Coda (Superhuman Docs)
by Superhuman Platform Inc. HTTP API in Spreadsheets & operational tables
Hosted
Superhuman Platform Inc. · coda.io since 2012 · status page · who's behind it
Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta.
Good for Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.
Is this your product? Claim this listing or verify it
Assessment. API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://coda.io/apis/v1- Auth
- OAuth or key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT
- Tools exposed
- 34
- Packages
npm@codahq/packs-sdk- llms.txt
- not found
- Last release
- npm / week
- 10k
- Surface graded
- REST API v1 (generally available, OpenAPI 1.6.0). The hosted MCP server is described alongside it and is in beta
- Tables
- List tables and columns, list rows with one
column:valuefilter, sort,limit,pageTokenandsyncToken, insert or upsert rows withkeyColumns, update one row, delete rows by ID, push a button column - Formulas
- REST reads named formulas and controls only. The MCP server adds formula columns through
table_columns_manageand evaluates Coda Formula Language withformula_execute - Consistency
- Writes return 202 and apply within a few seconds. Reads come from the latest snapshot, and
X-Coda-Doc-Version: latestreturns 400 when the snapshot is behind - Rate limits
- Per user across all docs. 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds, 4 doc listings per 6 seconds, 100 analytics reads per 6 seconds. Subject to change without notice
- Credentials
- Bearer API token, optionally restricted to one doc or one table and to read or write. MCP takes OAuth with PKCE and dynamic client registration (scope
mcp:all) or an API token with the MCP restriction - MCP server
- https://coda.io/apis/mcp, hosted, 34 tools, beta. Paid plans, with read-only access on Free capped at 30 requests a week. Batch sizes are 100 rows per add, 500 per delete, 20 columns per call
- Change events
- No outbound webhooks in the API.
syncTokenon row listings returns changes since an earlier call, andPOST /docs/{docId}/hooks/automation/{ruleId}triggers an automation inside a doc - Client libraries
- None official apart from a Google Apps Script library. The docs list six community libraries as unsupported. The Packs SDK (@codahq/packs-sdk 1.18.0, MIT) builds extensions and is not an API client
- Audit
- Audit APIs with 12 months of events for Enterprise workspaces, per the security page. Enterprise admins can control who may use API tokens with MCP
- Certifications
- ISO 27001, 27017 and 27018, SOC 2 Type 2 (report for enterprise customers), SOC 3, annual penetration test, public HackerOne bug bounty
- Status
- status.coda.io on Statuspage with API, Coda MCP, Docs, Doc Processing, Packs, Search and Login components. 99.9 per cent uptime commitment for Enterprise customers
- Sub-processors
- Published list covering Coda with each processor's purpose and country, all listed as USA, among them AWS, Anthropic, OpenAI, Azure and Google
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- API tokens can be restricted to one doc or one table, and to read or write access
- Public OpenAPI 3.0 description in JSON and YAML, 125 operations, all with descriptions and 429 documented on 124
- Rate limits are published with numbers, 100 reads and 10 writes per 6 seconds per user
- Hosted MCP server with 34 tools, OAuth with PKCE and dynamic client registration, and a dated changelog
- Public bug bounty on HackerOne, ISO 27001, 27017 and 27018 certificates, SOC 2 Type 2 and a SOC 3 report
Weaknesses
- Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale
- No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message
- No official client libraries apart from a Google Apps Script library
- The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped
- MCP OAuth has one scope,
mcp:all, and no confirmation step was found fordocument_deleteortable_delete - security.txt on coda.io expired on 31 December 2024
Before you call it notes for agents
- Poll
/mutationStatus/{requestId}after every row write. A 202 means queued, and the edit can still fail - Send
X-Coda-Doc-Version: latestwhen a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind - Use
keyColumnsonPOST .../rowsso a retried insert updates the same row instead of adding a duplicate - Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can
- Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta
Who's behind it provenance 90/100
- Legal entity namedSuperhuman Platform Inc. (parent of Coda Project LLC)20/20
- Domain agecoda.io, registered 2012-05-22 (14 years)15/15
- Endpoint on the vendor's domaincoda.io15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.coda.io10/10
- Changelogpublished10/10
- security.txtpublished but past its Expires date5/10
Terms and privacy, as read
Terms of service dated 2025-10-29, states 6 of 7, 4 to know
TL;DR Dated 2025-10-29. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, model training with no opt-out found, limits on benchmarking, cut-off without notice or for any reason and arbitration or a class action waiver.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Restricts benchmarking or competitive usecosts points
You also must not use our generative AI features i) in a way that infringes, violates, or misappropriates any of our rights or the rights of any third party, or ii) to develop foundation or large language models that compete with our Services.
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
We may terminate these Terms at any time without liability to you.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
AMONG OTHER THINGS, SECTION 12 INCLUDES AN AGREEMENT TO ARBITRATE (“ARBITRATION AGREEMENT”) WHICH REQUIRES, WITH LIMITED EXCEPTIONS, THAT ALL DISPUTES BETWEEN YOU AND US WILL BE RESOLVED BY BINDING AND FINAL ARBITRATION.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2025-10-29
Effective as of October 29, 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts Disputes go to the courts of San Francisco County, California
…request for relief will be severed from the arbitration and may be litigated in in the state or federal courts located in San Francisco County, California (but only after the arbitrator issues an award on the arbitrable claims and remedies).
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL SUPERHUMAN AND THE SUPERHUMAN ENTITIES' TOTAL AGGREGATE LIABILITY TO YOU UNDER THESE TERMS EXCEED THE AMOUNT THAT YOU HAVE PAID IN FEES TO SUPERHUMAN OR THE SUPERHUMAN ENTITIES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT(S) GIVING RI…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
As such, you acknowledge that the Organization may access, view, restrict, merge, or terminate your Account (each, an “Account Control Action”).
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
Superhuman will notify you of material changes to this Arbitration Agreement at least 30 days before they become effective.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Please note that once you delete your Account, you will not be able to reactivate it or retrieve any content or information associated with it.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Liability to a customer on a free subscription is capped at 100 US dollars, and otherwise at the fees paid in the preceding twelve months.
HOWEVER, IF THAT AMOUNT IS ZERO BECAUSE YOU HAVE A FREE SUBSCRIPTION, SUPERHUMAN AND THE SUPERHUMAN ENTITIES’ TOTAL AGGREGATE LIABILITY WILL NOT EXCEED ONE HUNDRED DOLLARS ($100).
Noted by a second reader on 2026-10-08.
The licence over user content lasts as long as intellectual property laws protect that content and extends to the vendor's service providers.
The above license lasts as long as intellectual property laws protect your User Content, and it also permits our service providers to assist us in performing these limited purposes.
Noted by a second reader on 2026-10-08.
On termination the vendor may delete user content from its live databases.
Upon termination of the Services or the applicable feature or functionality thereof, your right to use the Services or the applicable feature or functionality will automatically terminate, and we may delete User Content from our live databases.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 9,200 words
Privacy policy dated 2026-07-06, states 8 of 8, 2 to know
TL;DR Dated 2026-07-06. States all 8 things a reader expects. To know before relying on it, model training with an opt-out and selling or sharing data for advertising.
Says it may use customer content to train or improve models, and gives an opt-out
You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says it sells personal data or shares it for advertising
These activities–disclosing unique IDs and disclosing data through Cookies–may constitute “targeted advertising”, “sharing”, or “selling” under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-07-06
Effective as of July 6, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
The information we collect depends on how you use our products and how you manage your privacy settings.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain personal data for as long as necessary to provide our products to you, to complete the transactions you have requested, to comply with our legal obligations, to resolve disputes, and for other legitimate business purposes.
Says when data sent to the service is deleted.
Says who else receives the data
If you purchase our products through a third-party app store or payment processor, you may provide your payment information directly to those providers—not to us.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
These activities–disclosing unique IDs and disclosing data through Cookies–may constitute “targeted advertising”, “sharing”, or “selling” under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities.
A plain statement either way.
Says what rights people have over their data
You have the right not to be discriminated against for exercising any of your privacy rights.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@superhuman.com
You can unsubscribe from our marketing emails by following the instructions in those emails, adjusting the marketing communications preferences in your settings, or emailing us at privacy@superhuman.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
Data Privacy Framework, the UK Extension of the EU-U.S.
The countries data goes to and the safeguard used.
The policy does not cover content uploaded to or output from accounts managed by an organisation, which the organisation's contract governs.
This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization.
Noted by a second reader on 2026-10-08.
The vendor says it restricts its AI service providers from training their models on customers' user content.
For example, we restrict our AI service providers from training their models on user content of Superhuman customers.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,814 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (effective 29 October 2025) are an agreement with Superhuman Platform Inc., 2261 Market Street STE 85232, San Francisco, CA 94114, and call it the parent company of Coda Project LLC and Superhuman Labs LLC.
The privacy policy (effective 6 July 2026) describes Superhuman Platform Inc. as formerly Grammarly, with Grammarly Inc. and Coda Project LLC as subsidiaries.
coda.io/trust/tos, /trust/privacy, /trust/dpa and /trust/subprocessor redirect to superhuman.com/legal. coda.io/developers/apis/v1 redirects to docs.superhuman.com.
The API and the MCP server answer on coda.io and on docs.superhuman.com. The OAuth metadata names https://coda.io as issuer.
coda.io/.well-known/security.txt points to the HackerOne programme and carries Expires 2024-12-31. superhuman.com/.well-known/security.txt returns 404.
The registry's RDAP record for coda.io gives a registration date of 2012-05-22 and Gandi SAS as registrar.
The changelog link is the MCP server's. The REST API's update log at docs.superhuman.com/api-updates needs JavaScript and was not read.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://coda.io/apis/v1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- github
coda/packs-sdkv1.18.0, released 2026-10-07 - npm
@codahq/packs-sdk1.18.0 - GitHub stars 112
- npm downloads a week 10k
- security.txt expired, expires 2024-12-31T20:00:00.000Z · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/coda.json
Notable
- Coda was renamed Superhuman Docs on 8 July 2026. The terms name Superhuman Platform Inc. (formerly Grammarly) as the parent of Coda Project LLC source
- The API answers at both https://coda.io/apis/v1 and https://docs.superhuman.com/apis/v1, and the spec is version 1.6.0 with 125 operations, 60 of them for Packs source
- Limits per user are 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds and 4 doc listings per 6 seconds source
- Row inserts, updates and deletes return 202 with a
requestId, and status is kept for about a day at/mutationStatus/{requestId}source - The MCP server lists 34 tools for search, documents, pages, tables, content, comments and formulas, and its vendor page says tool names can change during the beta source
- The MCP changelog's 24 September 2026 entries rename chart layout values and restructure
table_columns_manage, marked as documented after shipping source - The API docs promise three months' notice before older APIs or functions are removed source
- A staff reply on 27 March 2026 attributed a day of API timeouts and 504 errors to reduced memory on the API servers. status.coda.io lists no incident for that date source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 16.2 | |
Graded on the hosted REST API, with the MCP server noted, using the hosted lines. Statuspage site at status.coda.io with API, Coda MCP, Docs, Doc Processing and Login among its components (20). Three incidents since 10 July 2026. Access to coda.io was affected for 4 hours 19 minutes on 16 July during a CloudFront outage (minor), docs were slow for 38 minutes on 29 July (marked major), and the coda.new shortcut was down on 13 and 14 August (minor). None was an hour or more of the API down (20). Limits are published per user, 100 reads and 10 writes per 6 seconds (15). The docs tell scripts to back off and retry on 429 and upserts take keyColumns, but no Retry-After header or idempotency key is documented (9). The trust page states a 99.9 per cent uptime commitment for Enterprise customers (10). The REST API is generally available and the MCP server is in beta (7). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.3 | |
Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. MCP tool schemas need a signed-in session and were not read (25). No llms.txt on coda.io, docs.superhuman.com or superhuman.com, all 404, and no Markdown docs found (0). All 125 operations carry descriptions, with guidance such as preferring IDs over names, and the vendor's MCP page gives each of 34 tools a purpose, use cases and key parameters (15). 411 schemas and 175 enums with additionalProperties: false on request bodies. Cell values are loosely typed (13). 651 examples, code samples in Python, shell and Google Apps Script, and 429 documented on 124 operations. Error bodies are generic (13). The API is versioned at v1 with a three-month removal notice, and the MCP server has a dated changelog. The REST update log needs JavaScript and was not read, which is our limitation (10). | |||
| Agent ergonomics | 13%16.2 | 9.9 | |
Row listings take limit (default 25), visibleOnly and three valueFormat levels, with no column selection on REST. The MCP server has 34 tools, columnsToInclude on row reads and a tool_guide tool that loads guidance by topic (15). pageToken paging, sortBy, syncToken for changes since an earlier call, and a query filter limited to one column and value (17). Errors return statusCode, statusMessage and message with no machine codes beyond the HTTP status (12). Upserts by keyColumns and /mutationStatus/{requestId} allow safe retries. No idempotency keys, writes are asynchronous with 202, and MCP annotations were unchecked (10). Few required parameters and sensible defaults. No official client libraries apart from Google Apps Script (7). | |||
| Security & auth | 14%17.5 | 12.4 | |
API tokens can be restricted to one doc or one table and to read or write. Unrestricted tokens carry all of the owner's access, and the docs say a token can't be viewed or changed after creation. MCP uses OAuth with PKCE S256 and dynamic client registration but one scope, mcp:all (26). Read-only tokens per doc or table, read-only MCP on the Free plan, and page locking enforced on MCP writes. The MCP product page says read-only and write-only controls are coming soon, and no confirmation step was found for document_delete or table_delete (13). The vendor has a help centre article titled Security recommendations for the Coda MCP, which a bot check stopped us reading, so only its existence is counted (4). Audit APIs with 12 months of events for Enterprise workspaces, and admin control over API tokens used with MCP (10). Public HackerOne bug bounty, ISO 27001, 27017 and 27018, SOC 2 Type 2, SOC 3 and annual penetration tests. security.txt expired on 31 December 2024 (18). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices are public per member a month, shown to us in pounds (Pro £10, Business £28 billed yearly), with nothing per call, and the API itself is free (10). A Free plan exists and the API works on free workspaces. No card requirement was found (20). A person signs up in a browser and creates a token or approves OAuth (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.3 | |
| The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). The MCP changelog has nine dated entries in July and three in September (20). Staff answer on the developer forum within a day in the threads we read, and the MCP server has a public changelog (12). No vendor entry in the official MCP registry, where a search for coda and superhuman returned only community servers, and no official API client libraries. The Packs SDK is current (4). Packs SDK CI and dependency updates are public, but it is not the API surface (6). | |||
| Transparency & trusteditorial 65, provenance 90 | 7%8.8 | 6.8 | |
| Closed service with published terms, developer terms and an MIT Packs SDK (15). Privacy policy effective 6 July 2026, DPA effective 8 July 2026 and a sub-processor list. Retention is stated as as long as necessary with no periods, user content can be used to train the vendor's AI models subject to an account setting whose default we did not establish, and enterprise customers sit under a separate agreement (19). The API docs promise three months' notice before removals and the developer terms 30 days before term changes. MCP tools changed in September 2026 with no advance notice (14). Sub-processors are listed with purpose and country, all USA (17). | |||
| Negative events | ≤15 |
| -3 |
| Total | 64.8 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Coda (Superhuman Docs), or have the agent fetch /fixes/coda.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Coda (Superhuman Docs)
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/coda, the October 2026 research run, assessed 8 October 2026. Grade B, 64.8 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Coda (Superhuman Docs): work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total
Why it scored 30: No x402, MPP or L402 (0). Plan prices are public per member a month, shown to us in pounds (Pro £10, Business £28 billed yearly), with nothing per call, and the API itself is free (10). A Free plan exists and the API works on free workspaces. No card requirement was found (20). A person signs up in a browser and creates a token or approves OAuth (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Agent ergonomics, 61 out of 100, up to 6.3 more on the total
Why it scored 61: Row listings take `limit` (default 25), `visibleOnly` and three `valueFormat` levels, with no column selection on REST. The MCP server has 34 tools, `columnsToInclude` on row reads and a `tool_guide` tool that loads guidance by topic (15). `pageToken` paging, `sortBy`, `syncToken` for changes since an earlier call, and a `query` filter limited to one column and value (17). Errors return `statusCode`, `statusMessage` and `message` with no machine codes beyond the HTTP status (12). Upserts by `keyColumns` and `/mutationStatus/{requestId}` allow safe retries. No idempotency keys, writes are asynchronous with 202, and MCP annotations were unchecked (10). Few required parameters and sensible defaults. No official client libraries apart from Google Apps Script (7).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 3. Security & auth, 71 out of 100, up to 5.1 more on the total
Why it scored 71: API tokens can be restricted to one doc or one table and to read or write. Unrestricted tokens carry all of the owner's access, and the docs say a token can't be viewed or changed after creation. MCP uses OAuth with PKCE S256 and dynamic client registration but one scope, `mcp:all` (26). Read-only tokens per doc or table, read-only MCP on the Free plan, and page locking enforced on MCP writes. The MCP product page says read-only and write-only controls are coming soon, and no confirmation step was found for `document_delete` or `table_delete` (13). The vendor has a help centre article titled Security recommendations for the Coda MCP, which a bot check stopped us reading, so only its existence is counted (4). Audit APIs with 12 months of events for Enterprise workspaces, and admin control over API tokens used with MCP (10). Public HackerOne bug bounty, ISO 27001, 27017 and 27018, SOC 2 Type 2, SOC 3 and annual penetration tests. security.txt expired on 31 December 2024 (18).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 4. Schema & documentation, 76 out of 100, up to 3.9 more on the total
Why it scored 76: Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. MCP tool schemas need a signed-in session and were not read (25). No llms.txt on coda.io, docs.superhuman.com or superhuman.com, all 404, and no Markdown docs found (0). All 125 operations carry descriptions, with guidance such as preferring IDs over names, and the vendor's MCP page gives each of 34 tools a purpose, use cases and key parameters (15). 411 schemas and 175 enums with `additionalProperties: false` on request bodies. Cell values are loosely typed (13). 651 examples, code samples in Python, shell and Google Apps Script, and 429 documented on 124 operations. Error bodies are generic (13). The API is versioned at v1 with a three-month removal notice, and the MCP server has a dated changelog. The REST update log needs JavaScript and was not read, which is our limitation (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 5. Reliability, 81 out of 100, up to 3.8 more on the total
Why it scored 81: Graded on the hosted REST API, with the MCP server noted, using the hosted lines. Statuspage site at status.coda.io with API, Coda MCP, Docs, Doc Processing and Login among its components (20). Three incidents since 10 July 2026. Access to coda.io was affected for 4 hours 19 minutes on 16 July during a CloudFront outage (minor), docs were slow for 38 minutes on 29 July (marked major), and the coda.new shortcut was down on 13 and 14 August (minor). None was an hour or more of the API down (20). Limits are published per user, 100 reads and 10 writes per 6 seconds (15). The docs tell scripts to back off and retry on 429 and upserts take `keyColumns`, but no Retry-After header or idempotency key is documented (9). The trust page states a 99.9 per cent uptime commitment for Enterprise customers (10). The REST API is generally available and the MCP server is in beta (7).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 6. Maintenance & community, 72 out of 100, up to 2.5 more on the total
Why it scored 72: The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). The MCP changelog has nine dated entries in July and three in September (20). Staff answer on the developer forum within a day in the threads we read, and the MCP server has a public changelog (12). No vendor entry in the official MCP registry, where a search for coda and superhuman returned only community servers, and no official API client libraries. The Packs SDK is current (4). Packs SDK CI and dependency updates are public, but it is not the API surface (6).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 7. Transparency & trust, 78 out of 100, up to 1.9 more on the total
Made of editorial 65, provenance 90.
Why it scored 78: Closed service with published terms, developer terms and an MIT Packs SDK (15). Privacy policy effective 6 July 2026, DPA effective 8 July 2026 and a sub-processor list. Retention is stated as as long as necessary with no periods, user content can be used to train the vendor's AI models subject to an account setting whose default we did not establish, and enterprise customers sit under a separate agreement (19). The API docs promise three months' notice before removals and the developer terms 30 days before term changes. MCP tools changed in September 2026 with no advance notice (14). Sub-processors are listed with purpose and country, all USA (17).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- security.txt: published but past its Expires date (5 of 10)
## Deductions
Each comes off the total. A fixed and documented problem counts for less at the next check.
- 24 September 2026 (date approximate per the vendor). The MCP changelog records chart `viewLayout` values renamed so the old ones are no longer valid, and `table_columns_manage` restructured, both marked as documented after shipping. The MCP server is in beta and its tools page warns that names can change, so the deduction is the minimum, 3 (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3).
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: help.superhuman.com answers with a bot check, so the MCP connection guide and the article Security recommendations for the Coda MCP were not read. Supported clients, admin controls and injection guidance may be better than scored
- unchecked: the REST API update log at docs.superhuman.com/api-updates needs JavaScript, so the date of the last REST API change is unknown. lastRelease uses the MCP changelog date of 24 September 2026
- unchecked: the Docs plan table at superhuman.com/plans/docs renders in the browser only. Prices come from superhuman.com/plans as shown in pounds to a UK request, and US dollar prices were not seen
- unchecked: MCP tool input schemas and annotations, which need a signed-in session
- Whether user content is used for AI training by default was not established. The privacy policy says an account setting controls it
- Whether the Free plan needs a card at signup was not tested. No requirement is stated on the pages read
- The MCP guides call the server available to everyone while the tools page still calls it beta. We treated it as beta
- API timeouts on 26 March 2026 were confirmed by staff on the forum but are missing from status.coda.io. Not deducted, since the rubric has no line for it
## Weaknesses
- Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale
- No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message
- No official client libraries apart from a Google Apps Script library
- The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped
- MCP OAuth has one scope, `mcp:all`, and no confirmation step was found for `document_delete` or `table_delete`
- security.txt on coda.io expired on 31 December 2024
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail
- Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind
- Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate
- Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can
- Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: help.superhuman.com answers with a bot check, so the MCP connection guide and the article Security recommendations for the Coda MCP were not read. Supported clients, admin controls and injection guidance may be better than scored
- unchecked: the REST API update log at docs.superhuman.com/api-updates needs JavaScript, so the date of the last REST API change is unknown. lastRelease uses the MCP changelog date of 24 September 2026
- unchecked: the Docs plan table at superhuman.com/plans/docs renders in the browser only. Prices come from superhuman.com/plans as shown in pounds to a UK request, and US dollar prices were not seen
- unchecked: MCP tool input schemas and annotations, which need a signed-in session
- Whether user content is used for AI training by default was not established. The privacy policy says an account setting controls it
- Whether the Free plan needs a card at signup was not tested. No requirement is stated on the pages read
- The MCP guides call the server available to everyone while the tools page still calls it beta. We treated it as beta
- API timeouts on 26 March 2026 were confirmed by staff on the forum but are missing from status.coda.io. Not deducted, since the rubric has no line for it
Sources 25
- API reference, rate limits, consistency and deprecation notice coda.io · seen 2026-10-08
- OpenAPI description, version 1.6.0 coda.io · seen 2026-10-08
- MCP tools and endpoints coda.io · seen 2026-10-08
- MCP changelog docs.superhuman.com · seen 2026-10-08
- MCP OAuth resource metadata coda.io · seen 2026-10-08
- OAuth authorisation server metadata coda.io · seen 2026-10-08
- Docs MCP product page, plans and limits superhuman.com · seen 2026-10-08
- MCP getting started guide coda.io · seen 2026-10-08
- status incidents status.coda.io · seen 2026-10-08
- status components status.coda.io · seen 2026-10-08
- plans and prices superhuman.com · seen 2026-10-08
- trust centre, uptime commitment coda.io · seen 2026-10-08
- security and compliance coda.io · seen 2026-10-08
- security.txt coda.io · seen 2026-10-08
- terms of service superhuman.com · seen 2026-10-08
- privacy policy superhuman.com · seen 2026-10-08
- data privacy addendum superhuman.com · seen 2026-10-08
- sub-processors superhuman.com · seen 2026-10-08
- developer terms coda.io · seen 2026-10-08
- rename announcement blog.superhuman.com · seen 2026-10-08
- forum thread, MCP auth for server-side agents (staff reply) connect.superhuman.com · seen 2026-10-08
- forum thread, API timeouts in March 2026 (staff reply) connect.superhuman.com · seen 2026-10-08
- Packs SDK repository and changelog github.com · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- RDAP for coda.io rdap.identitydigital.services · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium Freemium The API is free on free and paid workspaces, so an agent can start on the Free plan without a contract. Suite prices as shown to our UK request on 8 October 2026 were Free £0, Pro £10 a member a month billed yearly (£12 monthly), Business £28 (£33 monthly) and Enterprise by quote (https://superhuman.com/plans). MCP is included on paid plans, and Free accounts get read-only MCP access capped at 30 requests a week and 60 a month. US dollar prices and the Docs-only plan table were not readable.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/coda.xml, or this listing's score history at history.json.
Connect
First request
curl -s -H "Authorization: Bearer $CODA_API_TOKEN" "https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25&valueFormat=simpleWithArrays"
MCP client configuration
{
"mcpServers": {
"coda": {
"url": "https://coda.io/apis/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/coda
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Airtable BBGoogle Sheets API BBSmartsheet API + MCP BMicrosoft Excel (Microsoft Graph workbook API) CGoogle Drive API + MCP Amonday.com BB
Head to head Coda (Superhuman Docs) vs Google Sheets API · Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API) · Coda (Superhuman Docs) vs Smartsheet API + MCP · Airtable vs Coda (Superhuman Docs)
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Airtable Formagrid Inc (Airtable) | BB | 70.9 | sheets.records sheets.read sheets.write sheets.tables sheets.formulas | no |
| Google Sheets API Google | BB | 76.3 | sheets.read sheets.write sheets.formulas sheets.tables | no |
| Smartsheet API + MCP Smartsheet Inc. | B | 67.6 | sheets.read sheets.write sheets.records sheets.formulas | no |
| Microsoft Excel (Microsoft Graph workbook API) Microsoft | C | 58.5 | sheets.read sheets.write sheets.tables sheets.formulas | no |
| Google Drive API + MCP Google | A | 79.6 | work.docs | no |
| monday.com monday.com Ltd. | BB | 76.4 | work.docs | no |
Machine-readable
- JSON
/api/v1/tools/coda.json· historyhistory.json· badge/badges/coda.svg· changes feed/feeds/tools/coda.xml - Markdown
/tools/coda.md· slim/tools/coda.min.md(or sendAccept: text/markdown) - Fix list
/fixes/coda.md·/fixes/coda.json - From a terminal
anchor tool coda --md(the CLI) · over MCPget_tool {"slug": "coda"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/coda"><img src="https://www.anchorterminal.com/badges/coda.svg" alt="Coda (Superhuman Docs) on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/coda)<a href="https://www.anchorterminal.com/tools/coda">Coda (Superhuman Docs) on Anchor Terminal</a>It counts on a page on coda.io or one of its subdomains, or the README of github.com/coda/packs-sdk.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "coda", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
