# Fix list: meteoblue Weather API From Anchor Terminal's listing at https://www.anchorterminal.com/tools/meteoblue, the October 2026 research run, assessed 8 October 2026. Grade C, 61.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on meteoblue Weather API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 51 out of 100, up to 8.6 more on the total Why it scored 51: An account can hold several named keys, each deletable, each with a daily credit limit, an optional IP allow list, a referrer and origin allow list, and an optional shared secret that makes every URL carry an HMAC-SHA256 signature and an expiry. There are no scopes. The key is accepted only as the `apikey` query parameter (25 less 10, 15 of 30). All data is read-only, and package access follows the plan (16 of 20). Warning text is relayed from national authorities and place names from GeoNames. The rest is numeric (10 of 15). `/account/usage` returns request counts and credits per day and type, the key manager charts each key, and each response carries `MB-Credits-Accounted`. No per-call log was found (8 of 15). security.txt returns 404 on four hosts, and no disclosure policy, bounty, SOC 2 or ISO 27001 was found. The ISO 9001:2015 certificate covers quality management (2 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 34 out of 100, up to 8.3 more on the total Why it scored 34: No x402, MPP or L402 in the docs, the specs or the pricing page (0). Credits per package are published in the spec without a login, and the pricing page shows EUR 2,400 a year for 40,000 calls a month on the Premium Weather API. The price of a prepaid credit top-up is shown only inside the account, and larger tiers go through an enquiry form (14 of 20). The Free Weather API gives 10 million credits for one year from a free account with no purchase obligation stated. We did not sign up to confirm that no card is asked for (20). A person registers in a browser to get a key (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Agent ergonomics, 66 out of 100, up to 5.5 more on the total Why it scored 66: This is an API with no MCP server from the vendor. A caller sizes the response by choosing packages and a resolution and by setting `forecastDays` and `historyDays`. There is no field selection, and `basic-1h` returns 15 fields for each of 168 hours (16 of 25). The History API takes a time range, resolution and one of 14 aggregations, the Accounting API pages with `page` and `per`, and forecasts need no pagination (14 of 20). Errors are JSON with `error` and `error_message` under 400, 401, 403, 404 and 429, with no machine-readable code. A call with no key returned 400 with a message naming the missing parameter (12 of 20). Every endpoint is a read-only GET, and retry guidance is published. Whether a failed call is charged credits is not stated (16 of 20). Only `lat`, `lon` and `apikey` are required, and elevation and time zone are detected. One official SDK, `meteoblue-dataset-sdk` for Python, covers the Dataset API only and dates from January 2025 (8 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Reliability, 75 out of 100, up to 5 more on the total Why it scored 75: Graded as a hosted service. Status page at status.meteoblue.com, a Pingdom public report with 15 monitors, one-minute checks and monthly history back to July 2024 for the Forecast API. It is served over http only (20). In the 90 days to 8 October 2026 the Forecast API monitor shows one outage of 2 minutes on 15 September. The History API monitor shows 1 hour 26 minutes on 1 September, and the Warnings, Dataset, Image and Location Search monitors show outages of 1 to 17 minutes. We scored between minor only and one major, because the long outage was on the History API and not the forecast endpoint (15 of 30). 500 calls a minute and daily credit limits per account and key are documented (15). 429 is in every spec, and the availability page advises a 30-second timeout, a 30-second wait and at most 10 retries. No Retry-After header is documented. Every call is a GET (12 of 15). Custom SLAs are listed for enterprise plans with no published figure or credits. The vendor publishes its own yearly availability, 99.95 per cent for 2025, as a record and not a commitment (3 of 10). The Forecast API is generally available as version 2.0.0 (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 5. Maintenance & community, 57 out of 100, up to 3.8 more on the total Why it scored 57: The latest dated changelog entry is 22 August 2026, 47 days before this check. Docs pages were edited after that, the Model-Run Archive API page on 2 October and the History and Accounting pages on 9 September (20 of 30). Three changelog entries fall in the last 90 days, two on 29 July and one on 22 August (20). A public changelog, a community forum that the status page monitors, and email support for self-serve users, none of which we tested (9 of 15). The only official SDK, `meteoblue-dataset-sdk` 1.3.5, was last released on 10 January 2025 and covers one API (4 of 15). Its repository has test and publish workflows and a last commit on 19 February 2025 (4 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Schema & documentation, 77 out of 100, up to 3.7 more on the total Why it scored 77: OpenAPI 3.1 specs at `openapi.json` beside each ReDoc page, for the Forecast (54 paths), History, Accounting, Model-Run Archive, Dataset, Image, Warnings and Measurements APIs (25). business.meteoblue.com/llms.txt is a product index that links the docs. docs.meteoblue.com/llms.txt returns 404 and no Markdown docs were found (4 of 10). Package descriptions run long and say what each holds, which packages cannot be combined and when `raw` should not be set. They say less on choosing between similar packages (16 of 20). Coordinates carry minimum and maximum, units, formats, time formats and model domains are enums with defaults, and the History API marks five parameters required. The package path parameter is a comma-joined array (13 of 15). Samples in JavaScript, Python, shell and Java, and typed response fields with example values. Every error status shares one schema with a free-text `error_message` (10 of 15). Specs carry a version number, 2.0.0 for forecasts, with none in the path. The public changelog has 19 dated entries, mostly data additions (9 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Transparency & trust, 61 out of 100, up to 3.4 more on the total Made of editorial 35, provenance 87. Why it scored 61: Closed service under general terms last revised on 24 May 2018. They grant a non-commercial licence for open and registered access and leave commercial terms to a written agreement, while the Free Weather API table marks commercial use as allowed. The Python SDK is MIT (12 of 30). The privacy policy, last revised 15 May 2024, covers the API by name. It gives no retention period beyond as long as necessary, and no DPA was found (12 of 30). No deprecation policy was found. The terms let meteoblue change or revoke them at any time, and the changelog records removals after the fact, such as two COSMO models on 11 August 2025 (4 of 20). The policy names Google and Microsoft Clarity for the website and lists other contractors by category. The docs name Datatrans for payments, and the API answers through Cloudflare. No subprocessor list or stated data location for API logs was found (7 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the price of prepaid credits. It is shown inside the account after login, so `unitPrices` is empty. Public plan prices are in euros only - unchecked: whether the Free Weather API signup asks for a card. The docs say the account is free with no purchase obligation, and we did not register - The lead said keys come by request. A self-serve account now issues a Free Weather API key, though the docs overview still says to email support for a trial key and the pricing FAQ says trials are arranged by sales - The pricing page draws tier prices by script. We read 200, 400 and 800 from the markup as euros a month for the three Premium Weather API tiers, and only EUR 2,400 a year was displayed - The terms grant registered users a non-commercial licence, while the Free Weather API comparison table marks commercial use as allowed. Which applies to a free key is not settled by the documents - Whether the API accepts the key in a header, and whether failed or rate-limited calls are charged credits. Neither is documented - The spec names the parameters `forecastDays` and `historyDays`, and the docs FAQ writes `history_days`. We did not test which the API accepts - The spec lists 401 for a missing key, and our call without a key returned 400 - Whether the History API outage of 1 September 2026 affected customers or only the Pingdom check. The status page has no incident notes - No vendor MCP server was found. `mcp-meteoblue` on npm is published by a third party ## Weaknesses - The key is accepted only as the `apikey` query parameter, so it appears in URLs and logs unless request signing is switched on - The free trial covers nine forecast packages at hourly or coarser steps. Current conditions, sea, history, warnings and the Dataset API need a paid plan - No security.txt, disclosure policy, SOC 2 or ISO 27001 was found. The only certificate published is ISO 9001:2015 - The general terms date from 24 May 2018, give no API-specific clauses and let meteoblue change or revoke them at any time - The History API monitor shows an outage of 1 hour 26 minutes on 1 September 2026, and the status page is served over plain http only ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Pass `lat`, `lon` and `apikey` to `https://my.meteoblue.com/packages/`. Join packages with commas, such as `basic-1h,basic-day`, to get several in one call - Budget credits before calling. One call costs 4,000 to 96,000 credits by package, and the free trial holds 10 million for a year. Read `MB-Credits-Accounted` on each response - Set `forecastDays` and pick the coarsest resolution that does the job. Without it the API returns every forecast day it has - Call with a 30-second timeout, wait 30 seconds after an error and stop after 10 retries, as the availability page advises. The default limit is 500 calls a minute - Keep the key out of logs, since it is part of every URL. Ask for a shared secret and send `expire` and `sig` if URLs may be seen by others ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.