{
  "data": {
    "a": {
      "slug": "baserow",
      "name": "Baserow",
      "vendor": "Baserow B.V.",
      "vendorUrl": "https://baserow.io",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Baserow is an open-source database of typed rows in tables, sold as a hosted cloud and as software to self-host. Agents reach it through a REST API with database tokens and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/baserow",
      "markdownUrl": "https://www.anchorterminal.com/tools/baserow.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/baserow.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/baserow.json",
      "repo": "https://github.com/baserow/baserow",
      "license": "MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "sse"
      ],
      "remoteUrl": "https://api.baserow.io",
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve. A signed-in user creates a database token in the workspace settings, choosing the tables it can reach and whether it may create, read, update or delete rows. Tokens don't expire and can be regenerated or deleted. They cover rows only, so changing tables or fields needs a JWT from `/api/user/token-auth/` with the account's email and password, which carries the user's full access. The MCP server has no token header or OAuth. Each endpoint is a URL holding a 32-character key that carries the creating user's access across one workspace, and deleting the endpoint revokes it. On Enterprise licences only workspace admins and builders can create database tokens.",
      "pricing": "freemium",
      "pricingNotes": "Free cloud plan with 3,000 rows and 2 GB of storage per workspace, so an agent can start without a contract. Premium is $10 a user a month billed yearly ($12 monthly) and Advanced $18 ($22 monthly), Enterprise through sales. API calls aren't priced, the MCP server is on every plan, and there's no separate sandbox. The self-hosted core is free with no row or request limits (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI description, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 7,
      "popularity": {
        "githubStars": 6098,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://baserow.io/user-docs/database-api",
      "llmsTxt": "https://baserow.io/llms.txt",
      "openapi": "https://api.baserow.io/api/schema.json",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 72,
          "payments": 40,
          "reliability": 65,
          "schema": 77,
          "security": 54,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Database tokens are limited to chosen tables and to create, read, update or delete, and the REST API has a public OpenAPI description with batch calls of 200 rows. The MCP server authenticates with a key in its URL, runs over SSE only and has no read-only mode. Cloud requests are capped at 10 at a time.",
        "bestFor": "Teams that want Airtable-style typed tables they can also self-host, with row-level reads and writes by an agent through table-scoped tokens or a small MCP tool set.",
        "strengths": [
          "Database tokens are limited to one workspace, to chosen tables and to create, read, update or delete, and can be regenerated or deleted",
          "Public OpenAPI 3.0.3 description at api.baserow.io/api/schema.json with 424 operations and an enum of error codes on each response",
          "The MCP server exposes 7 tools with typed inputs, and its descriptions tell the caller to read the table schema before writing",
          "List rows takes `include`, `exclude`, `size`, `filters`, `search`, `order_by` and `view_id`, so responses can be sized",
          "The core, including the REST API and the MCP server, is MIT-licensed and can be self-hosted with no row or request limits"
        ],
        "weaknesses": [
          "The MCP endpoint's key sits in the URL path, and the docs say it grants full access to modify data in the workspace",
          "The MCP server speaks only the older SSE transport, with no OAuth, no read-only mode and no tool annotations",
          "Table and field changes over REST need a JWT obtained with the account's email and password, since database tokens cover rows only",
          "No SLA, security.txt, sub-processor list or published DPA text was found, and the privacy policy carries no date or retention periods",
          "No official client library was found, and Baserow isn't in the official MCP registry under its own namespace"
        ],
        "agentNotes": [
          "Create a database token with only the tables and operations needed. It can't change tables or fields, which need a JWT from `/api/user/token-auth/`",
          "Send `Authorization: Token YOUR_DATABASE_TOKEN`, and add `user_field_names=true` or rows come back keyed as `field_123`",
          "Use the `/batch/` endpoints for up to 200 rows a call, and keep to 10 requests in flight on Baserow Cloud",
          "Treat the MCP URL as a password. Keep it out of logs and version control, and delete the endpoint to revoke it",
          "Over MCP, call `get_table_schema` before `create_rows` or `update_rows`, and page `list_table_rows` with `page` and `size`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 72,
          "payments": 40,
          "reliability": 65,
          "schema": 77,
          "security": 54,
          "transparency": 49
        },
        "provenanceScore": 80
      },
      "connect": {
        "http": "curl \\\n-X GET \\\n-H \"Authorization: Token YOUR_DATABASE_TOKEN\" \\\n\"https://api.baserow.io/api/database/fields/table/TABLE_ID/\"",
        "config": {
          "mcpServers": {
            "Baserow MCP": {
              "url": "YOUR_MCP_URL_HERE"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/baserow"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Premium (cloud)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed yearly, $12 billed monthly, 50,000 rows per workspace"
        },
        {
          "item": "Advanced (cloud)",
          "unit": "seat-month",
          "usd": 18,
          "note": "billed yearly, $22 billed monthly, 250,000 rows per workspace"
        }
      ],
      "provenance": {
        "legalEntity": "Baserow B.V.",
        "domain": "baserow.io",
        "domainRegistered": "2019-01-19",
        "endpointOnVendorDomain": true,
        "terms": "https://baserow.io/terms-and-conditions",
        "privacy": "https://baserow.io/privacy-policy",
        "statusPage": "https://status.baserow.org",
        "changelog": "https://github.com/baserow/baserow/blob/develop/changelog.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The General Terms and Conditions name Baserow B.V., a Dutch private company with its registered office at Keurenplein 4, Amsterdam, trade register number 81129254. The page carries no date.",
          "The privacy policy is the only one found. It is written for visitors to baserow.io, mentions account registration, carries no date and names no retention periods. The terms incorporate a Data Processing Agreement by reference, and no public copy was found.",
          "The REST API and the MCP server answer at api.baserow.io, a baserow.io subdomain. The status page is on a separate domain, status.baserow.org, hosted by Better Stack.",
          "baserow.io/.well-known/security.txt and api.baserow.io/.well-known/security.txt return 404. SECURITY.md in the repository gives an email address for vulnerability reports.",
          "RDAP for baserow.io gives a registration date of 2019-01-19."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/baserow.json",
      "live": {
        "slug": "baserow",
        "probe": {
          "target": "https://api.baserow.io",
          "method": "get",
          "lastAt": "2026-10-08T21:12:05.351136961Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 75,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 91,
          "p95ms24h": 143,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.baserow.org",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:16.274385747Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/baserow/baserow/develop/changelog.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:01.724744684Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2a6db4300826"
          },
          {
            "url": "https://baserow.io/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:31.424595879Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9e86e4bd4127"
          },
          {
            "url": "https://baserow.io/terms-and-conditions",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:33.545863734Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1d9e20c33e8e"
          }
        ],
        "updatedAt": "2026-10-08T21:12:05.351136961Z"
      }
    },
    "answer": "Baserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "grist",
      "name": "Grist",
      "vendor": "Grist Labs Inc.",
      "vendorUrl": "https://www.getgrist.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/grist",
      "markdownUrl": "https://www.anchorterminal.com/tools/grist.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/grist.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/grist.json",
      "repo": "https://github.com/gristlabs/grist-core",
      "license": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://docs.getgrist.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "grist-api"
        },
        {
          "registry": "pypi",
          "name": "grist-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates an API key on the Developer page of account settings and sends it as `Authorization: Bearer`. The key carries its owner's full account access, and each account has one. The alternative is OAuth 2.0 with PKCE, used by the MCP server and by registered apps. The user approves any of seven scopes (`doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`) and can limit the grant to chosen sites, workspaces or documents. Access tokens last 1 hour and refresh tokens 60 days, and a grant can be revoked per app. Clients can register themselves by Client ID Metadata Document. Not every REST endpoint accepts an OAuth token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 5,000 rows a document and 3,000 API calls a month per site, REST and MCP calls together, so an agent can start without a contract. Pro is $10 a user a month ($8 billed yearly) and Business $30 ($24 yearly, minimum 5 users), Enterprise through sales. API calls aren't priced, the MCP server is on every plan for now, and there's no separate sandbox. The self-hosted community edition is free (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": 11900,
        "npmWeekly": 341,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://support.getgrist.com/rest-api/",
      "openapi": "https://raw.githubusercontent.com/gristlabs/grist-help/master/api/grist.yml",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "oauth",
        "api-key",
        "openapi",
        "webhooks",
        "python",
        "javascript"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.1,
        "grade": "D",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-13. GHSA-9x4j-4rw5-3vmq, critical (CVSS 10.0), remote code execution through prototype pollution from an imported crafted document, affecting Docker images before 1.7.19 and fixed in 1.7.19. Four more advisories were published in the last 12 months, among them GHSA-7xvx-8pf2-pv5g (CVE-2026-24002, critical, 21 January 2026) on the pyodide sandbox option, fixed in 1.7.9. All five are fixed and published and none says whether hosted Grist was affected, so the deduction is reduced (https://github.com/gristlabs/grist-core/security/advisories)"
        ],
        "verdict": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
        "bestFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "strengths": [
          "OAuth 2.0 with PKCE and seven scopes, with `doc:read`, `doc:write` and `doc.schema:write` granted separately and the grant limited to chosen sites, workspaces or documents",
          "Access tokens last 1 hour, refresh tokens 60 days, and a user can revoke one app's grant from the Authorised apps page",
          "Public OpenAPI 3.0.0 file with 101 paths and 120 operations, including a read-only SQL endpoint and `PUT` on `/records` to add or update by key columns",
          "Limits are published with numbers per plan, with 10 concurrent requests per document and a 1 MB request body on every plan",
          "The core is Apache-2.0 and four releases were tagged between 29 July and 28 September 2026"
        ],
        "weaknesses": [
          "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none",
          "An API key carries its owner's full account access, and each account has one key, so it can't be limited to a document or revoked per integration",
          "The data security page says hosted Grist has no SOC 2, ISO 27001, HIPAA or GDPR certification, and no DPA, sub-processor list or security.txt was found",
          "The MCP server and OAuth server are in the proprietary full edition, so the Apache-2.0 community edition has neither and the tool definitions aren't public",
          "Five security advisories were published in the last 12 months, two rated critical, the latest on 13 September 2026 with CVSS 10.0",
          "The Free plan allows 3,000 API calls a month across a site, with REST and MCP calls sharing the pool"
        ],
        "agentNotes": [
          "Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen",
          "Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules",
          "Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented",
          "Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row",
          "Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.1
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 50
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "pip install grist-api",
        "http": "curl -H \"Authorization: Bearer \u003cAPI-KEY-GOES-HERE\u003e\" https://docs.getgrist.com/api/orgs",
        "claudeCode": "claude mcp add --transport http grist https://docs.getgrist.com/api/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/grist"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro (hosted)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed monthly, $8 billed yearly, 100,000 rows a document, 40,000 API calls per document per day"
        },
        {
          "item": "Business (hosted)",
          "unit": "seat-month",
          "usd": 30,
          "note": "billed monthly, $24 billed yearly, minimum 5 users, 150,000 rows a document, 60,000 API calls per document per day"
        }
      ],
      "provenance": {
        "legalEntity": "Grist Labs Inc.",
        "domain": "getgrist.com",
        "domainRegistered": "2014-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.getgrist.com/terms/",
        "privacy": "https://www.getgrist.com/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/gristlabs/grist-core/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms page is an End-User Licence Agreement between the user and Grist Labs Inc., covering its products, software, services and websites, governed by New York State law, with legal notices to 93 4th Ave, #1127, New York, NY 10003. It carries no date.",
          "The privacy policy has an effective date of 1 April 2019 and covers the websites, products and services. It names no retention periods.",
          "The REST API and MCP server answer at docs.getgrist.com and \u003cteam\u003e.getgrist.com, and OAuth at login.getgrist.com, all getgrist.com subdomains.",
          "No status page was found. status.getgrist.com redirects to a signup form because every subdomain is treated as a team site.",
          "www.getgrist.com/.well-known/security.txt and docs.getgrist.com/.well-known/security.txt return 404. SECURITY.md in the repository gives security@getgrist.com.",
          "RDAP for getgrist.com gives a registration date of 2014-05-12."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/grist.json",
      "live": {
        "slug": "grist",
        "probe": {
          "target": "https://docs.getgrist.com/api",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.613117891Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 251,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 256,
          "p95ms24h": 311,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "updatedAt": "2026-10-08T21:12:11.613117891Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Baserow B.V.",
        "b": "Grist Labs Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.baserow.io",
        "b": "https://docs.getgrist.com/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, SSE (legacy)",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0",
        "b": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
        "name": "Licence"
      },
      {
        "a": "7",
        "b": "34",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-29",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2019-04-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6.1k stars",
        "b": "12k stars, 341 npm/wk, 240 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Baserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Baserow or Grist?"
      },
      {
        "answer": "Baserow needs an API key. Grist takes an API key or an OAuth sign-in.",
        "question": "Do Baserow and Grist need an API key?"
      },
      {
        "answer": "Yes. Baserow has a hosted endpoint at https://api.baserow.io and Grist at https://docs.getgrist.com/api.",
        "question": "Can an agent call Baserow and Grist without installing anything?"
      },
      {
        "answer": "Yes. Baserow is open source (MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0). Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0).",
        "question": "Are Baserow and Grist open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 65 against 39",
          "Schema \u0026 documentation, 77 against 63",
          "Agent ergonomics, 72 against 57",
          "Payments \u0026 pricing, 40 against 30"
        ],
        "also": [
          "No incidents deducted, where Grist loses 4 points for them"
        ],
        "goodFor": "Teams that want Airtable-style typed tables they can also self-host, with row-level reads and writes by an agent through table-scoped tokens or a small MCP tool set.",
        "slug": "baserow",
        "watchFor": "The MCP endpoint's key sits in the URL path, and the docs say it grants full access to modify data in the workspace"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 62 against 54",
          "Maintenance \u0026 community, 78 against 72"
        ],
        "also": null,
        "goodFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "slug": "grist",
        "watchFor": "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none"
      }
    ],
    "job": {
      "capability": "sheets.records",
      "name": "Sheets records"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-google-sheets-api.json",
        "title": "Baserow vs Google Sheets API",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-google-sheets-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph.json",
        "title": "Baserow vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-grist.json",
        "title": "Coda (Superhuman Docs) vs Grist",
        "url": "https://www.anchorterminal.com/compare/coda-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.json",
        "title": "Google Sheets API vs Grist",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json",
        "title": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-baserow.json",
        "title": "Airtable vs Baserow",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-baserow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-grist.json",
        "title": "Airtable vs Grist",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-coda.json",
        "title": "Baserow vs Coda (Superhuman Docs)",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-coda"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-nocodb.json",
        "title": "Baserow vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-seatable.json",
        "title": "Baserow vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-smartsheet.json",
        "title": "Baserow vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-teable.json",
        "title": "Baserow vs Teable",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-nocodb.json",
        "title": "Grist vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/grist-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-seatable.json",
        "title": "Grist vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.json",
        "title": "Grist vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/grist-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-teable.json",
        "title": "Grist vs Teable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-teable"
      }
    ],
    "scores": [
      {
        "baserow": 65,
        "by": 26,
        "edge": "baserow",
        "grist": 39,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "baserow": 77,
        "by": 14,
        "edge": "baserow",
        "grist": 63,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "baserow": 72,
        "by": 15,
        "edge": "baserow",
        "grist": 57,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "baserow": 54,
        "by": 8,
        "edge": "grist",
        "grist": 62,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "baserow": 40,
        "by": 10,
        "edge": "baserow",
        "grist": 30,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "baserow": 72,
        "by": 6,
        "edge": "grist",
        "grist": 78,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "baserow": 65,
        "by": 4,
        "edge": "baserow",
        "grist": 61,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Baserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community. Both do sheets records.",
    "verdicts": {
      "baserow": "Database tokens are limited to chosen tables and to create, read, update or delete, and the REST API has a public OpenAPI description with batch calls of 200 rows. The MCP server authenticates with a key in its URL, runs over SSE only and has no read-only mode. Cloud requests are capped at 10 at a time.",
      "grist": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/baserow-vs-grist",
    "json": "https://www.anchorterminal.com/compare/baserow-vs-grist.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/baserow-vs-grist.md",
    "slim": "https://www.anchorterminal.com/compare/baserow-vs-grist.min.md"
  },
  "markdown": "Baserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community. Both do sheets records.\n\n- Baserow: grade B, 63.6/100, rank #306 of 722. Markdown https://www.anchorterminal.com/tools/baserow.md · JSON https://www.anchorterminal.com/api/v1/tools/baserow.json\n- Grist: grade D, 50.1/100, rank #597 of 722. Markdown https://www.anchorterminal.com/tools/grist.md · JSON https://www.anchorterminal.com/api/v1/tools/grist.json\n\n## Which one, for what\n\n### Baserow (B)\n\nGood for: Teams that want Airtable-style typed tables they can also self-host, with row-level reads and writes by an agent through table-scoped tokens or a small MCP tool set.\n\nAhead on:\n- Reliability, 65 against 39\n- Schema \u0026 documentation, 77 against 63\n- Agent ergonomics, 72 against 57\n- Payments \u0026 pricing, 40 against 30\n\nAlso in its favour:\n- No incidents deducted, where Grist loses 4 points for them\n\nWatch for: The MCP endpoint's key sits in the URL path, and the docs say it grants full access to modify data in the workspace\n\n### Grist (D)\n\nGood for: Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.\n\nAhead on:\n- Security \u0026 auth, 62 against 54\n- Maintenance \u0026 community, 78 against 72\n\nWatch for: No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none\n\n\n## Score by category\n\n| Category | Weight | Baserow | Grist | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 39 | Baserow +26 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 63 | Baserow +14 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 57 | Baserow +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 54 | 62 | Grist +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Baserow +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 72 | 78 | Grist +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 65 | 61 | Baserow +4 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **63.6 · B** | **50.1 · D** | |\n\n## Facts side by side\n\n| Fact | Baserow | Grist |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Baserow B.V. | Grist Labs Inc. |\n| Hosted endpoint | `https://api.baserow.io` | `https://docs.getgrist.com/api` |\n| Transports | HTTP, SSE (legacy) | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0 | Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 |\n| Tools exposed | 7 | 34 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | no |\n| Last release | 2026-09-29 | 2026-09-28 |\n| Terms last updated | no date given | no date given |\n| Privacy policy last updated | no date given | 2019-04-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 6.1k stars | 12k stars, 341 npm/wk, 240 PyPI/wk |\n\n## Verdicts\n\n**Baserow.** Database tokens are limited to chosen tables and to create, read, update or delete, and the REST API has a public OpenAPI description with batch calls of 200 rows. The MCP server authenticates with a key in its URL, runs over SSE only and has no read-only mode. Cloud requests are capped at 10 at a time.\n\n**Grist.** OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.\n\n## Before you call either\n\n### Baserow\n\n1. Create a database token with only the tables and operations needed. It can't change tables or fields, which need a JWT from `/api/user/token-auth/`\n2. Send `Authorization: Token YOUR_DATABASE_TOKEN`, and add `user_field_names=true` or rows come back keyed as `field_123`\n3. Use the `/batch/` endpoints for up to 200 rows a call, and keep to 10 requests in flight on Baserow Cloud\n4. Treat the MCP URL as a password. Keep it out of logs and version control, and delete the endpoint to revoke it\n5. Over MCP, call `get_table_schema` before `create_rows` or `update_rows`, and page `list_table_rows` with `page` and `size`\n\n### Grist\n\n1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen\n2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules\n3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented\n4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row\n5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit\n\n## Questions\n\n### Which is better for AI agents, Baserow or Grist?\n\nBaserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community.\n\n### Do Baserow and Grist need an API key?\n\nBaserow needs an API key. Grist takes an API key or an OAuth sign-in.\n\n### Can an agent call Baserow and Grist without installing anything?\n\nYes. Baserow has a hosted endpoint at https://api.baserow.io and Grist at https://docs.getgrist.com/api.\n\n### Are Baserow and Grist open source?\n\nYes. Baserow is open source (MIT for the core, including the REST API and the MCP server. Code under premium/ and enterprise/ is source-available under Baserow's own licences and needs a paid subscription in production. Docs are CC BY-SA 4.0). Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/baserow-vs-grist.json, and with the fewest tokens: https://www.anchorterminal.com/compare/baserow-vs-grist.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"baserow\", \"b\": \"grist\"}`. From a terminal: `anchor compare baserow grist`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/baserow.json and https://www.anchorterminal.com/api/v1/tools/grist.json\n\n## Other comparisons with Baserow or Grist\n\n- [Baserow vs Google Sheets API](https://www.anchorterminal.com/compare/baserow-vs-google-sheets-api.md)\n- [Baserow vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph.md)\n- [Coda (Superhuman Docs) vs Grist](https://www.anchorterminal.com/compare/coda-vs-grist.md)\n- [Google Sheets API vs Grist](https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.md)\n- [Grist vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.md)\n- [Airtable vs Baserow](https://www.anchorterminal.com/compare/airtable-vs-baserow.md)\n- [Airtable vs Grist](https://www.anchorterminal.com/compare/airtable-vs-grist.md)\n- [Baserow vs Coda (Superhuman Docs)](https://www.anchorterminal.com/compare/baserow-vs-coda.md)\n- [Baserow vs NocoDB](https://www.anchorterminal.com/compare/baserow-vs-nocodb.md)\n- [Baserow vs SeaTable](https://www.anchorterminal.com/compare/baserow-vs-seatable.md)\n- [Baserow vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/baserow-vs-smartsheet.md)\n- [Baserow vs Teable](https://www.anchorterminal.com/compare/baserow-vs-teable.md)\n- [Grist vs NocoDB](https://www.anchorterminal.com/compare/grist-vs-nocodb.md)\n- [Grist vs SeaTable](https://www.anchorterminal.com/compare/grist-vs-seatable.md)\n- [Grist vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/grist-vs-smartsheet.md)\n- [Grist vs Teable](https://www.anchorterminal.com/compare/grist-vs-teable.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Baserow vs Grist",
        "url": ""
      }
    ],
    "description": "Baserow scores 63.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on security \u0026 auth and maintenance \u0026 community. Both do sheets records. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Baserow B 63.6",
      "Grist D 50.1",
      "scores"
    ],
    "h1": "Baserow vs Grist",
    "image": "https://www.anchorterminal.com/assets/og/compare-baserow-vs-grist.png",
    "path": "/compare/baserow-vs-grist",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Baserow vs Grist for AI agents, B 63.6 vs D 50.1 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/baserow-vs-grist"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
