{
  "data": {
    "a": {
      "slug": "grist",
      "name": "Grist",
      "vendor": "Grist Labs Inc.",
      "vendorUrl": "https://www.getgrist.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/grist",
      "markdownUrl": "https://www.anchorterminal.com/tools/grist.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/grist.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/grist.json",
      "repo": "https://github.com/gristlabs/grist-core",
      "license": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://docs.getgrist.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "grist-api"
        },
        {
          "registry": "pypi",
          "name": "grist-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates an API key on the Developer page of account settings and sends it as `Authorization: Bearer`. The key carries its owner's full account access, and each account has one. The alternative is OAuth 2.0 with PKCE, used by the MCP server and by registered apps. The user approves any of seven scopes (`doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`) and can limit the grant to chosen sites, workspaces or documents. Access tokens last 1 hour and refresh tokens 60 days, and a grant can be revoked per app. Clients can register themselves by Client ID Metadata Document. Not every REST endpoint accepts an OAuth token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 5,000 rows a document and 3,000 API calls a month per site, REST and MCP calls together, so an agent can start without a contract. Pro is $10 a user a month ($8 billed yearly) and Business $30 ($24 yearly, minimum 5 users), Enterprise through sales. API calls aren't priced, the MCP server is on every plan for now, and there's no separate sandbox. The self-hosted community edition is free (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": 11900,
        "npmWeekly": 341,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://support.getgrist.com/rest-api/",
      "openapi": "https://raw.githubusercontent.com/gristlabs/grist-help/master/api/grist.yml",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "oauth",
        "api-key",
        "openapi",
        "webhooks",
        "python",
        "javascript"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.1,
        "grade": "D",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-13. GHSA-9x4j-4rw5-3vmq, critical (CVSS 10.0), remote code execution through prototype pollution from an imported crafted document, affecting Docker images before 1.7.19 and fixed in 1.7.19. Four more advisories were published in the last 12 months, among them GHSA-7xvx-8pf2-pv5g (CVE-2026-24002, critical, 21 January 2026) on the pyodide sandbox option, fixed in 1.7.9. All five are fixed and published and none says whether hosted Grist was affected, so the deduction is reduced (https://github.com/gristlabs/grist-core/security/advisories)"
        ],
        "verdict": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
        "bestFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "strengths": [
          "OAuth 2.0 with PKCE and seven scopes, with `doc:read`, `doc:write` and `doc.schema:write` granted separately and the grant limited to chosen sites, workspaces or documents",
          "Access tokens last 1 hour, refresh tokens 60 days, and a user can revoke one app's grant from the Authorised apps page",
          "Public OpenAPI 3.0.0 file with 101 paths and 120 operations, including a read-only SQL endpoint and `PUT` on `/records` to add or update by key columns",
          "Limits are published with numbers per plan, with 10 concurrent requests per document and a 1 MB request body on every plan",
          "The core is Apache-2.0 and four releases were tagged between 29 July and 28 September 2026"
        ],
        "weaknesses": [
          "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none",
          "An API key carries its owner's full account access, and each account has one key, so it can't be limited to a document or revoked per integration",
          "The data security page says hosted Grist has no SOC 2, ISO 27001, HIPAA or GDPR certification, and no DPA, sub-processor list or security.txt was found",
          "The MCP server and OAuth server are in the proprietary full edition, so the Apache-2.0 community edition has neither and the tool definitions aren't public",
          "Five security advisories were published in the last 12 months, two rated critical, the latest on 13 September 2026 with CVSS 10.0",
          "The Free plan allows 3,000 API calls a month across a site, with REST and MCP calls sharing the pool"
        ],
        "agentNotes": [
          "Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen",
          "Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules",
          "Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented",
          "Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row",
          "Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.1
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 50
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "pip install grist-api",
        "http": "curl -H \"Authorization: Bearer \u003cAPI-KEY-GOES-HERE\u003e\" https://docs.getgrist.com/api/orgs",
        "claudeCode": "claude mcp add --transport http grist https://docs.getgrist.com/api/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/grist"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro (hosted)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed monthly, $8 billed yearly, 100,000 rows a document, 40,000 API calls per document per day"
        },
        {
          "item": "Business (hosted)",
          "unit": "seat-month",
          "usd": 30,
          "note": "billed monthly, $24 billed yearly, minimum 5 users, 150,000 rows a document, 60,000 API calls per document per day"
        }
      ],
      "provenance": {
        "legalEntity": "Grist Labs Inc.",
        "domain": "getgrist.com",
        "domainRegistered": "2014-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.getgrist.com/terms/",
        "privacy": "https://www.getgrist.com/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/gristlabs/grist-core/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms page is an End-User Licence Agreement between the user and Grist Labs Inc., covering its products, software, services and websites, governed by New York State law, with legal notices to 93 4th Ave, #1127, New York, NY 10003. It carries no date.",
          "The privacy policy has an effective date of 1 April 2019 and covers the websites, products and services. It names no retention periods.",
          "The REST API and MCP server answer at docs.getgrist.com and \u003cteam\u003e.getgrist.com, and OAuth at login.getgrist.com, all getgrist.com subdomains.",
          "No status page was found. status.getgrist.com redirects to a signup form because every subdomain is treated as a team site.",
          "www.getgrist.com/.well-known/security.txt and docs.getgrist.com/.well-known/security.txt return 404. SECURITY.md in the repository gives security@getgrist.com.",
          "RDAP for getgrist.com gives a registration date of 2014-05-12."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/grist.json",
      "live": {
        "slug": "grist",
        "probe": {
          "target": "https://docs.getgrist.com/api",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.613117891Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 251,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 256,
          "p95ms24h": 311,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "updatedAt": "2026-10-08T21:12:11.613117891Z"
      }
    },
    "answer": "NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "nocodb",
      "name": "NocoDB",
      "vendor": "NocoDB Inc",
      "vendorUrl": "https://nocodb.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth.",
      "url": "https://www.anchorterminal.com/tools/nocodb",
      "markdownUrl": "https://www.anchorterminal.com/tools/nocodb.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nocodb.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nocodb.json",
      "repo": "https://github.com/nocodb/nocodb",
      "license": "Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.nocodb.com",
      "packages": [
        {
          "registry": "npm",
          "name": "nocodb-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates a fine-grained API token in Account Settings, choosing permission categories, bases and an expiry, and sends it as `xc-token` or `Authorization: Bearer`. For MCP the user creates a connection with its own key, sent as `x-api-key`, or a web client uses OAuth with PKCE and dynamic client registration and the user picks bases and tools on the consent screen. No review step was found. A token or connection never exceeds its owner's role. Workspaces that enforce SSO accept only tokens created after an SSO sign-in.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 1,000 API calls a month, 1,000 records and 3 editor seats, no card required per the pricing page, so an agent can start without a contract. Plus is $12 a seat a month billed annually, Business $24 and Scale $45, with Plus and Business capped at 9 paid seats. Enterprise through sales. API calls aren't priced separately. The self-hosted Community Edition is free for internal use (checked 2026-10-08).",
      "priceSummary": "$12 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API docs, the MCP docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 199,
      "popularity": {
        "githubStars": 65215,
        "npmWeekly": 6282,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://nocodb.com/docs/apis-and-mcp",
      "llmsTxt": "https://nocodb.com/llms.txt",
      "openapi": "https://nocodb.com/apis/v3/swagger-v3.json",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "mcp",
        "source-available",
        "free-tier",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "javascript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 75.7,
        "grade": "BB",
        "agentReady": true,
        "rank": 37,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 87,
          "payments": 30,
          "reliability": 97,
          "schema": 85,
          "security": 71,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.",
        "bestFor": "Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.",
        "strengths": [
          "Fine-grained API tokens carry eight permission categories at Read or Read and write, a list of bases, an expiry and an on-off switch",
          "An MCP connection lists only the tools its owner allowed, by section at Read, Read and write, or Read, write and delete",
          "Public OpenAPI 3.1 file for the v3 REST API with 114 operations, plus llms.txt and a Markdown copy of every docs page",
          "The MCP record tools in the source set `readOnlyHint` and `destructiveHint`, and `deleteRecords` is marked destructive",
          "status.nocodb.com lists no incident from July to October 2026 and shows 99.9907 per cent for the application over 90 days"
        ],
        "weaknesses": [
          "5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429",
          "REST create, update and upsert calls take 10 records each by default",
          "The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan",
          "The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved",
          "No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry"
        ],
        "agentNotes": [
          "Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token",
          "Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds",
          "Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records",
          "Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or`",
          "Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 75.7
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 87,
          "payments": 30,
          "reliability": 97,
          "schema": 85,
          "security": 71,
          "transparency": 66
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "docker run -d \\\n  --name noco \\\n  -v \"$(pwd)\"/nocodb:/usr/app/data/ \\\n  -p 8080:8080 \\\n  nocodb/nocodb:latest",
        "http": "curl -H \"xc-token: nc_pat_...\" https://your-nocodb.com/api/v3/...",
        "config": {
          "mcpServers": {
            "NocoDB MCP": {
              "args": [
                "mcp-remote",
                "https://your-domain.com/mcp/\u003cncId\u003e",
                "--header",
                "x-api-key: \u003cncToken\u003e"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/nocodb"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Plus",
          "unit": "seat-month",
          "usd": 12,
          "note": "billed annually, at most 9 paid seats ($108 a month), 100,000 API calls a month"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 24,
          "note": "billed annually, at most 9 paid seats ($216 a month), 1,000,000 API calls a month"
        },
        {
          "item": "Scale",
          "unit": "seat-month",
          "usd": 45,
          "note": "billed annually, 3 seats minimum, 5,000,000 API calls a month"
        }
      ],
      "provenance": {
        "legalEntity": "NocoDB Inc (doing business as NocoDB)",
        "domain": "nocodb.com",
        "domainRegistered": "2021-04-14",
        "endpointOnVendorDomain": true,
        "terms": "https://nocodb.com/docs/legal/terms-of-service",
        "privacy": "https://nocodb.com/docs/legal/privacy",
        "statusPage": "https://status.nocodb.com",
        "changelog": "https://nocodb.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 14 October 2025) and the privacy policy (last updated 5 August 2025) name NocoDB Inc, doing business as NocoDB, and cover the website, the hosted services and the APIs. No postal address was found in the parts we read.",
          "The REST API and the MCP server answer at app.nocodb.com, a nocodb.com subdomain. A self-hosted instance answers on the owner's own domain.",
          "nocodb.com/.well-known/security.txt, nocodb.com/security.txt and app.nocodb.com/.well-known/security.txt return 404. SECURITY.md in the repository sends reports to security@nocodb.com.",
          "RDAP for nocodb.com gives a registration date of 2021-04-14.",
          "Organisations on an order form are governed by the Master Subscription Agreement (last updated 14 October 2025), which states SOC 2 Type II compliance with the report on request. The Service Level Agreement (last updated 6 October 2025) commits to 99.9 per cent monthly uptime for Enterprise plans."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nocodb.json",
      "live": {
        "slug": "nocodb",
        "probe": {
          "target": "https://app.nocodb.com",
          "method": "get",
          "lastAt": "2026-10-08T21:12:16.502721206Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 299,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 300,
          "p95ms24h": 340,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nocodb.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:50.166052501Z"
        },
        "pages": [
          {
            "url": "https://nocodb.com/docs/changelog",
            "kind": "changelog",
            "status": 404,
            "checkedAt": "2026-10-08T18:22:20.469505035Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://nocodb.com/docs/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:22.574237418Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0c382788e85c"
          },
          {
            "url": "https://nocodb.com/docs/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:24.679133564Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "78a7b9c3e6ab"
          }
        ],
        "updatedAt": "2026-10-08T21:12:16.502721206Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Grist Labs Inc.",
        "b": "NocoDB Inc",
        "name": "Vendor"
      },
      {
        "a": "https://docs.getgrist.com/api",
        "b": "https://app.nocodb.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
        "b": "Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service",
        "name": "Licence"
      },
      {
        "a": "34",
        "b": "199",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-10-14",
        "name": "Terms last updated"
      },
      {
        "a": "2019-04-01",
        "b": "2026-03-20",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "12k stars, 341 npm/wk, 240 PyPI/wk",
        "b": "65k stars, 6.3k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Grist or NocoDB?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Grist and NocoDB need an API key?"
      },
      {
        "answer": "Yes. Grist has a hosted endpoint at https://docs.getgrist.com/api and NocoDB at https://app.nocodb.com.",
        "question": "Can an agent call Grist and NocoDB without installing anything?"
      },
      {
        "answer": "Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for NocoDB.",
        "question": "Are Grist and NocoDB open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "slug": "grist",
        "watchFor": "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none"
      },
      {
        "aheadOn": [
          "Reliability, 97 against 39",
          "Schema \u0026 documentation, 85 against 63",
          "Agent ergonomics, 74 against 57",
          "Security \u0026 auth, 71 against 62",
          "Maintenance \u0026 community, 87 against 78",
          "Transparency \u0026 trust, 76 against 61"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No incidents deducted, where Grist loses 4 points for them"
        ],
        "goodFor": "Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.",
        "slug": "nocodb",
        "watchFor": "5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429"
      }
    ],
    "job": {
      "capability": "sheets.records",
      "name": "Sheets records"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-grist.json",
        "title": "Coda (Superhuman Docs) vs Grist",
        "url": "https://www.anchorterminal.com/compare/coda-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-nocodb.json",
        "title": "Coda (Superhuman Docs) vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/coda-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.json",
        "title": "Google Sheets API vs Grist",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-nocodb.json",
        "title": "Google Sheets API vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json",
        "title": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-grist.json",
        "title": "Airtable vs Grist",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-nocodb.json",
        "title": "Airtable vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-grist.json",
        "title": "Baserow vs Grist",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-nocodb.json",
        "title": "Baserow vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-seatable.json",
        "title": "Grist vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.json",
        "title": "Grist vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/grist-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-teable.json",
        "title": "Grist vs Teable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nocodb-vs-seatable.json",
        "title": "NocoDB vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/nocodb-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nocodb-vs-smartsheet.json",
        "title": "NocoDB vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/nocodb-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nocodb-vs-teable.json",
        "title": "NocoDB vs Teable",
        "url": "https://www.anchorterminal.com/compare/nocodb-vs-teable"
      }
    ],
    "scores": [
      {
        "by": 58,
        "edge": "nocodb",
        "grist": 39,
        "key": "reliability",
        "name": "Reliability",
        "nocodb": 97,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 22,
        "edge": "nocodb",
        "grist": 63,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "nocodb": 85,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "nocodb",
        "grist": 57,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "nocodb": 74,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "nocodb",
        "grist": 62,
        "key": "security",
        "name": "Security \u0026 auth",
        "nocodb": 71,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "grist": 30,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "nocodb": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "nocodb",
        "grist": 78,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "nocodb": 87,
        "weight": 7
      },
      {
        "by": 15,
        "edge": "nocodb",
        "grist": 61,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "nocodb": 76,
        "weight": 7
      }
    ],
    "summary": "NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Both do sheets records.",
    "verdicts": {
      "grist": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
      "nocodb": "API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/grist-vs-nocodb",
    "json": "https://www.anchorterminal.com/compare/grist-vs-nocodb.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/grist-vs-nocodb.md",
    "slim": "https://www.anchorterminal.com/compare/grist-vs-nocodb.min.md"
  },
  "markdown": "NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Both do sheets records.\n\n- Grist: grade D, 50.1/100, rank #597 of 722. Markdown https://www.anchorterminal.com/tools/grist.md · JSON https://www.anchorterminal.com/api/v1/tools/grist.json\n- NocoDB: grade BB, 75.7/100, rank #37 of 722. Markdown https://www.anchorterminal.com/tools/nocodb.md · JSON https://www.anchorterminal.com/api/v1/tools/nocodb.json\n\n## Which one, for what\n\n### Grist (D)\n\nGood for: Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.\n\nAlso in its favour:\n- Open source\n\nWatch for: No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none\n\n### NocoDB (BB)\n\nGood for: Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.\n\nAhead on:\n- Reliability, 97 against 39\n- Schema \u0026 documentation, 85 against 63\n- Agent ergonomics, 74 against 57\n- Security \u0026 auth, 71 against 62\n- Maintenance \u0026 community, 87 against 78\n- Transparency \u0026 trust, 76 against 61\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No incidents deducted, where Grist loses 4 points for them\n\nWatch for: 5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429\n\n\n## Score by category\n\n| Category | Weight | Grist | NocoDB | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 39 | 97 | NocoDB +58 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 63 | 85 | NocoDB +22 |\n| Agent ergonomics | 13% (16.2 this run) | 57 | 74 | NocoDB +17 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 71 | NocoDB +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 87 | NocoDB +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 76 | NocoDB +15 |\n| Negative events | ≤15 | -4 | 0 | |\n| **Total** | | **50.1 · D** | **75.7 · BB** | |\n\n## Facts side by side\n\n| Fact | Grist | NocoDB |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Grist Labs Inc. | NocoDB Inc |\n| Hosted endpoint | `https://docs.getgrist.com/api` | `https://app.nocodb.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 | Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service |\n| Tools exposed | 34 | 199 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-09-28 | 2026-09-29 |\n| Terms last updated | no date given | 2025-10-14 |\n| Privacy policy last updated | 2019-04-01 | 2026-03-20 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 12k stars, 341 npm/wk, 240 PyPI/wk | 65k stars, 6.3k npm/wk |\n\n## Verdicts\n\n**Grist.** OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.\n\n**NocoDB.** API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.\n\n## Before you call either\n\n### Grist\n\n1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen\n2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules\n3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented\n4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row\n5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit\n\n### NocoDB\n\n1. Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token\n2. Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds\n3. Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records\n4. Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or`\n5. Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate\n\n## Questions\n\n### Which is better for AI agents, Grist or NocoDB?\n\nNocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories.\n\n### Do Grist and NocoDB need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Grist and NocoDB without installing anything?\n\nYes. Grist has a hosted endpoint at https://docs.getgrist.com/api and NocoDB at https://app.nocodb.com.\n\n### Are Grist and NocoDB open source?\n\nGrist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for NocoDB.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/grist-vs-nocodb.json, and with the fewest tokens: https://www.anchorterminal.com/compare/grist-vs-nocodb.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"grist\", \"b\": \"nocodb\"}`. From a terminal: `anchor compare grist nocodb`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/grist.json and https://www.anchorterminal.com/api/v1/tools/nocodb.json\n\n## Other comparisons with Grist or NocoDB\n\n- [Coda (Superhuman Docs) vs Grist](https://www.anchorterminal.com/compare/coda-vs-grist.md)\n- [Coda (Superhuman Docs) vs NocoDB](https://www.anchorterminal.com/compare/coda-vs-nocodb.md)\n- [Google Sheets API vs Grist](https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.md)\n- [Google Sheets API vs NocoDB](https://www.anchorterminal.com/compare/google-sheets-api-vs-nocodb.md)\n- [Grist vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs NocoDB](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb.md)\n- [Airtable vs Grist](https://www.anchorterminal.com/compare/airtable-vs-grist.md)\n- [Airtable vs NocoDB](https://www.anchorterminal.com/compare/airtable-vs-nocodb.md)\n- [Baserow vs Grist](https://www.anchorterminal.com/compare/baserow-vs-grist.md)\n- [Baserow vs NocoDB](https://www.anchorterminal.com/compare/baserow-vs-nocodb.md)\n- [Grist vs SeaTable](https://www.anchorterminal.com/compare/grist-vs-seatable.md)\n- [Grist vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/grist-vs-smartsheet.md)\n- [Grist vs Teable](https://www.anchorterminal.com/compare/grist-vs-teable.md)\n- [NocoDB vs SeaTable](https://www.anchorterminal.com/compare/nocodb-vs-seatable.md)\n- [NocoDB vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/nocodb-vs-smartsheet.md)\n- [NocoDB vs Teable](https://www.anchorterminal.com/compare/nocodb-vs-teable.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Grist vs NocoDB",
        "url": ""
      }
    ],
    "description": "NocoDB scores 75.7 (BB) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Both do sheets records. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Grist D 50.1",
      "NocoDB BB 75.7",
      "scores"
    ],
    "h1": "Grist vs NocoDB",
    "image": "https://www.anchorterminal.com/assets/og/compare-grist-vs-nocodb.png",
    "path": "/compare/grist-vs-nocodb",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Grist vs NocoDB for AI agents, D 50.1 vs BB 75.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/grist-vs-nocodb"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 730
  },
  "version": 1
}
