{
  "data": {
    "a": {
      "slug": "grist",
      "name": "Grist",
      "vendor": "Grist Labs Inc.",
      "vendorUrl": "https://www.getgrist.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/grist",
      "markdownUrl": "https://www.anchorterminal.com/tools/grist.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/grist.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/grist.json",
      "repo": "https://github.com/gristlabs/grist-core",
      "license": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://docs.getgrist.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "grist-api"
        },
        {
          "registry": "pypi",
          "name": "grist-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in user creates an API key on the Developer page of account settings and sends it as `Authorization: Bearer`. The key carries its owner's full account access, and each account has one. The alternative is OAuth 2.0 with PKCE, used by the MCP server and by registered apps. The user approves any of seven scopes (`doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`) and can limit the grant to chosen sites, workspaces or documents. Access tokens last 1 hour and refresh tokens 60 days, and a grant can be revoked per app. Clients can register themselves by Client ID Metadata Document. Not every REST endpoint accepts an OAuth token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 5,000 rows a document and 3,000 API calls a month per site, REST and MCP calls together, so an agent can start without a contract. Pro is $10 a user a month ($8 billed yearly) and Business $30 ($24 yearly, minimum 5 users), Enterprise through sales. API calls aren't priced, the MCP server is on every plan for now, and there's no separate sandbox. The self-hosted community edition is free (checked 2026-10-08).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": 11900,
        "npmWeekly": 341,
        "pypiWeekly": 240,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://support.getgrist.com/rest-api/",
      "openapi": "https://raw.githubusercontent.com/gristlabs/grist-help/master/api/grist.yml",
      "capabilities": [
        "sheets.records",
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "mcp",
        "free-tier",
        "oauth",
        "api-key",
        "openapi",
        "webhooks",
        "python",
        "javascript"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.1,
        "grade": "D",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-09-13. GHSA-9x4j-4rw5-3vmq, critical (CVSS 10.0), remote code execution through prototype pollution from an imported crafted document, affecting Docker images before 1.7.19 and fixed in 1.7.19. Four more advisories were published in the last 12 months, among them GHSA-7xvx-8pf2-pv5g (CVE-2026-24002, critical, 21 January 2026) on the pyodide sandbox option, fixed in 1.7.9. All five are fixed and published and none says whether hosted Grist was affected, so the deduction is reduced (https://github.com/gristlabs/grist-core/security/advisories)"
        ],
        "verdict": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
        "bestFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "strengths": [
          "OAuth 2.0 with PKCE and seven scopes, with `doc:read`, `doc:write` and `doc.schema:write` granted separately and the grant limited to chosen sites, workspaces or documents",
          "Access tokens last 1 hour, refresh tokens 60 days, and a user can revoke one app's grant from the Authorised apps page",
          "Public OpenAPI 3.0.0 file with 101 paths and 120 operations, including a read-only SQL endpoint and `PUT` on `/records` to add or update by key columns",
          "Limits are published with numbers per plan, with 10 concurrent requests per document and a 1 MB request body on every plan",
          "The core is Apache-2.0 and four releases were tagged between 29 July and 28 September 2026"
        ],
        "weaknesses": [
          "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none",
          "An API key carries its owner's full account access, and each account has one key, so it can't be limited to a document or revoked per integration",
          "The data security page says hosted Grist has no SOC 2, ISO 27001, HIPAA or GDPR certification, and no DPA, sub-processor list or security.txt was found",
          "The MCP server and OAuth server are in the proprietary full edition, so the Apache-2.0 community edition has neither and the tool definitions aren't public",
          "Five security advisories were published in the last 12 months, two rated critical, the latest on 13 September 2026 with CVSS 10.0",
          "The Free plan allows 3,000 API calls a month across a site, with REST and MCP calls sharing the pool"
        ],
        "agentNotes": [
          "Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen",
          "Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules",
          "Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented",
          "Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row",
          "Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.1
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 78,
          "payments": 30,
          "reliability": 39,
          "schema": 63,
          "security": 62,
          "transparency": 50
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "pip install grist-api",
        "http": "curl -H \"Authorization: Bearer \u003cAPI-KEY-GOES-HERE\u003e\" https://docs.getgrist.com/api/orgs",
        "claudeCode": "claude mcp add --transport http grist https://docs.getgrist.com/api/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/sheets.records",
        "tool": "https://letme.dev/grist"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro (hosted)",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed monthly, $8 billed yearly, 100,000 rows a document, 40,000 API calls per document per day"
        },
        {
          "item": "Business (hosted)",
          "unit": "seat-month",
          "usd": 30,
          "note": "billed monthly, $24 billed yearly, minimum 5 users, 150,000 rows a document, 60,000 API calls per document per day"
        }
      ],
      "provenance": {
        "legalEntity": "Grist Labs Inc.",
        "domain": "getgrist.com",
        "domainRegistered": "2014-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.getgrist.com/terms/",
        "privacy": "https://www.getgrist.com/privacy/",
        "statusPage": "",
        "changelog": "https://github.com/gristlabs/grist-core/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms page is an End-User Licence Agreement between the user and Grist Labs Inc., covering its products, software, services and websites, governed by New York State law, with legal notices to 93 4th Ave, #1127, New York, NY 10003. It carries no date.",
          "The privacy policy has an effective date of 1 April 2019 and covers the websites, products and services. It names no retention periods.",
          "The REST API and MCP server answer at docs.getgrist.com and \u003cteam\u003e.getgrist.com, and OAuth at login.getgrist.com, all getgrist.com subdomains.",
          "No status page was found. status.getgrist.com redirects to a signup form because every subdomain is treated as a team site.",
          "www.getgrist.com/.well-known/security.txt and docs.getgrist.com/.well-known/security.txt return 404. SECURITY.md in the repository gives security@getgrist.com.",
          "RDAP for getgrist.com gives a registration date of 2014-05-12."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/grist.json",
      "live": {
        "slug": "grist",
        "probe": {
          "target": "https://docs.getgrist.com/api",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.613117891Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 251,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 256,
          "p95ms24h": 311,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "updatedAt": "2026-10-08T21:12:11.613117891Z"
      }
    },
    "answer": "Smartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing.",
    "b": {
      "slug": "smartsheet",
      "name": "Smartsheet API + MCP",
      "vendor": "Smartsheet Inc.",
      "vendorUrl": "https://www.smartsheet.com",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Smartsheet is a hosted work management product built on sheets with typed columns, rows, formulas, reports and dashboards. Agents reach it through a REST API (187 operations) and a hosted MCP server, both limited to Business plans and above.",
      "url": "https://www.anchorterminal.com/tools/smartsheet",
      "markdownUrl": "https://www.anchorterminal.com/tools/smartsheet.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/smartsheet.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smartsheet.json",
      "repo": "https://github.com/smartsheet/smartsheet-python-sdk",
      "license": "Proprietary service under Smartsheet's User Agreement and Developer Agreement. The SDKs on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.smartsheet.com/2.0",
      "packages": [
        {
          "registry": "pypi",
          "name": "smartsheet-python-sdk"
        },
        {
          "registry": "npm",
          "name": "smartsheet"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access needs a licensed user on a Business plan or higher. A user makes a raw API token in Personal Settings and sends it as a Bearer token. It has no scopes and carries all of that user's access. Apps acting for other users register in Developer Tools (Smartsheet approves the registration request) and use the OAuth 2.0 authorisation code grant with any of 17 scopes such as READ_SHEETS and WRITE_SHEETS. Access tokens last about 7 days and refresh. Scopes can't exceed the user's sharing level on a sheet. The MCP server takes OAuth from ChatGPT, Claude, Gemini Enterprise Plus and Microsoft 365 Copilot, and a Bearer API token from other clients. A System Admin's token can act as any user through the `Assume-User` header.",
      "pricing": "paid",
      "pricingNotes": "API and MCP access start at the Business plan, $24 a member a month billed monthly or $19 billed yearly, with a minimum of three members. Pro ($12, or $9 yearly) has no API calls. Enterprise and Advanced Work Management are priced through sales. API calls carry no separate charge. A 30-day trial needs no card, but we couldn't confirm that a trial account can make API tokens. No developer sandbox was found in the reviewed documentation (https://www.smartsheet.com/pricing, checked 2026-10-08).",
      "priceSummary": "$19 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 83,
      "popularity": {
        "githubStars": 82,
        "npmWeekly": 47484,
        "pypiWeekly": 311787,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.smartsheet.com",
      "llmsTxt": "https://developers.smartsheet.com/llms.txt",
      "openapi": "https://developers.smartsheet.com/_bundle/api/smartsheet/openapi.yaml",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.records",
        "sheets.formulas",
        "automation.workflows"
      ],
      "tags": [
        "official",
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "python",
        "typescript",
        "java",
        "csharp",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.6,
        "grade": "B",
        "agentReady": false,
        "rank": 205,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 80,
          "payments": 20,
          "reliability": 65,
          "schema": 88,
          "security": 66,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.0.3 spec with 187 operations, Markdown docs and llms.txt, and the hosted MCP server loads its 83 documented tools by toolset. API access needs a Business plan or higher, and the status page lists eight incidents marked major or critical between 15 July and 21 September 2026.",
        "bestFor": "An agent working inside a company that already runs projects in Smartsheet on a Business plan or above, especially row-level reads and batched writes, workflows and dashboards.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 187 operations, code samples on 180 of them, plus llms.txt and a Markdown copy of every docs page",
          "Hosted MCP server in three regions (US, EU, Australia) with toolsets, so a client loads tools by domain through `search_tools`",
          "OAuth 2.0 with 17 scopes, including READ_SHEETS for a read-only grant, and sheet sharing levels that scopes can't override",
          "Bulk row writes of up to 500 rows a call with optional partial success and per-row failure details",
          "Dated API changelog (latest 6 October 2026) with DEPRECATION and SUNSET entries and migration guides"
        ],
        "weaknesses": [
          "API and MCP access need a Business plan or higher, from $19 a member a month billed yearly with a three-member minimum",
          "Eight status incidents marked major or critical between 15 July and 21 September 2026, four of them stopping sheets from loading in the US region",
          "A raw API token carries all of its user's access with no scopes, and it's the credential the docs give for Claude Code, Cursor, Codex and Gemini CLI",
          "No idempotency keys, and 429 responses carry no documented Retry-After header",
          "security.txt expired on 1 July 2026, and no prompt-injection guidance was found in the MCP docs"
        ],
        "agentNotes": [
          "Send writes to one sheet one at a time. Parallel updates with the same token return error 4004",
          "Batch row changes, up to 500 rows a call, and add `allowPartialSuccess=true` to get per-row failures instead of a failed batch",
          "On error 4003 (HTTP 429) wait at least 60 seconds before retrying. The limit is 300 requests a minute per token, 30 for attachments and cell history",
          "Through MCP, call `get_columns` before filtering or writing. Column names are case-sensitive and guesses fail validation",
          "Use the regional host that matches the account (api.smartsheet.com, .eu or .au). Tokens don't work across regions"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.6
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 80,
          "payments": 20,
          "reliability": 65,
          "schema": 88,
          "security": 66,
          "transparency": 72
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "pip install smartsheet-python-sdk",
        "http": "curl \"https://api.smartsheet.com/2.0/workspaces?maxItems=100\" \\\n  -H \"Authorization: Bearer $SMARTSHEET_API_TOKEN\"",
        "claudeCode": "claude mcp add --transport http smartsheet-mcp https://mcp.smartsheet.com -H \"Authorization:Bearer ${SMARTSHEET_API_TOKEN}\"",
        "config": {
          "mcpServers": {
            "smartsheet-mcp": {
              "headers": {
                "Authorization": "Bearer ${SMARTSHEET_API_TOKEN}"
              },
              "httpUrl": "https://mcp.smartsheet.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sheets.read",
        "tool": "https://letme.dev/smartsheet"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Business plan (lowest plan with API and MCP access)",
          "unit": "seat-month",
          "usd": 19,
          "note": "billed yearly, $24 monthly, 3 members minimum"
        },
        {
          "item": "Pro plan (no API calls)",
          "unit": "seat-month",
          "usd": 9,
          "note": "billed yearly, $12 monthly, up to 10 members"
        }
      ],
      "provenance": {
        "legalEntity": "Smartsheet Inc.",
        "domain": "smartsheet.com",
        "domainRegistered": "2001-04-15",
        "endpointOnVendorDomain": true,
        "terms": "https://www.smartsheet.com/legal/developer-program-agreement",
        "privacy": "https://www.smartsheet.com/legal/privacy",
        "statusPage": "https://status.smartsheet.com",
        "changelog": "https://developers.smartsheet.com/api/smartsheet/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The User Agreement (last updated 3 April 2026) and the privacy notice (20 May 2026) give Smartsheet Inc., 500 108th Ave NE, Suite 200, Bellevue, WA 98004.",
          "The Developer Agreement governing the API and SDKs was last updated 1 July 2021. Revisions take effect 15 days after posting.",
          "www.smartsheet.com/.well-known/security.txt names security@smartsheet.com and the bug bounty page, with Expires 2026-07-01, three months before this check.",
          "The API answers at api.smartsheet.com and the MCP server at mcp.smartsheet.com, with regional hosts on smartsheet.eu and smartsheet.au.",
          "RDAP for smartsheet.com gives a registration date of 2001-04-15."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/smartsheet.json",
      "live": {
        "slug": "smartsheet",
        "probe": {
          "target": "https://api.smartsheet.com/2.0",
          "method": "get",
          "lastAt": "2026-10-08T21:12:21.863929508Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 407,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 410,
          "p95ms24h": 461,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.smartsheet.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:26.282322955Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "smartsheet/smartsheet-python-sdk",
            "version": "v4.4.0",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:29:43.071236352Z"
          },
          {
            "registry": "npm",
            "name": "smartsheet",
            "version": "5.3.0",
            "seenAt": "2026-10-08T16:29:42.658666425Z"
          },
          {
            "registry": "pypi",
            "name": "smartsheet-python-sdk",
            "version": "4.4.0",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:29:42.474478981Z"
          }
        ],
        "githubStars": 82,
        "npmWeekly": 47484,
        "pypiWeekly": 311787,
        "securityTxt": {
          "url": "https://smartsheet.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-07-01T04:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:51.088332618Z"
        },
        "pages": [
          {
            "url": "https://developers.smartsheet.com/api/smartsheet/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:00.810328989Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "295f068fdad5"
          },
          {
            "url": "https://www.smartsheet.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:35.945478338Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "15466e0b403d"
          },
          {
            "url": "https://www.smartsheet.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:35.349940575Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b189b00ce573"
          },
          {
            "url": "https://www.smartsheet.com/legal/developer-program-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:31.7907332Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ae127c8430bb"
          }
        ],
        "updatedAt": "2026-10-08T21:12:21.863929508Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Grist Labs Inc.",
        "b": "Smartsheet Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://docs.getgrist.com/api",
        "b": "https://api.smartsheet.com/2.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0",
        "b": "Proprietary service under Smartsheet's User Agreement and Developer Agreement. The SDKs on GitHub are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "34",
        "b": "83",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2021-07-01",
        "name": "Terms last updated"
      },
      {
        "a": "2019-04-01",
        "b": "2026-05-20",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "12k stars, 341 npm/wk, 240 PyPI/wk",
        "b": "82 stars, 47k npm/wk, 312k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Smartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Grist or Smartsheet API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Grist and Smartsheet API + MCP need an API key?"
      },
      {
        "answer": "Yes. Grist has a hosted endpoint at https://docs.getgrist.com/api and Smartsheet API + MCP at https://api.smartsheet.com/2.0.",
        "question": "Can an agent call Grist and Smartsheet API + MCP without installing anything?"
      },
      {
        "answer": "Grist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for Smartsheet API + MCP.",
        "question": "Are Grist and Smartsheet API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.",
        "slug": "grist",
        "watchFor": "No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none"
      },
      {
        "aheadOn": [
          "Reliability, 65 against 39",
          "Schema \u0026 documentation, 88 against 63",
          "Agent ergonomics, 74 against 57",
          "Transparency \u0026 trust, 82 against 61"
        ],
        "also": [
          "No incidents deducted, where Grist loses 4 points for them"
        ],
        "goodFor": "An agent working inside a company that already runs projects in Smartsheet on a Business plan or above, especially row-level reads and batched writes, workflows and dashboards.",
        "slug": "smartsheet",
        "watchFor": "API and MCP access need a Business plan or higher, from $19 a member a month billed yearly with a three-member minimum"
      }
    ],
    "job": {
      "capability": "sheets.records",
      "name": "Sheets records"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-grist.json",
        "title": "Coda (Superhuman Docs) vs Grist",
        "url": "https://www.anchorterminal.com/compare/coda-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coda-vs-smartsheet.json",
        "title": "Coda (Superhuman Docs) vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/coda-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.json",
        "title": "Google Sheets API vs Grist",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-sheets-api-vs-smartsheet.json",
        "title": "Google Sheets API vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/google-sheets-api-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.json",
        "title": "Grist vs Microsoft Excel (Microsoft Graph workbook API)",
        "url": "https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet.json",
        "title": "Microsoft Excel (Microsoft Graph workbook API) vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/smartsheet-vs-teable.json",
        "title": "Smartsheet API + MCP vs Teable",
        "url": "https://www.anchorterminal.com/compare/smartsheet-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-grist.json",
        "title": "Airtable vs Grist",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airtable-vs-smartsheet.json",
        "title": "Airtable vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/airtable-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-grist.json",
        "title": "Baserow vs Grist",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-grist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserow-vs-smartsheet.json",
        "title": "Baserow vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/baserow-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-nocodb.json",
        "title": "Grist vs NocoDB",
        "url": "https://www.anchorterminal.com/compare/grist-vs-nocodb"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-seatable.json",
        "title": "Grist vs SeaTable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-seatable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/grist-vs-teable.json",
        "title": "Grist vs Teable",
        "url": "https://www.anchorterminal.com/compare/grist-vs-teable"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nocodb-vs-smartsheet.json",
        "title": "NocoDB vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/nocodb-vs-smartsheet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/seatable-vs-smartsheet.json",
        "title": "SeaTable vs Smartsheet API + MCP",
        "url": "https://www.anchorterminal.com/compare/seatable-vs-smartsheet"
      }
    ],
    "scores": [
      {
        "by": 26,
        "edge": "smartsheet",
        "grist": 39,
        "key": "reliability",
        "name": "Reliability",
        "smartsheet": 65,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "smartsheet",
        "grist": 63,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "smartsheet": 88,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "smartsheet",
        "grist": 57,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "smartsheet": 74,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "smartsheet",
        "grist": 62,
        "key": "security",
        "name": "Security \u0026 auth",
        "smartsheet": 66,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "grist",
        "grist": 30,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "smartsheet": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "smartsheet",
        "grist": 78,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "smartsheet": 80,
        "weight": 7
      },
      {
        "by": 21,
        "edge": "smartsheet",
        "grist": 61,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "smartsheet": 82,
        "weight": 7
      }
    ],
    "summary": "Smartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing. Both do sheets records.",
    "verdicts": {
      "grist": "OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.",
      "smartsheet": "The REST API has a public OpenAPI 3.0.3 spec with 187 operations, Markdown docs and llms.txt, and the hosted MCP server loads its 83 documented tools by toolset. API access needs a Business plan or higher, and the status page lists eight incidents marked major or critical between 15 July and 21 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/grist-vs-smartsheet",
    "json": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.md",
    "slim": "https://www.anchorterminal.com/compare/grist-vs-smartsheet.min.md"
  },
  "markdown": "Smartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing. Both do sheets records.\n\n- Grist: grade D, 50.1/100, rank #597 of 722. Markdown https://www.anchorterminal.com/tools/grist.md · JSON https://www.anchorterminal.com/api/v1/tools/grist.json\n- Smartsheet API + MCP: grade B, 67.6/100, rank #205 of 722. Markdown https://www.anchorterminal.com/tools/smartsheet.md · JSON https://www.anchorterminal.com/api/v1/tools/smartsheet.json\n\n## Which one, for what\n\n### Grist (D)\n\nGood for: Teams that want a relational spreadsheet with Python formulas and per-document OAuth grants for an agent, or that need to self-host.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 20\n\nAlso in its favour:\n- Open source\n\nWatch for: No status page was found. status.getgrist.com redirects to a signup form, and the site footer and help centre link to none\n\n### Smartsheet API + MCP (B)\n\nGood for: An agent working inside a company that already runs projects in Smartsheet on a Business plan or above, especially row-level reads and batched writes, workflows and dashboards.\n\nAhead on:\n- Reliability, 65 against 39\n- Schema \u0026 documentation, 88 against 63\n- Agent ergonomics, 74 against 57\n- Transparency \u0026 trust, 82 against 61\n\nAlso in its favour:\n- No incidents deducted, where Grist loses 4 points for them\n\nWatch for: API and MCP access need a Business plan or higher, from $19 a member a month billed yearly with a three-member minimum\n\n\n## Score by category\n\n| Category | Weight | Grist | Smartsheet API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 39 | 65 | Smartsheet API + MCP +26 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 63 | 88 | Smartsheet API + MCP +25 |\n| Agent ergonomics | 13% (16.2 this run) | 57 | 74 | Smartsheet API + MCP +17 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 66 | Smartsheet API + MCP +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Grist +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 80 | Smartsheet API + MCP +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 82 | Smartsheet API + MCP +21 |\n| Negative events | ≤15 | -4 | 0 | |\n| **Total** | | **50.1 · D** | **67.6 · B** | |\n\n## Facts side by side\n\n| Fact | Grist | Smartsheet API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Grist Labs Inc. | Smartsheet Inc. |\n| Hosted endpoint | `https://docs.getgrist.com/api` | `https://api.smartsheet.com/2.0` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 | Proprietary service under Smartsheet's User Agreement and Developer Agreement. The SDKs on GitHub are Apache-2.0 |\n| Tools exposed | 34 | 83 |\n| Read-only variant documented | yes | yes |\n| llms.txt | no | yes |\n| Last release | 2026-09-28 | 2026-10-06 |\n| Terms last updated | no date given | 2021-07-01 |\n| Privacy policy last updated | 2019-04-01 | 2026-05-20 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 12k stars, 341 npm/wk, 240 PyPI/wk | 82 stars, 47k npm/wk, 312k PyPI/wk |\n\n## Verdicts\n\n**Grist.** OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit.\n\n**Smartsheet API + MCP.** The REST API has a public OpenAPI 3.0.3 spec with 187 operations, Markdown docs and llms.txt, and the hosted MCP server loads its 83 documented tools by toolset. API access needs a Business plan or higher, and the status page lists eight incidents marked major or critical between 15 July and 21 September 2026.\n\n## Before you call either\n\n### Grist\n\n1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen\n2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules\n3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented\n4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row\n5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit\n\n### Smartsheet API + MCP\n\n1. Send writes to one sheet one at a time. Parallel updates with the same token return error 4004\n2. Batch row changes, up to 500 rows a call, and add `allowPartialSuccess=true` to get per-row failures instead of a failed batch\n3. On error 4003 (HTTP 429) wait at least 60 seconds before retrying. The limit is 300 requests a minute per token, 30 for attachments and cell history\n4. Through MCP, call `get_columns` before filtering or writing. Column names are case-sensitive and guesses fail validation\n5. Use the regional host that matches the account (api.smartsheet.com, .eu or .au). Tokens don't work across regions\n\n## Questions\n\n### Which is better for AI agents, Grist or Smartsheet API + MCP?\n\nSmartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing.\n\n### Do Grist and Smartsheet API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Grist and Smartsheet API + MCP without installing anything?\n\nYes. Grist has a hosted endpoint at https://docs.getgrist.com/api and Smartsheet API + MCP at https://api.smartsheet.com/2.0.\n\n### Are Grist and Smartsheet API + MCP open source?\n\nGrist is open source (Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0). No open-source release is listed for Smartsheet API + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/grist-vs-smartsheet.json, and with the fewest tokens: https://www.anchorterminal.com/compare/grist-vs-smartsheet.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"grist\", \"b\": \"smartsheet\"}`. From a terminal: `anchor compare grist smartsheet`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/grist.json and https://www.anchorterminal.com/api/v1/tools/smartsheet.json\n\n## Other comparisons with Grist or Smartsheet API + MCP\n\n- [Coda (Superhuman Docs) vs Grist](https://www.anchorterminal.com/compare/coda-vs-grist.md)\n- [Coda (Superhuman Docs) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/coda-vs-smartsheet.md)\n- [Google Sheets API vs Grist](https://www.anchorterminal.com/compare/google-sheets-api-vs-grist.md)\n- [Google Sheets API vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/google-sheets-api-vs-smartsheet.md)\n- [Grist vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/grist-vs-microsoft-excel-graph.md)\n- [Microsoft Excel (Microsoft Graph workbook API) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet.md)\n- [Smartsheet API + MCP vs Teable](https://www.anchorterminal.com/compare/smartsheet-vs-teable.md)\n- [Airtable vs Grist](https://www.anchorterminal.com/compare/airtable-vs-grist.md)\n- [Airtable vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/airtable-vs-smartsheet.md)\n- [Baserow vs Grist](https://www.anchorterminal.com/compare/baserow-vs-grist.md)\n- [Baserow vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/baserow-vs-smartsheet.md)\n- [Grist vs NocoDB](https://www.anchorterminal.com/compare/grist-vs-nocodb.md)\n- [Grist vs SeaTable](https://www.anchorterminal.com/compare/grist-vs-seatable.md)\n- [Grist vs Teable](https://www.anchorterminal.com/compare/grist-vs-teable.md)\n- [NocoDB vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/nocodb-vs-smartsheet.md)\n- [SeaTable vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/seatable-vs-smartsheet.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Grist vs Smartsheet API + MCP",
        "url": ""
      }
    ],
    "description": "Smartsheet API + MCP scores 67.6 (B) on agent readiness against Grist's 50.1 (D), and leads in 6 of 7 scored categories. Grist leads on payments \u0026 pricing. Both do sheets records. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Grist D 50.1",
      "Smartsheet API + MCP B 67.6",
      "scores"
    ],
    "h1": "Grist vs Smartsheet API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-grist-vs-smartsheet.png",
    "path": "/compare/grist-vs-smartsheet",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Grist vs Smartsheet API + MCP for AI agents, D 50.1 vs B 67.6",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/grist-vs-smartsheet"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
