{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "notte",
    "name": "Notte",
    "vendor": "Notte Labs Inc.",
    "vendorUrl": "https://www.notte.cc",
    "kind": "http-api",
    "category": "browser",
    "summary": "Notte, from Notte Labs Inc., runs hosted browser sessions with web agents, scraping, search, serverless browser functions, credential vaults and personas. Access is by REST API, Python and Node SDKs, a CLI or a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/notte",
    "markdownUrl": "https://www.anchorterminal.com/tools/notte.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/notte.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/notte.json",
    "repo": "https://github.com/nottelabs/notte",
    "license": "Proprietary hosted service under Notte's terms of service. The core repository is SSPL-1.0 and the Node SDK is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.notte.cc",
    "packages": [
      {
        "registry": "pypi",
        "name": "notte-sdk"
      },
      {
        "registry": "npm",
        "name": "notte-sdk"
      },
      {
        "registry": "pypi",
        "name": "notte-mcp"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve API key from the console at console.notte.cc, sent as `Authorization: Bearer \u003ckey\u003e`. The hosted MCP server also accepts OAuth sign-in with a Notte account and a choice of workspace; its metadata lists one scope, `email`. No key scopes or rotation guidance were found in the reviewed documentation. No sales approval is needed below Enterprise.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with $10 of credits, granted once, no card, so an agent's owner can start without a contract. Credits are spent on browser functions at $0.05 an hour, residential proxies at $10 a GB and LLM tokens at the model's price. The pricing page lists browser sessions at $0 an hour on 8 October 2026. Developer is $20 a month and Startup $100, each with the same amount in monthly credits (https://www.notte.cc/pricing).",
    "priceSummary": "$0.05 / session-hr",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the OpenAPI document, the docs index or the pricing page (checked 2026-10-08). The session payment endpoints pay third-party merchants from a connected wallet and do not pay Notte.",
      "endpoints": []
    },
    "toolCount": 8,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 1299,
      "pypiWeekly": 5107,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.notte.cc",
    "llmsTxt": "https://docs.notte.cc/llms.txt",
    "openapi": "https://api.notte.cc/openapi.json",
    "capabilities": [
      "browser.control",
      "browser.hosted",
      "web.scrape",
      "web.search",
      "web.extract",
      "scraping.proxies",
      "scraping.anti-bot",
      "secrets.store"
    ],
    "tags": [
      "official",
      "hosted",
      "freemium",
      "no-card",
      "openapi",
      "llms-txt",
      "mcp",
      "oauth",
      "python",
      "typescript",
      "cli",
      "status-page",
      "soc2",
      "source-available"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 63.2,
      "grade": "B",
      "agentReady": false,
      "rank": 285,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 83,
        "payments": 40,
        "reliability": 58,
        "schema": 74,
        "security": 56,
        "transparency": 61
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 58,
          "points": 11.6,
          "reason": "Graded as a hosted API. status.notte.cc on Better Stack tracks six components with 90 days of daily history (20). In the 90 days to 8 October 2026 the core API read 100 per cent and the Session API 99.98 with two outages of about 15 minutes, but the Scrape API was down on 15 days for about 6 hours in total, including 61 minutes on 3 August and 51 on 30 August, and CAPTCHA solving read 88.93 per cent, so we score one major outage (10). Concurrency is published per plan and `X-RateLimit` headers are documented, but no request rate is stated per plan (8). The docs ask for exponential backoff on 429 and describe 529 for an overloaded cluster. The SDKs do not retry, and only the payment endpoint takes an idempotency key (10). SLAs are listed for Enterprise without published terms (0). The API is version 1.9.6 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "Graded on the REST API. OpenAPI 3.1.0 at api.notte.cc/openapi.json with 77 paths and 100 operations (25). llms.txt on the site and in the docs, a Markdown twin of every docs page and a keyless documentation MCP server (10). Every operation has a summary, 362 of 1,007 schema properties carry a description, and the guides explain each product (12). 196 schemas with 46 enums and ranges such as `max_duration_minutes` up to 1,440. `chrome_args` and `extra_http_headers` are free-form (11). The errors page shows the body format and six statuses, but 98 operations document only 422 as an error (8). The spec version matches the release tags. No dated API changelog page was found, so changes are visible only through GitHub tags and the Node SDK's CHANGELOG.md (8)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "The browser MCP endpoint has eight compact tools, and scrape accepts selectors and a structured output schema (22). List endpoints take `page` and `page_size` up to 100, and sessions filter by `only_active` (15). Errors are a `message` and `detail` with six documented statuses and an `x-error-class` header on execution failures (11). An `idempotency-key` header is required on session payments only, stopping a session is documented as safe to repeat, and the MCP docs mark three tools read-only and five as write. We could not list the tools to confirm the annotations (12). Session start has no required fields, and Python and Node SDKs and a CLI are official (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 56,
          "points": 9.8,
          "reason": "A Bearer API key from the console, or OAuth on the MCP server with one scope, `email`. No key scopes or rotation guidance found (18). The browser MCP endpoint leaves out administration tools, three of its tools are read-only, and vaults keep stored credentials away from the model. No read-only key or confirmation step found (9). Pages are untrusted content. The only guidance found is one line in the Claude managed agents guide about limiting where a credential may be sent (4). Session replays, a network log endpoint and usage logs give a per-session trail (11). A valid security.txt, a disclosure policy with safe harbour and a three-business-day acknowledgement, and a SOC 2 Type 2 report on the trust centre. The security page says there is no paid bounty (14)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 on Notte's endpoints (0). Unit prices are published without login, $0.05 an hour for browser functions, $10 a GB for residential proxies, LLM tokens at the model's price, and browser sessions listed at $0 an hour (20). Free plan with $10 of credits and no card (20). A person has to sign up in the console to create a key or approve OAuth (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "Version 1.9.6 was tagged and published to PyPI and npm on 7 October 2026 (30). 18 tags between 10 July and 7 October 2026 (20). The repository had commits on 8 October and the vendor runs a Slack community, but GitHub refused our API request, so issue reply times are unread (10 of 25). Current official SDKs in Python and Node. The hosted MCP server was not found in the official MCP registry, so we scored the SDK line for an API (15). CI runs tests, nightly examples and documentation tests. The notte-mcp package on PyPI was last published on 13 July 2026 at 1.8.28 while the SDK moved to 1.9.6 (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 61,
          "points": 5.34,
          "note": "editorial 36, provenance 86",
          "reason": "The hosted platform is closed. The core repository is public under SSPL-1.0, which is source-available and not OSI-approved, and the Node SDK is MIT (20). The privacy policy and terms answered with a bot check and were not read. The recordings page says replays are deleted after 24 hours, while an older page in the docs source gives 7 to 30 days by plan. No public DPA found (8). No deprecation policy found. The Node SDK changelog labels breaking changes and the spec marks one field deprecated (5). The trust centre page we read named no subprocessors or data locations, and other regions are an Enterprise option (3)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The browser MCP endpoint has eight compact tools, and scrape accepts selectors and a structured output schema (22). List endpoints take `page` and `page_size` up to 100, and sessions filter by `only_active` (15). Errors are a `message` and `detail` with six documented statuses and an `x-error-class` header on execution failures (11). An `idempotency-key` header is required on session payments only, stopping a session is documented as safe to repeat, and the MCP docs mark three tools read-only and five as write. We could not list the tools to confirm the annotations (12). Session start has no required fields, and Python and Node SDKs and a CLI are official (15).",
          "maintenance": "Version 1.9.6 was tagged and published to PyPI and npm on 7 October 2026 (30). 18 tags between 10 July and 7 October 2026 (20). The repository had commits on 8 October and the vendor runs a Slack community, but GitHub refused our API request, so issue reply times are unread (10 of 25). Current official SDKs in Python and Node. The hosted MCP server was not found in the official MCP registry, so we scored the SDK line for an API (15). CI runs tests, nightly examples and documentation tests. The notte-mcp package on PyPI was last published on 13 July 2026 at 1.8.28 while the SDK moved to 1.9.6 (8).",
          "payments": "No x402, MPP or L402 on Notte's endpoints (0). Unit prices are published without login, $0.05 an hour for browser functions, $10 a GB for residential proxies, LLM tokens at the model's price, and browser sessions listed at $0 an hour (20). Free plan with $10 of credits and no card (20). A person has to sign up in the console to create a key or approve OAuth (0).",
          "reliability": "Graded as a hosted API. status.notte.cc on Better Stack tracks six components with 90 days of daily history (20). In the 90 days to 8 October 2026 the core API read 100 per cent and the Session API 99.98 with two outages of about 15 minutes, but the Scrape API was down on 15 days for about 6 hours in total, including 61 minutes on 3 August and 51 on 30 August, and CAPTCHA solving read 88.93 per cent, so we score one major outage (10). Concurrency is published per plan and `X-RateLimit` headers are documented, but no request rate is stated per plan (8). The docs ask for exponential backoff on 429 and describe 529 for an overloaded cluster. The SDKs do not retry, and only the payment endpoint takes an idempotency key (10). SLAs are listed for Enterprise without published terms (0). The API is version 1.9.6 (10).",
          "schema": "Graded on the REST API. OpenAPI 3.1.0 at api.notte.cc/openapi.json with 77 paths and 100 operations (25). llms.txt on the site and in the docs, a Markdown twin of every docs page and a keyless documentation MCP server (10). Every operation has a summary, 362 of 1,007 schema properties carry a description, and the guides explain each product (12). 196 schemas with 46 enums and ranges such as `max_duration_minutes` up to 1,440. `chrome_args` and `extra_http_headers` are free-form (11). The errors page shows the body format and six statuses, but 98 operations document only 422 as an error (8). The spec version matches the release tags. No dated API changelog page was found, so changes are visible only through GitHub tags and the Node SDK's CHANGELOG.md (8).",
          "security": "A Bearer API key from the console, or OAuth on the MCP server with one scope, `email`. No key scopes or rotation guidance found (18). The browser MCP endpoint leaves out administration tools, three of its tools are read-only, and vaults keep stored credentials away from the model. No read-only key or confirmation step found (9). Pages are untrusted content. The only guidance found is one line in the Claude managed agents guide about limiting where a credential may be sent (4). Session replays, a network log endpoint and usage logs give a per-session trail (11). A valid security.txt, a disclosure policy with safe harbour and a three-business-day acknowledgement, and a SOC 2 Type 2 report on the trust centre. The security page says there is no paid bounty (14).",
          "transparency": "The hosted platform is closed. The core repository is public under SSPL-1.0, which is source-available and not OSI-approved, and the Node SDK is MIT (20). The privacy policy and terms answered with a bot check and were not read. The recordings page says replays are deleted after 24 hours, while an older page in the docs source gives 7 to 30 days by plan. No public DPA found (8). No deprecation policy found. The Node SDK changelog labels breaking changes and the spec marks one field deprecated (5). The trust centre page we read named no subprocessors or data locations, and other regions are an Enterprise option (3)."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://docs.notte.cc/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "site llms.txt",
            "url": "https://www.notte.cc/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document",
            "url": "https://api.notte.cc/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "API authentication",
            "url": "https://docs.notte.cc/api-reference/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API errors",
            "url": "https://docs.notte.cc/api-reference/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API rate limits",
            "url": "https://docs.notte.cc/api-reference/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK rate-limit guidance",
            "url": "https://docs.notte.cc/sdk-reference/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://docs.notte.cc/mcp-server.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP resource metadata",
            "url": "https://api.notte.cc/.well-known/oauth-protected-resource/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing and plan limits",
            "url": "https://www.notte.cc/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "status page JSON",
            "url": "https://status.notte.cc/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.notte.cc/",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://www.notte.cc/security",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.notte.cc/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "bug bounty page in docs",
            "url": "https://docs.notte.cc/legal/bug-bounty.md",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://trust.notte.cc/",
            "seen": "2026-10-08"
          },
          {
            "what": "vault docs",
            "url": "https://docs.notte.cc/concepts/vaults.md",
            "seen": "2026-10-08"
          },
          {
            "what": "session recordings",
            "url": "https://docs.notte.cc/features/sessions/recordings.md",
            "seen": "2026-10-08"
          },
          {
            "what": "repository, tags, licence, CI and docs source",
            "url": "https://github.com/nottelabs/notte",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK changelog",
            "url": "https://github.com/nottelabs/notte/blob/main/node-sdk/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/notte-sdk/json",
            "seen": "2026-10-08"
          },
          {
            "what": "notte-mcp on PyPI",
            "url": "https://pypi.org/pypi/notte-mcp/json",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK on npm",
            "url": "https://registry.npmjs.org/notte-sdk/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/notte-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI weekly downloads",
            "url": "https://pypistats.org/api/packages/notte-sdk/recent",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search (no result)",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=notte",
            "seen": "2026-10-08"
          },
          {
            "what": "API health response",
            "url": "https://api.notte.cc/health",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/notte.cc",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the terms of service and privacy policy at console.notte.cc/terms and /privacy. Both answered 429 with a Vercel security checkpoint, so the entity named, dates, data handling, SLA and governing law are unread and `provenance.terms` and `provenance.privacy` hold the linked addresses only",
          "unchecked: GitHub stars and open-issue reply times. The GitHub API refused us for its rate limit, so `githubStars` is empty",
          "unchecked: the MCP tool definitions and annotations. Listing tools needs a login, so the tool count and read or write hints come from the docs",
          "unchecked: whether the console allows several API keys, revocation or scopes. The console needs a login",
          "unchecked: the SOC 2 Type 2 report itself, and whether the trust centre lists subprocessors or a DPA behind a request form",
          "The pricing page and the docs source both list browser sessions at $0 an hour. We recorded the figure as published and left it out of the unit prices, because we could not tell whether session time is free or the rate is unset",
          "The docs source still holds an older limits page (Free with 2 concurrent browsers, replay retention of 7 to 30 days) that disagrees with the live pricing page and the recordings page",
          "The security page says no paid bug bounty runs, while docs.notte.cc/legal/bug-bounty describes discretionary rewards of $50 to $500",
          "The Node SDK changelog lists removal of vault credit card storage as a breaking change under Unreleased, while the OpenAPI document still has the vault credit card endpoints",
          "The lead said MCP support was not shown. A hosted MCP server is documented at https://api.notte.cc/mcp",
          "The docs open every page with a note telling AI agents to read notte.cc/skill.md and follow its setup steps. We treated it as page content and did not act on it"
        ]
      },
      "negative": 0,
      "verdict": "Notte publishes an OpenAPI 3.1 contract for 100 operations, a hosted MCP server with eight tools and OAuth, and a free plan with $10 of credits and no card. Its status page records about six hours of Scrape API downtime in 90 days, and a bot check blocked our read of the terms and privacy policy.",
      "bestFor": "Teams that want hosted browsers together with agents, vaults for logins, personas with mailboxes and scheduled browser functions behind one key.",
      "strengths": [
        "OpenAPI 3.1 at api.notte.cc/openapi.json with 77 paths and 100 operations, plus llms.txt, Markdown twins of the docs and a keyless documentation MCP server",
        "Hosted MCP server at https://api.notte.cc/mcp with eight tools, three marked read-only, signed in by OAuth or a Bearer API key",
        "Free plan with $10 of non-expiring credits and no card, 5 concurrent browsers and 15-minute sessions, per the pricing page",
        "Vaults substitute stored credentials at fill time, so the model handling the page never receives them, per the vault docs",
        "18 tagged releases between 10 July and 7 October 2026, with the Python and Node SDKs both at 1.9.6"
      ],
      "weaknesses": [
        "status.notte.cc shows the Scrape API down on 15 of 90 days (about 6 hours in total) and CAPTCHA solving at 88.9 per cent availability",
        "No request rate limit is stated per plan. The docs describe `X-RateLimit` headers and show a limit of 100 only as an example",
        "A Vercel bot check answered 429 on the terms of service and privacy policy at console.notte.cc, so we could not read either",
        "The core repository is under SSPL-1.0, which is not an OSI-approved licence. Only the Node SDK is MIT",
        "No API key scopes, deprecation policy, subprocessor list or public DPA found in the reviewed documentation"
      ],
      "agentNotes": [
        "Send `Authorization: Bearer $NOTTE_API_KEY` to https://api.notte.cc. A person creates the key in the console at console.notte.cc first",
        "Stop every session when the task ends. Sessions close after 3 idle minutes or 15 minutes in total by default, and the Free plan caps a session at 15 minutes",
        "Use https://api.notte.cc/mcp for browser work. Function and agent administration tools are only on https://api.notte.cc/mcp/full",
        "Back off on 429 and on 529, which means the cluster has too many sessions. The SDKs do not retry rate limits for you",
        "Download session replays within 24 hours. The recordings page says they are deleted after that"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 63.2
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 83,
        "payments": 40,
        "reliability": 58,
        "schema": 74,
        "security": 56,
        "transparency": 36
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "pip install notte-sdk",
      "http": "curl https://api.notte.cc/sessions -H \"Authorization: Bearer $NOTTE_API_KEY\"",
      "claudeCode": "claude mcp add --transport http notte https://api.notte.cc/mcp",
      "config": {
        "mcpServers": {
          "notte": {
            "headers": {
              "Authorization": "Bearer \u003cyour-notte-api-key\u003e"
            },
            "url": "https://api.notte.cc/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/browser.control",
      "tool": "https://letme.dev/notte"
    },
    "notable": [
      "Hosted MCP server at https://api.notte.cc/mcp with eight tools (manage_browsers, browser_observe, browser_scrape, browser_screenshot, browser_action, manage_files, manage_profiles, manage_auth). A wider endpoint at /mcp/full adds function and agent administration (https://docs.notte.cc/mcp-server.md)",
      "The MCP resource metadata names a Supabase authorisation server and one supported scope, `email`. An unauthenticated tools/list on 8 October 2026 returned 401 with a `resource_metadata` pointer (https://api.notte.cc/.well-known/oauth-protected-resource/mcp)",
      "The pricing page lists browser sessions at $0 an hour, browser functions at $0.05 an hour, residential proxies at $10 a GB and LLM tokens at the model's price with no markup (https://www.notte.cc/pricing)",
      "status.notte.cc on Better Stack tracks six components. In the 90 days to 8 October 2026 the core API and console read 100 per cent, the Session API 99.98, the Scrape API 99.72, proxies 99.82 and CAPTCHA solving 88.93 (https://status.notte.cc/index.json)",
      "The core repository nottelabs/notte is under SSPL-1.0 and the Node SDK folder is MIT, per COPYRIGHT.md (https://github.com/nottelabs/notte)",
      "The security page says Notte runs no paid bug bounty, while the docs page titled Bug Bounty describes discretionary rewards of $50 to $500 (https://www.notte.cc/security, https://docs.notte.cc/legal/bug-bounty.md)",
      "The trust centre shows a SOC 2 Type 2 report. No subprocessor list or DPA was visible on the page we read (https://trust.notte.cc/)",
      "The API includes session payment endpoints that let an agent pay a merchant from a connected wallet, with an `idempotency-key` header required. They are not a way to pay Notte (https://api.notte.cc/openapi.json)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST API at https://api.notte.cc (OpenAPI 3.1.0, version 1.9.6, 77 paths, 100 operations) with its Python and Node SDKs. The hosted MCP server is described from its docs, because listing its tools needs a login"
      },
      {
        "label": "API groups",
        "value": "Sessions 22 operations, functions 18, vaults 11, profiles 7, personas 7, managed auth 7, mailboxes 6, agents 5, secrets 4, payments 3, plus scrape, search, usage and health"
      },
      {
        "label": "Browser control",
        "value": "Observe, execute and scrape endpoints on a session, CDP for Playwright, Puppeteer and Selenium, a live view, and four browser types (chromium, chrome, chrome-nightly, chrome-turbo)"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://api.notte.cc/mcp, eight tools, OAuth sign-in or a Bearer API key. /mcp/full adds function and agent administration. A documentation server at https://docs.notte.cc/mcp needs no key. Not found in the official MCP registry"
      },
      {
        "label": "Free plan",
        "value": "$10 of credits granted once with no expiry and no card, 5 concurrent browsers, 5 concurrent agents or functions, 5 vaults, 5 personas, 15-minute sessions"
      },
      {
        "label": "Plans",
        "value": "Developer $20 a month with $20 of credits, 25 concurrent browsers and 120-minute sessions. Startup $100 a month with $100 of credits, 100 concurrent browsers, 300-minute sessions and bring-your-own keys and proxies. Enterprise custom"
      },
      {
        "label": "Rate limits",
        "value": "Concurrency per plan (5, 25, 100, custom). Responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. No requests-per-minute number is stated per plan"
      },
      {
        "label": "Errors",
        "value": "JSON with `message` and `detail`. Documented statuses are 401, 422, 429, 500 and 529 (cluster overloaded). Execution failures carry an `x-error-class: NotteApiExecutionError` header"
      },
      {
        "label": "Session defaults",
        "value": "No required fields. 15 minutes maximum (up to 1,440), 3 minutes idle timeout (up to 30), CAPTCHA solving and ad blocking on by default"
      },
      {
        "label": "SDKs",
        "value": "notte-sdk 1.9.6 on PyPI (Python 3.11 or later) and notte-sdk 1.9.6 on npm (Node 20 or later, MIT), both released 7 October 2026. A CLI installs with `brew install notte`"
      },
      {
        "label": "Recording",
        "value": "Session replays are kept for 24 hours, then deleted, per the recordings page. A session also exposes network logs and debug info endpoints"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 per trust.notte.cc. The pricing page lists HIPAA, SSO and SLAs under Enterprise"
      },
      {
        "label": "Licence",
        "value": "Hosted service under Notte's terms. Core repository SSPL-1.0, Node SDK MIT"
      }
    ],
    "unitPrices": [
      {
        "item": "Browser function runtime",
        "unit": "session-hour",
        "usd": 0.05,
        "note": "Rounded by Notte's billing policy"
      },
      {
        "item": "Residential proxy traffic",
        "unit": "gb",
        "usd": 10,
        "note": "Billed only when proxies are enabled"
      },
      {
        "item": "Developer plan",
        "unit": "month",
        "usd": 20,
        "note": "$20 of credits a month, 25 concurrent browsers"
      },
      {
        "item": "Startup plan",
        "unit": "month",
        "usd": 100,
        "note": "$100 of credits a month, 100 concurrent browsers"
      }
    ],
    "provenance": {
      "legalEntity": "Notte Labs Inc.",
      "domain": "notte.cc",
      "domainRegistered": "2024-09-25",
      "endpointOnVendorDomain": true,
      "terms": "https://console.notte.cc/terms",
      "privacy": "https://console.notte.cc/privacy",
      "statusPage": "https://status.notte.cc",
      "changelog": "https://github.com/nottelabs/notte/blob/main/node-sdk/CHANGELOG.md",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The site footer reads Notte Labs Inc. and COPYRIGHT.md in the repository reads Notte Labs, Inc.",
        "The site footer and llms.txt link the terms of service and privacy policy at console.notte.cc. Both answered 429 with a Vercel security checkpoint on 8 October 2026, so neither was read and their scope and dates are unconfirmed.",
        "The API and the hosted MCP server answer at api.notte.cc. The MCP authorisation server is a supabase.co host.",
        "www.notte.cc/.well-known/security.txt names security@notte.cc, a policy at www.notte.cc/security and an expiry of 17 September 2027.",
        "RDAP for notte.cc gives a registration date of 2024-09-25 and Tucows Domains Inc. as registrar.",
        "No changelog page was found in the docs. Dated changes come from GitHub tags and the Node SDK's CHANGELOG.md."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Notte Labs Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "notte.cc, registered 2024-09-25 (2 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.notte.cc",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.notte.cc",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://console.notte.cc/terms",
          "state": "unreadable",
          "reason": "the page answered HTTP 429 to our reader",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://console.notte.cc/privacy",
          "state": "unreadable",
          "reason": "the page answered HTTP 429 to our reader",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/notte.json",
    "live": {
      "slug": "notte",
      "probe": {
        "target": "https://api.notte.cc",
        "method": "get",
        "lastAt": "2026-10-08T19:08:54.052722798Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 360,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 385,
        "p95ms24h": 578,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.notte.cc",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:50:54.768128476Z"
      },
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/nottelabs/notte/main/node-sdk/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:33.737584359Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "3037f444edaa"
        },
        {
          "url": "https://www.notte.cc/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:29:23.383772418Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b9387c8cc40f"
        },
        {
          "url": "https://console.notte.cc/privacy",
          "kind": "privacy",
          "status": 429,
          "checkedAt": "2026-10-08T18:16:40.844983356Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://console.notte.cc/terms",
          "kind": "terms",
          "status": 429,
          "checkedAt": "2026-10-08T18:16:42.860158607Z",
          "changedAt": "0001-01-01T00:00:00Z"
        }
      ],
      "updatedAt": "2026-10-08T19:08:54.052722798Z"
    }
  }
}
