{
  "data": {
    "a": {
      "slug": "chroma",
      "name": "Chroma API + MCP",
      "vendor": "Chroma",
      "vendorUrl": "https://www.trychroma.com",
      "kind": "http-api",
      "category": "vector-search",
      "summary": "Open-source retrieval database that runs in-process, as a local server or as Chroma Cloud, a serverless hosted service.",
      "url": "https://www.anchorterminal.com/tools/chroma",
      "markdownUrl": "https://www.anchorterminal.com/tools/chroma.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/chroma.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/chroma.json",
      "repo": "https://github.com/chroma-core/chroma",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.trychroma.com/api/v2",
      "packages": [
        {
          "registry": "pypi",
          "name": "chromadb"
        },
        {
          "registry": "npm",
          "name": "chromadb"
        },
        {
          "registry": "pypi",
          "name": "chroma-mcp"
        }
      ],
      "auth": "api-key",
      "authNotes": "Chroma Cloud takes an API key in the `x-chroma-token` header, scoped to a tenant and database. A local or self-hosted server runs without auth unless you configure it. The MCP server takes `--client-type cloud` with tenant, database and API key, or connects to a local or self-hosted instance.",
      "pricing": "usage",
      "pricingNotes": "Chroma Cloud Starter is $0 a month plus usage with $5 of credit, 10 databases and 10 members. Team is $250 a month plus usage with $100 of credit, 100 databases and SOC 2. Enterprise is custom, with single-tenant and BYOC clusters. Writes $2.50 per logical GiB, storage $0.33 per GiB a month, queries $0.0075 per TiB scanned plus $0.09 per GiB returned, forks $0.03 each, Sync $0.04 per GiB processed and $0.01 per page extracted or scraped. The open-source database is free to run yourself (https://www.trychroma.com/pricing).",
      "priceSummary": "$250 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402 or per-call payment support in the docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": 29413,
        "npmWeekly": 301867,
        "pypiWeekly": 1590274,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.trychroma.com",
      "llmsTxt": "https://docs.trychroma.com/llms.txt",
      "openapi": "https://api.trychroma.com/openapi.json",
      "capabilities": [
        "db.vector",
        "db.hybrid",
        "db.fulltext",
        "db.filters",
        "db.serverless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "enterprise"
      ],
      "lastRelease": "2026-06-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 45.2,
        "grade": "E",
        "agentReady": false,
        "rank": 868,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 35,
          "payments": 30,
          "reliability": 60,
          "schema": 71,
          "security": 38,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -10,
        "negativeNotes": [
          "CVE-2026-45829 (GHSA-f4j7-r4q5-qw2c), published 18 May 2026, critical with CVSS 9.3. An unauthenticated request to the collections endpoint can set `trust_remote_code` and run code on a chromadb server from 1.0.0 to 1.5.9. The fix merged to main on 7 July 2026, but no release carries it, and the advisory still lists no patched version (https://github.com/advisories/GHSA-f4j7-r4q5-qw2c, https://pypi.org/project/chromadb/#history). We found nothing saying whether Chroma Cloud was exposed, so we deduct for the unpatched self-hosted path only."
        ],
        "verdict": "Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.",
        "bestFor": "Agent memory and small to mid-sized corpora where an in-process store or a serverless bill by the GiB suits.",
        "strengths": [
          "Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API",
          "Per-unit cloud prices published, $2.50 per GiB written and $0.33 per GiB a month stored",
          "One status incident in 90 days, a 2 hour 38 minute indexing slowdown on 18 August 2026",
          "Apache-2.0, with an OpenAPI file and llms.txt over 162 Markdown pages",
          "Current source sends no product telemetry, since the PostHog client is a no-op"
        ],
        "weaknesses": [
          "CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory",
          "No tagged or published release since 30 June 2026, and the server last shipped on 5 May",
          "`chroma-mcp` last released on 14 August 2025, with 13 tools and no read-only mode or tool annotations",
          "Cloud caps of 300 results a query, 300 records a write and 10 concurrent reads per collection, with no 429 or retry guidance",
          "Privacy policy dates from October 2024 and still says the service is hosted only in the United States"
        ],
        "agentNotes": [
          "Don't expose a self-hosted chromadb 1.5.9 server, which has no auth by default and an unpatched code execution flaw",
          "Batch writes in groups of 300 or fewer on Chroma Cloud",
          "Use the Search API for hybrid ranking. The older `query()` only does dense search plus filters",
          "Pass `include` without embeddings, since returned GiB are billed",
          "Don't pass `ollama` to `chroma_create_collection`. The description lists it but the server can't map it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 45.2
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 35,
          "payments": 30,
          "reliability": 60,
          "schema": 71,
          "security": 38,
          "transparency": 68
        },
        "provenanceScore": 76
      },
      "connect": {
        "install": "pip install chromadb",
        "http": "curl -s https://api.trychroma.com/api/v2/auth/identity -H \"x-chroma-token: $CHROMA_API_KEY\"",
        "claudeCode": "claude mcp add chroma -- uvx chroma-mcp --client-type cloud --tenant $CHROMA_TENANT --database $CHROMA_DATABASE --api-key $CHROMA_API_KEY",
        "config": {
          "mcpServers": {
            "chroma": {
              "args": [
                "chroma-mcp",
                "--client-type",
                "cloud",
                "--tenant",
                "${CHROMA_TENANT}",
                "--database",
                "${CHROMA_DATABASE}",
                "--api-key",
                "${CHROMA_API_KEY}"
              ],
              "command": "uvx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.vector",
        "tool": "https://letme.dev/chroma"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 250,
          "note": "$100 of usage credit included"
        },
        {
          "item": "Writes",
          "unit": "gb",
          "usd": 2.5,
          "note": "per logical GiB written"
        },
        {
          "item": "Storage",
          "unit": "gb",
          "usd": 0.33,
          "note": "per GiB a month"
        },
        {
          "item": "Data returned by queries",
          "unit": "gb",
          "usd": 0.09,
          "note": "plus $0.0075 per TiB scanned"
        },
        {
          "item": "Collection fork",
          "unit": "call",
          "usd": 0.03
        },
        {
          "item": "Sync processing",
          "unit": "gb",
          "usd": 0.04,
          "note": "plus $0.01 per page extracted or scraped"
        }
      ],
      "provenance": {
        "legalEntity": "Chroma Inc.",
        "domain": "trychroma.com",
        "domainRegistered": "2022-03-23",
        "endpointOnVendorDomain": true,
        "terms": "https://www.trychroma.com/terms",
        "privacy": "https://www.trychroma.com/privacy",
        "statusPage": "https://status.trychroma.com",
        "changelog": "https://www.trychroma.com/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/chroma.json",
      "live": {
        "slug": "chroma",
        "probe": {
          "target": "https://api.trychroma.com/api/v2",
          "method": "get",
          "lastAt": "2026-10-10T04:40:45.496208034Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 254,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 259,
          "p95ms24h": 316,
          "samples24h": 248,
          "samples30d": 2484,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 48,
              "ok": 48
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.trychroma.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:12.766184264Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "chroma-core/chroma",
            "version": "1.5.9",
            "released": "2026-05-05",
            "seenAt": "2026-10-09T16:45:01.678344519Z"
          },
          {
            "registry": "npm",
            "name": "chromadb",
            "version": "3.5.0",
            "seenAt": "2026-10-09T16:44:59.676771725Z"
          },
          {
            "registry": "pypi",
            "name": "chroma-mcp",
            "version": "0.2.6",
            "released": "2025-08-14",
            "seenAt": "2026-10-09T16:45:00.544385972Z"
          },
          {
            "registry": "pypi",
            "name": "chromadb",
            "version": "1.5.9",
            "released": "2026-05-05",
            "seenAt": "2026-10-09T16:44:59.550427485Z"
          }
        ],
        "githubStars": 29472,
        "npmWeekly": 234224,
        "pypiWeekly": 1691401,
        "securityTxt": {
          "url": "https://trychroma.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:22.719900658Z"
        },
        "llmsTxt": {
          "url": "https://docs.trychroma.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:01:35.610157292Z"
        },
        "domain": {
          "domain": "trychroma.com",
          "registered": "2022-03-23",
          "source": "https://rdap.verisign.com/com/v1/domain/trychroma.com",
          "checkedAt": "2026-10-04T13:09:39.725378578Z"
        },
        "pages": [
          {
            "url": "https://www.trychroma.com/changelog",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:05.794041048Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "301154ea7374"
          },
          {
            "url": "https://www.trychroma.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:07.971860551Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "677e379ceb9f"
          },
          {
            "url": "https://www.trychroma.com/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:09.96876324Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "489e02b4f673"
          },
          {
            "url": "https://www.trychroma.com/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:11.985604301Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "78c6afbde487"
          }
        ],
        "updatedAt": "2026-10-10T04:40:45.496208034Z"
      }
    },
    "answer": "OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency \u0026 trust.",
    "b": {
      "slug": "opensearch",
      "name": "OpenSearch",
      "vendor": "OpenSearch Software Foundation",
      "vendorUrl": "https://opensearch.org",
      "kind": "http-api",
      "category": "vector-search",
      "summary": "OpenSearch is an open-source search and analytics engine with vector, text and hybrid search, run by its owner. Agents reach it through a REST API, official clients, an OpenSearch MCP Server and an MCP endpoint inside the cluster.",
      "url": "https://www.anchorterminal.com/tools/opensearch",
      "markdownUrl": "https://www.anchorterminal.com/tools/opensearch.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opensearch.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opensearch.json",
      "repo": "https://github.com/opensearch-project/OpenSearch",
      "license": "Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "opensearchproject/opensearch"
        },
        {
          "registry": "pypi",
          "name": "opensearch-mcp-server-py"
        },
        {
          "registry": "pypi",
          "name": "opensearch-py"
        }
      ],
      "auth": "mixed",
      "authNotes": "The owner sets access up on their own cluster. The Security plugin accepts basic auth, client certificates, JWT, OpenID Connect and SAML, and since 3.7 API keys sent as `Authorization: ApiKey \u003ctoken\u003e`. Only a security administrator can create, list or revoke a key. Each key names cluster permissions and index patterns with allowed actions, lasts 90 days at most, and cannot reach system indexes or the Security API. API keys are off until enabled in `config.yml`. The MCP server takes basic auth, AWS IAM, request headers or mTLS, or no authentication.",
      "pricing": "free",
      "pricingNotes": "Free software under Apache-2.0 with nothing to buy from the foundation, so an agent can start on a local Docker container with no account or contract. The owner pays for the machines. Three certified vendors sell long-term support, and opensearch.org lists no price for it (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation source, the API specification or the MCP server source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": 13800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.opensearch.org/latest/vector-search/",
      "openapi": "https://api-spec.opensearch.org/opensearch-openapi.yaml",
      "capabilities": [
        "db.vector",
        "db.hybrid",
        "db.fulltext",
        "db.filters"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "mcp",
        "docker",
        "openapi",
        "api-key",
        "python",
        "javascript",
        "java",
        "go",
        "free"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 233,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 84,
          "payments": 60,
          "reliability": 77,
          "schema": 77,
          "security": 70,
          "transparency": 57
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "Until 0.12.0 (fix merged 3 August 2026, released 17 September 2026) the OpenSearch MCP Server attached its own configured credentials to any cluster URL a caller named in dynamic connection mode, which had shipped in 0.10.0 on 2 June 2026. The fix is described in the changelog and commit, and the repository lists no published advisory. Three points (https://github.com/opensearch-project/opensearch-mcp-server-py/blob/main/CHANGELOG.md).",
          "The Security plugin published four advisories on 30 April 2026, one moderate (GHSA-x83w-23jp-g6pw, document-level security not applied to documents linked by `has_child` or `has_parent`) and three low. Fixed and disclosed, so two points (https://github.com/opensearch-project/security/security/advisories)."
        ],
        "verdict": "OpenSearch 3.9.0 runs vector, text and hybrid search under Apache-2.0, with an OpenAPI 3.1 description of its REST API and API keys limited by permission and index pattern. The owner runs the cluster, no status page or SLA comes with the software, and no tool in the MCP server sets a read-only or destructive annotation.",
        "bestFor": "A team that already runs OpenSearch for logs or text search and wants vectors and hybrid search in the same cluster, with fine-grained access control.",
        "strengths": [
          "Apache-2.0 for the engine, the plugins, the clients and the MCP server, under a foundation hosted by The Linux Foundation",
          "An OpenAPI 3.1 description of the REST API is published as one file, with about 717 operations in 36 namespace files in the source repository",
          "API keys since 3.7 carry cluster and index permissions, expire within 90 days at most, and are revoked on every node at once",
          "Approximate k-NN with filters applied during the search on the Lucene and Faiss engines, plus hybrid and neural sparse search",
          "Releases follow a published schedule about every eight weeks. 3.8.0 was tagged on 31 July and 3.9.0 on 22 September 2026"
        ],
        "weaknesses": [
          "No hosted service from the foundation. The owner installs, secures and runs the cluster, and no status page or SLA exists for the software",
          "No `llms.txt` on docs.opensearch.org (HTTP 404), and doc pages carry about 160 KB of navigation text each",
          "The MCP server allows writes by default (`OPENSEARCH_SETTINGS_ALLOW_WRITE` is `true`) and no tool sets `readOnlyHint` or `destructiveHint`",
          "Before version 0.12.0 the MCP server sent its own configured credentials to any cluster URL a caller named. No advisory was published",
          "The core repository shows about 2,500 open issues, and 21 of the 25 newest carried the `untriaged` label on 9 October 2026"
        ],
        "agentNotes": [
          "Create the index with `index.knn` set to true and a `knn_vector` field of the right dimension before indexing vectors",
          "Put the `filter` clause inside the `knn` query for filtering during the search. A filter outside it runs afterwards and can return fewer than `k` hits",
          "Ask a security administrator for an API key and send it as `Authorization: ApiKey \u003ctoken\u003e`. The token is shown once and lasts 90 days at most",
          "Use `size`, `_source` and `filter_path` to keep responses small, and `search_after` with a point in time for deep paging",
          "Set `OPENSEARCH_SETTINGS_ALLOW_WRITE=false` on the MCP server unless writes are needed. `GenericOpenSearchApiTool` can call any endpoint"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 84,
          "payments": 60,
          "reliability": 77,
          "schema": 77,
          "security": 70,
          "transparency": 69
        },
        "provenanceScore": 45
      },
      "connect": {
        "install": "docker run -d -p 9200:9200 -p 9600:9600 -e \"discovery.type=single-node\" -e \"OPENSEARCH_INITIAL_ADMIN_PASSWORD=\u003ccustom-admin-password\u003e\" opensearchproject/opensearch:latest",
        "http": "curl https://localhost:9200 -ku admin:\"\u003ccustom-admin-password\u003e\"",
        "config": {
          "mcpServers": {
            "opensearch": {
              "args": [
                "opensearch-mcp-server-py"
              ],
              "command": "uvx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.vector",
        "tool": "https://letme.dev/opensearch"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "OpenSearch Software Foundation, a project of The Linux Foundation",
        "domain": "opensearch.org",
        "domainRegistered": "2003-05-15",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://docs.opensearch.org/latest/version-history/",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The foundation page says the OpenSearch Software Foundation is a project of The Linux Foundation and is not involved in technical oversight of the open source project.",
          "No terms or privacy document is set. The site footer links The Linux Foundation's general terms and privacy policy, which are a parent body's website notices. The Apache-2.0 licence stands in for the software.",
          "The software runs on the owner's machines, so no endpoint is on the vendor's domain and there is no status page.",
          "https://opensearch.org/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` in the core repository asks for reports by email to security@opensearch.org.",
          "RDAP for opensearch.org gives a registration date of 2003-05-15 and a transfer on 13 November 2024.",
          "The first release date is the 1.0 general availability date in the maintenance table on the releases page."
        ],
        "score": 45
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opensearch.json",
      "live": {
        "slug": "opensearch",
        "versions": [
          {
            "registry": "github",
            "name": "opensearch-project/OpenSearch",
            "version": "3.9.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-09T17:11:12.76716689Z"
          },
          {
            "registry": "pypi",
            "name": "opensearch-mcp-server-py",
            "version": "0.12.0",
            "released": "2026-09-17",
            "seenAt": "2026-10-09T17:11:10.759906653Z"
          },
          {
            "registry": "pypi",
            "name": "opensearch-py",
            "version": "3.2.0",
            "released": "2026-04-27",
            "seenAt": "2026-10-09T17:11:10.949518654Z"
          }
        ],
        "githubStars": 13832,
        "pypiWeekly": 75145,
        "pages": [
          {
            "url": "https://docs.opensearch.org/latest/version-history/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:58.648544982Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9aa4527e824d"
          }
        ],
        "updatedAt": "2026-10-09T18:37:58.648544982Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Chroma",
        "b": "OpenSearch Software Foundation",
        "name": "Vendor"
      },
      {
        "a": "https://api.trychroma.com/api/v2",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server",
        "name": "Licence"
      },
      {
        "a": "13",
        "b": "9",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-06-30",
        "b": "2026-09-22",
        "name": "Last release"
      },
      {
        "a": "2024-10-02",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2024-10-02",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "29k stars, 302k npm/wk, 1.6M PyPI/wk",
        "b": "14k stars",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Chroma API + MCP or OpenSearch?"
      },
      {
        "answer": "Chroma API + MCP needs an API key. OpenSearch takes an API key or an OAuth sign-in.",
        "question": "Do Chroma API + MCP and OpenSearch need an API key?"
      },
      {
        "answer": "Chroma API + MCP has a hosted endpoint at https://api.trychroma.com/api/v2. OpenSearch runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Chroma API + MCP and OpenSearch without installing anything?"
      },
      {
        "answer": "Yes. Chroma API + MCP is open source (Apache-2.0). OpenSearch is open source (Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server).",
        "question": "Are Chroma API + MCP and OpenSearch open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Transparency \u0026 trust, 72 against 57"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agent memory and small to mid-sized corpora where an in-process store or a serverless bill by the GiB suits.",
        "slug": "chroma",
        "watchFor": "CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory"
      },
      {
        "aheadOn": [
          "Reliability, 77 against 60",
          "Schema \u0026 documentation, 77 against 71",
          "Agent ergonomics, 80 against 73",
          "Security \u0026 auth, 70 against 38",
          "Payments \u0026 pricing, 60 against 30",
          "Maintenance \u0026 community, 84 against 35"
        ],
        "also": null,
        "goodFor": "A team that already runs OpenSearch for logs or text search and wants vectors and hybrid search in the same cluster, with fine-grained access control.",
        "slug": "opensearch",
        "watchFor": "No hosted service from the foundation. The owner installs, secures and runs the cluster, and no status page or SLA exists for the software"
      }
    ],
    "job": {
      "capability": "db.vector",
      "name": "Vector search"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-elasticsearch.json",
        "title": "Chroma API + MCP vs Elasticsearch",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-elasticsearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-epsilla.json",
        "title": "Chroma API + MCP vs Epsilla Vector Database",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-epsilla"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-lancedb.json",
        "title": "Chroma API + MCP vs LanceDB",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-lancedb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-meilisearch.json",
        "title": "Chroma API + MCP vs Meilisearch",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-meilisearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-milvus-zilliz.json",
        "title": "Chroma API + MCP vs Milvus and Zilliz Cloud API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-milvus-zilliz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-pinecone.json",
        "title": "Chroma API + MCP vs Pinecone API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-pinecone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-qdrant.json",
        "title": "Chroma API + MCP vs Qdrant API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-qdrant"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-typesense.json",
        "title": "Chroma API + MCP vs Typesense API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-typesense"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-upstash-vector.json",
        "title": "Chroma API + MCP vs Upstash Vector API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-upstash-vector"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-vespa.json",
        "title": "Chroma API + MCP vs Vespa",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-vespa"
      },
      {
        "json": "https://www.anchorterminal.com/compare/chroma-vs-weaviate.json",
        "title": "Chroma API + MCP vs Weaviate API + MCP",
        "url": "https://www.anchorterminal.com/compare/chroma-vs-weaviate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elasticsearch-vs-opensearch.json",
        "title": "Elasticsearch vs OpenSearch",
        "url": "https://www.anchorterminal.com/compare/elasticsearch-vs-opensearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/epsilla-vs-opensearch.json",
        "title": "Epsilla Vector Database vs OpenSearch",
        "url": "https://www.anchorterminal.com/compare/epsilla-vs-opensearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lancedb-vs-opensearch.json",
        "title": "LanceDB vs OpenSearch",
        "url": "https://www.anchorterminal.com/compare/lancedb-vs-opensearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/meilisearch-vs-opensearch.json",
        "title": "Meilisearch vs OpenSearch",
        "url": "https://www.anchorterminal.com/compare/meilisearch-vs-opensearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/milvus-zilliz-vs-opensearch.json",
        "title": "Milvus and Zilliz Cloud API + MCP vs OpenSearch",
        "url": "https://www.anchorterminal.com/compare/milvus-zilliz-vs-opensearch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-pinecone.json",
        "title": "OpenSearch vs Pinecone API + MCP",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-pinecone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-qdrant.json",
        "title": "OpenSearch vs Qdrant API + MCP",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-qdrant"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-typesense.json",
        "title": "OpenSearch vs Typesense API + MCP",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-typesense"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-upstash-vector.json",
        "title": "OpenSearch vs Upstash Vector API + MCP",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-upstash-vector"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-vespa.json",
        "title": "OpenSearch vs Vespa",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-vespa"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opensearch-vs-weaviate.json",
        "title": "OpenSearch vs Weaviate API + MCP",
        "url": "https://www.anchorterminal.com/compare/opensearch-vs-weaviate"
      }
    ],
    "scores": [
      {
        "by": 17,
        "chroma": 60,
        "edge": "opensearch",
        "key": "reliability",
        "name": "Reliability",
        "opensearch": 77,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "chroma": 71,
        "edge": "opensearch",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "opensearch": 77,
        "weight": 13
      },
      {
        "by": 7,
        "chroma": 73,
        "edge": "opensearch",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "opensearch": 80,
        "weight": 13
      },
      {
        "by": 32,
        "chroma": 38,
        "edge": "opensearch",
        "key": "security",
        "name": "Security \u0026 auth",
        "opensearch": 70,
        "weight": 14
      },
      {
        "by": 30,
        "chroma": 30,
        "edge": "opensearch",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "opensearch": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 49,
        "chroma": 35,
        "edge": "opensearch",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "opensearch": 84,
        "weight": 7
      },
      {
        "by": 15,
        "chroma": 72,
        "edge": "chroma",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "opensearch": 57,
        "weight": 7
      }
    ],
    "summary": "OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency \u0026 trust. Both do vector search.",
    "verdicts": {
      "chroma": "Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.",
      "opensearch": "OpenSearch 3.9.0 runs vector, text and hybrid search under Apache-2.0, with an OpenAPI 3.1 description of its REST API and API keys limited by permission and index pattern. The owner runs the cluster, no status page or SLA comes with the software, and no tool in the MCP server sets a read-only or destructive annotation."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/chroma-vs-opensearch",
    "json": "https://www.anchorterminal.com/compare/chroma-vs-opensearch.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/chroma-vs-opensearch.md",
    "slim": "https://www.anchorterminal.com/compare/chroma-vs-opensearch.min.md"
  },
  "markdown": "OpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency \u0026 trust. Both do vector search.\n\n- Chroma API + MCP: grade E, 45.2/100, rank #868 of 950. Markdown https://www.anchorterminal.com/tools/chroma.md · JSON https://www.anchorterminal.com/api/v1/tools/chroma.json\n- OpenSearch: grade B, 68/100, rank #233 of 950. Markdown https://www.anchorterminal.com/tools/opensearch.md · JSON https://www.anchorterminal.com/api/v1/tools/opensearch.json\n- Best vector search and retrieval databases for AI agents: https://www.anchorterminal.com/best/vector-search/index.md\n- All 85 retrieval comparisons: https://www.anchorterminal.com/compare/vector-search/index.md\n\n## Which one, for what\n\n### Chroma API + MCP (E)\n\nGood for: Agent memory and small to mid-sized corpora where an in-process store or a serverless bill by the GiB suits.\n\nAhead on:\n- Transparency \u0026 trust, 72 against 57\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory\n\n### OpenSearch (B)\n\nGood for: A team that already runs OpenSearch for logs or text search and wants vectors and hybrid search in the same cluster, with fine-grained access control.\n\nAhead on:\n- Reliability, 77 against 60\n- Schema \u0026 documentation, 77 against 71\n- Agent ergonomics, 80 against 73\n- Security \u0026 auth, 70 against 38\n- Payments \u0026 pricing, 60 against 30\n- Maintenance \u0026 community, 84 against 35\n\nWatch for: No hosted service from the foundation. The owner installs, secures and runs the cluster, and no status page or SLA exists for the software\n\n\n## Score by category\n\n| Category | Weight | Chroma API + MCP | OpenSearch | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 77 | OpenSearch +17 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 71 | 77 | OpenSearch +6 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 80 | OpenSearch +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 38 | 70 | OpenSearch +32 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 60 | OpenSearch +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 35 | 84 | OpenSearch +49 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 57 | Chroma API + MCP +15 |\n| Negative events | ≤15 | -10 | -5 | |\n| **Total** | | **45.2 · E** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Chroma API + MCP | OpenSearch |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Chroma | OpenSearch Software Foundation |\n| Hosted endpoint | `https://api.trychroma.com/api/v2` | no (local only) |\n| Transports | HTTP, stdio | HTTP, stdio |\n| Auth | API key | OAuth or key |\n| Pricing | Pay per use | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server |\n| Tools exposed | 13 | 9 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-06-30 | 2026-09-22 |\n| Terms last updated | 2024-10-02 | no document linked |\n| Privacy policy last updated | 2024-10-02 | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 29k stars, 302k npm/wk, 1.6M PyPI/wk | 14k stars |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Chroma API + MCP.** Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.\n\n**OpenSearch.** OpenSearch 3.9.0 runs vector, text and hybrid search under Apache-2.0, with an OpenAPI 3.1 description of its REST API and API keys limited by permission and index pattern. The owner runs the cluster, no status page or SLA comes with the software, and no tool in the MCP server sets a read-only or destructive annotation.\n\n## Before you call either\n\n### Chroma API + MCP\n\n1. Don't expose a self-hosted chromadb 1.5.9 server, which has no auth by default and an unpatched code execution flaw\n2. Batch writes in groups of 300 or fewer on Chroma Cloud\n3. Use the Search API for hybrid ranking. The older `query()` only does dense search plus filters\n4. Pass `include` without embeddings, since returned GiB are billed\n5. Don't pass `ollama` to `chroma_create_collection`. The description lists it but the server can't map it\n\n### OpenSearch\n\n1. Create the index with `index.knn` set to true and a `knn_vector` field of the right dimension before indexing vectors\n2. Put the `filter` clause inside the `knn` query for filtering during the search. A filter outside it runs afterwards and can return fewer than `k` hits\n3. Ask a security administrator for an API key and send it as `Authorization: ApiKey \u003ctoken\u003e`. The token is shown once and lasts 90 days at most\n4. Use `size`, `_source` and `filter_path` to keep responses small, and `search_after` with a point in time for deep paging\n5. Set `OPENSEARCH_SETTINGS_ALLOW_WRITE=false` on the MCP server unless writes are needed. `GenericOpenSearchApiTool` can call any endpoint\n\n## Questions\n\n### Which is better for AI agents, Chroma API + MCP or OpenSearch?\n\nOpenSearch scores 68 (B) on agent readiness against Chroma API + MCP's 45.2 (E), and leads in 6 of 7 scored categories. Chroma API + MCP leads on transparency \u0026 trust.\n\n### Do Chroma API + MCP and OpenSearch need an API key?\n\nChroma API + MCP needs an API key. OpenSearch takes an API key or an OAuth sign-in.\n\n### Can an agent call Chroma API + MCP and OpenSearch without installing anything?\n\nChroma API + MCP has a hosted endpoint at https://api.trychroma.com/api/v2. OpenSearch runs on your own machine, with no hosted endpoint listed.\n\n### Are Chroma API + MCP and OpenSearch open source?\n\nYes. Chroma API + MCP is open source (Apache-2.0). OpenSearch is open source (Apache-2.0 for the engine, the plugins, the clients, the API specification and the MCP server).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/chroma-vs-opensearch.json, and with the fewest tokens: https://www.anchorterminal.com/compare/chroma-vs-opensearch.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"chroma\", \"b\": \"opensearch\"}`. From a terminal: `anchor compare chroma opensearch`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/chroma.json and https://www.anchorterminal.com/api/v1/tools/opensearch.json\n\n## Other comparisons with Chroma API + MCP or OpenSearch\n\n- [Chroma API + MCP vs Elasticsearch](https://www.anchorterminal.com/compare/chroma-vs-elasticsearch.md)\n- [Chroma API + MCP vs Epsilla Vector Database](https://www.anchorterminal.com/compare/chroma-vs-epsilla.md)\n- [Chroma API + MCP vs LanceDB](https://www.anchorterminal.com/compare/chroma-vs-lancedb.md)\n- [Chroma API + MCP vs Meilisearch](https://www.anchorterminal.com/compare/chroma-vs-meilisearch.md)\n- [Chroma API + MCP vs Milvus and Zilliz Cloud API + MCP](https://www.anchorterminal.com/compare/chroma-vs-milvus-zilliz.md)\n- [Chroma API + MCP vs Pinecone API + MCP](https://www.anchorterminal.com/compare/chroma-vs-pinecone.md)\n- [Chroma API + MCP vs Qdrant API + MCP](https://www.anchorterminal.com/compare/chroma-vs-qdrant.md)\n- [Chroma API + MCP vs Typesense API + MCP](https://www.anchorterminal.com/compare/chroma-vs-typesense.md)\n- [Chroma API + MCP vs Upstash Vector API + MCP](https://www.anchorterminal.com/compare/chroma-vs-upstash-vector.md)\n- [Chroma API + MCP vs Vespa](https://www.anchorterminal.com/compare/chroma-vs-vespa.md)\n- [Chroma API + MCP vs Weaviate API + MCP](https://www.anchorterminal.com/compare/chroma-vs-weaviate.md)\n- [Elasticsearch vs OpenSearch](https://www.anchorterminal.com/compare/elasticsearch-vs-opensearch.md)\n- [Epsilla Vector Database vs OpenSearch](https://www.anchorterminal.com/compare/epsilla-vs-opensearch.md)\n- [LanceDB vs OpenSearch](https://www.anchorterminal.com/compare/lancedb-vs-opensearch.md)\n- [Meilisearch vs OpenSearch](https://www.anchorterminal.com/compare/meilisearch-vs-opensearch.md)\n- [Milvus and Zilliz Cloud API + MCP vs OpenSearch](https://www.anchorterminal.com/compare/milvus-zilliz-vs-opensearch.md)\n- [OpenSearch vs Pinecone API + MCP](https://www.anchorterminal.com/compare/opensearch-vs-pinecone.md)\n- [OpenSearch vs Qdrant API + MCP](https://www.anchorterminal.com/compare/opensearch-vs-qdrant.md)\n- [OpenSearch vs Typesense API + MCP](https://www.anchorterminal.com/compare/opensearch-vs-typesense.md)\n- [OpenSearch vs Upstash Vector API + MCP](https://www.anchorterminal.com/compare/opensearch-vs-upstash-vector.md)\n- [OpenSearch vs Vespa](https://www.anchorterminal.com/compare/opensearch-vs-vespa.md)\n- [OpenSearch vs Weaviate API + MCP](https://www.anchorterminal.com/compare/opensearch-vs-weaviate.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Chroma API + MCP vs OpenSearch",
        "url": ""
      }
    ],
    "description": "OpenSearch scores 68 (B) to Chroma's 45.2 (E) for vector search. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Chroma API + MCP E 45.2",
      "OpenSearch B 68",
      "scores"
    ],
    "h1": "Chroma API + MCP vs OpenSearch",
    "image": "https://www.anchorterminal.com/assets/og/compare-chroma-vs-opensearch.png",
    "path": "/compare/chroma-vs-opensearch",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Chroma vs OpenSearch for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/chroma-vs-opensearch"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
