 is not retryable",
        "Page with `limit` and `skip` and follow `X-Next-Page`. The BI Source API uses `offset`, and one call returns at most 1,000 objects"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.3
        }
      ],
      "editorialScores": {
        "ergonomics": 71,
        "maintenance": 71,
        "payments": 0,
        "reliability": 61,
        "schema": 78,
        "security": 63,
        "transparency": 65
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "uv pip install alation-ai-agent-mcp==1.0.0rc3",
      "config": {
        "mcpServers": {
          "alation": {
            "args": [
              "--from",
              "alation-ai-agent-mcp",
              "start-alation-mcp-server"
            ],
            "command": "uvx",
            "env": {
              "ALATION_AUTH_METHOD": "service_account",
              "ALATION_BASE_URL": "https://your-alation-instance.com",
              "ALATION_CLIENT_ID": "your-client-id",
              "ALATION_CLIENT_SECRET": "your-client-secret"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/data.catalogue",
      "tool": "https://letme.dev/alation"
    },
    "notable": [
      "The Aggregated Context API takes a natural-language question and returns matching schemas, tables, columns, documents, queries and BI objects, with a signature to choose object types and fields (https://developer.alation.com/dev/docs/guide-to-aggregated-context-api-beta)",
      "A remote MCP server answers on each cloud instance at `https://\u003cyour_instance\u003e/ai/mcp` and lists tools per user. It does not support dynamic client registration (https://github.com/Alation/alation-ai-agent-sdk)",
      "The local MCP server registers 16 tools and enables 8 by default, among them `catalog_context_search_agent`, `query_flow_agent` and `sql_query_agent` (https://github.com/Alation/alation-ai-agent-sdk/blob/main/python/dist-mcp/alation_ai_agent_mcp/register_tools.py)",
      "`alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3. PyPI still lists 0.12.0 of 9 October 2025 as the latest stable version (https://pypi.org/project/alation-ai-agent-mcp/)",
      "status.alationcloud.com lists four incidents between 10 August and 10 September 2026, the longest a 2 hour 26 minute loss of connectivity in US-East-1 (https://status.alationcloud.com/history)",
      "The MSA of 10 April 2026 sets a 99.5 per cent monthly uptime target with service credits of 1, 3 or 5 per cent of monthly fees (https://www.alation.com/legal/msa/)",
      "Since 18 August 2026 documentation for Alation Cloud Service lives in the Help Centre, and docs.alation.com covers customer-managed deployments (https://docs.alation.com/en/latest/)",
      "The SDK posts a tool event to the customer's own instance after each call, with the tool name, parameters, duration and status. The source says parameters are not redacted (https://github.com/Alation/alation-ai-agent-sdk/blob/main/python/core-sdk/alation_ai_agent_sdk/event.py)"
    ],
    "area": "business",
    "details": [
      {
        "label": "APIs",
        "value": "REST APIs under `/integration/v1` and `/integration/v2` for data sources, schemas, tables, columns, BI objects, lineage, documents, custom fields, search and data quality, the Aggregated Context API at `/integration/v2/context/`, and the Alation AI API under `/ai/api/v1`. About 380 reference pages on developer.alation.com"
      },
      {
        "label": "MCP server",
        "value": "Remote at `https://\u003cyour_instance\u003e/ai/mcp` on cloud instances, with tools listed per user. Local package `alation-ai-agent-mcp` over stdio or HTTP, 16 tools with 8 enabled by default, Python 3.10 or later"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 client credentials (JWT Bearer, one role per client, revocable, rotatable secret), authorisation code flow with refresh tokens, or API keys in a `TOKEN` header (refresh token 60 days, access token 24 hours by default)"
      },
      {
        "label": "Rate limits",
        "value": "AI API uses a two-tier token bucket with no numbers published. REST throttling is off by default and defaults to 20 requests a second for each API family when enabled, 100 a minute for document and folder writes. Aggregated Context API has a one-time quota of 2,000 calls"
      },
      {
        "label": "Errors",
        "value": "Six-digit codes such as 429000 with a published table. AI API 429s carry `Retry-After`, `Ai-RateLimit-Limit`, `Ai-RateLimit-Remaining` and `Ai-RateLimit-Tier`"
      },
      {
        "label": "Pagination",
        "value": "`limit` and `skip` with an `X-Next-Page` response header, 100 objects by default and 1,000 at most. The BI Source API uses `offset`, and the AI API uses `limit` and `offset`"
      },
      {
        "label": "Pricing",
        "value": "Sales contract only. No published price, trial or self-serve sign-up found"
      },
      {
        "label": "SLA and support",
        "value": "99.5 per cent monthly uptime target with service credits of 1 to 5 per cent. Standard support answers a P1 within 4 hours, Mission Critical support within 1 hour, 24x7 for P1 and P2"
      },
      {
        "label": "SDKs",
        "value": "`alation-ai-agent-sdk`, `alation-ai-agent-mcp` and `alation-ai-agent-langchain` 1.0.0rc3 (14 January 2026), `allie-sdk` 2.2.3 (25 May 2026), `alation-data-quality-sdk` 1.0.7 (14 May 2026), all Python and Apache-2.0"
      },
      {
        "label": "Hosting",
        "value": "Alation Cloud Service on AWS in nine regions across the Americas, Canada, EMEA and APAC, with instances on alationcloud.com. Model calls for the Aggregated Context API route through Amazon Bedrock inference profiles within a region group"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001, ISO 27701, ISO 27017, ISO 27018, SOC 2 Type 2 covering HIPAA and HITECH, per the security page dated July 2026. FedRAMP Moderate is being pursued"
      },
      {
        "label": "Status",
        "value": "status.alationcloud.com on Atlassian Statuspage, with production and development components by region, plus a private status page for each customer"
      }
    ],
    "provenance": {
      "legalEntity": "Alation, Inc.",
      "domain": "alation.com",
      "domainRegistered": "1998-07-27",
      "endpointOnVendorDomain": true,
      "terms": "https://www.alation.com/legal/msa/",
      "privacy": "https://www.alation.com/legal/privacy-policy/",
      "statusPage": "https://status.alationcloud.com",
      "changelog": "https://developer.alation.com/dev/docs/running-api-release-notes",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The MSA (version 10 April 2026) and the privacy policy (version 23 September 2026) name Alation, Inc., 3 Lagoon Drive, Suite 300, Redwood City, CA 94065. The MSA is governed by Delaware law, or by the law of England and Wales for customers in the UK, EEA and Switzerland.",
        "Cloud instances and the status page are on alationcloud.com, a second domain of the vendor's. The agent SDK's guides give `your-instance.alationcloud.com` as the instance host.",
        "www.alation.com/.well-known/security.txt returns 404. The security page sends reports to security@alation.com.",
        "The privacy policy covers Alation websites and other Alation services. Customer personal data in the product is governed by the Data Privacy Addendum of 10 April 2026 at https://www.alation.com/legal/online-dpa/.",
        "RDAP gives alation.com a registration date of 1998-07-27. We did not establish when Alation acquired the domain."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Alation, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "alation.com, registered 1998-07-27 (28 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "alation.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.alationcloud.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.alation.com/legal/msa/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 7663,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "a) General provision: The Agreement is governed by and construed under the laws of the State of Delaware without reference to conflict of laws principles.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Each Party’s total liability (including attorneys’ fees) arising out of or related to the Agreement will not exceed the amount paid by Customer to Alation under the Agreement during the twelve (12) month period prior to the date the claim arose.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The Agreement will start on the Effective Date and will continue until terminated pursuant to sections 5.2, 8.3(d) or 10.8 below."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "and (ii) Customer shall not, and shall ensure that Named Users do not, violate any export embargo, prohibition, restrictions or other similar law in connection with the Agreement."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Alation will use commercially reasonable efforts to make Alation Cloud available with a target uptime of 99.5% during each calendar month for all production environments that have been paid for (“Target Availability”).",
              "says": "Names 99.5% availability"
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "iii. develop or operate products or services to compete with it or allow access to it by any competitor of Alation or any unauthorized persons;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Alation may reference the customer's name, branding and logo in its marketing materials and sales presentations, and the clause states no consent requirement.",
              "quote": "10.7 Publicity. Alation may reference Customer’s name, branding, and logo in Alation’s marketing materials and as part of its sales presentations to other potential customers."
            },
            {
              "date": "2026-10-08",
              "text": "Customer Data and service accounts are permanently deleted within thirty calendar days of the agreement expiring or ending.",
              "quote": "(d) all Customer Data and any associated service accounts provisioned by Alation to Customer will be permanently deleted within thirty (30) calendar days from the effective date of expiration or termination"
            },
            {
              "date": "2026-10-08",
              "text": "Each Named User identification is tied to one individual and cannot be shared, and a Named User is defined as a customer employee or contractor with a unique email address.",
              "quote": "Unless as otherwise set out in an Order, Each individual will be assigned a unique Named User identification that cannot be shared or used by more than one individual."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.alation.com/legal/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 4197,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy applies to information we collect and use about you when you access or use an Alation website or other online or offline Alation services."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We keep your information for no longer than necessary for the purposes for which it is processed."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "As discussed further below, we and our service providers (which are third-party companies that work on our behalf), may use various technologies, including cookies and similar tools, to assist in collecting this information."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Notice of Right to Opt-Out of Sales of Personal Information and Sharing/Processing of Personal Information for Targeted Advertising Purposes"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You can also opt out of certain online advertising activities by following the instructions in the \"Your Rights and Choices\" section below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You can reach us via email, at privacy@alation.com, or by mail at 3 Lagoon Drive, Suite 300, Redwood City, CA 94065.",
              "says": "privacy@alation.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "These measures may include signing Standard Contractual Clauses (SCCs) in accordance with EU and other data protection laws to govern the transfers of such data.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "The disclosure of your information to these third parties to assist us in providing these services may be considered a “sale” of personal information under applicable law or the processing/sharing of personal information for targeted advertising purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Alation says it may use artificial intelligence and large language models to assist in processing personal information for the purposes the policy lists.",
              "quote": "Note that we may use artificial intelligence and large language models and tools to assist us in processing your information for these purposes."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/alation.json",
    "live": {
      "slug": "alation",
      "vendorStatus": {
        "page": "https://status.alationcloud.com",
        "indicator": "maintenance",
        "summary": "Service Under Maintenance",
        "checkedAt": "2026-10-09T10:10:42.354355559Z"
      },
      "updatedAt": "2026-10-09T10:10:42.354355559Z"
    }
  }
}
