{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "nocodb",
    "name": "NocoDB",
    "vendor": "NocoDB Inc",
    "vendorUrl": "https://nocodb.com",
    "kind": "http-api",
    "category": "spreadsheets",
    "summary": "NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth.",
    "url": "https://www.anchorterminal.com/tools/nocodb",
    "markdownUrl": "https://www.anchorterminal.com/tools/nocodb.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nocodb.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nocodb.json",
    "repo": "https://github.com/nocodb/nocodb",
    "license": "Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://app.nocodb.com",
    "packages": [
      {
        "registry": "npm",
        "name": "nocodb-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. A signed-in user creates a fine-grained API token in Account Settings, choosing permission categories, bases and an expiry, and sends it as `xc-token` or `Authorization: Bearer`. For MCP the user creates a connection with its own key, sent as `x-api-key`, or a web client uses OAuth with PKCE and dynamic client registration and the user picks bases and tools on the consent screen. No review step was found. A token or connection never exceeds its owner's role. Workspaces that enforce SSO accept only tokens created after an SSO sign-in.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with 1,000 API calls a month, 1,000 records and 3 editor seats, no card required per the pricing page, so an agent can start without a contract. Plus is $12 a seat a month billed annually, Business $24 and Scale $45, with Plus and Business capped at 9 paid seats. Enterprise through sales. API calls aren't priced separately. The self-hosted Community Edition is free for internal use (checked 2026-10-08).",
    "priceSummary": "$12 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the REST API docs, the MCP docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 199,
    "popularity": {
      "githubStars": 65215,
      "npmWeekly": 6282,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://nocodb.com/docs/apis-and-mcp",
    "llmsTxt": "https://nocodb.com/llms.txt",
    "openapi": "https://nocodb.com/apis/v3/swagger-v3.json",
    "capabilities": [
      "sheets.records",
      "sheets.read",
      "sheets.write",
      "sheets.tables",
      "sheets.formulas"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "mcp",
      "source-available",
      "free-tier",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "javascript",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-09-29",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 75.7,
      "grade": "BB",
      "agentReady": true,
      "rank": 37,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 74,
        "maintenance": 87,
        "payments": 30,
        "reliability": 97,
        "schema": 85,
        "security": 71,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 97,
          "points": 19.4,
          "reason": "Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus `.md` (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on `queryRecords` and a `generateSkillGuide` tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with `next` and `prev` URLs, `where`, `sort`, `fields` and `viewId` (20). v3 errors return a stable `error` code with a message and a request id, though some older paths return a bare `msg` (16). The record tools in the source set `readOnlyHint`, `destructiveHint` and in places `idempotentHint`, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 71,
          "points": 12.43,
          "reason": "Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 87,
          "points": 7.61,
          "reason": "Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 66, provenance 86",
          "reason": "Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented `NC_DISABLE_TELE` switch (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with `next` and `prev` URLs, `where`, `sort`, `fields` and `viewId` (20). v3 errors return a stable `error` code with a message and a request id, though some older paths return a bare `msg` (16). The record tools in the source set `readOnlyHint`, `destructiveHint` and in places `idempotentHint`, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8).",
          "maintenance": "Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10).",
          "payments": "No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored.",
          "reliability": "Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10).",
          "schema": "Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus `.md` (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on `queryRecords` and a `generateSkillGuide` tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15).",
          "security": "Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20).",
          "transparency": "Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented `NC_DISABLE_TELE` switch (18 of 20)."
        },
        "sources": [
          {
            "what": "MCP server docs (Markdown)",
            "url": "https://nocodb.com/docs/apis-and-mcp/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "REST API docs, rate limits and query parameters",
            "url": "https://nocodb.com/docs/apis-and-mcp/rest-apis",
            "seen": "2026-10-08"
          },
          {
            "what": "API tokens",
            "url": "https://nocodb.com/docs/product/account-settings/api-tokens",
            "seen": "2026-10-08"
          },
          {
            "what": "v3 OpenAPI file",
            "url": "https://nocodb.com/apis/v3/swagger-v3.json",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://nocodb.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog 2026.09.1",
            "url": "https://nocodb.com/docs/changelog/2026.09.1",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://nocodb.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.nocodb.com",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents, September 2026",
            "url": "https://status.nocodb.com/incidents/September-2026",
            "seen": "2026-10-08"
          },
          {
            "what": "Service Level Agreement",
            "url": "https://nocodb.com/docs/legal/sla",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://nocodb.com/docs/legal/terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://nocodb.com/docs/legal/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Subscription Agreement",
            "url": "https://nocodb.com/docs/legal/msa",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://nocodb.com/docs/legal/subprocessors",
            "seen": "2026-10-08"
          },
          {
            "what": "AI terms",
            "url": "https://nocodb.com/docs/legal/ai-terms",
            "seen": "2026-10-08"
          },
          {
            "what": "workspace audit logs",
            "url": "https://nocodb.com/docs/product/workspaces/workspace-audit",
            "seen": "2026-10-08"
          },
          {
            "what": "self-hosting licence page",
            "url": "https://nocodb.com/docs/self-hosting/license",
            "seen": "2026-10-08"
          },
          {
            "what": "environment variables (rate limits, telemetry)",
            "url": "https://nocodb.com/docs/self-hosting/environment-variables",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://app.nocodb.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "repository (clone of 8 October 2026: LICENSE.md, SECURITY.md, tags, packages/nocodb/src/mcp)",
            "url": "https://github.com/nocodb/nocodb",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub security advisories",
            "url": "https://github.com/nocodb/nocodb/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, nocodb-sdk",
            "url": "https://registry.npmjs.org/nocodb-sdk/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=nocodb",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for nocodb.com",
            "url": "https://rdap.verisign.com/com/v1/domain/nocodb.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead called NocoDB open source. Since January 2026 it is under the Sustainable Use License, which the vendor's own licence page says is not OSI-approved",
          "The lead's docs link (nocodb.com/docs/product-docs/mcp) now redirects to nocodb.com/docs/apis-and-mcp/mcp, and the vendor's documents name it NocoDB Inc, without a comma",
          "The tool count differs between vendor pages. llms.txt says 149 tools and the 2026.09.1 changelog says 199. The listing uses 199",
          "unchecked: the input schemas, descriptions and annotations of the Cloud-only MCP tools, which need a signed-in account and aren't in the public repository. Only the 13 record tools were read in the source",
          "unchecked: whether signup for the Free plan asks for a card. The pricing page says no card is required and we didn't complete a signup",
          "unchecked: reply times on GitHub issues and the results of the CI workflows",
          "unchecked: the first release date, left empty",
          "The pricing cards show Plus at $12 and Business at $24 a seat billed annually, while the comparison table on the same page shows 15 and 30. The listing uses the card prices",
          "No security.txt, bug bounty, separate DPA, API deprecation policy or prompt-injection guidance was found in the reviewed pages",
          "The docs give 30 seconds as the wait after a 429 and the OpenAPI file says the response carries Retry-After. We didn't trigger one",
          "GitHub advisories from May and June 2026 include two rated High (stored cross-site scripting through a form redirect URL, and an attachment size limit bypass). They are published by the maintainers and no deduction was taken"
        ]
      },
      "negative": 0,
      "verdict": "API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.",
      "bestFor": "Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.",
      "strengths": [
        "Fine-grained API tokens carry eight permission categories at Read or Read and write, a list of bases, an expiry and an on-off switch",
        "An MCP connection lists only the tools its owner allowed, by section at Read, Read and write, or Read, write and delete",
        "Public OpenAPI 3.1 file for the v3 REST API with 114 operations, plus llms.txt and a Markdown copy of every docs page",
        "The MCP record tools in the source set `readOnlyHint` and `destructiveHint`, and `deleteRecords` is marked destructive",
        "status.nocodb.com lists no incident from July to October 2026 and shows 99.9907 per cent for the application over 90 days"
      ],
      "weaknesses": [
        "5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429",
        "REST create, update and upsert calls take 10 records each by default",
        "The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan",
        "The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved",
        "No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry"
      ],
      "agentNotes": [
        "Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token",
        "Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds",
        "Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records",
        "Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or`",
        "Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 75.7
        }
      ],
      "editorialScores": {
        "ergonomics": 74,
        "maintenance": 87,
        "payments": 30,
        "reliability": 97,
        "schema": 85,
        "security": 71,
        "transparency": 66
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "docker run -d \\\n  --name noco \\\n  -v \"$(pwd)\"/nocodb:/usr/app/data/ \\\n  -p 8080:8080 \\\n  nocodb/nocodb:latest",
      "http": "curl -H \"xc-token: nc_pat_...\" https://your-nocodb.com/api/v3/...",
      "config": {
        "mcpServers": {
          "NocoDB MCP": {
            "args": [
              "mcp-remote",
              "https://your-domain.com/mcp/\u003cncId\u003e",
              "--header",
              "x-api-key: \u003cncToken\u003e"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/sheets.records",
      "tool": "https://letme.dev/nocodb"
    },
    "notable": [
      "The MCP server on NocoDB Cloud has 199 tools per the 2026.09.1 changelog, and one connection reaches every base its owner picks. The Community Edition has the record tools only, 13 in the source (https://nocodb.com/docs/changelog/2026.09.1)",
      "An MCP connection registers only the tools on its allowlist, set per section to Read, Read and write, Read, write and delete, or None, and its authority is checked against the owner's role on each call (https://nocodb.com/docs/apis-and-mcp/mcp)",
      "Fine-grained tokens are stored as SHA-256 hashes, shown once, and default to a 1-year expiry. Base selection, categories and expiry are on all Cloud plans, while Community Edition tokens reach all resources and never expire (https://nocodb.com/docs/product/account-settings/api-tokens)",
      "Rate limit of 5 requests a second per user on all plans, with a 429 and a 30-second wait (https://nocodb.com/docs/apis-and-mcp/rest-apis)",
      "MCP tool calls count against the workspace's monthly API calls as the same work would over REST, so creating 100 records counts as 10 calls (https://nocodb.com/docs/apis-and-mcp/mcp)",
      "The licence changed from AGPL-3.0 to the Sustainable Use License on 9 January 2026. Internal self-hosting stays free, and selling hosted access needs a commercial licence (https://nocodb.com/docs/self-hosting/license)",
      "The pricing page labels the v2 APIs 'will deprecate soon' with no date. Creating legacy org-wide tokens through the API was blocked on Cloud from v2026.08.1 (https://nocodb.com/pricing)",
      "status.nocodb.com lists no incident for July, August, September or October 2026 (https://status.nocodb.com/incidents/September-2026)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces graded",
        "value": "NocoDB Cloud. The v3 REST API at https://app.nocodb.com/api/v3 and the built-in MCP server at https://app.nocodb.com/mcp. The self-hosted Community Edition has the same REST API and a 13-tool MCP server"
      },
      {
        "label": "Free tier",
        "value": "Free plan, no card required per the pricing page. 3 editor seats, 1,000 records, 1 GB storage, 1,000 API calls a month, 100 automation runs"
      },
      {
        "label": "Rate limits",
        "value": "5 requests a second per user on all plans, shared by that user's tokens. A 429 carries Retry-After per the OpenAPI file, and the docs say to wait 30 seconds (vendor's figures)"
      },
      {
        "label": "Monthly API calls",
        "value": "1,000 on Free, 100,000 on Plus, 1,000,000 on Business, 5,000,000 on Scale, unlimited on Enterprise. Over a limit, a 2-week grace period applies before access may be restricted"
      },
      {
        "label": "Batch size",
        "value": "10 records per REST create, update or upsert by default. MCP record tools take up to 100 records a call, and `queryRecords` returns up to 200 a page"
      },
      {
        "label": "Auth and scopes",
        "value": "Fine-grained API tokens (`nc_pat_` prefix) with eight categories (Records, Comments, Tables, Fields, Views, Webhooks, Base, Users) at Read or Read and write, chosen bases, and expiry. OAuth authorisation code grant with PKCE (S256), refresh tokens, revocation and dynamic client registration for MCP clients"
      },
      {
        "label": "Read and write",
        "value": "Records (list, get, create, update, upsert, delete, count), links, attachment upload, tables, fields, views, filters, sorts, webhooks, members, scripts, dashboards and workflows in the v3 API"
      },
      {
        "label": "Filtering",
        "value": "`where` in NocoDB's own syntax, `fields`, `sort`, `viewId`, `page` and `pageSize` on list records, with `next` and `prev` page URLs in the response"
      },
      {
        "label": "MCP server",
        "value": "Built into the product, streamable HTTP. 199 tools on NocoDB Cloud per the 2026.09.1 changelog (llms.txt says 149). Per-connection allowlist by section. Token in `x-api-key` or `xc-mcp-token`, or OAuth at https://app.nocodb.com/mcp"
      },
      {
        "label": "Errors",
        "value": "v3 errors return `{error, message}` with optional `details`, and a `requestId` matching the `x-request-id` header outside the Community Edition. Some older paths return a bare `msg`"
      },
      {
        "label": "SDKs",
        "value": "nocodb-sdk 0.301.3 on npm (JavaScript and TypeScript), under the Sustainable Use License. The `nocodb` package on PyPI is community-built"
      },
      {
        "label": "Audit",
        "value": "Workspace audit logs with user, time, base, event, IP address and JSON payload, on the Scale plan and above. Per-record change history. The MCP tools can read both"
      },
      {
        "label": "Status and SLA",
        "value": "status.nocodb.com (Kener) with two components and 90-day availability. 99.9 per cent monthly uptime commitment for Enterprise plans"
      },
      {
        "label": "Sub-processors",
        "value": "16 listed with countries, 15 in the USA and one in Germany. AWS for infrastructure. Anthropic, OpenAI and Braintrust only for customers using NocoAI"
      },
      {
        "label": "Self-hosting",
        "value": "Docker image nocodb/nocodb, free for internal use under the Sustainable Use License. Rate limits are set by environment variables. Telemetry is on unless `NC_DISABLE_TELE` is set"
      }
    ],
    "unitPrices": [
      {
        "item": "Plus",
        "unit": "seat-month",
        "usd": 12,
        "note": "billed annually, at most 9 paid seats ($108 a month), 100,000 API calls a month"
      },
      {
        "item": "Business",
        "unit": "seat-month",
        "usd": 24,
        "note": "billed annually, at most 9 paid seats ($216 a month), 1,000,000 API calls a month"
      },
      {
        "item": "Scale",
        "unit": "seat-month",
        "usd": 45,
        "note": "billed annually, 3 seats minimum, 5,000,000 API calls a month"
      }
    ],
    "provenance": {
      "legalEntity": "NocoDB Inc (doing business as NocoDB)",
      "domain": "nocodb.com",
      "domainRegistered": "2021-04-14",
      "endpointOnVendorDomain": true,
      "terms": "https://nocodb.com/docs/legal/terms-of-service",
      "privacy": "https://nocodb.com/docs/legal/privacy",
      "statusPage": "https://status.nocodb.com",
      "changelog": "https://nocodb.com/docs/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (last updated 14 October 2025) and the privacy policy (last updated 5 August 2025) name NocoDB Inc, doing business as NocoDB, and cover the website, the hosted services and the APIs. No postal address was found in the parts we read.",
        "The REST API and the MCP server answer at app.nocodb.com, a nocodb.com subdomain. A self-hosted instance answers on the owner's own domain.",
        "nocodb.com/.well-known/security.txt, nocodb.com/security.txt and app.nocodb.com/.well-known/security.txt return 404. SECURITY.md in the repository sends reports to security@nocodb.com.",
        "RDAP for nocodb.com gives a registration date of 2021-04-14.",
        "Organisations on an order form are governed by the Master Subscription Agreement (last updated 14 October 2025), which states SOC 2 Type II compliance with the report on request. The Service Level Agreement (last updated 6 October 2025) commits to 99.9 per cent monthly uptime for Enterprise plans."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "NocoDB Inc (doing business as NocoDB)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "nocodb.com, registered 2021-04-14 (5 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "app.nocodb.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.nocodb.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://nocodb.com/docs/legal/terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-14",
          "words": 8206,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 2025-10-14",
              "says": "Last updated 2025-10-14"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms will be governed by the internal substantive laws of the State of California, without respect to its conflict of laws principles.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT WILL WE OR OUR AFFILIATES, AGENTS, SUPPLIERS, OR LICENSORS (OR OUR OR THEIR EMPLOYEES, CONTRACTORS, AGENTS, OFFICERS, OR DIRECTORS) BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS IN AN AMOUNT EXCEEDING THE AMOUNT OF FEES YOU PAID TO US HEREUNDER DURING THE…",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "* (iv) your individual right to access and use our Services may be suspended or terminated (and ownership and administration of your NocoDB Account (defined below) may be transferred) if you cease to be associated with, or cease to use an email address associated with, owned by, or provisioned by, that Organization"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Any change to a Subscription Plan's pricing or payment terms will become effective in the billing cycle following notice of such change to you as provided in these Terms.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "* (ii) you represent and warrant that you have the authority to bind that Organization to these Terms (and if you do not have the authority, you may not access or use our Services)"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "**TRIAL FEATURES ARE PROVIDED TO YOU FOR TESTING PURPOSES ONLY, ON AN \"AS IS\" BASIS, WITHOUT ANY WARRANTY, LIABILITY, INDEMNITY, OR PERFORMANCE OBLIGATIONS.** Trial Features are not subject to any service level agreements or support commitments."
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may permanently or temporarily terminate or suspend your access to our Services without notice or liability, without cause or for any reason, including if in our sole discretion you violate any provision of these Terms."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "…OPT OUT PURSUANT TO THE INSTRUCTIONS IN SECTION [14.2](#142-arbitration), THE EXCLUSIVE USE OF FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS ONLY TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS, COLLECTIVE, PRIVATE ATTORNEY GENERAL OR REPRESENTATIVE ACTIONS OR PROCEEDINGS."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer grants NocoDB an irrevocable, transferable and sublicensable licence to access, use, copy, store, modify and display its content for the purposes the clause lists.",
              "quote": "us an irrevocable, transferable, sublicensable (through multiple tiers), fully paid, royalty-free, and worldwide right and license to access, use, copy, store, modify, and display Your Content solely:"
            },
            {
              "date": "2026-10-08",
              "text": "Subscription plans renew automatically for terms equal to the original term, at the price that applies on the renewal date, until the customer cancels.",
              "quote": "Unless and until canceled by you, all Subscription Plans will automatically renew for renewal terms equal in length to the original Subscription Term, at the applicable price as of the renewal date."
            },
            {
              "date": "2026-10-08",
              "text": "NocoDB may name the customer in promotional materials and says it will stop on request.",
              "quote": "We may identify you as our customer in our promotional materials. We will promptly stop doing so upon your request, which you may send by emailing [legal@nocodb.com](mailto:legal@nocodb.com)."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://nocodb.com/docs/legal/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-03-20",
          "words": 4764,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 2026-03-20",
              "says": "Last updated 2026-03-20"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Read NocoDB’s Privacy Policy to understand how we collect, use, store, and protect your personal data when you use our services."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We store your personal information for no longer than necessary for the purposes for which it was collected, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "If you create your account using a service provided by a third party such as Google or Apple, or a single-sign-on service provided by a third party such as Okta, we may collect Customer Information about you from the third-party service (such as your username or user ID associated with that third-party service)."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell or share the personal information of consumers we know to be less than 16 years of age.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "**The Right to Know** any or all of the following information relating to your personal information we have collected and disclosed in the last 12 months, upon verification of your identity:"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For instructions on how to permanently delete Content from your NocoDB Account, please contact us at [privacy@nocodb.com](mailto:privacy@nocodb.com).",
              "says": "privacy@nocodb.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "When required by law, we will ensure that we rely on an appropriate legal mechanism for the transfer, such as your consent, standard contractual clauses (or their equivalent), or adequacy decisions.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Information is disclosed to AI observability and quality assurance providers for NocoAI, and this may include conversation content, inputs and outputs.",
              "quote": "With AI observability and quality assurance providers who help us monitor, trace, evaluate, and improve the performance and quality of our AI-powered features (such as NocoAI), which may include the processing of conversation content, inputs, and outputs"
            },
            {
              "date": "2026-10-08",
              "text": "Deleted content may be kept in archived or backup copies so that revision history and base snapshots keep working.",
              "quote": "Content you delete (including Content containing personal information) may be retained in archived or backup copies in order to enable you to use certain features like revision history and base snapshots."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/nocodb.json",
    "live": {
      "slug": "nocodb",
      "probe": {
        "target": "https://app.nocodb.com",
        "method": "get",
        "lastAt": "2026-10-08T19:08:53.946941776Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 289,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 298,
        "p95ms24h": 423,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.nocodb.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:50:54.642935507Z"
      },
      "pages": [
        {
          "url": "https://nocodb.com/docs/changelog",
          "kind": "changelog",
          "status": 404,
          "checkedAt": "2026-10-08T18:22:20.469505035Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://nocodb.com/docs/legal/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:22:22.574237418Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "0c382788e85c"
        },
        {
          "url": "https://nocodb.com/docs/legal/terms-of-service",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:22:24.679133564Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "78a7b9c3e6ab"
        }
      ],
      "updatedAt": "2026-10-08T19:08:53.946941776Z"
    }
  }
}
