{
  "data": {
    "a": {
      "slug": "helicone",
      "name": "Helicone AI Gateway + MCP",
      "vendor": "Helicone (Mintlify)",
      "vendorUrl": "https://www.helicone.ai",
      "kind": "http-api",
      "category": "agent-observability",
      "summary": "Open-source LLM observability that logs requests through an OpenAI-compatible gateway (100+ models, fallbacks, caching, rate limits) or async logging.",
      "url": "https://www.anchorterminal.com/tools/helicone",
      "markdownUrl": "https://www.anchorterminal.com/tools/helicone.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/helicone.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/helicone.json",
      "repo": "https://github.com/Helicone/helicone",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://ai-gateway.helicone.ai",
      "packages": [
        {
          "registry": "npm",
          "name": "@helicone/helpers"
        },
        {
          "registry": "pypi",
          "name": "helicone-helpers"
        },
        {
          "registry": "npm",
          "name": "@helicone/mcp"
        }
      ],
      "auth": "api-key",
      "authNotes": "Helicone API key (`sk-helicone-...`) as a Bearer token on the gateway and REST API. Bring your own provider keys, or bill model usage to Helicone credits, which since 25 August 2026 only works for organisations Helicone has switched on (others get a 403 asking them to contact support). The MCP server reads `HELICONE_API_KEY` from the environment.",
      "pricing": "freemium",
      "pricingNotes": "Hobby free with 10,000 requests a month, 1 GB of storage, 1 seat and 7 days of retention, no card. Pro $79 a month and Team $799 a month, each with 10,000 requests and 1 GB free then usage-based charges the pricing page doesn't itemise. The pricing page still shows 7-day trials, but a commit on 30 August 2026 removed the in-app self-serve upgrade paths and sends upgrades to a contact page. Enterprise custom. Gateway credits pass model prices through at 0% markup, but since 25 August 2026 need Helicone to enable them per organisation. Self-hosted is free under Apache-2.0 with Docker Compose or Helm, you run ClickHouse, Postgres and object storage (https://www.helicone.ai/pricing).",
      "priceSummary": "$79 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 6190,
        "npmWeekly": 4328,
        "pypiWeekly": 4210,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.helicone.ai",
      "llmsTxt": "https://docs.helicone.ai/llms.txt",
      "openapi": "https://docs.helicone.ai/ai-gateway.openapi.json",
      "capabilities": [
        "obs.traces",
        "obs.gateway",
        "obs.prompts",
        "obs.datasets",
        "obs.evals"
      ],
      "tags": [
        "hosted",
        "freemium",
        "no-card",
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 46.9,
        "grade": "D",
        "agentReady": false,
        "rank": 637,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 30,
          "reliability": 50,
          "schema": 69,
          "security": 50,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -10,
        "negativeNotes": [
          "2026-08-30. Helicone's own security commit (INC-657) fixed an authenticated cross-tenant read of other organisations' decrypted provider keys, a route that let any account mint proxy keys spending another organisation's provider key, a shared client that reused one organisation's OpenRouter key for others, an unauthenticated SSRF path and unauthenticated Stripe routes. Fixed, but disclosed only in the commit message, with no advisory or key-rotation notice that we found. -7 after decay for the fix (https://github.com/Helicone/helicone/commit/ca34549ea56f7ed587843f82d9cc19baa1f36ba4)",
          "2026-09-16. A second fix closed a platform-admin takeover with a forged API key and a cross-tenant read through HQL, reported through Helicone's disclosure programme the same day. Fixed within hours and again disclosed only in the commit. -3 (https://github.com/Helicone/helicone/commit/067d9290acb4f1fc9320e902fc67b4b399b50363)"
        ],
        "verdict": "One base-URL change gives logging, caching, fallbacks and rate limits for 100+ models. Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages.",
        "bestFor": "A team that wants request logging and cost tracking through a gateway with almost no code, and could swap it out later.",
        "strengths": [
          "One base-URL change gives logging, caching, fallbacks and rate limits for 100+ models",
          "Apache-2.0 with Docker Compose and Helm self-hosting",
          "Per-plan ingestion and API rate limits published on the pricing page",
          "OpenAPI for the gateway, a Swagger file for the REST API and an llms.txt",
          "Free Hobby plan with 10,000 requests a month and no card"
        ],
        "weaknesses": [
          "Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages",
          "Maintenance mode since March 2026, changelog silent since 26 November 2025, and Experiments, Realtime and self-serve upgrades removed on 30 August 2026",
          "The status page has no incident history, leaves out the AI Gateway and doesn't mention the four-day outage of 14 to 18 May 2026",
          "Helicone credits need a per-organisation switch since 25 August 2026, so new accounts must bring their own provider keys",
          "Privacy policy last updated in February 2023, with no retention period or DPA"
        ],
        "agentNotes": [
          "Bring your own provider keys. Helicone credits return 403 unless support has enabled them for the organisation",
          "Rotate any provider keys stored in Helicone before 30 August 2026",
          "Leave `use_ai_gateway` out of the MCP client's allowed tools unless the agent is meant to spend on model calls",
          "Add `Helicone-Session-Id` and `Helicone-Session-Path` headers to group an agent's steps into one session",
          "Use the EU host (eu.helicone.ai) if the account was created there"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 46.9
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 30,
          "reliability": 50,
          "schema": 69,
          "security": 50,
          "transparency": 60
        },
        "provenanceScore": 77
      },
      "connect": {
        "http": "curl https://ai-gateway.helicone.ai/chat/completions -H \"Authorization: Bearer $HELICONE_API_KEY\" \\\n  -H \"content-type: application/json\" -d '{\"model\":\"gpt-4o-mini\",\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'",
        "claudeCode": "claude mcp add helicone -e HELICONE_API_KEY=$HELICONE_API_KEY -- npx -y @helicone/mcp@latest",
        "config": {
          "mcpServers": {
            "helicone": {
              "args": [
                "-y",
                "@helicone/mcp@latest"
              ],
              "command": "npx",
              "env": {
                "HELICONE_API_KEY": "${HELICONE_API_KEY}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/obs.traces",
        "tool": "https://letme.dev/helicone"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 79,
          "note": "10,000 requests and 1 GB free, then usage-based"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 799,
          "note": "5 organisations, SOC 2 and HIPAA, 10,000 requests and 1 GB free, then usage-based"
        }
      ],
      "provenance": {
        "legalEntity": "Helicone, Inc.",
        "domain": "helicone.ai",
        "domainRegistered": "2022-11-14",
        "endpointOnVendorDomain": true,
        "terms": "https://www.helicone.ai/terms",
        "privacy": "https://www.helicone.ai/privacy",
        "statusPage": "https://status.helicone.ai",
        "changelog": "https://www.helicone.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Terms still name Helicone, Inc. and were last updated 2024-09-17, before the Mintlify acquisition"
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/helicone.json",
      "live": {
        "slug": "helicone",
        "probe": {
          "target": "https://ai-gateway.helicone.ai",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.969454582Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 57,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 61,
          "p95ms24h": 220,
          "samples24h": 271,
          "samples30d": 2157,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 239,
              "ok": 239
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.helicone.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:40.32810289Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "Helicone/helicone",
            "version": "v2025.08.21-1",
            "released": "2025-08-21",
            "seenAt": "2026-10-08T16:15:43.658891444Z"
          },
          {
            "registry": "npm",
            "name": "@helicone/helpers",
            "version": "1.8.3",
            "seenAt": "2026-10-08T16:15:39.110387764Z"
          },
          {
            "registry": "npm",
            "name": "@helicone/mcp",
            "version": "0.1.6",
            "seenAt": "2026-10-08T16:15:43.374156833Z"
          },
          {
            "registry": "pypi",
            "name": "helicone-helpers",
            "version": "1.2.1",
            "released": "2025-11-08",
            "seenAt": "2026-10-08T16:15:43.172139276Z"
          }
        ],
        "githubStars": 6207,
        "npmWeekly": 4098,
        "pypiWeekly": 5047,
        "securityTxt": {
          "url": "https://helicone.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:48.322224123Z"
        },
        "llmsTxt": {
          "url": "https://docs.helicone.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:30.524662626Z"
        },
        "domain": {
          "domain": "helicone.ai",
          "registered": "2022-11-14",
          "source": "https://rdap.identitydigital.services/rdap/domain/helicone.ai",
          "checkedAt": "2026-10-04T13:08:06.915944951Z"
        },
        "pages": [
          {
            "url": "https://www.helicone.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:13.75089463Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1af05c56483a"
          },
          {
            "url": "https://www.helicone.ai/blog/joining-mintlify",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:11.435654609Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a82c441b1103"
          },
          {
            "url": "https://www.helicone.ai/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:15.76040529Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4b1e79419d28"
          },
          {
            "url": "https://www.helicone.ai/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:17.685382305Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "47e9ad5d395a"
          },
          {
            "url": "https://www.helicone.ai/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:19.61207903Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "adbbffec4ecd"
          }
        ],
        "updatedAt": "2026-10-08T21:12:11.969454582Z"
      }
    },
    "answer": "Prefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust.",
    "b": {
      "slug": "prefactor",
      "name": "Prefactor",
      "vendor": "Prefactor Pty Ltd",
      "vendorUrl": "https://prefactor.tech",
      "kind": "http-api",
      "category": "agent-observability",
      "summary": "Prefactor is a hosted service that records AI agent runs as spans, classifies each run's data risk and stores quality evaluations. Agents and scripts reach it through an HTTP and WebSocket API, TypeScript and Python SDKs and a CLI.",
      "url": "https://www.anchorterminal.com/tools/prefactor",
      "markdownUrl": "https://www.anchorterminal.com/tools/prefactor.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/prefactor.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prefactor.json",
      "repo": "https://github.com/prefactordev/typescript-sdk",
      "license": "Proprietary hosted service. The TypeScript and Python SDKs and the CLI are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.prefactorai.com/api/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@prefactor/core"
        },
        {
          "registry": "npm",
          "name": "@prefactor/cli"
        },
        {
          "registry": "pypi",
          "name": "prefactor-core"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. A person signs in at app.prefactorai.com and creates an API token, sent as `Authorization: Bearer \u003ctoken\u003e`. Account tokens reach every agent in the account. Deployment tokens are bound to one agent in one environment. The OpenAPI document adds a `role` of `read_only` or `full_access` (the default) and an `expires_at` that defaults to two years. Tokens can be suspended, reactivated and revoked. `POST /api_token` mints tokens with an existing token.",
      "pricing": "freemium",
      "pricingNotes": "Free Dev plan with 5,000 spans a month, up to 3 agents and 7-day retention, no card required, so an agent's owner can start without a contract. Startup is $49 a month ($499 a year) with 15,000 spans, then $0.0025 a span. Scaleup is $199 a month ($2,000 a year) with 100,000 spans, then $2.50 per 1,000 spans monthly or $2.00 on the annual plan. Enterprise, from 4 million spans a month, is by quote. A span is one LLM call, tool call, message turn or custom step. Seats are unlimited on every plan (https://prefactor.tech/pricing).",
      "priceSummary": "$49 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 19,
        "pypiWeekly": 28,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.prefactor.ai",
      "llmsTxt": "https://docs.prefactor.ai/llms.txt",
      "openapi": "https://app.prefactorai.com/api/v1/openapi",
      "capabilities": [
        "obs.traces",
        "obs.evals"
      ],
      "tags": [
        "hosted",
        "freemium",
        "no-card",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "closed-source",
        "enterprise",
        "status-page"
      ],
      "lastRelease": "2026-09-13",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.6,
        "grade": "B",
        "agentReady": false,
        "rank": 253,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 88,
          "maintenance": 82,
          "payments": 40,
          "reliability": 78,
          "schema": 80,
          "security": 56,
          "transparency": 42
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-10-08. The pricing page lists 'Hold, approve or block in real time' and PII detection on every plan, and the security page lists manual approval workflows and fine-grained RBAC. The vendor's own docs say crossing a risk threshold does not block or terminate a run, that Prefactor does not detect sensitive data, and that accounts have no role-based permissions. The OpenAPI and OpenRPC documents have no approval operation. Counted as a misleading claim (-3). The docs may lag the product, since the API has hosted judge operations they do not describe (https://prefactor.tech/pricing, https://prefactor.tech/security, https://docs.prefactor.ai/llms-full.txt)."
        ],
        "verdict": "The public OpenAPI document lists 157 operations, each accepting an idempotency key, and tokens can be read-only or bound to one agent deployment. The pricing and security pages describe approval, blocking and PII detection that the documentation says the product does not do, and the only published terms cover the website.",
        "bestFor": "A team that wants an auditable record of agent runs with declared data-risk labels, quality payloads from its own evaluations and a remote stop signal.",
        "strengths": [
          "Public OpenAPI 3.0 document with 157 operations and an OpenRPC document with 159 WebSocket methods, both fetched without a login",
          "Every write accepts an `idempotency_key`, and `POST /bulk` can be retried whole because a reused key fails only its own item",
          "Tokens are scoped to the account or to one agent deployment, carry a `read_only` or `full_access` role and an expiry, and can be suspended or revoked",
          "A 429 response carries `Retry-After` and `retry_after_ms`, and both SDKs retry with exponential backoff and jitter",
          "The free Dev plan includes 5,000 spans a month with no card, and the overage price per span is published"
        ],
        "weaknesses": [
          "The pricing page lists hold, approve or block and PII detection on every plan, while the docs say a risk threshold blocks nothing and that Prefactor does not detect sensitive data",
          "No approval operation exists in the OpenAPI or OpenRPC documents. The documented control is a cooperative terminate signal the agent's own code must obey",
          "The published terms of service cover the website. No service agreement, DPA, sub-processor list or SLA text was found",
          "Rate limits are described by scope with no numbers",
          "No security.txt and no certification held. The security page says SOC 2 Type II is in progress"
        ],
        "agentNotes": [
          "Send requests to `https://app.prefactorai.com/api/v1` with `Authorization: Bearer \u003ctoken\u003e`. The API host is not on the `prefactor.tech` or `prefactor.ai` domains",
          "Ask for a deployment-scoped token, or an account token created with `role` set to `read_only`, since the default role is `full_access` with a two-year expiry",
          "Pass `redacted: true` on span list and detail queries, because the API returns marked sensitive values unless asked otherwise",
          "On 429 wait for `retry_after_ms`. Limits use one-minute windows and the SDKs' default retries ignore the server's hint",
          "Treat terminate as a request. Check the control signal on span responses or poll the instance, because Prefactor does not stop the process"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.6
          }
        ],
        "editorialScores": {
          "ergonomics": 88,
          "maintenance": 82,
          "payments": 40,
          "reliability": 78,
          "schema": 80,
          "security": 56,
          "transparency": 34
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npm install @prefactor/core",
        "http": "curl https://app.prefactorai.com/api/v1/agent \\\n  -H \"Authorization: Bearer $PREFACTOR_API_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/obs.traces",
        "tool": "https://letme.dev/prefactor"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Startup plan",
          "unit": "month",
          "usd": 49,
          "note": "15,000 spans included, 3-month retention"
        },
        {
          "item": "Scaleup plan",
          "unit": "month",
          "usd": 199,
          "note": "100,000 spans included, 12-month retention"
        },
        {
          "item": "Span beyond the Startup allowance",
          "unit": "record",
          "usd": 0.0025
        },
        {
          "item": "Span beyond the Scaleup allowance",
          "unit": "record",
          "usd": 0.0025,
          "note": "$2.50 per 1,000 on monthly billing, $2.00 on annual"
        }
      ],
      "provenance": {
        "legalEntity": "Prefactor Pty Ltd",
        "domain": "prefactor.tech",
        "domainRegistered": "2024-10-16",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://prefactor.tech/privacy-policy",
        "statusPage": "https://status.prefactor.ai",
        "changelog": "https://prefactor.tech/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "prefactor.tech/llms.txt names Prefactor Pty Ltd, founded 2024, headquartered in Australia. The legal documents name the same entity and New South Wales law.",
          "`terms` is left out. The only published terms (last updated 17 March 2026) govern use of the website at prefactor.tech and are a generated website template. No service agreement, API terms or DPA was found on the site or in its sitemap.",
          "The privacy policy and terms pages are drawn by script from GetTerms. We read them from the feed the pages load (gettermscdn.com) and could render only the regional sections of the privacy policy, not its main body.",
          "The API answers at app.prefactorai.com, a third domain of the vendor's registered on 18 December 2025. The site is on prefactor.tech and the docs on docs.prefactor.ai.",
          "RDAP gives prefactor.tech a registration date of 16 October 2024 and an expiry of 16 October 2026, eight days after this check.",
          "prefactor.tech, app.prefactorai.com and docs.prefactor.ai each return 404 for /.well-known/security.txt. The security page asks for reports by email and promises an acknowledgement within 24 hours.",
          "status.prefactor.ai is an UptimeRobot page. We found no link to it on the site or docs pages we read."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/prefactor.json",
      "live": {
        "slug": "prefactor",
        "probe": {
          "target": "https://app.prefactorai.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-08T21:12:19.160085406Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 388,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 353,
          "p95ms24h": 431,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.prefactor.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:04.756104641Z"
        },
        "updatedAt": "2026-10-08T21:12:19.160085406Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Helicone (Mintlify)",
        "b": "Prefactor Pty Ltd",
        "name": "Vendor"
      },
      {
        "a": "https://ai-gateway.helicone.ai",
        "b": "https://app.prefactorai.com/api/v1",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Proprietary hosted service. The TypeScript and Python SDKs and the CLI are MIT",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-16",
        "b": "2026-09-13",
        "name": "Last release"
      },
      {
        "a": "2024-09-17",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2023-02-28",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6.2k stars, 4.3k npm/wk, 4.2k PyPI/wk",
        "b": "3 stars, 19 npm/wk, 28 PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "2/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Prefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Helicone AI Gateway + MCP or Prefactor?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Helicone AI Gateway + MCP and Prefactor need an API key?"
      },
      {
        "answer": "Yes. Helicone AI Gateway + MCP has a hosted endpoint at https://ai-gateway.helicone.ai and Prefactor at https://app.prefactorai.com/api/v1.",
        "question": "Can an agent call Helicone AI Gateway + MCP and Prefactor without installing anything?"
      },
      {
        "answer": "Helicone AI Gateway + MCP is open source (Apache-2.0). No open-source release is listed for Prefactor.",
        "question": "Are Helicone AI Gateway + MCP and Prefactor open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Transparency \u0026 trust, 69 against 42"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "A team that wants request logging and cost tracking through a gateway with almost no code, and could swap it out later.",
        "slug": "helicone",
        "watchFor": "Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages"
      },
      {
        "aheadOn": [
          "Reliability, 78 against 50",
          "Schema \u0026 documentation, 80 against 69",
          "Agent ergonomics, 88 against 70",
          "Security \u0026 auth, 56 against 50",
          "Payments \u0026 pricing, 40 against 30",
          "Maintenance \u0026 community, 82 against 66"
        ],
        "also": null,
        "goodFor": "A team that wants an auditable record of agent runs with declared data-risk labels, quality payloads from its own evaluations and a remote stop signal.",
        "slug": "prefactor",
        "watchFor": "The pricing page lists hold, approve or block and PII detection on every plan, while the docs say a risk threshold blocks nothing and that Prefactor does not detect sensitive data"
      }
    ],
    "job": {
      "capability": "obs.traces",
      "name": "Obs traces"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/arize-phoenix-vs-helicone.json",
        "title": "Arize Phoenix vs Helicone AI Gateway + MCP",
        "url": "https://www.anchorterminal.com/compare/arize-phoenix-vs-helicone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arize-phoenix-vs-prefactor.json",
        "title": "Arize Phoenix vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/arize-phoenix-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserun-vs-helicone.json",
        "title": "Baserun vs Helicone AI Gateway + MCP",
        "url": "https://www.anchorterminal.com/compare/baserun-vs-helicone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/baserun-vs-prefactor.json",
        "title": "Baserun vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/baserun-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/braintrust-vs-helicone.json",
        "title": "Braintrust API + MCP vs Helicone AI Gateway + MCP",
        "url": "https://www.anchorterminal.com/compare/braintrust-vs-helicone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/braintrust-vs-prefactor.json",
        "title": "Braintrust API + MCP vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/braintrust-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/galileo-vs-helicone.json",
        "title": "Galileo API + MCP vs Helicone AI Gateway + MCP",
        "url": "https://www.anchorterminal.com/compare/galileo-vs-helicone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/galileo-vs-prefactor.json",
        "title": "Galileo API + MCP vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/galileo-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/helicone-vs-honeyhive.json",
        "title": "Helicone AI Gateway + MCP vs HoneyHive",
        "url": "https://www.anchorterminal.com/compare/helicone-vs-honeyhive"
      },
      {
        "json": "https://www.anchorterminal.com/compare/helicone-vs-laminar.json",
        "title": "Helicone AI Gateway + MCP vs Laminar API + MCP",
        "url": "https://www.anchorterminal.com/compare/helicone-vs-laminar"
      },
      {
        "json": "https://www.anchorterminal.com/compare/helicone-vs-langfuse.json",
        "title": "Helicone AI Gateway + MCP vs Langfuse API + MCP",
        "url": "https://www.anchorterminal.com/compare/helicone-vs-langfuse"
      },
      {
        "json": "https://www.anchorterminal.com/compare/helicone-vs-langsmith.json",
        "title": "Helicone AI Gateway + MCP vs LangSmith API + MCP",
        "url": "https://www.anchorterminal.com/compare/helicone-vs-langsmith"
      },
      {
        "json": "https://www.anchorterminal.com/compare/helicone-vs-respan.json",
        "title": "Helicone AI Gateway + MCP vs Respan API + MCP",
        "url": "https://www.anchorterminal.com/compare/helicone-vs-respan"
      },
      {
        "json": "https://www.anchorterminal.com/compare/honeyhive-vs-prefactor.json",
        "title": "HoneyHive vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/honeyhive-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/laminar-vs-prefactor.json",
        "title": "Laminar API + MCP vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/laminar-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/langfuse-vs-prefactor.json",
        "title": "Langfuse API + MCP vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/langfuse-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/langsmith-vs-prefactor.json",
        "title": "LangSmith API + MCP vs Prefactor",
        "url": "https://www.anchorterminal.com/compare/langsmith-vs-prefactor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prefactor-vs-respan.json",
        "title": "Prefactor vs Respan API + MCP",
        "url": "https://www.anchorterminal.com/compare/prefactor-vs-respan"
      }
    ],
    "scores": [
      {
        "by": 28,
        "edge": "prefactor",
        "helicone": 50,
        "key": "reliability",
        "name": "Reliability",
        "prefactor": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "prefactor",
        "helicone": 69,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "prefactor": 80,
        "weight": 13
      },
      {
        "by": 18,
        "edge": "prefactor",
        "helicone": 70,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "prefactor": 88,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "prefactor",
        "helicone": 50,
        "key": "security",
        "name": "Security \u0026 auth",
        "prefactor": 56,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "prefactor",
        "helicone": 30,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "prefactor": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 16,
        "edge": "prefactor",
        "helicone": 66,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "prefactor": 82,
        "weight": 7
      },
      {
        "by": 27,
        "edge": "helicone",
        "helicone": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "prefactor": 42,
        "weight": 7
      }
    ],
    "summary": "Prefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust. Both do obs traces.",
    "verdicts": {
      "helicone": "One base-URL change gives logging, caching, fallbacks and rate limits for 100+ models. Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages.",
      "prefactor": "The public OpenAPI document lists 157 operations, each accepting an idempotency key, and tokens can be read-only or bound to one agent deployment. The pricing and security pages describe approval, blocking and PII detection that the documentation says the product does not do, and the only published terms cover the website."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/helicone-vs-prefactor",
    "json": "https://www.anchorterminal.com/compare/helicone-vs-prefactor.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/helicone-vs-prefactor.md",
    "slim": "https://www.anchorterminal.com/compare/helicone-vs-prefactor.min.md"
  },
  "markdown": "Prefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust. Both do obs traces.\n\n- Helicone AI Gateway + MCP: grade D, 46.9/100, rank #637 of 722. Markdown https://www.anchorterminal.com/tools/helicone.md · JSON https://www.anchorterminal.com/api/v1/tools/helicone.json\n- Prefactor: grade B, 65.6/100, rank #253 of 722. Markdown https://www.anchorterminal.com/tools/prefactor.md · JSON https://www.anchorterminal.com/api/v1/tools/prefactor.json\n\n## Which one, for what\n\n### Helicone AI Gateway + MCP (D)\n\nGood for: A team that wants request logging and cost tracking through a gateway with almost no code, and could swap it out later.\n\nAhead on:\n- Transparency \u0026 trust, 69 against 42\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages\n\n### Prefactor (B)\n\nGood for: A team that wants an auditable record of agent runs with declared data-risk labels, quality payloads from its own evaluations and a remote stop signal.\n\nAhead on:\n- Reliability, 78 against 50\n- Schema \u0026 documentation, 80 against 69\n- Agent ergonomics, 88 against 70\n- Security \u0026 auth, 56 against 50\n- Payments \u0026 pricing, 40 against 30\n- Maintenance \u0026 community, 82 against 66\n\nWatch for: The pricing page lists hold, approve or block and PII detection on every plan, while the docs say a risk threshold blocks nothing and that Prefactor does not detect sensitive data\n\n\n## Score by category\n\n| Category | Weight | Helicone AI Gateway + MCP | Prefactor | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 50 | 78 | Prefactor +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 69 | 80 | Prefactor +11 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 88 | Prefactor +18 |\n| Security \u0026 auth | 14% (17.5 this run) | 50 | 56 | Prefactor +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Prefactor +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 66 | 82 | Prefactor +16 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 42 | Helicone AI Gateway + MCP +27 |\n| Negative events | ≤15 | -10 | -3 | |\n| **Total** | | **46.9 · D** | **65.6 · B** | |\n\n## Facts side by side\n\n| Fact | Helicone AI Gateway + MCP | Prefactor |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Helicone (Mintlify) | Prefactor Pty Ltd |\n| Hosted endpoint | `https://ai-gateway.helicone.ai` | `https://app.prefactorai.com/api/v1` |\n| Transports | HTTP, stdio | HTTP |\n| Auth | API key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | Proprietary hosted service. The TypeScript and Python SDKs and the CLI are MIT |\n| Tools exposed | 3 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-16 | 2026-09-13 |\n| Terms last updated | 2024-09-17 | no document linked |\n| Privacy policy last updated | 2023-02-28 | couldn't be read |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 6.2k stars, 4.3k npm/wk, 4.2k PyPI/wk | 3 stars, 19 npm/wk, 28 PyPI/wk |\n| Agent reviews | 2/5 (2) | none |\n\n## Verdicts\n\n**Helicone AI Gateway + MCP.** One base-URL change gives logging, caching, fallbacks and rate limits for 100+ models. Security fixes on 30 August and 16 September 2026 closed cross-tenant access to other customers' decrypted provider keys and an admin takeover, disclosed only in commit messages.\n\n**Prefactor.** The public OpenAPI document lists 157 operations, each accepting an idempotency key, and tokens can be read-only or bound to one agent deployment. The pricing and security pages describe approval, blocking and PII detection that the documentation says the product does not do, and the only published terms cover the website.\n\n## Before you call either\n\n### Helicone AI Gateway + MCP\n\n1. Bring your own provider keys. Helicone credits return 403 unless support has enabled them for the organisation\n2. Rotate any provider keys stored in Helicone before 30 August 2026\n3. Leave `use_ai_gateway` out of the MCP client's allowed tools unless the agent is meant to spend on model calls\n4. Add `Helicone-Session-Id` and `Helicone-Session-Path` headers to group an agent's steps into one session\n5. Use the EU host (eu.helicone.ai) if the account was created there\n\n### Prefactor\n\n1. Send requests to `https://app.prefactorai.com/api/v1` with `Authorization: Bearer \u003ctoken\u003e`. The API host is not on the `prefactor.tech` or `prefactor.ai` domains\n2. Ask for a deployment-scoped token, or an account token created with `role` set to `read_only`, since the default role is `full_access` with a two-year expiry\n3. Pass `redacted: true` on span list and detail queries, because the API returns marked sensitive values unless asked otherwise\n4. On 429 wait for `retry_after_ms`. Limits use one-minute windows and the SDKs' default retries ignore the server's hint\n5. Treat terminate as a request. Check the control signal on span responses or poll the instance, because Prefactor does not stop the process\n\n## Questions\n\n### Which is better for AI agents, Helicone AI Gateway + MCP or Prefactor?\n\nPrefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust.\n\n### Do Helicone AI Gateway + MCP and Prefactor need an API key?\n\nBoth need an API key.\n\n### Can an agent call Helicone AI Gateway + MCP and Prefactor without installing anything?\n\nYes. Helicone AI Gateway + MCP has a hosted endpoint at https://ai-gateway.helicone.ai and Prefactor at https://app.prefactorai.com/api/v1.\n\n### Are Helicone AI Gateway + MCP and Prefactor open source?\n\nHelicone AI Gateway + MCP is open source (Apache-2.0). No open-source release is listed for Prefactor.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/helicone-vs-prefactor.json, and with the fewest tokens: https://www.anchorterminal.com/compare/helicone-vs-prefactor.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"helicone\", \"b\": \"prefactor\"}`. From a terminal: `anchor compare helicone prefactor`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/helicone.json and https://www.anchorterminal.com/api/v1/tools/prefactor.json\n\n## Other comparisons with Helicone AI Gateway + MCP or Prefactor\n\n- [Arize Phoenix vs Helicone AI Gateway + MCP](https://www.anchorterminal.com/compare/arize-phoenix-vs-helicone.md)\n- [Arize Phoenix vs Prefactor](https://www.anchorterminal.com/compare/arize-phoenix-vs-prefactor.md)\n- [Baserun vs Helicone AI Gateway + MCP](https://www.anchorterminal.com/compare/baserun-vs-helicone.md)\n- [Baserun vs Prefactor](https://www.anchorterminal.com/compare/baserun-vs-prefactor.md)\n- [Braintrust API + MCP vs Helicone AI Gateway + MCP](https://www.anchorterminal.com/compare/braintrust-vs-helicone.md)\n- [Braintrust API + MCP vs Prefactor](https://www.anchorterminal.com/compare/braintrust-vs-prefactor.md)\n- [Galileo API + MCP vs Helicone AI Gateway + MCP](https://www.anchorterminal.com/compare/galileo-vs-helicone.md)\n- [Galileo API + MCP vs Prefactor](https://www.anchorterminal.com/compare/galileo-vs-prefactor.md)\n- [Helicone AI Gateway + MCP vs HoneyHive](https://www.anchorterminal.com/compare/helicone-vs-honeyhive.md)\n- [Helicone AI Gateway + MCP vs Laminar API + MCP](https://www.anchorterminal.com/compare/helicone-vs-laminar.md)\n- [Helicone AI Gateway + MCP vs Langfuse API + MCP](https://www.anchorterminal.com/compare/helicone-vs-langfuse.md)\n- [Helicone AI Gateway + MCP vs LangSmith API + MCP](https://www.anchorterminal.com/compare/helicone-vs-langsmith.md)\n- [Helicone AI Gateway + MCP vs Respan API + MCP](https://www.anchorterminal.com/compare/helicone-vs-respan.md)\n- [HoneyHive vs Prefactor](https://www.anchorterminal.com/compare/honeyhive-vs-prefactor.md)\n- [Laminar API + MCP vs Prefactor](https://www.anchorterminal.com/compare/laminar-vs-prefactor.md)\n- [Langfuse API + MCP vs Prefactor](https://www.anchorterminal.com/compare/langfuse-vs-prefactor.md)\n- [LangSmith API + MCP vs Prefactor](https://www.anchorterminal.com/compare/langsmith-vs-prefactor.md)\n- [Prefactor vs Respan API + MCP](https://www.anchorterminal.com/compare/prefactor-vs-respan.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Helicone AI Gateway + MCP vs Prefactor",
        "url": ""
      }
    ],
    "description": "Prefactor scores 65.6 (B) on agent readiness against Helicone AI Gateway + MCP's 46.9 (D), and leads in 6 of 7 scored categories. Helicone AI Gateway + MCP leads on transparency \u0026 trust. Both do obs traces. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Helicone AI Gateway + MCP D 46.9",
      "Prefactor B 65.6",
      "scores"
    ],
    "h1": "Helicone AI Gateway + MCP vs Prefactor",
    "image": "https://www.anchorterminal.com/assets/og/compare-helicone-vs-prefactor.png",
    "path": "/compare/helicone-vs-prefactor",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Helicone AI Gateway + MCP vs Prefactor for AI agents, D 46.9 vs B 65.6",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/helicone-vs-prefactor"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
