{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "seatable",
    "name": "SeaTable",
    "vendor": "SeaTable GmbH",
    "vendorUrl": "https://seatable.com",
    "kind": "http-api",
    "category": "spreadsheets",
    "summary": "SeaTable is a database of typed rows in tables and bases, sold as a cloud service hosted in Germany and as server software. Agents reach it through a REST API with per-base tokens and an official MCP server.",
    "url": "https://www.anchorterminal.com/tools/seatable",
    "markdownUrl": "https://www.anchorterminal.com/tools/seatable.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/seatable.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/seatable.json",
    "repo": "https://github.com/seatable/seatable-mcp",
    "license": "Proprietary cloud service under the Terms of Service for SeaTable Cloud. The MCP server is MIT. SeaTable Server Enterprise Edition is licensed under an EULA",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://cloud.seatable.io",
    "packages": [
      {
        "registry": "npm",
        "name": "@seatable/mcp-seatable"
      },
      {
        "registry": "pypi",
        "name": "seatable-api"
      },
      {
        "registry": "npm",
        "name": "seatable-api"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve. A signed-in user creates an API token for one base, read-only or read-write, which never expires and can be deleted. Base calls need a Base-Token, a JWT valid for 3 days, obtained from the API token at `/api/v2.1/dtable/app-access-token/`. Account calls (bases, groups, webhooks, sharing) need an Account-Token obtained with the username and password, which never expires and carries the user's full access. The hosted MCP server takes the API token as a Bearer header, or runs an OAuth flow with PKCE and dynamic client registration in which the user enters the API token and the server issues a one-hour access token. The OAuth flow has no scopes.",
    "pricing": "freemium",
    "pricingNotes": "Free cloud plan for up to 25 users with 10,000 rows, 2 GB of files and 3,000 API calls a month for the team, with no card at signup, so an agent can start without a contract. Plus is €7 a user a month billed yearly (€9 monthly) with 10,000 API calls per user, and Enterprise €14 (€18 monthly) with 50,000. Dedicated is sold through sales from 100 users with unlimited calls. Prices are in euros before VAT and aren't converted here. The MCP server is free to use and there is no separate sandbox (checked 2026-10-08).",
    "priceSummary": "Freemium",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI files, the MCP server's README or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 21,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 103,
      "pypiWeekly": 1657,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://api.seatable.com/",
    "llmsTxt": "https://api.seatable.com/llms.txt",
    "openapi": "https://github.com/seatable/openapi/blob/v6.2/base_operations.yaml",
    "registryName": "io.github.seatable/seatable",
    "capabilities": [
      "sheets.records",
      "sheets.read",
      "sheets.write",
      "sheets.tables",
      "sheets.formulas"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "mcp",
      "free-tier",
      "api-key",
      "openapi",
      "llms-txt",
      "webhooks",
      "status-page",
      "python",
      "javascript",
      "php",
      "eu-hosted"
    ],
    "lastRelease": "2026-09-04",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 66.3,
      "grade": "B",
      "agentReady": false,
      "rank": 241,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 74,
        "maintenance": 76,
        "payments": 30,
        "reliability": 69,
        "schema": 81,
        "security": 59,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 69,
          "points": 13.8,
          "reason": "Graded on SeaTable Cloud's REST API and hosted MCP server, with the hosted lines. Status page at status.seatable.com, a Gatus dashboard with 15 components and uptime per component for up to 365 days (20). It publishes no incident reports. The base operations API shows 99.23 per cent over 30 days and 99.38 per cent over 365, the account API 99.95 per cent and the MCP server 99.98 per cent over 30 days. The failed checks we could read, from 5 to 8 October 2026, answered HTTP 200 with a body status of degraded, the longest stretch 34 minutes on 8 October. That is frequent degradation with no outage established, so 15 of 30 as a judgement call. Rate limits are published with numbers, 200 base calls and 1,000 account calls a minute on the cloud, plus monthly quotas (15). The docs recommend exponential backoff and base calls return `x-ratelimit-limit`, `x-ratelimit-remaining` and `x-ratelimit-reset` headers, but a 429 has no body, no Retry-After header is documented and there are no idempotency keys. The MCP server retries a 429 three times with backoff (9 of 15). No SLA text found. The pricing page names optional SLAs for Dedicated only (0). The REST API is generally available and the MCP server is at 1.6.4 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "Public OpenAPI 3.0 files for version 6.2, 404 operations in 8 files, and every MCP tool has a JSON Schema generated from a Zod model (25). `llms.txt`, `llms-full.txt` and Markdown copies of the reference pages are served at api.seatable.com (10). MCP tool descriptions say which tool to use for which job, and `query_sql` lists its syntax limits and tells the caller to switch tools after a failure. REST descriptions are specific but uneven (16 of 20). Parameters are typed, with a UUID pattern on `base_uuid`, 67 enums in the base operations file and column types as a oneOf, but row bodies are free-form objects keyed by column name and SQL is one string (9 of 15). The base operations file has 136 examples. Most operations document only a 200 response, and the status codes page is a generic table (8 of 15). The API changelog has an entry per server version with breaking changes marked, the spec repository has a branch per version, and paths carry `v2` or `v2.1`. No changelog file was found in the MCP repository (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "The hosted MCP server registers 21 tools, in the 11 to 30 band, and leaves out table and column changes by design. REST list calls take `start` and `limit`, and SQL can select columns (17 of 25). List rows pages by `start` and `limit` up to 1,000 and reads a saved view, SQL takes WHERE, ORDER BY and LIMIT up to 10,000 rows, and MCP has `page` and `page_size` (20). The reference lists status codes and says most 4xx answers carry an error code, but a 429 has no body and few operations document an error response. The MCP README maps common error messages to causes (11 of 20). No idempotency keys on the REST API. Every MCP tool carries readOnlyHint, destructiveHint and idempotentHint, and `upsert_rows` writes by key columns (14 of 20). Official clients for Python, JavaScript and PHP. A REST caller has to exchange the API token for a Base-Token and renew it every 3 days, which the clients and the MCP server do for it (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "API tokens are limited to one base, set to read-only or read-write, named, deletable and listed with their last access time. They never expire unless the one-hour temporary kind is used, and can't be limited to a table. The Account-Token comes from the username and password, never expires and carries the whole account. The MCP server's OAuth flow has PKCE and dynamic client registration but no scopes, and wraps the same API token. No secret in a query string was found (25 of 30). Read-only tokens per base, and the MCP server leaves out schema changes and marks destructive tools, but `query_sql` accepts UPDATE and DELETE and there is no confirmation step (13 of 20). Rows and comments can hold text written by others, and no prompt-injection guidance was found. Write tools reject unknown columns (3 of 15). Tokens show last access time, each base has an activity log and row history, and team admins get operation and login logs. No per-call log for a token was found (10 of 15). The security page gives security@seatable.com, links the management report of a September 2024 penetration test, says SeaTable has no certification and that a bug bounty is under construction. No security.txt and no published advisory found (8 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "Graded on the hosted cloud. No x402, MPP or L402 found (0). Plan prices are public in euros, Plus at €7 and Enterprise at €14 a user a month billed yearly, each with a monthly API call quota and no per-call price (10). A permanent Free plan with 3,000 API calls a month, and the registration page says no credit card is required. We didn't complete a signup (20). Access starts with registration in a browser, and the security page lists a captcha among access controls. API tokens can then be created by API with an Account-Token (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "reason": "The newest release we could date is MCP server 1.6.4 on 4 September 2026, 34 days before the check. SeaTable Cloud reported server version 6.2.13, whose date we didn't find. The product changelog gives 6.2.12 on 17 July 2026 (20 of 30). Five MCP server releases since 25 August 2026 and the API changelog entry for version 6.2 on 21 July (20). The forum's latest topics each had replies within a few days, in English and German. We didn't read who replied, and GitHub's API refused us, so issue reply times are unread (14 of 25). The MCP server is in the official MCP registry as `io.github.seatable/seatable` at 1.6.4, and the Python client had release 4.0.0 on 17 July 2026 (15). The MCP repository's CI runs lint, a type check and tests before each publish, and the OpenAPI repository has an API test suite. We didn't read the current CI result (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 65, provenance 85",
          "reason": "SeaTable Cloud is a closed service with clear terms, and the MCP server and its tool definitions are MIT (18 of 30). The privacy policy (version 1.3.0, 5 February 2026), a public data processing agreement and a page of technical and organisational measures agree on hosting in German data centres. Server logs are deleted within 180 days and deleted bases after 30 days in the recycle bin, but account data is removed 'after a few days' with no figure. The 2022 terms name only Frankfurt and say processor agreements are available on request, while the security page adds Munich and the agreement is public (23 of 30). No deprecation policy found. Breaking changes are marked in the API changelog at release, and the terms say they may be updated without prior notice (6 of 20). A sub-processor list (version 1.1.5, 16 October 2025) gives six companies with addresses and roles, and the security page names the two data centres (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The hosted MCP server registers 21 tools, in the 11 to 30 band, and leaves out table and column changes by design. REST list calls take `start` and `limit`, and SQL can select columns (17 of 25). List rows pages by `start` and `limit` up to 1,000 and reads a saved view, SQL takes WHERE, ORDER BY and LIMIT up to 10,000 rows, and MCP has `page` and `page_size` (20). The reference lists status codes and says most 4xx answers carry an error code, but a 429 has no body and few operations document an error response. The MCP README maps common error messages to causes (11 of 20). No idempotency keys on the REST API. Every MCP tool carries readOnlyHint, destructiveHint and idempotentHint, and `upsert_rows` writes by key columns (14 of 20). Official clients for Python, JavaScript and PHP. A REST caller has to exchange the API token for a Base-Token and renew it every 3 days, which the clients and the MCP server do for it (12 of 15).",
          "maintenance": "The newest release we could date is MCP server 1.6.4 on 4 September 2026, 34 days before the check. SeaTable Cloud reported server version 6.2.13, whose date we didn't find. The product changelog gives 6.2.12 on 17 July 2026 (20 of 30). Five MCP server releases since 25 August 2026 and the API changelog entry for version 6.2 on 21 July (20). The forum's latest topics each had replies within a few days, in English and German. We didn't read who replied, and GitHub's API refused us, so issue reply times are unread (14 of 25). The MCP server is in the official MCP registry as `io.github.seatable/seatable` at 1.6.4, and the Python client had release 4.0.0 on 17 July 2026 (15). The MCP repository's CI runs lint, a type check and tests before each publish, and the OpenAPI repository has an API test suite. We didn't read the current CI result (7 of 10).",
          "payments": "Graded on the hosted cloud. No x402, MPP or L402 found (0). Plan prices are public in euros, Plus at €7 and Enterprise at €14 a user a month billed yearly, each with a monthly API call quota and no per-call price (10). A permanent Free plan with 3,000 API calls a month, and the registration page says no credit card is required. We didn't complete a signup (20). Access starts with registration in a browser, and the security page lists a captcha among access controls. API tokens can then be created by API with an Account-Token (0).",
          "reliability": "Graded on SeaTable Cloud's REST API and hosted MCP server, with the hosted lines. Status page at status.seatable.com, a Gatus dashboard with 15 components and uptime per component for up to 365 days (20). It publishes no incident reports. The base operations API shows 99.23 per cent over 30 days and 99.38 per cent over 365, the account API 99.95 per cent and the MCP server 99.98 per cent over 30 days. The failed checks we could read, from 5 to 8 October 2026, answered HTTP 200 with a body status of degraded, the longest stretch 34 minutes on 8 October. That is frequent degradation with no outage established, so 15 of 30 as a judgement call. Rate limits are published with numbers, 200 base calls and 1,000 account calls a minute on the cloud, plus monthly quotas (15). The docs recommend exponential backoff and base calls return `x-ratelimit-limit`, `x-ratelimit-remaining` and `x-ratelimit-reset` headers, but a 429 has no body, no Retry-After header is documented and there are no idempotency keys. The MCP server retries a 429 three times with backoff (9 of 15). No SLA text found. The pricing page names optional SLAs for Dedicated only (0). The REST API is generally available and the MCP server is at 1.6.4 (10).",
          "schema": "Public OpenAPI 3.0 files for version 6.2, 404 operations in 8 files, and every MCP tool has a JSON Schema generated from a Zod model (25). `llms.txt`, `llms-full.txt` and Markdown copies of the reference pages are served at api.seatable.com (10). MCP tool descriptions say which tool to use for which job, and `query_sql` lists its syntax limits and tells the caller to switch tools after a failure. REST descriptions are specific but uneven (16 of 20). Parameters are typed, with a UUID pattern on `base_uuid`, 67 enums in the base operations file and column types as a oneOf, but row bodies are free-form objects keyed by column name and SQL is one string (9 of 15). The base operations file has 136 examples. Most operations document only a 200 response, and the status codes page is a generic table (8 of 15). The API changelog has an entry per server version with breaking changes marked, the spec repository has a branch per version, and paths carry `v2` or `v2.1`. No changelog file was found in the MCP repository (13 of 15).",
          "security": "API tokens are limited to one base, set to read-only or read-write, named, deletable and listed with their last access time. They never expire unless the one-hour temporary kind is used, and can't be limited to a table. The Account-Token comes from the username and password, never expires and carries the whole account. The MCP server's OAuth flow has PKCE and dynamic client registration but no scopes, and wraps the same API token. No secret in a query string was found (25 of 30). Read-only tokens per base, and the MCP server leaves out schema changes and marks destructive tools, but `query_sql` accepts UPDATE and DELETE and there is no confirmation step (13 of 20). Rows and comments can hold text written by others, and no prompt-injection guidance was found. Write tools reject unknown columns (3 of 15). Tokens show last access time, each base has an activity log and row history, and team admins get operation and login logs. No per-call log for a token was found (10 of 15). The security page gives security@seatable.com, links the management report of a September 2024 penetration test, says SeaTable has no certification and that a bug bounty is under construction. No security.txt and no published advisory found (8 of 20).",
          "transparency": "SeaTable Cloud is a closed service with clear terms, and the MCP server and its tool definitions are MIT (18 of 30). The privacy policy (version 1.3.0, 5 February 2026), a public data processing agreement and a page of technical and organisational measures agree on hosting in German data centres. Server logs are deleted within 180 days and deleted bases after 30 days in the recycle bin, but account data is removed 'after a few days' with no figure. The 2022 terms name only Frankfurt and say processor agreements are available on request, while the security page adds Munich and the agreement is public (23 of 30). No deprecation policy found. Breaking changes are marked in the API changelog at release, and the terms say they may be updated without prior notice (6 of 20). A sub-processor list (version 1.1.5, 16 October 2025) gives six companies with addresses and roles, and the security page names the two data centres (18 of 20)."
        },
        "sources": [
          {
            "what": "API reference index for agents",
            "url": "https://api.seatable.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "full API reference text",
            "url": "https://api.seatable.com/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API limits",
            "url": "https://api.seatable.com/reference/limits",
            "seen": "2026-10-08"
          },
          {
            "what": "API authentication",
            "url": "https://api.seatable.com/reference/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "API status codes",
            "url": "https://api.seatable.com/reference/errors",
            "seen": "2026-10-08"
          },
          {
            "what": "API changelog",
            "url": "https://api.seatable.com/reference/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI repository (cloned at commit c6d0ad9, branch v6.2)",
            "url": "https://github.com/seatable/openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository (cloned at commit d69d9b6, tag release-v1.6.4)",
            "url": "https://github.com/seatable/seatable-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool definitions in source",
            "url": "https://github.com/seatable/seatable-mcp/tree/main/src/mcp/tools",
            "seen": "2026-10-08"
          },
          {
            "what": "hosted MCP server's OAuth metadata",
            "url": "https://mcp.seatable.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=seatable",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.seatable.com",
            "seen": "2026-10-08"
          },
          {
            "what": "status feed (components, events and uptime)",
            "url": "https://status.seatable.com/api/v1/endpoints/statuses?page=1",
            "seen": "2026-10-08"
          },
          {
            "what": "server version on SeaTable Cloud",
            "url": "https://cloud.seatable.io/server-info/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://seatable.com/prices/",
            "seen": "2026-10-08"
          },
          {
            "what": "registration page",
            "url": "https://seatable.com/registration/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service for SeaTable Cloud",
            "url": "https://seatable.com/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://seatable.com/data-privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement",
            "url": "https://seatable.com/data-processing-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://seatable.com/subprocessors/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://seatable.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "legal documents index",
            "url": "https://seatable.com/legal/",
            "seen": "2026-10-08"
          },
          {
            "what": "imprint",
            "url": "https://seatable.com/imprint/",
            "seen": "2026-10-08"
          },
          {
            "what": "product changelog",
            "url": "https://seatable.com/changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "developer manual (client libraries)",
            "url": "https://developer.seatable.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "community forum, latest topics",
            "url": "https://forum.seatable.com/latest.json",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package for the MCP server",
            "url": "https://registry.npmjs.org/@seatable/mcp-seatable/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI package seatable-api",
            "url": "https://pypi.org/pypi/seatable-api/json",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://seatable.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for seatable.com",
            "url": "https://rdap.verisign.com/com/v1/domain/seatable.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: incident history before 5 October 2026. The status page keeps only the last 50 events per component and publishes no incident reports, so the record rests on its uptime percentages",
          "unchecked: GitHub stars, issue reply times and the current CI result. GitHub's API answered with a rate limit, so `githubStars` is empty",
          "unchecked: the hosted MCP server's live tool list. The 21 tools come from the source at tag release-v1.6.4, and the endpoint answered 401 without a token",
          "unchecked: whether signup asks for email confirmation or a captcha. We didn't create an account. The registration page says no credit card is required",
          "unchecked: the release date of server version 6.2.13, which SeaTable Cloud reported. The product changelog page lists 6.2.12 on 17 July 2026",
          "unchecked: the registration record of seatable.io, the domain the REST API answers on",
          "unchecked: the rendered API reference pages. api.seatable.com answered 429 to our later requests, so limits, authentication, status codes and the changelog were read from the Markdown sources in the OpenAPI repository and from `llms-full.txt`",
          "No SLA text, security.txt, bug bounty, certification, deprecation policy, Retry-After header, idempotency key or prompt-injection guidance was found in the reviewed pages",
          "The limits page gives 200 base calls a minute for SeaTable Cloud, and the MCP server's README gives a default of 500 per base, which is the figure for Dedicated and Server",
          "The pricing page lists prices in euros only, so `unitPrices` is empty and the figures are in `pricingNotes`",
          "The lead was right on vendor, URL and the REST interface. It missed the official MCP server, hosted at mcp.seatable.com and listed in the official MCP registry. API tokens are per base and read-only or read-write, with no finer scope, and base calls need a 3-day Base-Token generated from them"
        ]
      },
      "negative": 0,
      "verdict": "API tokens are limited to one base and to read-only or read-write, and the official MCP server marks every tool as read-only or destructive. The Free plan allows 3,000 API calls a month in total, and base calls are capped at 200 a minute. The status page showed the base API degraded for 0.77 per cent of 30 days.",
      "bestFor": "Teams that want typed tables hosted in Germany or on their own server, with an agent reading and writing rows through a per-base token or the official MCP server.",
      "strengths": [
        "API tokens are limited to one base, set to read-only or read-write, named per app and deletable, and the token list shows each token's last access time",
        "Official MCP server, MIT-licensed, hosted at `https://mcp.seatable.com/mcp` and listed in the official MCP registry as `io.github.seatable/seatable` at version 1.6.4",
        "All 21 hosted MCP tools carry readOnlyHint, destructiveHint and idempotentHint annotations, and the tool set leaves out table and column changes",
        "Public OpenAPI 3.0 files with 404 operations, plus `llms.txt`, `llms-full.txt` and Markdown copies of the reference pages",
        "Sub-processor list, data processing agreement and security measures are public, and the security page places all user data in Frankfurt and Munich"
      ],
      "weaknesses": [
        "Monthly API call quotas by plan, 3,000 for a whole Free team, 10,000 per user on Plus and 50,000 per user on Enterprise",
        "A 429 response has no body and no Retry-After header is documented, and the REST API has no idempotency keys",
        "Tokens can't be limited to a table, and the MCP tool `query_sql` accepts UPDATE and DELETE statements with no confirmation step",
        "The security page says SeaTable holds no certification, and its bug bounty, expected in 2025, is still described as under construction",
        "No SLA text is published. The pricing page names optional SLAs for Dedicated only, and the terms exclude liability for uninterrupted availability"
      ],
      "agentNotes": [
        "Create an API token for the one base with read-only permission unless writes are needed, then exchange it at `/api/v2.1/dtable/app-access-token/` for a Base-Token",
        "Renew the Base-Token before it expires after 3 days, and send it as `Authorization: Bearer` to `/api-gateway/api/v2/dtables/{base_uuid}/`",
        "Read `x-ratelimit-remaining` and `x-ratelimit-reset` on every base call. SeaTable Cloud allows 200 base calls a minute and answers 429 with no body",
        "Batch writes to save the monthly quota. One call appends or updates up to 1,000 rows over REST and 100 over MCP",
        "Over MCP, prefer `update_rows` and `delete_rows` to `query_sql`, which can run UPDATE and DELETE, and call `get_schema` before writing"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 66.3
        }
      ],
      "editorialScores": {
        "ergonomics": 74,
        "maintenance": 76,
        "payments": 30,
        "reliability": 69,
        "schema": 81,
        "security": 59,
        "transparency": 65
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "npx -y @seatable/mcp-seatable",
      "http": "curl -H \"Authorization: Bearer YOUR_API_TOKEN\" \"https://cloud.seatable.io/api/v2.1/dtable/app-access-token/\"",
      "config": {
        "mcpServers": {
          "seatable": {
            "headers": {
              "Authorization": "Bearer your-api-token"
            },
            "type": "streamable-http",
            "url": "https://mcp.seatable.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/sheets.records",
      "tool": "https://letme.dev/seatable"
    },
    "notable": [
      "The official MCP server is hosted for SeaTable Cloud at https://mcp.seatable.com/mcp over Streamable HTTP, with a Bearer API token or an OAuth flow with PKCE and dynamic client registration (https://github.com/seatable/seatable-mcp)",
      "The MCP server registers 21 tools on the hosted endpoint, 22 in multi-base mode, and its README says it leaves out creating or deleting tables and columns on purpose (https://github.com/seatable/seatable-mcp)",
      "An API token belongs to one base, is read-only or read-write and never expires. Base calls need a Base-Token, a JWT valid for 3 days, generated from it (https://api.seatable.com/reference/authentication)",
      "SeaTable Cloud limits base operations to 200 calls a minute and account operations to 1,000, and has had monthly API quotas by plan since summer 2025 (https://api.seatable.com/reference/limits)",
      "The OpenAPI 3.0 files for version 6.2 hold 404 operations in 8 files, 54 of them base operations (https://github.com/seatable/openapi)",
      "API changelog entry for version 6.2 is dated 21 July 2026 and marks one breaking change, a renamed response field on Get Team Info (https://api.seatable.com/reference/changelog)",
      "The status page reports the base operations API at 99.23 per cent over 30 days and 99.38 per cent over 365, the account API at 99.95 per cent and the MCP server at 99.98 per cent over 30 days (https://status.seatable.com)",
      "The security page says there is no certification for SeaTable, that a penetration test of SeaTable Server was done in September 2024, and that a bug bounty is under construction (https://seatable.com/security/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces graded",
        "value": "SeaTable Cloud's REST API at https://cloud.seatable.io and the hosted MCP server at https://mcp.seatable.com/mcp. The same API and MCP server run against a self-hosted SeaTable Server"
      },
      {
        "label": "Free tier",
        "value": "Free plan for up to 25 users with 10,000 rows, 2 GB of files and 3,000 API calls a month for the team. The registration page says no credit card is required"
      },
      {
        "label": "Rate limits",
        "value": "SeaTable Cloud allows 200 base calls a minute counted per base, 1,000 account calls a minute and 60 Account-Token requests a minute. Dedicated and Server default to 500 and 3,000. The hosted MCP server adds 60 requests a minute per token and 20 concurrent connections"
      },
      {
        "label": "Monthly API quota",
        "value": "3,000 calls for a Free team, 10,000 per user on Plus, 50,000 per user on Enterprise, unlimited on Dedicated, reset each month"
      },
      {
        "label": "Batch size",
        "value": "List, append and update up to 1,000 rows a call and delete up to 10,000. SQL SELECT returns up to 10,000 rows. MCP write tools take up to 100 rows a call"
      },
      {
        "label": "Auth and scopes",
        "value": "API-Token per base, read-only (`r`) or read-write (`rw`), permanent until deleted, or a temporary one valid for one hour. Base-Token (JWT, 3 days) for base calls. Account-Token from username and password for account calls, permanent"
      },
      {
        "label": "Read and write",
        "value": "With a Base-Token, rows, links, tables, views, columns, select options, comments, snapshots, the activity log and SQL. With an Account-Token, bases, groups, sharing, webhooks, automations and import or export"
      },
      {
        "label": "Filtering",
        "value": "`start`, `limit`, `view_name` and `convert_keys` on list rows, and SQL with WHERE, ORDER BY, GROUP BY and LIMIT at `/api-gateway/api/v2/dtables/{base_uuid}/sql/`"
      },
      {
        "label": "MCP server",
        "value": "`@seatable/mcp-seatable` 1.6.4, MIT. 21 tools on the hosted endpoint, among them list_tables, get_schema, list_rows, find_rows, search_rows, query_sql, append_rows, update_rows, upsert_rows, delete_rows, link_rows, upload_file and create_snapshot. Streamable HTTP when hosted, stdio by `npx` for self-hosted servers"
      },
      {
        "label": "Change events",
        "value": "Webhooks per base, created with an Account-Token at `/api/v2.1/workspace/{workspace_id}/dtable/{base_name}/webhooks/`"
      },
      {
        "label": "SDKs",
        "value": "Python `seatable-api` 4.0.0 on PyPI (17 July 2026), JavaScript `seatable-api` 1.0.46 on npm (22 May 2026) and a PHP client generated from the OpenAPI files"
      },
      {
        "label": "Deprecations",
        "value": "No deprecation policy found. Breaking changes are marked in the API changelog entry for each server version"
      },
      {
        "label": "Certifications",
        "value": "None for SeaTable, per its security page. The hosting provider Exoscale's data centres are ISO 27001 certified. Penetration test of SeaTable Server in September 2024 by SRC Security Research \u0026 Consulting"
      },
      {
        "label": "SLA",
        "value": "No SLA text found. The pricing page lists optional corporate support and SLAs for Dedicated, sold through sales with a minimum of 100 users"
      },
      {
        "label": "Data location",
        "value": "Exoscale data centres in Frankfurt and Munich for all user data except subscription and payment data, per the security page. Hetzner in Germany is also on the sub-processor list"
      },
      {
        "label": "Open source",
        "value": "The MCP server is MIT. SeaTable Cloud is a closed service, and SeaTable Server Enterprise Edition is licensed under an EULA"
      }
    ],
    "provenance": {
      "legalEntity": "SeaTable GmbH",
      "domain": "seatable.com",
      "domainRegistered": "2010-03-12",
      "endpointOnVendorDomain": true,
      "terms": "https://seatable.com/terms-of-service/",
      "privacy": "https://seatable.com/data-privacy/",
      "statusPage": "https://status.seatable.com",
      "changelog": "https://api.seatable.com/reference/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The imprint names SeaTable GmbH, 117er Ehrenhof 5, 55118 Mainz, Germany, District Court Mainz, commercial register number HRB 49723.",
        "The Terms of Service for SeaTable Cloud are version 1.0.1, published on 14 April 2022. The German original is binding and the English page is a convenience translation.",
        "The privacy policy is version 1.3.0, published on 5 February 2026, and covers registration and the cloud service as well as the website. A data processing agreement (version 1.1.6, 16 October 2024) and a sub-processor list (version 1.1.5, 16 October 2025) are separate public pages.",
        "The MCP server answers at mcp.seatable.com and the API reference at api.seatable.com. The REST API answers at cloud.seatable.io, a second domain the vendor's site links for login. We didn't check the registration record of seatable.io.",
        "seatable.com/.well-known/security.txt and cloud.seatable.io/.well-known/security.txt return 404. The security page gives security@seatable.com for vulnerability reports.",
        "RDAP for seatable.com gives a registration date of 2010-03-12."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "SeaTable GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "seatable.com, registered 2010-03-12 (16 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "cloud.seatable.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.seatable.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://seatable.com/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 2370,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms of Use shall be governed by and construed in accordance with the law of the Federal Republic of Germany, excluding rules relating to conflict of laws.",
              "says": "The law of Federal Republic of Germany"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "These terms of service are only available in English and German."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "In case of long payment arrears and after repeated requests for payment including setting a deadline, we can terminate your subscription and delete your data."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will inform you about material changes of the Terms at our own discretion by e-mail or notification.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Store copyright/trademark/patent protected material for which no corresponding rights of use exist, as well as its processing, publication, making accessible, editing and redesign"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "The Terms may be updated by us without prior notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We reserve the right to unilaterally terminate your access or restrict your access at any time without prior notice to you."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "SeaTable may use the names, logos and marks of corporate customers on its website and in marketing materials as reference customers.",
              "quote": "We reserve the right to use the name, logo and marks of corporate customers on the seatable.io website and other marketing materials as reference customers."
            },
            {
              "date": "2026-10-08",
              "text": "The user must make their own backups of their files at least every 24 hours.",
              "quote": "The user has to carry out backups and other security measures of his files independently at least every 24 hours."
            },
            {
              "date": "2026-10-08",
              "text": "Once a termination takes effect at the end of the subscription period, data generally cannot be restored, and a restore may be attempted for a fee in justified exceptional cases.",
              "quote": "Once the termination takes effect at the end of the subscription period, it is generally not possible to restore data."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://seatable.com/data-privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 6470,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "When visiting this online offering, we collect data about your browsing behavior and make it analyzable."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "The data collected during registration are stored by us as long as you are registered and will then be deleted."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We do not provide these ourselves but obtain them from service providers."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to Object to Data Collection in Specific Cases and to Direct Marketing"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For this and other questions regarding data protection, you may contact us at any time at the address provided in the legal notice."
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In particular, personal data is not transferred to countries outside the European Union."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "SeaTable says the AI functions in its cloud services run on a self-hosted model and that no personal data is sent outside Europe for them.",
              "quote": "This applies in particular to the use of AI functions in our cloud services. These use a self-hosted AI model (see hoster)."
            },
            {
              "date": "2026-10-08",
              "text": "SeaTable says it does not control how third-party applications, including AI services connected through its API or MCP, process the data they retrieve.",
              "quote": "SeaTable does not control how third-party applications process data retrieved through these interfaces."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/seatable.json",
    "live": {
      "slug": "seatable",
      "probe": {
        "target": "https://cloud.seatable.io",
        "method": "get",
        "lastAt": "2026-10-08T21:12:21.042309916Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 375,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 375,
        "p95ms24h": 411,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.seatable.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:09.649561498Z"
      },
      "updatedAt": "2026-10-08T21:12:21.042309916Z"
    }
  }
}
