{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "semrush",
    "name": "Semrush API + MCP",
    "vendor": "Semrush Inc. (an Adobe company)",
    "vendorUrl": "https://www.semrush.com",
    "kind": "http-api",
    "category": "seo",
    "summary": "Semrush is a search marketing data platform, owned by Adobe since April 2026. Agents reach its keyword, backlink, ranking and traffic data through REST APIs with API keys or a hosted MCP server that spends the same API units.",
    "url": "https://www.anchorterminal.com/tools/semrush",
    "markdownUrl": "https://www.anchorterminal.com/tools/semrush.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/semrush.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/semrush.json",
    "license": "Proprietary service under the Semrush terms of service",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.semrush.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Version 4 methods take an API key in `Authorization: Apikey \u003ckey\u003e`, created in the profile with a read-only or read and write permission and an optional expiry. Version 3 methods take the account's single key as the `key` query parameter. The MCP server signs in by OAuth 2.1 against the user's Semrush account, or takes the API key header. Access is self-serve for a paying account, with no app review. Trends Premium and custom plans go through sales.",
    "pricing": "paid",
    "pricingNotes": "Every API needs a paid subscription, and calls spend API units. The Standard API needs the SEO Business plan plus a unit package of 2 to 20 million units, whose prices aren't on a public page. The MCP page says Semrush One Starter and Pro+ and SEO Classic Pro and Guru include 50,000 units. Our request saw plan prices in pounds, from £113 a month for SEO to £444 for Advanced. The free plan (no card, 10 reports a day) has no API units, and the 7-day trial's card requirement wasn't checked.",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the MCP page or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 14,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.semrush.com/api/",
    "llmsTxt": "https://developer.semrush.com/api/llms.txt",
    "capabilities": [
      "seo.keywords",
      "seo.backlinks",
      "seo.rankings",
      "seo.traffic",
      "seo.serp"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "api-key",
      "llms-txt",
      "closed-source",
      "subscription",
      "usage-units",
      "bug-bounty",
      "adobe"
    ],
    "lastRelease": "2026-09-04",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 53.1,
      "grade": "D",
      "agentReady": false,
      "rank": 487,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 77,
        "maintenance": 57,
        "payments": 17,
        "reliability": 34,
        "schema": 70,
        "security": 54,
        "transparency": 67
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 34,
          "points": 6.8,
          "reason": "Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 54,
          "points": 9.45,
          "reason": "Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 17,
          "points": 2.13,
          "reason": "No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 57,
          "points": 4.99,
          "reason": "The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 67,
          "points": 5.86,
          "note": "editorial 59, provenance 75",
          "reason": "Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77.",
          "maintenance": "The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57.",
          "payments": "No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17.",
          "reliability": "Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34.",
          "schema": "No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70.",
          "security": "Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54.",
          "transparency": "Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59."
        },
        "sources": [
          {
            "what": "API docs index for agents",
            "url": "https://developer.semrush.com/api/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server guide",
            "url": "https://developer.semrush.com/api/introduction/semrush-mcp/",
            "seen": "2026-10-08"
          },
          {
            "what": "version 4 authorisation",
            "url": "https://developer.semrush.com/api/v4/get-started/authorization/",
            "seen": "2026-10-08"
          },
          {
            "what": "version 3 authorisation",
            "url": "https://developer.semrush.com/api/v3/get-started/authorization/",
            "seen": "2026-10-08"
          },
          {
            "what": "API versions and keys",
            "url": "https://developer.semrush.com/api/v4/introduction/api-versions/",
            "seen": "2026-10-08"
          },
          {
            "what": "API access and plans",
            "url": "https://developer.semrush.com/api/v4/get-started/api-access/",
            "seen": "2026-10-08"
          },
          {
            "what": "usage restrictions",
            "url": "https://developer.semrush.com/api/v4/introduction/api-usage-restrictions/",
            "seen": "2026-10-08"
          },
          {
            "what": "API unit balance and query log",
            "url": "https://developer.semrush.com/api/v4/get-started/api-units-balance/",
            "seen": "2026-10-08"
          },
          {
            "what": "SEO API overview, errors and filtering",
            "url": "https://developer.semrush.com/api/v4/seo/overview/",
            "seen": "2026-10-08"
          },
          {
            "what": "Backlinks API v4",
            "url": "https://developer.semrush.com/api/v4/seo/backlinks/",
            "seen": "2026-10-08"
          },
          {
            "what": "Keyword reports API v4",
            "url": "https://developer.semrush.com/api/v4/seo/keyword-reports/",
            "seen": "2026-10-08"
          },
          {
            "what": "Domain reports API v3",
            "url": "https://developer.semrush.com/api/v3/seo/domain-reports/",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://developer.semrush.com/api/v4/introduction/release-notes/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth metadata",
            "url": "https://mcp.semrush.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=semrush",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.semrush.com/pricing/seo-ai-search/",
            "seen": "2026-10-08"
          },
          {
            "what": "API knowledge base article",
            "url": "https://www.semrush.com/kb/5-api",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.semrush.com/company/legal/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.semrush.com/company/legal/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "DPA",
            "url": "https://www.semrush.com/company/legal/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://www.semrush.com/company/legal/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "AI services terms",
            "url": "https://www.semrush.com/company/legal/semrush-artificial-intelligence-services-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.semrush.com/company/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "Adobe acquisition press release",
            "url": "https://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/semrush.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account",
          "unchecked: prices of API unit packages and of the Trends API, which the public pages don't show",
          "unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty",
          "unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access",
          "unchecked: the HackerOne programme page, which needs JavaScript",
          "No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points",
          "The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both",
          "Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition"
        ]
      },
      "negative": 0,
      "verdict": "The hosted MCP server exposes 14 tools that load a report's parameters on demand, and version 4 API keys can be read-only, time-limited and revoked. Most reports still sit in version 3, whose single key travels in the URL and can't be revoked. No status page, OpenAPI file or API unit price was found.",
      "bestFor": "Teams already paying for Semrush who want an agent to pull keyword, backlink, ranking and traffic estimates in one place, mainly through the MCP server.",
      "strengths": [
        "Hosted MCP server at mcp.semrush.com/v2/mcp with OAuth 2.1, dynamic client registration and 14 named tools, limited to reads",
        "Version 4 keys can be read-only or read and write, carry an expiry, and be revoked. An account can hold up to 100",
        "Every method page states its cost in API units, and `limit`, `fields` and `filter` cap what a call spends",
        "llms.txt indexes for the developer site and for each API version, with dated release notes since March 2026",
        "API Query log records time, IP address, report type and units spent for SEO API and Projects v4 calls, with CSV export"
      ],
      "weaknesses": [
        "Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked",
        "Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change",
        "No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages",
        "API unit package prices aren't published, and every API needs a paid subscription",
        "When units run short, per-line SEO and Trends reports return fewer lines instead of an error"
      ],
      "agentNotes": [
        "Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report`",
        "Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50",
        "Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error",
        "Send the version 4 key as `Authorization: Apikey \u003ckey\u003e`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs",
        "Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 53.1
        }
      ],
      "editorialScores": {
        "ergonomics": 77,
        "maintenance": 57,
        "payments": 17,
        "reliability": 34,
        "schema": 70,
        "security": 54,
        "transparency": 59
      },
      "provenanceScore": 75
    },
    "connect": {
      "http": "curl -H 'Authorization: Apikey YOUR_API_KEY' \"https://api.semrush.com/apis/v4/keywords/v1/metrics?keyword=seo%20tools\u0026country=US\"",
      "claudeCode": "claude mcp add semrush https://mcp.semrush.com/v2/mcp -t http",
      "config": {
        "mcpServers": {
          "semrush": {
            "url": "https://mcp.semrush.com/v2/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/seo.keywords",
      "tool": "https://letme.dev/semrush"
    },
    "notable": [
      "The MCP server uses streamable HTTP only at https://mcp.semrush.com/v2/mcp and covers all Trends API and SEO API methods plus the read-only Projects API v3 methods (https://developer.semrush.com/api/introduction/semrush-mcp/)",
      "Version 4 keys are per integration, up to 100 an account, each read-only or read and write with an optional expiry. The version 3 key is single, automatic and can't be revoked or deleted (https://developer.semrush.com/api/v4/introduction/api-versions/)",
      "The Keyword and Backlinks reports in version 4 carry an Early Access notice, billed at version 3 rates until general availability (https://developer.semrush.com/api/v4/seo/backlinks/)",
      "All API methods are limited to 10 requests a second and 10 simultaneous requests per account, and responses may be cached for one month at most (https://developer.semrush.com/api/v4/introduction/api-usage-restrictions/)",
      "Adobe completed its acquisition of Semrush Holdings, Inc. on 28 April 2026 (https://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/)",
      "The terms bar use of the Services or their data as input to, or for training, any artificial intelligence or machine learning technology, which we read as a limit an agent builder should check (https://www.semrush.com/company/legal/terms-of-service/)"
    ],
    "area": "web-data",
    "details": [
      {
        "label": "Surfaces graded",
        "value": "The public REST APIs at api.semrush.com (version 3 and version 4) and the official hosted MCP server, which the vendor's llms.txt recommends for agents"
      },
      {
        "label": "APIs",
        "value": "SEO API (version 4 Backlinks and Keyword reports; version 3 Domain, Overview, URL, subdomain and subfolder reports), Trends API (version 3), Projects API (folders in version 4; Position Tracking and Site Audit in version 3), Local API (version 4)"
      },
      {
        "label": "MCP server",
        "value": "Hosted, streamable HTTP, https://mcp.semrush.com/v2/mcp. 12 discovery tools (domain_overview, organic_research, keyword_research, competitors_research, backlinks_research, audience_research, traffic_overview, paid_search_research, shopping_research, position_tracking, site_audit, projects) plus get_report_schema and execute_report"
      },
      {
        "label": "Credentials",
        "value": "Version 4 API key in `Authorization: Apikey \u003ckey\u003e` or `?key=`; version 3 key in `?key=` only; MCP by OAuth 2.1 (scope mcp.access, dynamic client registration, PKCE) or the API key header. OAuth 2.0 device flow remains for deprecated methods"
      },
      {
        "label": "Access",
        "value": "Standard API needs the SEO Business plan plus an API unit package, per the API access page. The MCP page lists Semrush One Starter and Pro+ and SEO Classic Pro and Guru with 50,000 units included. Trends API is a separate subscription, Premium through sales"
      },
      {
        "label": "Unit costs",
        "value": "Keyword metrics 20 units a request; backlinks overview 45 a request; backlinks and referring domains 40 to 45 a line; domain organic keywords 10 a line, 50 for historical data. Empty responses cost nothing. Local API calls use no units"
      },
      {
        "label": "Unit packages",
        "value": "2, 5, 10 or 20 million units, renewed with the subscription, unused units expire. Package prices are shown in the account, not on a public page"
      },
      {
        "label": "Rate limits",
        "value": "10 requests a second and 10 simultaneous requests per account. Trends API 10,000 requests a month by default. Listing Management Get Categories 10 a minute"
      },
      {
        "label": "Errors",
        "value": "Version 4 returns JSON with meta.request_id, error.code, error.message and error.retryable, and lists 400, 401, 403, 404, 409, 429, 499, 500, 501, 503 and 504. Version 3 returns text codes such as `ERROR 132 :: API UNITS BALANCE IS ZERO`"
      },
      {
        "label": "Response control",
        "value": "Version 4 has `fields`, `limit`, `offset`, `order_by`, `direction`, a `filter` expression language and JSON or CSV. Version 3 has `export_columns`, `display_limit`, `display_offset`, `display_filter`, `display_sort` and CSV"
      },
      {
        "label": "Audit",
        "value": "API Query log in the profile with query, time, IP address, database, report type, rows, cost and remaining balance, exportable to CSV up to 50,000 rows. SEO API and Projects v4 only"
      },
      {
        "label": "Security programme",
        "value": "PCI DSS Level 1, annual penetration tests, a bug bounty on HackerOne, SAML SSO and two-factor sign-in per the security page. No SOC 2 or ISO 27001 statement on that page. No security.txt"
      },
      {
        "label": "Data locations",
        "value": "Data centres in the United States on Amazon Web Services, Google Cloud Platform and Digital Realty, per the security page. Sub-processor list last updated November 2025"
      },
      {
        "label": "Ownership",
        "value": "Semrush Inc., Boston, is the contracting entity in the terms of 25 August 2026. Adobe completed the acquisition of Semrush Holdings, Inc. on 28 April 2026"
      }
    ],
    "provenance": {
      "legalEntity": "Semrush Inc.",
      "domain": "semrush.com",
      "domainRegistered": "2008-10-03",
      "endpointOnVendorDomain": true,
      "terms": "https://www.semrush.com/company/legal/terms-of-service/",
      "privacy": "https://www.semrush.com/company/legal/privacy-policy/",
      "statusPage": "",
      "changelog": "https://developer.semrush.com/api/v4/introduction/release-notes/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (last updated 25 August 2026) name Semrush Inc., a Delaware corporation at 800 Boylston Street, Suite 2475, Boston, MA 02199. The site footer reads © 2026 Semrush Holdings and carries an Adobe logo.",
        "Adobe announced completion of its acquisition of Semrush Holdings, Inc. on 28 April 2026, in a press release on semrush.com. The terms and the privacy policy (last modified 13 October 2025) don't mention Adobe.",
        "The APIs answer at api.semrush.com and the MCP server at mcp.semrush.com, with OAuth metadata pointing to oauth.semrush.com and api.semrush.com.",
        "www.semrush.com/.well-known/security.txt returns 404. The security page gives security@semrush.com and links to a HackerOne programme.",
        "No status page is linked from the developer docs, the home page or the security page. status.semrush.com doesn't resolve in DNS.",
        "RDAP for semrush.com gives a registration date of 2008-10-03 and MarkMonitor Inc. as registrar."
      ],
      "score": 75,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Semrush Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "semrush.com, registered 2008-10-03 (18 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.semrush.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.semrush.com/company/legal/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-25",
          "words": 9558,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: August 25, 2026",
              "says": "Last updated 2026-08-25"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "Subject to Section 2 (Dispute Resolution by Binding Arbitration), if you are located in the European Economic Area (EEA), Switzerland or the United Kingdom, this Agreement is governed by the laws of the Republic of Ireland and jurisdiction and venue shall be Dublin, Ireland.",
              "says": "The law of the Republic of Ireland"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Our maximum aggregate liability to you for any damages arising from or related to this Agreement is limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises.",
              "says": "Capped at the greater of fifty dollars and the fees paid in the 3 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Semrush may suspend, limit or terminate access to a Beta Version at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will notify you of changes to this arbitration provision by posting the amended terms on the Site or by email, in each case at least thirty (30) days before the effective date of the changes.",
              "says": "Gives thirty days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not have such authority, or if you do not agree with the terms of this Agreement, you must not accept this Agreement and may not use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(k) use or launch any automated system, including, “robots,” “spiders,” or “offline readers,” that sends more request messages to our servers in a given period of time than a human can reasonably produce in the same period by using a conventional browser",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(i) access the Services if you are a competitor of ours or use the Services to build a similar or competitive work",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Notwithstanding anything contrary herein, Semrush reserves the right to cancel your subscription upon notice immediately for any reasons"
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "You agree to arbitrate all Claims between you and us, that cannot be amicably resolved in accordance with the foregoing paragraph."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers may not use Semrush outputs as inputs or prompts to, or to train or improve, any AI system, except through Semrush's official integrations embedded into an AI system.",
              "quote": "use, access, copy, or process any Semrush intellectual property (including insights, analyses, suggestions, graphs and other outputs from the Services, including generative AI outputs) or Semrush Confidential Information as inputs/prompts into"
            },
            {
              "date": "2026-10-08",
              "text": "Semrush API subscribers may not send more than ten inquiries a second from one IP address, or cache information from the service for more than one month without written consent.",
              "quote": "(i) not to forward more than ten (10) inquiries per one (1) second from one unique IP address or more than ten (10) simultaneous inquiries from one (1) Authorized User; and (ii) not to cache the information received from the Services for more than one (1) month"
            },
            {
              "date": "2026-10-08",
              "text": "Semrush limits its total liability to the greater of 50 US dollars or the amount paid in the three months before the cause of action arose.",
              "quote": "limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.semrush.com/company/legal/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-13",
          "words": 5434,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Modified Date: October 13, 2025",
              "says": "Last updated 2025-10-13"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "…Policy explains how Semrush collects, uses, stores, discloses and otherwise processes the personal data we collect when you use and interact with our websites and apps that display or link to this Privacy Policy, register for an account and use our Services, visit our branded social media pages, register for, attend o…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain your personal data for as long as reasonably necessary to provide the Services and fulfil the transactions you have requested, complying with our legal obligations or for other legitimate business purposes, such as maintaining business and financial records, resolving disputes, maintaining security, detectin…",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers as a service provider or processor."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Semrush will not sell, rent, lease or otherwise provide your personal data to others, except in order to provide you with the products and services you request and as further described below, or with your permission or as required by applicable law.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "It also tells you about your rights and choices with respect to your personal data, and how you can contact us if you have any questions or concerns."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you wish to update or delete your testimonial, you can contact us at privacy@semrush.com.",
              "says": "privacy@semrush.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…continue to be protected pursuant to the applicable data protection law, including through the use of Standard Contractual Clauses approved by the European Commission.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "limited personal data about you, such as your email address, to hash it and to share it with social network"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The policy does not cover personal data that Semrush processes on behalf of business customers as a service provider or processor.",
              "quote": "This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/semrush.json",
    "live": {
      "slug": "semrush",
      "probe": {
        "target": "https://api.semrush.com",
        "method": "get",
        "lastAt": "2026-10-08T18:20:39.850276067Z",
        "lastOk": true,
        "lastStatus": 400,
        "lastMs": 139,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 133,
        "p95ms24h": 189,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "securityTxt": {
        "url": "https://semrush.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:05.730669338Z"
      },
      "pages": [
        {
          "url": "https://developer.semrush.com/api/v4/introduction/release-notes/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:17.791899201Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8ec987932bb2"
        }
      ],
      "updatedAt": "2026-10-08T18:20:39.850276067Z"
    }
  }
}
