Head to head · Db vector · October 2026 research run

Chroma API + MCP vs Elasticsearch

Elasticsearch scores 67.7 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Both do db vector.

Which one, for what

Chroma API + MCP E

Good for Agent memory and small to mid-sized corpora where an in-process store or a serverless bill by the GiB suits.

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine

Watch for

CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory

Elasticsearch B

Good for Retrieval that needs keyword relevance, filters and vectors in one query, and teams already running Elastic for logs or security.

Ahead on

  • Schema & documentation, 88 against 71
  • Security & auth, 72 against 38
  • Payments & pricing, 35 against 30
  • Maintenance & community, 83 against 35

Also in its favour

  • Free to start without a card

Watch for

More than 20 status notices marked major between 10 July and 8 October 2026, three of them regional service incidents

Score by category

CategoryWeight this runChroma API + MCPElasticsearchEdge
Reliability16%206062Elasticsearch +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27188Elasticsearch +17
Agent ergonomics13%16.27377Elasticsearch +4
Security & auth14%17.53872Elasticsearch +34
Payments & pricing10%12.53035Elasticsearch +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83583Elasticsearch +48
Transparency & trust7%8.87271Chroma API + MCP +1
Negative events≤15-10-2
Total45.2 · E67.7 · B

Facts side by side

FactChroma API + MCPElasticsearch
KindHTTP APIHTTP API
VendorChromaElastic
Hosted endpointhttps://api.trychroma.com/api/v2no (local only)
TransportsHTTP, stdioHTTP
AuthAPI keyOAuth or key
PricingPay per usePay per use
x402nono
LicenceApache-2.0AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0 at the user's choice for most source. The x-pack folder is under Elastic Licence 2.0 only. Elastic Cloud is a proprietary service under Elastic's terms
Tools exposed13none
Read-only variant documentednono
llms.txtyesyes
Last release2026-06-302026-10-06
Terms last updated2024-10-02couldn't be read
Privacy policy last updated2024-10-022026-09-07
Customer content may train modelsnot found in the textcouldn't be read
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingyescouldn't be read
Terms or service can change without noticeyescouldn't be read
Arbitration or class-action waiveryescouldn't be read
Popularity29k stars, 302k npm/wk, 1.6M PyPI/wk3.1M npm/wk, 7.8M PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Chroma API + MCP

Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.

Elasticsearch

Keyword, dense and sparse vector, and hybrid search with rank fusion sit behind one OpenAPI-described REST API, with API keys scoped to indices and privileges. The status page lists more than 20 incidents marked major since July 2026, and Elasticsearch 9.5.0 returned incorrect results for some queries without raising an error.

Before you call either

Chroma API + MCP

  1. Don't expose a self-hosted chromadb 1.5.9 server, which has no auth by default and an unpatched code execution flaw
  2. Batch writes in groups of 300 or fewer on Chroma Cloud
  3. Use the Search API for hybrid ranking. The older query() only does dense search plus filters
  4. Pass include without embeddings, since returned GiB are billed
  5. Don't pass ollama to chroma_create_collection. The description lists it but the server can't map it

Elasticsearch

  1. Send Authorization: ApiKey <key> to the project's Elasticsearch URL. The MCP server is on the Kibana URL at /api/agent_builder/mcp
  2. Create the MCP key with feature_agentBuilder.read and only the index patterns needed, or the endpoint answers 403
  3. On 429, wait and retry with exponential backoff. Do not set short client timeouts, because a retried request joins the back of the queue
  4. Page past 10,000 hits with search_after, not from and size
  5. Tool calls made directly through the Tools API skip Agent Builder's confirmation prompts, so restrict the key instead

Questions

Which is better for AI agents, Chroma API + MCP or Elasticsearch?

Elasticsearch scores 67.7 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories.

Do Chroma API + MCP and Elasticsearch need an API key?

Chroma API + MCP needs an API key. Elasticsearch takes an API key or an OAuth sign-in.

Can an agent call Chroma API + MCP and Elasticsearch without installing anything?

Chroma API + MCP has a hosted endpoint at https://api.trychroma.com/api/v2. No hosted endpoint is listed for Elasticsearch.

Are Chroma API + MCP and Elasticsearch open source?

Yes. Chroma API + MCP is open source (Apache-2.0). Elasticsearch is open source (AGPL-3.0, SSPL-1.0 or Elastic Licence 2.0 at the user's choice for most source. The `x-pack` folder is under Elastic Licence 2.0 only. Elastic Cloud is a proprietary service under Elastic's terms).

Other comparisons with Chroma API + MCP or Elasticsearch

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.