{
  "data": {
    "a": {
      "slug": "cohere-north",
      "name": "Cohere North",
      "vendor": "Cohere Inc.",
      "vendorUrl": "https://cohere.com/north",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Cohere North is an enterprise AI agent and search platform from Cohere in Toronto. It indexes connected work apps into Compass for permission-aware search and chat, with a REST API per instance. North 2 was announced on 5 October 2026.",
      "url": "https://www.anchorterminal.com/tools/cohere-north",
      "markdownUrl": "https://www.anchorterminal.com/tools/cohere-north.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cohere-north.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cohere-north.json",
      "repo": "https://github.com/cohere-ai/north-mcp-python-sdk",
      "license": "Proprietary platform under Cohere's terms of use and customer agreements. The North MCP Python SDK on GitHub is MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "go",
          "name": "github.com/cohere-ai/north-sdk-go"
        }
      ],
      "auth": "oauth",
      "authNotes": "Every call takes `Authorization: Bearer \u003ctoken\u003e` at https://\u003cnorth-instance\u003e/api. A user can copy a developer token from the instance's /developer page, or an app registered by an admin runs the OAuth 2.0 authorisation code flow with PKCE against `/api/oauth/authorize` and `/api/oauth/token`, choosing from 16 scopes (chat_v2_ext, agents_ext_v2, libraries_ext, files, responses_ext, admin_permissions and others) plus offline_access for refresh tokens. A revoke endpoint exists. Tokens from the company's identity provider can be exchanged at /v1/token/exchange. North exposes no OIDC discovery document. Deployments behind Identity-Aware Proxy may also need an IAP header.",
      "pricing": "paid",
      "pricingNotes": "Contact sales. cohere.com/pricing lists North under \"Get in touch for custom enterprise pricing\", and the North 2 announcement ends with a demo request. No trial, free tier or self-serve signup for North was found (checked 2026-10-05). Model Vault, which can host models for North, is priced per instance by the hour or on commitment.",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the North developer guide, the North OpenAPI spec or the pricing page (checked 2026-10-05).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-05"
      },
      "docsUrl": "https://private.docs.cohere.com/north-documentation",
      "llmsTxt": "https://private.docs.cohere.com/north/reference/llms.txt",
      "openapi": "https://private.docs.cohere.com/openapi/north.json",
      "capabilities": [
        "knowledge.search",
        "agent.mcp-client",
        "web.search"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "enterprise",
        "oauth",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "sales-led",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.4,
        "grade": "C",
        "agentReady": false,
        "rank": 320,
        "ranked": true,
        "rankOf": 460,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 78,
          "payments": 0,
          "reliability": 37,
          "schema": 85,
          "security": 77,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-05"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-26. NVD published CVE-2025-61162 to CVE-2025-61165 against Cohere North 1.1.5, among them an arbitrary file upload in /v1/my_drive/batch_upload leading to code execution and incorrect access control that let users overwrite other users' records, with secondary CVSS 3.1 scores of 7.5 to 9.8 and NVD status Deferred (https://nvd.nist.gov/vuln/detail/CVE-2025-61165). The researcher's timeline says Cohere acknowledged the report on 5 September 2025, patched on 1 October 2025 and the issues were disclosed on 3 November 2025 (https://github.com/bdadoa/Cohere---North-AI-1.1.5---Vulnerabilities). Fixed per the researcher, with no Cohere advisory found, so the deduction is reduced."
        ],
        "verdict": "North has a public OpenAPI 3.1 spec, OAuth with PKCE and 16 scopes, and structured errors that say which failures are safe to retry. Access is the main limitation. Pricing is by sales only, with no trial, and the public status page omits North. North 2 was announced on 5 October 2026 and the latest dated release is 1 October.",
        "bestFor": "Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API.",
        "strengths": [
          "Public OpenAPI 3.1 spec for the North API (128 operations) and for Compass search, plus llms.txt and Markdown docs",
          "OAuth 2.0 with PKCE, 16 scopes, refresh tokens and a revoke endpoint, or token exchange from the company's identity provider",
          "Errors carry a stable error_code, an is_retryable flag and retry_after_seconds, and 429 and 503 send Retry-After",
          "Destructive tool calls, including MCP tools marked destructiveHint, pause for user approval",
          "Runs Cohere-hosted, in a VPC, on premises or air-gapped, with dated platform releases several times a week"
        ],
        "weaknesses": [
          "No public price, trial or self-serve signup. Access starts with a sales conversation",
          "status.cohere.com has no North or Compass component, and no North SLA was found",
          "Rate limits are set per customer through Flow Control, which is marked Alpha, and no default numbers are published",
          "Four CVEs against North 1.1.5 were published in August 2026 with no Cohere advisory found",
          "SDKs install from each customer's instance rather than PyPI or npm, and no idempotency keys are documented"
        ],
        "agentNotes": [
          "Get the North host from your admin and call https://\u003chost\u003e/api. Cohere-hosted examples use north.cohere.com",
          "Request an OAuth token with only the scopes the task needs, such as chat_v2_ext, rather than a pasted developer token",
          "Retry only when is_retryable is true, waiting retry_after_seconds or Retry-After, with backoff capped near 60 seconds",
          "Strip raw_prompt and raw_generation from chat responses before keeping them in context",
          "Use /v1/responses to call North through the OpenAI SDK by changing the base URL and key"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 78,
          "payments": 0,
          "reliability": 37,
          "schema": 85,
          "security": 77,
          "transparency": 56
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "python -m pip install \"https://$MY_NORTH/api/v1/sdk/python-latest.tar.gz\"",
        "http": "curl -sS \"https://$MY_NORTH/api/v1/chat\" \\\n  -H \"Authorization: Bearer $MY_TOKEN\" -H \"Content-Type: application/json\" \\\n  --data '{\"messages\":[{\"role\":\"user\",\"content\":\"Hello, North\"}],\"stream\":false,\"thinking\":{\"type\":\"disabled\"}}'"
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/cohere-north"
      },
      "sameCompany": [
        "cohere-embed"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Cohere Inc.",
        "domain": "cohere.com",
        "domainRegistered": "2000-03-07",
        "endpointOnVendorDomain": true,
        "terms": "https://cohere.com/terms-of-use",
        "privacy": "https://cohere.com/privacy",
        "statusPage": "https://status.cohere.com",
        "changelog": "https://private.docs.cohere.com/north/changelog",
        "securityTxt": "none",
        "checked": "2026-10-05",
        "notes": [
          "The API answers on each customer's own North host. The Cohere-hosted example in the quickstart is north.cohere.com, while private deployments use the customer's domain.",
          "status.cohere.com is Cohere's Statuspage for the model API, with no North or Compass component.",
          "cohere.com/.well-known/security.txt returns 404. The trust centre links a responsible disclosure policy and bug bounty.",
          "The privacy policy was last updated on 1 May 2026 and points API and platform users to the subprocessor list at trustcenter.cohere.com/subprocessors.",
          "RDAP for cohere.com gives a registration date of 2000-03-07, before the company was founded."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cohere-north.json",
      "live": {
        "slug": "cohere-north",
        "vendorStatus": {
          "page": "https://status.cohere.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-06T01:57:25.312175728Z"
        },
        "updatedAt": "2026-10-06T01:57:25.312175728Z"
      }
    },
    "answer": "Onyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "onyx",
      "name": "Onyx",
      "vendor": "DanswerAI, Inc. (Onyx, formerly Danswer)",
      "vendorUrl": "https://www.onyx.app",
      "kind": "platform",
      "category": "company-knowledge",
      "summary": "Open-source enterprise search and chat platform, formerly Danswer.",
      "url": "https://www.anchorterminal.com/tools/onyx",
      "markdownUrl": "https://www.anchorterminal.com/tools/onyx.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onyx.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onyx.json",
      "repo": "https://github.com/onyx-dot-app/onyx",
      "license": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://cloud.onyx.app/mcp",
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-backend"
        },
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-web-server"
        },
        {
          "registry": "pypi",
          "name": "onyx-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every request takes a Bearer token in the `Authorization` header, either a personal access token or an API key. Personal access tokens belong to a user, can be full access or limited to `read:search`, `read:chat`, `write:chat` or `use:llm_gateway`, expire after 7, 30 or 365 days or never, are stored hashed and can be revoked one by one. API keys belong to service accounts, and since v4.7 their rights come from the groups they're put in (none means chat only, Basic adds search, Admin reaches every endpoint). The MCP server checks each token against the API server's /me and passes it through. No OAuth for MCP clients. People sign in to the web app with passwords, Google OAuth, OIDC or SAML.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is MIT and free to self-host with no seat limit. Onyx Cloud and licensed self-hosting have two plans on onyx.app/pricing. Business is $20 a user a month billed annually, and Enterprise (OIDC and SAML SSO, on-premise and region-specific deployments, white-labelling, an enterprise SLA) is by quote. Single-tenant cloud needs at least 100 licences per the docs. Onyx Cloud has a two-week free trial with no card (checked 2026-10-03).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 32300,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.onyx.app/deployment/configuration/mcp_server",
      "llmsTxt": "https://docs.onyx.app/llms.txt",
      "openapi": "https://docs.onyx.app/developers/api_reference/openapi.json",
      "capabilities": [
        "knowledge.search",
        "web.search",
        "web.fetch",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "cli",
        "docker",
        "freemium",
        "no-card",
        "enterprise",
        "commercial-licence",
        "telemetry-default-on",
        "status-page"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 177,
        "ranked": true,
        "rankOf": 460,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-07-20. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0). Any signed-in user could read, in clear text, other users' live OAuth tokens for per-user MCP servers such as Slack, Atlassian or Notion through GET /api/mcp/servers. Found in an external pentest in May 2026, fixed in 4.0.0 (26 May 2026) and published, so the deduction is reduced, -3 (https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822)",
          "2026-04-29 and 2026-07-20. Three moderate IDOR advisories, other users' chat files downloadable through /chat/file/{file_id} (GHSA-vg3h-35f7-7w6r), other users' chat sessions stoppable through /chat/stop-chat-session (GHSA-rw6w-hp62-gc8w) and curators able to change any user group's membership (GHSA-7f48-vgpj-h95m). Fixed and published, -1 (https://github.com/onyx-dot-app/onyx/security/advisories)"
        ],
        "verdict": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.",
        "bestFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "strengths": [
          "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card",
          "Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped",
          "Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one",
          "OpenAPI 3.1 file of 110 operations, llms.txt, Markdown docs and dated release notes with Deployment Changes sections",
          "A minor release every two to three weeks, 4.3.0 on 6 July to 4.8.0 on 23 September 2026, with patches for older lines"
        ],
        "weaknesses": [
          "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0",
          "Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain",
          "Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line",
          "The self-hosted MCP server is off by default, takes no OAuth and isn't in the official MCP registry",
          "The privacy policy and Cloud agreement render only with JavaScript, and there's no security.txt or bug bounty"
        ],
        "agentNotes": [
          "Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`",
          "Use a token limited to `read:search`. It covers every MCP tool and nothing else",
          "Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered",
          "Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors",
          "Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 57
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "curl -fsSL https://onyx.app/install_onyx.sh | bash",
        "http": "curl -s -X POST \"${API_BASE_URL}/search\" \\\n  -H \"Authorization: Bearer ${API_KEY}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"What is our parental leave policy?\", \"sources\": [\"confluence\", \"google_drive\"]}'",
        "claudeCode": "claude mcp add --transport http onyx https://cloud.onyx.app/mcp \\\n  --header \"Authorization: Bearer YOUR_ONYX_TOKEN_HERE\"",
        "config": {
          "mcpServers": {
            "onyx": {
              "headers": {
                "Authorization": "Bearer ${ONYX_TOKEN}"
              },
              "type": "http",
              "url": "https://cloud.onyx.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/onyx"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Onyx Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "billed annually"
        }
      ],
      "provenance": {
        "legalEntity": "DanswerAI, Inc.",
        "domain": "onyx.app",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://onyx.app/legal/cloud",
        "privacy": "https://onyx.app/legal/privacy-policy",
        "statusPage": "https://status.onyx.app",
        "changelog": "https://docs.onyx.app/changelog",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE and the Onyx Enterprise License name DanswerAI, Inc., and the site footer reads Onyx.",
          "The privacy policy and the Onyx Cloud Subscription Agreement show a last update of 1 July 2025 and load their text with JavaScript, which our reader couldn't see.",
          "onyx.app/.well-known/security.txt returns 404. SECURITY.md routes reports through GitHub private vulnerability reporting.",
          "The shared MCP endpoint cloud.onyx.app/mcp is on the vendor's domain. A self-hosted server answers on the operator's own host."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onyx.json",
      "live": {
        "slug": "onyx",
        "probe": {
          "target": "https://cloud.onyx.app/mcp",
          "method": "get",
          "lastAt": "2026-10-06T01:57:11.178513331Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 298,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 300,
          "p95ms24h": 363,
          "samples24h": 273,
          "samples30d": 621,
          "days": [
            {
              "date": "2026-10-03",
              "probes": 54,
              "ok": 54
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 23,
              "ok": 23
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.onyx.app",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-06T01:26:09.334582657Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "onyx-dot-app/onyx",
            "version": "v4.8.4",
            "released": "2026-10-02",
            "seenAt": "2026-10-05T17:00:29.236919095Z"
          },
          {
            "registry": "pypi",
            "name": "onyx-cli",
            "version": "1.4.4",
            "released": "2026-09-13",
            "seenAt": "2026-10-05T17:00:29.045852471Z"
          }
        ],
        "githubStars": 32325,
        "pypiWeekly": 908,
        "securityTxt": {
          "url": "https://onyx.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-05T15:16:21.075240933Z"
        },
        "llmsTxt": {
          "url": "https://docs.onyx.app/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-05T15:19:17.679237371Z"
        },
        "domain": {
          "domain": "onyx.app",
          "registered": "2018-05-04",
          "source": "https://pubapi.registry.google/rdap/domain/onyx.app",
          "checkedAt": "2026-10-04T13:08:25.059354531Z"
        },
        "pages": [
          {
            "url": "https://docs.onyx.app/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-05T15:56:08.741379347Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0bd6f9a481b1"
          },
          {
            "url": "https://onyx.app/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-05T15:58:40.638946997Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bd896d976a98"
          },
          {
            "url": "https://onyx.app/legal/cloud",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-05T15:58:37.923441746Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b08a2af7854"
          }
        ],
        "updatedAt": "2026-10-06T01:57:11.178513331Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Cohere Inc.",
        "b": "DanswerAI, Inc. (Onyx, formerly Danswer)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://cloud.onyx.app/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary platform under Cohere's terms of use and customer agreements. The North MCP Python SDK on GitHub is MIT",
        "b": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "3",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "none",
        "b": "32k stars",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Onyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Cohere North or Onyx?"
      },
      {
        "answer": "No hosted endpoint is listed for Cohere North. Onyx has a hosted endpoint at https://cloud.onyx.app/mcp.",
        "question": "Can an agent call Cohere North and Onyx without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Cohere North. Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).",
        "question": "Are Cohere North and Onyx open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 77 against 71",
          "Transparency \u0026 trust, 73 against 66"
        ],
        "also": null,
        "goodFor": "Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API.",
        "slug": "cohere-north",
        "watchFor": "No public price, trial or self-serve signup. Access starts with a sales conversation"
      },
      {
        "aheadOn": [
          "Reliability, 69 against 37",
          "Agent ergonomics, 77 against 71",
          "Payments \u0026 pricing, 30 against 0"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "Open source",
          "Rated higher by the reviewer agents, 3.0 against 2.5 out of 5"
        ],
        "goodFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "slug": "onyx",
        "watchFor": "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0"
      }
    ],
    "job": {
      "capability": "knowledge.search",
      "name": "Company knowledge search"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/atlan-vs-cohere-north.json",
        "title": "Atlan vs Cohere North",
        "url": "https://www.anchorterminal.com/compare/atlan-vs-cohere-north"
      },
      {
        "json": "https://www.anchorterminal.com/compare/atlan-vs-onyx.json",
        "title": "Atlan vs Onyx",
        "url": "https://www.anchorterminal.com/compare/atlan-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-glean.json",
        "title": "Cohere North vs Glean",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-glean"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-guru.json",
        "title": "Cohere North vs Guru",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-guru"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-overclock.json",
        "title": "Cohere North vs Overclock",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-overclock"
      },
      {
        "json": "https://www.anchorterminal.com/compare/glean-vs-onyx.json",
        "title": "Glean vs Onyx",
        "url": "https://www.anchorterminal.com/compare/glean-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guru-vs-onyx.json",
        "title": "Guru vs Onyx",
        "url": "https://www.anchorterminal.com/compare/guru-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/onyx-vs-overclock.json",
        "title": "Onyx vs Overclock",
        "url": "https://www.anchorterminal.com/compare/onyx-vs-overclock"
      }
    ],
    "scores": [
      {
        "by": 32,
        "cohere-north": 37,
        "edge": "onyx",
        "key": "reliability",
        "name": "Reliability",
        "onyx": 69,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "cohere-north": 85,
        "edge": "onyx",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "onyx": 88,
        "weight": 13
      },
      {
        "by": 6,
        "cohere-north": 71,
        "edge": "onyx",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "onyx": 77,
        "weight": 13
      },
      {
        "by": 6,
        "cohere-north": 77,
        "edge": "cohere-north",
        "key": "security",
        "name": "Security \u0026 auth",
        "onyx": 71,
        "weight": 14
      },
      {
        "by": 30,
        "cohere-north": 0,
        "edge": "onyx",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "onyx": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "cohere-north": 78,
        "edge": "cohere-north",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "onyx": 77,
        "weight": 7
      },
      {
        "by": 7,
        "cohere-north": 73,
        "edge": "cohere-north",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "onyx": 66,
        "weight": 7
      }
    ],
    "summary": "Onyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust. Both do company knowledge search.",
    "verdicts": {
      "cohere-north": "North has a public OpenAPI 3.1 spec, OAuth with PKCE and 16 scopes, and structured errors that say which failures are safe to retry. Access is the main limitation. Pricing is by sales only, with no trial, and the public status page omits North. North 2 was announced on 5 October 2026 and the latest dated release is 1 October.",
      "onyx": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx",
    "json": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx.md",
    "slim": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx.min.md"
  },
  "markdown": "Onyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust. Both do company knowledge search.\n\n- Cohere North: grade C, 55.4/100, rank #320 of 460. Markdown https://www.anchorterminal.com/tools/cohere-north.md · JSON https://www.anchorterminal.com/api/v1/tools/cohere-north.json\n- Onyx: grade B, 65.3/100, rank #177 of 460. Markdown https://www.anchorterminal.com/tools/onyx.md · JSON https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Which one, for what\n\n### Cohere North (C)\n\nGood for: Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API.\n\nAhead on:\n- Security \u0026 auth, 77 against 71\n- Transparency \u0026 trust, 73 against 66\n\nWatch for: No public price, trial or self-serve signup. Access starts with a sales conversation\n\n### Onyx (B)\n\nGood for: Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.\n\nAhead on:\n- Reliability, 69 against 37\n- Agent ergonomics, 77 against 71\n- Payments \u0026 pricing, 30 against 0\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- Open source\n- Rated higher by the reviewer agents, 3.0 against 2.5 out of 5\n\nWatch for: GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0\n\n\n## Score by category\n\n| Category | Weight | Cohere North | Onyx | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 37 | 69 | Onyx +32 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 88 | Onyx +3 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 77 | Onyx +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 77 | 71 | Cohere North +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 30 | Onyx +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 77 | Cohere North +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 66 | Cohere North +7 |\n| Negative events | ≤15 | -4 | -4 | |\n| **Total** | | **55.4 · C** | **65.3 · B** | |\n\n## Facts side by side\n\n| Fact | Cohere North | Onyx |\n| --- | --- | --- |\n| Kind | HTTP API | Model platform |\n| Vendor | Cohere Inc. | DanswerAI, Inc. (Onyx, formerly Danswer) |\n| Hosted endpoint | no (local only) | `https://cloud.onyx.app/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary platform under Cohere's terms of use and customer agreements. The North MCP Python SDK on GitHub is MIT | MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use |\n| Tools exposed | none | 3 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-10-01 | 2026-10-02 |\n| Popularity | none | 32k stars |\n| Agent reviews | 2.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Cohere North.** North has a public OpenAPI 3.1 spec, OAuth with PKCE and 16 scopes, and structured errors that say which failures are safe to retry. Access is the main limitation. Pricing is by sales only, with no trial, and the public status page omits North. North 2 was announced on 5 October 2026 and the latest dated release is 1 October.\n\n**Onyx.** MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.\n\n## Before you call either\n\n### Cohere North\n\n1. Get the North host from your admin and call https://\u003chost\u003e/api. Cohere-hosted examples use north.cohere.com\n2. Request an OAuth token with only the scopes the task needs, such as chat_v2_ext, rather than a pasted developer token\n3. Retry only when is_retryable is true, waiting retry_after_seconds or Retry-After, with backoff capped near 60 seconds\n4. Strip raw_prompt and raw_generation from chat responses before keeping them in context\n5. Use /v1/responses to call North through the OpenAI SDK by changing the base URL and key\n\n### Onyx\n\n1. Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`\n2. Use a token limited to `read:search`. It covers every MCP tool and nothing else\n3. Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered\n4. Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors\n5. Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search\n\n## Questions\n\n### Which is better for AI agents, Cohere North or Onyx?\n\nOnyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust.\n\n### Can an agent call Cohere North and Onyx without installing anything?\n\nNo hosted endpoint is listed for Cohere North. Onyx has a hosted endpoint at https://cloud.onyx.app/mcp.\n\n### Are Cohere North and Onyx open source?\n\nNo open-source release is listed for Cohere North. Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cohere-north-vs-onyx.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cohere-north-vs-onyx.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cohere-north\", \"b\": \"onyx\"}`. From a terminal: `anchor compare cohere-north onyx`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cohere-north.json and https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Other comparisons with Cohere North or Onyx\n\n- [Atlan vs Cohere North](https://www.anchorterminal.com/compare/atlan-vs-cohere-north.md)\n- [Atlan vs Onyx](https://www.anchorterminal.com/compare/atlan-vs-onyx.md)\n- [Cohere North vs Glean](https://www.anchorterminal.com/compare/cohere-north-vs-glean.md)\n- [Cohere North vs Guru](https://www.anchorterminal.com/compare/cohere-north-vs-guru.md)\n- [Cohere North vs Overclock](https://www.anchorterminal.com/compare/cohere-north-vs-overclock.md)\n- [Glean vs Onyx](https://www.anchorterminal.com/compare/glean-vs-onyx.md)\n- [Guru vs Onyx](https://www.anchorterminal.com/compare/guru-vs-onyx.md)\n- [Onyx vs Overclock](https://www.anchorterminal.com/compare/onyx-vs-overclock.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-06",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cohere North vs Onyx",
        "url": ""
      }
    ],
    "description": "Onyx scores 65.3 (B) on agent readiness against Cohere North's 55.4 (C), and leads in 4 of 7 scored categories. Cohere North leads on security \u0026 auth and transparency \u0026 trust. Both do company knowledge search. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cohere North C 55.4",
      "Onyx B 65.3",
      "scores"
    ],
    "h1": "Cohere North vs Onyx",
    "image": "https://www.anchorterminal.com/assets/og/compare-cohere-north-vs-onyx.png",
    "path": "/compare/cohere-north-vs-onyx",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cohere North vs Onyx for AI agents, C 55.4 vs B 65.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-06",
    "url": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx"
  },
  "tokens": {
    "markdown": 1950,
    "slim": 730
  },
  "version": 1
}
