{
  "data": {
    "a": {
      "slug": "grist",
      "name": "Grist",
      "vendor": "Grist Labs Inc.",
      "vendorUrl": "https://www.getgrist.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/grist",
      "markdownUrl": "https://www.anchorterminal.com/tools/grist.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/grist.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/grist.json",
      "repo": "https://github.com/gristlabs/grist-core",
      "license": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://docs.getgrist.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "grist-api"
        },
        {
          "registry": "pypi",
          "name": "grist-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates an API key on the Developer page of account settings and sends it as `Authorization: Bearer`. The key carries its owner's full account access, and each account has one. The alternative is OAuth 2.0 with PKCE, used by the MCP server and by registered apps. The user approves any of seven scopes (`doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`) and can limit the grant to chosen sites, workspaces or documents. Access tokens last 1 hour and refresh tokens 60 days, and a grant can be revoked per app. Clients can register themselves by Client ID Metadata Document. Not every REST endpoint accepts an OAuth token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 5,000 rows a document and 3,000 API calls a month per site, REST and MCP calls together, so an agent can start without a contract. Pro is $10 a user a month ($8 billed yearly) and Business $30 ($24 yearly, minimum 5 users), Enterprise through sales. API calls aren't priced, the MCP server is on every plan for now, and there's no separate sandbox. The self-hosted community edition is free (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": 11900,
        "npmWeekly": 341,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://support.getgrist.com/rest-api/",
      "openapi": "https://raw.githubusercontent.com/gristlabs/grist-help/master/api/grist.yml",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "oauth",
        "api-key",
        "openapi",
        "webhooks",
        "python",
        "javascript"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.1,
        "grade": "D",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-13. GHSA-9x4j-4rw5-3vmq, critical (CVSS 10.0), remote code execution through prototype pollution from an imported crafted document, affecting Docker images before 1.7.19 and fixed in 1.7.19. Four more advisories were published in the last 12 months, among them GHSA-7xvx-8pf2-pv5g (CVE-2026-24002, critical, 21 January 2026) on the pyodide sandbox option, fixed in 1.7.9. All five are fixed and published and none says whether hosted Grist was affected, so the deduction is reduced (https://github.com/gristlabs/grist-core/security/advisories)"
        ],
        "verdict": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
        "bestFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "strengths": [
          "OAuth 2.0 with PKCE and seven scopes, with `doc:read`, `doc:write` and `doc.schema:write` granted separately and the grant limited to chosen sites, workspaces or documents",
          "Access tokens last 1 hour, refresh tokens 60 days, and a user can revoke one app's grant from the Authorised apps page",
          "Public OpenAPI 3.0.0 file with 101 paths and 120 operations, including a read-only SQL endpoint and `PUT` on `/records` to add or update by key columns",
          "Limits are published with numbers per plan, with 10 concurrent requests per document and a 1 MB request body on every plan",
          "The core is Apache-2.0 and four releases were tagged between 29 July and 28 September 2026"
        ],
        "weaknesses": [
          "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none",
          "An API key carries its owner's full account access, and each account has one key, so it can't be limited to a document or revoked per integration",
          "The data security page says hosted Grist has no SOC 2, ISO 27001, HIPAA or GDPR certification, and no DPA, sub-processor list or security.txt was found",
          "The MCP server and OAuth server are in the proprietary full edition, so the Apache-2.0 community edition has neither and the tool definitions aren't public",
          "Five security advisories were published in the last 12 months, two rated critical, the latest on 13 September 2026 with CVSS 10.0",
          "The Free plan allows 3,000 API calls a month across a site, with REST and MCP calls sharing the pool"
        ],
        "agentNotes": [
          "Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen",
          "Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules",
          "Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented",
          "Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row",
          "Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.1
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 50
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "pip install grist-api",
        "http": "curl -H \"Authorization: Bearer \u003cAPI-KEY-GOES-HERE\u003e\" https://docs.getgrist.com/api/orgs",
        "claudeCode": "claude mcp add --transport http grist https://docs.getgrist.com/api/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/grist"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro (hosted)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed monthly, $8 billed yearly, 100,000 rows a document, 40,000 API calls per document per day"
        },
        {
          "item": "Business (hosted)",
          "unit": "seat-month",
          "usd": 30,
          "note": "billed monthly, $24 billed yearly, minimum 5 users, 150,000 rows a document, 60,000 API calls per document per day"
        }
      ],
      "provenance": {
        "legalEntity": "Grist Labs Inc.",
        "domain": "getgrist.com",
        "domainRegistered": "2014-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.getgrist.com/terms/",
        "privacy": "https://www.getgrist.com/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/gristlabs/grist-core/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms page is an End-User Licence Agreement between the user and Grist Labs Inc., covering its products, software, services and websites, governed by New York State law, with legal notices to 93 4th Ave, #1127, New York, NY 10003. It carries no date.",
          "The privacy policy has an effective date of 1 April 2019 and covers the websites, products and services. It names no retention periods.",
          "The REST API and MCP server answer at docs.getgrist.com and \u003cteam\u003e.getgrist.com, and OAuth at login.getgrist.com, all getgrist.com subdomains.",
          "No status page was found. status.getgrist.com redirects to a signup form because every subdomain is treated as a team site.",
          "www.getgrist.com/.well-known/security.txt and docs.getgrist.com/.well-known/security.txt return 404. SECURITY.md in the repository gives security@getgrist.com.",
          "RDAP for getgrist.com gives a registration date of 2014-05-12."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/grist.json",
      "live": {
        "slug": "grist",
        "probe": {
          "target": "https://docs.getgrist.com/api",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.613117891Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 251,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 256,
          "p95ms24h": 311,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "updatedAt": "2026-10-08T21:12:11.613117891Z"
      }
    },
    "answer": "Microsoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "microsoft-excel-graph",
      "name": "Microsoft Excel (Microsoft Graph workbook API)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/excel-concept-overview",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Workbook endpoints of Microsoft Graph for Excel files stored in OneDrive for work or school and SharePoint. Calls read and write ranges, tables, charts and named items, and run Excel worksheet functions on a file in place.",
      "url": "https://www.anchorterminal.com/tools/microsoft-excel-graph",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. The workbook reference pages list delegated permissions only, with Files.ReadWrite as least privileged, and mark application permissions as not supported. The overview page names Files.Read for read actions. A delegated token reaches every file its user can open.",
      "pricing": "byo-plan",
      "pricingNotes": "Workbook calls carry no per-call charge. Microsoft's list of metered Graph APIs names only SharePoint and OneDrive `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Files must sit in OneDrive for work or school or SharePoint, which need a Microsoft 365 licence. The Microsoft 365 plan price page refused our reader on 2026-10-08. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and members of named partner programmes (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the workbook documentation or the metered API list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/excel",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2025-09-19",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.5,
        "grade": "C",
        "agentReady": false,
        "rank": 450,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 53,
          "payments": 15,
          "reliability": 62,
          "schema": 85,
          "security": 65,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 8 October 2026 and the repository lists no published advisory. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the workbook API through that client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.",
        "bestFor": "Agents working on .xlsx files that already live in a Microsoft 365 tenant, and for using Excel's calculation engine through function endpoints.",
        "strengths": [
          "Non-persistent sessions (`persistChanges: false`) keep changes in a temporary copy, so an agent can calculate or test edits without saving",
          "The OpenAPI for Graph v1.0 holds 1,442 workbook paths and 1,765 operations, 366 of the paths for worksheet functions",
          "Error handling guide gives a retry instruction for each of 22 required second-level error codes",
          "Throttling limits are published at 5,000 requests per 10 seconds per app and 1,500 per app per tenant, with `Retry-After` on throttled responses",
          "Microsoft's policy is at least 24 months' notice before a generally available Graph API is removed"
        ],
        "weaknesses": [
          "Reference pages list delegated permissions only and mark application permissions as not supported",
          "Files.ReadWrite is the least privileged permission on the reference pages, even for reading a range or listing rows",
          "No idempotency key on writes. The row-add page says to repeat the request on a 504",
          "Cell values, formulas and number formats are untyped JSON in the OpenAPI",
          "The last Workbooks and charts changelog entry is dated 19 September 2025, and the overview page is dated March 2024"
        ],
        "agentNotes": [
          "Create a session with POST /workbook/createSession and send `workbook-session-id` on every call. Persistent sessions expire after about 5 minutes idle",
          "Set `persistChanges` to false when you only need a calculation or a chart image, so nothing is saved to the file",
          "Send one request at a time per workbook and wait for each response. Microsoft warns that parallel writes cause throttling, timeouts and merge conflicts",
          "Add rows in one call with a two-dimensional `values` array, and check the table before repeating a row add that returned 504",
          "Read bounded addresses such as A1:D500. A whole-column range such as C:C returns null for values, and writes to it are refused"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.5
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 53,
          "payments": 15,
          "reliability": 62,
          "schema": 85,
          "security": 65,
          "transparency": 65
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl https://graph.microsoft.com/v1.0/me/drive/items/{id}/workbook/worksheets \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\" \\\n  -H \"workbook-session-id: $SESSION_ID\""
      },
      "letme": {
        "capability": "https://letme.dev/sheets.read",
        "tool": "https://letme.dev/microsoft-excel-graph"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "outlook-mail-graph"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.json",
      "live": {
        "slug": "microsoft-excel-graph",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-08T21:12:15.715687497Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 23,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 22,
          "p95ms24h": 57,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.cloud.microsoft",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:36:56.168932402Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "microsoftgraph/msgraph-sdk-javascript",
            "version": "3.0.7",
            "released": "2023-09-19",
            "seenAt": "2026-10-08T16:20:40.005701271Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/microsoft-graph-client",
            "version": "3.0.7",
            "seenAt": "2026-10-08T16:20:38.997085198Z"
          },
          {
            "registry": "pypi",
            "name": "msgraph-sdk",
            "version": "1.64.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:20:39.875494563Z"
          }
        ],
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://developer.microsoft.com/en-us/graph/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:14.635541799Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7bb1f9551c94"
          }
        ],
        "updatedAt": "2026-10-08T21:12:15.715687497Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Grist Labs Inc.",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://docs.getgrist.com/api",
        "b": "https://graph.microsoft.com/v1.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Your plan",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
        "b": "MIT (SDKs)",
        "name": "Licence"
      },
      {
        "a": "34",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2025-09-19",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "2019-04-01",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "12k stars, 341 npm/wk, 240 PyPI/wk",
        "b": "835 stars, 2.9M npm/wk, 1.6M PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Grist or Microsoft Excel (Microsoft Graph workbook API)?"
      },
      {
        "answer": "Grist takes an API key or an OAuth sign-in. Microsoft Excel (Microsoft Graph workbook API) uses an OAuth sign-in.",
        "question": "Do Grist and Microsoft Excel (Microsoft Graph workbook API) need an API key?"
      },
      {
        "answer": "Yes. Grist has a hosted endpoint at https://docs.getgrist.com/api and Microsoft Excel (Microsoft Graph workbook API) at https://graph.microsoft.com/v1.0.",
        "question": "Can an agent call Grist and Microsoft Excel (Microsoft Graph workbook API) without installing anything?"
      },
      {
        "answer": "Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for Microsoft Excel (Microsoft Graph workbook API).",
        "question": "Are Grist and Microsoft Excel (Microsoft Graph workbook API) open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 15",
          "Maintenance \u0026 community, 78 against 53"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "slug": "grist",
        "watchFor": "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none"
      },
      {
        "aheadOn": [
          "Reliability, 62 against 39",
          "Schema \u0026 documentation, 85 against 63",
          "Agent ergonomics, 73 against 57",
          "Transparency \u0026 trust, 75 against 61"
        ],
        "also": null,
        "goodFor": "Agents working on .xlsx files that already live in a Microsoft 365 tenant, and for using Excel's calculation engine through function endpoints.",
        "slug": "microsoft-excel-graph",
        "watchFor": "Reference pages list delegated permissions only and mark application permissions as not supported"
      }
    ],
    "job": {
      "capability": "sheets.read",
      "name": "Sheets read"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-microsoft-excel-graph.json",
        "title": "Airtable vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph.json",
        "title": "Baserow vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-grist.json",
        "title": "Coda (Superhuman Docs) vs Grist",
        "url": "https://www.anchorterminal.com/compare/coda-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.json",
        "title": "Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.json",
        "title": "Google Sheets API vs Grist",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-microsoft-excel-graph.json",
        "title": "Google Sheets API vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-seatable.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-teable.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs Teable",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-grist.json",
        "title": "Airtable vs Grist",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-grist.json",
        "title": "Baserow vs Grist",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-nocodb.json",
        "title": "Grist vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/grist-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-seatable.json",
        "title": "Grist vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.json",
        "title": "Grist vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/grist-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-teable.json",
        "title": "Grist vs Teable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-teable"
      }
    ],
    "scores": [
      {
        "by": 23,
        "edge": "microsoft-excel-graph",
        "grist": 39,
        "key": "reliability",
        "microsoft-excel-graph": 62,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 22,
        "edge": "microsoft-excel-graph",
        "grist": 63,
        "key": "schema",
        "microsoft-excel-graph": 85,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 16,
        "edge": "microsoft-excel-graph",
        "grist": 57,
        "key": "ergonomics",
        "microsoft-excel-graph": 73,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 3,
        "edge": "microsoft-excel-graph",
        "grist": 62,
        "key": "security",
        "microsoft-excel-graph": 65,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 15,
        "edge": "grist",
        "grist": 30,
        "key": "payments",
        "microsoft-excel-graph": 15,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "grist",
        "grist": 78,
        "key": "maintenance",
        "microsoft-excel-graph": 53,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 14,
        "edge": "microsoft-excel-graph",
        "grist": 61,
        "key": "transparency",
        "microsoft-excel-graph": 75,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community. Both do sheets read.",
    "verdicts": {
      "grist": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
      "microsoft-excel-graph": "Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph",
    "json": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.md",
    "slim": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.min.md"
  },
  "markdown": "Microsoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community. Both do sheets read.\n\n- Grist: grade D, 50.1/100, rank #597 of 722. Markdown https://www.anchorterminal.com/tools/grist.md · JSON https://www.anchorterminal.com/api/v1/tools/grist.json\n- Microsoft Excel (Microsoft Graph workbook API): grade C, 58.5/100, rank #450 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-excel-graph.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json\n\n## Which one, for what\n\n### Grist (D)\n\nGood for: Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 15\n- Maintenance \u0026 community, 78 against 53\n\nAlso in its favour:\n- Open source\n\nWatch for: No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none\n\n### Microsoft Excel (Microsoft Graph workbook API) (C)\n\nGood for: Agents working on .xlsx files that already live in a Microsoft 365 tenant, and for using Excel's calculation engine through function endpoints.\n\nAhead on:\n- Reliability, 62 against 39\n- Schema \u0026 documentation, 85 against 63\n- Agent ergonomics, 73 against 57\n- Transparency \u0026 trust, 75 against 61\n\nWatch for: Reference pages list delegated permissions only and mark application permissions as not supported\n\n\n## Score by category\n\n| Category | Weight | Grist | Microsoft Excel (Microsoft Graph workbook API) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 39 | 62 | Microsoft Excel (Microsoft Graph workbook API) +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 63 | 85 | Microsoft Excel (Microsoft Graph workbook API) +22 |\n| Agent ergonomics | 13% (16.2 this run) | 57 | 73 | Microsoft Excel (Microsoft Graph workbook API) +16 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 65 | Microsoft Excel (Microsoft Graph workbook API) +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 15 | Grist +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 53 | Grist +25 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 75 | Microsoft Excel (Microsoft Graph workbook API) +14 |\n| Negative events | ≤15 | -4 | -4 | |\n| **Total** | | **50.1 · D** | **58.5 · C** | |\n\n## Facts side by side\n\n| Fact | Grist | Microsoft Excel (Microsoft Graph workbook API) |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Grist Labs Inc. | Microsoft |\n| Hosted endpoint | `https://docs.getgrist.com/api` | `https://graph.microsoft.com/v1.0` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Your plan |\n| x402 | no | no |\n| Licence | Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 | MIT (SDKs) |\n| Tools exposed | 34 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | no | no |\n| Last release | 2026-09-28 | 2025-09-19 |\n| Terms last updated | no date given | 2025-10-01 |\n| Privacy policy last updated | 2019-04-01 | 2026-09-01 |\n| Customer content may train models | not found in the text | yes |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 12k stars, 341 npm/wk, 240 PyPI/wk | 835 stars, 2.9M npm/wk, 1.6M PyPI/wk |\n\n## Verdicts\n\n**Grist.** OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.\n\n**Microsoft Excel (Microsoft Graph workbook API).** Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.\n\n## Before you call either\n\n### Grist\n\n1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen\n2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules\n3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented\n4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row\n5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit\n\n### Microsoft Excel (Microsoft Graph workbook API)\n\n1. Create a session with POST /workbook/createSession and send `workbook-session-id` on every call. Persistent sessions expire after about 5 minutes idle\n2. Set `persistChanges` to false when you only need a calculation or a chart image, so nothing is saved to the file\n3. Send one request at a time per workbook and wait for each response. Microsoft warns that parallel writes cause throttling, timeouts and merge conflicts\n4. Add rows in one call with a two-dimensional `values` array, and check the table before repeating a row add that returned 504\n5. Read bounded addresses such as A1:D500. A whole-column range such as C:C returns null for values, and writes to it are refused\n\n## Questions\n\n### Which is better for AI agents, Grist or Microsoft Excel (Microsoft Graph workbook API)?\n\nMicrosoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Grist and Microsoft Excel (Microsoft Graph workbook API) need an API key?\n\nGrist takes an API key or an OAuth sign-in. Microsoft Excel (Microsoft Graph workbook API) uses an OAuth sign-in.\n\n### Can an agent call Grist and Microsoft Excel (Microsoft Graph workbook API) without installing anything?\n\nYes. Grist has a hosted endpoint at https://docs.getgrist.com/api and Microsoft Excel (Microsoft Graph workbook API) at https://graph.microsoft.com/v1.0.\n\n### Are Grist and Microsoft Excel (Microsoft Graph workbook API) open source?\n\nGrist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for Microsoft Excel (Microsoft Graph workbook API).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json, and with the fewest tokens: https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"grist\", \"b\": \"microsoft-excel-graph\"}`. From a terminal: `anchor compare grist microsoft-excel-graph`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/grist.json and https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json\n\n## Other comparisons with Grist or Microsoft Excel (Microsoft Graph workbook API)\n\n- [Airtable vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/airtable-vs-microsoft-excel-graph.md)\n- [Baserow vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph.md)\n- [Coda (Superhuman Docs) vs Grist](https://www.anchorterminal.com/compare/coda-vs-grist.md)\n- [Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.md)\n- [Google Sheets API vs Grist](https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.md)\n- [Google Sheets API vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/google-sheets-api-vs-microsoft-excel-graph.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs NocoDB](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs SeaTable](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-seatable.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs Teable](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-teable.md)\n- [Airtable vs Grist](https://www.anchorterminal.com/compare/airtable-vs-grist.md)\n- [Baserow vs Grist](https://www.anchorterminal.com/compare/baserow-vs-grist.md)\n- [Grist vs NocoDB](https://www.anchorterminal.com/compare/grist-vs-nocodb.md)\n- [Grist vs SeaTable](https://www.anchorterminal.com/compare/grist-vs-seatable.md)\n- [Grist vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/grist-vs-smartsheet.md)\n- [Grist vs Teable](https://www.anchorterminal.com/compare/grist-vs-teable.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": ""
      }
    ],
    "description": "Microsoft Excel (Microsoft Graph workbook API) scores 58.5 (C) on agent readiness against Grist's 50.1 (D), and leads in 5 of 7 scored categories. Grist leads on payments \u0026 pricing and maintenance \u0026 community. Both do sheets read. Category scores, facts, verdicts and agent notes…",
    "facts": [
      "Grist D 50.1",
      "Microsoft Excel (Microsoft Graph workbook API) C 58.5",
      "scores"
    ],
    "h1": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
    "image": "https://www.anchorterminal.com/assets/og/compare-grist-vs-microsoft-excel-graph.png",
    "path": "/compare/grist-vs-microsoft-excel-graph",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Grist vs Microsoft Excel (Microsoft Graph workbook API) for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph"
  },
  "tokens": {
    "markdown": 2650,
    "slim": 780
  },
  "version": 1
}
