Head to head · Sheets records · October 2026 research run

Grist vs NocoDB

NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Both do sheets records.

Which one, for what

Grist D

Good for Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.

Also in its favour

  • Open source

Watch for

No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none

NocoDB BB

Good for Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.

Ahead on

  • Reliability, 97 against 39
  • Schema & documentation, 85 against 63
  • Agent ergonomics, 74 against 57
  • Security & auth, 71 against 62
  • Maintenance & community, 87 against 78
  • Transparency & trust, 76 against 61

Also in its favour

  • Agent-ready, a grade of BB or better
  • No incidents deducted, where Grist loses 4 points for them

Watch for

5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429

Score by category

CategoryWeight this runGristNocoDBEdge
Reliability16%203997NocoDB +58
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26385NocoDB +22
Agent ergonomics13%16.25774NocoDB +17
Security & auth14%17.56271NocoDB +9
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87887NocoDB +9
Transparency & trust7%8.86176NocoDB +15
Negative events≤15-40
Total50.1 · D75.7 · BB

Facts side by side

FactGristNocoDB
KindHTTP APIHTTP API
VendorGrist Labs Inc.NocoDB Inc
Hosted endpointhttps://docs.getgrist.com/apihttps://app.nocodb.com
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service
Tools exposed34199
Read-only variant documentedyesno
llms.txtnoyes
Last release2026-09-282026-09-29
Terms last updatedno date given2025-10-14
Privacy policy last updated2019-04-012026-03-20
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity12k stars, 341 npm/wk, 240 PyPI/wk65k stars, 6.3k npm/wk

Verdicts

Grist

OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.

NocoDB

API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.

Before you call either

Grist

  1. Connect through OAuth, not an API key. Ask for doc:read alone for reading, and have the user pick Selected resources on the consent screen
  2. Keep doc.schema:write off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules
  3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented
  4. Use PUT /api/docs/{docId}/tables/{tableId}/records with require to add or update by key, so a retried write doesn't create a duplicate row
  5. Use the /records endpoints, not the deprecated /data ones, and split large writes to stay under the 1 MB body limit

NocoDB

  1. Create a fine-grained token limited to the bases and categories the task needs. Send it as xc-token or as a Bearer token
  2. Stay under 5 requests a second across all tokens of one user. After a 429, honour Retry-After or wait 30 seconds
  3. Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records
  4. Write date filters with a sub-operator, such as (due_date,eq,exactDate,2026-06-01), and put no space after ~and or ~or
  5. Use /records/upsert with a merge key so a repeated write updates the record instead of adding a duplicate

Questions

Which is better for AI agents, Grist or NocoDB?

NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories.

Do Grist and NocoDB need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Grist and NocoDB without installing anything?

Yes. Grist has a hosted endpoint at https://docs.getgrist.com/api and NocoDB at https://app.nocodb.com.

Are Grist and NocoDB open source?

Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for NocoDB.

Other comparisons with Grist or NocoDB

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.