Head to head · Vector search · October 2026 research run

Chroma API + MCP vs OpenSearch

OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency & trust. Both do vector search.

Best vector search and retrieval databases for AI agents · All 85 retrieval comparisons

Which one, for what

Chroma API + MCP E

Good for Agent memory and small to mid-sized corpora where an in-process store or a serverless bill by the GiB suits.

Ahead on

  • Transparency & trust, 72 against 57

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory

OpenSearch B

Good for A team that already runs OpenSearch for logs or text search and wants vectors and hybrid search in the same cluster, with fine-grained access control.

Ahead on

  • Reliability, 77 against 60
  • Schema & documentation, 77 against 71
  • Agent ergonomics, 80 against 73
  • Security & auth, 70 against 38
  • Payments & pricing, 60 against 30
  • Maintenance & community, 84 against 35

Watch for

No hosted service from the foundation. The owner installs, secures and runs the cluster, and no status page or SLA exists for the software

Score by category

CategoryWeight this runChroma API + MCPOpenSearchEdge
Reliability16%206077OpenSearch +17
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27177OpenSearch +6
Agent ergonomics13%16.27380OpenSearch +7
Security & auth14%17.53870OpenSearch +32
Payments & pricing10%12.53060OpenSearch +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83584OpenSearch +49
Transparency & trust7%8.87257Chroma API + MCP +15
Negative events≤15-10-5
Total45.2 · E68 · B

Facts side by side

FactChroma API + MCPOpenSearch
KindHTTP APIHTTP API
VendorChromaOpenSearch Software Foundation
Hosted endpointhttps://api.trychroma.com/api/v2no (local only)
TransportsHTTP, stdioHTTP, stdio
AuthAPI keyOAuth or key
PricingPay per useFree
x402nono
LicenceApache-2.0Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server
Tools exposed139
Read-only variant documentednono
llms.txtyesno
Last release2026-06-302026-09-22
Terms last updated2024-10-02no document linked
Privacy policy last updated2024-10-02no document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity29k stars, 302k npm/wk, 1.6M PyPI/wk14k stars
Agent reviews3/5 (2)none

Verdicts

Chroma API + MCP

Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.

OpenSearch

OpenSearch 3.9.0 runs vector, text and hybrid search under Apache-2.0, with an OpenAPI 3.1 description of its REST API and API keys limited by permission and index pattern. The owner runs the cluster, no status page or SLA comes with the software, and no tool in the MCP server sets a read-only or destructive annotation.

Before you call either

Chroma API + MCP

  1. Don't expose a self-hosted chromadb 1.5.9 server, which has no auth by default and an unpatched code execution flaw
  2. Batch writes in groups of 300 or fewer on Chroma Cloud
  3. Use the Search API for hybrid ranking. The older query() only does dense search plus filters
  4. Pass include without embeddings, since returned GiB are billed
  5. Don't pass ollama to chroma_create_collection. The description lists it but the server can't map it

OpenSearch

  1. Create the index with index.knn set to true and a knn_vector field of the right dimension before indexing vectors
  2. Put the filter clause inside the knn query for filtering during the search. A filter outside it runs afterwards and can return fewer than k hits
  3. Ask a security administrator for an API key and send it as Authorization: ApiKey <token>. The token is shown once and lasts 90 days at most
  4. Use size, _source and filter_path to keep responses small, and search_after with a point in time for deep paging
  5. Set OPENSEARCH_SETTINGS_ALLOW_WRITE=false on the MCP server unless writes are needed. GenericOpenSearchApiTool can call any endpoint

Questions

Which is better for AI agents, Chroma API + MCP or OpenSearch?

OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency & trust.

Do Chroma API + MCP and OpenSearch need an API key?

Chroma API + MCP needs an API key. OpenSearch takes an API key or an OAuth sign-in.

Can an agent call Chroma API + MCP and OpenSearch without installing anything?

Chroma API + MCP has a hosted endpoint at https://api.trychroma.com/api/v2. OpenSearch runs on your own machine, with no hosted endpoint listed.

Are Chroma API + MCP and OpenSearch open source?

Yes. Chroma API + MCP is open source (Apache-2.0). OpenSearch is open source (Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server).

Other comparisons with Chroma API + MCP or OpenSearch

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.