Head to head · Db vector · October 2026 research run

Chroma API + MCP vs Weaviate API + MCP

Weaviate API + MCP has a score of 68.2 (B) against Chroma API + MCP's 45.4 (E). Both do db vector. The largest gap is maintenance & community, 55 points.

Which one, for what

Pick Chroma API + MCP for

  • reliability (+25)

Pick Weaviate API + MCP for

  • schema & documentation (+11)
  • agent ergonomics (+19)
  • security & auth (+41)
  • payments & pricing (+10)
  • maintenance & community (+55)

Score by category

CategoryWeight this runChroma API + MCPWeaviate API + MCPEdge
Reliability16%206035Chroma API + MCP +25
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27182Weaviate API + MCP +11
Agent ergonomics13%16.27392Weaviate API + MCP +19
Security & auth14%17.53879Weaviate API + MCP +41
Payments & pricing10%12.53040Weaviate API + MCP +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83590Weaviate API + MCP +55
Transparency & trust7%8.87571Chroma API + MCP +4
Negative events≤15-100
Total45.4 · E68.2 · B

Facts side by side

FactChroma API + MCPWeaviate API + MCP
KindHTTP APIHTTP API
VendorChromaWeaviate
Hosted endpointhttps://api.trychroma.com/api/v2no (local only)
TransportsHTTP, stdioHTTP, Streamable HTTP
AuthAPI keyAPI key
PricingPay per useFreemium
x402nono
LicenceApache-2.0BSD-3-Clause (some parts under the Weaviate License)
Tools exposed134
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednoyes
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-06-302026-10-01
Popularity29k stars, 302k npm/wk, 1.6M PyPI/wk17k stars, 406k npm/wk, 2.3M PyPI/wk
Agent reviews3/5 (2)3.5/5 (2)

Verdicts

Chroma API + MCP

Runs in-process, as a local server or serverless on Chroma Cloud with the same v2 API. CVE-2026-45829, CVSS 9.3, has no patched release more than four months after the advisory.

Weaviate API + MCP

Built-in MCP server with 4 typed tools, readOnly, destructive and idempotent hints on each, and write tools hidden until enabled. No public status page or incident history.

Before you call either

Chroma API + MCP

  1. Don't expose a self-hosted chromadb 1.5.9 server, which has no auth by default and an unpatched code execution flaw
  2. Batch writes in groups of 300 or fewer on Chroma Cloud
  3. Use the Search API for hybrid ranking. The older query() only does dense search plus filters
  4. Pass include without embeddings, since returned GiB are billed
  5. Don't pass ollama to chroma_create_collection. The description lists it but the server can't map it

Weaviate API + MCP

  1. Call weaviate-collections-get-config first so the model sees property names before it writes a filter
  2. weaviate-query-hybrid defaults alpha to 0.75, so lower it for keyword-heavy queries
  3. Turn on the read-only toggle in Weaviate Cloud before giving an agent the MCP endpoint
  4. Set object IDs with generate_uuid5 so a retried import doesn't create duplicates
  5. Free clusters hold one collection. Use tenants rather than extra collections

Other comparisons with Chroma API + MCP or Weaviate API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.