{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "xweather",
    "name": "Xweather Weather API",
    "vendor": "Vaisala Oyj",
    "vendorUrl": "https://www.xweather.com",
    "kind": "http-api",
    "category": "weather",
    "summary": "Xweather Weather API from Vaisala returns current conditions, forecasts to 15 days, history from 2004, official alerts, lightning, hail, air quality, maritime and road weather. Agents reach it as a REST API or a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/xweather",
    "markdownUrl": "https://www.anchorterminal.com/tools/xweather.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/xweather.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/xweather.json",
    "repo": "https://github.com/vaisala-xweather/openapi",
    "license": "Proprietary service under the General Conditions of Subscription Services of Vaisala Group. The OpenAPI files and the agent skills on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://data.api.xweather.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@aerisweather/javascript-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "A person signs up in a browser, registers an app in the account portal and receives a `client_id` and `client_secret` tied to a domain or app bundle namespace. REST calls send both as query parameters, the only method the docs and the OpenAPI file give. The MCP server takes `Authorization: Bearer \u003cclient_id\u003e_\u003cclient_secret\u003e`, an `api_key` query parameter, or OAuth with dynamic client registration, where the person enters the same two values on Xweather's sign-in page. Keys are regenerated in the dashboard.",
    "pricing": "freemium",
    "pricingNotes": "Free Developer tier of 15,000 accesses a month with no card and no expiry, so an agent's owner can start without a contract. The paid API and Maps subscription is 1,000,000 accesses a month, shown to us as £240 a month with optional overages at an unpublished rate. Enterprise is by quote. One request can cost 1 to 25 accesses or more. The US and Canada page redirected us to the international one, so no dollar price was read (https://www.xweather.com/pricing/weather-api-subscription, checked 2026-10-08).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 19,
    "popularity": {
      "githubStars": 0,
      "npmWeekly": 1403,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.xweather.com/docs/weather-api",
    "llmsTxt": "https://www.xweather.com/llms.txt",
    "openapi": "https://vaisala-xweather.github.io/openapi/weather-api-3.1.yaml",
    "registryName": "com.xweather/weather",
    "capabilities": [
      "weather.current",
      "weather.forecast",
      "weather.historical",
      "weather.alerts",
      "weather.marine",
      "data.weather"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "closed-source",
      "openapi",
      "llms-txt",
      "mcp",
      "mcp-registry",
      "oauth",
      "agent-skills",
      "webhooks",
      "status-page",
      "lightning",
      "finland"
    ],
    "lastRelease": "2026-09-14",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.1,
      "grade": "B",
      "agentReady": false,
      "rank": 219,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 81,
        "payments": 32,
        "reliability": 74,
        "schema": 83,
        "security": 52,
        "transparency": 68
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 74,
          "points": 14.8,
          "reason": "Graded as a hosted service. Status page at status.xweather.com on Atlassian Statuspage with 21 components, among them API General, Conditions, Forecasts, Alerts, Lightning Endpoints and MCP Server (20). It lists three incidents between 10 July and 8 October 2026. Two on 24 July are marked major and report reduced data rates from the lightning network for 33 and 72 minutes, and one on 15 July relays an upstream GOES-East satellite outage. None names the general API, conditions or forecasts components (20 of 30). Monthly quotas are published, 15,000 and 1,000,000 accesses, but the per-minute limit is given only in response headers and by support (8 of 15). 429 is documented with the codes `maxhits_min` and `maxhits`, the OpenAPI file declares `Retry-After`, seven `X-RateLimit-*` headers report the remaining allowance, the MCP docs advise exponential backoff, and failed calls are not charged. The API is read-only, so no idempotency keys are needed (13 of 15). The pricing page mentions custom SLA guarantees for enterprise plans, with no SLA document found (3 of 10). The REST API at 1.43.5 and the MCP server at 1.2.2 are generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "OpenAPI 3.2.0 and 3.1.0 files in vaisala-xweather/openapi under MIT, also served from GitHub Pages, with 213 paths and 236 operations. They were first published on 30 September 2026. The MCP tools' input schemas need a key to list and were not read (25). llms.txt at www.xweather.com/llms.txt indexes the site and docs pages. The docs pages have no Markdown copies (a .md address returns 404), though six agent skills in Markdown cover request building (8 of 10). Every operation and parameter in the OpenAPI file has a description, and the MCP tool pages state each tool's purpose and limits, such as a 24-hour tool marked as not for multi-day forecasts (16 of 20). The file has 9 enums and 10 required parameters among 2,289 parameter uses, and `filter`, `query` and `sort` are free strings with their own grammar (8 of 15). Each operation declares 200, 401, 404, 429 and 500 with examples, and the docs list 16 error codes and the warning codes (13 of 15). Dated, numbered changelogs for the API and the MCP server. The API path carries no version (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "`fields`, `limit` and `plimit` size a REST response, and the docs give a 15-day hourly forecast as about 600 KB, or 25 KB with three fields. The MCP server documents 19 tools, with `include_tags`, `exclude_tags`, `include_tools` and `exclude_tools` filters on the server URL (22 of 25). `limit`, `skip`, `plimit`, `pskip`, `sort`, `filter`, `query`, `from` and `to` cover paging and filtering, and `/batch` combines requests (18 of 20). Errors carry a code and description, but application errors such as `invalid_location` arrive with HTTP 200 and `success` false, so the status code alone misleads (15 of 20). All calls are reads and safe to repeat, and failed calls cost nothing. The MCP tools' annotations could not be read without a key (14 of 20). A location is the only required input and accepts a place name, coordinates or a postal code. Official SDKs are client-side, namely JavaScript (last released October 2024), iOS and Android, with Python notebooks and no server-side library (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 52,
          "points": 9.1,
          "reason": "Credentials are a `client_id` and `client_secret` per registered app, limited to a domain or app bundle namespace and regenerated in the dashboard. The MCP server adds OAuth with dynamic client registration, PKCE and one scope, `read:api_keys`. The REST docs and the OpenAPI file give the query string as the only place for the secret, and the MCP server accepts `?api_key=` (22 less 10, 12 of 30). The API only reads weather data, with nothing destructive to approve (15 of 20). Responses are mostly numeric. Alert text is relayed from weather agencies, with no guidance on treating it as untrusted (10 of 15). Cost and quota headers come back on each call. No per-call log for the account holder was found in the docs (4 of 15). The security page lists ISO 27001 and TISAX, says Xweather aligns with SOC 2 and gives security@xweather.com, with no report linked and no bounty. xweather.com has no security.txt, while the parent vaisala.com has one with a policy link (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 32,
          "points": 4,
          "reason": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (0). Plan prices are public without a login, and the cost of each endpoint in accesses is published. The overage rate is not, and the page showed us pounds only, £240 a month for 1,000,000 accesses (12 of 20). A free Developer tier of 15,000 accesses a month, with no card and no expiry per the pricing page (20). A person signs up in a browser. The MCP OAuth flow registers clients by API but still needs a human to enter the key (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "reason": "The newest API release is 1.43.5 on 14 September 2026, 24 days before this check (30). Three API releases fall in the last 90 days, 1.43.3 on 29 July, 1.43.4 on 31 August and 1.43.5 on 14 September, and the agent skills repository had releases 0.14.1 to 0.15.1 between 1 September and 5 October (20). Public changelogs, a ticket form and support@xweather.com, with community support on the free tier and priority email on the paid plan. Response times were not tested (10 of 15). The MCP server is in the official registry as com.xweather/weather, active since 2 September 2026 (15). The JavaScript SDK `@aerisweather/javascript-sdk` was last released in October 2024, while the OpenAPI and skills repositories carry CI and recent commits (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "note": "editorial 51, provenance 85",
          "reason": "Closed service under Vaisala's group subscription terms, dated 1 January 2023, which set a liability cap of twelve months' fees and ICC arbitration. They are written for annual, invoiced contracts and leave the product's own rules to service descriptions that were not found in public. The OpenAPI files and agent skills are MIT (15 of 30). The privacy policy is the group policy effective 1 June 2020. It covers online services, keeps data for a period it calls reasonable with no figure, and still cites the US Privacy Shield. No DPA was found (12 of 30). The changelog marks deprecations with dates, the API has `deprecated` and `warn_deprecated` codes, and the terms promise notice of modifications with a 30-day right to end the contract after a material reduction. No notice period is stated (8 of 20). A data processors page names about 40 processors with a location for each, with a caveat that it may be incomplete (16 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`fields`, `limit` and `plimit` size a REST response, and the docs give a 15-day hourly forecast as about 600 KB, or 25 KB with three fields. The MCP server documents 19 tools, with `include_tags`, `exclude_tags`, `include_tools` and `exclude_tools` filters on the server URL (22 of 25). `limit`, `skip`, `plimit`, `pskip`, `sort`, `filter`, `query`, `from` and `to` cover paging and filtering, and `/batch` combines requests (18 of 20). Errors carry a code and description, but application errors such as `invalid_location` arrive with HTTP 200 and `success` false, so the status code alone misleads (15 of 20). All calls are reads and safe to repeat, and failed calls cost nothing. The MCP tools' annotations could not be read without a key (14 of 20). A location is the only required input and accepts a place name, coordinates or a postal code. Official SDKs are client-side, namely JavaScript (last released October 2024), iOS and Android, with Python notebooks and no server-side library (9 of 15).",
          "maintenance": "The newest API release is 1.43.5 on 14 September 2026, 24 days before this check (30). Three API releases fall in the last 90 days, 1.43.3 on 29 July, 1.43.4 on 31 August and 1.43.5 on 14 September, and the agent skills repository had releases 0.14.1 to 0.15.1 between 1 September and 5 October (20). Public changelogs, a ticket form and support@xweather.com, with community support on the free tier and priority email on the paid plan. Response times were not tested (10 of 15). The MCP server is in the official registry as com.xweather/weather, active since 2 September 2026 (15). The JavaScript SDK `@aerisweather/javascript-sdk` was last released in October 2024, while the OpenAPI and skills repositories carry CI and recent commits (6 of 10).",
          "payments": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (0). Plan prices are public without a login, and the cost of each endpoint in accesses is published. The overage rate is not, and the page showed us pounds only, £240 a month for 1,000,000 accesses (12 of 20). A free Developer tier of 15,000 accesses a month, with no card and no expiry per the pricing page (20). A person signs up in a browser. The MCP OAuth flow registers clients by API but still needs a human to enter the key (0).",
          "reliability": "Graded as a hosted service. Status page at status.xweather.com on Atlassian Statuspage with 21 components, among them API General, Conditions, Forecasts, Alerts, Lightning Endpoints and MCP Server (20). It lists three incidents between 10 July and 8 October 2026. Two on 24 July are marked major and report reduced data rates from the lightning network for 33 and 72 minutes, and one on 15 July relays an upstream GOES-East satellite outage. None names the general API, conditions or forecasts components (20 of 30). Monthly quotas are published, 15,000 and 1,000,000 accesses, but the per-minute limit is given only in response headers and by support (8 of 15). 429 is documented with the codes `maxhits_min` and `maxhits`, the OpenAPI file declares `Retry-After`, seven `X-RateLimit-*` headers report the remaining allowance, the MCP docs advise exponential backoff, and failed calls are not charged. The API is read-only, so no idempotency keys are needed (13 of 15). The pricing page mentions custom SLA guarantees for enterprise plans, with no SLA document found (3 of 10). The REST API at 1.43.5 and the MCP server at 1.2.2 are generally available (10).",
          "schema": "OpenAPI 3.2.0 and 3.1.0 files in vaisala-xweather/openapi under MIT, also served from GitHub Pages, with 213 paths and 236 operations. They were first published on 30 September 2026. The MCP tools' input schemas need a key to list and were not read (25). llms.txt at www.xweather.com/llms.txt indexes the site and docs pages. The docs pages have no Markdown copies (a .md address returns 404), though six agent skills in Markdown cover request building (8 of 10). Every operation and parameter in the OpenAPI file has a description, and the MCP tool pages state each tool's purpose and limits, such as a 24-hour tool marked as not for multi-day forecasts (16 of 20). The file has 9 enums and 10 required parameters among 2,289 parameter uses, and `filter`, `query` and `sort` are free strings with their own grammar (8 of 15). Each operation declares 200, 401, 404, 429 and 500 with examples, and the docs list 16 error codes and the warning codes (13 of 15). Dated, numbered changelogs for the API and the MCP server. The API path carries no version (13 of 15).",
          "security": "Credentials are a `client_id` and `client_secret` per registered app, limited to a domain or app bundle namespace and regenerated in the dashboard. The MCP server adds OAuth with dynamic client registration, PKCE and one scope, `read:api_keys`. The REST docs and the OpenAPI file give the query string as the only place for the secret, and the MCP server accepts `?api_key=` (22 less 10, 12 of 30). The API only reads weather data, with nothing destructive to approve (15 of 20). Responses are mostly numeric. Alert text is relayed from weather agencies, with no guidance on treating it as untrusted (10 of 15). Cost and quota headers come back on each call. No per-call log for the account holder was found in the docs (4 of 15). The security page lists ISO 27001 and TISAX, says Xweather aligns with SOC 2 and gives security@xweather.com, with no report linked and no bounty. xweather.com has no security.txt, while the parent vaisala.com has one with a policy link (11 of 20).",
          "transparency": "Closed service under Vaisala's group subscription terms, dated 1 January 2023, which set a liability cap of twelve months' fees and ICC arbitration. They are written for annual, invoiced contracts and leave the product's own rules to service descriptions that were not found in public. The OpenAPI files and agent skills are MIT (15 of 30). The privacy policy is the group policy effective 1 June 2020. It covers online services, keeps data for a period it calls reasonable with no figure, and still cites the US Privacy Shield. No DPA was found (12 of 30). The changelog marks deprecations with dates, the API has `deprecated` and `warn_deprecated` codes, and the terms promise notice of modifications with a 30-day right to end the contract after a material reduction. No notice period is stated (8 of 20). A data processors page names about 40 processors with a location for each, with a caveat that it may be incomplete (16 of 20)."
        },
        "sources": [
          {
            "what": "API docs",
            "url": "https://www.xweather.com/docs/weather-api",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://www.xweather.com/docs/weather-api/getting-started/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiting",
            "url": "https://www.xweather.com/docs/weather-api/getting-started/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "cost headers",
            "url": "https://www.xweather.com/docs/weather-api/getting-started/cost-headers",
            "seen": "2026-10-08"
          },
          {
            "what": "responses, headers and errors",
            "url": "https://www.xweather.com/docs/weather-api/getting-started/responses",
            "seen": "2026-10-08"
          },
          {
            "what": "reducing output",
            "url": "https://www.xweather.com/docs/weather-api/getting-started/reducing-output",
            "seen": "2026-10-08"
          },
          {
            "what": "scripting best practices",
            "url": "https://www.xweather.com/docs/weather-api/reference/best-practices",
            "seen": "2026-10-08"
          },
          {
            "what": "API changelog",
            "url": "https://www.xweather.com/docs/weather-api/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "forecasts endpoint",
            "url": "https://www.xweather.com/docs/weather-api/endpoints/forecasts",
            "seen": "2026-10-08"
          },
          {
            "what": "conditions endpoint",
            "url": "https://www.xweather.com/docs/weather-api/endpoints/conditions",
            "seen": "2026-10-08"
          },
          {
            "what": "toolkits",
            "url": "https://www.xweather.com/docs/weather-api/resources/toolkits",
            "seen": "2026-10-08"
          },
          {
            "what": "attribution guide",
            "url": "https://www.xweather.com/docs/weather-api/resources/attribution",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://www.xweather.com/docs/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP authentication",
            "url": "https://www.xweather.com/docs/mcp-server/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP filtering and tool scoping",
            "url": "https://www.xweather.com/docs/mcp-server/filtering-tool-scoping",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool catalogue",
            "url": "https://www.xweather.com/docs/mcp-server/tools",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP changelog",
            "url": "https://www.xweather.com/docs/mcp-server/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth metadata",
            "url": "https://mcp.api.xweather.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry entry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=xweather",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI repository",
            "url": "https://github.com/vaisala-xweather/openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.1 file",
            "url": "https://vaisala-xweather.github.io/openapi/weather-api-3.1.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "agent skills repository",
            "url": "https://github.com/vaisala-xweather/xweather-agent-skills",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing, as served to us",
            "url": "https://www.xweather.com/pricing/weather-api-subscription",
            "seen": "2026-10-08"
          },
          {
            "what": "product page",
            "url": "https://www.xweather.com/products/weather-api",
            "seen": "2026-10-08"
          },
          {
            "what": "subscription terms (PDF)",
            "url": "https://docs.vaisala.com/api/khub/documents/_2cuASo637CBKluQEurbLA/content",
            "seen": "2026-10-08"
          },
          {
            "what": "legal index",
            "url": "https://www.xweather.com/legal",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.xweather.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.xweather.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "data processors",
            "url": "https://www.xweather.com/company/data-processors",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.xweather.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.xweather.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://www.xweather.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript SDK on npm",
            "url": "https://registry.npmjs.org/@aerisweather%2Fjavascript-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "parent security.txt",
            "url": "https://www.vaisala.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/xweather.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the US dollar plan price. The US and Canada pricing page redirected us to the international page, which showed £240 a month, so unitPrices is empty",
          "unchecked: the overage rate beyond 1,000,000 accesses, which the pricing page does not state",
          "unchecked: the MCP tools' input schemas and annotations, which need a key to list. The count of 19 is from the docs pages",
          "unchecked: whether the free Developer tier includes MCP access. The docs say a 403 means the subscription lacks it",
          "unchecked: per-minute rate limits by plan. The docs give headers and refer callers to support",
          "unchecked: whether signup asks for a card. The pricing page says none is required for the Developer tier, and we did not open the checkout",
          "Whether a Weather API service description permits commercial use or redistribution. The group terms prohibit commercial use of freemiums and bar passing data to third parties unless a service description allows it, and no such description was found in public",
          "Which Vaisala company contracts for Xweather. The terms say the company named on the quotation or invoice, and the privacy policy names Vaisala Oyj, which we used as the legal entity",
          "The security page says Xweather maintains ISO 27001 practices and aligns with SOC 2. No certificate or report was linked, so the scope is unknown",
          "The docs' authentication page calls the scheme OAuth 2.0, but REST calls send a static ID and secret in the query string",
          "The lead was right about the MCP server, agent skills and SDKs. The SDKs are client-side (JavaScript, iOS, Android), and the docs link the old status address status.aerisweather.com, which redirects to status.xweather.com"
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI file with 236 operations, a hosted MCP server in the official registry and a free tier of 15,000 accesses a month suit agents. REST credentials travel only in the query string, per-minute limits are unpublished, and the group terms bar commercial use of free plans and passing data to third parties unless a service description allows it.",
      "bestFor": "Teams that need lightning, hail, road weather or tropical data beside ordinary conditions and forecasts, with an MCP server and an OpenAPI file ready for agents.",
      "strengths": [
        "OpenAPI 3.2 and 3.1 files under MIT, published 30 September 2026, with 213 paths, 236 operations and 401, 404, 429 and 500 responses on each",
        "Hosted MCP server at `https://mcp.api.xweather.com/mcp` with 19 documented tools, tag and tool filters, and an active entry in the official MCP registry",
        "Free Developer tier of 15,000 accesses a month with no card and no expiry, per the pricing page",
        "Every 2xx response carries `X-Cost-Tokens` and `X-RateLimit-*` headers, and 4xx and 5xx responses are not charged",
        "Dated changelogs for the API (1.43.5 on 14 September 2026) and the MCP server (1.2.2 on 22 June 2026)"
      ],
      "weaknesses": [
        "The REST API documents `client_id` and `client_secret` only as query parameters, and the MCP server also accepts the key as `?api_key=`",
        "Per-minute rate limits are not published. The docs refer callers to response headers, support or an account executive",
        "The group subscription terms prohibit commercial use of freemium plans and bar making data available to third parties unless a service description allows it",
        "One access is not one request. `/impacts` costs 25 accesses, `/lightning` 10 and air quality 5, multiplied by the time intervals requested",
        "No overage price or US dollar price was readable. The pricing page served us pounds, £240 a month for 1,000,000 accesses",
        "The privacy policy is Vaisala's group policy effective 1 June 2020, with no retention period stated and no DPA found"
      ],
      "agentNotes": [
        "Check `success` and `error.code` on every response. Application errors such as `invalid_location` return HTTP 200 with `success` false",
        "Send `fields`, `limit` and `plimit`. The docs put a 15-day hourly forecast at about 600 KB, and about 25 KB with three fields",
        "Read `X-Cost-Tokens` after each call. Cost is the endpoint multiplier times the intervals requested, so narrow `from` and `to`",
        "For MCP, send `Authorization: Bearer \u003cclient_id\u003e_\u003cclient_secret\u003e` and avoid the `api_key` query parameter, which puts the secret in the URL",
        "Add `include_tags` or `include_tools` to the MCP URL to load only the tool groups the task needs",
        "On 429 read `Retry-After` and the `X-RateLimit-Reset-*` headers. `maxhits_min` clears at the next minute, `maxhits` at the period reset"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.1
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 81,
        "payments": 32,
        "reliability": 74,
        "schema": 83,
        "security": 52,
        "transparency": 51
      },
      "provenanceScore": 85
    },
    "connect": {
      "http": "curl 'https://data.api.xweather.com/places/98109?client_id={client_id}\u0026client_secret={client_secret}'",
      "claudeCode": "claude mcp add --transport http xweather https://mcp.api.xweather.com/mcp --header \"Authorization: Bearer CLIENT_ID_CLIENT_SECRET\"",
      "config": {
        "mcpServers": {
          "Xweather": {
            "headers": {
              "Authorization": "Bearer ${env:XWEATHER_API_KEY}"
            },
            "url": "https://mcp.api.xweather.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/weather.current",
      "tool": "https://letme.dev/xweather"
    },
    "notable": [
      "The OpenAPI repository was published on 30 September 2026 with 3.2.0 and 3.1.0 files of 58 endpoint groups and 236 operations, generated from the docs, the API source and recorded responses per its README (https://github.com/vaisala-xweather/openapi)",
      "The MCP server is listed in the official MCP registry as com.xweather/weather, version 1.2.2, status active, published 2 September 2026 (https://registry.modelcontextprotocol.io/v0/servers?search=xweather)",
      "The MCP endpoint's live metadata advertises an authorisation server at oauth.api.xweather.com with dynamic client registration, PKCE (S256 and plain) and one scope, `read:api_keys`, and lists both header and query as bearer methods (https://mcp.api.xweather.com/.well-known/oauth-authorization-server)",
      "The group subscription terms prohibit commercial use of freemiums and trials (section 17.1), limit paid use to internal business purposes and bar making data available to third parties unless a service description allows it (sections 2.2 and 2.3) (https://docs.vaisala.com/api/khub/documents/_2cuASo637CBKluQEurbLA/content)",
      "Under the same terms Vaisala may use analyses of a customer's use of the service for training machine learning algorithms and for benchmarking (section 12.2)",
      "A request's cost in accesses is the endpoint multiplier times the time intervals covered, reported in `X-Cost-Tokens`, and only 2xx responses are charged (https://www.xweather.com/docs/weather-api/getting-started/cost-headers)",
      "The status page lists three incidents between 10 July and 8 October 2026. Two on 24 July, marked major, were reduced data rates from the lightning network for 33 and 72 minutes. The third was an upstream GOES-East satellite outage (https://status.xweather.com/api/v2/incidents.json)",
      "The data processors page names OpenAI as an LLM processor in the USA, with AWS, Hetzner, Equinix, MongoDB, Sentry, Auth0, Stripe and others, each with a location (https://www.xweather.com/company/data-processors)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST API at https://data.api.xweather.com (version 1.43.5), with the hosted MCP server at https://mcp.api.xweather.com/mcp (version 1.2.2) noted beside it"
      },
      {
        "label": "Endpoints",
        "value": "OpenAPI 3.2.0 and 3.1.0 files, 58 endpoint groups, 213 paths and 236 operations (213 GET, 23 POST). Conditions, forecasts, observations, alerts, lightning, hail, air quality, maritime, tides, tropical cyclones, road weather, storm reports, normals, irradiance and places"
      },
      {
        "label": "MCP tools",
        "value": "19 documented, all named `xweather_get_*`. General 7, forecast 2, air quality 2, lightning 1, tropical 4, maps 1, road weather 2. Filters `include_tags`, `exclude_tags`, `include_tools` and `exclude_tools` on the server URL"
      },
      {
        "label": "Forecast range",
        "value": "Up to 15 days, in daily, day and night, 3-hour or 1-hour intervals. Maritime forecasts reach 7 days"
      },
      {
        "label": "History",
        "value": "Conditions from January 2004 to today. Archive endpoints for observations, air quality, lightning, hail, maritime and tropical cyclones, some as paid add-ons"
      },
      {
        "label": "Credentials",
        "value": "`client_id` and `client_secret` per registered app, limited to a domain or app bundle namespace, sent as query parameters. MCP takes `Authorization: Bearer \u003cclient_id\u003e_\u003cclient_secret\u003e`, `?api_key=`, or OAuth with dynamic client registration and PKCE"
      },
      {
        "label": "Plans",
        "value": "Developer, free, 15,000 accesses a month, no card, service pauses at the limit. API and Maps subscription, 1,000,000 accesses a month, shown to us as £240 a month with optional overages. Enterprise from 2 million accesses by quote"
      },
      {
        "label": "Access cost",
        "value": "Accesses = endpoint multiplier × time intervals. `/impacts` 25, `/hail/threats` and `/lightning/analytics` 12, `/lightning` 10, `/airquality` 5, conditions, forecasts, alerts and observations 1. Each request inside `/batch` counts separately. 4xx and 5xx are free"
      },
      {
        "label": "Rate limits",
        "value": "A per-minute limit and a per-period limit by plan. No per-minute number in the docs. `X-RateLimit-Limit-Minute`, `-Remaining-Minute`, `-Reset-Minute` and the `-Period` equivalents on responses. 429 with `maxhits_min` or `maxhits`, and `Retry-After` per the OpenAPI file"
      },
      {
        "label": "Errors",
        "value": "JSON envelope `success`, `error`, `response`. 16 error codes such as `invalid_client`, `invalid_location`, `insufficient_scope` and `maxhits_min`, plus `warn_*` warnings. Application errors can arrive with HTTP 200"
      },
      {
        "label": "Output",
        "value": "JSON, GeoJSON, CSV and TSV through `format`. `fields`, `limit`, `plimit`, `skip`, `pskip`, `sort`, `filter` and `query` shape the response"
      },
      {
        "label": "Webhooks",
        "value": "Pushed data is a separate paid subscription arranged through sales. The agent skill says deliveries are retried two or three times with no replay"
      },
      {
        "label": "SDKs and skills",
        "value": "JavaScript `@aerisweather/javascript-sdk` 1.8.6 (October 2024), iOS and Android SDKs, Python notebooks. Six agent skills under MIT in vaisala-xweather/xweather-agent-skills, release 0.15.1 on 5 October 2026"
      },
      {
        "label": "Attribution",
        "value": "Required on all products. A link to https://www.xweather.com/ reading Powered by Vaisala Xweather, or the logo"
      },
      {
        "label": "Status",
        "value": "status.xweather.com on Atlassian Statuspage, 21 components, among them API General, Conditions Endpoint, Forecasts Endpoint, Alerts Endpoint, Lightning Endpoints and MCP Server"
      },
      {
        "label": "Certifications",
        "value": "The security page lists ISO 27001 and TISAX and says Xweather aligns with SOC 2. No report or certificate is linked"
      }
    ],
    "provenance": {
      "legalEntity": "Vaisala Oyj",
      "domain": "xweather.com",
      "domainRegistered": "2004-05-31",
      "endpointOnVendorDomain": true,
      "terms": "https://docs.vaisala.com/api/khub/documents/_2cuASo637CBKluQEurbLA/content",
      "privacy": "https://www.xweather.com/privacy",
      "statusPage": "https://status.xweather.com",
      "changelog": "https://www.xweather.com/docs/weather-api/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms are the General Conditions of Subscription Services of Vaisala Group, DOC250754-B, dated 1 January 2023, a nine-page PDF. www.xweather.com/terms and the legal page redirect to a script-drawn viewer on docs.vaisala.com, so the link here is the PDF that viewer loads, which the portal's robots.txt allows. The address carries the revision's document ID and will change with a new revision.",
        "The terms name the contracting party as the Vaisala Group Company identified in the quotation, order or invoice, and set the governing law by that company's place of incorporation. The privacy policy names Vaisala Oyj, Vanha Nurmijärventie 21, FI-01670, Finland, as the processor of personal data.",
        "The privacy policy at www.xweather.com/privacy is Vaisala's group policy (effective 2020-06-01, Ref. DOC229710-D). It covers online services supplied for a fee or as a free trial.",
        "The API answers at data.api.xweather.com, the MCP server at mcp.api.xweather.com and its authorisation server at oauth.api.xweather.com.",
        "www.xweather.com/.well-known/security.txt returns 404 and data.api.xweather.com answers 401 for it. The parent's www.vaisala.com/.well-known/security.txt exists, with security@vaisala.com and a policy link but no Expires field.",
        "RDAP gives a registration date of 2004-05-31 for xweather.com, with GoDaddy as registrar. The status page runs on Atlassian Statuspage, and status.aerisweather.com redirects to it."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Vaisala Oyj",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "xweather.com, registered 2004-05-31 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "data.api.xweather.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.xweather.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://docs.vaisala.com/api/khub/documents/_2cuASo637CBKluQEurbLA/content",
          "state": "unreadable",
          "reason": "not a text document (application/pdf)",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.xweather.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2020-06-01",
          "words": 1929,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "(Effective as of 2020-06-01, Ref. DOC229710-D)",
              "says": "Last updated 2020-06-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Vaisala typically collects and processes personal data of the contact persons of Vaisala's customers, the Site visitors and the users of the online store."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Vaisala does not transfer or disclose your personal data to a third party without your permission, except when necessary for processing a request for quotation or fulfilling an order, including without limitation, providing necessary information to relevant finance-related companies, logistics and transport service pr…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Because Vaisala is committed to protecting your privacy, Vaisala does not sell or transfer personal data to third parties for their promotional purposes.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Such transfers will be carried out in compliance with applicable laws and necessary safeguards, such as EU Commission’s standard contractual clauses, adequacy decisions, binding corporate rules, or US Privacy Shield framework, in order to ensure adequate level of protection for personal data.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "(Effective as of 2020-06-01, Ref. DOC229710-D)"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Vaisala may share contact details and online behaviour data with sales channel partners for sales and marketing of its own products and services.",
              "quote": "Additionally, Vaisala may share your contact details and online behaviour data, such as Site visits, with sales channel partners for the purpose of sales and marketing of Vaisala’s products and services."
            },
            {
              "date": "2026-10-08",
              "text": "Vaisala may receive names and email addresses from third-party marketing databases and public sources such as Google and LinkedIn.",
              "quote": "Vaisala may receive and collect personal data (including e.g. name and email) from marketing databases provided to Vaisala by third parties or public sources such as Google, LinkedIn"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/xweather.json",
    "live": {
      "slug": "xweather",
      "probe": {
        "target": "https://data.api.xweather.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:26.246184839Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 284,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 271,
        "p95ms24h": 315,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.xweather.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:31.231174608Z"
      },
      "updatedAt": "2026-10-08T21:12:26.246184839Z"
    }
  }
}
