{
  "fixes": {
    "slug": "cognee",
    "name": "Cognee",
    "listing": "https://www.anchorterminal.com/tools/cognee",
    "markdown": "# Fix list: Cognee\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/cognee, the October 2026 research run, assessed 1 October 2026. Grade C, 54.6 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Cognee: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Security \u0026 auth, 39 out of 100, up to 10.7 more on the total\n\nWhy it scored 39: Cloud takes an `X-Api-Key` per tenant, which the security page says can be rotated, and the OpenAPI file lists endpoints to create and delete keys. The local REST server runs without auth unless you turn it on, then takes a Bearer token (15 of 30). Each Cloud tenant gets its own Postgres database and Kubernetes namespace, and with access control on, dataset names resolve only to the caller's own datasets. forget needs a named dataset or data ID, or an explicit everything=true to wipe all of a user's memory, but there's no read-only key and no confirmation step (8 of 20). Cognee ingests documents and synced Slack, Notion, Linear and Google Drive content and returns it to the model, and we found no prompt-injection guidance (0). Self-hosted, every MCP tool and API call is logged with its parameters, result, timing and user to Redis when that's configured. We found no audit log for Cloud (6 of 15). SECURITY.md asks for reports to security@cognee.ai, and an OpenSSF Scorecard workflow runs in CI. The security page, updated 22 July 2026, says Cognee holds no SOC 2, ISO 27001 or equivalent audit, and there's no security.txt (10 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 2. Reliability, 50 out of 100, up to 10 more on the total\n\nWhy it scored 50: We departed from the checklist here. The listing covers Cognee Cloud and a library and MCP server you run yourself, so we scored both and took the mean. For Cloud, no status page found (0), no incident history to read (5), no rate limits in the docs or the OpenAPI file (0), no 429 guidance (0), Enterprise names a \"Support SLA\" with no figure (5 of 10), generally available (10), 20 in all. In August 2026 a Cloud tenant's add and search calls hung for over 56 hours instead of returning an error, which maintainers traced to an empty credit balance (issue #4673, still open). For the local package, cognee on PyPI with Python 3.10 to below 3.15 stated (20), 63 GitHub Actions workflows with the test suites passing on main in the ten most recent runs we read on 2 October (25), open regressions we couldn't count because GitHub's issue search is closed to our reader (10 of 25), release notes that flag breaking changes such as dlt becoming a core dependency in 1.6.1, though 11 MCP tools were removed in May without a version bump (10 of 15), version 1.6 (15), 80 in all. Mean 50.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 3. Payments \u0026 pricing, 35 out of 100, up to 8.1 more on the total\n\nWhy it scored 35: No x402, MPP or L402 (0). Standard is $1 per million tokens processed and $5 a month per extra workspace, published without a login, but the billing docs re-read on 2 October still show Hobby with 10 million tokens, Growth at $5 a tenant and Enterprise at $2,916 a month, which disagree with the pricing page (15 of 20). Free includes 1 million tokens and 1 workspace, \"no card required\" (20). A person signs up for a Cloud tenant in the browser (0). Self-hosting is free, and since 1.6.0 runs local models with no LLM key, but the rubric scores the hosted option.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 4. Agent ergonomics, 59 out of 100, up to 6.7 more on the total\n\nWhy it scored 59: The tools reference lists 7 MCP tools, remember, recall, forget, code_search, search_tools, call_tool and cognify_status, with search_tools and call_tool reaching further tools on demand and COGNEE_MCP_TOOL_MODE=minimal cutting the list to the memory tools (25). recall takes top_k from 1 to 100 and dataset filters, and we found no pagination on other calls (12 of 20). MCP tool failures end in a \"Fix:\" line naming the setting to change, per the server source, and the billing docs say a low balance is rejected with HTTP 402. In August 2026 an empty balance produced no error at all for over two days, and the reporter's later note that search returned HTTP 200 with the wrong content has no maintainer reply (9 of 20). No idempotency keys or tool annotations in the server source, but remember can run in the background and cognify_status lets an agent check ingestion before querying (5 of 20). Python only, and the MCP server starts with one docker run (8 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Transparency \u0026 trust, 67 out of 100, up to 2.9 more on the total\n\nMade of editorial 69, provenance 65.\n\nWhy it scored 67: The library, REST server and MCP server are Apache-2.0, and Cloud is closed (25 of 30). The privacy notice of 20 September 2026 gives retention by data type (account data deleted 30 days after termination, product usage 24 months, technical logs 30 days to 12 months, billing 10 years for the EU entity and 7 for the US one), and the security page names a data protection officer and deletes a tenant's whole database when it goes. The notice calls library telemetry anonymous, while the source sends a machine ID that survives reinstalls, the user and tenant UUIDs and an ID derived from the LLM key (22 of 30). On 1 May 2026 eleven MCP tools the README called \"still available\" the day before were removed in a fix commit, and there's no written deprecation policy (6 of 20). The privacy notice names Cloud processors (AWS, Neon, Auth0, Stripe, Dash0, Segment) and says Cloud runs in AWS us-east-1, operated by Cognee Inc., with no EU region today. The library's telemetry is on by default and disclosed there, with TELEMETRY_DISABLED as the opt-out, though the README doesn't mention it (16 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Domain age: cognee.ai, no registry record we could read (0 of 15)\n- Status page: not found (0 of 10)\n- security.txt: not found (0 of 10)\n\n## 6. Schema \u0026 documentation, 85 out of 100, up to 2.4 more on the total\n\nWhy it scored 85: A public OpenAPI 3.1 file at docs.cognee.ai/cognee_openapi_spec.json with 46 paths, Bearer and API key security schemes and 4xx error models, regenerated from the FastAPI app on each release. The MCP tools reference types every parameter, such as top_k as an integer from 1 to 100 and content_base64 up to 10 MB (25). llms.txt plus separate llms-mcp.md and llms-api.md indexes (10). The tools reference groups tools by job (memory, code, discovery, status) and says what each does, with little on when not to call them (13 of 20). Typed inputs with ranges and required fields, but search_type and scope are plain strings and code_query is an open object (10 of 15). Examples in the guides, error models in the OpenAPI file, and the billing docs name HTTP 402 for a low balance, but no error catalogue (12 of 15). Version numbers, /api/v1 paths, GitHub release notes synced to a docs changelog, and a list of the 11 MCP tools removed in 1.x (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 7. Maintenance \u0026 community, 82 out of 100, up to 1.6 more on the total\n\nWhy it scored 82: cognee 1.6.2 on PyPI on 2026-09-29 (30). 1.5.0 to 1.6.2 is eight stable releases since 15 August (20). A maintainer replied within a day on issue #4673 and topped up the tenant, but the reporter's follow-up from 30 August has no answer and the issue is open (12 of 25). The official Python package is current, but it's the only language, and the registry API returns no cognee server in the official MCP registry (10 of 15). Dependabot, uv.lock and CI passing on main (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 2026-05-01: a commit titled as a fix removed 11 MCP tools, including cognify, search, delete and prune, with cognee-mcp at 0.5.4 before and after, and the README the day before listed them as \"still available\" with no deprecation note. The replacements remember, recall and forget had shipped on 10 April and the tools reference now lists what went, so we deduct at the low end (https://github.com/topoteretes/cognee/commit/b52fcc335f6bfc090d1c892afa9c4e81909336fe)\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: open crash and regression issues, since GitHub's issue search and label pages are closed to our reader. The local reliability score keeps 10 of 25 for this line on the strength of the #4673 handling.\n- No rate limits or 429 guidance found for Cloud in the docs or the OpenAPI file.\n- The privacy notice puts Cloud in AWS us-east-1 under Cognee Inc., while the security page and terms point to Topoteretes UG and German law. The listing's eu tag may mislead readers about data residency.\n- The listing carried a -2 deduction for the August 2026 hang. A hang isn't a negative-event category in the brief, so we scored it under reliability and ergonomics. The -3 now in place is for the May 2026 MCP tool removal.\n- Whether the HTTP 402 on low balance the billing docs describe is live, since #4673 has no maintainer confirmation.\n\n## Weaknesses\n\n- No status page, rate limits, SLA or SOC 2 for Cloud, and Cloud runs in AWS us-east-1 with no EU region\n- Cloud calls hung rather than failing when a tenant ran out of credit (August 2026), and the issue is still open\n- Billing docs and pricing page disagree on plans and the free allowance\n- Library telemetry is on by default and sends a persistent machine ID and an ID derived from the LLM key\n- 11 MCP tools were removed in May 2026 without a version bump or notice\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Use remember, recall and forget. The older cognify, search and delete MCP tools are gone\n- Always include /api/v1 in REST paths\n- Check cognify_status before querying data you added with background=true\n- Never pass everything=true to forget unless you mean to wipe all of the user's memory\n- Set a client timeout on Cloud calls and treat HTTP 402 as an empty balance, since an empty balance has also shown up as hangs\n\n## What the review panel asked for\n\n- Catalogue the error codes\n- Note removed tools in the old docs\n- a read-only key\n- auth on by default\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "C",
    "score": 54.6,
    "assessed": "2026-10-01",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 39,
        "maxGain": 10.7,
        "reason": "Cloud takes an `X-Api-Key` per tenant, which the security page says can be rotated, and the OpenAPI file lists endpoints to create and delete keys. The local REST server runs without auth unless you turn it on, then takes a Bearer token (15 of 30). Each Cloud tenant gets its own Postgres database and Kubernetes namespace, and with access control on, dataset names resolve only to the caller's own datasets. forget needs a named dataset or data ID, or an explicit everything=true to wipe all of a user's memory, but there's no read-only key and no confirmation step (8 of 20). Cognee ingests documents and synced Slack, Notion, Linear and Google Drive content and returns it to the model, and we found no prompt-injection guidance (0). Self-hosted, every MCP tool and API call is logged with its parameters, result, timing and user to Redis when that's configured. We found no audit log for Cloud (6 of 15). SECURITY.md asks for reports to security@cognee.ai, and an OpenSSF Scorecard workflow runs in CI. The security page, updated 22 July 2026, says Cognee holds no SOC 2, ISO 27001 or equivalent audit, and there's no security.txt (10 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 50,
        "maxGain": 10,
        "reason": "We departed from the checklist here. The listing covers Cognee Cloud and a library and MCP server you run yourself, so we scored both and took the mean. For Cloud, no status page found (0), no incident history to read (5), no rate limits in the docs or the OpenAPI file (0), no 429 guidance (0), Enterprise names a \"Support SLA\" with no figure (5 of 10), generally available (10), 20 in all. In August 2026 a Cloud tenant's add and search calls hung for over 56 hours instead of returning an error, which maintainers traced to an empty credit balance (issue #4673, still open). For the local package, cognee on PyPI with Python 3.10 to below 3.15 stated (20), 63 GitHub Actions workflows with the test suites passing on main in the ten most recent runs we read on 2 October (25), open regressions we couldn't count because GitHub's issue search is closed to our reader (10 of 25), release notes that flag breaking changes such as dlt becoming a core dependency in 1.6.1, though 11 MCP tools were removed in May without a version bump (10 of 15), version 1.6 (15), 80 in all. Mean 50.",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 35,
        "maxGain": 8.1,
        "reason": "No x402, MPP or L402 (0). Standard is $1 per million tokens processed and $5 a month per extra workspace, published without a login, but the billing docs re-read on 2 October still show Hobby with 10 million tokens, Growth at $5 a tenant and Enterprise at $2,916 a month, which disagree with the pricing page (15 of 20). Free includes 1 million tokens and 1 workspace, \"no card required\" (20). A person signs up for a Cloud tenant in the browser (0). Self-hosting is free, and since 1.6.0 runs local models with no LLM key, but the rubric scores the hosted option.",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 59,
        "maxGain": 6.7,
        "reason": "The tools reference lists 7 MCP tools, remember, recall, forget, code_search, search_tools, call_tool and cognify_status, with search_tools and call_tool reaching further tools on demand and COGNEE_MCP_TOOL_MODE=minimal cutting the list to the memory tools (25). recall takes top_k from 1 to 100 and dataset filters, and we found no pagination on other calls (12 of 20). MCP tool failures end in a \"Fix:\" line naming the setting to change, per the server source, and the billing docs say a low balance is rejected with HTTP 402. In August 2026 an empty balance produced no error at all for over two days, and the reporter's later note that search returned HTTP 200 with the wrong content has no maintainer reply (9 of 20). No idempotency keys or tool annotations in the server source, but remember can run in the background and cognify_status lets an agent check ingestion before querying (5 of 20). Python only, and the MCP server starts with one docker run (8 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 67,
        "maxGain": 2.9,
        "reason": "The library, REST server and MCP server are Apache-2.0, and Cloud is closed (25 of 30). The privacy notice of 20 September 2026 gives retention by data type (account data deleted 30 days after termination, product usage 24 months, technical logs 30 days to 12 months, billing 10 years for the EU entity and 7 for the US one), and the security page names a data protection officer and deletes a tenant's whole database when it goes. The notice calls library telemetry anonymous, while the source sends a machine ID that survives reinstalls, the user and tenant UUIDs and an ID derived from the LLM key (22 of 30). On 1 May 2026 eleven MCP tools the README called \"still available\" the day before were removed in a fix commit, and there's no written deprecation policy (6 of 20). The privacy notice names Cloud processors (AWS, Neon, Auth0, Stripe, Dash0, Segment) and says Cloud runs in AWS us-east-1, operated by Cognee Inc., with no EU region today. The library's telemetry is on by default and disclosed there, with TELEMETRY_DISABLED as the opt-out, though the README doesn't mention it (16 of 20).",
        "blend": "editorial 69, provenance 65",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 85,
        "maxGain": 2.4,
        "reason": "A public OpenAPI 3.1 file at docs.cognee.ai/cognee_openapi_spec.json with 46 paths, Bearer and API key security schemes and 4xx error models, regenerated from the FastAPI app on each release. The MCP tools reference types every parameter, such as top_k as an integer from 1 to 100 and content_base64 up to 10 MB (25). llms.txt plus separate llms-mcp.md and llms-api.md indexes (10). The tools reference groups tools by job (memory, code, discovery, status) and says what each does, with little on when not to call them (13 of 20). Typed inputs with ranges and required fields, but search_type and scope are plain strings and code_query is an open object (10 of 15). Examples in the guides, error models in the OpenAPI file, and the billing docs name HTTP 402 for a low balance, but no error catalogue (12 of 15). Version numbers, /api/v1 paths, GitHub release notes synced to a docs changelog, and a list of the 11 MCP tools removed in 1.x (15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 82,
        "maxGain": 1.6,
        "reason": "cognee 1.6.2 on PyPI on 2026-09-29 (30). 1.5.0 to 1.6.2 is eight stable releases since 15 August (20). A maintainer replied within a day on issue #4673 and topped up the tenant, but the reporter's follow-up from 30 August has no answer and the issue is open (12 of 25). The official Python package is current, but it's the only language, and the registry API returns no cognee server in the official MCP registry (10 of 15). Dependabot, uv.lock and CI passing on main (10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Domain age",
        "value": "cognee.ai, no registry record we could read",
        "points": 0,
        "max": 15
      },
      {
        "label": "Status page",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "2026-05-01: a commit titled as a fix removed 11 MCP tools, including cognify, search, delete and prune, with cognee-mcp at 0.5.4 before and after, and the README the day before listed them as \"still available\" with no deprecation note. The replacements remember, recall and forget had shipped on 10 April and the tools reference now lists what went, so we deduct at the low end (https://github.com/topoteretes/cognee/commit/b52fcc335f6bfc090d1c892afa9c4e81909336fe)"
    ],
    "unchecked": [
      "unchecked: open crash and regression issues, since GitHub's issue search and label pages are closed to our reader. The local reliability score keeps 10 of 25 for this line on the strength of the #4673 handling.",
      "No rate limits or 429 guidance found for Cloud in the docs or the OpenAPI file.",
      "The privacy notice puts Cloud in AWS us-east-1 under Cognee Inc., while the security page and terms point to Topoteretes UG and German law. The listing's eu tag may mislead readers about data residency.",
      "The listing carried a -2 deduction for the August 2026 hang. A hang isn't a negative-event category in the brief, so we scored it under reliability and ergonomics. The -3 now in place is for the May 2026 MCP tool removal.",
      "Whether the HTTP 402 on low balance the billing docs describe is live, since #4673 has no maintainer confirmation."
    ],
    "weaknesses": [
      "No status page, rate limits, SLA or SOC 2 for Cloud, and Cloud runs in AWS us-east-1 with no EU region",
      "Cloud calls hung rather than failing when a tenant ran out of credit (August 2026), and the issue is still open",
      "Billing docs and pricing page disagree on plans and the free allowance",
      "Library telemetry is on by default and sends a persistent machine ID and an ID derived from the LLM key",
      "11 MCP tools were removed in May 2026 without a version bump or notice"
    ],
    "agentNotes": [
      "Use remember, recall and forget. The older cognify, search and delete MCP tools are gone",
      "Always include /api/v1 in REST paths",
      "Check cognify_status before querying data you added with background=true",
      "Never pass everything=true to forget unless you mean to wipe all of the user's memory",
      "Set a client timeout on Cloud calls and treat HTTP 402 as an empty balance, since an empty balance has also shown up as hangs"
    ],
    "requests": [
      {
        "text": "Catalogue the error codes",
        "reviews": 1
      },
      {
        "text": "Note removed tools in the old docs",
        "reviews": 1
      },
      {
        "text": "a read-only key",
        "reviews": 1
      },
      {
        "text": "auth on by default",
        "reviews": 1
      }
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
