{
  "data": {
    "a": {
      "slug": "coda",
      "name": "Coda (Superhuman Docs)",
      "vendor": "Superhuman Platform Inc.",
      "vendorUrl": "https://coda.io",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta.",
      "url": "https://www.anchorterminal.com/tools/coda",
      "markdownUrl": "https://www.anchorterminal.com/tools/coda.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/coda.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/coda.json",
      "repo": "https://github.com/coda/packs-sdk",
      "license": "Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://coda.io/apis/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@codahq/packs-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes `Authorization: Bearer \u003capi_token\u003e`, a token a signed-in user creates under account settings. A token can do everything its owner can unless it is created with restrictions, which limit it to one doc or one table and to read, write or both. The MCP server at https://coda.io/apis/mcp takes OAuth (authorisation code grant with PKCE S256, dynamic client registration, one scope `mcp:all`) or an API token created with the MCP restriction, per a staff reply on the vendor's community forum. Access is self-serve with no app review.",
      "pricing": "freemium",
      "pricingNotes": "The API is free on free and paid workspaces, so an agent can start on the Free plan without a contract. Suite prices as shown to our UK request on 8 October 2026 were Free £0, Pro £10 a member a month billed yearly (£12 monthly), Business £28 (£33 monthly) and Enterprise by quote (https://superhuman.com/plans). MCP is included on paid plans, and Free accounts get read-only MCP access capped at 30 requests a week and 60 a month. US dollar prices and the Docs-only plan table were not readable.",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI description or the plans page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 10270,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://coda.io/developers/apis/v1",
      "openapi": "https://coda.io/apis/v1/openapi.json",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.records",
        "sheets.formulas",
        "work.docs"
      ],
      "tags": [
        "official",
        "hosted",
        "closed-source",
        "freemium",
        "free-tier",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "status-page",
        "bug-bounty",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 270,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 72,
          "payments": 30,
          "reliability": 81,
          "schema": 76,
          "security": 71,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "24 September 2026 (date approximate per the vendor). The MCP changelog records chart `viewLayout` values renamed so the old ones are no longer valid, and `table_columns_manage` restructured, both marked as documented after shipping. The MCP server is in beta and its tools page warns that names can change, so the deduction is the minimum, 3 (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3)."
        ],
        "verdict": "API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.",
        "bestFor": "Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.",
        "strengths": [
          "API tokens can be restricted to one doc or one table, and to read or write access",
          "Public OpenAPI 3.0 description in JSON and YAML, 125 operations, all with descriptions and 429 documented on 124",
          "Rate limits are published with numbers, 100 reads and 10 writes per 6 seconds per user",
          "Hosted MCP server with 34 tools, OAuth with PKCE and dynamic client registration, and a dated changelog",
          "Public bug bounty on HackerOne, ISO 27001, 27017 and 27018 certificates, SOC 2 Type 2 and a SOC 3 report"
        ],
        "weaknesses": [
          "Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale",
          "No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message",
          "No official client libraries apart from a Google Apps Script library",
          "The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped",
          "MCP OAuth has one scope, `mcp:all`, and no confirmation step was found for `document_delete` or `table_delete`",
          "security.txt on coda.io expired on 31 December 2024"
        ],
        "agentNotes": [
          "Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail",
          "Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind",
          "Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate",
          "Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can",
          "Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 72,
          "payments": 30,
          "reliability": 81,
          "schema": 76,
          "security": 71,
          "transparency": 65
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl -s -H \"Authorization: Bearer $CODA_API_TOKEN\" \"https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25\u0026valueFormat=simpleWithArrays\"",
        "config": {
          "mcpServers": {
            "coda": {
              "url": "https://coda.io/apis/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sheets.read",
        "tool": "https://letme.dev/coda"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Superhuman Platform Inc. (parent of Coda Project LLC)",
        "domain": "coda.io",
        "domainRegistered": "2012-05-22",
        "endpointOnVendorDomain": true,
        "terms": "https://superhuman.com/legal/terms",
        "privacy": "https://superhuman.com/legal/privacy-policy",
        "statusPage": "https://status.coda.io",
        "changelog": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 29 October 2025) are an agreement with Superhuman Platform Inc., 2261 Market Street STE 85232, San Francisco, CA 94114, and call it the parent company of Coda Project LLC and Superhuman Labs LLC.",
          "The privacy policy (effective 6 July 2026) describes Superhuman Platform Inc. as formerly Grammarly, with Grammarly Inc. and Coda Project LLC as subsidiaries.",
          "coda.io/trust/tos, /trust/privacy, /trust/dpa and /trust/subprocessor redirect to superhuman.com/legal. coda.io/developers/apis/v1 redirects to docs.superhuman.com.",
          "The API and the MCP server answer on coda.io and on docs.superhuman.com. The OAuth metadata names https://coda.io as issuer.",
          "coda.io/.well-known/security.txt points to the HackerOne programme and carries Expires 2024-12-31. superhuman.com/.well-known/security.txt returns 404.",
          "The registry's RDAP record for coda.io gives a registration date of 2012-05-22 and Gandi SAS as registrar.",
          "The changelog link is the MCP server's. The REST API's update log at docs.superhuman.com/api-updates needs JavaScript and was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/coda.json",
      "live": {
        "slug": "coda",
        "probe": {
          "target": "https://coda.io/apis/v1",
          "method": "get",
          "lastAt": "2026-10-08T21:53:19.337557115Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 182,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 187,
          "p95ms24h": 229,
          "samples24h": 71,
          "samples30d": 71,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 71,
              "ok": 71
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.coda.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:47.226325138Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "coda/packs-sdk",
            "version": "v1.18.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:06:05.16888764Z"
          },
          {
            "registry": "npm",
            "name": "@codahq/packs-sdk",
            "version": "1.18.0",
            "seenAt": "2026-10-08T16:06:01.042367623Z"
          }
        ],
        "githubStars": 112,
        "npmWeekly": 10270,
        "securityTxt": {
          "url": "https://coda.io/.well-known/security.txt",
          "state": "expired",
          "expires": "2024-12-31T20:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:55.777108046Z"
        },
        "pages": [
          {
            "url": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
            "kind": "changelog",
            "status": 0,
            "checkedAt": "2026-10-08T18:19:33.846152714Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          },
          {
            "url": "https://superhuman.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:58.353462251Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "247a8f92d92b"
          },
          {
            "url": "https://superhuman.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:00.904608476Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b95766421539"
          }
        ],
        "updatedAt": "2026-10-08T21:57:47.226325138Z"
      }
    },
    "answer": "Coda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community.",
    "b": {
      "slug": "grist",
      "name": "Grist",
      "vendor": "Grist Labs Inc.",
      "vendorUrl": "https://www.getgrist.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/grist",
      "markdownUrl": "https://www.anchorterminal.com/tools/grist.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/grist.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/grist.json",
      "repo": "https://github.com/gristlabs/grist-core",
      "license": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://docs.getgrist.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "grist-api"
        },
        {
          "registry": "pypi",
          "name": "grist-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates an API key on the Developer page of account settings and sends it as `Authorization: Bearer`. The key carries its owner's full account access, and each account has one. The alternative is OAuth 2.0 with PKCE, used by the MCP server and by registered apps. The user approves any of seven scopes (`doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`) and can limit the grant to chosen sites, workspaces or documents. Access tokens last 1 hour and refresh tokens 60 days, and a grant can be revoked per app. Clients can register themselves by Client ID Metadata Document. Not every REST endpoint accepts an OAuth token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 5,000 rows a document and 3,000 API calls a month per site, REST and MCP calls together, so an agent can start without a contract. Pro is $10 a user a month ($8 billed yearly) and Business $30 ($24 yearly, minimum 5 users), Enterprise through sales. API calls aren't priced, the MCP server is on every plan for now, and there's no separate sandbox. The self-hosted community edition is free (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": 11900,
        "npmWeekly": 341,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://support.getgrist.com/rest-api/",
      "openapi": "https://raw.githubusercontent.com/gristlabs/grist-help/master/api/grist.yml",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "oauth",
        "api-key",
        "openapi",
        "webhooks",
        "python",
        "javascript"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.1,
        "grade": "D",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-13. GHSA-9x4j-4rw5-3vmq, critical (CVSS 10.0), remote code execution through prototype pollution from an imported crafted document, affecting Docker images before 1.7.19 and fixed in 1.7.19. Four more advisories were published in the last 12 months, among them GHSA-7xvx-8pf2-pv5g (CVE-2026-24002, critical, 21 January 2026) on the pyodide sandbox option, fixed in 1.7.9. All five are fixed and published and none says whether hosted Grist was affected, so the deduction is reduced (https://github.com/gristlabs/grist-core/security/advisories)"
        ],
        "verdict": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
        "bestFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "strengths": [
          "OAuth 2.0 with PKCE and seven scopes, with `doc:read`, `doc:write` and `doc.schema:write` granted separately and the grant limited to chosen sites, workspaces or documents",
          "Access tokens last 1 hour, refresh tokens 60 days, and a user can revoke one app's grant from the Authorised apps page",
          "Public OpenAPI 3.0.0 file with 101 paths and 120 operations, including a read-only SQL endpoint and `PUT` on `/records` to add or update by key columns",
          "Limits are published with numbers per plan, with 10 concurrent requests per document and a 1 MB request body on every plan",
          "The core is Apache-2.0 and four releases were tagged between 29 July and 28 September 2026"
        ],
        "weaknesses": [
          "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none",
          "An API key carries its owner's full account access, and each account has one key, so it can't be limited to a document or revoked per integration",
          "The data security page says hosted Grist has no SOC 2, ISO 27001, HIPAA or GDPR certification, and no DPA, sub-processor list or security.txt was found",
          "The MCP server and OAuth server are in the proprietary full edition, so the Apache-2.0 community edition has neither and the tool definitions aren't public",
          "Five security advisories were published in the last 12 months, two rated critical, the latest on 13 September 2026 with CVSS 10.0",
          "The Free plan allows 3,000 API calls a month across a site, with REST and MCP calls sharing the pool"
        ],
        "agentNotes": [
          "Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen",
          "Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules",
          "Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented",
          "Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row",
          "Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.1
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 50
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "pip install grist-api",
        "http": "curl -H \"Authorization: Bearer \u003cAPI-KEY-GOES-HERE\u003e\" https://docs.getgrist.com/api/orgs",
        "claudeCode": "claude mcp add --transport http grist https://docs.getgrist.com/api/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/grist"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro (hosted)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed monthly, $8 billed yearly, 100,000 rows a document, 40,000 API calls per document per day"
        },
        {
          "item": "Business (hosted)",
          "unit": "seat-month",
          "usd": 30,
          "note": "billed monthly, $24 billed yearly, minimum 5 users, 150,000 rows a document, 60,000 API calls per document per day"
        }
      ],
      "provenance": {
        "legalEntity": "Grist Labs Inc.",
        "domain": "getgrist.com",
        "domainRegistered": "2014-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.getgrist.com/terms/",
        "privacy": "https://www.getgrist.com/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/gristlabs/grist-core/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms page is an End-User Licence Agreement between the user and Grist Labs Inc., covering its products, software, services and websites, governed by New York State law, with legal notices to 93 4th Ave, #1127, New York, NY 10003. It carries no date.",
          "The privacy policy has an effective date of 1 April 2019 and covers the websites, products and services. It names no retention periods.",
          "The REST API and MCP server answer at docs.getgrist.com and \u003cteam\u003e.getgrist.com, and OAuth at login.getgrist.com, all getgrist.com subdomains.",
          "No status page was found. status.getgrist.com redirects to a signup form because every subdomain is treated as a team site.",
          "www.getgrist.com/.well-known/security.txt and docs.getgrist.com/.well-known/security.txt return 404. SECURITY.md in the repository gives security@getgrist.com.",
          "RDAP for getgrist.com gives a registration date of 2014-05-12."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/grist.json",
      "live": {
        "slug": "grist",
        "probe": {
          "target": "https://docs.getgrist.com/api",
          "method": "get",
          "lastAt": "2026-10-08T21:53:23.437064771Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 262,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 256,
          "p95ms24h": 311,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "updatedAt": "2026-10-08T21:53:23.437064771Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Superhuman Platform Inc.",
        "b": "Grist Labs Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://coda.io/apis/v1",
        "b": "https://docs.getgrist.com/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT",
        "b": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
        "name": "Licence"
      },
      {
        "a": "34",
        "b": "34",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-24",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "2025-10-29",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-07-06",
        "b": "2019-04-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "10k npm/wk",
        "b": "12k stars, 341 npm/wk, 240 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Coda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community.",
        "question": "Which is better for AI agents, Coda (Superhuman Docs) or Grist?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Coda (Superhuman Docs) and Grist need an API key?"
      },
      {
        "answer": "Yes. Coda (Superhuman Docs) has a hosted endpoint at https://coda.io/apis/v1 and Grist at https://docs.getgrist.com/api.",
        "question": "Can an agent call Coda (Superhuman Docs) and Grist without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Coda (Superhuman Docs). Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0).",
        "question": "Are Coda (Superhuman Docs) and Grist open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 39",
          "Schema \u0026 documentation, 76 against 63",
          "Security \u0026 auth, 71 against 62",
          "Transparency \u0026 trust, 78 against 61"
        ],
        "also": null,
        "goodFor": "Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.",
        "slug": "coda",
        "watchFor": "Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale"
      },
      {
        "aheadOn": [
          "Maintenance \u0026 community, 78 against 72"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "slug": "grist",
        "watchFor": "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none"
      }
    ],
    "job": {
      "capability": "sheets.read",
      "name": "Sheets read"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-google-sheets-api.json",
        "title": "Coda (Superhuman Docs) vs Google Sheets API",
        "url": "https://www.anchorterminal.com/compare/coda-vs-google-sheets-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.json",
        "title": "Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-nocodb.json",
        "title": "Coda (Superhuman Docs) vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/coda-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-seatable.json",
        "title": "Coda (Superhuman Docs) vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/coda-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-smartsheet.json",
        "title": "Coda (Superhuman Docs) vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/coda-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-teable.json",
        "title": "Coda (Superhuman Docs) vs Teable",
        "url": "https://www.anchorterminal.com/compare/coda-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.json",
        "title": "Google Sheets API vs Grist",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json",
        "title": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-coda.json",
        "title": "Airtable vs Coda (Superhuman Docs)",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-coda"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-grist.json",
        "title": "Airtable vs Grist",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-coda.json",
        "title": "Baserow vs Coda (Superhuman Docs)",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-coda"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-grist.json",
        "title": "Baserow vs Grist",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-nocodb.json",
        "title": "Grist vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/grist-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-seatable.json",
        "title": "Grist vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.json",
        "title": "Grist vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/grist-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-teable.json",
        "title": "Grist vs Teable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-teable"
      }
    ],
    "scores": [
      {
        "by": 42,
        "coda": 81,
        "edge": "coda",
        "grist": 39,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "coda": 76,
        "edge": "coda",
        "grist": 63,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 4,
        "coda": 61,
        "edge": "coda",
        "grist": 57,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 9,
        "coda": 71,
        "edge": "coda",
        "grist": 62,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 0,
        "coda": 30,
        "edge": "",
        "grist": 30,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "coda": 72,
        "edge": "grist",
        "grist": 78,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 17,
        "coda": 78,
        "edge": "coda",
        "grist": 61,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Coda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community. Both do sheets read.",
    "verdicts": {
      "coda": "API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.",
      "grist": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/coda-vs-grist",
    "json": "https://www.anchorterminal.com/compare/coda-vs-grist.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/coda-vs-grist.md",
    "slim": "https://www.anchorterminal.com/compare/coda-vs-grist.min.md"
  },
  "markdown": "Coda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community. Both do sheets read.\n\n- Coda (Superhuman Docs): grade B, 64.8/100, rank #270 of 722. Markdown https://www.anchorterminal.com/tools/coda.md · JSON https://www.anchorterminal.com/api/v1/tools/coda.json\n- Grist: grade D, 50.1/100, rank #597 of 722. Markdown https://www.anchorterminal.com/tools/grist.md · JSON https://www.anchorterminal.com/api/v1/tools/grist.json\n\n## Which one, for what\n\n### Coda (Superhuman Docs) (B)\n\nGood for: Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.\n\nAhead on:\n- Reliability, 81 against 39\n- Schema \u0026 documentation, 76 against 63\n- Security \u0026 auth, 71 against 62\n- Transparency \u0026 trust, 78 against 61\n\nWatch for: Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale\n\n### Grist (D)\n\nGood for: Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.\n\nAhead on:\n- Maintenance \u0026 community, 78 against 72\n\nAlso in its favour:\n- Open source\n\nWatch for: No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none\n\n\n## Score by category\n\n| Category | Weight | Coda (Superhuman Docs) | Grist | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 39 | Coda (Superhuman Docs) +42 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 76 | 63 | Coda (Superhuman Docs) +13 |\n| Agent ergonomics | 13% (16.2 this run) | 61 | 57 | Coda (Superhuman Docs) +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 62 | Coda (Superhuman Docs) +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 72 | 78 | Grist +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 78 | 61 | Coda (Superhuman Docs) +17 |\n| Negative events | ≤15 | -3 | -4 | |\n| **Total** | | **64.8 · B** | **50.1 · D** | |\n\n## Facts side by side\n\n| Fact | Coda (Superhuman Docs) | Grist |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Superhuman Platform Inc. | Grist Labs Inc. |\n| Hosted endpoint | `https://coda.io/apis/v1` | `https://docs.getgrist.com/api` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT | Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 |\n| Tools exposed | 34 | 34 |\n| Read-only variant documented | no | yes |\n| llms.txt | no | no |\n| Last release | 2026-09-24 | 2026-09-28 |\n| Terms last updated | 2025-10-29 | no date given |\n| Privacy policy last updated | 2026-07-06 | 2019-04-01 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 10k npm/wk | 12k stars, 341 npm/wk, 240 PyPI/wk |\n\n## Verdicts\n\n**Coda (Superhuman Docs).** API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.\n\n**Grist.** OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.\n\n## Before you call either\n\n### Coda (Superhuman Docs)\n\n1. Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail\n2. Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind\n3. Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate\n4. Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can\n5. Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta\n\n### Grist\n\n1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen\n2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules\n3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented\n4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row\n5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit\n\n## Questions\n\n### Which is better for AI agents, Coda (Superhuman Docs) or Grist?\n\nCoda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community.\n\n### Do Coda (Superhuman Docs) and Grist need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Coda (Superhuman Docs) and Grist without installing anything?\n\nYes. Coda (Superhuman Docs) has a hosted endpoint at https://coda.io/apis/v1 and Grist at https://docs.getgrist.com/api.\n\n### Are Coda (Superhuman Docs) and Grist open source?\n\nNo open-source release is listed for Coda (Superhuman Docs). Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/coda-vs-grist.json, and with the fewest tokens: https://www.anchorterminal.com/compare/coda-vs-grist.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"coda\", \"b\": \"grist\"}`. From a terminal: `anchor compare coda grist`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/coda.json and https://www.anchorterminal.com/api/v1/tools/grist.json\n\n## Other comparisons with Coda (Superhuman Docs) or Grist\n\n- [Coda (Superhuman Docs) vs Google Sheets API](https://www.anchorterminal.com/compare/coda-vs-google-sheets-api.md)\n- [Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.md)\n- [Coda (Superhuman Docs) vs NocoDB](https://www.anchorterminal.com/compare/coda-vs-nocodb.md)\n- [Coda (Superhuman Docs) vs SeaTable](https://www.anchorterminal.com/compare/coda-vs-seatable.md)\n- [Coda (Superhuman Docs) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/coda-vs-smartsheet.md)\n- [Coda (Superhuman Docs) vs Teable](https://www.anchorterminal.com/compare/coda-vs-teable.md)\n- [Google Sheets API vs Grist](https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.md)\n- [Grist vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.md)\n- [Airtable vs Coda (Superhuman Docs)](https://www.anchorterminal.com/compare/airtable-vs-coda.md)\n- [Airtable vs Grist](https://www.anchorterminal.com/compare/airtable-vs-grist.md)\n- [Baserow vs Coda (Superhuman Docs)](https://www.anchorterminal.com/compare/baserow-vs-coda.md)\n- [Baserow vs Grist](https://www.anchorterminal.com/compare/baserow-vs-grist.md)\n- [Grist vs NocoDB](https://www.anchorterminal.com/compare/grist-vs-nocodb.md)\n- [Grist vs SeaTable](https://www.anchorterminal.com/compare/grist-vs-seatable.md)\n- [Grist vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/grist-vs-smartsheet.md)\n- [Grist vs Teable](https://www.anchorterminal.com/compare/grist-vs-teable.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Coda (Superhuman Docs) vs Grist",
        "url": ""
      }
    ],
    "description": "Coda (Superhuman Docs) scores 64.8 (B) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on maintenance \u0026 community. Both do sheets read. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Coda (Superhuman Docs) B 64.8",
      "Grist D 50.1",
      "scores"
    ],
    "h1": "Coda (Superhuman Docs) vs Grist",
    "image": "https://www.anchorterminal.com/assets/og/compare-coda-vs-grist.png",
    "path": "/compare/coda-vs-grist",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Coda (Superhuman Docs) vs Grist for AI agents, B 64.8 vs D 50.1",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/coda-vs-grist"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
