{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "opensearch",
    "name": "OpenSearch",
    "vendor": "OpenSearch Software Foundation",
    "vendorUrl": "https://opensearch.org",
    "kind": "http-api",
    "category": "vector-search",
    "summary": "OpenSearch is an open-source search and analytics engine with vector, text and hybrid search, run by its owner. Agents reach it through a REST API, official clients, an OpenSearch MCP Server and an MCP endpoint inside the cluster.",
    "url": "https://www.anchorterminal.com/tools/opensearch",
    "markdownUrl": "https://www.anchorterminal.com/tools/opensearch.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opensearch.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opensearch.json",
    "repo": "https://github.com/opensearch-project/OpenSearch",
    "license": "Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server",
    "transports": [
      "http",
      "stdio"
    ],
    "packages": [
      {
        "registry": "oci",
        "name": "opensearchproject/opensearch"
      },
      {
        "registry": "pypi",
        "name": "opensearch-mcp-server-py"
      },
      {
        "registry": "pypi",
        "name": "opensearch-py"
      }
    ],
    "auth": "mixed",
    "authNotes": "The owner sets access up on their own cluster. The Security plugin accepts basic auth, client certificates, JWT, OpenID Connect and SAML, and since 3.7 API keys sent as `Authorization: ApiKey \u003ctoken\u003e`. Only a security administrator can create, list or revoke a key. Each key names cluster permissions and index patterns with allowed actions, lasts 90 days at most, and cannot reach system indexes or the Security API. API keys are off until enabled in `config.yml`. The MCP server takes basic auth, AWS IAM, request headers or mTLS, or no authentication.",
    "pricing": "free",
    "pricingNotes": "Free software under Apache-2.0 with nothing to buy from the foundation, so an agent can start on a local Docker container with no account or contract. The owner pays for the machines. Three certified vendors sell long-term support, and opensearch.org lists no price for it (checked 2026-10-09).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the documentation source, the API specification or the MCP server source (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 9,
    "popularity": {
      "githubStars": 13800,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.opensearch.org/latest/vector-search/",
    "openapi": "https://api-spec.opensearch.org/opensearch-openapi.yaml",
    "capabilities": [
      "db.vector",
      "db.hybrid",
      "db.fulltext",
      "db.filters"
    ],
    "tags": [
      "open-source",
      "self-hosted",
      "http-api",
      "mcp",
      "docker",
      "openapi",
      "api-key",
      "python",
      "javascript",
      "java",
      "go",
      "free"
    ],
    "lastRelease": "2026-09-22",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68,
      "grade": "B",
      "agentReady": false,
      "rank": 233,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 80,
        "maintenance": 84,
        "payments": 60,
        "reliability": 77,
        "schema": 77,
        "security": 70,
        "transparency": 57
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 77,
          "points": 15.4,
          "reason": "Read with the local-software lines, because the foundation runs no hosted service and the owner runs the cluster. No status page or SLA exists for the software. Docker image `opensearchproject/opensearch`, tarball, RPM and Debian packages with a bundled JDK (20). The core repository holds 24 public workflows, among them `gradle-check.yml`, `codeql-analysis.yml` and `detect-breaking-change.yml`. Whether the default branch passes was not checked (15 of 25). GitHub shows about 2,500 open issues, and 21 of the 25 newest carried the `untriaged` label on 9 October 2026, most of them one to three days old (12 of 25). The releases page states semantic versioning with breaking changes only in major versions, and a breaking-changes page lists them per version (15). Version 3.9.0, with 1.0 in July 2021 (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "OpenAPI 3.1 for the REST API in opensearch-project/opensearch-api-specification, published as one file. We counted about 717 operations in 36 namespace files in the source (25). No `llms.txt` on docs.opensearch.org (HTTP 404). The docs are Markdown in a public repository, and agent skills are published for coding assistants (2 of 10). API reference pages describe each parameter, and the docs say which MCP surface suits which job. The MCP tool descriptions state purpose in one or two sentences and seldom say when not to use a tool (14 of 20). Parameters are typed in the specification, with enums such as `op_type`. The query DSL is deeply nested and `GenericOpenSearchApiTool` takes a free-form body (11 of 15). Request and response examples on most reference pages. No catalogue of error types was found in the pages read (10 of 15). A version history with dated release notes, a breaking-changes page and a changelog for the specification (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 80,
          "points": 13,
          "reason": "Responses are sized with `size`, `_source` and `filter_path`. The MCP server starts with nine core tools and keeps four more categories off until enabled, and hides connection fields from tool schemas once a cluster is configured (22 of 25). `from` and `size`, `search_after`, point in time, and filters inside or outside the k-NN clause (20). Errors come back as JSON with a type and reason, 429 is documented for concurrency limits, and the MCP server sets `isError` since 0.11.0. No error catalogue (13 of 20). `op_type=create`, `if_seq_no` and `if_primary_term` make writes safe to repeat. No MCP tool sets `readOnlyHint` or `destructiveHint` in the source at 0.12.0 (12 of 20). Official clients in eight languages. A vector index needs a mapping before any search (13 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 70,
          "points": 12.25,
          "reason": "API keys since 3.7 carry cluster and index permissions, expire within 90 days at most and are revoked on all nodes at once. They are off until enabled, and only a security administrator can create them. Basic auth, client certificates, JWT, OpenID Connect and SAML also work (27 of 30). Roles with document-level and field-level security allow read-only access to named indexes. The MCP server allows writes by default and has no confirmation step, though `OPENSEARCH_SETTINGS_ALLOW_WRITE=false` blocks write methods (14 of 20). Search returns stored documents as written, and no prompt-injection guidance was found. The MCP server has an opt-in guard that restricts caller-named URLs to public addresses (3 of 15). Audit logs with configurable categories, an `API_TOKEN_WRITE` category for keys, and structured JSON logs of every MCP tool call (14 of 15). `SECURITY.md` with a reporting address, published advisories, CodeQL in CI and a stated 60-day target for fixing known vulnerabilities. No security.txt (HTTP 404), and no bug bounty or certification found (12 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Read with the self-hosted rule. Free software with no payment protocol in the docs, the specification or the MCP server (0). Nothing to buy from the foundation, so no price to publish (20). No card or trial needed (20). An agent can pull the Docker image and call the API with no signup (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 84,
          "points": 7.35,
          "reason": "OpenSearch 3.9.0 was tagged on 22 September 2026, 17 days before the check (30). Core releases 3.8.0 on 31 July and 3.9.0 on 22 September, and MCP server releases 0.11.0 on 28 July and 0.12.0 on 17 September, fall inside 90 days. The core alone has two (20). 200 commits reached the core's main branch between 18 August and 9 October 2026, and new issues are labelled within days, but about 2,500 stay open. Reply times were not sampled (15 of 25). Official clients in eight languages are listed in the docs. Their current versions and the MCP registry were not checked (10 of 15). Dependabot, CodeQL and a breaking-change detector run in the core repository, and the MCP server pins patched `aiohttp` and `click` versions (9 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 57,
          "points": 4.99,
          "note": "editorial 69, provenance 45",
          "reason": "Apache-2.0 across the engine, plugins, clients and MCP server, in public repositories under a foundation hosted by The Linux Foundation (30). The software runs on the owner's machines and the data stays there. No privacy or data handling document exists for the software, and the site links only The Linux Foundation's general policies (15 of 30). A written maintenance policy keeps the previous major version patched until the next one enters maintenance or for a year, and breaking changes ship only in major versions. No notice period for removing a single API was found (16 of 20). No statement on telemetry was found in the install or about pages read. The MCP server adds a `User-Agent` naming itself to requests it sends to the cluster (8 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses are sized with `size`, `_source` and `filter_path`. The MCP server starts with nine core tools and keeps four more categories off until enabled, and hides connection fields from tool schemas once a cluster is configured (22 of 25). `from` and `size`, `search_after`, point in time, and filters inside or outside the k-NN clause (20). Errors come back as JSON with a type and reason, 429 is documented for concurrency limits, and the MCP server sets `isError` since 0.11.0. No error catalogue (13 of 20). `op_type=create`, `if_seq_no` and `if_primary_term` make writes safe to repeat. No MCP tool sets `readOnlyHint` or `destructiveHint` in the source at 0.12.0 (12 of 20). Official clients in eight languages. A vector index needs a mapping before any search (13 of 15).",
          "maintenance": "OpenSearch 3.9.0 was tagged on 22 September 2026, 17 days before the check (30). Core releases 3.8.0 on 31 July and 3.9.0 on 22 September, and MCP server releases 0.11.0 on 28 July and 0.12.0 on 17 September, fall inside 90 days. The core alone has two (20). 200 commits reached the core's main branch between 18 August and 9 October 2026, and new issues are labelled within days, but about 2,500 stay open. Reply times were not sampled (15 of 25). Official clients in eight languages are listed in the docs. Their current versions and the MCP registry were not checked (10 of 15). Dependabot, CodeQL and a breaking-change detector run in the core repository, and the MCP server pins patched `aiohttp` and `click` versions (9 of 10).",
          "payments": "Read with the self-hosted rule. Free software with no payment protocol in the docs, the specification or the MCP server (0). Nothing to buy from the foundation, so no price to publish (20). No card or trial needed (20). An agent can pull the Docker image and call the API with no signup (20).",
          "reliability": "Read with the local-software lines, because the foundation runs no hosted service and the owner runs the cluster. No status page or SLA exists for the software. Docker image `opensearchproject/opensearch`, tarball, RPM and Debian packages with a bundled JDK (20). The core repository holds 24 public workflows, among them `gradle-check.yml`, `codeql-analysis.yml` and `detect-breaking-change.yml`. Whether the default branch passes was not checked (15 of 25). GitHub shows about 2,500 open issues, and 21 of the 25 newest carried the `untriaged` label on 9 October 2026, most of them one to three days old (12 of 25). The releases page states semantic versioning with breaking changes only in major versions, and a breaking-changes page lists them per version (15). Version 3.9.0, with 1.0 in July 2021 (15).",
          "schema": "OpenAPI 3.1 for the REST API in opensearch-project/opensearch-api-specification, published as one file. We counted about 717 operations in 36 namespace files in the source (25). No `llms.txt` on docs.opensearch.org (HTTP 404). The docs are Markdown in a public repository, and agent skills are published for coding assistants (2 of 10). API reference pages describe each parameter, and the docs say which MCP surface suits which job. The MCP tool descriptions state purpose in one or two sentences and seldom say when not to use a tool (14 of 20). Parameters are typed in the specification, with enums such as `op_type`. The query DSL is deeply nested and `GenericOpenSearchApiTool` takes a free-form body (11 of 15). Request and response examples on most reference pages. No catalogue of error types was found in the pages read (10 of 15). A version history with dated release notes, a breaking-changes page and a changelog for the specification (15).",
          "security": "API keys since 3.7 carry cluster and index permissions, expire within 90 days at most and are revoked on all nodes at once. They are off until enabled, and only a security administrator can create them. Basic auth, client certificates, JWT, OpenID Connect and SAML also work (27 of 30). Roles with document-level and field-level security allow read-only access to named indexes. The MCP server allows writes by default and has no confirmation step, though `OPENSEARCH_SETTINGS_ALLOW_WRITE=false` blocks write methods (14 of 20). Search returns stored documents as written, and no prompt-injection guidance was found. The MCP server has an opt-in guard that restricts caller-named URLs to public addresses (3 of 15). Audit logs with configurable categories, an `API_TOKEN_WRITE` category for keys, and structured JSON logs of every MCP tool call (14 of 15). `SECURITY.md` with a reporting address, published advisories, CodeQL in CI and a stated 60-day target for fixing known vulnerabilities. No security.txt (HTTP 404), and no bug bounty or certification found (12 of 20).",
          "transparency": "Apache-2.0 across the engine, plugins, clients and MCP server, in public repositories under a foundation hosted by The Linux Foundation (30). The software runs on the owner's machines and the data stays there. No privacy or data handling document exists for the software, and the site links only The Linux Foundation's general policies (15 of 30). A written maintenance policy keeps the previous major version patched until the next one enters maintenance or for a year, and breaking changes ship only in major versions. No notice period for removing a single API was found (16 of 20). No statement on telemetry was found in the install or about pages read. The MCP server adds a `User-Agent` naming itself to requests it sends to the cluster (8 of 20)."
        },
        "sources": [
          {
            "what": "vector search docs, source of docs.opensearch.org at 3.9",
            "url": "https://docs.opensearch.org/latest/vector-search/",
            "seen": "2026-10-09"
          },
          {
            "what": "filtering vector search results",
            "url": "https://docs.opensearch.org/latest/vector-search/filter-search-knn/index/",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server APIs in ML Commons",
            "url": "https://docs.opensearch.org/latest/ml-commons-plugin/api/mcp-server-apis/index/",
            "seen": "2026-10-09"
          },
          {
            "what": "AI agent integrations and agent skills",
            "url": "https://docs.opensearch.org/latest/ai-agent-integrations/",
            "seen": "2026-10-09"
          },
          {
            "what": "API keys",
            "url": "https://docs.opensearch.org/latest/security/access-control/api-keys/",
            "seen": "2026-10-09"
          },
          {
            "what": "concurrency limits and 429",
            "url": "https://docs.opensearch.org/latest/tuning-your-cluster/availability-and-recovery/concurrency-limits/",
            "seen": "2026-10-09"
          },
          {
            "what": "version history",
            "url": "https://docs.opensearch.org/latest/version-history/",
            "seen": "2026-10-09"
          },
          {
            "what": "breaking changes",
            "url": "https://docs.opensearch.org/latest/breaking-changes/",
            "seen": "2026-10-09"
          },
          {
            "what": "docs source repository, read from a shallow clone",
            "url": "https://github.com/opensearch-project/documentation-website",
            "seen": "2026-10-09"
          },
          {
            "what": "release schedule and maintenance policy",
            "url": "https://opensearch.org/releases/",
            "seen": "2026-10-09"
          },
          {
            "what": "foundation page",
            "url": "https://opensearch.org/foundation/",
            "seen": "2026-10-09"
          },
          {
            "what": "long-term support page",
            "url": "https://opensearch.org/long-term-support/",
            "seen": "2026-10-09"
          },
          {
            "what": "core repository, tags, workflows and SECURITY.md from a shallow clone, stars and open issues from the page",
            "url": "https://github.com/opensearch-project/OpenSearch",
            "seen": "2026-10-09"
          },
          {
            "what": "newest open issues in the core repository",
            "url": "https://github.com/opensearch-project/OpenSearch/issues",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server source, README, user guide and changelog at 0.12.0",
            "url": "https://github.com/opensearch-project/opensearch-mcp-server-py",
            "seen": "2026-10-09"
          },
          {
            "what": "API specification source and changelog",
            "url": "https://github.com/opensearch-project/opensearch-api-specification",
            "seen": "2026-10-09"
          },
          {
            "what": "Security plugin advisories",
            "url": "https://github.com/opensearch-project/security/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "core advisories, newest dated 30 November 2023",
            "url": "https://github.com/opensearch-project/OpenSearch/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server advisories, none published",
            "url": "https://github.com/opensearch-project/opensearch-mcp-server-py/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt, HTTP 404",
            "url": "https://opensearch.org/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP record for opensearch.org",
            "url": "https://rdap.org/domain/opensearch.org",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: whether the core's `gradle-check` and other workflows pass on the default branch",
          "unchecked: PyPI and npm download counts, and the current versions of the official clients",
          "unchecked: whether the MCP server is in the official MCP registry. No `server.json` is in its repository",
          "unchecked: issue reply times in the core repository. Only the newest page of open issues was read",
          "unchecked: the published OpenAPI file at api-spec.opensearch.org. The count of about 717 operations comes from the YAML source and a pattern match, so it is approximate",
          "unchecked: where https://opensearch.org/llms.txt redirects. It answered 301 and was not followed",
          "Whether OpenSearch or OpenSearch Dashboards sends any usage telemetry. No statement was found in the pages read",
          "The date 3.9.0 was announced to the public. `lastRelease` is the tag date, 22 September 2026, and the schedule's window closed on 29 September",
          "The maintenance table on the releases page still names 3.7.0 as the latest minor version of the 3 line",
          "The docs page for the MCP server asks for Python 3.11 or later, while the package's `pyproject.toml` says 3.10 or later",
          "The lead held. The docs site has no `llms.txt`, and terms and privacy are left unset because the foundation publishes none for the software"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "Until 0.12.0 (fix merged 3 August 2026, released 17 September 2026) the OpenSearch MCP Server attached its own configured credentials to any cluster URL a caller named in dynamic connection mode, which had shipped in 0.10.0 on 2 June 2026. The fix is described in the changelog and commit, and the repository lists no published advisory. Three points (https://github.com/opensearch-project/opensearch-mcp-server-py/blob/main/CHANGELOG.md).",
        "The Security plugin published four advisories on 30 April 2026, one moderate (GHSA-x83w-23jp-g6pw, document-level security not applied to documents linked by `has_child` or `has_parent`) and three low. Fixed and disclosed, so two points (https://github.com/opensearch-project/security/security/advisories)."
      ],
      "verdict": "OpenSearch 3.9.0 runs vector, text and hybrid search under Apache-2.0, with an OpenAPI 3.1 description of its REST API and API keys limited by permission and index pattern. The owner runs the cluster, no status page or SLA comes with the software, and no tool in the MCP server sets a read-only or destructive annotation.",
      "bestFor": "A team that already runs OpenSearch for logs or text search and wants vectors and hybrid search in the same cluster, with fine-grained access control.",
      "strengths": [
        "Apache-2.0 for the engine, the plugins, the clients and the MCP server, under a foundation hosted by The Linux Foundation",
        "An OpenAPI 3.1 description of the REST API is published as one file, with about 717 operations in 36 namespace files in the source repository",
        "API keys since 3.7 carry cluster and index permissions, expire within 90 days at most, and are revoked on every node at once",
        "Approximate k-NN with filters applied during the search on the Lucene and Faiss engines, plus hybrid and neural sparse search",
        "Releases follow a published schedule about every eight weeks. 3.8.0 was tagged on 31 July and 3.9.0 on 22 September 2026"
      ],
      "weaknesses": [
        "No hosted service from the foundation. The owner installs, secures and runs the cluster, and no status page or SLA exists for the software",
        "No `llms.txt` on docs.opensearch.org (HTTP 404), and doc pages carry about 160 KB of navigation text each",
        "The MCP server allows writes by default (`OPENSEARCH_SETTINGS_ALLOW_WRITE` is `true`) and no tool sets `readOnlyHint` or `destructiveHint`",
        "Before version 0.12.0 the MCP server sent its own configured credentials to any cluster URL a caller named. No advisory was published",
        "The core repository shows about 2,500 open issues, and 21 of the 25 newest carried the `untriaged` label on 9 October 2026"
      ],
      "agentNotes": [
        "Create the index with `index.knn` set to true and a `knn_vector` field of the right dimension before indexing vectors",
        "Put the `filter` clause inside the `knn` query for filtering during the search. A filter outside it runs afterwards and can return fewer than `k` hits",
        "Ask a security administrator for an API key and send it as `Authorization: ApiKey \u003ctoken\u003e`. The token is shown once and lasts 90 days at most",
        "Use `size`, `_source` and `filter_path` to keep responses small, and `search_after` with a point in time for deep paging",
        "Set `OPENSEARCH_SETTINGS_ALLOW_WRITE=false` on the MCP server unless writes are needed. `GenericOpenSearchApiTool` can call any endpoint"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68
        }
      ],
      "editorialScores": {
        "ergonomics": 80,
        "maintenance": 84,
        "payments": 60,
        "reliability": 77,
        "schema": 77,
        "security": 70,
        "transparency": 69
      },
      "provenanceScore": 45
    },
    "connect": {
      "install": "docker run -d -p 9200:9200 -p 9600:9600 -e \"discovery.type=single-node\" -e \"OPENSEARCH_INITIAL_ADMIN_PASSWORD=\u003ccustom-admin-password\u003e\" opensearchproject/opensearch:latest",
      "http": "curl https://localhost:9200 -ku admin:\"\u003ccustom-admin-password\u003e\"",
      "config": {
        "mcpServers": {
          "opensearch": {
            "args": [
              "opensearch-mcp-server-py"
            ],
            "command": "uvx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/db.vector",
      "tool": "https://letme.dev/opensearch"
    },
    "notable": [
      "OpenSearch 3.9.0 was tagged on 22 September 2026 and adds the `half_float` vector type and 2-bit and 4-bit scalar quantisation, per the version history (https://docs.opensearch.org/latest/version-history/)",
      "The cluster has its own MCP server at `/_plugins/_ml/mcp` over Streamable HTTP since 3.3, off until `plugins.ml_commons.mcp_server_enabled` is set. The experimental SSE APIs were removed in 3.3 (https://docs.opensearch.org/latest/ml-commons-plugin/api/mcp-server-apis/index/)",
      "`opensearch-mcp-server-py` 0.12.0 (17 September 2026) runs outside the cluster over stdio or Streamable HTTP with nine core tools on by default, among them `GenericOpenSearchApiTool` (https://github.com/opensearch-project/opensearch-mcp-server-py)",
      "API keys arrived in 3.7 with cluster and index permissions, a 90-day maximum life, 100 outstanding keys by default and an `API_TOKEN_WRITE` audit category (https://docs.opensearch.org/latest/security/access-control/api-keys/)",
      "Concurrency limits arrived in 3.9, are off by default and reject excess requests with HTTP 429 once enforced (https://docs.opensearch.org/latest/tuning-your-cluster/availability-and-recovery/concurrency-limits/)",
      "The Security plugin published four advisories on 30 April 2026, one moderate (document-level security not applied through `has_child` and `has_parent`) and three low (https://github.com/opensearch-project/security/security/advisories)",
      "Agent skills for Claude Code, Cursor and Kiro install with `npx skills add opensearch-project/opensearch-agent-skills` (https://docs.opensearch.org/latest/ai-agent-integrations/agent-skills/)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "The REST API of a self-hosted OpenSearch 3.9.0 cluster, with `opensearch-mcp-server-py` 0.12.0 and the in-cluster MCP endpoint as second surfaces. The foundation runs no hosted service. Amazon OpenSearch Service and other vendors' hosting are not graded here"
      },
      {
        "label": "Search modes",
        "value": "Approximate and exact k-NN on `knn_vector` fields with the Lucene and Faiss engines (`nmslib` is deprecated), BM25 text search, hybrid search through a search pipeline, neural sparse search and semantic search with a model, per the docs"
      },
      {
        "label": "Filters",
        "value": "Efficient k-NN filtering applied during the search on Lucene HNSW and Faiss HNSW or IVF, post-filtering with a Boolean clause or `post_filter`, and a scoring script filter for exact search"
      },
      {
        "label": "Update delay",
        "value": "A document is searchable after the next index refresh, which `index.refresh_interval` controls. Not measured by us"
      },
      {
        "label": "Setup",
        "value": "Docker image `opensearchproject/opensearch`, tarball, RPM or Debian package with a bundled JDK. The demo security setup needs `OPENSEARCH_INITIAL_ADMIN_PASSWORD`. A vector index needs a mapping with a `knn_vector` field"
      },
      {
        "label": "Auth",
        "value": "Security plugin with basic auth, client certificates, JWT, OpenID Connect and SAML. API keys since 3.7, sent as `Authorization: ApiKey \u003ctoken\u003e`, with cluster and index permissions"
      },
      {
        "label": "Limits",
        "value": "No fixed request quota. Concurrency limits per action (off by default, HTTP 429 once enforced), search backpressure and shard indexing backpressure are the operator's settings. `from` plus `size` paging has a result window limit"
      },
      {
        "label": "MCP server (external)",
        "value": "`opensearch-mcp-server-py` 0.12.0, Python 3.10 or later per `pyproject.toml`, stdio and Streamable HTTP. Nine core tools by default, further categories (`search_relevance`, `skills`, `observability`, `agentic_memory`) off until enabled"
      },
      {
        "label": "MCP server (in cluster)",
        "value": "`/_plugins/_ml/mcp` over stateless Streamable HTTP, with APIs to register, update, list and remove tools. Introduced 3.0, Streamable HTTP since 3.3"
      },
      {
        "label": "API description",
        "value": "OpenAPI 3.1 in opensearch-project/opensearch-api-specification, published as one file at https://api-spec.opensearch.org/opensearch-openapi.yaml. About 717 operations counted in the source on 9 October 2026"
      },
      {
        "label": "Clients",
        "value": "Official clients for Python, JavaScript, Java, Go, Ruby, PHP, .NET and Rust, per the docs"
      },
      {
        "label": "Releases",
        "value": "Minor versions about every eight weeks on a published schedule. 3.10.0 is planned for 3 to 17 November 2026. The 2.19 line is in maintenance until 4.0 is released"
      },
      {
        "label": "Cost",
        "value": "Free software. The owner pays for the machines. Long-term support is sold by three vendors the foundation certifies, with no prices on opensearch.org"
      }
    ],
    "provenance": {
      "legalEntity": "OpenSearch Software Foundation, a project of The Linux Foundation",
      "domain": "opensearch.org",
      "domainRegistered": "2003-05-15",
      "endpointOnVendorDomain": false,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://docs.opensearch.org/latest/version-history/",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The foundation page says the OpenSearch Software Foundation is a project of The Linux Foundation and is not involved in technical oversight of the open source project.",
        "No terms or privacy document is set. The site footer links The Linux Foundation's general terms and privacy policy, which are a parent body's website notices. The Apache-2.0 licence stands in for the software.",
        "The software runs on the owner's machines, so no endpoint is on the vendor's domain and there is no status page.",
        "https://opensearch.org/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` in the core repository asks for reports by email to security@opensearch.org.",
        "RDAP for opensearch.org gives a registration date of 2003-05-15 and a transfer on 13 November 2024.",
        "The first release date is the 1.0 general availability date in the maintenance table on the releases page."
      ],
      "score": 45,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "OpenSearch Software Foundation, a project of The Linux Foundation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "opensearch.org, registered 2003-05-15 (23 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on opensearch.org",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Privacy policy",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/opensearch.json",
    "live": {
      "slug": "opensearch",
      "versions": [
        {
          "registry": "github",
          "name": "opensearch-project/OpenSearch",
          "version": "3.9.0",
          "released": "2026-09-29",
          "seenAt": "2026-10-09T17:11:12.76716689Z"
        },
        {
          "registry": "pypi",
          "name": "opensearch-mcp-server-py",
          "version": "0.12.0",
          "released": "2026-09-17",
          "seenAt": "2026-10-09T17:11:10.759906653Z"
        },
        {
          "registry": "pypi",
          "name": "opensearch-py",
          "version": "3.2.0",
          "released": "2026-04-27",
          "seenAt": "2026-10-09T17:11:10.949518654Z"
        }
      ],
      "githubStars": 13832,
      "pypiWeekly": 75145,
      "pages": [
        {
          "url": "https://docs.opensearch.org/latest/version-history/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:37:58.648544982Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "9aa4527e824d"
        }
      ],
      "updatedAt": "2026-10-09T18:37:58.648544982Z"
    }
  }
}
