{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "tomorrow-io",
    "name": "Tomorrow.io Weather API",
    "vendor": "The Tomorrow Companies Inc.",
    "vendorUrl": "https://www.tomorrow.io",
    "kind": "http-api",
    "category": "weather",
    "summary": "Tomorrow.io's Weather API returns current conditions, forecasts, recent and archived history, map tiles, route weather and alert webhooks for a coordinate, place name or GeoJSON shape. It is a REST API with a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/tomorrow-io",
    "markdownUrl": "https://www.anchorterminal.com/tools/tomorrow-io.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tomorrow-io.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tomorrow-io.json",
    "license": "Proprietary service under Tomorrow.io's subscription terms",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.tomorrow.io/v4",
    "packages": [],
    "auth": "mixed",
    "authNotes": "A person signs up in a browser and copies the key from the dashboard. The key goes in an `apikey` header or query parameter on REST calls and in `X-Api-Key` for the MCP server. The docs say keys carry full privileges, and more keys are created by an account manager. The MCP endpoint also advertises OAuth with dynamic client registration, PKCE and one scope, `mcp:read`.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with no published price for anything above it. Free covers core data layers, a 5-day forecast, 24 hours of history, one monitored location and one alert, and the terms bar commercial use on self-generated accounts. Enterprise is by quote and adds the 14-day forecast, premium layers, routes, maps and the historical archive, which is metered in tokens with no public token price (https://www.tomorrow.io/weather-api/, checked 2026-10-08).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the plan table (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 11,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.tomorrow.io/reference/welcome",
    "llmsTxt": "https://docs.tomorrow.io/llms.txt",
    "openapi": "https://docs.tomorrow.io/openapi/tomorrowio-api.json",
    "capabilities": [
      "weather.current",
      "weather.forecast",
      "weather.historical",
      "weather.alerts",
      "weather.marine",
      "data.weather"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "closed-source",
      "openapi",
      "llms-txt",
      "mcp",
      "webhooks",
      "status-page",
      "sales-led",
      "us"
    ],
    "lastRelease": "2026-07-14",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 51.4,
      "grade": "D",
      "agentReady": false,
      "rank": 504,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 73,
        "maintenance": 27,
        "payments": 20,
        "reliability": 55,
        "schema": 75,
        "security": 34,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 55,
          "points": 11,
          "reason": "Graded as a hosted service. Status page at status.tomorrow.io on Atlassian Statuspage with 22 components, among them Timeline API, Historical API, Alerts API and Gale AI (20). It lists 50 incidents between 15 July and 2 October 2026, 25 naming the Timeline or Historical API. Most are stale or degraded data for a region or product. Three are marked major, namely regional FOCUS forecast data missing for about 10 hours on 14 August, alerts and monitors stale for 3 hours 44 minutes on 12 August and feed monitors delayed for 104 minutes on 29 July. A high error rate on the Timeline API from 11:52 to 12:09 UTC was posted for 3 August (15 of 30). The rate-limit page says limits are per second, hour and day by plan and gives no numbers. The help centre answered 403 to our reader (0 of 15). 429 is documented for a passed limit and `Retry-After` for 503, with no backoff guidance for 429 and no idempotency keys on the location, insight and alert writes (7 of 15). The pricing page lists Custom SLAs on Enterprise and its title claims 99.9% uptime, but no SLA document was found (3 of 10). Version 4 of the REST API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "OpenAPI 3.1.0 file at docs.tomorrow.io/openapi/tomorrowio-api.json, version 4.0.1, 31 paths and 39 operations (25). llms.txt at docs.tomorrow.io/llms.txt, and every reference page is served as Markdown at the same address with .md added (10). The specification has 40 empty descriptions, while the reference pages and the MCP page state purpose and use cases, and the MCP page says when to prefer the structured tools over the Gale AI question tool (12 of 20). One enum in the whole specification. `location` is a free string that takes coordinates, a city, a US zip or UK postcode, a location ID or GeoJSON, and `fields` is an untyped array (7 of 15). Example responses on each page and an error table with 15 numbered codes, though most operations declare only a 200 response (11 of 15). A written versioning policy that names which changes raise the version, and release notes dated by month with four entries from October 2025 to July 2026, listed out of order (10 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 73,
          "points": 11.86,
          "reason": "`fields`, `timesteps`, `startTime` and `endTime` size a Timelines response, and the MCP server has 11 tools (22 of 25). Offset and limit pagination with `next` and `prev` links on locations, insights and alerts, `pageSize` and `nextPageToken` on the MCP feed query, and a 31-day cap per historical call (16 of 20). Six-digit error codes with a type and message, which the docs say stay fixed, and soft warnings with field-level `meta` beside partial data (17 of 20). Weather reads repeat safely, including the POST reads. No idempotency keys on writes, and we couldn't list the MCP tools without a key to read their annotations (10 of 20). Forecast and realtime need only `location`, which accepts a place name. No official SDK was found. The vendor's GitHub organisation holds a Postman collection and samples, last pushed in January 2024 (8 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 34,
          "points": 5.95,
          "reason": "The docs state that API keys carry full privileges, with one default key on the dashboard and more keys created by an account manager. The key may travel as an `apikey` query parameter, which the OpenAPI file declares as the scheme, or as a header. The MCP endpoint also advertises OAuth with dynamic client registration, PKCE (S256) and one scope, `mcp:read`, in its live metadata, which the MCP docs page doesn't mention (12 of 30, after the 10-point deduction for a secret in the URL). Weather calls only read, the OAuth scope is read-only, and the key can also create, change and delete locations, insights and alerts with no confirmation step (10 of 20). Responses are mostly numeric fields. Gale AI returns generated text and the feeds carry third-party event text, with no guidance on treating it as untrusted (8 of 15). An `X-Correlation-ID` on every response and an Activity section in the dashboard for webhooks. No per-call log was found in the docs (4 of 15). No security.txt (404 on www, the apex and api hosts), and no disclosure policy, bounty or certification found on the pages read. The terms forbid probing the service for vulnerabilities (0 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 in the docs or the OpenAPI file. A 402 response exists for spent tokens, with no payment protocol behind it (0). The plan table is public and lists what Free includes, but Enterprise is by quote and token prices for the Historical API aren't published (5 of 20). A free plan with a 5-day forecast, 24 hours of history, one monitored location and one alert. The pages read name no card or payment step, but the signup form is a script-rendered app we couldn't read (15 of 20). A person signs up in a browser. The MCP OAuth flow registers clients by API but still needs a human login (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 27,
          "points": 2.36,
          "reason": "The newest release-note entry is July 2026 (the Gale AI question and summary endpoints), on a page last updated 14 July 2026, 86 days before this check (20 of 30). That is one dated entry in the last 90 days, not three (0). Release notes with four entries in twelve months, a status page updated several times a week, and a help centre that answered 403 to our reader. The community repository on GitHub was last pushed in April 2021 (7 of 15). No official SDK, and the MCP registry has only a third-party entry, io.github.pipeworx-io/tomorrow-io (0). No packages to assess (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 42, provenance 84",
          "reason": "Closed service under subscription terms last updated 19 October 2023, with Massachusetts law and a named Delaware corporation (15 of 30). The product privacy policy, last updated 17 December 2024, lists what is collected and how to ask for deletion, keeps data for a period it calls appropriate with no figure, and names Tomorrow.io Inc. as operator where the terms name The Tomorrow Companies Inc. No DPA was found (12 of 30). The versioning policy promises notice far in advance of a breaking change with no period, and the docs mark the `best` timestep as deprecated without a date (6 of 20). The privacy policy names Twilio, MailGun, Salesforce, Salesloft, Intercom, Drift, Google Cloud and AWS as examples, with no locations, and a data sources page updated 14 April 2026 lists upstream providers (9 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`fields`, `timesteps`, `startTime` and `endTime` size a Timelines response, and the MCP server has 11 tools (22 of 25). Offset and limit pagination with `next` and `prev` links on locations, insights and alerts, `pageSize` and `nextPageToken` on the MCP feed query, and a 31-day cap per historical call (16 of 20). Six-digit error codes with a type and message, which the docs say stay fixed, and soft warnings with field-level `meta` beside partial data (17 of 20). Weather reads repeat safely, including the POST reads. No idempotency keys on writes, and we couldn't list the MCP tools without a key to read their annotations (10 of 20). Forecast and realtime need only `location`, which accepts a place name. No official SDK was found. The vendor's GitHub organisation holds a Postman collection and samples, last pushed in January 2024 (8 of 15).",
          "maintenance": "The newest release-note entry is July 2026 (the Gale AI question and summary endpoints), on a page last updated 14 July 2026, 86 days before this check (20 of 30). That is one dated entry in the last 90 days, not three (0). Release notes with four entries in twelve months, a status page updated several times a week, and a help centre that answered 403 to our reader. The community repository on GitHub was last pushed in April 2021 (7 of 15). No official SDK, and the MCP registry has only a third-party entry, io.github.pipeworx-io/tomorrow-io (0). No packages to assess (0).",
          "payments": "No x402, MPP or L402 in the docs or the OpenAPI file. A 402 response exists for spent tokens, with no payment protocol behind it (0). The plan table is public and lists what Free includes, but Enterprise is by quote and token prices for the Historical API aren't published (5 of 20). A free plan with a 5-day forecast, 24 hours of history, one monitored location and one alert. The pages read name no card or payment step, but the signup form is a script-rendered app we couldn't read (15 of 20). A person signs up in a browser. The MCP OAuth flow registers clients by API but still needs a human login (0).",
          "reliability": "Graded as a hosted service. Status page at status.tomorrow.io on Atlassian Statuspage with 22 components, among them Timeline API, Historical API, Alerts API and Gale AI (20). It lists 50 incidents between 15 July and 2 October 2026, 25 naming the Timeline or Historical API. Most are stale or degraded data for a region or product. Three are marked major, namely regional FOCUS forecast data missing for about 10 hours on 14 August, alerts and monitors stale for 3 hours 44 minutes on 12 August and feed monitors delayed for 104 minutes on 29 July. A high error rate on the Timeline API from 11:52 to 12:09 UTC was posted for 3 August (15 of 30). The rate-limit page says limits are per second, hour and day by plan and gives no numbers. The help centre answered 403 to our reader (0 of 15). 429 is documented for a passed limit and `Retry-After` for 503, with no backoff guidance for 429 and no idempotency keys on the location, insight and alert writes (7 of 15). The pricing page lists Custom SLAs on Enterprise and its title claims 99.9% uptime, but no SLA document was found (3 of 10). Version 4 of the REST API is generally available (10).",
          "schema": "OpenAPI 3.1.0 file at docs.tomorrow.io/openapi/tomorrowio-api.json, version 4.0.1, 31 paths and 39 operations (25). llms.txt at docs.tomorrow.io/llms.txt, and every reference page is served as Markdown at the same address with .md added (10). The specification has 40 empty descriptions, while the reference pages and the MCP page state purpose and use cases, and the MCP page says when to prefer the structured tools over the Gale AI question tool (12 of 20). One enum in the whole specification. `location` is a free string that takes coordinates, a city, a US zip or UK postcode, a location ID or GeoJSON, and `fields` is an untyped array (7 of 15). Example responses on each page and an error table with 15 numbered codes, though most operations declare only a 200 response (11 of 15). A written versioning policy that names which changes raise the version, and release notes dated by month with four entries from October 2025 to July 2026, listed out of order (10 of 15).",
          "security": "The docs state that API keys carry full privileges, with one default key on the dashboard and more keys created by an account manager. The key may travel as an `apikey` query parameter, which the OpenAPI file declares as the scheme, or as a header. The MCP endpoint also advertises OAuth with dynamic client registration, PKCE (S256) and one scope, `mcp:read`, in its live metadata, which the MCP docs page doesn't mention (12 of 30, after the 10-point deduction for a secret in the URL). Weather calls only read, the OAuth scope is read-only, and the key can also create, change and delete locations, insights and alerts with no confirmation step (10 of 20). Responses are mostly numeric fields. Gale AI returns generated text and the feeds carry third-party event text, with no guidance on treating it as untrusted (8 of 15). An `X-Correlation-ID` on every response and an Activity section in the dashboard for webhooks. No per-call log was found in the docs (4 of 15). No security.txt (404 on www, the apex and api hosts), and no disclosure policy, bounty or certification found on the pages read. The terms forbid probing the service for vulnerabilities (0 of 20).",
          "transparency": "Closed service under subscription terms last updated 19 October 2023, with Massachusetts law and a named Delaware corporation (15 of 30). The product privacy policy, last updated 17 December 2024, lists what is collected and how to ask for deletion, keeps data for a period it calls appropriate with no figure, and names Tomorrow.io Inc. as operator where the terms name The Tomorrow Companies Inc. No DPA was found (12 of 30). The versioning policy promises notice far in advance of a breaking change with no period, and the docs mark the `best` timestep as deprecated without a date (6 of 20). The privacy policy names Twilio, MailGun, Salesforce, Salesloft, Intercom, Drift, Google Cloud and AWS as examples, with no locations, and a data sources page updated 14 April 2026 lists upstream providers (9 of 20)."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://docs.tomorrow.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI file",
            "url": "https://docs.tomorrow.io/openapi/tomorrowio-api.json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://docs.tomorrow.io/reference/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth metadata",
            "url": "https://api.tomorrow.io/v4/oauth/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "access keys",
            "url": "https://docs.tomorrow.io/reference/api-authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiting and tokens",
            "url": "https://docs.tomorrow.io/reference/rate-limiting.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error handling",
            "url": "https://docs.tomorrow.io/reference/api-errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning policy",
            "url": "https://docs.tomorrow.io/reference/api-versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://docs.tomorrow.io/reference/release-notes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "timestep availability by plan",
            "url": "https://docs.tomorrow.io/reference/weather-data-layers.md",
            "seen": "2026-10-08"
          },
          {
            "what": "historical API limits and tokens",
            "url": "https://docs.tomorrow.io/reference/historical-overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://docs.tomorrow.io/reference/api-webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "plans",
            "url": "https://www.tomorrow.io/weather-api/",
            "seen": "2026-10-08"
          },
          {
            "what": "subscription terms",
            "url": "https://www.tomorrow.io/legal/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "product privacy policy",
            "url": "https://www.tomorrow.io/legal/product-privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data sources and attribution",
            "url": "https://www.tomorrow.io/legal/data-source-attribution/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.tomorrow.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub organisation",
            "url": "https://github.com/orgs/Tomorrow-io-API/repositories",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=tomorrow",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.identitydigital.services/rdap/domain/tomorrow.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the free plan's numeric rate limits. The docs give none and support.tomorrow.io answered 403 to our reader",
          "unchecked: whether signup asks for a card. app.tomorrow.io/signup is a script-rendered app we couldn't read",
          "unchecked: the MCP tools' input schemas and annotations, which need a key to list",
          "unchecked: whether the July 2026 release note falls inside the last 90 days. Entries are dated by month and the page was last updated 14 July 2026",
          "No SOC 2, ISO 27001 or other certification was found on the legal, API or docs pages read. A trust page may exist elsewhere",
          "The lead gave a range of 7 days back to 14 days ahead. The docs give 7 days back and 15 ahead on premium plans, and 24 hours back and 5 days ahead on Free",
          "The auth docs say an unauthenticated request returns 403. The live API returned 401 with code 401001",
          "The MCP docs describe only the X-Api-Key header, while the endpoint's live metadata advertises OAuth with dynamic client registration"
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI 3.1 file, Markdown docs with llms.txt and a hosted MCP server with 11 tools suit agents, and a free plan exists. Paid prices are by quote only, free keys are barred from commercial use, the docs give no numeric rate limits, and the status page lists 50 incidents in 85 days, mostly stale or degraded data.",
      "bestFor": "Teams that need minute-level and route or polygon forecasts, alert webhooks and a hosted MCP server, and will buy through sales.",
      "strengths": [
        "Public OpenAPI 3.1.0 file (version 4.0.1, 31 paths, 39 operations), plus llms.txt and a Markdown copy of every docs page",
        "Hosted MCP server at api.tomorrow.io/v4/tomorrow-weather/mcp with 11 documented tools, added in April 2026",
        "The `fields`, `timesteps`, `startTime` and `endTime` parameters size a Timelines response to what the task needs",
        "Six-digit error codes that the docs say stay fixed, and soft warnings returned beside partial data",
        "Alert webhooks signed with HMAC-SHA256 in an `X-Signature` header, retried up to two times"
      ],
      "weaknesses": [
        "No public price for paid use. The plan table lists Free and Enterprise, the second by quote",
        "The subscription terms bar commercial use on self-generated accounts and forbid storing unaltered data without an order",
        "No numeric rate limits in the reviewed docs, and remaining-limit headers are documented for Enterprise accounts only",
        "Keys carry full privileges and may be sent as an `apikey` query parameter. More keys come through an account manager",
        "50 incidents on the status page between 15 July and 2 October 2026, 25 naming the Timeline or Historical API",
        "No official SDK, no security.txt, and no certification or disclosure policy found on the pages read"
      ],
      "agentNotes": [
        "Send the key in the `apikey` header, not the query string, so it stays out of URLs and logs",
        "Request only the `fields` and `timesteps` needed on POST /timelines. Free plans cover 24 hours back and 5 days ahead at `1h` and `1d`",
        "Split archive requests. POST /historical takes at most 31 days per call and deducts tokens, 1 for a point and 10 for a polygon",
        "Treat 401 with code 401001 as a missing or bad key. The docs say 403, the live API answered 401 on 8 October 2026",
        "On 429 back off without a hint. `Retry-After` is documented only for 503",
        "Check the plan's terms before storing or reselling responses. Free accounts are limited to non-commercial use with a Powered by Tomorrow.io link"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 51.4
        }
      ],
      "editorialScores": {
        "ergonomics": 73,
        "maintenance": 27,
        "payments": 20,
        "reliability": 55,
        "schema": 75,
        "security": 34,
        "transparency": 42
      },
      "provenanceScore": 84
    },
    "connect": {
      "http": "curl --request GET --url 'https://api.tomorrow.io/v4/weather/realtime?location=42.3478,-71.0466' --header 'apikey: API_KEY'",
      "config": {
        "mcpServers": {
          "tomorrow-weather-mcp": {
            "headers": {
              "X-Api-Key": "${TOMORROW_API_KEY}"
            },
            "type": "http",
            "url": "https://api.tomorrow.io/v4/tomorrow-weather/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/weather.current",
      "tool": "https://letme.dev/tomorrow-io"
    },
    "notable": [
      "Timestep availability differs by plan. Premium plans reach 7 days back and 15 days ahead at `1h` and `1d`, Free reaches 24 hours back and 5 days ahead, and minute-level steps reach 6 hours ahead (https://docs.tomorrow.io/reference/weather-data-layers)",
      "The Historical API archive starts on 1 January 2000 and ends 7 days ago (90 days for some fields), takes at most 31 days per call and deducts tokens, 1 for a point and 10 for a polygon (https://docs.tomorrow.io/reference/historical-overview)",
      "The hosted MCP server at https://api.tomorrow.io/v4/tomorrow-weather/mcp has 11 documented tools for realtime, forecast, history, climate normals, events, routes, Gale AI answers and data feeds, and was added in April 2026 (https://docs.tomorrow.io/reference/mcp)",
      "The subscription terms bar commercial use on self-generated accounts, require a Powered by Tomorrow.io link beside the data, and forbid storing unaltered data unless an order allows it (https://www.tomorrow.io/legal/terms-of-service/)",
      "Alerts post to a webhook signed with HMAC-SHA256 in an `X-Signature` header, sent from 35.231.166.26 and retried up to two times (https://docs.tomorrow.io/reference/api-webhooks)",
      "The status page lists 50 incidents between 15 July and 2 October 2026, three marked major, most of them stale or degraded data for a region or product (https://status.tomorrow.io/history)",
      "A data sources page updated 14 April 2026 names the UK Met Office, EUMETSAT, Copernicus, ECMWF, NOAA, NASA, the Australian Bureau of Meteorology, Synoptic and Earth Networks among upstream providers (https://www.tomorrow.io/legal/data-source-attribution/)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST API, version 4, at https://api.tomorrow.io/v4, with the hosted MCP server noted beside it"
      },
      {
        "label": "Endpoints",
        "value": "OpenAPI 3.1.0 file, version 4.0.1, 31 paths and 39 operations. Forecast, realtime, timelines, route, map tiles, recent history, historical archive, climate normals, locations, insights, alerts, events and notifications"
      },
      {
        "label": "MCP tools",
        "value": "get_realtime_weather, get_forecast_timeline, get_historical_weather, get_climate_normals, get_weather_events, get_route_weather_events, get_weather_summary, ask_weather_question, query_feed_data, get_feed_last_updated, get_feed_count"
      },
      {
        "label": "Free plan",
        "value": "Core data layers, 5-day forecast, 24 hours of history, 1 monitored location, 1 alert. Non-commercial use only under the terms"
      },
      {
        "label": "Forecast range",
        "value": "Free 5 days at `1h` and `1d`. Premium 15 days per the docs (the plan table says 14). Minute-level steps 6 hours ahead"
      },
      {
        "label": "History",
        "value": "Free 24 hours. Premium 7 days through Timelines. Archive from 1 January 2000 through the Historical API, 31 days per call, metered in tokens"
      },
      {
        "label": "Rate limits",
        "value": "Per second, hour and day by plan. No numbers in the docs. `X-RateLimit-*` headers for Enterprise accounts only. 429 when passed"
      },
      {
        "label": "Errors",
        "value": "Six-digit codes such as 400001, 401001, 402001 (insufficient tokens), 403002 (plan limit) and 503001 with `Retry-After`. Soft warnings returned with partial data. `X-Correlation-ID` on each response"
      },
      {
        "label": "Location formats",
        "value": "lat,lon, city name, US zip, UK postcode, a saved location ID, or GeoJSON Point, Polygon and LineString. Timelines polygons up to 500 square km"
      },
      {
        "label": "Webhooks",
        "value": "Alerts only. HMAC-SHA256 `X-Signature` with timestamp, source IP 35.231.166.26, up to two retries"
      },
      {
        "label": "Status",
        "value": "status.tomorrow.io on Atlassian Statuspage, 22 components"
      },
      {
        "label": "SDKs",
        "value": "None official. A Postman collection and samples on GitHub, last pushed January 2024"
      }
    ],
    "provenance": {
      "legalEntity": "The Tomorrow Companies Inc.",
      "domain": "tomorrow.io",
      "domainRegistered": "2012-02-15",
      "endpointOnVendorDomain": true,
      "terms": "https://www.tomorrow.io/legal/terms-of-service/",
      "privacy": "https://www.tomorrow.io/legal/product-privacy-policy/",
      "statusPage": "https://status.tomorrow.io",
      "changelog": "https://docs.tomorrow.io/reference/release-notes",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The subscription terms (last updated 19 October 2023) name The Tomorrow Companies Inc., a Delaware corporation with its principal place of business in Boston, Massachusetts, and cover the API, the dashboard and the data portal.",
        "The product privacy policy (last updated 17 December 2024) covers the API and platform and names Tomorrow.io Inc. as operator. The website has a separate privacy policy and terms of use, which we did not use here.",
        "The API and the MCP server answer at api.tomorrow.io.",
        "www.tomorrow.io, tomorrow.io and api.tomorrow.io each return 404 for /.well-known/security.txt.",
        "RDAP gives a registration date of 2012-02-15 for tomorrow.io. The status page runs on Atlassian Statuspage."
      ],
      "score": 84,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "The Tomorrow Companies Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "tomorrow.io, registered 2012-02-15 (14 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.tomorrow.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.tomorrow.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.tomorrow.io/legal/terms-of-service/",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.tomorrow.io/legal/product-privacy-policy/",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/tomorrow-io.json",
    "live": {
      "slug": "tomorrow-io",
      "probe": {
        "target": "https://api.tomorrow.io/v4",
        "method": "get",
        "lastAt": "2026-10-08T19:09:00.549742716Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 187,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 156,
        "p95ms24h": 187,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.tomorrow.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:07:01.865665571Z"
      },
      "pages": [
        {
          "url": "https://docs.tomorrow.io/reference/release-notes",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:19:37.617241436Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "5c08804d147f"
        },
        {
          "url": "https://www.tomorrow.io/legal/product-privacy-policy/",
          "kind": "privacy",
          "status": 0,
          "checkedAt": "2026-10-08T18:31:01.004304542Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "blockedByRobots": true
        },
        {
          "url": "https://www.tomorrow.io/legal/terms-of-service/",
          "kind": "terms",
          "status": 0,
          "checkedAt": "2026-10-08T18:31:01.446636319Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "blockedByRobots": true
        }
      ],
      "updatedAt": "2026-10-08T19:09:00.549742716Z"
    }
  }
}
