{
  "data": {
    "category": {
      "area": "business",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas",
        "sheets.records"
      ],
      "description": "Spreadsheets and table products an agent can read and write. Cells, ranges and formulas in a workbook, or typed records in a base. Compared on read and write calls, batch limits, formulas, change events and how access to one file is scoped.",
      "json": "https://www.anchorterminal.com/categories/spreadsheets.json",
      "name": "Spreadsheets \u0026 operational tables",
      "slug": "spreadsheets",
      "test": "The same workbook of one thousand rows in each listing. The same tasks run through its API (read a range, append rows, update cells in a batch, add a formula column, filter records). We check limits, consistency after writes and change notifications. In this run listings are graded from public evidence against the published checklist.",
      "title": "Spreadsheet and operational table APIs for AI agents",
      "toolCount": 7,
      "tools": [
        "google-sheets-api",
        "nocodb",
        "airtable",
        "smartsheet",
        "coda",
        "baserow",
        "microsoft-excel-graph"
      ],
      "url": "https://www.anchorterminal.com/categories/spreadsheets"
    },
    "tools": [
      {
        "slug": "google-sheets-api",
        "name": "Google Sheets API",
        "vendor": "Google",
        "vendorUrl": "https://developers.google.com/workspace/sheets",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "REST API from Google for reading and writing Google Sheets spreadsheets, covering cell values, ranges, formulas, formatting, tables and comments. Access is by OAuth 2.0, and a six-tool MCP server is in Developer Preview.",
        "url": "https://www.anchorterminal.com/tools/google-sheets-api",
        "markdownUrl": "https://www.anchorterminal.com/tools/google-sheets-api.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/google-sheets-api.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/google-sheets-api.json",
        "repo": "https://github.com/googleapis/google-api-nodejs-client",
        "license": "Proprietary service under the Google APIs Terms of Service. The client libraries are Apache-2.0",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://sheets.googleapis.com/v4",
        "packages": [
          {
            "registry": "npm",
            "name": "@googleapis/sheets"
          },
          {
            "registry": "pypi",
            "name": "google-api-python-client"
          }
        ],
        "auth": "oauth",
        "authNotes": "OAuth 2.0, set up by a person in a Google Cloud project with a consent screen. No partner or sales approval. drive.file is non-sensitive and covers only files the user opens with the app. spreadsheets and spreadsheets.readonly are sensitive and need extra verification for a public app, and drive and drive.readonly are restricted. Scopes apply to a whole spreadsheet file, not one sheet. Service accounts work, and their calls count as one user for quota. An API key reads only files shared with anyone who has the link. The MCP server also needs sheetsmcp.googleapis.com enabled, your own OAuth client and Developer Preview Programme membership.",
        "pricing": "free",
        "pricingNotes": "Standard use of the Sheets API has no additional cost, and a free Google account can start without a card or contract. Quotas are 300 reads and 300 writes a minute per project and 60 each per user, with no daily limit. Google says exceeding the quota request limits is planned to incur charges to the Cloud billing account later in 2026, with no price published and 90 days' notice promised. There is no separate sandbox; a test spreadsheet in any account does that job (https://developers.google.com/workspace/sheets/api/limits; https://developers.google.com/workspace/tools-safety).",
        "priceSummary": "Free",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Sheets API docs, the limits page or the discovery document (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 6,
        "popularity": {
          "githubStars": 12262,
          "npmWeekly": 1859932,
          "pypiWeekly": 31750331,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developers.google.com/workspace/sheets/api/guides/concepts",
        "capabilities": [
          "sheets.read",
          "sheets.write",
          "sheets.formulas",
          "sheets.tables"
        ],
        "tags": [
          "hosted",
          "official",
          "free-tier",
          "mcp",
          "oauth",
          "typescript",
          "python",
          "enterprise",
          "status-page"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 76.3,
          "grade": "BB",
          "agentReady": true,
          "rank": 33,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 1,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 85,
            "payments": 35,
            "reliability": 90,
            "schema": 83,
            "security": 80,
            "transparency": 80
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "Batch updates apply atomically and count as one request, and the drive.file scope limits an app to files the user picks. Quotas are 300 reads and 300 writes a minute per project, reads are by range with no row filter or paging, and a person must complete OAuth consent first.",
          "bestFor": "Agents reading and writing cells, formulas and formatting in spreadsheets people already keep in Google Sheets.",
          "strengths": [
            "spreadsheets.batchUpdate takes 74 request kinds, applies them atomically and counts as one request against quota",
            "Public discovery document for v4 (revision 20260930, 17 methods, 273 schemas) and Markdown copies of doc pages at .md.txt URLs",
            "drive.file is a non-sensitive scope that limits an app to the files a user opens with it, and spreadsheets.readonly exists for reading",
            "No Sheets incident on the Workspace status dashboard since 12 November 2025, read on 8 October 2026",
            "Standard use costs nothing, with no daily request cap inside the per-minute quotas"
          ],
          "weaknesses": [
            "Quotas are 300 reads and 300 writes a minute per project and 60 each per user per project",
            "No row filter, query or paging on reads. An agent asks for A1 ranges and trims with a fields mask",
            "No idempotency key, so a values.append retried after the 180-second timeout can add the rows twice",
            "The MCP server is Developer Preview, and its update_spreadsheet tool carries destructiveHint false although it can delete sheets, rows and ranges",
            "Scopes apply to a whole spreadsheet file, not one sheet, and overage charges planned for later in 2026 have no published price"
          ],
          "agentNotes": [
            "Ask for drive.file where the user picks the files. spreadsheets and spreadsheets.readonly are sensitive scopes and need extra verification for a public app",
            "Send valueInputOption=USER_ENTERED to write formulas. With RAW the string =1+2 is stored as text",
            "Put related changes in one spreadsheets.batchUpdate. It counts as one write request and none of it applies if any request is invalid",
            "Pass ranges and a fields mask on spreadsheets.get and leave includeGridData off for large files",
            "Back off exponentially on 429 and 503, and keep to one request a second per spreadsheet. After a timeout on values.append, read the range before retrying"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 76.3
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 85,
            "payments": 35,
            "reliability": 90,
            "schema": 83,
            "security": 80,
            "transparency": 65
          },
          "provenanceScore": 94
        },
        "connect": {
          "install": "npm install @googleapis/sheets",
          "http": "curl \"https://sheets.googleapis.com/v4/spreadsheets/$SPREADSHEET_ID/values/Sheet1!A1:D10\" \\\n  -H \"Authorization: Bearer $GOOGLE_ACCESS_TOKEN\"",
          "config": {
            "mcpServers": {
              "sheets": {
                "url": "https://sheetsmcp.googleapis.com/mcp/v1"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.read",
          "tool": "https://letme.dev/google-sheets-api"
        },
        "sameCompany": [
          "gemini-api",
          "gemini-embedding",
          "vertex-ai-tuning",
          "google-model-armor",
          "google-imagen",
          "google-veo",
          "google-lyria",
          "google-speech-to-text",
          "google-adk",
          "google-secret-manager",
          "google-weather-api",
          "chrome-devtools-mcp",
          "google-maps-platform",
          "google-cloud-translation",
          "google-calendar-api",
          "google-drive-api",
          "gemini-cli",
          "google-ads-api",
          "gmail-api"
        ],
        "area": "business",
        "provenance": {
          "legalEntity": "Google LLC",
          "domain": "google.com",
          "domainRegistered": "1997-09-15",
          "domainNote": "The endpoint is on googleapis.com, Google's API domain. google.com was registered in 1997.",
          "endpointOnVendorDomain": true,
          "terms": "https://developers.google.com/terms",
          "privacy": "https://policies.google.com/privacy",
          "statusPage": "https://www.google.com/appsstatus/dashboard/",
          "changelog": "https://developers.google.com/workspace/sheets/release-notes",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The Google APIs Terms of Service (last modified 9 November 2021) name Google LLC, 1600 Amphitheatre Parkway, Mountain View.",
            "RDAP for google.com gives a registration date of 1997-09-15.",
            "www.google.com/.well-known/security.txt expires on 1 April 2030 and names g.co/vulnz, security@google.com and the vulnerability reward programme.",
            "Google publishes a discovery document for the API, not an OpenAPI spec.",
            "The MCP server is part of the Workspace Developer Preview Programme and can change.",
            "The Google privacy policy read on 8 October 2026 is the version effective 1 October 2026."
          ],
          "score": 94
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/google-sheets-api.json",
        "live": {
          "slug": "google-sheets-api",
          "probe": {
            "target": "https://sheets.googleapis.com/v4",
            "method": "get",
            "lastAt": "2026-10-08T17:36:36.670614924Z",
            "lastOk": true,
            "lastStatus": 400,
            "lastMs": 192,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 188,
            "p95ms24h": 700,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "versions": [
            {
              "registry": "github",
              "name": "googleapis/google-api-nodejs-client",
              "version": "agentidentity-v3.2.0",
              "released": "2026-10-07",
              "seenAt": "2026-10-08T16:14:25.225453746Z"
            },
            {
              "registry": "npm",
              "name": "@googleapis/sheets",
              "version": "18.1.1",
              "seenAt": "2026-10-08T16:14:21.513613578Z"
            },
            {
              "registry": "pypi",
              "name": "google-api-python-client",
              "version": "2.201.0",
              "released": "2026-09-30",
              "seenAt": "2026-10-08T16:14:25.103740958Z"
            }
          ],
          "githubStars": 12263,
          "npmWeekly": 1859932,
          "pypiWeekly": 31750331,
          "securityTxt": {
            "url": "https://google.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2030-04-01T00:00:00z",
            "checkedAt": "2026-10-08T15:38:39.75078566Z"
          },
          "updatedAt": "2026-10-08T17:36:36.670614924Z"
        }
      },
      {
        "slug": "nocodb",
        "name": "NocoDB",
        "vendor": "NocoDB Inc",
        "vendorUrl": "https://nocodb.com",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth.",
        "url": "https://www.anchorterminal.com/tools/nocodb",
        "markdownUrl": "https://www.anchorterminal.com/tools/nocodb.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nocodb.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nocodb.json",
        "repo": "https://github.com/nocodb/nocodb",
        "license": "Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://app.nocodb.com",
        "packages": [
          {
            "registry": "npm",
            "name": "nocodb-sdk"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. A signed-in user creates a fine-grained API token in Account Settings, choosing permission categories, bases and an expiry, and sends it as `xc-token` or `Authorization: Bearer`. For MCP the user creates a connection with its own key, sent as `x-api-key`, or a web client uses OAuth with PKCE and dynamic client registration and the user picks bases and tools on the consent screen. No review step was found. A token or connection never exceeds its owner's role. Workspaces that enforce SSO accept only tokens created after an SSO sign-in.",
        "pricing": "freemium",
        "pricingNotes": "Free plan with 1,000 API calls a month, 1,000 records and 3 editor seats, no card required per the pricing page, so an agent can start without a contract. Plus is $12 a seat a month billed annually, Business $24 and Scale $45, with Plus and Business capped at 9 paid seats. Enterprise through sales. API calls aren't priced separately. The self-hosted Community Edition is free for internal use (checked 2026-10-08).",
        "priceSummary": "$12 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the REST API docs, the MCP docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 199,
        "popularity": {
          "githubStars": 65215,
          "npmWeekly": 6282,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://nocodb.com/docs/apis-and-mcp",
        "llmsTxt": "https://nocodb.com/llms.txt",
        "openapi": "https://nocodb.com/apis/v3/swagger-v3.json",
        "capabilities": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "tags": [
          "official",
          "hosted",
          "self-hosted",
          "mcp",
          "source-available",
          "free-tier",
          "oauth",
          "openapi",
          "llms-txt",
          "webhooks",
          "javascript",
          "status-page",
          "soc2"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 75.7,
          "grade": "BB",
          "agentReady": true,
          "rank": 37,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 2,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 87,
            "payments": 30,
            "reliability": 97,
            "schema": 85,
            "security": 71,
            "transparency": 76
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.",
          "bestFor": "Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.",
          "strengths": [
            "Fine-grained API tokens carry eight permission categories at Read or Read and write, a list of bases, an expiry and an on-off switch",
            "An MCP connection lists only the tools its owner allowed, by section at Read, Read and write, or Read, write and delete",
            "Public OpenAPI 3.1 file for the v3 REST API with 114 operations, plus llms.txt and a Markdown copy of every docs page",
            "The MCP record tools in the source set `readOnlyHint` and `destructiveHint`, and `deleteRecords` is marked destructive",
            "status.nocodb.com lists no incident from July to October 2026 and shows 99.9907 per cent for the application over 90 days"
          ],
          "weaknesses": [
            "5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429",
            "REST create, update and upsert calls take 10 records each by default",
            "The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan",
            "The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved",
            "No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry"
          ],
          "agentNotes": [
            "Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token",
            "Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds",
            "Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records",
            "Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or`",
            "Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 75.7
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 87,
            "payments": 30,
            "reliability": 97,
            "schema": 85,
            "security": 71,
            "transparency": 66
          },
          "provenanceScore": 86
        },
        "connect": {
          "install": "docker run -d \\\n  --name noco \\\n  -v \"$(pwd)\"/nocodb:/usr/app/data/ \\\n  -p 8080:8080 \\\n  nocodb/nocodb:latest",
          "http": "curl -H \"xc-token: nc_pat_...\" https://your-nocodb.com/api/v3/...",
          "config": {
            "mcpServers": {
              "NocoDB MCP": {
                "args": [
                  "mcp-remote",
                  "https://your-domain.com/mcp/\u003cncId\u003e",
                  "--header",
                  "x-api-key: \u003cncToken\u003e"
                ],
                "command": "npx"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.records",
          "tool": "https://letme.dev/nocodb"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Plus",
            "unit": "seat-month",
            "usd": 12,
            "note": "billed annually, at most 9 paid seats ($108 a month), 100,000 API calls a month"
          },
          {
            "item": "Business",
            "unit": "seat-month",
            "usd": 24,
            "note": "billed annually, at most 9 paid seats ($216 a month), 1,000,000 API calls a month"
          },
          {
            "item": "Scale",
            "unit": "seat-month",
            "usd": 45,
            "note": "billed annually, 3 seats minimum, 5,000,000 API calls a month"
          }
        ],
        "provenance": {
          "legalEntity": "NocoDB Inc (doing business as NocoDB)",
          "domain": "nocodb.com",
          "domainRegistered": "2021-04-14",
          "endpointOnVendorDomain": true,
          "terms": "https://nocodb.com/docs/legal/terms-of-service",
          "privacy": "https://nocodb.com/docs/legal/privacy",
          "statusPage": "https://status.nocodb.com",
          "changelog": "https://nocodb.com/docs/changelog",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The Terms of Service (last updated 14 October 2025) and the privacy policy (last updated 5 August 2025) name NocoDB Inc, doing business as NocoDB, and cover the website, the hosted services and the APIs. No postal address was found in the parts we read.",
            "The REST API and the MCP server answer at app.nocodb.com, a nocodb.com subdomain. A self-hosted instance answers on the owner's own domain.",
            "nocodb.com/.well-known/security.txt, nocodb.com/security.txt and app.nocodb.com/.well-known/security.txt return 404. SECURITY.md in the repository sends reports to security@nocodb.com.",
            "RDAP for nocodb.com gives a registration date of 2021-04-14.",
            "Organisations on an order form are governed by the Master Subscription Agreement (last updated 14 October 2025), which states SOC 2 Type II compliance with the report on request. The Service Level Agreement (last updated 6 October 2025) commits to 99.9 per cent monthly uptime for Enterprise plans."
          ],
          "score": 86
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/nocodb.json",
        "live": {
          "slug": "nocodb",
          "probe": {
            "target": "https://app.nocodb.com",
            "method": "get",
            "lastAt": "2026-10-08T17:36:41.111085446Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 302,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 298,
            "p95ms24h": 302,
            "samples24h": 2,
            "samples30d": 2,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 2,
                "ok": 2
              }
            ]
          },
          "updatedAt": "2026-10-08T17:36:41.111085446Z"
        }
      },
      {
        "slug": "airtable",
        "name": "Airtable",
        "vendor": "Formagrid Inc (Airtable)",
        "vendorUrl": "https://www.airtable.com",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "Airtable is a hosted database of typed records organised in bases, tables and views. Agents reach it through a REST Web API and an official hosted MCP server, using personal access tokens or OAuth.",
        "url": "https://www.anchorterminal.com/tools/airtable",
        "markdownUrl": "https://www.anchorterminal.com/tools/airtable.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/airtable.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/airtable.json",
        "repo": "https://github.com/Airtable/airtable-mcp-cli",
        "license": "Proprietary service under Airtable's Terms of Service and Developer Terms. The airtable.js client and the MCP CLI on GitHub are MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.airtable.com",
        "packages": [
          {
            "registry": "npm",
            "name": "airtable"
          },
          {
            "registry": "npm",
            "name": "@airtable/mcp-cli"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. A signed-in user creates a personal access token at airtable.com/create/tokens, choosing scopes and the bases or workspaces it can reach, or registers an OAuth integration at airtable.com/create/oauth with no review step found in the docs. OAuth uses the authorisation code grant with PKCE, 60-minute access tokens and 60-day refresh tokens that rotate on use. The MCP server takes either, and supports dynamic client registration. Tokens act as the granting user, so the user's role on a base still applies. Enterprise admin scopes and service accounts need an Enterprise Scale plan.",
        "pricing": "freemium",
        "pricingNotes": "Free plan with 1,000 API calls a month per workspace and 1,000 records per base, so an agent can start without a contract. Team is $20 a seat a month billed annually ($24 monthly) with 100,000 calls a month, Business $45 billed annually, Enterprise Scale through sales. API calls aren't priced separately, and there's no separate sandbox. The MCP server is included on every plan (checked 2026-10-08).",
        "priceSummary": "$20 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Web API docs, the MCP docs or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 40,
        "popularity": {
          "githubStars": 2229,
          "npmWeekly": 568991,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://airtable.com/developers/web/api/introduction",
        "llmsTxt": "https://airtable.com/developers/llms.txt",
        "registryName": "com.airtable/mcp",
        "capabilities": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "tags": [
          "official",
          "hosted",
          "mcp",
          "closed-source",
          "free-tier",
          "oauth",
          "llms-txt",
          "webhooks",
          "javascript",
          "status-page",
          "bug-bounty",
          "soc2"
        ],
        "lastRelease": "2026-08-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 70.9,
          "grade": "BB",
          "agentReady": true,
          "rank": 118,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 3,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 68,
            "maintenance": 49,
            "payments": 30,
            "reliability": 94,
            "schema": 73,
            "security": 78,
            "transparency": 86
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "Tokens are limited by scope and by base, and the official MCP server at mcp.airtable.com covers records, schema, interfaces and automations in 40 tools. The REST API allows 5 requests a second per base with a 30-second lockout after a 429, writes take 10 records a call, and the Free plan stops at 1,000 calls a month.",
          "bestFor": "Teams that already keep operational data in Airtable and want an agent to read, filter and update typed records or build bases through MCP.",
          "strengths": [
            "Personal access tokens and OAuth grants are limited by scope and by base or workspace, and the legacy `api_key` URL parameter is refused",
            "Official hosted MCP server at https://mcp.airtable.com/mcp, open to every plan and listed in the MCP registry as com.airtable/mcp",
            "Markdown copy of every API reference page, indexed by llms.txt files under airtable.com/developers",
            "List records takes `fields`, `pageSize`, `maxRecords`, `view`, `sort` and `filterByFormula`, so responses can be sized",
            "Published deprecation guidelines aim for 12 months' notice on the Web API, and no deprecation was listed as upcoming on 8 October 2026"
          ],
          "weaknesses": [
            "5 requests a second per base, and a 429 blocks further requests for 30 seconds",
            "Create, update and delete calls take at most 10 records each",
            "Free plan allows 1,000 API calls a month per workspace and 1,000 records per base",
            "No OpenAPI description was found in the reviewed documentation",
            "The only official client library is airtable.js, last released as v0.12.2 on 16 August 2023"
          ],
          "agentNotes": [
            "Create a personal access token with only the scopes needed and add each base to it. A token with no base added sees nothing",
            "Stay under 5 requests a second per base. After a 429, wait 30 seconds before the next call",
            "Send writes in batches of 10 records, and use `performUpsert` with `fieldsToMergeOn` so a repeated call updates instead of duplicating",
            "Use table and field IDs, not names, and set `returnFieldsByFieldId` so a rename doesn't break the call",
            "POST to `/listRecords` when a `filterByFormula` would push the URL past 16,000 characters"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 70.9
            }
          ],
          "editorialScores": {
            "ergonomics": 68,
            "maintenance": 49,
            "payments": 30,
            "reliability": 94,
            "schema": 73,
            "security": 78,
            "transparency": 72
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm install -g @airtable/mcp-cli",
          "http": "curl https://api.airtable.com/v0/YOUR_BASE_ID/YOUR_TABLE_ID_OR_NAME -H \\\n\"Authorization: Bearer YOUR_TOKEN\"",
          "claudeCode": "claude mcp add --transport http airtable https://mcp.airtable.com/mcp",
          "config": {
            "mcpServers": {
              "airtable": {
                "type": "http",
                "url": "https://mcp.airtable.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.records",
          "tool": "https://letme.dev/airtable"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Team",
            "unit": "seat-month",
            "usd": 20,
            "note": "billed annually, $24 billed monthly, 100,000 API calls a month per workspace"
          },
          {
            "item": "Business",
            "unit": "seat-month",
            "usd": 45,
            "note": "billed annually"
          }
        ],
        "provenance": {
          "legalEntity": "Formagrid Inc (doing business as Airtable)",
          "domain": "airtable.com",
          "domainRegistered": "2003-12-10",
          "endpointOnVendorDomain": true,
          "terms": "https://www.airtable.com/company/tos",
          "privacy": "https://www.airtable.com/company/privacy",
          "statusPage": "https://status.airtable.com",
          "changelog": "https://airtable.com/developers/web/api/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The Terms of Service (last updated 31 May 2024) and the privacy policy (last updated 15 July 2026) name Formagrid Inc, doing business as Airtable, with a postal address at 1 Front Street, Fl 28, San Francisco, CA 94111.",
            "The REST API answers at api.airtable.com and the MCP server at mcp.airtable.com, both airtable.com subdomains.",
            "airtable.com/.well-known/security.txt gives security@airtable.com and the HackerOne programme and has no Expires field. www.airtable.com/.well-known/security.txt returns 404.",
            "RDAP for airtable.com gives a registration date of 2003-12-10.",
            "The Service Level Agreement (last updated 26 March 2024) commits to 99.9 per cent monthly uptime for Enterprise plans."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/airtable.json",
        "live": {
          "slug": "airtable",
          "probe": {
            "target": "https://api.airtable.com",
            "method": "get",
            "lastAt": "2026-10-08T17:36:29.354996508Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 817,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 807,
            "p95ms24h": 910,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.airtable.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:37:07.01310139Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "Airtable/airtable-mcp-cli",
              "version": "v0.2.9",
              "released": "2026-08-07",
              "seenAt": "2026-10-08T15:57:17.360180778Z"
            },
            {
              "registry": "npm",
              "name": "@airtable/mcp-cli",
              "version": "0.2.9",
              "seenAt": "2026-10-08T15:57:17.136543533Z"
            },
            {
              "registry": "npm",
              "name": "airtable",
              "version": "0.12.2",
              "seenAt": "2026-10-08T15:57:14.88836809Z"
            }
          ],
          "githubStars": 39,
          "npmWeekly": 568991,
          "securityTxt": {
            "url": "https://airtable.com/.well-known/security.txt",
            "state": "valid",
            "checkedAt": "2026-10-08T15:38:43.521220209Z"
          },
          "updatedAt": "2026-10-08T17:37:07.01310139Z"
        }
      },
      {
        "slug": "smartsheet",
        "name": "Smartsheet API + MCP",
        "vendor": "Smartsheet Inc.",
        "vendorUrl": "https://www.smartsheet.com",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "Smartsheet is a hosted work management product built on sheets with typed columns, rows, formulas, reports and dashboards. Agents reach it through a REST API (187 operations) and a hosted MCP server, both limited to Business plans and above.",
        "url": "https://www.anchorterminal.com/tools/smartsheet",
        "markdownUrl": "https://www.anchorterminal.com/tools/smartsheet.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/smartsheet.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smartsheet.json",
        "repo": "https://github.com/smartsheet/smartsheet-python-sdk",
        "license": "Proprietary service under Smartsheet's User Agreement and Developer Agreement. The SDKs on GitHub are Apache-2.0",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.smartsheet.com/2.0",
        "packages": [
          {
            "registry": "pypi",
            "name": "smartsheet-python-sdk"
          },
          {
            "registry": "npm",
            "name": "smartsheet"
          }
        ],
        "auth": "mixed",
        "authNotes": "Access needs a licensed user on a Business plan or higher. A user makes a raw API token in Personal Settings and sends it as a Bearer token. It has no scopes and carries all of that user's access. Apps acting for other users register in Developer Tools (Smartsheet approves the registration request) and use the OAuth 2.0 authorisation code grant with any of 17 scopes such as READ_SHEETS and WRITE_SHEETS. Access tokens last about 7 days and refresh. Scopes can't exceed the user's sharing level on a sheet. The MCP server takes OAuth from ChatGPT, Claude, Gemini Enterprise Plus and Microsoft 365 Copilot, and a Bearer API token from other clients. A System Admin's token can act as any user through the `Assume-User` header.",
        "pricing": "paid",
        "pricingNotes": "API and MCP access start at the Business plan, $24 a member a month billed monthly or $19 billed yearly, with a minimum of three members. Pro ($12, or $9 yearly) has no API calls. Enterprise and Advanced Work Management are priced through sales. API calls carry no separate charge. A 30-day trial needs no card, but we couldn't confirm that a trial account can make API tokens. No developer sandbox was found in the reviewed documentation (https://www.smartsheet.com/pricing, checked 2026-10-08).",
        "priceSummary": "$19 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 83,
        "popularity": {
          "githubStars": 82,
          "npmWeekly": 47484,
          "pypiWeekly": 311787,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developers.smartsheet.com",
        "llmsTxt": "https://developers.smartsheet.com/llms.txt",
        "openapi": "https://developers.smartsheet.com/_bundle/api/smartsheet/openapi.yaml",
        "capabilities": [
          "sheets.read",
          "sheets.write",
          "sheets.records",
          "sheets.formulas",
          "automation.workflows"
        ],
        "tags": [
          "official",
          "hosted",
          "closed-source",
          "mcp",
          "oauth",
          "openapi",
          "llms-txt",
          "webhooks",
          "python",
          "typescript",
          "java",
          "csharp",
          "status-page",
          "soc2",
          "sla"
        ],
        "lastRelease": "2026-10-06",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 67.6,
          "grade": "B",
          "agentReady": false,
          "rank": 190,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 4,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 80,
            "payments": 20,
            "reliability": 65,
            "schema": 88,
            "security": 66,
            "transparency": 82
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "The REST API has a public OpenAPI 3.0.3 spec with 187 operations, Markdown docs and llms.txt, and the hosted MCP server loads its 83 documented tools by toolset. API access needs a Business plan or higher, and the status page lists eight incidents marked major or critical between 15 July and 21 September 2026.",
          "bestFor": "An agent working inside a company that already runs projects in Smartsheet on a Business plan or above, especially row-level reads and batched writes, workflows and dashboards.",
          "strengths": [
            "Public OpenAPI 3.0.3 spec with 187 operations, code samples on 180 of them, plus llms.txt and a Markdown copy of every docs page",
            "Hosted MCP server in three regions (US, EU, Australia) with toolsets, so a client loads tools by domain through `search_tools`",
            "OAuth 2.0 with 17 scopes, including READ_SHEETS for a read-only grant, and sheet sharing levels that scopes can't override",
            "Bulk row writes of up to 500 rows a call with optional partial success and per-row failure details",
            "Dated API changelog (latest 6 October 2026) with DEPRECATION and SUNSET entries and migration guides"
          ],
          "weaknesses": [
            "API and MCP access need a Business plan or higher, from $19 a member a month billed yearly with a three-member minimum",
            "Eight status incidents marked major or critical between 15 July and 21 September 2026, four of them stopping sheets from loading in the US region",
            "A raw API token carries all of its user's access with no scopes, and it's the credential the docs give for Claude Code, Cursor, Codex and Gemini CLI",
            "No idempotency keys, and 429 responses carry no documented Retry-After header",
            "security.txt expired on 1 July 2026, and no prompt-injection guidance was found in the MCP docs"
          ],
          "agentNotes": [
            "Send writes to one sheet one at a time. Parallel updates with the same token return error 4004",
            "Batch row changes, up to 500 rows a call, and add `allowPartialSuccess=true` to get per-row failures instead of a failed batch",
            "On error 4003 (HTTP 429) wait at least 60 seconds before retrying. The limit is 300 requests a minute per token, 30 for attachments and cell history",
            "Through MCP, call `get_columns` before filtering or writing. Column names are case-sensitive and guesses fail validation",
            "Use the regional host that matches the account (api.smartsheet.com, .eu or .au). Tokens don't work across regions"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 67.6
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 80,
            "payments": 20,
            "reliability": 65,
            "schema": 88,
            "security": 66,
            "transparency": 72
          },
          "provenanceScore": 92
        },
        "connect": {
          "install": "pip install smartsheet-python-sdk",
          "http": "curl \"https://api.smartsheet.com/2.0/workspaces?maxItems=100\" \\\n  -H \"Authorization: Bearer $SMARTSHEET_API_TOKEN\"",
          "claudeCode": "claude mcp add --transport http smartsheet-mcp https://mcp.smartsheet.com -H \"Authorization:Bearer ${SMARTSHEET_API_TOKEN}\"",
          "config": {
            "mcpServers": {
              "smartsheet-mcp": {
                "headers": {
                  "Authorization": "Bearer ${SMARTSHEET_API_TOKEN}"
                },
                "httpUrl": "https://mcp.smartsheet.com"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.read",
          "tool": "https://letme.dev/smartsheet"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Business plan (lowest plan with API and MCP access)",
            "unit": "seat-month",
            "usd": 19,
            "note": "billed yearly, $24 monthly, 3 members minimum"
          },
          {
            "item": "Pro plan (no API calls)",
            "unit": "seat-month",
            "usd": 9,
            "note": "billed yearly, $12 monthly, up to 10 members"
          }
        ],
        "provenance": {
          "legalEntity": "Smartsheet Inc.",
          "domain": "smartsheet.com",
          "domainRegistered": "2001-04-15",
          "endpointOnVendorDomain": true,
          "terms": "https://www.smartsheet.com/legal/developer-program-agreement",
          "privacy": "https://www.smartsheet.com/legal/privacy",
          "statusPage": "https://status.smartsheet.com",
          "changelog": "https://developers.smartsheet.com/api/smartsheet/changelog",
          "securityTxt": "expired",
          "checked": "2026-10-08",
          "notes": [
            "The User Agreement (last updated 3 April 2026) and the privacy notice (20 May 2026) give Smartsheet Inc., 500 108th Ave NE, Suite 200, Bellevue, WA 98004.",
            "The Developer Agreement governing the API and SDKs was last updated 1 July 2021. Revisions take effect 15 days after posting.",
            "www.smartsheet.com/.well-known/security.txt names security@smartsheet.com and the bug bounty page, with Expires 2026-07-01, three months before this check.",
            "The API answers at api.smartsheet.com and the MCP server at mcp.smartsheet.com, with regional hosts on smartsheet.eu and smartsheet.au.",
            "RDAP for smartsheet.com gives a registration date of 2001-04-15."
          ],
          "score": 92
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/smartsheet.json",
        "live": {
          "slug": "smartsheet",
          "probe": {
            "target": "https://api.smartsheet.com/2.0",
            "method": "get",
            "lastAt": "2026-10-08T17:36:45.675177967Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 410,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 413,
            "p95ms24h": 453,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.smartsheet.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:25:48.658239085Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "smartsheet/smartsheet-python-sdk",
              "version": "v4.4.0",
              "released": "2026-08-12",
              "seenAt": "2026-10-08T16:29:43.071236352Z"
            },
            {
              "registry": "npm",
              "name": "smartsheet",
              "version": "5.3.0",
              "seenAt": "2026-10-08T16:29:42.658666425Z"
            },
            {
              "registry": "pypi",
              "name": "smartsheet-python-sdk",
              "version": "4.4.0",
              "released": "2026-08-12",
              "seenAt": "2026-10-08T16:29:42.474478981Z"
            }
          ],
          "githubStars": 82,
          "npmWeekly": 47484,
          "pypiWeekly": 311787,
          "securityTxt": {
            "url": "https://smartsheet.com/.well-known/security.txt",
            "state": "expired",
            "expires": "2026-07-01T04:00:00.000Z",
            "checkedAt": "2026-10-08T15:38:51.088332618Z"
          },
          "updatedAt": "2026-10-08T17:36:45.675177967Z"
        }
      },
      {
        "slug": "coda",
        "name": "Coda (Superhuman Docs)",
        "vendor": "Superhuman Platform Inc.",
        "vendorUrl": "https://coda.io",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta.",
        "url": "https://www.anchorterminal.com/tools/coda",
        "markdownUrl": "https://www.anchorterminal.com/tools/coda.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/coda.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/coda.json",
        "repo": "https://github.com/coda/packs-sdk",
        "license": "Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://coda.io/apis/v1",
        "packages": [
          {
            "registry": "npm",
            "name": "@codahq/packs-sdk"
          }
        ],
        "auth": "mixed",
        "authNotes": "REST API takes `Authorization: Bearer \u003capi_token\u003e`, a token a signed-in user creates under account settings. A token can do everything its owner can unless it is created with restrictions, which limit it to one doc or one table and to read, write or both. The MCP server at https://coda.io/apis/mcp takes OAuth (authorisation code grant with PKCE S256, dynamic client registration, one scope `mcp:all`) or an API token created with the MCP restriction, per a staff reply on the vendor's community forum. Access is self-serve with no app review.",
        "pricing": "freemium",
        "pricingNotes": "The API is free on free and paid workspaces, so an agent can start on the Free plan without a contract. Suite prices as shown to our UK request on 8 October 2026 were Free £0, Pro £10 a member a month billed yearly (£12 monthly), Business £28 (£33 monthly) and Enterprise by quote (https://superhuman.com/plans). MCP is included on paid plans, and Free accounts get read-only MCP access capped at 30 requests a week and 60 a month. US dollar prices and the Docs-only plan table were not readable.",
        "priceSummary": "Freemium",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI description or the plans page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 34,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 10270,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://coda.io/developers/apis/v1",
        "openapi": "https://coda.io/apis/v1/openapi.json",
        "capabilities": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.records",
          "sheets.formulas",
          "work.docs"
        ],
        "tags": [
          "official",
          "hosted",
          "closed-source",
          "freemium",
          "free-tier",
          "api-key",
          "oauth",
          "mcp",
          "openapi",
          "status-page",
          "bug-bounty",
          "soc2",
          "iso27001"
        ],
        "lastRelease": "2026-09-24",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 64.8,
          "grade": "B",
          "agentReady": false,
          "rank": 247,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 5,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 61,
            "maintenance": 72,
            "payments": 30,
            "reliability": 81,
            "schema": 76,
            "security": 71,
            "transparency": 78
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -3,
          "negativeNotes": [
            "24 September 2026 (date approximate per the vendor). The MCP changelog records chart `viewLayout` values renamed so the old ones are no longer valid, and `table_columns_manage` restructured, both marked as documented after shipping. The MCP server is in beta and its tools page warns that names can change, so the deduction is the minimum, 3 (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3)."
          ],
          "verdict": "API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.",
          "bestFor": "Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.",
          "strengths": [
            "API tokens can be restricted to one doc or one table, and to read or write access",
            "Public OpenAPI 3.0 description in JSON and YAML, 125 operations, all with descriptions and 429 documented on 124",
            "Rate limits are published with numbers, 100 reads and 10 writes per 6 seconds per user",
            "Hosted MCP server with 34 tools, OAuth with PKCE and dynamic client registration, and a dated changelog",
            "Public bug bounty on HackerOne, ISO 27001, 27017 and 27018 certificates, SOC 2 Type 2 and a SOC 3 report"
          ],
          "weaknesses": [
            "Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale",
            "No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message",
            "No official client libraries apart from a Google Apps Script library",
            "The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped",
            "MCP OAuth has one scope, `mcp:all`, and no confirmation step was found for `document_delete` or `table_delete`",
            "security.txt on coda.io expired on 31 December 2024"
          ],
          "agentNotes": [
            "Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail",
            "Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind",
            "Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate",
            "Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can",
            "Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 64.8
            }
          ],
          "editorialScores": {
            "ergonomics": 61,
            "maintenance": 72,
            "payments": 30,
            "reliability": 81,
            "schema": 76,
            "security": 71,
            "transparency": 65
          },
          "provenanceScore": 90
        },
        "connect": {
          "http": "curl -s -H \"Authorization: Bearer $CODA_API_TOKEN\" \"https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25\u0026valueFormat=simpleWithArrays\"",
          "config": {
            "mcpServers": {
              "coda": {
                "url": "https://coda.io/apis/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.read",
          "tool": "https://letme.dev/coda"
        },
        "area": "business",
        "provenance": {
          "legalEntity": "Superhuman Platform Inc. (parent of Coda Project LLC)",
          "domain": "coda.io",
          "domainRegistered": "2012-05-22",
          "endpointOnVendorDomain": true,
          "terms": "https://superhuman.com/legal/terms",
          "privacy": "https://superhuman.com/legal/privacy-policy",
          "statusPage": "https://status.coda.io",
          "changelog": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
          "securityTxt": "expired",
          "checked": "2026-10-08",
          "notes": [
            "The terms of service (effective 29 October 2025) are an agreement with Superhuman Platform Inc., 2261 Market Street STE 85232, San Francisco, CA 94114, and call it the parent company of Coda Project LLC and Superhuman Labs LLC.",
            "The privacy policy (effective 6 July 2026) describes Superhuman Platform Inc. as formerly Grammarly, with Grammarly Inc. and Coda Project LLC as subsidiaries.",
            "coda.io/trust/tos, /trust/privacy, /trust/dpa and /trust/subprocessor redirect to superhuman.com/legal. coda.io/developers/apis/v1 redirects to docs.superhuman.com.",
            "The API and the MCP server answer on coda.io and on docs.superhuman.com. The OAuth metadata names https://coda.io as issuer.",
            "coda.io/.well-known/security.txt points to the HackerOne programme and carries Expires 2024-12-31. superhuman.com/.well-known/security.txt returns 404.",
            "The registry's RDAP record for coda.io gives a registration date of 2012-05-22 and Gandi SAS as registrar.",
            "The changelog link is the MCP server's. The REST API's update log at docs.superhuman.com/api-updates needs JavaScript and was not read."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/coda.json",
        "live": {
          "slug": "coda",
          "probe": {
            "target": "https://coda.io/apis/v1",
            "method": "get",
            "lastAt": "2026-10-08T17:36:33.302473956Z",
            "lastOk": true,
            "lastStatus": 401,
            "lastMs": 173,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 186,
            "p95ms24h": 229,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.coda.io",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:38:24.133244937Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "coda/packs-sdk",
              "version": "v1.18.0",
              "released": "2026-10-07",
              "seenAt": "2026-10-08T16:06:05.16888764Z"
            },
            {
              "registry": "npm",
              "name": "@codahq/packs-sdk",
              "version": "1.18.0",
              "seenAt": "2026-10-08T16:06:01.042367623Z"
            }
          ],
          "githubStars": 112,
          "npmWeekly": 10270,
          "securityTxt": {
            "url": "https://coda.io/.well-known/security.txt",
            "state": "expired",
            "expires": "2024-12-31T20:00:00.000Z",
            "checkedAt": "2026-10-08T15:38:55.777108046Z"
          },
          "updatedAt": "2026-10-08T17:38:24.133244937Z"
        }
      },
      {
        "slug": "baserow",
        "name": "Baserow",
        "vendor": "Baserow B.V.",
        "vendorUrl": "https://baserow.io",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "Baserow is an open-source database of typed rows in tables, sold as a hosted cloud and as software to self-host. Agents reach it through a REST API with database tokens and a built-in MCP server.",
        "url": "https://www.anchorterminal.com/tools/baserow",
        "markdownUrl": "https://www.anchorterminal.com/tools/baserow.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/baserow.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/baserow.json",
        "repo": "https://github.com/baserow/baserow",
        "license": "MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0",
        "transports": [
          "http",
          "sse"
        ],
        "remoteUrl": "https://api.baserow.io",
        "packages": [],
        "auth": "api-key",
        "authNotes": "Self-serve. A signed-in user creates a database token in the workspace settings, choosing the tables it can reach and whether it may create, read, update or delete rows. Tokens don't expire and can be regenerated or deleted. They cover rows only, so changing tables or fields needs a JWT from `/api/user/token-auth/` with the account's email and password, which carries the user's full access. The MCP server has no token header or OAuth. Each endpoint is a URL holding a 32-character key that carries the creating user's access across one workspace, and deleting the endpoint revokes it. On Enterprise licences only workspace admins and builders can create database tokens.",
        "pricing": "freemium",
        "pricingNotes": "Free cloud plan with 3,000 rows and 2 GB of storage per workspace, so an agent can start without a contract. Premium is $10 a user a month billed yearly ($12 monthly) and Advanced $18 ($22 monthly), Enterprise through sales. API calls aren't priced, the MCP server is on every plan, and there's no separate sandbox. The self-hosted core is free with no row or request limits (checked 2026-10-08).",
        "priceSummary": "$10 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI description, the MCP docs or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 7,
        "popularity": {
          "githubStars": 6098,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://baserow.io/user-docs/database-api",
        "llmsTxt": "https://baserow.io/llms.txt",
        "openapi": "https://api.baserow.io/api/schema.json",
        "capabilities": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "tags": [
          "official",
          "hosted",
          "self-hosted",
          "open-source",
          "mcp",
          "free-tier",
          "api-key",
          "openapi",
          "llms-txt",
          "webhooks",
          "status-page",
          "soc2"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 63.6,
          "grade": "B",
          "agentReady": false,
          "rank": 276,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 6,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 72,
            "maintenance": 72,
            "payments": 40,
            "reliability": 65,
            "schema": 77,
            "security": 54,
            "transparency": 65
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "Database tokens are limited to chosen tables and to create, read, update or delete, and the REST API has a public OpenAPI description with batch calls of 200 rows. The MCP server authenticates with a key in its URL, runs over SSE only and has no read-only mode. Cloud requests are capped at 10 at a time.",
          "bestFor": "Teams that want Airtable-style typed tables they can also self-host, with row-level reads and writes by an agent through table-scoped tokens or a small MCP tool set.",
          "strengths": [
            "Database tokens are limited to one workspace, to chosen tables and to create, read, update or delete, and can be regenerated or deleted",
            "Public OpenAPI 3.0.3 description at api.baserow.io/api/schema.json with 424 operations and an enum of error codes on each response",
            "The MCP server exposes 7 tools with typed inputs, and its descriptions tell the caller to read the table schema before writing",
            "List rows takes `include`, `exclude`, `size`, `filters`, `search`, `order_by` and `view_id`, so responses can be sized",
            "The core, including the REST API and the MCP server, is MIT-licensed and can be self-hosted with no row or request limits"
          ],
          "weaknesses": [
            "The MCP endpoint's key sits in the URL path, and the docs say it grants full access to modify data in the workspace",
            "The MCP server speaks only the older SSE transport, with no OAuth, no read-only mode and no tool annotations",
            "Table and field changes over REST need a JWT obtained with the account's email and password, since database tokens cover rows only",
            "No SLA, security.txt, sub-processor list or published DPA text was found, and the privacy policy carries no date or retention periods",
            "No official client library was found, and Baserow isn't in the official MCP registry under its own namespace"
          ],
          "agentNotes": [
            "Create a database token with only the tables and operations needed. It can't change tables or fields, which need a JWT from `/api/user/token-auth/`",
            "Send `Authorization: Token YOUR_DATABASE_TOKEN`, and add `user_field_names=true` or rows come back keyed as `field_123`",
            "Use the `/batch/` endpoints for up to 200 rows a call, and keep to 10 requests in flight on Baserow Cloud",
            "Treat the MCP URL as a password. Keep it out of logs and version control, and delete the endpoint to revoke it",
            "Over MCP, call `get_table_schema` before `create_rows` or `update_rows`, and page `list_table_rows` with `page` and `size`"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 63.6
            }
          ],
          "editorialScores": {
            "ergonomics": 72,
            "maintenance": 72,
            "payments": 40,
            "reliability": 65,
            "schema": 77,
            "security": 54,
            "transparency": 49
          },
          "provenanceScore": 80
        },
        "connect": {
          "http": "curl \\\n-X GET \\\n-H \"Authorization: Token YOUR_DATABASE_TOKEN\" \\\n\"https://api.baserow.io/api/database/fields/table/TABLE_ID/\"",
          "config": {
            "mcpServers": {
              "Baserow MCP": {
                "url": "YOUR_MCP_URL_HERE"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sheets.records",
          "tool": "https://letme.dev/baserow"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Premium (cloud)",
            "unit": "seat-month",
            "usd": 10,
            "note": "billed yearly, $12 billed monthly, 50,000 rows per workspace"
          },
          {
            "item": "Advanced (cloud)",
            "unit": "seat-month",
            "usd": 18,
            "note": "billed yearly, $22 billed monthly, 250,000 rows per workspace"
          }
        ],
        "provenance": {
          "legalEntity": "Baserow B.V.",
          "domain": "baserow.io",
          "domainRegistered": "2019-01-19",
          "endpointOnVendorDomain": true,
          "terms": "https://baserow.io/terms-and-conditions",
          "privacy": "https://baserow.io/privacy-policy",
          "statusPage": "https://status.baserow.org",
          "changelog": "https://github.com/baserow/baserow/blob/develop/changelog.md",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The General Terms and Conditions name Baserow B.V., a Dutch private company with its registered office at Keurenplein 4, Amsterdam, trade register number 81129254. The page carries no date.",
            "The privacy policy is the only one found. It is written for visitors to baserow.io, mentions account registration, carries no date and names no retention periods. The terms incorporate a Data Processing Agreement by reference, and no public copy was found.",
            "The REST API and the MCP server answer at api.baserow.io, a baserow.io subdomain. The status page is on a separate domain, status.baserow.org, hosted by Better Stack.",
            "baserow.io/.well-known/security.txt and api.baserow.io/.well-known/security.txt return 404. SECURITY.md in the repository gives an email address for vulnerability reports.",
            "RDAP for baserow.io gives a registration date of 2019-01-19."
          ],
          "score": 80
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/baserow.json",
        "live": {
          "slug": "baserow",
          "probe": {
            "target": "https://api.baserow.io",
            "method": "get",
            "lastAt": "2026-10-08T17:36:31.178894752Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 92,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 91,
            "p95ms24h": 92,
            "samples24h": 2,
            "samples30d": 2,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 2,
                "ok": 2
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.baserow.org",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T17:37:55.152885918Z"
          },
          "updatedAt": "2026-10-08T17:37:55.152885918Z"
        }
      },
      {
        "slug": "microsoft-excel-graph",
        "name": "Microsoft Excel (Microsoft Graph workbook API)",
        "vendor": "Microsoft",
        "vendorUrl": "https://learn.microsoft.com/en-us/graph/excel-concept-overview",
        "kind": "http-api",
        "category": "spreadsheets",
        "summary": "Workbook endpoints of Microsoft Graph for Excel files stored in OneDrive for work or school and SharePoint. Calls read and write ranges, tables, charts and named items, and run Excel worksheet functions on a file in place.",
        "url": "https://www.anchorterminal.com/tools/microsoft-excel-graph",
        "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json",
        "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
        "license": "MIT (SDKs)",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://graph.microsoft.com/v1.0",
        "packages": [
          {
            "registry": "npm",
            "name": "@microsoft/microsoft-graph-client"
          },
          {
            "registry": "pypi",
            "name": "msgraph-sdk"
          }
        ],
        "auth": "oauth",
        "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. The workbook reference pages list delegated permissions only, with Files.ReadWrite as least privileged, and mark application permissions as not supported. The overview page names Files.Read for read actions. A delegated token reaches every file its user can open.",
        "pricing": "byo-plan",
        "pricingNotes": "Workbook calls carry no per-call charge. Microsoft's list of metered Graph APIs names only SharePoint and OneDrive `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Files must sit in OneDrive for work or school or SharePoint, which need a Microsoft 365 licence. The Microsoft 365 plan price page refused our reader on 2026-10-08. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and members of named partner programmes (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
        "priceSummary": "Your plan",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the workbook documentation or the metered API list (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 835,
          "npmWeekly": 2882852,
          "pypiWeekly": 1578201,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/excel",
        "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
        "capabilities": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "tags": [
          "hosted",
          "official",
          "oauth",
          "openapi",
          "typescript",
          "python",
          "enterprise"
        ],
        "lastRelease": "2025-09-19",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 58.5,
          "grade": "C",
          "agentReady": false,
          "rank": 399,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 7,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 73,
            "maintenance": 53,
            "payments": 15,
            "reliability": 62,
            "schema": 85,
            "security": 65,
            "transparency": 75
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -4,
          "negativeNotes": [
            "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 8 October 2026 and the repository lists no published advisory. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the workbook API through that client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
          ],
          "verdict": "Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.",
          "bestFor": "Agents working on .xlsx files that already live in a Microsoft 365 tenant, and for using Excel's calculation engine through function endpoints.",
          "strengths": [
            "Non-persistent sessions (`persistChanges: false`) keep changes in a temporary copy, so an agent can calculate or test edits without saving",
            "The OpenAPI for Graph v1.0 holds 1,442 workbook paths and 1,765 operations, 366 of the paths for worksheet functions",
            "Error handling guide gives a retry instruction for each of 22 required second-level error codes",
            "Throttling limits are published at 5,000 requests per 10 seconds per app and 1,500 per app per tenant, with `Retry-After` on throttled responses",
            "Microsoft's policy is at least 24 months' notice before a generally available Graph API is removed"
          ],
          "weaknesses": [
            "Reference pages list delegated permissions only and mark application permissions as not supported",
            "Files.ReadWrite is the least privileged permission on the reference pages, even for reading a range or listing rows",
            "No idempotency key on writes. The row-add page says to repeat the request on a 504",
            "Cell values, formulas and number formats are untyped JSON in the OpenAPI",
            "The last Workbooks and charts changelog entry is dated 19 September 2025, and the overview page is dated March 2024"
          ],
          "agentNotes": [
            "Create a session with POST /workbook/createSession and send `workbook-session-id` on every call. Persistent sessions expire after about 5 minutes idle",
            "Set `persistChanges` to false when you only need a calculation or a chart image, so nothing is saved to the file",
            "Send one request at a time per workbook and wait for each response. Microsoft warns that parallel writes cause throttling, timeouts and merge conflicts",
            "Add rows in one call with a two-dimensional `values` array, and check the table before repeating a row add that returned 504",
            "Read bounded addresses such as A1:D500. A whole-column range such as C:C returns null for values, and writes to it are refused"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 58.5
            }
          ],
          "editorialScores": {
            "ergonomics": 73,
            "maintenance": 53,
            "payments": 15,
            "reliability": 62,
            "schema": 85,
            "security": 65,
            "transparency": 65
          },
          "provenanceScore": 85
        },
        "connect": {
          "http": "curl https://graph.microsoft.com/v1.0/me/drive/items/{id}/workbook/worksheets \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\" \\\n  -H \"workbook-session-id: $SESSION_ID\""
        },
        "letme": {
          "capability": "https://letme.dev/sheets.read",
          "tool": "https://letme.dev/microsoft-excel-graph"
        },
        "sameCompany": [
          "azure-foundry-fine-tuning",
          "azure-ai-content-safety",
          "azure-speech-to-text",
          "azure-text-to-speech",
          "microsoft-agent-framework",
          "microsoft-execution-containers",
          "microsoft-entra-agent-id",
          "azure-key-vault",
          "azure-devops-mcp",
          "microsoft-learn-mcp",
          "playwright-mcp",
          "azure-mcp",
          "azure-translator",
          "microsoft-graph-calendar",
          "dynamics-365-sales",
          "microsoft-advertising-api",
          "outlook-mail-graph"
        ],
        "area": "business",
        "provenance": {
          "legalEntity": "Microsoft Corporation",
          "domain": "microsoft.com",
          "domainRegistered": "1991-05-02",
          "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
          "endpointOnVendorDomain": true,
          "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
          "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
          "statusPage": "https://status.cloud.microsoft",
          "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
          "securityTxt": "expired",
          "checked": "2026-10-08",
          "notes": [
            "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
            "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
            "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
            "The Microsoft privacy statement was last updated in September 2026.",
            "RDAP for microsoft.com gives a registration date of 1991-05-02."
          ],
          "score": 85
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.json",
        "live": {
          "slug": "microsoft-excel-graph",
          "probe": {
            "target": "https://graph.microsoft.com/v1.0",
            "method": "get",
            "lastAt": "2026-10-08T17:36:40.30570825Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 3,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 34,
            "p95ms24h": 57,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.cloud.microsoft",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T15:36:56.168932402Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "microsoftgraph/msgraph-sdk-javascript",
              "version": "3.0.7",
              "released": "2023-09-19",
              "seenAt": "2026-10-08T16:20:40.005701271Z"
            },
            {
              "registry": "npm",
              "name": "@microsoft/microsoft-graph-client",
              "version": "3.0.7",
              "seenAt": "2026-10-08T16:20:38.997085198Z"
            },
            {
              "registry": "pypi",
              "name": "msgraph-sdk",
              "version": "1.64.0",
              "released": "2026-10-06",
              "seenAt": "2026-10-08T16:20:39.875494563Z"
            }
          ],
          "githubStars": 835,
          "npmWeekly": 2882852,
          "pypiWeekly": 1578201,
          "securityTxt": {
            "url": "https://microsoft.com/.well-known/security.txt",
            "state": "expired",
            "expires": "2026-09-23T16:00:00.000Z",
            "checkedAt": "2026-10-08T15:39:08.216544687Z"
          },
          "updatedAt": "2026-10-08T17:36:40.30570825Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/spreadsheets",
    "json": "https://www.anchorterminal.com/categories/spreadsheets.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/spreadsheets.md",
    "slim": "https://www.anchorterminal.com/categories/spreadsheets.min.md"
  },
  "markdown": "Spreadsheets and table products an agent can read and write. Cells, ranges and formulas in a workbook, or typed records in a base. Compared on read and write calls, batch limits, formulas, change events and how access to one file is scoped.\n\n- Tools ranked: 7 · agent-ready (BB or better): 3 · accept x402: 0 · hosted endpoints: 7 · desk reviews by the panel: 0\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: sheets.read, sheets.write, sheets.tables, sheets.formulas, sheets.records\n- https://letme.dev/sheets.read picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 33 | Google Sheets API | Google | HTTP API | Spreadsheets | BB | 76.3 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/google-sheets-api.md |\n| 37 | NocoDB | NocoDB Inc | HTTP API | Spreadsheets | BB | 75.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/nocodb.md |\n| 118 | Airtable | Formagrid Inc (Airtable) | HTTP API | Spreadsheets | BB | 70.9 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/airtable.md |\n| 190 | Smartsheet API + MCP | Smartsheet Inc. | HTTP API | Spreadsheets | B | 67.6 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/smartsheet.md |\n| 247 | Coda (Superhuman Docs) | Superhuman Platform Inc. | HTTP API | Spreadsheets | B | 64.8 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/coda.md |\n| 276 | Baserow | Baserow B.V. | HTTP API | Spreadsheets | B | 63.6 | medium | no | API key | hosted | none | https://www.anchorterminal.com/tools/baserow.md |\n| 399 | Microsoft Excel (Microsoft Graph workbook API) | Microsoft | HTTP API | Spreadsheets | C | 58.5 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/microsoft-excel-graph.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 33. Google Sheets API, BB (76.3)\n\nREST API from Google for reading and writing Google Sheets spreadsheets, covering cell values, ranges, formulas, formatting, tables and comments. Access is by OAuth 2.0, and a six-tool MCP server is in Developer Preview. Batch updates apply atomically and count as one request, and the drive.file scope limits an app to files the user picks. Quotas are 300 reads and 300 writes a minute per project, reads are by range with no row filter or paging, and a person must complete OAuth consent first.\n\n- Page: https://www.anchorterminal.com/tools/google-sheets-api · Markdown: https://www.anchorterminal.com/tools/google-sheets-api.md · JSON: https://www.anchorterminal.com/api/v1/tools/google-sheets-api.json\n- Capabilities: sheets.read, sheets.write, sheets.formulas, sheets.tables · endpoint: `https://sheets.googleapis.com/v4`\n\n### 37. NocoDB, BB (75.7)\n\nNocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth. API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.\n\n- Page: https://www.anchorterminal.com/tools/nocodb · Markdown: https://www.anchorterminal.com/tools/nocodb.md · JSON: https://www.anchorterminal.com/api/v1/tools/nocodb.json\n- Capabilities: sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas · endpoint: `https://app.nocodb.com`\n\n### 118. Airtable, BB (70.9)\n\nAirtable is a hosted database of typed records organised in bases, tables and views. Agents reach it through a REST Web API and an official hosted MCP server, using personal access tokens or OAuth. Tokens are limited by scope and by base, and the official MCP server at mcp.airtable.com covers records, schema, interfaces and automations in 40 tools. The REST API allows 5 requests a second per base with a 30-second lockout after a 429, writes take 10 records a call, and the Free plan stops at 1,000 calls a month.\n\n- Page: https://www.anchorterminal.com/tools/airtable · Markdown: https://www.anchorterminal.com/tools/airtable.md · JSON: https://www.anchorterminal.com/api/v1/tools/airtable.json\n- Capabilities: sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas · endpoint: `https://api.airtable.com`\n\n### 190. Smartsheet API + MCP, B (67.6)\n\nSmartsheet is a hosted work management product built on sheets with typed columns, rows, formulas, reports and dashboards. Agents reach it through a REST API (187 operations) and a hosted MCP server, both limited to Business plans and above. The REST API has a public OpenAPI 3.0.3 spec with 187 operations, Markdown docs and llms.txt, and the hosted MCP server loads its 83 documented tools by toolset. API access needs a Business plan or higher, and the status page lists eight incidents marked major or critical between 15 July and 21 September 2026.\n\n- Page: https://www.anchorterminal.com/tools/smartsheet · Markdown: https://www.anchorterminal.com/tools/smartsheet.md · JSON: https://www.anchorterminal.com/api/v1/tools/smartsheet.json\n- Capabilities: sheets.read, sheets.write, sheets.records, sheets.formulas, automation.workflows · endpoint: `https://api.smartsheet.com/2.0`\n\n### 247. Coda (Superhuman Docs), B (64.8)\n\nCoda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta. API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.\n\n- Page: https://www.anchorterminal.com/tools/coda · Markdown: https://www.anchorterminal.com/tools/coda.md · JSON: https://www.anchorterminal.com/api/v1/tools/coda.json\n- Capabilities: sheets.read, sheets.write, sheets.tables, sheets.records, sheets.formulas, work.docs · endpoint: `https://coda.io/apis/v1`\n\n### 276. Baserow, B (63.6)\n\nBaserow is an open-source database of typed rows in tables, sold as a hosted cloud and as software to self-host. Agents reach it through a REST API with database tokens and a built-in MCP server. Database tokens are limited to chosen tables and to create, read, update or delete, and the REST API has a public OpenAPI description with batch calls of 200 rows. The MCP server authenticates with a key in its URL, runs over SSE only and has no read-only mode. Cloud requests are capped at 10 at a time.\n\n- Page: https://www.anchorterminal.com/tools/baserow · Markdown: https://www.anchorterminal.com/tools/baserow.md · JSON: https://www.anchorterminal.com/api/v1/tools/baserow.json\n- Capabilities: sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas · endpoint: `https://api.baserow.io`\n\n### 399. Microsoft Excel (Microsoft Graph workbook API), C (58.5)\n\nWorkbook endpoints of Microsoft Graph for Excel files stored in OneDrive for work or school and SharePoint. Calls read and write ranges, tables, charts and named items, and run Excel worksheet functions on a file in place. Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.\n\n- Page: https://www.anchorterminal.com/tools/microsoft-excel-graph · Markdown: https://www.anchorterminal.com/tools/microsoft-excel-graph.md · JSON: https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json\n- Capabilities: sheets.read, sheets.write, sheets.tables, sheets.formulas · endpoint: `https://graph.microsoft.com/v1.0`\n\n## How we test this category\n\nThe same workbook of one thousand rows in each listing. The same tasks run through its API (read a range, append rows, update cells in a batch, add a formula column, filter records). We check limits, consistency after writes and change notifications. In this run listings are graded from public evidence against the published checklist. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Spreadsheets \u0026 operational tables",
        "url": ""
      }
    ],
    "description": "7 spreadsheets \u0026 operational tables ranked by the Anchor benchmark. Leader Google Sheets API (BB). Spreadsheets and table products an agent can read and write. Cells, ranges and formulas in a workbook, or typed records in a base. Compared on read and write calls, batch limits, formulas, change events and how access to one file is scoped.",
    "facts": [
      "Google Sheets API BB",
      "NocoDB BB",
      "Airtable BB"
    ],
    "h1": "Spreadsheet and operational table APIs for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-spreadsheets.png",
    "path": "/categories/spreadsheets",
    "published": "",
    "section": "tools",
    "title": "Spreadsheet and operational table APIs for AI agents, ranked",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/categories/spreadsheets"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 430
  },
  "version": 1
}
