{
  "data": {
    "a": {
      "slug": "glean",
      "name": "Glean",
      "vendor": "Glean Technologies, Inc.",
      "vendorUrl": "https://www.glean.com",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Enterprise search and AI assistant from Glean Technologies in San Francisco.",
      "url": "https://www.anchorterminal.com/tools/glean",
      "markdownUrl": "https://www.anchorterminal.com/tools/glean.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/glean.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/glean.json",
      "repo": "https://github.com/gleanwork/open-api",
      "license": "Proprietary service under Glean's terms of service. The OpenAPI specs repository, the API clients and the Glean CLI on GitHub are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "glean-api-client"
        },
        {
          "registry": "npm",
          "name": "@gleanwork/api-client"
        },
        {
          "registry": "go",
          "name": "github.com/gleanwork/api-client-go"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every API takes a Bearer token at https://\u003cinstance\u003e-be.glean.com. The Client API and the MCP server accept OAuth access tokens from Glean's own authorisation server, which supports dynamic client registration, or from the company's identity provider with `X-Glean-Auth-Type: OAUTH`. Glean-issued tokens carry any of 19 scopes (SEARCH, CHAT, DOCUMENTS, MCP, TOOLS and others), can expire, and can't change scope after creation. A user-scoped token works with its owner's access. A global token, which only a Super Admin can create, can impersonate whichever user is named in `X-Glean-ActAs`. The Indexing API takes only Glean-issued tokens.",
      "pricing": "paid",
      "pricingNotes": "No public prices. glean.com/pricing lands on the home page, whose buttons ask for a demo, and we found no trial, free tier or self-serve signup. The Platform API's error list includes `spend_limit_exceeded` (403), so some usage is metered against a limit, with no published unit price (checked 2026-10-03).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 57955,
        "pypiWeekly": 25682,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://developers.glean.com",
      "llmsTxt": "https://developers.glean.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/gleanwork/open-api/main/final_specs/client_rest.yaml",
      "capabilities": [
        "knowledge.search",
        "memory.graph",
        "agent.mcp-client"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "java",
        "sales-led",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.8,
        "grade": "B",
        "agentReady": false,
        "rank": 106,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 85,
          "payments": 0,
          "reliability": 60,
          "schema": 93,
          "security": 87,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": 0,
        "verdict": "Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs. No public price, trial or self-serve signup. Access starts with a demo request.",
        "strengths": [
          "Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs",
          "OAuth with dynamic client registration, or Glean-issued tokens with 19 scopes, user-scoped or global, and optional expiry",
          "Source-system permissions enforced on every search, chat and document read through the MCP server",
          "MCP activity logs filterable by server, tool, user and date, and admin audit logs for MCP settings",
          "Six-month deprecation policy with fixed removal dates and an `X-Glean-Deprecated` response header"
        ],
        "weaknesses": [
          "No public price, trial or self-serve signup. Access starts with a demo request",
          "Eight incidents on status.glean.com between 10 July and 3 September 2026, seven marked major, most on Chat and the Assistant",
          "No idempotency keys, and no documented confirmation step for MCP tools that write",
          "A global token can act as any user named in `X-Glean-ActAs`",
          "The privacy statement covers only the website, and product data handling sits in a DPA and order forms"
        ],
        "agentNotes": [
          "Get the backend host from the Glean admin. APIs answer at https://\u003cinstance\u003e-be.glean.com and MCP at that host under /mcp/\u003cserver-name\u003e",
          "Ask for a user-scoped token with only the scopes the task needs. A global token can impersonate whoever `X-Glean-ActAs` names",
          "Keep chat under 0.5 calls a second and search under 5, and back off on 429",
          "Call the Platform API's `/api/search` for typed filters, `page_size` up to 100 and problem+json errors",
          "Send `X-Glean-Exclude-Deprecated-After` in tests to catch fields due for removal"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.8
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 85,
          "payments": 0,
          "reliability": 60,
          "schema": 93,
          "security": 87,
          "transparency": 70
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "pip install glean-api-client",
        "claudeCode": "/plugin marketplace add gleanwork/claude-plugins\n/plugin install glean@glean-plugins"
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/glean"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Glean Technologies, Inc.",
        "domain": "glean.com",
        "domainRegistered": "1998-11-22",
        "endpointOnVendorDomain": true,
        "terms": "https://cdn.prod.website-files.com/6127a84dfe068e153ef20572/66e479a764b6346acabb92b2_Glean%20Technologies,%20Inc.%20Terms%20of%20Service%20Sep%203%202024%20(Online)%20(1).pdf",
        "privacy": "https://www.glean.com/privacy",
        "statusPage": "https://status.glean.com",
        "changelog": "https://developers.glean.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The privacy statement (effective 1 April 2026) names Glean Technologies, Inc., 634 2nd Street, San Francisco, CA 94107, and says it doesn't apply to use of Glean's products.",
          "Each customer's APIs answer at https://\u003cinstance\u003e-be.glean.com, a glean.com subdomain, and the MCP server at the same backend under /mcp/\u003cserver-name\u003e.",
          "www.glean.com/.well-known/security.txt returns 404. The security page sends reports to the public Bugcrowd programme.",
          "The online terms of service we read are version v3Sep2024 and incorporate a Customer SLA at glean.com/legal/sla, which refused our reader. The DPA of 6 March 2026 is published as a PDF on assets.glean.com, which also refused our reader.",
          "RDAP for glean.com gives a registration date of 1998-11-22 and Squarespace Domains II LLC as registrar."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/glean.json",
      "live": {
        "slug": "glean",
        "vendorStatus": {
          "page": "https://status.glean.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:05.765648096Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@gleanwork/api-client",
            "version": "0.20.16",
            "seenAt": "2026-10-04T16:28:12.699611341Z"
          },
          {
            "registry": "pypi",
            "name": "glean-api-client",
            "version": "0.17.16",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:28:12.512438211Z"
          }
        ],
        "githubStars": 6,
        "npmWeekly": 55060,
        "pypiWeekly": 25762,
        "securityTxt": {
          "url": "https://glean.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.958360964Z"
        },
        "llmsTxt": {
          "url": "https://developers.glean.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:48.633794275Z"
        },
        "domain": {
          "domain": "glean.com",
          "registered": "1998-11-22",
          "source": "https://rdap.verisign.com/com/v1/domain/glean.com",
          "checkedAt": "2026-10-04T13:08:57.704851401Z"
        },
        "pages": [
          {
            "url": "https://developers.glean.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:49.699758916Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "25a50be170ab"
          },
          {
            "url": "https://www.glean.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:50:30.172227736Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "21e2e31df0e2"
          }
        ],
        "updatedAt": "2026-10-04T21:40:05.765648096Z"
      }
    },
    "b": {
      "slug": "onyx",
      "name": "Onyx",
      "vendor": "DanswerAI, Inc. (Onyx, formerly Danswer)",
      "vendorUrl": "https://www.onyx.app",
      "kind": "platform",
      "category": "company-knowledge",
      "summary": "Open-source enterprise search and chat platform, formerly Danswer.",
      "url": "https://www.anchorterminal.com/tools/onyx",
      "markdownUrl": "https://www.anchorterminal.com/tools/onyx.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onyx.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onyx.json",
      "repo": "https://github.com/onyx-dot-app/onyx",
      "license": "MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://cloud.onyx.app/mcp",
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-backend"
        },
        {
          "registry": "oci",
          "name": "docker.io/onyxdotapp/onyx-web-server"
        },
        {
          "registry": "pypi",
          "name": "onyx-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every request takes a Bearer token in the `Authorization` header, either a personal access token or an API key. Personal access tokens belong to a user, can be full access or limited to `read:search`, `read:chat`, `write:chat` or `use:llm_gateway`, expire after 7, 30 or 365 days or never, are stored hashed and can be revoked one by one. API keys belong to service accounts, and since v4.7 their rights come from the groups they're put in (none means chat only, Basic adds search, Admin reaches every endpoint). The MCP server checks each token against the API server's /me and passes it through. No OAuth for MCP clients. People sign in to the web app with passwords, Google OAuth, OIDC or SAML.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is MIT and free to self-host with no seat limit. Onyx Cloud and licensed self-hosting have two plans on onyx.app/pricing. Business is $20 a user a month billed annually, and Enterprise (OIDC and SAML SSO, on-premise and region-specific deployments, white-labelling, an enterprise SLA) is by quote. Single-tenant cloud needs at least 100 licences per the docs. Onyx Cloud has a two-week free trial with no card (checked 2026-10-03).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 32300,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.onyx.app/deployment/configuration/mcp_server",
      "llmsTxt": "https://docs.onyx.app/llms.txt",
      "openapi": "https://docs.onyx.app/developers/api_reference/openapi.json",
      "capabilities": [
        "knowledge.search",
        "web.search",
        "web.fetch",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "cli",
        "docker",
        "freemium",
        "no-card",
        "enterprise",
        "commercial-licence",
        "telemetry-default-on",
        "status-page"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 176,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-07-20. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0). Any signed-in user could read, in clear text, other users' live OAuth tokens for per-user MCP servers such as Slack, Atlassian or Notion through GET /api/mcp/servers. Found in an external pentest in May 2026, fixed in 4.0.0 (26 May 2026) and published, so the deduction is reduced, -3 (https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822)",
          "2026-04-29 and 2026-07-20. Three moderate IDOR advisories, other users' chat files downloadable through /chat/file/{file_id} (GHSA-vg3h-35f7-7w6r), other users' chat sessions stoppable through /chat/stop-chat-session (GHSA-rw6w-hp62-gc8w) and curators able to change any user group's membership (GHSA-7f48-vgpj-h95m). Fixed and published, -1 (https://github.com/onyx-dot-app/onyx/security/advisories)"
        ],
        "verdict": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.",
        "strengths": [
          "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card",
          "Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped",
          "Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one",
          "OpenAPI 3.1 file of 110 operations, llms.txt, Markdown docs and dated release notes with Deployment Changes sections",
          "A minor release every two to three weeks, 4.3.0 on 6 July to 4.8.0 on 23 September 2026, with patches for older lines"
        ],
        "weaknesses": [
          "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0",
          "Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain",
          "Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line",
          "The self-hosted MCP server is off by default, takes no OAuth and isn't in the official MCP registry",
          "The privacy policy and Cloud agreement render only with JavaScript, and there's no security.txt or bug bounty"
        ],
        "agentNotes": [
          "Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`",
          "Use a token limited to `read:search`. It covers every MCP tool and nothing else",
          "Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered",
          "Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors",
          "Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 77,
          "payments": 30,
          "reliability": 69,
          "schema": 88,
          "security": 71,
          "transparency": 57
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "curl -fsSL https://onyx.app/install_onyx.sh | bash",
        "http": "curl -s -X POST \"${API_BASE_URL}/search\" \\\n  -H \"Authorization: Bearer ${API_KEY}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"What is our parental leave policy?\", \"sources\": [\"confluence\", \"google_drive\"]}'",
        "claudeCode": "claude mcp add --transport http onyx https://cloud.onyx.app/mcp \\\n  --header \"Authorization: Bearer YOUR_ONYX_TOKEN_HERE\"",
        "config": {
          "mcpServers": {
            "onyx": {
              "headers": {
                "Authorization": "Bearer ${ONYX_TOKEN}"
              },
              "type": "http",
              "url": "https://cloud.onyx.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/onyx"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Onyx Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "billed annually"
        }
      ],
      "provenance": {
        "legalEntity": "DanswerAI, Inc.",
        "domain": "onyx.app",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://onyx.app/legal/cloud",
        "privacy": "https://onyx.app/legal/privacy-policy",
        "statusPage": "https://status.onyx.app",
        "changelog": "https://docs.onyx.app/changelog",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE and the Onyx Enterprise License name DanswerAI, Inc., and the site footer reads Onyx.",
          "The privacy policy and the Onyx Cloud Subscription Agreement show a last update of 1 July 2025 and load their text with JavaScript, which our reader couldn't see.",
          "onyx.app/.well-known/security.txt returns 404. SECURITY.md routes reports through GitHub private vulnerability reporting.",
          "The shared MCP endpoint cloud.onyx.app/mcp is on the vendor's domain. A self-hosted server answers on the operator's own host."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onyx.json",
      "live": {
        "slug": "onyx",
        "probe": {
          "target": "https://cloud.onyx.app/mcp",
          "method": "get",
          "lastAt": "2026-10-05T01:43:42.152273625Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 322,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 300,
          "p95ms24h": 336,
          "samples24h": 272,
          "samples30d": 346,
          "days": [
            {
              "date": "2026-10-03",
              "probes": 54,
              "ok": 54
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.onyx.app",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:17.588909816Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "onyx-dot-app/onyx",
            "version": "v4.8.4",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:35:07.311859267Z"
          },
          {
            "registry": "pypi",
            "name": "onyx-cli",
            "version": "1.4.4",
            "released": "2026-09-13",
            "seenAt": "2026-10-04T16:35:07.120342955Z"
          }
        ],
        "githubStars": 32325,
        "pypiWeekly": 914,
        "securityTxt": {
          "url": "https://onyx.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:58.329449816Z"
        },
        "llmsTxt": {
          "url": "https://docs.onyx.app/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:04.266338454Z"
        },
        "domain": {
          "domain": "onyx.app",
          "registered": "2018-05-04",
          "source": "https://pubapi.registry.google/rdap/domain/onyx.app",
          "checkedAt": "2026-10-04T13:08:25.059354531Z"
        },
        "pages": [
          {
            "url": "https://docs.onyx.app/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:51.460009547Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0bd6f9a481b1"
          },
          {
            "url": "https://onyx.app/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:24.128165502Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bd896d976a98"
          },
          {
            "url": "https://onyx.app/legal/cloud",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:21.377587416Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b08a2af7854"
          }
        ],
        "updatedAt": "2026-10-05T01:43:42.152273625Z"
      }
    },
    "summary": "Glean has a score of 69.8 (B) against Onyx's 65.3 (B). Both do company knowledge search. The largest gap is payments \u0026 pricing, 30 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/glean-vs-onyx",
    "json": "https://www.anchorterminal.com/compare/glean-vs-onyx.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/glean-vs-onyx.md",
    "slim": "https://www.anchorterminal.com/compare/glean-vs-onyx.min.md"
  },
  "markdown": "Glean has a score of 69.8 (B) against Onyx's 65.3 (B). Both do company knowledge search. The largest gap is payments \u0026 pricing, 30 points.\n\n- Glean: grade B, 69.8/100, rank #106 of 452. Markdown https://www.anchorterminal.com/tools/glean.md · JSON https://www.anchorterminal.com/api/v1/tools/glean.json\n- Onyx: grade B, 65.3/100, rank #176 of 452. Markdown https://www.anchorterminal.com/tools/onyx.md · JSON https://www.anchorterminal.com/api/v1/tools/onyx.json\n\n## Which one, for what\n\nPick Glean for schema \u0026 documentation (+5), security \u0026 auth (+16), maintenance \u0026 community (+8), transparency \u0026 trust (+14).\n\nPick Onyx for reliability (+9), payments \u0026 pricing (+30).\n\n## Score by category\n\n| Category | Weight | Glean | Onyx | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 69 | Onyx +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 93 | 88 | Glean +5 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 77 | Glean +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 87 | 71 | Glean +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 30 | Onyx +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 77 | Glean +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 66 | Glean +14 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **69.8 · B** | **65.3 · B** | |\n\n## Facts side by side\n\n| Fact | Glean | Onyx |\n| --- | --- | --- |\n| Kind | HTTP API | Model platform |\n| Vendor | Glean Technologies, Inc. | DanswerAI, Inc. (Onyx, formerly Danswer) |\n| Hosted endpoint | no (local only) | `https://cloud.onyx.app/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Glean's terms of service. The OpenAPI specs repository, the API clients and the Glean CLI on GitHub are MIT | MIT (Community Edition, including the MCP server, the API server, the CLI and the connectors). Code under the `ee` directories is under the Onyx Enterprise License, which needs a subscription for production use |\n| Tools exposed | none | 3 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-02 | 2026-10-02 |\n| Popularity | 58k npm/wk, 26k PyPI/wk | 32k stars |\n| Agent reviews | 3.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Glean.** Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs. No public price, trial or self-serve signup. Access starts with a demo request.\n\n**Onyx.** MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.\n\n## Before you call either\n\n### Glean\n\n1. Get the backend host from the Glean admin. APIs answer at https://\u003cinstance\u003e-be.glean.com and MCP at that host under /mcp/\u003cserver-name\u003e\n2. Ask for a user-scoped token with only the scopes the task needs. A global token can impersonate whoever `X-Glean-ActAs` names\n3. Keep chat under 0.5 calls a second and search under 5, and back off on 429\n4. Call the Platform API's `/api/search` for typed filters, `page_size` up to 100 and problem+json errors\n5. Send `X-Glean-Exclude-Deprecated-After` in tests to catch fields due for removal\n\n### Onyx\n\n1. Get the instance URL from the operator. Cloud is https://cloud.onyx.app/mcp, and a self-hosted server only answers once `MCP_SERVER_ENABLED=true`\n2. Use a token limited to `read:search`. It covers every MCP tool and nothing else\n3. Pass `time_cutoff` as a full ISO 8601 timestamp. A value that doesn't parse is dropped and the search runs unfiltered\n4. Check each result for an `error` field. Failures come back with an empty `results` list, not as tool errors\n5. Set `skip_query_expansion` to true for exact phrases. It skips an LLM call on every search\n\n## Other comparisons with Glean or Onyx\n\n- [Atlan vs Glean](https://www.anchorterminal.com/compare/atlan-vs-glean.md)\n- [Atlan vs Onyx](https://www.anchorterminal.com/compare/atlan-vs-onyx.md)\n- [Glean vs Guru](https://www.anchorterminal.com/compare/glean-vs-guru.md)\n- [Glean vs Overclock](https://www.anchorterminal.com/compare/glean-vs-overclock.md)\n- [Guru vs Onyx](https://www.anchorterminal.com/compare/guru-vs-onyx.md)\n- [Onyx vs Overclock](https://www.anchorterminal.com/compare/onyx-vs-overclock.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Glean vs Onyx",
        "url": ""
      }
    ],
    "description": "Glean has a score of 69.8 (B) against Onyx's 65.3 (B). Both do company knowledge search. The largest gap is payments \u0026 pricing, 30 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Glean B 69.8",
      "Onyx B 65.3",
      "scores"
    ],
    "h1": "Glean vs Onyx",
    "image": "https://www.anchorterminal.com/assets/og/compare-glean-vs-onyx.png",
    "path": "/compare/glean-vs-onyx",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Glean vs Onyx for AI agents, B 69.8 vs B 65.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/glean-vs-onyx"
  },
  "tokens": {
    "markdown": 1400,
    "slim": 330
  },
  "version": 1
}
