{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "rocketreach",
    "name": "RocketReach API",
    "vendor": "RocketReach, LLC",
    "vendorUrl": "https://rocketreach.co",
    "kind": "http-api",
    "category": "lead-data",
    "summary": "RocketReach is a contact and company database with people and company search, contact lookup, bulk lookup and single-address email verification. Agents reach it through a REST API (v2) with an account API key, or a hosted MCP server with OAuth.",
    "url": "https://www.anchorterminal.com/tools/rocketreach",
    "markdownUrl": "https://www.anchorterminal.com/tools/rocketreach.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/rocketreach.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rocketreach.json",
    "repo": "https://github.com/rocketreach/rocketreach_python",
    "license": "Proprietary service under RocketReach's Terms of Service. The Python SDK on GitHub is MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.rocketreach.co/api/v2",
    "packages": [
      {
        "registry": "pypi",
        "name": "rocketreach"
      }
    ],
    "auth": "mixed",
    "authNotes": "A person signs up in a browser and generates a key in account settings. REST calls send it in the `Api-Key` header. One key is active per account, and generating a new one invalidates the old. The `api_key` query parameter is deprecated. The MCP server at https://mcp.rocketreach.co/mcp uses OAuth 2.1 with PKCE and open dynamic client registration, with one scope, `rocketreach:read`, and the user approves access in a browser. The docs list an account with API access as a prerequisite.",
    "pricing": "paid",
    "pricingNotes": "No price was read. The pricing page is drawn by script and showed only its title (checked 2026-10-09). The docs name four API plans, Essentials, Pro, Ultimate and Custom, and tell users without a paid plan to email for an API plan. Universal Credits cost 2 for a professional email, 3 for a personal email, 6 for a phone and 1 a page of person search. Whether a free account or trial includes API calls was not established. Fees are non-refundable under the Subscription Agreement.",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the reference pages or the terms (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 9,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.rocketreach.co/",
    "llmsTxt": "https://docs.rocketreach.co/llms.txt",
    "capabilities": [
      "lead.search",
      "lead.enrichment",
      "email.verification",
      "email.finder",
      "data.company"
    ],
    "tags": [
      "hosted",
      "mcp",
      "oauth",
      "api-key",
      "llms-txt",
      "webhooks",
      "async-jobs",
      "credits",
      "lead-search",
      "enrichment",
      "email-verification",
      "status-page",
      "closed-source"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 51.2,
      "grade": "D",
      "agentReady": false,
      "rank": 755,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 11,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 31,
        "payments": 10,
        "reliability": 64,
        "schema": 72,
        "security": 34,
        "transparency": 58
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 64,
          "points": 12.8,
          "reason": "Hosted lines. Status page on incident.io at status.rocketreach.co with five components, among them API and MCP (20). In the last 90 days it lists eight entries. On 20 August 2026 degraded performance ran from 12:00 AM to 10:00 AM across the site, extension, API and MCP, with a second hour that afternoon, delayed webhooks and a 29-minute outage in the evening. On 27 August elevated errors lasted 61 minutes. A 71-minute maintenance window on 27 September, in which the notice said API and MCP calls would be unresponsive or throttled, was announced on 15 September. Read as one major day and a second incident of about an hour (7 of 30). Rate limits published per plan and endpoint, plus a global 10 requests a second (15). 429 carries `Retry-After` and the docs show a retry example. No idempotency keys, though repeat lookups are free (12 of 15). No SLA found in the terms, the subscription agreement or the docs (0). The API and MCP server are not marked beta (10). Total 64."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "Each reference page's Markdown twin carries an OpenAPI 3.1 definition for its operation, 17 operations in all. No single downloadable file was found (22 of 25). llms.txt and Markdown twins on the docs host (10). The MCP tools page states what each tool returns, what it costs and which tool to call next. REST operation descriptions are thin, and Company Lookup carries the Company Search subtitle (14 of 20). Query parameters are typed, with enums on `lookup_type` and `order_by`. No lookup parameter is marked required although one identifier is needed, and `metadata` is a free object (10 of 15). Error table, a worked 402 body, an MCP error catalogue and response examples. Every operation lists the same generic error set (11 of 15). The version sits in the path (`/api/v2`), with the Universal Credits endpoints alongside. No changelog was found (5 of 15). Total 72."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "The MCP server documents nine tools. We read the docs page and did not connect, so the size of the live definitions is unread (22 of 25). `start`, `page_size` up to 100, `order_by`, an `exclude` object and about 50 search facets, with a ceiling of 10,000 results a query (18 of 20). MCP errors carry `error_code` in `_meta` with `retry_after_seconds`, `credit_type` or `field` and `reason`. On REST only the 402 from email verification is structured, and running out of lookup credits returns a 403 with a text `detail` (15 of 20). Repeat lookups and polling are free and terminal errors are named. No idempotency keys, and MCP tool annotations were not read (9 of 20). Few parameters are needed for a call. One official SDK, Python 2.1.8, whose last code change is dated 26 March 2025 (8 of 15). Total 72."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 34,
          "points": 5.95,
          "reason": "REST takes one key per account in the `Api-Key` header. Only one key is active at a time and generating a new one invalidates the old. The MCP server uses OAuth 2.1 with PKCE, open dynamic client registration, one-hour access tokens, 30-day refresh tokens that rotate, and a revocation endpoint. The access token carries the API key inside an encrypted envelope, and the `account` tool returns `api_key` in its response, so the key reaches the model's context (18 of 30). The docs say older clients may still send the key as an `api_key` query parameter, marked deprecated (5 off, 13). One scope, `rocketreach:read`, covers every tool, including lookups that spend credits and add contacts to My Contacts. No read-only mode, per-key limit or confirmation step was found. The account object has an `api_key_domain` field (4 of 20). Results are third-party profile data. No prompt-injection guidance was found (3 of 15). Usage and rate-limit counts from the account endpoint, a recent-errors panel in account settings, `RR-Request-ID` on webhooks, and MCP lookups tagged with the client name. No per-call log was found (8 of 15). security.txt is valid, with a contact address and an expiry of 8 June 2029. The DPA lists security measures in an annex and names a Trust Centre that we did not find linked. No certification or bug bounty was found (6 of 20). Total 34."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 in the docs or terms (0). The docs publish credit costs per action for Universal Credits, such as 2 credits for a professional email and 6 for a phone. The pricing page is drawn by script and showed our reader only its title, so no price in dollars was read, and the docs tell users without a paid plan to email for an API plan (5 of 20). The site's description says to try for free, and the rate-limit page implies an unpaid account can call the API until throttled. What a free account gets through the API was not established (5 of 20). A person signs up in a browser, the terms say account holders warrant they are human, and MCP authorisation needs a browser login (0). Total 10. The pricing lines are scored on what could be read."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 31,
          "points": 2.71,
          "reason": "No changelog or release notes were found. The docs pages carry update dates. Four were updated on 8 October 2026 and the Email Verify reference on 11 September 2026. Read as recent API activity from docs metadata and not from a release record (20 of 30). No dated changelog entries (0 of 20). Support by email and a status page that posts updates. The help centre answered 403 and was not read (5 of 15). The Python SDK on GitHub is at 2.1.8 with its last code change on 26 March 2025 and no tags. The official MCP registry answered 500 to our search, so a registry entry is unchecked (3 of 15). The SDK repository has a Renovate configuration and states Python 3.4 or later (3 of 10). Total 31."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 58,
          "points": 5.08,
          "note": "editorial 45, provenance 70",
          "reason": "Closed service with terms that name RocketReach, LLC and cover the API (15 of 30). The privacy policy, updated 30 September 2026, covers people in the database as well as customers. It names sources (public web pages, data brokers, and customers' connected email accounts by opt-in), a removal form, a DPO, EU and UK representatives, a Texas data broker notice and 2025 request counts. A DPA is public. Retention has no stated period (20 of 30). The API definitions mark deprecated fields with no dates, and no deprecation policy was found (4 of 20). The policy says data is collected and held in the US. The DPA says a sub-processor list is in a Trust Centre, which we did not find linked and did not read (6 of 20). Total 45."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server documents nine tools. We read the docs page and did not connect, so the size of the live definitions is unread (22 of 25). `start`, `page_size` up to 100, `order_by`, an `exclude` object and about 50 search facets, with a ceiling of 10,000 results a query (18 of 20). MCP errors carry `error_code` in `_meta` with `retry_after_seconds`, `credit_type` or `field` and `reason`. On REST only the 402 from email verification is structured, and running out of lookup credits returns a 403 with a text `detail` (15 of 20). Repeat lookups and polling are free and terminal errors are named. No idempotency keys, and MCP tool annotations were not read (9 of 20). Few parameters are needed for a call. One official SDK, Python 2.1.8, whose last code change is dated 26 March 2025 (8 of 15). Total 72.",
          "maintenance": "No changelog or release notes were found. The docs pages carry update dates. Four were updated on 8 October 2026 and the Email Verify reference on 11 September 2026. Read as recent API activity from docs metadata and not from a release record (20 of 30). No dated changelog entries (0 of 20). Support by email and a status page that posts updates. The help centre answered 403 and was not read (5 of 15). The Python SDK on GitHub is at 2.1.8 with its last code change on 26 March 2025 and no tags. The official MCP registry answered 500 to our search, so a registry entry is unchecked (3 of 15). The SDK repository has a Renovate configuration and states Python 3.4 or later (3 of 10). Total 31.",
          "payments": "No x402, MPP or L402 in the docs or terms (0). The docs publish credit costs per action for Universal Credits, such as 2 credits for a professional email and 6 for a phone. The pricing page is drawn by script and showed our reader only its title, so no price in dollars was read, and the docs tell users without a paid plan to email for an API plan (5 of 20). The site's description says to try for free, and the rate-limit page implies an unpaid account can call the API until throttled. What a free account gets through the API was not established (5 of 20). A person signs up in a browser, the terms say account holders warrant they are human, and MCP authorisation needs a browser login (0). Total 10. The pricing lines are scored on what could be read.",
          "reliability": "Hosted lines. Status page on incident.io at status.rocketreach.co with five components, among them API and MCP (20). In the last 90 days it lists eight entries. On 20 August 2026 degraded performance ran from 12:00 AM to 10:00 AM across the site, extension, API and MCP, with a second hour that afternoon, delayed webhooks and a 29-minute outage in the evening. On 27 August elevated errors lasted 61 minutes. A 71-minute maintenance window on 27 September, in which the notice said API and MCP calls would be unresponsive or throttled, was announced on 15 September. Read as one major day and a second incident of about an hour (7 of 30). Rate limits published per plan and endpoint, plus a global 10 requests a second (15). 429 carries `Retry-After` and the docs show a retry example. No idempotency keys, though repeat lookups are free (12 of 15). No SLA found in the terms, the subscription agreement or the docs (0). The API and MCP server are not marked beta (10). Total 64.",
          "schema": "Each reference page's Markdown twin carries an OpenAPI 3.1 definition for its operation, 17 operations in all. No single downloadable file was found (22 of 25). llms.txt and Markdown twins on the docs host (10). The MCP tools page states what each tool returns, what it costs and which tool to call next. REST operation descriptions are thin, and Company Lookup carries the Company Search subtitle (14 of 20). Query parameters are typed, with enums on `lookup_type` and `order_by`. No lookup parameter is marked required although one identifier is needed, and `metadata` is a free object (10 of 15). Error table, a worked 402 body, an MCP error catalogue and response examples. Every operation lists the same generic error set (11 of 15). The version sits in the path (`/api/v2`), with the Universal Credits endpoints alongside. No changelog was found (5 of 15). Total 72.",
          "security": "REST takes one key per account in the `Api-Key` header. Only one key is active at a time and generating a new one invalidates the old. The MCP server uses OAuth 2.1 with PKCE, open dynamic client registration, one-hour access tokens, 30-day refresh tokens that rotate, and a revocation endpoint. The access token carries the API key inside an encrypted envelope, and the `account` tool returns `api_key` in its response, so the key reaches the model's context (18 of 30). The docs say older clients may still send the key as an `api_key` query parameter, marked deprecated (5 off, 13). One scope, `rocketreach:read`, covers every tool, including lookups that spend credits and add contacts to My Contacts. No read-only mode, per-key limit or confirmation step was found. The account object has an `api_key_domain` field (4 of 20). Results are third-party profile data. No prompt-injection guidance was found (3 of 15). Usage and rate-limit counts from the account endpoint, a recent-errors panel in account settings, `RR-Request-ID` on webhooks, and MCP lookups tagged with the client name. No per-call log was found (8 of 15). security.txt is valid, with a contact address and an expiry of 8 June 2029. The DPA lists security measures in an annex and names a Trust Centre that we did not find linked. No certification or bug bounty was found (6 of 20). Total 34.",
          "transparency": "Closed service with terms that name RocketReach, LLC and cover the API (15 of 30). The privacy policy, updated 30 September 2026, covers people in the database as well as customers. It names sources (public web pages, data brokers, and customers' connected email accounts by opt-in), a removal form, a DPO, EU and UK representatives, a Texas data broker notice and 2025 request counts. A DPA is public. Retention has no stated period (20 of 30). The API definitions mark deprecated fields with no dates, and no deprecation policy was found (4 of 20). The policy says data is collected and held in the US. The DPA says a sub-processor list is in a Trust Centre, which we did not find linked and did not read (6 of 20). Total 45."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.rocketreach.co/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP overview",
            "url": "https://docs.rocketreach.co/reference/mcp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP authentication",
            "url": "https://docs.rocketreach.co/reference/mcp-auth.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP tools reference",
            "url": "https://docs.rocketreach.co/reference/mcp-tools.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP errors",
            "url": "https://docs.rocketreach.co/reference/mcp-errors.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP quick start and Claude Code setup",
            "url": "https://docs.rocketreach.co/reference/quick-start.md",
            "seen": "2026-10-09"
          },
          {
            "what": "rate limits",
            "url": "https://docs.rocketreach.co/reference/rate-limits.md",
            "seen": "2026-10-09"
          },
          {
            "what": "responses and errors",
            "url": "https://docs.rocketreach.co/reference/responses-and-errors.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Universal Credits costs",
            "url": "https://docs.rocketreach.co/reference/universal-credits-overview.md",
            "seen": "2026-10-09"
          },
          {
            "what": "FAQ (credit charging, pagination)",
            "url": "https://docs.rocketreach.co/reference/faq.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhooks",
            "url": "https://docs.rocketreach.co/reference/webhooks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference pages, read as the OpenAPI definitions embedded in each page's Markdown twin and not the rendered pages",
            "url": "https://docs.rocketreach.co/reference/people-lookup-api.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API key reference (one key, deprecated query parameter)",
            "url": "https://docs.rocketreach.co/reference/rocketreach-api-account-newaccount.md",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service, updated 31 January 2024",
            "url": "https://rocketreach.co/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "subscription agreement, updated 10 January 2025",
            "url": "https://rocketreach.co/subscriber_terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy, updated 30 September 2026",
            "url": "https://rocketreach.co/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "data processing addendum",
            "url": "https://rocketreach.co/dpa",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing page (title only, script-drawn)",
            "url": "https://rocketreach.co/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://rocketreach.co/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.rocketreach.co",
            "seen": "2026-10-09"
          },
          {
            "what": "status history and five incident pages",
            "url": "https://status.rocketreach.co/history",
            "seen": "2026-10-09"
          },
          {
            "what": "Python SDK repository (shallow clone)",
            "url": "https://github.com/rocketreach/rocketreach_python",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: plan prices, what each plan includes, and whether a free account or trial includes API access. https://rocketreach.co/pricing is drawn by script and showed only its title to curl and to our reader",
          "unchecked: the help centre at knowledgebase.rocketreach.co, which answered 403 to its first page request. We did not retry",
          "unchecked: a Trust Centre the DPA names as holding the sub-processor list. No page read links it, so certifications and sub-processors are scored as not found",
          "unchecked: the official MCP registry. Its search answered 500, so `registryName` is empty",
          "unchecked: the domain registration date. rdap.org has no RDAP service for rocketreach.co",
          "unchecked: live MCP tool definitions and annotations. We read the docs page and did not connect",
          "unchecked: download counts and repository stars for the Python SDK",
          "The site's home page is drawn by script and links nothing. The pricing, terms and privacy pages were requested at their conventional addresses, which the terms page then confirmed in its own links",
          "The terms (updated 31 January 2024) say account holders warrant they are human, bar accounts registered by automated methods, and forbid scripts or robots that extract lookup data. Recorded as a fact with no deduction. It matters before any probe is run",
          "Two credit systems are documented side by side (lookup and export credits, and Universal Credits). Which one a new account gets was not established"
        ]
      },
      "negative": 0,
      "verdict": "The hosted MCP server has nine documented tools, OAuth 2.1 with dynamic client registration and machine-readable error codes, and searches cost no credits. Plan prices were not readable, the docs send API plan requests to email, the terms require a human account holder, and the `account` tool returns the account's API key to the model.",
      "bestFor": "Teams that already hold a RocketReach plan and want an agent to search people and companies, reveal emails and phones, and verify single addresses over MCP.",
      "strengths": [
        "Hosted MCP server with nine documented tools, OAuth 2.1 with PKCE, dynamic client registration, one-hour access tokens and rotating refresh tokens",
        "MCP errors carry a stable `error_code` in `_meta`, with `retry_after_seconds`, `credit_type` or the failing `field`",
        "Rate limits published per plan and per endpoint by minute, hour, day and month, and 429 responses carry `Retry-After`",
        "Lookups that find no data are not charged, B and F grade emails are not charged, and repeat lookups of a profile are free while the plan is active",
        "Status page with separate API and MCP components, and the 27 September 2026 maintenance was announced 12 days ahead"
      ],
      "weaknesses": [
        "The pricing page is drawn by script and was not read, and the docs tell users without a paid plan to email for an API plan",
        "The MCP `account` tool returns the account's API key in its response, and the OAuth access token carries the same key inside it",
        "One API key per account with no scopes. The single MCP scope `rocketreach:read` covers the tools that spend credits and add contacts",
        "On 20 August 2026 the status page shows ten hours of degraded performance across the site, API and MCP, then a 29-minute outage",
        "The terms say account holders warrant they are human and forbid automated extraction of lookup data. No deduction is taken, and it matters before any probe is run",
        "No changelog or deprecation policy was found, and the Python SDK's last code change is dated 26 March 2025"
      ],
      "agentNotes": [
        "Search first with `person_search` or `company_search`, which cost no credits, then look up only the profile IDs needed",
        "Treat `status: \"pending\"` as normal. Poll `check_person_status` after at least 3 seconds, and polling is free",
        "Do not echo the `account` tool's output to users or logs. It includes the account's API key",
        "Send the key in the `Api-Key` header. The `api_key` query parameter is deprecated",
        "Bulk lookup takes 1 to 100 queries and needs a webhook. Results arrive at the webhook, signed in `X-RocketReach-Signature`",
        "Do not loop on `unknown` from `email_verify`, or on `lookup_failed` and `not_found`. The last two are terminal"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 51.2
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 31,
        "payments": 10,
        "reliability": 64,
        "schema": 72,
        "security": 34,
        "transparency": 45
      },
      "provenanceScore": 70
    },
    "connect": {
      "claudeCode": "claude mcp add rocketreach https://mcp.rocketreach.co/mcp",
      "config": {
        "mcpServers": {
          "rocketreach": {
            "url": "https://mcp.rocketreach.co/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/lead.search",
      "tool": "https://letme.dev/rocketreach"
    },
    "notable": [
      "The MCP server documents nine tools, and the two search tools cost no credits (https://docs.rocketreach.co/reference/mcp.md)",
      "The MCP `account` tool's response includes the account's API key, and the OAuth access token carries the key inside an encrypted envelope (https://docs.rocketreach.co/reference/mcp-tools.md, https://docs.rocketreach.co/reference/mcp-auth.md)",
      "The three MCP lookup tools add the contact or company to the account's My Contacts list, tagged `MCP Lookups` and the client's name (https://docs.rocketreach.co/reference/mcp-tools.md)",
      "The docs tell users who are not on a paid plan to email for an API plan (https://docs.rocketreach.co/reference/rate-limits.md)",
      "The terms say account holders warrant they are human and forbid scripts or robots that extract lookup data (https://rocketreach.co/terms)",
      "The privacy policy says RocketReach is a data broker under Texas law and reports 23,688 opt-out or deletion requests in 2025 (https://rocketreach.co/privacy)",
      "On 20 August 2026 the status page shows ten hours of degraded performance and a 29-minute outage (https://status.rocketreach.co/history)"
    ],
    "area": "web-data",
    "details": [
      {
        "label": "Modes",
        "value": "Search (people and companies, no credits over MCP), enrichment (person, company and combined lookups, bulk lookup of 1 to 100 by webhook) and email verification (one address a call, no bulk)"
      },
      {
        "label": "API",
        "value": "REST at https://api.rocketreach.co/api/v2, 17 documented operations, among them `/person/search`, `/person/lookup`, `/bulkLookup`, `/company/lookup/`, `/email/verify/` and the `/universal/` set billed in Universal Credits"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.rocketreach.co/mcp over Streamable HTTP. Nine tools, `person_search`, `company_search`, `person_lookup`, `profile_company_lookup`, `company_lookup`, `email_verify`, `account`, `check_person_status` and `ping`"
      },
      {
        "label": "Credentials",
        "value": "`Api-Key` header, one active key per account. MCP by OAuth 2.1 with PKCE and dynamic client registration, scope `rocketreach:read`, access token 1 hour, refresh token 30 days and rotating"
      },
      {
        "label": "Rate limits",
        "value": "Global 10 requests a second. Person lookup a minute, Essentials 15, Pro 50, Ultimate 100, Custom 250. Person and company search a minute, 15, 30, 60 and 100. Bulk jobs 10 a minute. Email verification 300 a minute on every plan. MCP calls share the same budget"
      },
      {
        "label": "Credits",
        "value": "Universal Credits, person search 1 a page, company search 2 a page, professional email 2, personal email 3, phone 6, enrichment 1. Email verification uses a separate pool"
      },
      {
        "label": "Async lookups",
        "value": "A lookup may return pending. Poll the status endpoint or tool after 3 seconds, or receive a webhook signed with HMAC-SHA256 in `X-RocketReach-Signature`"
      },
      {
        "label": "Errors",
        "value": "MCP codes `auth_required`, `insufficient_credits`, `not_found`, `lookup_failed`, `rate_limited`, `validation_error` and `service_error`. REST uses 400, 401, 402, 403, 404, 429 and 500, and 429 carries `Retry-After`"
      },
      {
        "label": "SDK",
        "value": "Python `rocketreach` 2.1.8 in rocketreach/rocketreach_python, MIT, last code change 26 March 2025"
      },
      {
        "label": "Status",
        "value": "status.rocketreach.co on incident.io, components RocketReach.co, Extension, API, MCP and RocketReach Verify"
      },
      {
        "label": "Legal",
        "value": "Terms of Service (31 January 2024), Subscription Agreement (10 January 2025), DPA, Privacy Policy (30 September 2026). Fees are non-refundable"
      }
    ],
    "provenance": {
      "legalEntity": "RocketReach, LLC",
      "domain": "rocketreach.co",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://rocketreach.co/terms",
      "privacy": "https://rocketreach.co/privacy",
      "statusPage": "https://status.rocketreach.co",
      "changelog": "",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Service (updated 31 January 2024) name RocketReach, LLC, 144 N 7th St, PO #421, Brooklyn, NY 11211, are governed by Washington law, and say they apply to users of the API and their end users.",
        "The API answers at api.rocketreach.co and the MCP server at mcp.rocketreach.co, both subdomains of the vendor's domain.",
        "https://rocketreach.co/.well-known/security.txt gives a contact address and expires on 8 June 2029.",
        "Paid subscribers also accept a Subscription Agreement at https://rocketreach.co/subscriber_terms, and a DPA at https://rocketreach.co/dpa forms part of the terms.",
        "No changelog was found on the docs site or the main site. The registration date of rocketreach.co was not established."
      ],
      "score": 70,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "RocketReach, LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "rocketreach.co, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.rocketreach.co",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.rocketreach.co",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://rocketreach.co/terms",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2024-01-31",
          "words": 4409,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: January 31, 2024",
              "says": "Last updated 2024-01-31"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by the laws of the State of Washington without regard to conflict of law principles.",
              "says": "The law of the State of Washington"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event will RocketReach, or its suppliers or licensors, be liable with respect to any subject matter of this agreement under any contract, negligence, strict liability or other legal or equitable theory for: (i) any special, incidental or consequential damages;",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "…change to RocketReach’s address for Notice of Arbitration, in which case your account with RocketReach will be immediately terminated and this arbitration provision, as in effect immediately prior to the changes you rejected will survive."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Your continued use of or access to the Services following the posting of any changes to this Agreement constitutes acceptance of those changes.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to all the terms and conditions of this Agreement, you may not access or use the"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Accounts registered by “bots” or other automated methods are not permitted.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "RocketReach reserves the right, at its sole discretion, to modify or replace any part of this Agreement. It is your responsibility to check this Agreement periodically for changes.",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "In the interest of resolving disputes between you and RocketReach in the most expedient and cost effective manner, and except as expressly described herein, you and RocketReach agree that every dispute arising in connection with these Terms will be resolved by binding arbitration."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability is capped at the fees paid in the three months before the cause of action.",
              "quote": "(iv) for any amounts that exceed the fees paid by you to RocketReach under this agreement during the three (3) month period prior to the cause of action."
            },
            {
              "date": "2026-10-08",
              "text": "Lookup results may not be transferred or disclosed to anyone else, or used in data for commercial sale, without prior written consent.",
              "quote": "Without the prior written consent of RocketReach, you may not develop or derive for commercial sale or otherwise commercially exploit any data in any form that incorporates or uses the Lookup Information, and you may not transfer or disclose the Lookup Information to anyone else."
            },
            {
              "date": "2026-10-08",
              "text": "A company user grants a perpetual, revocable right to use its name and logos for marketing and sales, and can revoke it by written notice.",
              "quote": "you grant (and you represent and warrant that you have the authority to grant) RocketReach, solely for marketing and sales purposes, an unrestricted, perpetual, revocable, non-exclusive, fully-paid, royalty-free right to use your company’s name and/or logos."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://rocketreach.co/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-30",
          "words": 4123,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 30, 2026",
              "says": "Last updated 2026-09-30"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy (“Policy”) describes how we collect, process, share and safeguard Personal Data we collect from you, or that you provide to us, in connection with your use of our website https://rocketreach.co/ (“Website”) or in connection with the provision of any services through the Website or elsewhere, includ…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We store all Personal Data for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal or regulatory obligations, or where we otherwise reasonably believe that we have a legit…",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Information Collected via Automated Means Single Sign-On through Internet Service Providers."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "If your Personal Data appears within our Services, you may opt out of the \"selling\" (as the term is defined under applicable US privacy laws) of your Personal Data by using our Do Not Sell or Share My Info tool.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "This Policy also applies to the Personal Data of professionals whose business contact details appear in our Services, and tells you about your rights and choices with respect to your Personal Data, and how you can contact us if you have any questions or concerns."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may submit evidence of your designation of an authorized agent in writing to: privacy@rocketreach.co or 144 N 7th St, PO #421 Brooklyn, NY 11211, US.",
              "says": "privacy@rocketreach.co"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com International Data Transfers"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We share Personal Data with advertising partners that display offsite RocketReach targeted advertising around the web as described in the “How We Use Personal Data We Receive or Collect” section above."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers who connect a cloud email account give the vendor access to address book data, email headers, signature blocks and information from correspondence with their contacts.",
              "quote": "Customers share this Personal Data with us by connecting their cloud email account (e.g., Google or Microsoft) to our Services to allow us to access information stored by the provider."
            },
            {
              "date": "2026-10-08",
              "text": "Personal data may be processed by third-party artificial intelligence model suppliers that support product functions.",
              "quote": "We use providers of artificial intelligence models to support and provide features of our Services."
            },
            {
              "date": "2026-10-08",
              "text": "Personal data held about a user can only be deleted by deleting the user account as well.",
              "quote": "We cannot delete your Personal Data except by also deleting your user account."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/rocketreach.json",
    "live": {
      "slug": "rocketreach",
      "probe": {
        "target": "https://api.rocketreach.co/api/v2",
        "method": "get",
        "lastAt": "2026-10-10T02:55:08.295305547Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 1581,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 570,
        "p95ms24h": 1542,
        "samples24h": 115,
        "samples30d": 115,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 30,
            "ok": 30
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.rocketreach.co",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-10T02:50:45.712247973Z"
      },
      "versions": [
        {
          "registry": "pypi",
          "name": "rocketreach",
          "version": "2.1.8",
          "released": "2025-03-26",
          "seenAt": "2026-10-09T17:17:24.557829144Z"
        }
      ],
      "githubStars": 18,
      "pypiWeekly": 13874,
      "pages": [
        {
          "url": "https://rocketreach.co/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:44:37.647800452Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "bb39d156c3b5"
        },
        {
          "url": "https://rocketreach.co/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:44:39.963033716Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ac842cb8d9d8"
        }
      ],
      "updatedAt": "2026-10-10T02:55:08.295305547Z"
    }
  }
}
