{
  "data": {
    "a": {
      "slug": "alation",
      "name": "Alation",
      "vendor": "Alation, Inc.",
      "vendorUrl": "https://www.alation.com",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Alation is a hosted data catalogue for tables, queries, BI reports, lineage and data quality. Agents reach it through REST APIs, a natural-language Aggregated Context API, a Python agent SDK and an MCP server on each cloud instance.",
      "url": "https://www.anchorterminal.com/tools/alation",
      "markdownUrl": "https://www.anchorterminal.com/tools/alation.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/alation.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/alation.json",
      "repo": "https://github.com/Alation/alation-ai-agent-sdk",
      "license": "Proprietary service under Alation's Master Cloud Software Licence and Services Agreement. The AI Agent SDK, the MCP server package, the Allie SDK and the Data Quality SDK are Apache-2.0",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "alation-ai-agent-mcp"
        },
        {
          "registry": "pypi",
          "name": "alation-ai-agent-sdk"
        },
        {
          "registry": "pypi",
          "name": "allie-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is granted inside a customer's Alation instance. On Alation Cloud Service a Server Admin registers an OAuth client application, which creates a system user with one Alation role, and the client exchanges its ID and secret for a JWT sent as a Bearer token. An authorisation code flow with refresh tokens covers user sign-in, and the remote MCP server needs a client that accepts a `client_id` and `client_secret`, since dynamic client registration is not supported. Any signed-in user can also create an API key pair, a refresh token (60 days by default) and an access token (24 hours) sent in a `TOKEN` header. Permissions follow the user's role, as listed in the APIs by Roles table.",
      "pricing": "paid",
      "pricingNotes": "No prices are published. www.alation.com/pricing redirects to a form for a sales call, and we found no trial or self-serve sign-up. Each cloud tenant gets a one-time allowance of 2,000 Aggregated Context API calls, with 429 responses from 2,400 calls until a paid tier is bought through the account manager (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer portal, the agent SDK source or the legal pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 16,
      "popularity": {
        "githubStars": 19,
        "npmWeekly": null,
        "pypiWeekly": 2087,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.alation.com/",
      "capabilities": [
        "data.catalogue",
        "knowledge.search",
        "data.lineage",
        "db.sql"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "enterprise",
        "official",
        "mcp",
        "oauth",
        "openapi",
        "python",
        "sales-led",
        "status-page",
        "sla",
        "soc2"
      ],
      "lastRelease": "2026-10-03",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.3,
        "grade": "C",
        "agentReady": false,
        "rank": 472,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 71,
          "payments": 0,
          "reliability": 61,
          "schema": 78,
          "security": 63,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.",
        "bestFor": "A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.",
        "strengths": [
          "OpenAPI 3.0 definitions for each API, shown on every reference page and served by each instance under `/openapi/`",
          "OAuth 2.0 client credentials tied to a system user with one Alation role, with token revocation, secret rotation and offline JWT verification",
          "The AI API answers 429 with `Retry-After` and three `Ai-RateLimit` headers, and the REST 429 body states the seconds to wait",
          "The local MCP server enables 8 of its 16 tools by default, with allow and deny lists, and the remote server lists only tools the user may call",
          "A 99.5 per cent monthly uptime target with service credits of 1 to 5 per cent in the published MSA"
        ],
        "weaknesses": [
          "No published price, trial or self-serve sign-up. The pricing address redirects to a sales form",
          "Four incidents between 10 August and 10 September 2026, two of them regional outages longer than an hour",
          "`alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, and a plain `pip install` still resolves to 0.12.0",
          "No guidance on prompt injection, although tools return catalogue descriptions, documents and query text written by users",
          "No `security.txt` and no bug bounty, and security advisories sit behind a Community login"
        ],
        "agentNotes": [
          "Ask a Server Admin to register an OAuth client application with the lowest role that fits. Only admins can create one, and the secret is shown once",
          "Pin `alation-ai-agent-mcp==1.0.0rc3`. An unpinned install resolves to 0.12.0, which predates the catalogue search agent",
          "Call `catalog_context_search_agent` for catalogue questions. `alation_context` is deprecated and its description tells models not to call it directly",
          "Watch `X-Entitlement-Usage` on Aggregated Context API responses. The 2,000 free calls never reset, and a quota 429 is not retryable",
          "Page with `limit` and `skip` and follow `X-Next-Page`. The BI Source API uses `offset`, and one call returns at most 1,000 objects"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.3
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 71,
          "payments": 0,
          "reliability": 61,
          "schema": 78,
          "security": 63,
          "transparency": 65
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "uv pip install alation-ai-agent-mcp==1.0.0rc3",
        "config": {
          "mcpServers": {
            "alation": {
              "args": [
                "--from",
                "alation-ai-agent-mcp",
                "start-alation-mcp-server"
              ],
              "command": "uvx",
              "env": {
                "ALATION_AUTH_METHOD": "service_account",
                "ALATION_BASE_URL": "https://your-alation-instance.com",
                "ALATION_CLIENT_ID": "your-client-id",
                "ALATION_CLIENT_SECRET": "your-client-secret"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/data.catalogue",
        "tool": "https://letme.dev/alation"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Alation, Inc.",
        "domain": "alation.com",
        "domainRegistered": "1998-07-27",
        "endpointOnVendorDomain": true,
        "terms": "https://www.alation.com/legal/msa/",
        "privacy": "https://www.alation.com/legal/privacy-policy/",
        "statusPage": "https://status.alationcloud.com",
        "changelog": "https://developer.alation.com/dev/docs/running-api-release-notes",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The MSA (version 10 April 2026) and the privacy policy (version 23 September 2026) name Alation, Inc., 3 Lagoon Drive, Suite 300, Redwood City, CA 94065. The MSA is governed by Delaware law, or by the law of England and Wales for customers in the UK, EEA and Switzerland.",
          "Cloud instances and the status page are on alationcloud.com, a second domain of the vendor's. The agent SDK's guides give `your-instance.alationcloud.com` as the instance host.",
          "www.alation.com/.well-known/security.txt returns 404. The security page sends reports to security@alation.com.",
          "The privacy policy covers Alation websites and other Alation services. Customer personal data in the product is governed by the Data Privacy Addendum of 10 April 2026 at https://www.alation.com/legal/online-dpa/.",
          "RDAP gives alation.com a registration date of 1998-07-27. We did not establish when Alation acquired the domain."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/alation.json",
      "live": {
        "slug": "alation",
        "vendorStatus": {
          "page": "https://status.alationcloud.com",
          "indicator": "maintenance",
          "summary": "Service Under Maintenance",
          "checkedAt": "2026-10-09T10:41:24.91593843Z"
        },
        "updatedAt": "2026-10-09T10:41:24.91593843Z"
      }
    },
    "answer": "Onyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust.",
    "b": {
      "slug": "onyx",
      "name": "Onyx",
      "vendor": "DanswerAI, Inc. (Onyx, formerly Danswer)",
      "vendorUrl": "https://www.onyx.app",
      "kind": "platform",
      "category": "company-knowledge",
      "summary": "Open-source enterprise search and chat platform, formerly Danswer.",
      "url": "https://www.anchorterminal.com/tools/onyx",
      "markdownUrl": "https://www.anchorterminal.com/tools/onyx.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onyx.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onyx.json",
      "repo": "https://github.com/onyx-dot-app/onyx",
      "license": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://cloud.onyx.app/mcp",
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-backend"
        },
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-web-server"
        },
        {
          "registry": "pypi",
          "name": "onyx-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every request takes a Bearer token in the `Authorization` header, either a personal access token or an API key. Personal access tokens belong to a user, can be full access or limited to `read:search`, `read:chat`, `write:chat` or `use:llm_gateway`, expire after 7, 30 or 365 days or never, are stored hashed and can be revoked one by one. API keys belong to service accounts, and since v4.7 their rights come from the groups they're put in (none means chat only, Basic adds search, Admin reaches every endpoint). The MCP server checks each token against the API server's /me and passes it through. No OAuth for MCP clients. People sign in to the web app with passwords, Google OAuth, OIDC or SAML.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is MIT and free to self-host with no seat limit. Onyx Cloud and licensed self-hosting have two plans on onyx.app/pricing. Business is $20 a user a month billed annually, and Enterprise (OIDC and SAML SSO, on-premise and region-specific deployments, white-labelling, an enterprise SLA) is by quote. Single-tenant cloud needs at least 100 licences per the docs. Onyx Cloud has a two-week free trial with no card (checked 2026-10-03).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 32300,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.onyx.app/deployment/configuration/mcp_server",
      "llmsTxt": "https://docs.onyx.app/llms.txt",
      "openapi": "https://docs.onyx.app/developers/api_reference/openapi.json",
      "capabilities": [
        "knowledge.search",
        "web.search",
        "web.fetch",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "cli",
        "docker",
        "freemium",
        "no-card",
        "enterprise",
        "commercial-licence",
        "telemetry-default-on",
        "status-page"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65,
        "grade": "B",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-07-20. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0). Any signed-in user could read, in clear text, other users' live OAuth tokens for per-user MCP servers such as Slack, Atlassian or Notion through GET /api/mcp/servers. Found in an external pentest in May 2026, fixed in 4.0.0 (26 May 2026) and published, so the deduction is reduced, -3 (https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822)",
          "2026-04-29 and 2026-07-20. Three moderate IDOR advisories, other users' chat files downloadable through /chat/file/{file_id} (GHSA-vg3h-35f7-7w6r), other users' chat sessions stoppable through /chat/stop-chat-session (GHSA-rw6w-hp62-gc8w) and curators able to change any user group's membership (GHSA-7f48-vgpj-h95m). Fixed and published, -1 (https://github.com/onyx-dot-app/onyx/security/advisories)"
        ],
        "verdict": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.",
        "bestFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "strengths": [
          "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card",
          "Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped",
          "Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one",
          "OpenAPI 3.1 file of 110 operations, llms.txt, Markdown docs and dated release notes with Deployment Changes sections",
          "A minor release every two to three weeks, 4.3.0 on 6 July to 4.8.0 on 23 September 2026, with patches for older lines"
        ],
        "weaknesses": [
          "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0",
          "Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain",
          "Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line",
          "The self-hosted MCP server is off by default, takes no OAuth and isn't in the official MCP registry",
          "The privacy policy and Cloud agreement render only with JavaScript, and there's no security.txt or bug bounty"
        ],
        "agentNotes": [
          "Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`",
          "Use a token limited to `read:search`. It covers every MCP tool and nothing else",
          "Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered",
          "Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors",
          "Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 57
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "curl -fsSL https://onyx.app/install_onyx.sh | bash",
        "http": "curl -s -X POST \"${API_BASE_URL}/search\" \\\n  -H \"Authorization: Bearer ${API_KEY}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"What is our parental leave policy?\", \"sources\": [\"confluence\", \"google_drive\"]}'",
        "claudeCode": "claude mcp add --transport http onyx https://cloud.onyx.app/mcp \\\n  --header \"Authorization: Bearer YOUR_ONYX_TOKEN_HERE\"",
        "config": {
          "mcpServers": {
            "onyx": {
              "headers": {
                "Authorization": "Bearer ${ONYX_TOKEN}"
              },
              "type": "http",
              "url": "https://cloud.onyx.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/onyx"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Onyx Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "billed annually"
        }
      ],
      "provenance": {
        "legalEntity": "DanswerAI, Inc.",
        "domain": "onyx.app",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://onyx.app/legal/cloud",
        "privacy": "https://onyx.app/legal/privacy-policy",
        "statusPage": "https://status.onyx.app",
        "changelog": "https://docs.onyx.app/changelog",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE and the Onyx Enterprise License name DanswerAI, Inc., and the site footer reads Onyx.",
          "The privacy policy and the Onyx Cloud Subscription Agreement show a last update of 1 July 2025 and load their text with JavaScript, which our reader couldn't see.",
          "onyx.app/.well-known/security.txt returns 404. SECURITY.md routes reports through GitHub private vulnerability reporting.",
          "The shared MCP endpoint cloud.onyx.app/mcp is on the vendor's domain. A self-hosted server answers on the operator's own host."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onyx.json",
      "live": {
        "slug": "onyx",
        "probe": {
          "target": "https://cloud.onyx.app/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:42:51.399914989Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 302,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 303,
          "p95ms24h": 335,
          "samples24h": 260,
          "samples30d": 1524,
          "days": [
            {
              "date": "2026-10-03",
              "probes": 54,
              "ok": 54
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.onyx.app",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:14.63709355Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "onyx-dot-app/onyx",
            "version": "v4.9.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:23:15.301712603Z"
          },
          {
            "registry": "pypi",
            "name": "onyx-cli",
            "version": "1.4.4",
            "released": "2026-09-13",
            "seenAt": "2026-10-08T16:23:15.106102182Z"
          }
        ],
        "githubStars": 32357,
        "pypiWeekly": 781,
        "securityTxt": {
          "url": "https://onyx.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:29.983427844Z"
        },
        "llmsTxt": {
          "url": "https://docs.onyx.app/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:42.879073728Z"
        },
        "domain": {
          "domain": "onyx.app",
          "registered": "2018-05-04",
          "source": "https://pubapi.registry.google/rdap/domain/onyx.app",
          "checkedAt": "2026-10-04T13:08:25.059354531Z"
        },
        "pages": [
          {
            "url": "https://docs.onyx.app/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:12.353203571Z",
            "changedAt": "2026-10-08T18:19:12.353203571Z",
            "fingerprint": "903bb0fb92dc"
          },
          {
            "url": "https://onyx.app/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:33.516398975Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bd896d976a98"
          },
          {
            "url": "https://onyx.app/legal/cloud",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:31.357169656Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b08a2af7854"
          }
        ],
        "updatedAt": "2026-10-09T10:42:51.399914989Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Alation, Inc.",
        "b": "DanswerAI, Inc. (Onyx, formerly Danswer)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://cloud.onyx.app/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP, stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Alation's Master Cloud Software Licence and Services Agreement. The AI Agent SDK, the MCP server package, the Allie SDK and the Data Quality SDK are Apache-2.0",
        "b": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
        "name": "Licence"
      },
      {
        "a": "16",
        "b": "3",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-03",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "19 stars, 2.1k PyPI/wk",
        "b": "32k stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Onyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Alation or Onyx?"
      },
      {
        "answer": "Alation runs on your own machine, with no hosted endpoint listed. Onyx has a hosted endpoint at https://cloud.onyx.app/mcp.",
        "question": "Can an agent call Alation and Onyx without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Alation. Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).",
        "question": "Are Alation and Onyx open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Transparency \u0026 trust, 76 against 63"
        ],
        "also": [
          "Runs on your own machine",
          "No incidents deducted, where Onyx loses 4 points for them"
        ],
        "goodFor": "A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.",
        "slug": "alation",
        "watchFor": "No published price, trial or self-serve sign-up. The pricing address redirects to a sales form"
      },
      {
        "aheadOn": [
          "Reliability, 69 against 61",
          "Schema \u0026 documentation, 88 against 78",
          "Agent ergonomics, 77 against 71",
          "Security \u0026 auth, 71 against 63",
          "Payments \u0026 pricing, 30 against 0",
          "Maintenance \u0026 community, 77 against 71"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "slug": "onyx",
        "watchFor": "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0"
      }
    ],
    "job": {
      "capability": "knowledge.search",
      "name": "Company knowledge search"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-cohere-north.json",
        "title": "Alation vs Cohere North",
        "url": "https://www.anchorterminal.com/compare/alation-vs-cohere-north"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-dust.json",
        "title": "Alation vs Dust",
        "url": "https://www.anchorterminal.com/compare/alation-vs-dust"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-glean.json",
        "title": "Alation vs Glean",
        "url": "https://www.anchorterminal.com/compare/alation-vs-glean"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-guru.json",
        "title": "Alation vs Guru",
        "url": "https://www.anchorterminal.com/compare/alation-vs-guru"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-overclock.json",
        "title": "Alation vs Overclock",
        "url": "https://www.anchorterminal.com/compare/alation-vs-overclock"
      },
      {
        "json": "https://www.anchorterminal.com/compare/atlan-vs-onyx.json",
        "title": "Atlan vs Onyx",
        "url": "https://www.anchorterminal.com/compare/atlan-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx.json",
        "title": "Cohere North vs Onyx",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dust-vs-onyx.json",
        "title": "Dust vs Onyx",
        "url": "https://www.anchorterminal.com/compare/dust-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/glean-vs-onyx.json",
        "title": "Glean vs Onyx",
        "url": "https://www.anchorterminal.com/compare/glean-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guru-vs-onyx.json",
        "title": "Guru vs Onyx",
        "url": "https://www.anchorterminal.com/compare/guru-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/onyx-vs-overclock.json",
        "title": "Onyx vs Overclock",
        "url": "https://www.anchorterminal.com/compare/onyx-vs-overclock"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-atlan.json",
        "title": "Alation vs Atlan",
        "url": "https://www.anchorterminal.com/compare/alation-vs-atlan"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-datahub.json",
        "title": "Alation vs DataHub",
        "url": "https://www.anchorterminal.com/compare/alation-vs-datahub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-marmot.json",
        "title": "Alation vs Marmot",
        "url": "https://www.anchorterminal.com/compare/alation-vs-marmot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-openmetadata.json",
        "title": "Alation vs OpenMetadata",
        "url": "https://www.anchorterminal.com/compare/alation-vs-openmetadata"
      }
    ],
    "scores": [
      {
        "alation": 61,
        "by": 8,
        "edge": "onyx",
        "key": "reliability",
        "name": "Reliability",
        "onyx": 69,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "alation": 78,
        "by": 10,
        "edge": "onyx",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "onyx": 88,
        "weight": 13
      },
      {
        "alation": 71,
        "by": 6,
        "edge": "onyx",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "onyx": 77,
        "weight": 13
      },
      {
        "alation": 63,
        "by": 8,
        "edge": "onyx",
        "key": "security",
        "name": "Security \u0026 auth",
        "onyx": 71,
        "weight": 14
      },
      {
        "alation": 0,
        "by": 30,
        "edge": "onyx",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "onyx": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "alation": 71,
        "by": 6,
        "edge": "onyx",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "onyx": 77,
        "weight": 7
      },
      {
        "alation": 76,
        "by": 13,
        "edge": "alation",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "onyx": 63,
        "weight": 7
      }
    ],
    "summary": "Onyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust. Both do company knowledge search.",
    "verdicts": {
      "alation": "Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.",
      "onyx": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/alation-vs-onyx",
    "json": "https://www.anchorterminal.com/compare/alation-vs-onyx.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/alation-vs-onyx.md",
    "slim": "https://www.anchorterminal.com/compare/alation-vs-onyx.min.md"
  },
  "markdown": "Onyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust. Both do company knowledge search.\n\n- Alation: grade C, 60.3/100, rank #472 of 842. Markdown https://www.anchorterminal.com/tools/alation.md · JSON https://www.anchorterminal.com/api/v1/tools/alation.json\n- Onyx: grade B, 65/100, rank #303 of 842. Markdown https://www.anchorterminal.com/tools/onyx.md · JSON https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Which one, for what\n\n### Alation (C)\n\nGood for: A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.\n\nAhead on:\n- Transparency \u0026 trust, 76 against 63\n\nAlso in its favour:\n- Runs on your own machine\n- No incidents deducted, where Onyx loses 4 points for them\n\nWatch for: No published price, trial or self-serve sign-up. The pricing address redirects to a sales form\n\n### Onyx (B)\n\nGood for: Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.\n\nAhead on:\n- Reliability, 69 against 61\n- Schema \u0026 documentation, 88 against 78\n- Agent ergonomics, 77 against 71\n- Security \u0026 auth, 71 against 63\n- Payments \u0026 pricing, 30 against 0\n- Maintenance \u0026 community, 77 against 71\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- Open source\n\nWatch for: GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0\n\n\n## Score by category\n\n| Category | Weight | Alation | Onyx | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 61 | 69 | Onyx +8 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 88 | Onyx +10 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 77 | Onyx +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 71 | Onyx +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 30 | Onyx +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 71 | 77 | Onyx +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 63 | Alation +13 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **60.3 · C** | **65 · B** | |\n\n## Facts side by side\n\n| Fact | Alation | Onyx |\n| --- | --- | --- |\n| Kind | HTTP API | Model platform |\n| Vendor | Alation, Inc. | DanswerAI, Inc. (Onyx, formerly Danswer) |\n| Hosted endpoint | no (local only) | `https://cloud.onyx.app/mcp` |\n| Transports | HTTP, Streamable HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Alation's Master Cloud Software Licence and Services Agreement. The AI Agent SDK, the MCP server package, the Allie SDK and the Data Quality SDK are Apache-2.0 | MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use |\n| Tools exposed | 16 | 3 |\n| Read-only variant documented | no | yes |\n| llms.txt | no | yes |\n| Last release | 2026-10-03 | 2026-10-02 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated | no date given | couldn't be read |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | yes | couldn't be read |\n| Terms or service can change without notice | not found in the text | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n| Popularity | 19 stars, 2.1k PyPI/wk | 32k stars |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Alation.** Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.\n\n**Onyx.** MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.\n\n## Before you call either\n\n### Alation\n\n1. Ask a Server Admin to register an OAuth client application with the lowest role that fits. Only admins can create one, and the secret is shown once\n2. Pin `alation-ai-agent-mcp==1.0.0rc3`. An unpinned install resolves to 0.12.0, which predates the catalogue search agent\n3. Call `catalog_context_search_agent` for catalogue questions. `alation_context` is deprecated and its description tells models not to call it directly\n4. Watch `X-Entitlement-Usage` on Aggregated Context API responses. The 2,000 free calls never reset, and a quota 429 is not retryable\n5. Page with `limit` and `skip` and follow `X-Next-Page`. The BI Source API uses `offset`, and one call returns at most 1,000 objects\n\n### Onyx\n\n1. Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`\n2. Use a token limited to `read:search`. It covers every MCP tool and nothing else\n3. Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered\n4. Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors\n5. Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search\n\n## Questions\n\n### Which is better for AI agents, Alation or Onyx?\n\nOnyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust.\n\n### Can an agent call Alation and Onyx without installing anything?\n\nAlation runs on your own machine, with no hosted endpoint listed. Onyx has a hosted endpoint at https://cloud.onyx.app/mcp.\n\n### Are Alation and Onyx open source?\n\nNo open-source release is listed for Alation. Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/alation-vs-onyx.json, and with the fewest tokens: https://www.anchorterminal.com/compare/alation-vs-onyx.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"alation\", \"b\": \"onyx\"}`. From a terminal: `anchor compare alation onyx`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/alation.json and https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Other comparisons with Alation or Onyx\n\n- [Alation vs Cohere North](https://www.anchorterminal.com/compare/alation-vs-cohere-north.md)\n- [Alation vs Dust](https://www.anchorterminal.com/compare/alation-vs-dust.md)\n- [Alation vs Glean](https://www.anchorterminal.com/compare/alation-vs-glean.md)\n- [Alation vs Guru](https://www.anchorterminal.com/compare/alation-vs-guru.md)\n- [Alation vs Overclock](https://www.anchorterminal.com/compare/alation-vs-overclock.md)\n- [Atlan vs Onyx](https://www.anchorterminal.com/compare/atlan-vs-onyx.md)\n- [Cohere North vs Onyx](https://www.anchorterminal.com/compare/cohere-north-vs-onyx.md)\n- [Dust vs Onyx](https://www.anchorterminal.com/compare/dust-vs-onyx.md)\n- [Glean vs Onyx](https://www.anchorterminal.com/compare/glean-vs-onyx.md)\n- [Guru vs Onyx](https://www.anchorterminal.com/compare/guru-vs-onyx.md)\n- [Onyx vs Overclock](https://www.anchorterminal.com/compare/onyx-vs-overclock.md)\n- [Alation vs Atlan](https://www.anchorterminal.com/compare/alation-vs-atlan.md)\n- [Alation vs DataHub](https://www.anchorterminal.com/compare/alation-vs-datahub.md)\n- [Alation vs Marmot](https://www.anchorterminal.com/compare/alation-vs-marmot.md)\n- [Alation vs OpenMetadata](https://www.anchorterminal.com/compare/alation-vs-openmetadata.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Alation vs Onyx",
        "url": ""
      }
    ],
    "description": "Onyx scores 65 (B) on agent readiness against Alation's 60.3 (C), and leads in 6 of 7 scored categories. Alation leads on transparency \u0026 trust. Both do company knowledge search. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Alation C 60.3",
      "Onyx B 65",
      "scores"
    ],
    "h1": "Alation vs Onyx",
    "image": "https://www.anchorterminal.com/assets/og/compare-alation-vs-onyx.png",
    "path": "/compare/alation-vs-onyx",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Alation vs Onyx for AI agents, C 60.3 vs B 65 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/alation-vs-onyx"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 880
  },
  "version": 1
}
