{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "elasticsearch",
    "name": "Elasticsearch",
    "vendor": "Elastic",
    "vendorUrl": "https://www.elastic.co",
    "kind": "http-api",
    "category": "vector-search",
    "summary": "Elasticsearch is Elastic's search engine and vector database, with keyword, vector and hybrid search over a REST API. Agents reach it through that API or the Agent Builder MCP server on Elastic Cloud and Elastic Stack 9.2 or later.",
    "url": "https://www.anchorterminal.com/tools/elasticsearch",
    "markdownUrl": "https://www.anchorterminal.com/tools/elasticsearch.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/elasticsearch.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/elasticsearch.json",
    "repo": "https://github.com/elastic/elasticsearch",
    "license": "AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0 at the user's choice for most source. The `x-pack` folder is under Elastic Licence 2.0 only. Elastic Cloud is a proprietary service under Elastic's terms",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@elastic/elasticsearch"
      },
      {
        "registry": "pypi",
        "name": "elasticsearch"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. The REST API takes `Authorization: ApiKey \u003ckey\u003e`, with keys created in Kibana or by `POST /_security/api_key` and limited by role descriptors and an expiry. The Agent Builder MCP server takes the same kind of key, which needs the `feature_agentBuilder.read` Kibana privilege, or OAuth 2.1 on Serverless projects, where a registered client and a browser consent give each user a revocable connection.",
    "pricing": "usage",
    "pricingNotes": "Serverless bills by use, with search from $0.09 a VCU-hour, ingest from $0.14, storage from $0.047 a GB a month and egress from $0.05 a GB. Agent Builder has 1,000 free executions a month, then from $0.025 each. A 14-day Elastic Cloud trial needs no credit card. Self-managed Elasticsearch is free to run under its source licences (https://www.elastic.co/pricing/serverless-search, checked 2026-10-08).",
    "priceSummary": "$0.09 / unit",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the Serverless OpenAPI file or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 3136798,
      "pypiWeekly": 7755257,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.elastic.co/docs/solutions/search",
    "llmsTxt": "https://www.elastic.co/docs/llms.txt",
    "openapi": "https://www.elastic.co/docs/api/doc/elasticsearch-serverless.json",
    "capabilities": [
      "db.vector",
      "db.hybrid",
      "db.fulltext",
      "db.filters",
      "db.serverless"
    ],
    "tags": [
      "hosted",
      "usage",
      "free-trial",
      "no-card",
      "open-source",
      "self-hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "typescript",
      "python",
      "status-page",
      "bug-bounty",
      "soc2",
      "sla"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.7,
      "grade": "B",
      "agentReady": false,
      "rank": 224,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 77,
        "maintenance": 83,
        "payments": 35,
        "reliability": 62,
        "schema": 88,
        "security": 72,
        "transparency": 71
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 62,
          "points": 12.4,
          "reason": "Graded as a hosted service on Elastic Cloud Serverless. Statuspage at status.elastic.co with 638 components by region (20). Between 10 July and 8 October 2026 it lists more than 20 notices marked major. Most concern provisioning, metrics or the console, but three are regional service incidents, GCP us-central1 for 4 hours 47 minutes on 1 September, high latency in GCP asia-south1 for 3 hours on 6 August, and Serverless projects in GCP us-central1 delayed or unavailable on 8 October and still open when read. Elasticsearch 9.5.0 also returned incorrect results for some queries from 5 to 20 August (5 of 30). No request rate limit with numbers found, only project limits (5 of 15). The API conventions page says to retry 429 after a delay with exponential backoff, with no `Retry-After` header documented, and `_create` with an explicit ID makes a retried write safe (12 of 15). Serverless SLA of 99.95 per cent at Platinum or Enterprise level (10). The REST API and the MCP server are generally available on Serverless (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "OpenAPI 3.0.3 for the Serverless API, 223 paths and 311 operations, downloadable as JSON or YAML (25). llms.txt and a Markdown twin of each docs page (10). 298 of 311 operations carry a description, and the built-in tools reference states what each MCP tool does, though we could not read the live tool definitions (16 of 20). Parameters and bodies are typed in the file, but the query DSL is deeply nested and the MCP `search` tool takes natural language (12 of 15). 292 operations carry examples. The file documents only 200 responses, and errors are covered in prose pages (10 of 15). Release notes per version, a breaking-changes page and compatibility headers (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "The API sizes responses with `size` and `_source` includes and excludes. The MCP server exposes the Agent Builder tool list, 88 built-in tools in the reference with 21 in `platform.core`, and a key's privileges decide which ones work (15 of 25). `from` and `size`, `search_after`, filters and sorting (20). Errors come back as JSON with a type, reason and status, and the 429 and rejected-request pages say how to recover (15 of 20). `_create` and explicit document IDs make writes safe to retry. MCP annotations unchecked (12 of 20). Official clients for JavaScript and Python at 9.5.1, among others (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 72,
          "points": 12.6,
          "reason": "API keys take role descriptors that limit cluster, index and Kibana privileges and carry an expiry, and the MCP server accepts OAuth 2.1 on Serverless with per-user connections that can be revoked (30). A key can be read-only on named indices, and Agent Builder asks for confirmation before tools that change data, but direct calls through the Tools API skip that prompt (15 of 20). Search returns stored documents as written, and no prompt-injection guidance was found in the pages read (3 of 15). Agent traces can be collected into `traces-agent_builder.otel-*`. Audit logging on Serverless is unchecked (6 of 15). No security.txt (404). HackerOne bug bounty, CVE Numbering Authority, public advisories, SOC 2 and ISO 27001 (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (0). Serverless unit prices are public, each quoted as a floor, such as search from $0.09 a VCU-hour and storage from $0.047 a GB a month (15 of 20). 14-day trial with no credit card (20). A person signs up in a browser and creates the first key (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "Elasticsearch 9.5.5 was tagged on 30 September 2026 and announced on 6 October (30). 9.5.3, 9.5.4, 9.5.5 and three 9.4 patch releases fall inside 90 days (20). Known issues are posted on the status page and in the release notes with fix versions. GitHub issue handling is unchecked because the API refused us (12 of 25). JavaScript and Python clients at 9.5.1, matching the server line (15). Build and CI configuration is in the repository. The 9.5 line needed three patch releases for correctness and replication defects (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "note": "editorial 70, provenance 71",
          "reason": "Source is under AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0, with `x-pack` under Elastic Licence 2.0 only, and Serverless itself is closed (22 of 30). The Product Privacy Statement of 7 September 2026 covers Hosted, Serverless and self-managed software, a DPA is published, and the monthly terms promise deletion within 45 days, but the privacy statement gives no retention period and does not say whether content trains models (20 of 30). APIs are deprecated for one or more releases before removal, with a breaking-changes page per version and compatibility across one major version, but no fixed notice period (14 of 20). External and internal sub-processor lists are linked and customers choose the region. We did not read the lists (14 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The API sizes responses with `size` and `_source` includes and excludes. The MCP server exposes the Agent Builder tool list, 88 built-in tools in the reference with 21 in `platform.core`, and a key's privileges decide which ones work (15 of 25). `from` and `size`, `search_after`, filters and sorting (20). Errors come back as JSON with a type, reason and status, and the 429 and rejected-request pages say how to recover (15 of 20). `_create` and explicit document IDs make writes safe to retry. MCP annotations unchecked (12 of 20). Official clients for JavaScript and Python at 9.5.1, among others (15).",
          "maintenance": "Elasticsearch 9.5.5 was tagged on 30 September 2026 and announced on 6 October (30). 9.5.3, 9.5.4, 9.5.5 and three 9.4 patch releases fall inside 90 days (20). Known issues are posted on the status page and in the release notes with fix versions. GitHub issue handling is unchecked because the API refused us (12 of 25). JavaScript and Python clients at 9.5.1, matching the server line (15). Build and CI configuration is in the repository. The 9.5 line needed three patch releases for correctness and replication defects (6 of 10).",
          "payments": "No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (0). Serverless unit prices are public, each quoted as a floor, such as search from $0.09 a VCU-hour and storage from $0.047 a GB a month (15 of 20). 14-day trial with no credit card (20). A person signs up in a browser and creates the first key (0).",
          "reliability": "Graded as a hosted service on Elastic Cloud Serverless. Statuspage at status.elastic.co with 638 components by region (20). Between 10 July and 8 October 2026 it lists more than 20 notices marked major. Most concern provisioning, metrics or the console, but three are regional service incidents, GCP us-central1 for 4 hours 47 minutes on 1 September, high latency in GCP asia-south1 for 3 hours on 6 August, and Serverless projects in GCP us-central1 delayed or unavailable on 8 October and still open when read. Elasticsearch 9.5.0 also returned incorrect results for some queries from 5 to 20 August (5 of 30). No request rate limit with numbers found, only project limits (5 of 15). The API conventions page says to retry 429 after a delay with exponential backoff, with no `Retry-After` header documented, and `_create` with an explicit ID makes a retried write safe (12 of 15). Serverless SLA of 99.95 per cent at Platinum or Enterprise level (10). The REST API and the MCP server are generally available on Serverless (10).",
          "schema": "OpenAPI 3.0.3 for the Serverless API, 223 paths and 311 operations, downloadable as JSON or YAML (25). llms.txt and a Markdown twin of each docs page (10). 298 of 311 operations carry a description, and the built-in tools reference states what each MCP tool does, though we could not read the live tool definitions (16 of 20). Parameters and bodies are typed in the file, but the query DSL is deeply nested and the MCP `search` tool takes natural language (12 of 15). 292 operations carry examples. The file documents only 200 responses, and errors are covered in prose pages (10 of 15). Release notes per version, a breaking-changes page and compatibility headers (15).",
          "security": "API keys take role descriptors that limit cluster, index and Kibana privileges and carry an expiry, and the MCP server accepts OAuth 2.1 on Serverless with per-user connections that can be revoked (30). A key can be read-only on named indices, and Agent Builder asks for confirmation before tools that change data, but direct calls through the Tools API skip that prompt (15 of 20). Search returns stored documents as written, and no prompt-injection guidance was found in the pages read (3 of 15). Agent traces can be collected into `traces-agent_builder.otel-*`. Audit logging on Serverless is unchecked (6 of 15). No security.txt (404). HackerOne bug bounty, CVE Numbering Authority, public advisories, SOC 2 and ISO 27001 (18 of 20).",
          "transparency": "Source is under AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0, with `x-pack` under Elastic Licence 2.0 only, and Serverless itself is closed (22 of 30). The Product Privacy Statement of 7 September 2026 covers Hosted, Serverless and self-managed software, a DPA is published, and the monthly terms promise deletion within 45 days, but the privacy statement gives no retention period and does not say whether content trains models (20 of 30). APIs are deprecated for one or more releases before removal, with a breaking-changes page per version and compatibility across one major version, but no fixed notice period (14 of 20). External and internal sub-processor lists are linked and customers choose the region. We did not read the lists (14 of 20)."
        },
        "sources": [
          {
            "what": "MCP options for Elasticsearch",
            "url": "https://www.elastic.co/docs/solutions/search/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "Agent Builder MCP server",
            "url": "https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP API key authentication",
            "url": "https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server-api-keys",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth clients for the MCP server",
            "url": "https://www.elastic.co/docs/deploy-manage/app-connections/oauth-clients",
            "seen": "2026-10-08"
          },
          {
            "what": "Built-in tools reference",
            "url": "https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/tools/builtin-tools-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "Agent Builder permissions",
            "url": "https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/permissions",
            "seen": "2026-10-08"
          },
          {
            "what": "Agent Builder limitations and known issues",
            "url": "https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/limitations-known-issues",
            "seen": "2026-10-08"
          },
          {
            "what": "Serverless API reference and OpenAPI file",
            "url": "https://www.elastic.co/docs/api/doc/elasticsearch-serverless",
            "seen": "2026-10-08"
          },
          {
            "what": "API conventions, 429 guidance",
            "url": "https://www.elastic.co/docs/reference/elasticsearch/rest-apis/api-conventions",
            "seen": "2026-10-08"
          },
          {
            "what": "REST API compatibility",
            "url": "https://www.elastic.co/docs/reference/elasticsearch/rest-apis/compatibility",
            "seen": "2026-10-08"
          },
          {
            "what": "Rejected requests",
            "url": "https://www.elastic.co/docs/troubleshoot/elasticsearch/rejected-requests",
            "seen": "2026-10-08"
          },
          {
            "what": "Pagination",
            "url": "https://www.elastic.co/docs/reference/elasticsearch/rest-apis/paginate-search-results",
            "seen": "2026-10-08"
          },
          {
            "what": "Serverless differences and project limits",
            "url": "https://www.elastic.co/docs/deploy-manage/deploy/elastic-cloud/differences-from-other-elasticsearch-offerings",
            "seen": "2026-10-08"
          },
          {
            "what": "Vector search",
            "url": "https://www.elastic.co/docs/solutions/search/vector",
            "seen": "2026-10-08"
          },
          {
            "what": "Hybrid search",
            "url": "https://www.elastic.co/docs/solutions/search/hybrid-search",
            "seen": "2026-10-08"
          },
          {
            "what": "Serverless pricing",
            "url": "https://www.elastic.co/pricing/serverless-search",
            "seen": "2026-10-08"
          },
          {
            "what": "Serverless billing dimensions",
            "url": "https://www.elastic.co/docs/deploy-manage/cloud-organization/billing/elasticsearch-billing-dimensions",
            "seen": "2026-10-08"
          },
          {
            "what": "Trial",
            "url": "https://www.elastic.co/cloud/cloud-trial-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Status incident feed",
            "url": "https://status.elastic.co/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Release notes",
            "url": "https://www.elastic.co/docs/release-notes/elasticsearch",
            "seen": "2026-10-08"
          },
          {
            "what": "Breaking changes",
            "url": "https://www.elastic.co/docs/release-notes/elasticsearch/breaking-changes",
            "seen": "2026-10-08"
          },
          {
            "what": "Repository tags and licence file",
            "url": "https://github.com/elastic/elasticsearch",
            "seen": "2026-10-08"
          },
          {
            "what": "Security announcements",
            "url": "https://discuss.elastic.co/c/announcements/security-announcements/31",
            "seen": "2026-10-08"
          },
          {
            "what": "ESA-2026-199",
            "url": "https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-199/390874",
            "seen": "2026-10-08"
          },
          {
            "what": "Security issues page",
            "url": "https://www.elastic.co/community/security",
            "seen": "2026-10-08"
          },
          {
            "what": "Trust centre",
            "url": "https://www.elastic.co/trust",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud Monthly Terms of Service",
            "url": "https://www.elastic.co/agreements/cloud-monthly",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud Service Subscription Agreement",
            "url": "https://www.elastic.co/agreements/global/cloud-services",
            "seen": "2026-10-08"
          },
          {
            "what": "Serverless SLA",
            "url": "https://www.elastic.co/agreements/sla-elastic-cloud-serverless",
            "seen": "2026-10-08"
          },
          {
            "what": "Product Privacy Statement",
            "url": "https://www.elastic.co/legal/product-privacy-statement",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy portal",
            "url": "https://www.elastic.co/trust/privacy",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: GitHub star count and issue responsiveness, because the GitHub API refused us for its rate limit",
          "unchecked: the MCP server's live tool definitions, its transport, and whether tools carry readOnlyHint or destructiveHint",
          "unchecked: audit logging on Serverless. The docs page we tried returned 404",
          "unchecked: the contents of the external and internal sub-processor lists linked from elastic.co/trust/privacy",
          "unchecked: the registration date of elastic.co. No RDAP service answered for the domain",
          "The MCP options page, as our reader summarised it, labels the Agent Builder MCP server preview, while the server's own page says generally available on Serverless and since 9.3. We followed the server's page",
          "Whether the 9.5.0 query defect reached Serverless projects. The status notice names versions, not deployment types",
          "The lead called the MCP server a preview on Serverless. Elastic's page for it says generally available",
          "The Cloud Monthly Terms and the Cloud Service Subscription Agreement are published as PDFs behind cover pages, which our policy reader does not fetch",
          "www.elastic.co/.well-known/security.txt returned 404"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "Sixteen Elasticsearch security advisories were posted between 25 September and 6 October 2026. The one we read, ESA-2026-199 (CVE-2026-103009, CVSS 7.1), is an authorisation bypass in cross-cluster search on self-managed clusters, fixed in 8.19.23, 9.4.8 and 9.5.5, and Elastic says Serverless is not affected. Fixed and disclosed, so a small deduction (https://discuss.elastic.co/c/announcements/security-announcements/31)."
      ],
      "verdict": "Keyword, dense and sparse vector, and hybrid search with rank fusion sit behind one OpenAPI-described REST API, with API keys scoped to indices and privileges. The status page lists more than 20 incidents marked major since July 2026, and Elasticsearch 9.5.0 returned incorrect results for some queries without raising an error.",
      "bestFor": "Retrieval that needs keyword relevance, filters and vectors in one query, and teams already running Elastic for logs or security.",
      "strengths": [
        "OpenAPI 3.0.3 file for the Serverless API with 311 operations, plus llms.txt and a Markdown twin of every docs page",
        "API keys take role descriptors that limit indices and privileges, with an expiry, and the MCP server accepts OAuth 2.1 on Serverless",
        "Agent Builder MCP server is generally available on Serverless and on Elastic Stack 9.3 and later",
        "14-day Elastic Cloud trial with no credit card, and unit prices published for Serverless",
        "Public bug bounty on HackerOne, CVE Numbering Authority status and dated security advisories"
      ],
      "weaknesses": [
        "More than 20 status notices marked major between 10 July and 8 October 2026, three of them regional service incidents",
        "Elasticsearch 9.5.0 (29 July 2026) returned incorrect results for some `must_not` queries with no error, fixed in 9.5.1 and 9.5.2",
        "No request rate limit with numbers was found in the reviewed documentation",
        "The 99.95 per cent Serverless SLA applies only at Platinum or Enterprise subscription level",
        "The monthly terms forbid use of the cloud service for benchmarking, competitive or comparative purposes",
        "Search compute on Serverless does not scale to zero, so an idle project is still billed a baseline"
      ],
      "agentNotes": [
        "Send `Authorization: ApiKey \u003ckey\u003e` to the project's Elasticsearch URL. The MCP server is on the Kibana URL at `/api/agent_builder/mcp`",
        "Create the MCP key with `feature_agentBuilder.read` and only the index patterns needed, or the endpoint answers 403",
        "On 429, wait and retry with exponential backoff. Do not set short client timeouts, because a retried request joins the back of the queue",
        "Page past 10,000 hits with `search_after`, not `from` and `size`",
        "Tool calls made directly through the Tools API skip Agent Builder's confirmation prompts, so restrict the key instead"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.7
        }
      ],
      "editorialScores": {
        "ergonomics": 77,
        "maintenance": 83,
        "payments": 35,
        "reliability": 62,
        "schema": 88,
        "security": 72,
        "transparency": 70
      },
      "provenanceScore": 71
    },
    "connect": {
      "install": "npm install @elastic/elasticsearch",
      "http": "curl -X GET \"${ES_URL}/_cat/indices?v=true\" \\\n  -H \"Authorization: ApiKey ${API_KEY}\"",
      "config": {
        "mcpServers": {
          "elastic-agent-builder": {
            "args": [
              "mcp-remote",
              "${KIBANA_URL}/api/agent_builder/mcp",
              "--header",
              "Authorization:${AUTH_HEADER}"
            ],
            "command": "npx",
            "env": {
              "AUTH_HEADER": "ApiKey ${API_KEY}",
              "KIBANA_URL": "${KIBANA_URL}"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/db.vector",
      "tool": "https://letme.dev/elasticsearch"
    },
    "notable": [
      "The Agent Builder MCP server answers at `{KIBANA_URL}/api/agent_builder/mcp` and is generally available on Serverless and on Elastic Stack 9.3 and later, preview in 9.2 (https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server)",
      "The older `elastic/mcp-server-elasticsearch` is marked deprecated for Serverless and Elastic Stack 9.2 and later (https://www.elastic.co/docs/solutions/search/mcp)",
      "The built-in tools reference lists 88 tools, 21 of them in `platform.core`, including `search`, `execute_esql`, `get_index_mapping` and `list_indices` (https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/tools/builtin-tools-reference)",
      "Elasticsearch 9.5.0 could return documents a `must_not` clause should have excluded, with no error. The status page carried it from 5 to 20 August 2026 until 9.5.2 (https://status.elastic.co)",
      "The Cloud Monthly Terms of Service (12 September 2025) forbid use of the service for benchmarking, competitive or comparative purposes (https://www.elastic.co/agreements/cloud-monthly)",
      "Elastic runs a bug bounty on HackerOne and is a CVE Numbering Authority (https://www.elastic.co/community/security)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "Elastic Cloud Serverless Elasticsearch projects, through the REST API and the Agent Builder MCP server. Elastic Cloud Hosted and self-managed Elasticsearch run the same engine and are not scored apart"
      },
      {
        "label": "Search modes",
        "value": "Full-text, `dense_vector` kNN (approximate or exact), `sparse_vector`, the managed `semantic_text` workflow, and hybrid search with reciprocal rank fusion"
      },
      {
        "label": "MCP server",
        "value": "Agent Builder MCP server at `{KIBANA_URL}/api/agent_builder/mcp`, or `/s/{SPACE_NAME}/api/agent_builder/mcp` for a Kibana space. API key on any deployment, OAuth 2.1 on Serverless only. Exposes built-in and custom Agent Builder tools"
      },
      {
        "label": "Credentials",
        "value": "API keys with `role_descriptors` (cluster, index and Kibana application privileges) and an expiry. OAuth connections act with the consenting user's permissions, can be revoked singly, and lapse after 30 days unused"
      },
      {
        "label": "OpenAPI",
        "value": "Elasticsearch Serverless API, OpenAPI 3.0.3, 223 paths and 311 operations, generated from elastic/elasticsearch-specification, updated 6 October 2026"
      },
      {
        "label": "Rate limits",
        "value": "No request rate limit with numbers found. Project limits are 15,000 indices a project, 500 projects an organisation and 1 TB a Vector Database project. A busy cluster answers 429"
      },
      {
        "label": "Pagination",
        "value": "`from` and `size` up to 10,000 hits, then `search_after`. `_source` includes and excludes size the response"
      },
      {
        "label": "Serverless billing",
        "value": "Virtual compute units (VCUs) for ingest, search and machine learning, storage per GB a month and egress per GB. Ingest scales to zero after 15 minutes idle. Search keeps a billed baseline"
      },
      {
        "label": "Agent Builder billing",
        "value": "1,000 executions a month free, then from $0.025 an execution. A turn over 50,000 input tokens counts as more than one. Error responses are not billed"
      },
      {
        "label": "Trial",
        "value": "14 days on Elastic Cloud, no credit card. The trial terms allow only internal evaluation and forbid publishing performance data"
      },
      {
        "label": "SLA",
        "value": "Serverless SLA of 12 September 2025, 99.95 per cent monthly uptime, Platinum or Enterprise subscription level only. Credits of 10, 30 or 100 per cent, requested by support ticket within 10 days"
      },
      {
        "label": "Releases",
        "value": "9.5.0 tagged 29 July 2026, 9.5.3 on 1 September, 9.5.4 on 9 September, 9.5.5 on 30 September. Clients `@elastic/elasticsearch` 9.5.1 on npm and `elasticsearch` 9.5.1 on PyPI (9 September 2026)"
      },
      {
        "label": "Licence",
        "value": "Source under AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0 at the user's choice. Code in the `x-pack` folder is under Elastic Licence 2.0 only. Serverless is a closed hosted service"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 and SOC 3, ISO/IEC 27001, 27017 and 27018, PCI DSS, HIPAA, FedRAMP High and Moderate, CSA STAR, per elastic.co/trust"
      },
      {
        "label": "Data deletion",
        "value": "The monthly terms say content is deleted within 45 days of the customer deleting all projects, apart from backups and copies the law requires"
      }
    ],
    "unitPrices": [
      {
        "item": "Serverless search compute, VCU-hour",
        "unit": "compute-unit",
        "usd": 0.09,
        "note": "Quoted as a floor on the pricing page"
      },
      {
        "item": "Serverless ingest compute, VCU-hour",
        "unit": "compute-unit",
        "usd": 0.14,
        "note": "Quoted as a floor on the pricing page"
      },
      {
        "item": "Serverless storage",
        "unit": "gb-month",
        "usd": 0.047,
        "note": "Quoted as a floor on the pricing page"
      },
      {
        "item": "Serverless egress",
        "unit": "gb",
        "usd": 0.05,
        "note": "Quoted as a floor on the pricing page"
      },
      {
        "item": "Agent Builder execution",
        "unit": "call",
        "usd": 0.025,
        "note": "After 1,000 free executions a month, quoted as a floor"
      }
    ],
    "provenance": {
      "legalEntity": "Elasticsearch B.V.",
      "domain": "elastic.co",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://www.elastic.co/agreements/cloud-monthly",
      "privacy": "https://www.elastic.co/legal/product-privacy-statement",
      "statusPage": "https://status.elastic.co",
      "changelog": "https://www.elastic.co/docs/release-notes/elasticsearch",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Cloud Monthly Terms of Service (effective 12 September 2025) name the contracting entity by customer location, Elasticsearch, Inc. for the United States and Elasticsearch B.V. or Elastic International B.V. elsewhere. The page is a cover that links the PDF.",
        "Customers with an order form are under the Elastic Cloud Service Subscription Agreement of 5 March 2026 at https://www.elastic.co/agreements/global/cloud-services.",
        "The Product Privacy Statement (7 September 2026) is issued by Elastic N.V. and its subsidiaries and covers Elastic Cloud Hosted, Serverless and self-managed software. The General Privacy Statement covers only websites and events.",
        "www.elastic.co/.well-known/security.txt returned 404. Reports go to HackerOne or security@elastic.co.",
        "No RDAP service answered for elastic.co, so the registration date is not recorded.",
        "Project endpoints are on Elastic Cloud hostnames that we did not call. `endpointOnVendorDomain` rests on the docs, not on a request."
      ],
      "score": 71,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Elasticsearch B.V.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "elastic.co, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "elastic.co",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.elastic.co",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.elastic.co/agreements/cloud-monthly",
          "state": "unreadable",
          "reason": "the page is a cover page that links the agreement as a PDF, not the agreement itself",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.elastic.co/legal/product-privacy-statement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-07",
          "words": 5823,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: September 7, 2026",
              "says": "Last updated 2026-09-07"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Statement applies to the information we collect in connection with your use of the Products and for which we determine the means and purposes of processing (i.e., as a \"data controller\")."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "…Statement does not apply to personal data processed by Elastic in the role of a Processor or Service Provider (as applicable), for the purposes of the provision, delivery, operation, maintenance, and ongoing efficacy of Elastic's Products, which is subject to the terms of the applicable customer agreement."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We will not sell your personal data or allow a third party to use your personal data for its own commercial purpose.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If we are unable to resolve your concerns, you have the right to contact your local data privacy supervisory authority or seek a remedy through the courts if you believe your requests to exercise your rights have not been honored."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Elastic has appointed an external Data Protection Officer for German data subjects and designated internal Data Protection Officers (or equivalent) among our global privacy staff for other locations as required in Brazil, Mexico, Quebec, Singapore, and South Africa.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Department of Commerce's Data Privacy Framework (“DPF”), implementing the European Commission's standard contractual clauses along with supplementary measures, implementing the Information Commissioner's Office international data transfer addendum to the European Commission's standard contractual clauses, and relying…",
              "says": "Relies on standard contractual clauses and the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Elastic uses artificial intelligence and machine learning to process Product Usage Data for the purposes in the statement.",
              "quote": "We use artificial intelligence and machine learning to help process Product Usage Data for the purposes described in this Statement."
            },
            {
              "date": "2026-10-08",
              "text": "Where the law permits, Elastic may use Product Usage Data to suggest and market other Elastic products to customers and users.",
              "quote": "Elastic may use Product Usage Data to personalize your experience and to suggest other Elastic Products to you, to solicit your feedback, to increase engagement and adoption of our features (e.g., by providing in-Product suggestions), to market additional Products to our customers and users"
            },
            {
              "date": "2026-10-08",
              "text": "Product Usage Data can include contents of potentially malicious binaries, and code or natural language inputs or outputs that might threaten Elastic products.",
              "quote": "hashes and contents of potentially malicious executable binaries, other file hashes, samples and metadata, or code or natural language inputs or outputs that might interfere with, disable, misuse, or threaten Elastic Products"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/elasticsearch.json",
    "live": {
      "slug": "elasticsearch",
      "vendorStatus": {
        "page": "https://status.elastic.co",
        "indicator": "major",
        "summary": "Partial System Outage",
        "checkedAt": "2026-10-09T10:10:52.878383539Z"
      },
      "updatedAt": "2026-10-09T10:10:52.878383539Z"
    }
  }
}
