{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "smithery",
    "name": "Smithery",
    "vendor": "Smithery (Arcade.dev)",
    "vendorUrl": "https://smithery.ai",
    "kind": "http-api",
    "category": "aggregator",
    "summary": "Smithery is a hosted registry and connection service for MCP servers, part of Arcade.dev since August 2026. Agents search the registry, create connections and call tools through a REST API, a per-namespace MCP endpoint, a TypeScript client or a CLI.",
    "url": "https://www.anchorterminal.com/tools/smithery",
    "markdownUrl": "https://www.anchorterminal.com/tools/smithery.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/smithery.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smithery.json",
    "repo": "https://github.com/smithery-ai/cli",
    "license": "Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.smithery.ai",
    "packages": [
      {
        "registry": "npm",
        "name": "@smithery/api"
      },
      {
        "registry": "npm",
        "name": "smithery"
      }
    ],
    "auth": "mixed",
    "authNotes": "A person signs in at smithery.ai and creates an API key, which has full access to the namespace and is sent as a Bearer token. `POST /tokens` mints service tokens limited by namespace, resource (connections, servers, namespaces, skills), operation (read, write, execute) and connection metadata, with a default lifetime of one hour and a maximum of 24. Organisation admins can create, list and revoke team API keys. The CLI signs in with OAuth in a browser. Upstream services are authorised by each end user on a hosted setup page, and Smithery stores and refreshes those credentials. Token Scoping is marked preview.",
    "pricing": "freemium",
    "pricingNotes": "Prices were not established. smithery.ai/pricing is drawn by script and showed our reader only the navigation. Arcade's announcement of 5 August 2026 says people can sign up for free. Whether a card is needed, what a paid plan costs and whether tool calls are metered were not read (checked 2026-10-09).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or the CLI source. The pricing page is drawn by script and was not read (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 840,
      "npmWeekly": 2729,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://smithery.ai/docs",
    "llmsTxt": "https://smithery.ai/docs/llms.txt",
    "openapi": "https://smithery.ai/docs/openapi.json",
    "capabilities": [
      "automation.apps",
      "automation.auth",
      "automation.actions",
      "agent.tools",
      "automation.webhooks"
    ],
    "tags": [
      "hosted",
      "mcp",
      "registry",
      "freemium",
      "api-key",
      "oauth",
      "openapi",
      "llms-txt",
      "typescript",
      "cli",
      "status-page",
      "closed-source"
    ],
    "lastRelease": "2026-07-20",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 50.7,
      "grade": "D",
      "agentReady": false,
      "rank": 766,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 65,
        "maintenance": 43,
        "payments": 10,
        "reliability": 60,
        "schema": 76,
        "security": 50,
        "transparency": 46
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Read with the hosted lines. status.smithery.ai on Better Stack lists the site, the API and the gateway (20). Each shows 100 per cent uptime over 90 days. The page's incident list is a script-drawn tab and was not read, so 25 of 30 (25). No rate limits were found in the docs index or the API description (0). The API description declares no 429. The TypeScript client retries 408, 409, 429 and 5xx twice with backoff, and the `PUT` endpoints are described as idempotent upserts. No retry guidance for tool calls was found (8). No SLA was found (0). The connection API carries no beta label, while Token Scoping and the typed SDKs are marked preview and the client is at 0.68 (7)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "An OpenAPI 3.1 file with 35 paths and 55 operations is linked from the docs index. We read the description file, not the rendered reference (25). `/docs/llms.txt`, a Markdown twin of every page and a docs MCP server (10). Every operation has a description, mostly one line, some naming the scope needed or the replacement for a deprecated call. None says when not to use it (12). 24 enums, length limits and patterns on names, and `additionalProperties: false` on most objects. Tool arguments and results are open objects, as a pass-through must be (10). 161 examples in the file, curl, TypeScript and CLI samples in the guides, and declared 400, 401, 403, 404, 409 and 422 responses. No error catalogue was found (11). The API states version 1.0.0 with no version in the path and no API changelog. The client and CLI changelogs are dated, and three operations are marked deprecated (8)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "Graded as an API. Registry lists take `fields`, the CLI has `tool find` and `tool get`, and one call lists tools across a namespace. The namespace MCP endpoint loads every connection's tools, so context grows with the number of connections (15). `page` and `pageSize` up to 100, `cursor` and `limit` on connections, and metadata filters (16). Errors carry `error` and `message`, and a connection that needs action returns `auth_required` or `input_required` with `setupUrl` and the missing fields (15). Upserts are idempotent and the client retries safely. Tool calls take no idempotency key, and whether upstream MCP annotations are passed through was not established (10). A namespace and connection ID are created when omitted. One official client language, TypeScript, plus the CLI (9)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 50,
          "points": 8.75,
          "reason": "An API key has full namespace access. Service tokens are scoped by namespace, resource, operation and metadata, last 24 hours at most and can be narrowed, and team keys can be revoked. Token Scoping is in preview (26). Read-only and execute-only tokens are documented. No approval step for destructive tools was found (12). Connected servers return third-party content. A registry record carries `security.scanPassed`, and no prompt-injection guidance was found (4). Runtime logs by invocation exist for people who publish a server. No call log for connection users was found (5). The docs say stored credentials are encrypted and write-only. security.txt answered 404, and no certification, bounty or disclosure policy was found beyond a contact address (3)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). The pricing page is drawn by script and was not read, so no price is scored. This is a limit of our reading and not a finding about the vendor (0). Arcade's announcement says sign-up is free. Whether a card is needed was not established, so half marks (10). A person signs in through a browser to get an API key or to log the CLI in (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 43,
          "points": 3.76,
          "reason": "The newest release found is `@smithery/api` 0.68.0 on 20 July 2026, 81 days before the check. The CLI's last release and last commit are 1.2.0 on 31 May 2026 (20). One release in the last 90 days (0). The CLI repository, now under arcadeai-labs, shows 51 open issues and no push since 31 May. The issues themselves were not read, and a Discord server is linked for support (6). One current official client, in TypeScript (10). Both repositories carry CI workflows, lockfiles and release automation (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 46,
          "points": 4.03,
          "note": "editorial 27, provenance 65",
          "reason": "The editorial half. The hosted service is closed and no terms of service were found. The CLI is AGPL-3.0, the client Apache-2.0 and the credential layer MIT (12). The privacy notice of 20 June 2025 gives no retention periods, says customer content is used to improve products, describes targeted advertising, and links a Data Policy that answers 404. A data processing agreement is available on request (8). Deprecated operations are marked in the API description with their replacements, with no dates and no policy (5). Stripe is the only processor named, and no hosting location or sub-processor list was found (2)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded as an API. Registry lists take `fields`, the CLI has `tool find` and `tool get`, and one call lists tools across a namespace. The namespace MCP endpoint loads every connection's tools, so context grows with the number of connections (15). `page` and `pageSize` up to 100, `cursor` and `limit` on connections, and metadata filters (16). Errors carry `error` and `message`, and a connection that needs action returns `auth_required` or `input_required` with `setupUrl` and the missing fields (15). Upserts are idempotent and the client retries safely. Tool calls take no idempotency key, and whether upstream MCP annotations are passed through was not established (10). A namespace and connection ID are created when omitted. One official client language, TypeScript, plus the CLI (9).",
          "maintenance": "The newest release found is `@smithery/api` 0.68.0 on 20 July 2026, 81 days before the check. The CLI's last release and last commit are 1.2.0 on 31 May 2026 (20). One release in the last 90 days (0). The CLI repository, now under arcadeai-labs, shows 51 open issues and no push since 31 May. The issues themselves were not read, and a Discord server is linked for support (6). One current official client, in TypeScript (10). Both repositories carry CI workflows, lockfiles and release automation (7).",
          "payments": "No x402, MPP or L402 (0). The pricing page is drawn by script and was not read, so no price is scored. This is a limit of our reading and not a finding about the vendor (0). Arcade's announcement says sign-up is free. Whether a card is needed was not established, so half marks (10). A person signs in through a browser to get an API key or to log the CLI in (0).",
          "reliability": "Read with the hosted lines. status.smithery.ai on Better Stack lists the site, the API and the gateway (20). Each shows 100 per cent uptime over 90 days. The page's incident list is a script-drawn tab and was not read, so 25 of 30 (25). No rate limits were found in the docs index or the API description (0). The API description declares no 429. The TypeScript client retries 408, 409, 429 and 5xx twice with backoff, and the `PUT` endpoints are described as idempotent upserts. No retry guidance for tool calls was found (8). No SLA was found (0). The connection API carries no beta label, while Token Scoping and the typed SDKs are marked preview and the client is at 0.68 (7).",
          "schema": "An OpenAPI 3.1 file with 35 paths and 55 operations is linked from the docs index. We read the description file, not the rendered reference (25). `/docs/llms.txt`, a Markdown twin of every page and a docs MCP server (10). Every operation has a description, mostly one line, some naming the scope needed or the replacement for a deprecated call. None says when not to use it (12). 24 enums, length limits and patterns on names, and `additionalProperties: false` on most objects. Tool arguments and results are open objects, as a pass-through must be (10). 161 examples in the file, curl, TypeScript and CLI samples in the guides, and declared 400, 401, 403, 404, 409 and 422 responses. No error catalogue was found (11). The API states version 1.0.0 with no version in the path and no API changelog. The client and CLI changelogs are dated, and three operations are marked deprecated (8).",
          "security": "An API key has full namespace access. Service tokens are scoped by namespace, resource, operation and metadata, last 24 hours at most and can be narrowed, and team keys can be revoked. Token Scoping is in preview (26). Read-only and execute-only tokens are documented. No approval step for destructive tools was found (12). Connected servers return third-party content. A registry record carries `security.scanPassed`, and no prompt-injection guidance was found (4). Runtime logs by invocation exist for people who publish a server. No call log for connection users was found (5). The docs say stored credentials are encrypted and write-only. security.txt answered 404, and no certification, bounty or disclosure policy was found beyond a contact address (3).",
          "transparency": "The editorial half. The hosted service is closed and no terms of service were found. The CLI is AGPL-3.0, the client Apache-2.0 and the credential layer MIT (12). The privacy notice of 20 June 2025 gives no retention periods, says customer content is used to improve products, describes targeted advertising, and links a Data Policy that answers 404. A data processing agreement is available on request (8). Deprecated operations are marked in the API description with their replacements, with no dates and no policy (5). Stripe is the only processor named, and no hosting location or sub-processor list was found (2)."
        },
        "sources": [
          {
            "what": "robots.txt, which disallows `/api/`, `/_next/`, `/admin/`, `/settings/` and `/deploy/` and nothing we read",
            "url": "https://smithery.ai/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "home page",
            "url": "https://smithery.ai/",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index",
            "url": "https://smithery.ai/docs/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "Connect to MCPs guide",
            "url": "https://smithery.ai/docs/use/connect.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Token Scoping guide",
            "url": "https://smithery.ai/docs/use/token-scoping.md",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI docs",
            "url": "https://smithery.ai/docs/concepts/cli.md",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI description, read as the file and not the rendered reference",
            "url": "https://smithery.ai/docs/openapi.json",
            "seen": "2026-10-09"
          },
          {
            "what": "Call tool reference page",
            "url": "https://smithery.ai/docs/api-reference/connect/call-tool.md",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy notice, last updated 20 June 2025",
            "url": "https://smithery.ai/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing page, navigation only",
            "url": "https://smithery.ai/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "about page",
            "url": "https://smithery.ai/about",
            "seen": "2026-10-09"
          },
          {
            "what": "status page (its robots.txt answered 200 with an empty body)",
            "url": "https://status.smithery.ai/",
            "seen": "2026-10-09"
          },
          {
            "what": "Arcade's acquisition announcement of 5 August 2026",
            "url": "https://arcade.dev/blog/smithery-joins-arcade",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI source, changelog and tags, read from a shallow clone",
            "url": "https://github.com/smithery-ai/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "TypeScript client README, changelog, tags and SECURITY.md, read from a shallow clone",
            "url": "https://github.com/smithery-ai/typescript-api",
            "seen": "2026-10-09"
          },
          {
            "what": "agent.pw README and licence, read from a shallow clone",
            "url": "https://github.com/smithery-ai/agent.pw",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI repository record, which redirects to arcadeai-labs/smithery-cli",
            "url": "https://api.github.com/repos/smithery-ai/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "npm package records and weekly downloads",
            "url": "https://registry.npmjs.org/@smithery/api/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP record for smithery.ai",
            "url": "https://rdap.org/domain/smithery.ai",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the pricing page, which is drawn by script. Plans, unit prices, the free allowance and whether a card is needed are unknown, and Payments is scored without them.",
          "unchecked: the status page's incident list, a script-drawn tab.",
          "unchecked: the open issues in the CLI repository, the Uplink, Triggers and Publish guides, and the second API description hosted by Stainless.",
          "No terms of service were found for the hosted service. Whether Arcade's terms now govern Smithery accounts was not established.",
          "The privacy notice's Data Policy link answers 404, so how Smithery handles data passing through connections is not stated anywhere we read.",
          "Whether Smithery will remain a separate product under Arcade. The announcement says to keep using smithery.ai and gives no plan or date.",
          "The lead was right about the interface. It did not mention the acquisition by Arcade.dev, and data/tools/arcade.json is a separate listing with its own domain, API and terms.",
          "`githubStars` is the CLI repository's count. The number of servers in the registry was not established."
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "22 May 2026. CLI release 1.1.1 removed the `smithery skill` subcommand, and on 9 October 2026 the CLI docs page and the repository README still tell users to run `smithery skill search` and `smithery skill add`. A stale claim in the docs, so 2 points (https://github.com/smithery-ai/cli/blob/main/CHANGELOG.md, https://smithery.ai/docs/concepts/cli.md)."
      ],
      "verdict": "Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.",
      "bestFor": "A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.",
      "strengths": [
        "Service tokens are scoped by namespace, resource, operation (read, write, execute) and connection metadata, expire within 24 hours and can be narrowed further",
        "An OpenAPI 3.1 file with 55 operations, `/docs/llms.txt` and a Markdown twin of every docs page",
        "Connections report `auth_required` or `input_required` with a hosted `setupUrl` and the list of missing fields",
        "Stored credentials are write-only per the docs, and the credential layer, agent.pw, is published under MIT",
        "The status page shows 100 per cent uptime over 90 days for the site, the API and the gateway"
      ],
      "weaknesses": [
        "No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found",
        "The privacy notice links a Data Policy at `/docs/use/data-policy`, which answers 404",
        "No rate limits, 429 response or SLA appear in the docs or the API description",
        "The CLI repository has had no commit since 31 May 2026 and the API client's last release is 0.68.0 of 20 July 2026",
        "The CLI docs and README still list `smithery skill` commands that release 1.1.1 removed on 22 May 2026",
        "Token Scoping and the typed SDKs are marked preview, with breaking changes possible without notice"
      ],
      "agentNotes": [
        "Keep the API key on the backend and hand an agent a service token limited to `connections` with `read` and `execute` and a `metadata` match",
        "Create connections with `PUT /connect/{namespace}/{connectionId}`, which is an upsert, and check `status.state` before calling a tool",
        "On `auth_required` or `input_required`, send the person to `setupUrl`, then retry with the same `connectionId`",
        "Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as `user-123-github.search_repositories`",
        "Do not rely on `smithery skill` commands. Version 1.1.1 of the CLI removed them"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 50.7
        }
      ],
      "editorialScores": {
        "ergonomics": 65,
        "maintenance": 43,
        "payments": 10,
        "reliability": 60,
        "schema": 76,
        "security": 50,
        "transparency": 27
      },
      "provenanceScore": 65
    },
    "connect": {
      "install": "npm install -g smithery@latest",
      "http": "curl -X PUT \"https://smithery.run/my-app/my-browserbase\" \\\n  -H \"Authorization: Bearer $SMITHERY_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"mcpUrl\": \"https://mcp.browserbase.com/mcp\"}'"
    },
    "letme": {
      "capability": "https://letme.dev/automation.apps",
      "tool": "https://letme.dev/smithery"
    },
    "notable": [
      "Arcade.dev announced on 5 August 2026 that it had acquired Smithery, and every smithery.ai page carries a banner saying so (https://arcade.dev/blog/smithery-joins-arcade)",
      "A namespace URL, `https://mcp.smithery.run/{namespace}`, puts every connection in a namespace behind one MCP endpoint, with tool names prefixed by connection ID (https://smithery.ai/docs/use/connect.md)",
      "The docs say credentials are encrypted and write-only, and that the auth and credential layer is the open-source agent.pw (https://smithery.ai/docs/use/connect.md)",
      "The CLI repository now answers at arcadeai-labs/smithery-cli, with 840 stars, 51 open issues and a last push on 31 May 2026 (https://github.com/smithery-ai/cli)",
      "The CLI asks for consent before sending analytics, and consent defaults to off in its settings file (https://github.com/smithery-ai/cli/blob/main/src/utils/smithery-settings.ts)",
      "npm counted 2,729 downloads of `@smithery/api` and 770 of `smithery` in the week to 7 October 2026 (https://api.npmjs.org/downloads/point/last-week/@smithery/api)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "REST API at `https://api.smithery.ai` (55 operations in the OpenAPI 3.1 file), connection calls at `https://smithery.run/{namespace}/{connectionId}`, a namespace MCP endpoint at `https://mcp.smithery.run/{namespace}`, the `@smithery/api` TypeScript client and the `smithery` CLI"
      },
      {
        "label": "Connections",
        "value": "A long-lived session to one MCP server, named by `server` (a registry name) or `mcpUrl`, with free-form `metadata` for filtering by user. States are `connected`, `disconnected`, `auth_required`, `input_required` and `error`"
      },
      {
        "label": "Credentials",
        "value": "API key with full namespace access, team API keys an organisation admin can revoke, and service tokens scoped by namespace, resource, operation and metadata, one hour by default and 24 at most. Token Scoping is in preview"
      },
      {
        "label": "End-user authorisation",
        "value": "Smithery keeps OAuth apps for popular integrations and returns a hosted `setupUrl`. Tokens refresh automatically, and a failed refresh sets the connection to `auth_required`"
      },
      {
        "label": "Registry",
        "value": "`GET /servers` and `GET /skills` search by full text and meaning, with `page`, `pageSize` (maximum 100), `topK` and `fields`. A server record carries `security.scanPassed`"
      },
      {
        "label": "Triggers",
        "value": "Connections can expose trigger types, and subscriptions deliver events to a webhook URL with a secret and a TTL"
      },
      {
        "label": "Uplink",
        "value": "The CLI can expose a local MCP server as a Smithery connection over `wss://uplink.smithery.run` without deploying it"
      },
      {
        "label": "Errors",
        "value": "JSON with `error` and `message`. Declared statuses are 400, 401, 403, 404, 409, 422, 500 and 502. No 429 is declared"
      },
      {
        "label": "Client",
        "value": "`@smithery/api` 0.68.0 of 20 July 2026, generated by Stainless, Apache-2.0. It retries connection errors, 408, 409, 429 and 5xx twice with backoff and times out after one minute"
      },
      {
        "label": "CLI",
        "value": "`smithery` 1.2.0 of 31 May 2026, AGPL-3.0, Node.js 20 or later. `--json` output is chosen automatically outside a terminal"
      },
      {
        "label": "Status",
        "value": "status.smithery.ai on Better Stack, three components (smithery.ai, Smithery API, Smithery Gateway), each at 100 per cent over 90 days on 9 October 2026"
      },
      {
        "label": "Ownership",
        "value": "Clavia, Inc. doing business as Smithery, per the privacy notice of 20 June 2025. Acquired by Arcade.dev, announced 5 August 2026"
      }
    ],
    "provenance": {
      "legalEntity": "Clavia, Inc. (doing business as Smithery)",
      "domain": "smithery.ai",
      "domainRegistered": "2024-12-10",
      "endpointOnVendorDomain": true,
      "terms": "",
      "privacy": "https://smithery.ai/privacy",
      "statusPage": "https://status.smithery.ai",
      "changelog": "https://github.com/smithery-ai/typescript-api/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Smithery Privacy Notice, last updated 20 June 2025, names Clavia, Inc. doing business as Smithery and covers the Smithery platform and the smithery.ai website. It predates the acquisition and does not name Arcade.",
        "No terms of service were found. The home page, the pricing page, the about page and the docs link only the privacy notice, so `terms` is left out.",
        "The privacy notice links a Data Policy at https://smithery.ai/docs/use/data-policy, which answered 404 on 9 October 2026.",
        "Arcade.dev announced the acquisition of Smithery on 5 August 2026. The acquiring company's legal name was not read.",
        "The management API answers at api.smithery.ai. Connection calls, the namespace MCP endpoint and Uplink use a second domain, smithery.run.",
        "smithery.ai/.well-known/security.txt answered 404. The client repository's SECURITY.md sends reports about the service to contact@smithery.ai.",
        "RDAP gives a registration date of 2024-12-10 for smithery.ai, a transfer on 10 September 2026 and Cloudflare as registrar.",
        "The changelog link is the TypeScript client's. No dated changelog for the hosted service was found."
      ],
      "score": 65,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Clavia, Inc. (doing business as Smithery)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "smithery.ai, registered 2024-12-10 (1 year)",
          "points": 3,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.smithery.ai",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 4 of the 8 things a reader expects",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.smithery.ai",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "",
          "state": "none-found",
          "points": 0,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://smithery.ai/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2025-06-20",
          "words": 4556,
          "points": 7,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: June 20, 2025",
              "says": "Last updated 2025-06-20"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The categories of personal data we collect depend on how you interact with us and our services."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Under certain data protection laws, the term “service provider” is used instead of “processor.”"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "This information is used to provide and inform targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may share a common account identifier (such as a hashed email address or user ID) with our third-party advertising partners to help link the personal data we and our third-party partners collect to the same person, or otherwise target advertising to an individual on a third-party website or platform."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Smithery's business partners may use personal data for their own business and commercial purposes, including marketing their own products.",
              "quote": "Our business partners may use your personal data for their own business and commercial purposes, including to improve their products and services and to send you information about their products and services."
            },
            {
              "date": "2026-10-08",
              "text": "Third-party technologies on the service may record mouse movements, clicks and keystrokes, and what a user enters into the products or chat.",
              "quote": "These third-party technologies may also record information you enter when you interact with our products or services, or engage in chat features or other communication platforms we provide."
            },
            {
              "date": "2026-10-08",
              "text": "Customer content sent to the products, including content about a customer's servers, is used to improve the products as well as to run them.",
              "quote": "We use this content primarily to provide you with our products and services, to facilitate your requests, and to improve our products and services."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/smithery.json",
    "live": {
      "slug": "smithery",
      "probe": {
        "target": "https://api.smithery.ai",
        "method": "get",
        "lastAt": "2026-10-10T01:38:07.956543153Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 206,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 200,
        "p95ms24h": 322,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.smithery.ai",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:51:16.433925119Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "smithery-ai/cli",
          "version": "v1.2.0",
          "released": "2026-05-31",
          "seenAt": "2026-10-09T17:20:48.992258676Z"
        },
        {
          "registry": "npm",
          "name": "@smithery/api",
          "version": "0.68.0",
          "seenAt": "2026-10-09T17:20:46.778269251Z"
        },
        {
          "registry": "npm",
          "name": "smithery",
          "version": "1.2.0",
          "seenAt": "2026-10-09T17:20:47.691292694Z"
        }
      ],
      "githubStars": 840,
      "npmWeekly": 2729,
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/smithery-ai/typescript-api/main/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:46:07.185814834Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8bd4ab2d180a"
        },
        {
          "url": "https://smithery.ai/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:45:32.741358495Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4143bed484bd"
        }
      ],
      "updatedAt": "2026-10-10T01:38:07.956543153Z"
    }
  }
}
