{
  "data": {
    "a": {
      "slug": "dust",
      "name": "Dust",
      "vendor": "Permutation Labs",
      "vendorUrl": "https://dust.tt",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Dust is a platform for building AI agents on a company's documents and connected tools, from Permutation Labs in Paris. Outside agents reach it through a REST API, a JavaScript SDK, a CLI and a remote MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/dust",
      "markdownUrl": "https://www.anchorterminal.com/tools/dust.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dust.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dust.json",
      "repo": "https://github.com/dust-tt/dust",
      "license": "MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli`",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://dust.tt/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@dust-tt/client"
        },
        {
          "registry": "npm",
          "name": "@dust-tt/dust-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The REST API takes a workspace API key as a Bearer token, created by an admin in the workspace under Developers, API Keys. A key can be limited to chosen spaces and given a spending cap on a rolling 30 days. The remote MCP server takes OAuth only, with dynamic client registration or a client ID metadata document, and the token works as the signed-in user. The client-side MCP server (preview) needs an OAuth personal access token. Sign-in to create a workspace is in a browser.",
      "pricing": "freemium",
      "pricingNotes": "Free seat with 500 lifetime credits. Pro is €30 a seat a month (€24 billed yearly) with 8,000 credits, Max €150 (€120 yearly) with 40,000, and Enterprise is by quote, as dust.tt/home/pricing showed our reader in euros. API and other programmatic usage has no free credits and draws only on the workspace credit pool, bought as top-ups on Business or committed on Enterprise. No price per top-up credit was found (checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1482,
        "npmWeekly": 17225,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.dust.tt",
      "llmsTxt": "https://docs.dust.tt/llms.txt",
      "openapi": "https://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json",
      "capabilities": [
        "knowledge.search",
        "agent.mcp-client"
      ],
      "tags": [
        "hosted",
        "open-source",
        "mit",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "eu-region",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.8,
        "grade": "B",
        "agentReady": false,
        "rank": 378,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 86,
          "payments": 20,
          "reliability": 53,
          "schema": 75,
          "security": 75,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.",
        "bestFor": "A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.",
        "strengths": [
          "The platform's source is public under the MIT licence at github.com/dust-tt/dust, with commits on the day of the check",
          "Public OpenAPI 3.0 document with 68 operations, plus llms.txt and a Markdown copy of each docs page",
          "Remote MCP server at `https://dust.tt/mcp` and `https://eu.dust.tt/mcp`, with OAuth, dynamic client registration and the signed-in user's own access",
          "API keys can be limited to chosen spaces and given a spending cap on a rolling 30 days",
          "SOC 2 Type II on the security page, a HackerOne disclosure programme, and US or EU hosting"
        ],
        "weaknesses": [
          "Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use",
          "Rate limits are published for document upserts and app runs only, and no Retry-After guidance was found in the docs",
          "The terms link redirects to a Notion site drawn by script, so the service terms, any SLA and the DPA went unread",
          "Audit logs are an Enterprise feature, and no security.txt is published (404)",
          "Two major incidents on status.dust.tt in the last 90 days, one of 2 hours 3 minutes on 16 July 2026 that covered the API"
        ],
        "agentNotes": [
          "Use `https://eu.dust.tt` for a workspace in the EU region and `https://dust.tt` otherwise, for both the API and the MCP server",
          "Connect an MCP client by OAuth and send the `resource` parameter in authorisation and token requests. API keys do not work on the MCP server",
          "Expect HTTP 429 with type `rate_limit_error` when the credit pool, the programmatic monthly cap or the key's spend cap is exhausted. Retrying will not help",
          "Call `GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25) and `cursor`, or a data source view's search with `top_k`",
          "Keep document upserts under 120 a minute per workspace"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.8
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 86,
          "payments": 20,
          "reliability": 53,
          "schema": 75,
          "security": 75,
          "transparency": 71
        },
        "provenanceScore": 64
      },
      "connect": {
        "install": "npm install @dust-tt/client",
        "config": {
          "mcpServers": {
            "dust": {
              "type": "http",
              "url": "https://dust.tt/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/dust"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Permutation Labs",
        "domain": "dust.tt",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://dust.tt/home/platform-privacy",
        "statusPage": "https://status.dust.tt",
        "changelog": "https://docs.dust.tt/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Privacy Policy names Permutation Labs, 86 avenue de Wagram, 75017 Paris, France. It covers the platform where Dust is the data controller, not customer data Dust handles as a processor.",
          "No terms link is recorded. dust.tt/terms redirects (308) to a Notion site, dust-tt.notion.site, which is drawn by script and gave our reader no text, so we could not tell which document there governs the platform.",
          "The API and the MCP server answer on dust.tt and eu.dust.tt. OAuth for MCP is at signin.dust.tt.",
          "dust.tt/.well-known/security.txt returns 404. The repository's SECURITY.md sends reports to dust.tt/home/vulnerability, a HackerOne programme.",
          "No RDAP service answers for the .tt registry, so the domain's registration date is not recorded.",
          "dust.tt/robots.txt returns 404. docs.dust.tt/robots.txt carries `Content-Signal: ai-train=yes, search=yes, ai-input=yes`."
        ],
        "score": 64
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dust.json",
      "live": {
        "slug": "dust",
        "probe": {
          "target": "https://dust.tt/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:42:41.938062523Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 202,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 156,
          "p95ms24h": 202,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.dust.tt",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:41:35.388664013Z"
        },
        "updatedAt": "2026-10-09T10:42:41.938062523Z"
      }
    },
    "answer": "Onyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "onyx",
      "name": "Onyx",
      "vendor": "DanswerAI, Inc. (Onyx, formerly Danswer)",
      "vendorUrl": "https://www.onyx.app",
      "kind": "platform",
      "category": "company-knowledge",
      "summary": "Open-source enterprise search and chat platform, formerly Danswer.",
      "url": "https://www.anchorterminal.com/tools/onyx",
      "markdownUrl": "https://www.anchorterminal.com/tools/onyx.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onyx.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onyx.json",
      "repo": "https://github.com/onyx-dot-app/onyx",
      "license": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://cloud.onyx.app/mcp",
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-backend"
        },
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-web-server"
        },
        {
          "registry": "pypi",
          "name": "onyx-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every request takes a Bearer token in the `Authorization` header, either a personal access token or an API key. Personal access tokens belong to a user, can be full access or limited to `read:search`, `read:chat`, `write:chat` or `use:llm_gateway`, expire after 7, 30 or 365 days or never, are stored hashed and can be revoked one by one. API keys belong to service accounts, and since v4.7 their rights come from the groups they're put in (none means chat only, Basic adds search, Admin reaches every endpoint). The MCP server checks each token against the API server's /me and passes it through. No OAuth for MCP clients. People sign in to the web app with passwords, Google OAuth, OIDC or SAML.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is MIT and free to self-host with no seat limit. Onyx Cloud and licensed self-hosting have two plans on onyx.app/pricing. Business is $20 a user a month billed annually, and Enterprise (OIDC and SAML SSO, on-premise and region-specific deployments, white-labelling, an enterprise SLA) is by quote. Single-tenant cloud needs at least 100 licences per the docs. Onyx Cloud has a two-week free trial with no card (checked 2026-10-03).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 32300,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.onyx.app/deployment/configuration/mcp_server",
      "llmsTxt": "https://docs.onyx.app/llms.txt",
      "openapi": "https://docs.onyx.app/developers/api_reference/openapi.json",
      "capabilities": [
        "knowledge.search",
        "web.search",
        "web.fetch",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "cli",
        "docker",
        "freemium",
        "no-card",
        "enterprise",
        "commercial-licence",
        "telemetry-default-on",
        "status-page"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65,
        "grade": "B",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-07-20. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0). Any signed-in user could read, in clear text, other users' live OAuth tokens for per-user MCP servers such as Slack, Atlassian or Notion through GET /api/mcp/servers. Found in an external pentest in May 2026, fixed in 4.0.0 (26 May 2026) and published, so the deduction is reduced, -3 (https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822)",
          "2026-04-29 and 2026-07-20. Three moderate IDOR advisories, other users' chat files downloadable through /chat/file/{file_id} (GHSA-vg3h-35f7-7w6r), other users' chat sessions stoppable through /chat/stop-chat-session (GHSA-rw6w-hp62-gc8w) and curators able to change any user group's membership (GHSA-7f48-vgpj-h95m). Fixed and published, -1 (https://github.com/onyx-dot-app/onyx/security/advisories)"
        ],
        "verdict": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.",
        "bestFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "strengths": [
          "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card",
          "Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped",
          "Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one",
          "OpenAPI 3.1 file of 110 operations, llms.txt, Markdown docs and dated release notes with Deployment Changes sections",
          "A minor release every two to three weeks, 4.3.0 on 6 July to 4.8.0 on 23 September 2026, with patches for older lines"
        ],
        "weaknesses": [
          "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0",
          "Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain",
          "Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line",
          "The self-hosted MCP server is off by default, takes no OAuth and isn't in the official MCP registry",
          "The privacy policy and Cloud agreement render only with JavaScript, and there's no security.txt or bug bounty"
        ],
        "agentNotes": [
          "Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`",
          "Use a token limited to `read:search`. It covers every MCP tool and nothing else",
          "Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered",
          "Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors",
          "Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 57
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "curl -fsSL https://onyx.app/install_onyx.sh | bash",
        "http": "curl -s -X POST \"${API_BASE_URL}/search\" \\\n  -H \"Authorization: Bearer ${API_KEY}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"What is our parental leave policy?\", \"sources\": [\"confluence\", \"google_drive\"]}'",
        "claudeCode": "claude mcp add --transport http onyx https://cloud.onyx.app/mcp \\\n  --header \"Authorization: Bearer YOUR_ONYX_TOKEN_HERE\"",
        "config": {
          "mcpServers": {
            "onyx": {
              "headers": {
                "Authorization": "Bearer ${ONYX_TOKEN}"
              },
              "type": "http",
              "url": "https://cloud.onyx.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/onyx"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Onyx Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "billed annually"
        }
      ],
      "provenance": {
        "legalEntity": "DanswerAI, Inc.",
        "domain": "onyx.app",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://onyx.app/legal/cloud",
        "privacy": "https://onyx.app/legal/privacy-policy",
        "statusPage": "https://status.onyx.app",
        "changelog": "https://docs.onyx.app/changelog",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE and the Onyx Enterprise License name DanswerAI, Inc., and the site footer reads Onyx.",
          "The privacy policy and the Onyx Cloud Subscription Agreement show a last update of 1 July 2025 and load their text with JavaScript, which our reader couldn't see.",
          "onyx.app/.well-known/security.txt returns 404. SECURITY.md routes reports through GitHub private vulnerability reporting.",
          "The shared MCP endpoint cloud.onyx.app/mcp is on the vendor's domain. A self-hosted server answers on the operator's own host."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onyx.json",
      "live": {
        "slug": "onyx",
        "probe": {
          "target": "https://cloud.onyx.app/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:42:51.399914989Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 302,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 303,
          "p95ms24h": 335,
          "samples24h": 260,
          "samples30d": 1524,
          "days": [
            {
              "date": "2026-10-03",
              "probes": 54,
              "ok": 54
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.onyx.app",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:14.63709355Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "onyx-dot-app/onyx",
            "version": "v4.9.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:23:15.301712603Z"
          },
          {
            "registry": "pypi",
            "name": "onyx-cli",
            "version": "1.4.4",
            "released": "2026-09-13",
            "seenAt": "2026-10-08T16:23:15.106102182Z"
          }
        ],
        "githubStars": 32357,
        "pypiWeekly": 781,
        "securityTxt": {
          "url": "https://onyx.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:29.983427844Z"
        },
        "llmsTxt": {
          "url": "https://docs.onyx.app/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:42.879073728Z"
        },
        "domain": {
          "domain": "onyx.app",
          "registered": "2018-05-04",
          "source": "https://pubapi.registry.google/rdap/domain/onyx.app",
          "checkedAt": "2026-10-04T13:08:25.059354531Z"
        },
        "pages": [
          {
            "url": "https://docs.onyx.app/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:12.353203571Z",
            "changedAt": "2026-10-08T18:19:12.353203571Z",
            "fingerprint": "903bb0fb92dc"
          },
          {
            "url": "https://onyx.app/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:33.516398975Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bd896d976a98"
          },
          {
            "url": "https://onyx.app/legal/cloud",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:31.357169656Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b08a2af7854"
          }
        ],
        "updatedAt": "2026-10-09T10:42:51.399914989Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Permutation Labs",
        "b": "DanswerAI, Inc. (Onyx, formerly Danswer)",
        "name": "Vendor"
      },
      {
        "a": "https://dust.tt/mcp",
        "b": "https://cloud.onyx.app/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli",
        "b": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "3",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 17k npm/wk",
        "b": "32k stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Onyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Dust or Onyx?"
      },
      {
        "answer": "Yes. Dust has a hosted endpoint at https://dust.tt/mcp and Onyx at https://cloud.onyx.app/mcp.",
        "question": "Can an agent call Dust and Onyx without installing anything?"
      },
      {
        "answer": "Yes. Dust is open source (MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli`). Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).",
        "question": "Are Dust and Onyx open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Maintenance \u0026 community, 86 against 77",
          "Transparency \u0026 trust, 68 against 63"
        ],
        "also": [
          "No incidents deducted, where Onyx loses 4 points for them"
        ],
        "goodFor": "A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.",
        "slug": "dust",
        "watchFor": "Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use"
      },
      {
        "aheadOn": [
          "Reliability, 69 against 53",
          "Schema \u0026 documentation, 88 against 75",
          "Agent ergonomics, 77 against 67",
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "slug": "onyx",
        "watchFor": "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0"
      }
    ],
    "job": {
      "capability": "knowledge.search",
      "name": "Company knowledge search"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-dust.json",
        "title": "Alation vs Dust",
        "url": "https://www.anchorterminal.com/compare/alation-vs-dust"
      },
      {
        "json": "https://www.anchorterminal.com/compare/alation-vs-onyx.json",
        "title": "Alation vs Onyx",
        "url": "https://www.anchorterminal.com/compare/alation-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/atlan-vs-dust.json",
        "title": "Atlan vs Dust",
        "url": "https://www.anchorterminal.com/compare/atlan-vs-dust"
      },
      {
        "json": "https://www.anchorterminal.com/compare/atlan-vs-onyx.json",
        "title": "Atlan vs Onyx",
        "url": "https://www.anchorterminal.com/compare/atlan-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-dust.json",
        "title": "Cohere North vs Dust",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-dust"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx.json",
        "title": "Cohere North vs Onyx",
        "url": "https://www.anchorterminal.com/compare/cohere-north-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dust-vs-glean.json",
        "title": "Dust vs Glean",
        "url": "https://www.anchorterminal.com/compare/dust-vs-glean"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dust-vs-guru.json",
        "title": "Dust vs Guru",
        "url": "https://www.anchorterminal.com/compare/dust-vs-guru"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dust-vs-overclock.json",
        "title": "Dust vs Overclock",
        "url": "https://www.anchorterminal.com/compare/dust-vs-overclock"
      },
      {
        "json": "https://www.anchorterminal.com/compare/glean-vs-onyx.json",
        "title": "Glean vs Onyx",
        "url": "https://www.anchorterminal.com/compare/glean-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guru-vs-onyx.json",
        "title": "Guru vs Onyx",
        "url": "https://www.anchorterminal.com/compare/guru-vs-onyx"
      },
      {
        "json": "https://www.anchorterminal.com/compare/onyx-vs-overclock.json",
        "title": "Onyx vs Overclock",
        "url": "https://www.anchorterminal.com/compare/onyx-vs-overclock"
      }
    ],
    "scores": [
      {
        "by": 16,
        "dust": 53,
        "edge": "onyx",
        "key": "reliability",
        "name": "Reliability",
        "onyx": 69,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "dust": 75,
        "edge": "onyx",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "onyx": 88,
        "weight": 13
      },
      {
        "by": 10,
        "dust": 67,
        "edge": "onyx",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "onyx": 77,
        "weight": 13
      },
      {
        "by": 4,
        "dust": 75,
        "edge": "dust",
        "key": "security",
        "name": "Security \u0026 auth",
        "onyx": 71,
        "weight": 14
      },
      {
        "by": 10,
        "dust": 20,
        "edge": "onyx",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "onyx": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "dust": 86,
        "edge": "dust",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "onyx": 77,
        "weight": 7
      },
      {
        "by": 5,
        "dust": 68,
        "edge": "dust",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "onyx": 63,
        "weight": 7
      }
    ],
    "summary": "Onyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust. Both do company knowledge search.",
    "verdicts": {
      "dust": "The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.",
      "onyx": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/dust-vs-onyx",
    "json": "https://www.anchorterminal.com/compare/dust-vs-onyx.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/dust-vs-onyx.md",
    "slim": "https://www.anchorterminal.com/compare/dust-vs-onyx.min.md"
  },
  "markdown": "Onyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust. Both do company knowledge search.\n\n- Dust: grade B, 62.8/100, rank #378 of 842. Markdown https://www.anchorterminal.com/tools/dust.md · JSON https://www.anchorterminal.com/api/v1/tools/dust.json\n- Onyx: grade B, 65/100, rank #303 of 842. Markdown https://www.anchorterminal.com/tools/onyx.md · JSON https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Which one, for what\n\n### Dust (B)\n\nGood for: A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.\n\nAhead on:\n- Maintenance \u0026 community, 86 against 77\n- Transparency \u0026 trust, 68 against 63\n\nAlso in its favour:\n- No incidents deducted, where Onyx loses 4 points for them\n\nWatch for: Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use\n\n### Onyx (B)\n\nGood for: Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.\n\nAhead on:\n- Reliability, 69 against 53\n- Schema \u0026 documentation, 88 against 75\n- Agent ergonomics, 77 against 67\n- Payments \u0026 pricing, 30 against 20\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0\n\n\n## Score by category\n\n| Category | Weight | Dust | Onyx | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 53 | 69 | Onyx +16 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 75 | 88 | Onyx +13 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 77 | Onyx +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 75 | 71 | Dust +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 30 | Onyx +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 77 | Dust +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 68 | 63 | Dust +5 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **62.8 · B** | **65 · B** | |\n\n## Facts side by side\n\n| Fact | Dust | Onyx |\n| --- | --- | --- |\n| Kind | HTTP API | Model platform |\n| Vendor | Permutation Labs | DanswerAI, Inc. (Onyx, formerly Danswer) |\n| Hosted endpoint | `https://dust.tt/mcp` | `https://cloud.onyx.app/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli` | MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use |\n| Tools exposed | none | 3 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-10-08 | 2026-10-02 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no date given | couldn't be read |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 1.5k stars, 17k npm/wk | 32k stars |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Dust.** The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.\n\n**Onyx.** MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.\n\n## Before you call either\n\n### Dust\n\n1. Use `https://eu.dust.tt` for a workspace in the EU region and `https://dust.tt` otherwise, for both the API and the MCP server\n2. Connect an MCP client by OAuth and send the `resource` parameter in authorisation and token requests. API keys do not work on the MCP server\n3. Expect HTTP 429 with type `rate_limit_error` when the credit pool, the programmatic monthly cap or the key's spend cap is exhausted. Retrying will not help\n4. Call `GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25) and `cursor`, or a data source view's search with `top_k`\n5. Keep document upserts under 120 a minute per workspace\n\n### Onyx\n\n1. Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`\n2. Use a token limited to `read:search`. It covers every MCP tool and nothing else\n3. Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered\n4. Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors\n5. Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search\n\n## Questions\n\n### Which is better for AI agents, Dust or Onyx?\n\nOnyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust.\n\n### Can an agent call Dust and Onyx without installing anything?\n\nYes. Dust has a hosted endpoint at https://dust.tt/mcp and Onyx at https://cloud.onyx.app/mcp.\n\n### Are Dust and Onyx open source?\n\nYes. Dust is open source (MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli`). Onyx is open source (MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/dust-vs-onyx.json, and with the fewest tokens: https://www.anchorterminal.com/compare/dust-vs-onyx.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"dust\", \"b\": \"onyx\"}`. From a terminal: `anchor compare dust onyx`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/dust.json and https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Other comparisons with Dust or Onyx\n\n- [Alation vs Dust](https://www.anchorterminal.com/compare/alation-vs-dust.md)\n- [Alation vs Onyx](https://www.anchorterminal.com/compare/alation-vs-onyx.md)\n- [Atlan vs Dust](https://www.anchorterminal.com/compare/atlan-vs-dust.md)\n- [Atlan vs Onyx](https://www.anchorterminal.com/compare/atlan-vs-onyx.md)\n- [Cohere North vs Dust](https://www.anchorterminal.com/compare/cohere-north-vs-dust.md)\n- [Cohere North vs Onyx](https://www.anchorterminal.com/compare/cohere-north-vs-onyx.md)\n- [Dust vs Glean](https://www.anchorterminal.com/compare/dust-vs-glean.md)\n- [Dust vs Guru](https://www.anchorterminal.com/compare/dust-vs-guru.md)\n- [Dust vs Overclock](https://www.anchorterminal.com/compare/dust-vs-overclock.md)\n- [Glean vs Onyx](https://www.anchorterminal.com/compare/glean-vs-onyx.md)\n- [Guru vs Onyx](https://www.anchorterminal.com/compare/guru-vs-onyx.md)\n- [Onyx vs Overclock](https://www.anchorterminal.com/compare/onyx-vs-overclock.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Dust vs Onyx",
        "url": ""
      }
    ],
    "description": "Onyx scores 65 (B) on agent readiness against Dust's 62.8 (B), and leads in 4 of 7 scored categories. Dust leads on maintenance \u0026 community and transparency \u0026 trust. Both do company knowledge search. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Dust B 62.8",
      "Onyx B 65",
      "scores"
    ],
    "h1": "Dust vs Onyx",
    "image": "https://www.anchorterminal.com/assets/og/compare-dust-vs-onyx.png",
    "path": "/compare/dust-vs-onyx",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Dust vs Onyx for AI agents, B 62.8 vs B 65 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/dust-vs-onyx"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 780
  },
  "version": 1
}
