{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "arcgis",
    "name": "ArcGIS Location Platform",
    "vendor": "Esri",
    "vendorUrl": "https://location.arcgis.com",
    "kind": "http-api",
    "category": "maps",
    "summary": "Esri's pay-as-you-go location services for developers. REST APIs cover geocoding, reverse and batch geocoding, place search, routing, basemap tiles, static maps, elevation and demographic enrichment, with an Esri-hosted MCP server in beta.",
    "url": "https://www.anchorterminal.com/tools/arcgis",
    "markdownUrl": "https://www.anchorterminal.com/tools/arcgis.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/arcgis.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/arcgis.json",
    "repo": "https://github.com/Esri/arcgis-rest-js",
    "license": "Proprietary service under the ArcGIS Location Platform Agreement. The ArcGIS REST JS client library is Apache-2.0",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://geocode-api.arcgis.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@esri/arcgis-rest-geocoding"
      },
      {
        "registry": "npm",
        "name": "@esri/arcgis-rest-request"
      },
      {
        "registry": "pypi",
        "name": "arcgis"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. A free ArcGIS Location Platform account created in a browser issues API key credentials with selected privileges, an expiry date of up to one year, optional referrer limits and two tokens for rotation. OAuth 2.0 user authentication and app authentication (client ID and secret, short-lived tokens) are also supported. Requests take the token as a `token` parameter or in an `X-Esri-Authorization` or `Authorization` header. Accounts are for one person and may not be shared.",
    "pricing": "freemium",
    "pricingNotes": "Usage-based in US dollars with a monthly free tier and no contract. Free each month are 20,000 unstored geocodes, 20,000 routes, 500 place searches, 2 million basemap tiles, 1,000 static maps and 50,000 elevation points. A payment method (card, purchase order or voucher) is needed only to turn on pay-as-you-go, which services without a free tier, among them stored geocodes, require. The sign-up form is drawn by script and we couldn't read whether it asks for a card.",
    "priceSummary": "$0.50 / 1k req",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 on the pricing page, the billing help or the REST and MCP documentation (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 8,
    "popularity": {
      "githubStars": 392,
      "npmWeekly": 65286,
      "pypiWeekly": 32974,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.arcgis.com/rest/location-based-services/",
    "capabilities": [
      "geo.geocode",
      "geo.reverse",
      "geo.places",
      "geo.routing",
      "geo.tiles"
    ],
    "tags": [
      "hosted",
      "maps",
      "geocoding",
      "routing",
      "places",
      "api-key",
      "oauth",
      "mcp",
      "beta-mcp",
      "free-tier",
      "usage-priced",
      "sla",
      "status-page",
      "typescript",
      "python"
    ],
    "lastRelease": "2026-09-29",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 65.4,
      "grade": "B",
      "agentReady": false,
      "rank": 259,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 83,
        "payments": 40,
        "reliability": 65,
        "schema": 61,
        "security": 64,
        "transparency": 72
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Graded as a hosted service on the REST location services, which are generally available. Esri runs its own status page at status.location.arcgis.com with current status and an event history (20). The history is drawn by script, so we read the RSS feed the page links. Its newest entry is an intermittent basemap tile slowdown on 16 June 2026, outside the 90 days to 8 October, so we gave 25 of 30 and held back 5 because the feed's depth is unknown. No request rate limits with numbers were found in the geocoding, places or routing reference (0). No 429 or backoff guidance was found. The geocoding output page says only that a timeout after 60 seconds may be retried later (0). The SLA of 23 December 2025 commits to 99.9 per cent monthly uptime for ten services (10). The REST services are generally available, and the MCP server is a beta (10). Total 65."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 61,
          "points": 9.91,
          "reason": "No OpenAPI description was found for geocoding, places or routing. The geocoding service description at `GeocodeServer?f=pjson` lists each parameter with its type, allowed values and supported operations, which earns 8 of 25. `/llms.txt` returns 404 on developers.arcgis.com and location.arcgis.com (0). The reference explains when to use a direct request or a job, and stored or unstored geocoding (16 of 20). Parameters carry types, defaults, allowed values and maximums, such as `maxLocations` up to 50 and `pageSize` up to 20 (12 of 15). Each operation has request and response examples, and the geocoding output page lists error codes with extended codes and causes (13 of 15). Geocoding has dated release notes back to 2023 and the platform has release notes by month, but the geocoding path carries no version while places uses `/v1` (12 of 15). Total 61."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Responses can be sized with `outFields` and `maxLocations` on geocoding and `pageSize` on places (20 of 25). Places pages with `pageSize` and `offset` and filters by category and text, and geocoding filters by extent, country and category (18 of 20). Errors are a JSON object with `code`, `message` and `details`, with documented causes for 400, 403, 498 and 499 (15 of 20). The geocoding, places and routing calls are reads, so retries are safe, but no retry guidance was found and we didn't read the MCP tools' annotations (10 of 20). A geocode needs `f`, a token and an address, and Esri publishes ArcGIS REST JS and the ArcGIS API for Python (15). Total 78."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 64,
          "points": 11.2,
          "reason": "API key credentials carry selected privileges, an expiry date of at most one year, optional referrer limits and two tokens for rotation, and OAuth 2.0 user and app authentication are supported, which earns 30. Less 10 because the documented examples send the token as a `token` request parameter, although headers are accepted and recommended (20). Privileges are chosen per key, down to stored or unstored geocoding and simple or optimised routing, and the MCP server filters tools by them (16 of 20). Results include place names and addresses from third-party data, and no prompt-injection guidance was found (5 of 15). The dashboard shows usage by service and by credential per day, with no per-call log found (10 of 15). The trust centre has a coordinated disclosure programme with a safe harbour statement and a PGP key, and says Online Services are covered by FedRAMP moderate and ISO 27001, without naming ArcGIS Location Platform. No security.txt and no bug bounty were found (13 of 20). Total 64."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Unit prices for every service are public without a login (20). A monthly free tier of 20,000 geocodes, 20,000 routes and 500 place searches, and the billing help says a payment method is needed only to turn on pay-as-you-go. The sign-up form is drawn by script and we couldn't read it, so the no-card reading rests on the billing help (20). An account is created by a person in a browser (0). Total 40."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "The latest dated change is MCP server 1.0.0-beta.1.7 on 29 September 2026, and the geocoding service has release notes for September 2026 (30). Dated entries in the last 90 days include MCP releases on 27 July, 10 August, 1, 15 and 29 September, and ArcGIS REST JS 4.11.0 on 7 August (20). Public release notes and the Esri Community forum exist, technical support is a paid extra, and we didn't read reply times. The ArcGIS REST JS repository shows 60 open issues and a push on 24 September 2026 (10 of 15). Official SDKs are current, ArcGIS REST JS 4.11.0 and `arcgis` 2.4.3 of 21 April 2026 (15). The JS repository has pull-request test and release workflows, and we didn't check that they pass (8 of 10). Total 83."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "note": "editorial 54, provenance 89",
          "reason": "A closed service with a dated agreement that states what may be stored, cached and shared, and an Apache-2.0 client library (15 of 30). The privacy statement was revised on 31 July 2026, the Products \u0026 Services supplement on 9 September 2025 and the Data Processing Addendum on 12 March 2024. None states a retention period, and neither the supplement nor the addendum names ArcGIS Location Platform (14 of 30). The agreement promises 90 days' notice for deprecations, and the July 2026 release notes record the retirement of legacy API keys (16 of 20). The addendum names four sub-processors as examples and the GDPR page says information is stored in the United States, with no list specific to this product (9 of 20). Total 54."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses can be sized with `outFields` and `maxLocations` on geocoding and `pageSize` on places (20 of 25). Places pages with `pageSize` and `offset` and filters by category and text, and geocoding filters by extent, country and category (18 of 20). Errors are a JSON object with `code`, `message` and `details`, with documented causes for 400, 403, 498 and 499 (15 of 20). The geocoding, places and routing calls are reads, so retries are safe, but no retry guidance was found and we didn't read the MCP tools' annotations (10 of 20). A geocode needs `f`, a token and an address, and Esri publishes ArcGIS REST JS and the ArcGIS API for Python (15). Total 78.",
          "maintenance": "The latest dated change is MCP server 1.0.0-beta.1.7 on 29 September 2026, and the geocoding service has release notes for September 2026 (30). Dated entries in the last 90 days include MCP releases on 27 July, 10 August, 1, 15 and 29 September, and ArcGIS REST JS 4.11.0 on 7 August (20). Public release notes and the Esri Community forum exist, technical support is a paid extra, and we didn't read reply times. The ArcGIS REST JS repository shows 60 open issues and a push on 24 September 2026 (10 of 15). Official SDKs are current, ArcGIS REST JS 4.11.0 and `arcgis` 2.4.3 of 21 April 2026 (15). The JS repository has pull-request test and release workflows, and we didn't check that they pass (8 of 10). Total 83.",
          "payments": "No x402, MPP or L402 (0). Unit prices for every service are public without a login (20). A monthly free tier of 20,000 geocodes, 20,000 routes and 500 place searches, and the billing help says a payment method is needed only to turn on pay-as-you-go. The sign-up form is drawn by script and we couldn't read it, so the no-card reading rests on the billing help (20). An account is created by a person in a browser (0). Total 40.",
          "reliability": "Graded as a hosted service on the REST location services, which are generally available. Esri runs its own status page at status.location.arcgis.com with current status and an event history (20). The history is drawn by script, so we read the RSS feed the page links. Its newest entry is an intermittent basemap tile slowdown on 16 June 2026, outside the 90 days to 8 October, so we gave 25 of 30 and held back 5 because the feed's depth is unknown. No request rate limits with numbers were found in the geocoding, places or routing reference (0). No 429 or backoff guidance was found. The geocoding output page says only that a timeout after 60 seconds may be retried later (0). The SLA of 23 December 2025 commits to 99.9 per cent monthly uptime for ten services (10). The REST services are generally available, and the MCP server is a beta (10). Total 65.",
          "schema": "No OpenAPI description was found for geocoding, places or routing. The geocoding service description at `GeocodeServer?f=pjson` lists each parameter with its type, allowed values and supported operations, which earns 8 of 25. `/llms.txt` returns 404 on developers.arcgis.com and location.arcgis.com (0). The reference explains when to use a direct request or a job, and stored or unstored geocoding (16 of 20). Parameters carry types, defaults, allowed values and maximums, such as `maxLocations` up to 50 and `pageSize` up to 20 (12 of 15). Each operation has request and response examples, and the geocoding output page lists error codes with extended codes and causes (13 of 15). Geocoding has dated release notes back to 2023 and the platform has release notes by month, but the geocoding path carries no version while places uses `/v1` (12 of 15). Total 61.",
          "security": "API key credentials carry selected privileges, an expiry date of at most one year, optional referrer limits and two tokens for rotation, and OAuth 2.0 user and app authentication are supported, which earns 30. Less 10 because the documented examples send the token as a `token` request parameter, although headers are accepted and recommended (20). Privileges are chosen per key, down to stored or unstored geocoding and simple or optimised routing, and the MCP server filters tools by them (16 of 20). Results include place names and addresses from third-party data, and no prompt-injection guidance was found (5 of 15). The dashboard shows usage by service and by credential per day, with no per-call log found (10 of 15). The trust centre has a coordinated disclosure programme with a safe harbour statement and a PGP key, and says Online Services are covered by FedRAMP moderate and ISO 27001, without naming ArcGIS Location Platform. No security.txt and no bug bounty were found (13 of 20). Total 64.",
          "transparency": "A closed service with a dated agreement that states what may be stored, cached and shared, and an Apache-2.0 client library (15 of 30). The privacy statement was revised on 31 July 2026, the Products \u0026 Services supplement on 9 September 2025 and the Data Processing Addendum on 12 March 2024. None states a retention period, and neither the supplement nor the addendum names ArcGIS Location Platform (14 of 30). The agreement promises 90 days' notice for deprecations, and the July 2026 release notes record the retirement of legacy API keys (16 of 20). The addendum names four sub-processors as examples and the GDPR page says information is stored in the United States, with no list specific to this product (9 of 20). Total 54."
        },
        "sources": [
          {
            "what": "product home page",
            "url": "https://location.arcgis.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing and free tiers",
            "url": "https://location.arcgis.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "billing help, payment methods and pay-as-you-go",
            "url": "https://location.arcgis.com/help/billing/",
            "seen": "2026-10-08"
          },
          {
            "what": "service reliability and support",
            "url": "https://location.arcgis.com/help/service-reliability-and-support/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use index for the product",
            "url": "https://location.arcgis.com/help/terms-of-use/",
            "seen": "2026-10-08"
          },
          {
            "what": "ArcGIS Location Platform Agreement, revised 21 November 2025",
            "url": "https://www.esri.com/content/dam/esrisites/en-us/media/legal/platform/platform-legal.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA, 23 December 2025",
            "url": "https://www.esri.com/content/dam/esrisites/en-us/media/legal/referenced-files/service-level-agmt-arcgis-platform.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.location.arcgis.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status RSS feed",
            "url": "https://status.location.arcgis.com/admin/api/rss/all.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "account management, inactivity and individual use",
            "url": "https://location.arcgis.com/help/account-management/",
            "seen": "2026-10-08"
          },
          {
            "what": "developer credentials help",
            "url": "https://location.arcgis.com/help/developer-credentials/",
            "seen": "2026-10-08"
          },
          {
            "what": "usage monitoring help",
            "url": "https://location.arcgis.com/help/usage/",
            "seen": "2026-10-08"
          },
          {
            "what": "platform release notes, July 2026",
            "url": "https://location.arcgis.com/help/release-notes/2026-07/",
            "seen": "2026-10-08"
          },
          {
            "what": "location services REST index",
            "url": "https://developers.arcgis.com/rest/location-based-services/",
            "seen": "2026-10-08"
          },
          {
            "what": "geocoding service overview and prices",
            "url": "https://developers.arcgis.com/rest/geocode/",
            "seen": "2026-10-08"
          },
          {
            "what": "findAddressCandidates reference",
            "url": "https://developers.arcgis.com/rest/geocode/find-address-candidates/",
            "seen": "2026-10-08"
          },
          {
            "what": "geocoding request types and error handling",
            "url": "https://developers.arcgis.com/rest/geocode/service-requests/",
            "seen": "2026-10-08"
          },
          {
            "what": "geocoding service output and error codes",
            "url": "https://developers.arcgis.com/rest/geocode/service-output/",
            "seen": "2026-10-08"
          },
          {
            "what": "geocoding release notes",
            "url": "https://developers.arcgis.com/rest/geocode/whats-new-world-geocoding-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "geocoding service description",
            "url": "https://geocode.arcgis.com/arcgis/rest/services/World/GeocodeServer?f=pjson",
            "seen": "2026-10-08"
          },
          {
            "what": "places service and near-point reference",
            "url": "https://developers.arcgis.com/rest/places/near-point-get/",
            "seen": "2026-10-08"
          },
          {
            "what": "API key authentication",
            "url": "https://developers.arcgis.com/documentation/security-and-authentication/api-key-authentication/",
            "seen": "2026-10-08"
          },
          {
            "what": "security best practices",
            "url": "https://developers.arcgis.com/documentation/security-and-authentication/security-best-practices/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server overview",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP get started",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/get-started/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/tools/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP pricing",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP FAQ",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/faq/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP release notes",
            "url": "https://developers.arcgis.com/ai/mcp-arcgis-location-services/release-notes/beta/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statement, revised 31 July 2026",
            "url": "https://www.esri.com/en-us/privacy/privacy-statements/privacy-statement",
            "seen": "2026-10-08"
          },
          {
            "what": "Products \u0026 Services Privacy Statement Supplement",
            "url": "https://www.esri.com/en-us/privacy/privacy-statements/privacy-supplement",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum, 12 March 2024",
            "url": "https://www.esri.com/content/dam/esrisites/en-us/media/legal/gdpr-data-processing-addendums/data-process-addend.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "GDPR page",
            "url": "https://www.esri.com/en-us/privacy/privacy-gdpr",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre, reporting a security concern",
            "url": "https://trust.arcgis.com/en/security-concern/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre, compliance",
            "url": "https://trust.arcgis.com/en/compliance/compliance.htm",
            "seen": "2026-10-08"
          },
          {
            "what": "ArcGIS REST JS repository (clone, tags)",
            "url": "https://github.com/Esri/arcgis-rest-js",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads, @esri/arcgis-rest-request",
            "url": "https://api.npmjs.org/downloads/point/last-week/@esri/arcgis-rest-request",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI, arcgis",
            "url": "https://pypi.org/pypi/arcgis/json",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP, arcgis.com",
            "url": "https://rdap.verisign.com/com/v1/domain/arcgis.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether the sign-up form asks for a card. The form at https://location.arcgis.com/sign-up/ is drawn by script. The billing help says a payment method is needed only for pay-as-you-go.",
          "unchecked: the status page's event history beyond its RSS feed, which holds one incident (16 June 2026). The page is drawn by script.",
          "unchecked: the MCP tools' input schemas and annotations, which need an account with beta access to list.",
          "unchecked: reply times on Esri Community and on the ArcGIS REST JS issue tracker, and whether that repository's CI passes.",
          "No request rate limits, 429 behaviour or retry guidance were found on the pages we read. They may be documented elsewhere on developers.arcgis.com.",
          "Whether FedRAMP moderate and ISO 27001 cover ArcGIS Location Platform. The trust centre speaks of Online Services and names ArcGIS Online.",
          "The agreement bars benchmarking and publishing benchmark results without written permission, which matters before our probes run.",
          "The MCP release notes list 1.0.0-beta.1.8 as released on 9 October 2026, a day after the check. The listing's lastRelease is the 29 September entry.",
          "The lead was right on vendor, URLs and interface. It did not mention the beta MCP server, which launched on 3 June 2026."
        ]
      },
      "negative": 0,
      "verdict": "Per-unit prices are public for every service, with a monthly free tier of 20,000 geocodes and 20,000 routes, keys limited to chosen privileges and a 99.9 per cent SLA. No rate limits or OpenAPI description were found, results may not be stored unless the dearer stored geocode is bought, and the agreement bars benchmarking without written permission.",
      "bestFor": "Organisations already on Esri software, and work that needs demographic enrichment, service areas or fleet routing beside geocoding.",
      "strengths": [
        "Every service has a public unit price and most have a monthly free tier, such as 20,000 geocodes, 20,000 routes and 2 million basemap tiles (https://location.arcgis.com/pricing/).",
        "API key credentials carry selected privileges, an expiry date of up to one year, optional referrer limits and two tokens for rotation. OAuth 2.0 user and app authentication are also supported.",
        "A published SLA commits to 99.9 per cent monthly uptime for ten services, with credits of 10 or 20 per cent of the monthly bill for the affected service (document G632a, 23 December 2025).",
        "The agreement promises 90 days' notice for deprecations of SDKs, APIs and location services (ArcGIS Location Platform Agreement, revised 21 November 2025, section 4.1).",
        "An Esri-hosted MCP server at `https://location-services-mcp.arcgis.com/beta/mcp` has eight tools, filters them by the token's privileges and adds no charge on top of service rates."
      ],
      "weaknesses": [
        "The agreement bars benchmarking availability, performance or functionality, and publishing benchmark results, without prior written permission from Esri and its licensors (sections 3.1.b.6 and 3.1.c.6.F).",
        "No request rate limits, 429 behaviour or retry guidance were found in the geocoding, places or routing reference pages we read.",
        "No OpenAPI description or llms.txt was found. `/llms.txt` returns 404 on developers.arcgis.com and location.arcgis.com.",
        "Storing a geocode needs `forStorage=true` at $4 per 1,000 with no free tier, against $0.50 per 1,000 for results that may not be kept. The MCP geocoding tools bill at the stored rate.",
        "The MCP server is a beta under an Early Access programme, and the SLA excludes beta, evaluation and free services. Technical support is sold separately."
      ],
      "agentNotes": [
        "Send the token in an `X-Esri-Authorization: Bearer` or `Authorization` header. The docs' examples put it in a `token` parameter, which Esri's own best-practice page calls less secure.",
        "Set `forStorage=true` on `findAddressCandidates` or `reverseGeocode` only when results will be kept. It needs pay-as-you-go and the Geocode (stored) privilege, and costs eight times the unstored rate.",
        "Cap geocoding output with `maxLocations` (default and maximum 50) and `outFields`, because billing counts results returned and the default returns every field.",
        "Page place searches with `pageSize` (maximum 20) and `offset`. A nearby or extent search costs $8 per 1,000 requests after 500 free a month.",
        "Check the JSON body for an `error` object with `code`, `message` and `details`. Code 499 means the token is missing and 403 means it lacks the privilege."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 65.4
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 83,
        "payments": 40,
        "reliability": 65,
        "schema": 61,
        "security": 64,
        "transparency": 54
      },
      "provenanceScore": 89
    },
    "connect": {
      "install": "npm install @esri/arcgis-rest-request @esri/arcgis-rest-geocoding",
      "http": "curl https://geocode-api.arcgis.com/arcgis/rest/services/World/GeocodeServer/findAddressCandidates \\\n  -d \"f=pjson\" \\\n  -d \"address=1600 Pennsylvania Ave NW, DC\" \\\n  -d \"token=\u003cACCESS_TOKEN\u003e\"",
      "config": {
        "servers": {
          "mcpArcGISLocationServices": {
            "headers": {
              "Authorization": "Bearer ${input:esriApiKey}"
            },
            "type": "http",
            "url": "https://location-services-mcp.arcgis.com/beta/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/geo.geocode",
      "tool": "https://letme.dev/arcgis"
    },
    "notable": [
      "The pricing page lists a unit price for every service, in US dollars, with a cost estimator and no login (https://location.arcgis.com/pricing/)",
      "MCP for ArcGIS Location Services (beta) is an Esri-hosted server with eight tools for geocoding, routing, elevation, static maps, enrichment and buffers, billed at standard service rates (https://developers.arcgis.com/ai/mcp-arcgis-location-services/)",
      "The agreement bars benchmarking the availability, performance or functionality of the platform, and publishing benchmark results, without prior written permission (https://www.esri.com/content/dam/esrisites/en-us/media/legal/platform/platform-legal.pdf)",
      "Geocoding results may be kept only when requested with `forStorage=true`, billed at $4 per 1,000 against $0.50 per 1,000 unstored (https://developers.arcgis.com/rest/geocode/)",
      "The SLA commits to 99.9 per cent monthly uptime for ten covered services and excludes beta, evaluation and free services (https://www.esri.com/content/dam/esrisites/en-us/media/legal/referenced-files/service-level-agmt-arcgis-platform.pdf)",
      "The MCP release notes carry an entry for 1.0.0-beta.1.8 dated 9 October 2026, a day after we read the page (https://developers.arcgis.com/ai/mcp-arcgis-location-services/release-notes/beta/)",
      "The geocoding reference asks callers not to include personally identifiable information in requests (https://developers.arcgis.com/rest/geocode/find-address-candidates/)"
    ],
    "area": "everyday",
    "details": [
      {
        "label": "Services",
        "value": "Geocoding (`findAddressCandidates`, `reverseGeocode`, `suggest`, `geocodeAddresses`, a batch job), Places (`/places/near-point`, `/places/within-extent`, `/places/{placeId}`, categories), Routing (routes, service areas, closest facility, fleet routing, travel cost matrix, snap to roads), Basemap Styles, Static Basemap Tiles, Static Maps, Elevation and GeoEnrichment"
      },
      {
        "label": "Base URLs",
        "value": "https://geocode-api.arcgis.com/arcgis/rest/services/World/GeocodeServer and https://places-api.arcgis.com/arcgis/rest/services/places-service/v1. The geocoding docs also list an Enhanced endpoint on geocode.arcgis.com that adds the batch file job"
      },
      {
        "label": "Credentials",
        "value": "API key credentials (selected privileges, expiry up to one year, optional referrers, two tokens for rotation), OAuth 2.0 user authentication, and app authentication with a client ID and secret for short-lived tokens. API keys (legacy) were retired in the July 2026 release"
      },
      {
        "label": "Token placement",
        "value": "`token` request parameter in the docs' examples, or an `X-Esri-Authorization: Bearer` or `Authorization` header"
      },
      {
        "label": "MCP server",
        "value": "MCP for ArcGIS Location Services (beta), Esri-hosted, Streamable HTTP only, at https://location-services-mcp.arcgis.com/beta/mcp. Version 1.0.0-beta.1.7 of 29 September 2026. API key as a Bearer header or OAuth 2.0. The key needs the Allow beta access privilege"
      },
      {
        "label": "MCP tools",
        "value": "find_address_candidates, reverse_geocode, solve_route, elevation_at_locations, map_with_overlay, get_topic_fields, describe_location, buffer. Tools are filtered by the token's privileges. No places tool"
      },
      {
        "label": "Output controls",
        "value": "Geocoding has `maxLocations` (default and maximum 50), `outFields`, `searchExtent`, `sourceCountry`, `category` and `langCode`. Places has `pageSize` (maximum 20), `offset`, `categoryIds` (up to 10) and `searchText`"
      },
      {
        "label": "Errors",
        "value": "A JSON `error` object with `code`, `message` and `details`. The geocoding output page lists 400, 403, 498 and 499 with extended codes and causes, and a 60-second timeout. An unauthenticated places request answered HTTP 401 with code 499 and a `WWW-Authenticate` header"
      },
      {
        "label": "Rate limits",
        "value": "None found in the reviewed documentation"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly uptime per covered service, measured in one-minute intervals. Credit of 10 per cent of that service's monthly bill below 99.9 and 20 per cent below 95, with a $100 minimum threshold and a 30-day claim window. Excludes beta, evaluation and free services"
      },
      {
        "label": "Storage terms",
        "value": "Results may be pre-cached only as the HTTP caching headers allow. Geocodes may be stored only from the Geocode (stored) service. Routing output may be stored for personal and internal business use. One request may serve one application user"
      },
      {
        "label": "Benchmarking",
        "value": "The agreement bars benchmarking availability, performance or functionality, and publishing benchmark results, without prior written permission of Esri and its licensors"
      },
      {
        "label": "SDKs",
        "value": "ArcGIS REST JS (`@esri/arcgis-rest-geocoding`, `-places`, `-routing`, `-elevation` and nine more packages, 4.11.0 of 7 August 2026, Apache-2.0) and the ArcGIS API for Python (`arcgis` 2.4.3 of 21 April 2026, under Esri's master licence agreement), plus the ArcGIS Maps SDKs"
      },
      {
        "label": "Usage monitoring",
        "value": "A usage page with daily graphs by service and by developer credential, and a billing summary by service for each billing cycle"
      },
      {
        "label": "Account rules",
        "value": "Accounts are for one person and may not be shared. A subscription with no payment method and no non-storage usage in 12 months is treated as inactive, then suspended and deleted"
      },
      {
        "label": "Support",
        "value": "Technical support is not included and is sold as annual plans through sales. Esri Community and Stack Overflow are the free channels"
      },
      {
        "label": "Assurance",
        "value": "The trust centre says Esri's Online Services are covered by a FedRAMP moderate authorisation and ISO 27001 certification, and that Esri's SOC 2 covers internal systems, not products. The pages we read don't name ArcGIS Location Platform"
      },
      {
        "label": "Sub-processors",
        "value": "The Data Processing Addendum (12 March 2024) names Microsoft Corporation, Amazon Web Services, Inc., Salesforce, Inc. and Akamai Technologies, introduced with 'including, but not limited to'"
      }
    ],
    "unitPrices": [
      {
        "item": "Geocodes, not stored (after 20,000 free a month)",
        "unit": "1k-requests",
        "usd": 0.5
      },
      {
        "item": "Geocodes, stored (`forStorage=true`, no free tier)",
        "unit": "1k-requests",
        "usd": 4
      },
      {
        "item": "Places nearby and extent search (after 500 free a month)",
        "unit": "1k-requests",
        "usd": 8
      },
      {
        "item": "Routes (after 20,000 free a month)",
        "unit": "1k-requests",
        "usd": 0.5
      },
      {
        "item": "Routes, stop-optimised (no free tier)",
        "unit": "1k-requests",
        "usd": 50
      },
      {
        "item": "Service areas (after 5,000 free a month)",
        "unit": "1k-requests",
        "usd": 50
      },
      {
        "item": "Basemap tiles (after 2 million free a month)",
        "unit": "1k-requests",
        "usd": 0.15
      },
      {
        "item": "Static maps (after 1,000 free a month)",
        "unit": "1k-requests",
        "usd": 0.9
      },
      {
        "item": "Elevation, per 1,000 points (after 50,000 free a month)",
        "unit": "1k-requests",
        "usd": 1
      }
    ],
    "provenance": {
      "legalEntity": "Environmental Systems Research Institute, Inc.",
      "domain": "arcgis.com",
      "domainRegistered": "1999-06-09",
      "endpointOnVendorDomain": true,
      "terms": "https://www.esri.com/content/dam/esrisites/en-us/media/legal/platform/platform-legal.pdf",
      "privacy": "https://www.esri.com/en-us/privacy/privacy-statements/privacy-statement",
      "statusPage": "https://status.location.arcgis.com",
      "changelog": "https://location.arcgis.com/help/release-notes/2026-07/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The ArcGIS Location Platform Agreement (E204 Platform Legal, revised 21 November 2025) is between the customer and Environmental Systems Research Institute, Inc., a California corporation at 380 New York Street, Redlands, California 92373-8100.",
        "The privacy statement (revised 31 July 2026) is the one the product's pages link. Esri also publishes a Products \u0026 Services Privacy Statement Supplement (9 September 2025) and a Data Processing Addendum (12 March 2024). Neither names ArcGIS Location Platform. The agreement's section 11.5 points to the addendum.",
        "The services answer on arcgis.com subdomains, among them geocode-api.arcgis.com, places-api.arcgis.com and location-services-mcp.arcgis.com.",
        "`/.well-known/security.txt` returns 404 on www.esri.com, developers.arcgis.com, location.arcgis.com and www.arcgis.com. The trust centre takes reports through a form, with a PGP key and a safe harbour statement.",
        "RDAP gives 1999-06-09 for arcgis.com and 1990-04-18 for esri.com, both registered through MarkMonitor Inc.",
        "The status page is Esri's own. Its event history is drawn by script, so we read the RSS feed it links, whose newest entry is dated 16 June 2026."
      ],
      "score": 89,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Environmental Systems Research Institute, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "arcgis.com, registered 1999-06-09 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "geocode-api.arcgis.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.location.arcgis.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.esri.com/content/dam/esrisites/en-us/media/legal/platform/platform-legal.pdf",
          "state": "not-read",
          "points": 10,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.esri.com/en-us/privacy/privacy-statements/privacy-statement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-31",
          "words": 2531,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Revised July 31, 2026",
              "says": "Last updated 2026-07-31"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The personal information we collect is used by Esri and its service providers to:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will retain the personal information we process on behalf of our users for as long as needed to provide services to our users, comply with our legal obligations, resolve disputes, and enforce our agreements.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "This information includes the internet protocol (IP) address, browser type, internet service provider (ISP), and clickstream data."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Your friend may contact us at privacy@esri.com to request that we remove this information from our database.",
              "says": "privacy@esri.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Esri also commits to the EU Standard Contractual Clauses and supplementary measures identified in its pre-signed Data Processing Addendum and the UK Addendum (for processing data by Esri as a processor on behalf of its customers) and the Data Transfer Agreement (for processing data by Esri as a controller).",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The statement says ArcGIS Online has privacy terms that differ from it, and points to a separate Products and Services supplement to review before contributing data.",
              "quote": "Before you access or contribute information or data to these systems, please review this Privacy Statement and the Esri Products \u0026 Services Privacy Statement Supplement at https://www.esri.com/en-us/privacy/privacy-statements/privacy-supplement."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/arcgis.json",
    "live": {
      "slug": "arcgis",
      "probe": {
        "target": "https://geocode-api.arcgis.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:04.262139857Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 145,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 138,
        "p95ms24h": 386,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.location.arcgis.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:38:14.482657019Z"
      },
      "updatedAt": "2026-10-08T21:12:04.262139857Z"
    }
  }
}
