{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "tinyfish",
    "name": "TinyFish",
    "vendor": "Tiny Fish, Inc.",
    "vendorUrl": "https://www.tinyfish.ai",
    "kind": "http-api",
    "category": "browser",
    "summary": "TinyFish is a hosted web agent platform from Tiny Fish, Inc. Agents call it through REST APIs for goal-driven automation, remote browser sessions over CDP, search, fetch and research, or through a remote MCP server with OAuth.",
    "url": "https://www.anchorterminal.com/tools/tinyfish",
    "markdownUrl": "https://www.anchorterminal.com/tools/tinyfish.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tinyfish.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tinyfish.json",
    "repo": "https://github.com/tinyfish-io/tinyfish-mcp-server",
    "license": "Proprietary service under Tiny Fish's terms of service. The MCP proxy `@tiny-fish/mcp` and the cookbook are MIT. The SDK packages state no licence in npm or PyPI metadata",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://agent.tinyfish.ai",
    "packages": [
      {
        "registry": "pypi",
        "name": "tinyfish"
      },
      {
        "registry": "npm",
        "name": "@tiny-fish/sdk"
      },
      {
        "registry": "npm",
        "name": "@tiny-fish/cli"
      },
      {
        "registry": "npm",
        "name": "@tiny-fish/mcp"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve API key from agent.tinyfish.ai/api-keys, sent in the `X-API-Key` header on every REST call. Keys are shown once and can be deleted, and no scopes were found. The MCP server at `https://agent.tinyfish.ai/mcp` uses OAuth 2.1 with a browser sign-in, or a key as a Bearer token for clients without OAuth. No sales approval is needed.",
    "pricing": "freemium",
    "pricingNotes": "Search and Fetch are free up to 12,000 requests and 1,000 URLs a day. Agent runs cost $0.016 a step and Browser sessions $0.002 a minute, drawn from a prepaid wallet with a $10 minimum top-up and no subscription. New accounts start with $8 of wallet funds and need no card, so an agent's owner can start without a contract. Enterprise is by contract (https://www.tinyfish.ai/pricing).",
    "priceSummary": "$0.016 / call",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402 or L402 in the docs or the OpenAPI documents. `POST /v1/wallet/top-up` accepts the Machine Payments Protocol with a Stripe Shared Payment Token to refill the prepaid wallet ($10 to $500), for accounts in a gradual rollout and with an API key (https://docs.tinyfish.ai/agent-payments.md, checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 5721,
      "pypiWeekly": 6540,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.tinyfish.ai",
    "llmsTxt": "https://docs.tinyfish.ai/llms.txt",
    "openapi": "https://agent.tinyfish.ai/v1/openapi/main",
    "registryName": "ai.tinyfish.agent/web-agent",
    "capabilities": [
      "browser.control",
      "browser.hosted",
      "web.extract",
      "web.fetch",
      "web.search",
      "search.research",
      "scraping.proxies",
      "scraping.anti-bot"
    ],
    "tags": [
      "official",
      "hosted",
      "freemium",
      "no-card",
      "prepaid",
      "mpp",
      "openapi",
      "llms-txt",
      "mcp",
      "oauth",
      "api-key",
      "python",
      "typescript",
      "cli",
      "webhooks",
      "status-page",
      "pre-1.0"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.7,
      "grade": "B",
      "agentReady": false,
      "rank": 227,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 79,
        "maintenance": 80,
        "payments": 55,
        "reliability": 60,
        "schema": 85,
        "security": 57,
        "transparency": 59
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Graded as a hosted API. agent.tinyfish.ai/status is the vendor's own page with five components and 90 daily bars each, but no incident write-ups (15 of 20). From 11 July to 8 October 2026 the Agent API shows no downtime. The Browser API shows 420 minutes across six days, with 120 on 28 September. The Search API shows 1,500 minutes across seven days, with 420 on 7 August, and the Fetch API 240 on 27 August. Several outages of an hour or more, so 5 of 30, kept above 0 for the clean Agent API record. Limits are published (Search 30 requests a minute, Fetch 150 URLs a minute, 2 concurrent Agent runs, 5 concurrent Browser sessions) (15). Search and Fetch 429s carry `Retry-After` and `X-RateLimit-*` headers, the docs give backoff guidance and the SDKs retry 429 and 5xx. The Agent pending-run 429 has no `Retry-After` and run creation has no idempotency keys (11). The pricing page lists a 99.99 per cent uptime SLA for Enterprise, with no SLA document found (5). Browser, Search and MCP were declared generally available in June 2026 and the API is `/v1`. The SDKs are 0.x and some Agent settings are beta-gated (9)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "Graded on the REST API. OpenAPI 3.0.0 documents are linked from `llms.txt` for five APIs. We read two, the main document with 28 operations and the Browser document with 3 (25). `llms.txt`, a 460 KB `llms-full.txt`, a Markdown twin of every page and a single page for coding agents (10). All 31 operations we read carry a description, several say which endpoint to pick instead, and the MCP tool definitions state when to use and when not to use each tool (17). 189 enums in the main document, ranges such as `max_steps` 1 to 500, and unknown fields rejected. 730 of 1,068 properties carry a description, `goal` is free text by design and the MCP `search` tool takes a JSON-encoded `fetch` string (12). 698 examples in the main document, every operation documents an error response, and an error-code page gives a fix for each code (14). The path is versioned `/v1` and the document is 1.0.0. The Pulse changelog stops at 22 June 2026 and the docs have no API changelog (7)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 79,
          "points": 12.84,
          "reason": "Fetch takes an output format, include and exclude selectors, a cache age and a per-URL timeout, and run reads choose whether screenshots come back as URLs or inline. The MCP server has 28 tools per its repository, with a `guide_next_step` tool (18). Run lists take a cursor, a limit of 1 to 100 and filters for status, goal text and dates, and Search pages from 0 to 10 (18). Errors carry a code, a message, optional `details` and a `request_id`, and wallet denials add `non_retryable` and balance fields (19). The docs say run creation doesn't support idempotency keys and a retry may create duplicate runs. Cancels and session deletes are idempotent and a replayed wallet top-up is credited once. We couldn't read MCP annotations without signing in (9). A run needs only `url` and `goal`, a browser session needs nothing, and there are official Python and TypeScript SDKs and a CLI (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 57,
          "points": 9.98,
          "reason": "REST calls take an `X-API-Key` header. Keys are created and deleted in the dashboard and shown once, with no scopes found. MCP uses OAuth 2.1, and run IDs are separated between CLI or REST tokens and MCP tokens (21). Vault credentials are opt-in per run with `use_vault` and can be limited with `credential_item_ids`, and the docs say the agent never sees passwords. No read-only key or approval step for agent actions was found, and `max_steps` is beta-gated (9). Pages are untrusted content. The plugin page mentions safety rules for untrusted content, and the API docs have no prompt-injection guidance (3). Each run keeps per-step screenshots and optional HTML snapshots, usage lists exist for Search, Fetch and Browser sessions, and audit logs are listed under Enterprise (11). security.txt is valid until 1 September 2027, and the disclosure policy v1.1 of 15 September 2026 has safe harbour and discretionary rewards with no formal bounty. The terms cite an ISO 27001 certification, and the trust centre that would show it is drawn by script and was unread (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 55,
          "points": 6.88,
          "reason": "`POST /v1/wallet/top-up` on agent.tinyfish.ai answers 402 with a Machine Payments Protocol challenge and takes a Stripe Shared Payment Token for $10 to $500. It refills a prepaid wallet instead of paying per call, needs an existing API key, and the docs say it is rolling out gradually, so partial credit (15). Per-unit prices are public, $0.016 an Agent step and $0.002 a Browser minute, with Search and Fetch at $0 (20). Search and Fetch are free within daily allowances and new accounts start with $8 of wallet funds, no card required per the pricing page (20). A person has to sign up in a browser to get a key or complete OAuth (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "`@tiny-fish/cli` 0.48.1 was published to npm on 7 October 2026, and `@tiny-fish/sdk` 0.8.0 and `tinyfish` 0.9.0 on PyPI on 29 September (30). The TypeScript SDK had nine releases and the Python SDK seven since 22 July 2026 (20). The Pulse changelog stops at 22 June 2026. Support is by e-mail and Discord, and the public MCP proxy repository has commits to 8 October. We didn't read issue reply times (8 of 15 on the closed-service line). The hosted MCP server is in the official MCP registry as `ai.tinyfish.agent/web-agent`, version 1.0.1, published 17 February 2026, and both SDKs are current (15). The MCP proxy repository runs CI, Renovate, and OSV and secrets scanners, and publishes through npm trusted publishing. The SDK packages name no source repository (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 59,
          "points": 5.16,
          "note": "editorial 32, provenance 85",
          "reason": "The platform is closed with published terms, effective 17 August 2026. The MCP proxy and cookbook are MIT, and the SDK packages state no licence in npm or PyPI metadata (14). The terms allow Tiny Fish to review runs and to train and improve its models on customer data, which is stated plainly. The privacy policy of 14 December 2025 gives no retention periods and names TinyFish Inc. in Cupertino, while the terms name Tiny Fish, Inc. in Los Altos. No public DPA was found (10). No deprecation policy was found. The docs flag two parameters as deprecated without dates, and the terms give 30 days' notice of material changes to the terms (5). No subprocessor list or hosting location was found on readable pages. The enterprise page says data residency is agreed by contract, and the trust centre was unread (3)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Fetch takes an output format, include and exclude selectors, a cache age and a per-URL timeout, and run reads choose whether screenshots come back as URLs or inline. The MCP server has 28 tools per its repository, with a `guide_next_step` tool (18). Run lists take a cursor, a limit of 1 to 100 and filters for status, goal text and dates, and Search pages from 0 to 10 (18). Errors carry a code, a message, optional `details` and a `request_id`, and wallet denials add `non_retryable` and balance fields (19). The docs say run creation doesn't support idempotency keys and a retry may create duplicate runs. Cancels and session deletes are idempotent and a replayed wallet top-up is credited once. We couldn't read MCP annotations without signing in (9). A run needs only `url` and `goal`, a browser session needs nothing, and there are official Python and TypeScript SDKs and a CLI (15).",
          "maintenance": "`@tiny-fish/cli` 0.48.1 was published to npm on 7 October 2026, and `@tiny-fish/sdk` 0.8.0 and `tinyfish` 0.9.0 on PyPI on 29 September (30). The TypeScript SDK had nine releases and the Python SDK seven since 22 July 2026 (20). The Pulse changelog stops at 22 June 2026. Support is by e-mail and Discord, and the public MCP proxy repository has commits to 8 October. We didn't read issue reply times (8 of 15 on the closed-service line). The hosted MCP server is in the official MCP registry as `ai.tinyfish.agent/web-agent`, version 1.0.1, published 17 February 2026, and both SDKs are current (15). The MCP proxy repository runs CI, Renovate, and OSV and secrets scanners, and publishes through npm trusted publishing. The SDK packages name no source repository (7).",
          "payments": "`POST /v1/wallet/top-up` on agent.tinyfish.ai answers 402 with a Machine Payments Protocol challenge and takes a Stripe Shared Payment Token for $10 to $500. It refills a prepaid wallet instead of paying per call, needs an existing API key, and the docs say it is rolling out gradually, so partial credit (15). Per-unit prices are public, $0.016 an Agent step and $0.002 a Browser minute, with Search and Fetch at $0 (20). Search and Fetch are free within daily allowances and new accounts start with $8 of wallet funds, no card required per the pricing page (20). A person has to sign up in a browser to get a key or complete OAuth (0).",
          "reliability": "Graded as a hosted API. agent.tinyfish.ai/status is the vendor's own page with five components and 90 daily bars each, but no incident write-ups (15 of 20). From 11 July to 8 October 2026 the Agent API shows no downtime. The Browser API shows 420 minutes across six days, with 120 on 28 September. The Search API shows 1,500 minutes across seven days, with 420 on 7 August, and the Fetch API 240 on 27 August. Several outages of an hour or more, so 5 of 30, kept above 0 for the clean Agent API record. Limits are published (Search 30 requests a minute, Fetch 150 URLs a minute, 2 concurrent Agent runs, 5 concurrent Browser sessions) (15). Search and Fetch 429s carry `Retry-After` and `X-RateLimit-*` headers, the docs give backoff guidance and the SDKs retry 429 and 5xx. The Agent pending-run 429 has no `Retry-After` and run creation has no idempotency keys (11). The pricing page lists a 99.99 per cent uptime SLA for Enterprise, with no SLA document found (5). Browser, Search and MCP were declared generally available in June 2026 and the API is `/v1`. The SDKs are 0.x and some Agent settings are beta-gated (9).",
          "schema": "Graded on the REST API. OpenAPI 3.0.0 documents are linked from `llms.txt` for five APIs. We read two, the main document with 28 operations and the Browser document with 3 (25). `llms.txt`, a 460 KB `llms-full.txt`, a Markdown twin of every page and a single page for coding agents (10). All 31 operations we read carry a description, several say which endpoint to pick instead, and the MCP tool definitions state when to use and when not to use each tool (17). 189 enums in the main document, ranges such as `max_steps` 1 to 500, and unknown fields rejected. 730 of 1,068 properties carry a description, `goal` is free text by design and the MCP `search` tool takes a JSON-encoded `fetch` string (12). 698 examples in the main document, every operation documents an error response, and an error-code page gives a fix for each code (14). The path is versioned `/v1` and the document is 1.0.0. The Pulse changelog stops at 22 June 2026 and the docs have no API changelog (7).",
          "security": "REST calls take an `X-API-Key` header. Keys are created and deleted in the dashboard and shown once, with no scopes found. MCP uses OAuth 2.1, and run IDs are separated between CLI or REST tokens and MCP tokens (21). Vault credentials are opt-in per run with `use_vault` and can be limited with `credential_item_ids`, and the docs say the agent never sees passwords. No read-only key or approval step for agent actions was found, and `max_steps` is beta-gated (9). Pages are untrusted content. The plugin page mentions safety rules for untrusted content, and the API docs have no prompt-injection guidance (3). Each run keeps per-step screenshots and optional HTML snapshots, usage lists exist for Search, Fetch and Browser sessions, and audit logs are listed under Enterprise (11). security.txt is valid until 1 September 2027, and the disclosure policy v1.1 of 15 September 2026 has safe harbour and discretionary rewards with no formal bounty. The terms cite an ISO 27001 certification, and the trust centre that would show it is drawn by script and was unread (13).",
          "transparency": "The platform is closed with published terms, effective 17 August 2026. The MCP proxy and cookbook are MIT, and the SDK packages state no licence in npm or PyPI metadata (14). The terms allow Tiny Fish to review runs and to train and improve its models on customer data, which is stated plainly. The privacy policy of 14 December 2025 gives no retention periods and names TinyFish Inc. in Cupertino, while the terms name Tiny Fish, Inc. in Los Altos. No public DPA was found (10). No deprecation policy was found. The docs flag two parameters as deprecated without dates, and the terms give 30 days' notice of material changes to the terms (5). No subprocessor list or hosting location was found on readable pages. The enterprise page says data residency is agreed by contract, and the trust centre was unread (3)."
        },
        "sources": [
          {
            "what": "docs index",
            "url": "https://docs.tinyfish.ai/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "full docs text",
            "url": "https://docs.tinyfish.ai/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "coding-agent page",
            "url": "https://docs.tinyfish.ai/for-coding-agents.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://docs.tinyfish.ai/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes and rate-limit headers",
            "url": "https://docs.tinyfish.ai/error-codes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Browser API reference",
            "url": "https://docs.tinyfish.ai/browser-api/reference.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Browser API overview",
            "url": "https://docs.tinyfish.ai/browser-api/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP integration",
            "url": "https://docs.tinyfish.ai/mcp-integration/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "agent payments (MPP)",
            "url": "https://docs.tinyfish.ai/agent-payments.md",
            "seen": "2026-10-08"
          },
          {
            "what": "vault credentials",
            "url": "https://docs.tinyfish.ai/key-concepts/credentials.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://docs.tinyfish.ai/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ",
            "url": "https://docs.tinyfish.ai/faq.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI, main",
            "url": "https://agent.tinyfish.ai/v1/openapi/main",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI, Browser",
            "url": "https://agent.tinyfish.ai/v1/openapi/browser",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://agent.tinyfish.ai/status",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.tinyfish.ai/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.tinyfish.ai/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.tinyfish.ai/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.tinyfish.ai/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability disclosure policy",
            "url": "https://www.tinyfish.ai/security/vulnerability-disclosure-policy.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Pulse changelog",
            "url": "https://www.tinyfish.ai/pulse",
            "seen": "2026-10-08"
          },
          {
            "what": "enterprise page",
            "url": "https://www.tinyfish.ai/enterprise",
            "seen": "2026-10-08"
          },
          {
            "what": "site llms.txt",
            "url": "https://www.tinyfish.ai/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre (script-drawn, unread)",
            "url": "https://trust.tinyfish.ai/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP proxy repository and tool reference",
            "url": "https://github.com/tinyfish-io/tinyfish-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub organisation",
            "url": "https://api.github.com/orgs/tinyfish-io/repos",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK on npm",
            "url": "https://registry.npmjs.org/@tiny-fish/sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI on npm",
            "url": "https://registry.npmjs.org/@tiny-fish/cli",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/tinyfish/json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=tinyfish",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/tinyfish.ai",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.tinyfish.ai is drawn by script (Vanta), so the ISO 27001 certificate, any SOC 2 report, DPA and subprocessor list were unread",
          "unchecked: the OpenAPI documents for Fetch, Search and Research. We read the main and Browser documents only, to keep requests to the API host few",
          "unchecked: whether the hosted MCP server's `tools/list` carries `readOnlyHint` or `destructiveHint`. Reading it needs a signed-in account",
          "unchecked: GitHub issue reply times, and whether the dashboard supports key expiry or per-key limits",
          "The Enterprise SLA of 99.99 per cent is a line on the pricing page. No SLA document was found",
          "The MCP docs page lists 17 tools while the MCP proxy repository's reference lists 28, with profile and monitor tools added",
          "The MCP `search` tool definition tells the model to prefer it over native web search tools and to use it when the user hasn't asked for a search. Recorded as a fact, with no deduction",
          "The privacy policy names TinyFish Inc. in Cupertino and the terms name Tiny Fish, Inc. in Los Altos. We used the name in the terms as the legal entity",
          "The status page reports downtime in whole hours per day, so short incidents may be rounded up",
          "The lead was right about the interfaces. It didn't mention the Monitor API, the CLI or MPP wallet top-ups, which the docs also describe"
        ]
      },
      "negative": 0,
      "verdict": "OpenAPI documents are published for five APIs, errors carry typed codes and request IDs, and Search and Fetch are free within daily allowances. The terms let Tiny Fish train its models on customer data, run creation takes no idempotency keys, and the status page shows an hour or more of downtime on several days for the Browser and Search APIs.",
      "bestFor": "Agents that want one account for a goal-driven web agent, a raw CDP browser, and free search and fetch.",
      "strengths": [
        "OpenAPI 3.0 documents for the Agent, Browser, Fetch, Search and Research APIs, plus `llms.txt`, `llms-full.txt` and a Markdown twin of every docs page",
        "Search and Fetch are free up to 12,000 requests and 1,000 URLs a day, and new accounts start with $8 of wallet funds with no card",
        "Errors carry a code, a message, optional `details` and a `request_id`. Search and Fetch 429s carry `Retry-After` and `X-RateLimit-*` headers",
        "Remote MCP server at `https://agent.tinyfish.ai/mcp` with OAuth 2.1, listed in the official MCP registry as `ai.tinyfish.agent/web-agent`",
        "Vault credentials from 1Password or Bitwarden are opt-in per run and can be limited with `credential_item_ids`. The docs say the agent never sees the passwords",
        "A valid security.txt and a disclosure policy (v1.1, 15 September 2026) with safe harbour and response times"
      ],
      "weaknesses": [
        "The terms of 17 August 2026 allow Tiny Fish to train and improve its models on customer data. No opt-out was found in the reviewed pages",
        "The status page shows downtime of an hour or more on six days for the Browser API and five for the Search API between 11 July and 8 October 2026, with no incident write-ups",
        "No idempotency keys on run or session creation. The docs say retrying a failed request may create duplicate runs",
        "API keys have no scopes and no read-only mode was found. No prompt-injection guidance was found in the API docs",
        "No retention periods, public DPA or subprocessor list on the pages we could read. The trust centre is drawn by script and was unread",
        "The Pulse changelog's newest entry is 22 June 2026, and the Python and TypeScript SDKs are 0.x with no public source repository found"
      ],
      "agentNotes": [
        "Check `result` as well as `status`. A run can be `COMPLETED` while the goal failed, with `result.status` set to `failure`",
        "Don't retry `POST /v1/automation/run` blindly after a timeout. There are no idempotency keys, so list runs first to avoid duplicates",
        "Use `/v1/automation/run-async` or `/run-sse` when a run may need cancelling. Runs started with the synchronous endpoint can't be cancelled",
        "Allow 60 seconds for Browser session creation, connect Playwright to `cdp_url` (not `base_url`), and `DELETE` the session when done because billing is per minute",
        "Never put passwords in `goal`, which is logged. Pass `use_vault: true` with `credential_item_ids`, or `use_profile: true` for saved login state"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.7
        }
      ],
      "editorialScores": {
        "ergonomics": 79,
        "maintenance": 80,
        "payments": 55,
        "reliability": 60,
        "schema": 85,
        "security": 57,
        "transparency": 32
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "pip install -U tinyfish",
      "http": "curl -X POST https://agent.tinyfish.ai/v1/automation/run -H \"X-API-Key: $TINYFISH_API_KEY\" -H \"Content-Type: application/json\" -d '{\"url\": \"https://example.com\", \"goal\": \"Extract the page title\"}'",
      "claudeCode": "claude mcp add --transport http tinyfish https://agent.tinyfish.ai/mcp",
      "config": {
        "mcpServers": {
          "tinyfish": {
            "url": "https://agent.tinyfish.ai/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/browser.control",
      "tool": "https://letme.dev/tinyfish"
    },
    "sameCompany": [
      "tinyfish-search"
    ],
    "notable": [
      "The Browser API returns a `cdp_url` for Playwright, Puppeteer or any CDP client. Sessions use a residential proxy in the United States by default, with a sticky exit IP, another country or a custom proxy on request (https://docs.tinyfish.ai/browser-api/reference.md)",
      "The Agent API takes a `url` and a natural-language `goal` and runs synchronously, asynchronously, in batches or over SSE. A run that ends `COMPLETED` may still have failed its goal, so the docs tell callers to check `result` (https://docs.tinyfish.ai/faq.md)",
      "`POST /v1/wallet/top-up` answers 402 with a Machine Payments Protocol challenge and accepts a Stripe Shared Payment Token for $10 to $500. The docs say it is rolling out gradually (https://docs.tinyfish.ai/agent-payments.md)",
      "The terms effective 17 August 2026 allow Tiny Fish to train, fine-tune and improve its models on customer data, and bar using the services or outputs to build a competing product (https://www.tinyfish.ai/terms)",
      "The status page's 90 daily bars to 8 October 2026 show no downtime for the Agent API, 420 minutes across six days for the Browser API and 1,500 minutes across seven days for the Search API (https://agent.tinyfish.ai/status)",
      "The hosted MCP server is in the official MCP registry as `ai.tinyfish.agent/web-agent`, and its repository reference lists 28 tools for search, fetch, automation, browser sessions, profiles, monitors and the wallet (https://github.com/tinyfish-io/tinyfish-mcp-server)",
      "The MCP `search` tool definition tells the model to prefer it over native web search tools when TinyFish is connected (https://github.com/tinyfish-io/tinyfish-mcp-server/blob/main/docs/tools.md)",
      "security.txt is valid until 1 September 2027 and points to a disclosure policy, v1.1 of 15 September 2026, with safe harbour and discretionary rewards (https://www.tinyfish.ai/.well-known/security.txt)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST APIs with their Python and TypeScript SDKs. The Agent, profile, vault and wallet routes are at https://agent.tinyfish.ai/v1 (28 operations) and the Browser API at https://api.browser.tinyfish.ai (3). The remote MCP server is noted alongside"
      },
      {
        "label": "Browser control",
        "value": "`POST https://api.browser.tinyfish.ai` returns `session_id`, `cdp_url` and `base_url`. Connect Playwright, Puppeteer or a CDP client to `cdp_url`. `DELETE /{session_id}` ends the session and is idempotent. Creation takes 10 to 30 seconds per the docs"
      },
      {
        "label": "Agent runs",
        "value": "`/v1/automation/run` (synchronous, can't be cancelled), `/run-async`, `/run-batch` and `/run-sse`. Lite or stealth browser, proxy country from US, GB, CA, DE, FR, JP and AU, optional `output_schema`, webhooks, and up to 150 steps by default"
      },
      {
        "label": "Free allowance",
        "value": "Search 12,000 requests a day and Fetch 1,000 URLs a day, reset at 00:00 UTC, working at a $0 balance. New accounts start with $8 of promotional wallet funds, no card required per the pricing page"
      },
      {
        "label": "Rate limits",
        "value": "Search 30 requests a minute and 500 an hour. Fetch 150 URLs a minute. Agent 2 concurrent runs. Browser 5 concurrent sessions. Higher limits by contract. Search and Fetch 429s carry `Retry-After` and `X-RateLimit-*` headers"
      },
      {
        "label": "Session limits",
        "value": "Browser sessions end after an inactivity timeout, `timeout_seconds` from 5 to 86,400, capped at 15 minutes on free accounts and 60 on paid. Sessions are isolated, and saved login state comes from Browser Context Profiles"
      },
      {
        "label": "Machine payment",
        "value": "Machine Payments Protocol on `POST /v1/wallet/top-up`, Stripe Shared Payment Token, $10 to $500 in whole cents, USD. Refills the prepaid wallet. Gradual rollout, API key needed. No x402"
      },
      {
        "label": "MCP server",
        "value": "Remote, Streamable HTTP at `https://agent.tinyfish.ai/mcp`, OAuth 2.1, 28 tools per the repository reference. `@tiny-fish/mcp` 0.1.0 is a local proxy to it for API-key use (Node 22 or later, MIT). Registry name `ai.tinyfish.agent/web-agent`"
      },
      {
        "label": "SDKs",
        "value": "`tinyfish` 0.9.0 on PyPI (Python 3.11 or later) and `@tiny-fish/sdk` 0.8.0 on npm (Node 18 or later), both of 29 September 2026. `@tiny-fish/cli` 0.48.1 of 7 October 2026 (Node 24 or later)"
      },
      {
        "label": "Credentials for sites",
        "value": "1Password and Bitwarden vault connections, opt-in per run with `use_vault` and limited with `credential_item_ids`. Browser Context Profiles save cookies and storage for reuse with `use_profile`"
      },
      {
        "label": "Data use",
        "value": "The terms allow Tiny Fish to review runs and to train and improve its models on customer data. The privacy policy states no retention periods. Enterprise data residency is agreed by contract per the enterprise page"
      },
      {
        "label": "Certifications",
        "value": "The terms and the pricing page cite ISO 27001. The trust centre at trust.tinyfish.ai is drawn by script and was unread"
      }
    ],
    "unitPrices": [
      {
        "item": "Agent step",
        "unit": "call",
        "usd": 0.016,
        "note": "Model inference, residential proxy and anti-bot handling included per the pricing page"
      },
      {
        "item": "Browser session",
        "unit": "browser-hour",
        "usd": 0.12,
        "note": "Billed at $0.002 a minute"
      },
      {
        "item": "Search",
        "unit": "1k-requests",
        "usd": 0,
        "note": "Free up to 12,000 requests a day, 30 a minute"
      },
      {
        "item": "Fetch",
        "unit": "1k-pages",
        "usd": 0,
        "note": "Free up to 1,000 URLs a day, 150 a minute"
      },
      {
        "item": "Monitor run",
        "unit": "call",
        "usd": 0.005,
        "note": "Per completed run, failed runs free, per the MCP docs"
      }
    ],
    "provenance": {
      "legalEntity": "Tiny Fish, Inc.",
      "domain": "tinyfish.ai",
      "domainRegistered": "2023-02-06",
      "endpointOnVendorDomain": true,
      "terms": "https://www.tinyfish.ai/terms",
      "privacy": "https://www.tinyfish.ai/privacy-policy",
      "statusPage": "https://agent.tinyfish.ai/status",
      "changelog": "https://www.tinyfish.ai/pulse",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service, effective 17 August 2026, name Tiny Fish, Inc., a Delaware corporation at 4410 El Camino Real, Los Altos, CA 94022, cover the APIs and the wallet, and choose California law.",
        "The privacy policy, effective 14 December 2025, names TinyFish Inc. in Cupertino, California, and covers the website, products and services.",
        "The APIs answer at agent.tinyfish.ai, api.browser.tinyfish.ai, api.search.tinyfish.ai and api.fetch.tinyfish.ai. The docs' example `cdp_url` is on a tinyfish.io subdomain, the vendor's second domain.",
        "www.tinyfish.ai/.well-known/security.txt gives a contact, a policy link and an expiry of 1 September 2027.",
        "RDAP for tinyfish.ai gives a registration date of 2023-02-06.",
        "Pulse, the product changelog, has its newest entry dated 22 June 2026. Current release dates come from npm and PyPI.",
        "The same GitHub organisation, tinyfish-io, publishes AgentQL, which is a separate product and isn't graded here."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Tiny Fish, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "tinyfish.ai, registered 2023-02-06 (3 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "agent.tinyfish.ai",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "agent.tinyfish.ai/status",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.tinyfish.ai/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-17",
          "words": 6271,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective August 17, 2026",
              "says": "Last updated 2026-08-17"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and all related matters arising out of or relating to these Terms are governed by, and construed in accordance with, the laws of the State of California, without giving effect to conflict of law principles.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "The parties understand and agree that, to the fullest extent provided by law, in no event will either party be liable to the other for any loss of profits, revenue, or data, indirect, incidental, special, consequential, exemplary, or punitive damages, or damages or costs due to loss of use, business interruption, or p…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Tiny Fish may recover any negative balance by deducting it from your next top-up or, if you have a saved payment method, by charging that payment method, and may suspend the Services until a negative balance is settled."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may reduce Published Rates at any time and may increase Published Rates on at least 14 days' advance notice by posting updated rates or notifying you in-product or by email;",
              "says": "Gives 14 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Except as may be expressly permitted by applicable law or expressly permitted by us in writing, you will not, and will not permit anyone else to: (a) store, copy, modify, distribute, or resell any information or material available on the Services (\"Site Content\") or compile or collect any Site Content as part of a dat…"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "(d) train, fine-tune, evaluate, and improve Tiny Fish's artificial intelligence and machine learning models, subject to commercially reasonable safeguards designed to prevent the disclosure of your confidential information to other customers",
              "costsPoints": true
            },
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(b) scrape, index, or compile Site Content, or use any automated means to access the Services other than through the programmatic interfaces Tiny Fish provides",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(h) access or use the Services or any Outputs to develop, train, or improve a product or service that competes with the Services, including by training or fine-tuning any machine-learning model for such a purpose.",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "…the right to go to court individually or as part of a class action, subject to your right to opt out of arbitration as described in the Dispute Resolution section."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Tiny Fish may use the customer's company name and logo on its websites and in marketing, unless the customer opts out in writing.",
              "quote": "You grant Tiny Fish the right to use your Company name and logo on our websites and in marketing materials to identify you as a customer."
            },
            {
              "date": "2026-10-08",
              "text": "Fees for a renewal term may be changed by posting updated pricing, or with at least 60 days' written notice for Order Form customers.",
              "quote": "Tiny Fish may adjust fees for any renewal term by posting updated pricing or, for Order Form customers, by giving at least 60 days' written notice before the end of the then-current term."
            },
            {
              "date": "2026-10-08",
              "text": "The licence over customer data covers aggregated or de-identified data, which Tiny Fish may use for any lawful purpose, including external publication.",
              "quote": "(e) generate aggregated or de-identified data, which Tiny Fish may use for any lawful purpose, including benchmarking, analytics, and external publication"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.tinyfish.ai/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-12-14",
          "words": 937,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective December 14, 2025",
              "says": "Last updated 2025-12-14"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, products, and services (collectively, the \"Services\")."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share your information with third parties in the following circumstances:"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell your personal information to third parties.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "–EU and UK Users: Under GDPR, you have the right to access, correct, delete, or restrict processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Your information may be transferred to and processed in countries other than your country of residence."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/tinyfish.json",
    "live": {
      "slug": "tinyfish",
      "probe": {
        "target": "https://agent.tinyfish.ai",
        "method": "get",
        "lastAt": "2026-10-09T09:27:07.559977621Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 608,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 645,
        "p95ms24h": 705,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 20
          }
        ]
      },
      "vendorStatus": {
        "page": "https://agent.tinyfish.ai/status",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:36.020771067Z"
      },
      "updatedAt": "2026-10-09T09:27:07.559977621Z"
    }
  }
}
