{
  "fixes": {
    "slug": "semrush",
    "name": "Semrush API + MCP",
    "listing": "https://www.anchorterminal.com/tools/semrush",
    "markdown": "# Fix list: Semrush API + MCP\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/semrush, the October 2026 research run, assessed 8 October 2026. Grade D, 53.1 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Semrush API + MCP: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Reliability, 34 out of 100, up to 13.2 more on the total\n\nWhy it scored 34: Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 2. Payments \u0026 pricing, 17 out of 100, up to 10.4 more on the total\n\nWhy it scored 17: No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Security \u0026 auth, 54 out of 100, up to 8.1 more on the total\n\nWhy it scored 54: Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 4. Schema \u0026 documentation, 70 out of 100, up to 4.9 more on the total\n\nWhy it scored 70: No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 5. Maintenance \u0026 community, 57 out of 100, up to 3.8 more on the total\n\nWhy it scored 57: The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## 6. Agent ergonomics, 77 out of 100, up to 3.7 more on the total\n\nWhy it scored 77: The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 7. Transparency \u0026 trust, 67 out of 100, up to 2.9 more on the total\n\nMade of editorial 59, provenance 75.\n\nWhy it scored 67: Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59.\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)\n- Status page: not found (0 of 10)\n- security.txt: not found (0 of 10)\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account\n- unchecked: prices of API unit packages and of the Trends API, which the public pages don't show\n- unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty\n- unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access\n- unchecked: the HackerOne programme page, which needs JavaScript\n- No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points\n- The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both\n- Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition\n\n## Weaknesses\n\n- Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked\n- Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change\n- No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages\n- API unit package prices aren't published, and every API needs a paid subscription\n- When units run short, per-line SEO and Trends reports return fewer lines instead of an error\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report`\n- Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50\n- Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error\n- Send the version 4 key as `Authorization: Apikey \u003ckey\u003e`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs\n- Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "D",
    "score": 53.1,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 34,
        "maxGain": 13.2,
        "reason": "Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34.",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 17,
        "maxGain": 10.4,
        "reason": "No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17.",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 54,
        "maxGain": 8.1,
        "reason": "Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54.",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 70,
        "maxGain": 4.9,
        "reason": "No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70.",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 57,
        "maxGain": 3.8,
        "reason": "The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57.",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 77,
        "maxGain": 3.7,
        "reason": "The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77.",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 67,
        "maxGain": 2.9,
        "reason": "Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59.",
        "blend": "editorial 59, provenance 75",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      }
    ],
    "provenance": [
      {
        "label": "Terms of service",
        "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
        "points": 5.1,
        "max": 10
      },
      {
        "label": "Status page",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account",
      "unchecked: prices of API unit packages and of the Trends API, which the public pages don't show",
      "unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty",
      "unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access",
      "unchecked: the HackerOne programme page, which needs JavaScript",
      "No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points",
      "The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both",
      "Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition"
    ],
    "weaknesses": [
      "Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked",
      "Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change",
      "No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages",
      "API unit package prices aren't published, and every API needs a paid subscription",
      "When units run short, per-line SEO and Trends reports return fewer lines instead of an error"
    ],
    "agentNotes": [
      "Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report`",
      "Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50",
      "Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error",
      "Send the version 4 key as `Authorization: Apikey \u003ckey\u003e`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs",
      "Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
