{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/nocodb.json",
        "name": "NocoDB",
        "score": 75.7,
        "shared": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "nocodb"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/airtable.json",
        "name": "Airtable",
        "score": 70.9,
        "shared": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "airtable"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/baserow.json",
        "name": "Baserow",
        "score": 63.6,
        "shared": [
          "sheets.records",
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "baserow"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-sheets-api.json",
        "name": "Google Sheets API",
        "score": 76.3,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.formulas",
          "sheets.tables"
        ],
        "slug": "google-sheets-api"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/smartsheet.json",
        "name": "Smartsheet API + MCP",
        "score": 67.6,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.records",
          "sheets.formulas"
        ],
        "slug": "smartsheet"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/microsoft-excel-graph.json",
        "name": "Microsoft Excel (Microsoft Graph workbook API)",
        "score": 58.5,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "microsoft-excel-graph"
      }
    ],
    "tool": {
      "slug": "coda",
      "name": "Coda (Superhuman Docs)",
      "vendor": "Superhuman Platform Inc.",
      "vendorUrl": "https://coda.io",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta.",
      "url": "https://www.anchorterminal.com/tools/coda",
      "markdownUrl": "https://www.anchorterminal.com/tools/coda.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/coda.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/coda.json",
      "repo": "https://github.com/coda/packs-sdk",
      "license": "Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://coda.io/apis/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@codahq/packs-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes `Authorization: Bearer \u003capi_token\u003e`, a token a signed-in user creates under account settings. A token can do everything its owner can unless it is created with restrictions, which limit it to one doc or one table and to read, write or both. The MCP server at https://coda.io/apis/mcp takes OAuth (authorisation code grant with PKCE S256, dynamic client registration, one scope `mcp:all`) or an API token created with the MCP restriction, per a staff reply on the vendor's community forum. Access is self-serve with no app review.",
      "pricing": "freemium",
      "pricingNotes": "The API is free on free and paid workspaces, so an agent can start on the Free plan without a contract. Suite prices as shown to our UK request on 8 October 2026 were Free £0, Pro £10 a member a month billed yearly (£12 monthly), Business £28 (£33 monthly) and Enterprise by quote (https://superhuman.com/plans). MCP is included on paid plans, and Free accounts get read-only MCP access capped at 30 requests a week and 60 a month. US dollar prices and the Docs-only plan table were not readable.",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI description or the plans page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 10270,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://coda.io/developers/apis/v1",
      "openapi": "https://coda.io/apis/v1/openapi.json",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.records",
        "sheets.formulas",
        "work.docs"
      ],
      "tags": [
        "official",
        "hosted",
        "closed-source",
        "freemium",
        "free-tier",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "status-page",
        "bug-bounty",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 247,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 72,
          "payments": 30,
          "reliability": 81,
          "schema": 76,
          "security": 71,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 81,
            "points": 16.2,
            "reason": "Graded on the hosted REST API, with the MCP server noted, using the hosted lines. Statuspage site at status.coda.io with API, Coda MCP, Docs, Doc Processing and Login among its components (20). Three incidents since 10 July 2026. Access to coda.io was affected for 4 hours 19 minutes on 16 July during a CloudFront outage (minor), docs were slow for 38 minutes on 29 July (marked major), and the coda.new shortcut was down on 13 and 14 August (minor). None was an hour or more of the API down (20). Limits are published per user, 100 reads and 10 writes per 6 seconds (15). The docs tell scripts to back off and retry on 429 and upserts take `keyColumns`, but no Retry-After header or idempotency key is documented (9). The trust page states a 99.9 per cent uptime commitment for Enterprise customers (10). The REST API is generally available and the MCP server is in beta (7)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. MCP tool schemas need a signed-in session and were not read (25). No llms.txt on coda.io, docs.superhuman.com or superhuman.com, all 404, and no Markdown docs found (0). All 125 operations carry descriptions, with guidance such as preferring IDs over names, and the vendor's MCP page gives each of 34 tools a purpose, use cases and key parameters (15). 411 schemas and 175 enums with `additionalProperties: false` on request bodies. Cell values are loosely typed (13). 651 examples, code samples in Python, shell and Google Apps Script, and 429 documented on 124 operations. Error bodies are generic (13). The API is versioned at v1 with a three-month removal notice, and the MCP server has a dated changelog. The REST update log needs JavaScript and was not read, which is our limitation (10)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 61,
            "points": 9.91,
            "reason": "Row listings take `limit` (default 25), `visibleOnly` and three `valueFormat` levels, with no column selection on REST. The MCP server has 34 tools, `columnsToInclude` on row reads and a `tool_guide` tool that loads guidance by topic (15). `pageToken` paging, `sortBy`, `syncToken` for changes since an earlier call, and a `query` filter limited to one column and value (17). Errors return `statusCode`, `statusMessage` and `message` with no machine codes beyond the HTTP status (12). Upserts by `keyColumns` and `/mutationStatus/{requestId}` allow safe retries. No idempotency keys, writes are asynchronous with 202, and MCP annotations were unchecked (10). Few required parameters and sensible defaults. No official client libraries apart from Google Apps Script (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 71,
            "points": 12.43,
            "reason": "API tokens can be restricted to one doc or one table and to read or write. Unrestricted tokens carry all of the owner's access, and the docs say a token can't be viewed or changed after creation. MCP uses OAuth with PKCE S256 and dynamic client registration but one scope, `mcp:all` (26). Read-only tokens per doc or table, read-only MCP on the Free plan, and page locking enforced on MCP writes. The MCP product page says read-only and write-only controls are coming soon, and no confirmation step was found for `document_delete` or `table_delete` (13). The vendor has a help centre article titled Security recommendations for the Coda MCP, which a bot check stopped us reading, so only its existence is counted (4). Audit APIs with 12 months of events for Enterprise workspaces, and admin control over API tokens used with MCP (10). Public HackerOne bug bounty, ISO 27001, 27017 and 27018, SOC 2 Type 2, SOC 3 and annual penetration tests. security.txt expired on 31 December 2024 (18)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Plan prices are public per member a month, shown to us in pounds (Pro £10, Business £28 billed yearly), with nothing per call, and the API itself is free (10). A Free plan exists and the API works on free workspaces. No card requirement was found (20). A person signs up in a browser and creates a token or approves OAuth (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "reason": "The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). The MCP changelog has nine dated entries in July and three in September (20). Staff answer on the developer forum within a day in the threads we read, and the MCP server has a public changelog (12). No vendor entry in the official MCP registry, where a search for coda and superhuman returned only community servers, and no official API client libraries. The Packs SDK is current (4). Packs SDK CI and dependency updates are public, but it is not the API surface (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 78,
            "points": 6.83,
            "note": "editorial 65, provenance 90",
            "reason": "Closed service with published terms, developer terms and an MIT Packs SDK (15). Privacy policy effective 6 July 2026, DPA effective 8 July 2026 and a sub-processor list. Retention is stated as as long as necessary with no periods, user content can be used to train the vendor's AI models subject to an account setting whose default we did not establish, and enterprise customers sit under a separate agreement (19). The API docs promise three months' notice before removals and the developer terms 30 days before term changes. MCP tools changed in September 2026 with no advance notice (14). Sub-processors are listed with purpose and country, all USA (17)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Row listings take `limit` (default 25), `visibleOnly` and three `valueFormat` levels, with no column selection on REST. The MCP server has 34 tools, `columnsToInclude` on row reads and a `tool_guide` tool that loads guidance by topic (15). `pageToken` paging, `sortBy`, `syncToken` for changes since an earlier call, and a `query` filter limited to one column and value (17). Errors return `statusCode`, `statusMessage` and `message` with no machine codes beyond the HTTP status (12). Upserts by `keyColumns` and `/mutationStatus/{requestId}` allow safe retries. No idempotency keys, writes are asynchronous with 202, and MCP annotations were unchecked (10). Few required parameters and sensible defaults. No official client libraries apart from Google Apps Script (7).",
            "maintenance": "The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). The MCP changelog has nine dated entries in July and three in September (20). Staff answer on the developer forum within a day in the threads we read, and the MCP server has a public changelog (12). No vendor entry in the official MCP registry, where a search for coda and superhuman returned only community servers, and no official API client libraries. The Packs SDK is current (4). Packs SDK CI and dependency updates are public, but it is not the API surface (6).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public per member a month, shown to us in pounds (Pro £10, Business £28 billed yearly), with nothing per call, and the API itself is free (10). A Free plan exists and the API works on free workspaces. No card requirement was found (20). A person signs up in a browser and creates a token or approves OAuth (0).",
            "reliability": "Graded on the hosted REST API, with the MCP server noted, using the hosted lines. Statuspage site at status.coda.io with API, Coda MCP, Docs, Doc Processing and Login among its components (20). Three incidents since 10 July 2026. Access to coda.io was affected for 4 hours 19 minutes on 16 July during a CloudFront outage (minor), docs were slow for 38 minutes on 29 July (marked major), and the coda.new shortcut was down on 13 and 14 August (minor). None was an hour or more of the API down (20). Limits are published per user, 100 reads and 10 writes per 6 seconds (15). The docs tell scripts to back off and retry on 429 and upserts take `keyColumns`, but no Retry-After header or idempotency key is documented (9). The trust page states a 99.9 per cent uptime commitment for Enterprise customers (10). The REST API is generally available and the MCP server is in beta (7).",
            "schema": "Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. MCP tool schemas need a signed-in session and were not read (25). No llms.txt on coda.io, docs.superhuman.com or superhuman.com, all 404, and no Markdown docs found (0). All 125 operations carry descriptions, with guidance such as preferring IDs over names, and the vendor's MCP page gives each of 34 tools a purpose, use cases and key parameters (15). 411 schemas and 175 enums with `additionalProperties: false` on request bodies. Cell values are loosely typed (13). 651 examples, code samples in Python, shell and Google Apps Script, and 429 documented on 124 operations. Error bodies are generic (13). The API is versioned at v1 with a three-month removal notice, and the MCP server has a dated changelog. The REST update log needs JavaScript and was not read, which is our limitation (10).",
            "security": "API tokens can be restricted to one doc or one table and to read or write. Unrestricted tokens carry all of the owner's access, and the docs say a token can't be viewed or changed after creation. MCP uses OAuth with PKCE S256 and dynamic client registration but one scope, `mcp:all` (26). Read-only tokens per doc or table, read-only MCP on the Free plan, and page locking enforced on MCP writes. The MCP product page says read-only and write-only controls are coming soon, and no confirmation step was found for `document_delete` or `table_delete` (13). The vendor has a help centre article titled Security recommendations for the Coda MCP, which a bot check stopped us reading, so only its existence is counted (4). Audit APIs with 12 months of events for Enterprise workspaces, and admin control over API tokens used with MCP (10). Public HackerOne bug bounty, ISO 27001, 27017 and 27018, SOC 2 Type 2, SOC 3 and annual penetration tests. security.txt expired on 31 December 2024 (18).",
            "transparency": "Closed service with published terms, developer terms and an MIT Packs SDK (15). Privacy policy effective 6 July 2026, DPA effective 8 July 2026 and a sub-processor list. Retention is stated as as long as necessary with no periods, user content can be used to train the vendor's AI models subject to an account setting whose default we did not establish, and enterprise customers sit under a separate agreement (19). The API docs promise three months' notice before removals and the developer terms 30 days before term changes. MCP tools changed in September 2026 with no advance notice (14). Sub-processors are listed with purpose and country, all USA (17)."
          },
          "sources": [
            {
              "what": "API reference, rate limits, consistency and deprecation notice",
              "url": "https://coda.io/developers/apis/v1",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI description, version 1.6.0",
              "url": "https://coda.io/apis/v1/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tools and endpoints",
              "url": "https://coda.io/resources/mcp/tools-and-endpoints",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP changelog",
              "url": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth resource metadata",
              "url": "https://coda.io/.well-known/oauth-protected-resource/apis/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth authorisation server metadata",
              "url": "https://coda.io/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "Docs MCP product page, plans and limits",
              "url": "https://superhuman.com/docs/features/docs-mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP getting started guide",
              "url": "https://coda.io/resources/guides/getting_started_with_coda_mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://status.coda.io/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status components",
              "url": "https://status.coda.io/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "plans and prices",
              "url": "https://superhuman.com/plans",
              "seen": "2026-10-08"
            },
            {
              "what": "trust centre, uptime commitment",
              "url": "https://coda.io/trust",
              "seen": "2026-10-08"
            },
            {
              "what": "security and compliance",
              "url": "https://coda.io/trust/security",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://coda.io/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://superhuman.com/legal/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://superhuman.com/legal/privacy-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "data privacy addendum",
              "url": "https://superhuman.com/legal/dpa",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://superhuman.com/legal/subprocessors",
              "seen": "2026-10-08"
            },
            {
              "what": "developer terms",
              "url": "https://coda.io/trust/developer",
              "seen": "2026-10-08"
            },
            {
              "what": "rename announcement",
              "url": "https://blog.superhuman.com/introducing-superhuman-docs/",
              "seen": "2026-10-08"
            },
            {
              "what": "forum thread, MCP auth for server-side agents (staff reply)",
              "url": "https://connect.superhuman.com/t/60859",
              "seen": "2026-10-08"
            },
            {
              "what": "forum thread, API timeouts in March 2026 (staff reply)",
              "url": "https://connect.superhuman.com/t/60264",
              "seen": "2026-10-08"
            },
            {
              "what": "Packs SDK repository and changelog",
              "url": "https://github.com/coda/packs-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=coda",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for coda.io",
              "url": "https://rdap.identitydigital.services/rdap/domain/coda.io",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: help.superhuman.com answers with a bot check, so the MCP connection guide and the article Security recommendations for the Coda MCP were not read. Supported clients, admin controls and injection guidance may be better than scored",
            "unchecked: the REST API update log at docs.superhuman.com/api-updates needs JavaScript, so the date of the last REST API change is unknown. lastRelease uses the MCP changelog date of 24 September 2026",
            "unchecked: the Docs plan table at superhuman.com/plans/docs renders in the browser only. Prices come from superhuman.com/plans as shown in pounds to a UK request, and US dollar prices were not seen",
            "unchecked: MCP tool input schemas and annotations, which need a signed-in session",
            "Whether user content is used for AI training by default was not established. The privacy policy says an account setting controls it",
            "Whether the Free plan needs a card at signup was not tested. No requirement is stated on the pages read",
            "The MCP guides call the server available to everyone while the tools page still calls it beta. We treated it as beta",
            "API timeouts on 26 March 2026 were confirmed by staff on the forum but are missing from status.coda.io. Not deducted, since the rubric has no line for it"
          ]
        },
        "negative": -3,
        "negativeNotes": [
          "24 September 2026 (date approximate per the vendor). The MCP changelog records chart `viewLayout` values renamed so the old ones are no longer valid, and `table_columns_manage` restructured, both marked as documented after shipping. The MCP server is in beta and its tools page warns that names can change, so the deduction is the minimum, 3 (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3)."
        ],
        "verdict": "API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.",
        "bestFor": "Teams whose working data already sits in Coda docs and who want an agent to read and upsert table rows or build docs.",
        "strengths": [
          "API tokens can be restricted to one doc or one table, and to read or write access",
          "Public OpenAPI 3.0 description in JSON and YAML, 125 operations, all with descriptions and 429 documented on 124",
          "Rate limits are published with numbers, 100 reads and 10 writes per 6 seconds per user",
          "Hosted MCP server with 34 tools, OAuth with PKCE and dynamic client registration, and a dated changelog",
          "Public bug bounty on HackerOne, ISO 27001, 27017 and 27018 certificates, SOC 2 Type 2 and a SOC 3 report"
        ],
        "weaknesses": [
          "Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale",
          "No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message",
          "No official client libraries apart from a Google Apps Script library",
          "The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped",
          "MCP OAuth has one scope, `mcp:all`, and no confirmation step was found for `document_delete` or `table_delete`",
          "security.txt on coda.io expired on 31 December 2024"
        ],
        "agentNotes": [
          "Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail",
          "Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind",
          "Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate",
          "Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can",
          "Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 72,
          "payments": 30,
          "reliability": 81,
          "schema": 76,
          "security": 71,
          "transparency": 65
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl -s -H \"Authorization: Bearer $CODA_API_TOKEN\" \"https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25\u0026valueFormat=simpleWithArrays\"",
        "config": {
          "mcpServers": {
            "coda": {
              "url": "https://coda.io/apis/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sheets.read",
        "tool": "https://letme.dev/coda"
      },
      "notable": [
        "Coda was renamed Superhuman Docs on 8 July 2026. The terms name Superhuman Platform Inc. (formerly Grammarly) as the parent of Coda Project LLC (https://blog.superhuman.com/introducing-superhuman-docs/, https://superhuman.com/legal/terms)",
        "The API answers at both https://coda.io/apis/v1 and https://docs.superhuman.com/apis/v1, and the spec is version 1.6.0 with 125 operations, 60 of them for Packs (https://coda.io/apis/v1/openapi.json)",
        "Limits per user are 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds and 4 doc listings per 6 seconds (https://coda.io/developers/apis/v1)",
        "Row inserts, updates and deletes return 202 with a `requestId`, and status is kept for about a day at `/mutationStatus/{requestId}` (https://coda.io/developers/apis/v1)",
        "The MCP server lists 34 tools for search, documents, pages, tables, content, comments and formulas, and its vendor page says tool names can change during the beta (https://coda.io/resources/mcp/tools-and-endpoints)",
        "The MCP changelog's 24 September 2026 entries rename chart layout values and restructure `table_columns_manage`, marked as documented after shipping (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3)",
        "The API docs promise three months' notice before older APIs or functions are removed (https://coda.io/developers/apis/v1)",
        "A staff reply on 27 March 2026 attributed a day of API timeouts and 504 errors to reduced memory on the API servers. status.coda.io lists no incident for that date (https://connect.superhuman.com/t/60264)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "REST API v1 (generally available, OpenAPI 1.6.0). The hosted MCP server is described alongside it and is in beta"
        },
        {
          "label": "Tables",
          "value": "List tables and columns, list rows with one `column:value` filter, sort, `limit`, `pageToken` and `syncToken`, insert or upsert rows with `keyColumns`, update one row, delete rows by ID, push a button column"
        },
        {
          "label": "Formulas",
          "value": "REST reads named formulas and controls only. The MCP server adds formula columns through `table_columns_manage` and evaluates Coda Formula Language with `formula_execute`"
        },
        {
          "label": "Consistency",
          "value": "Writes return 202 and apply within a few seconds. Reads come from the latest snapshot, and `X-Coda-Doc-Version: latest` returns 400 when the snapshot is behind"
        },
        {
          "label": "Rate limits",
          "value": "Per user across all docs. 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds, 4 doc listings per 6 seconds, 100 analytics reads per 6 seconds. Subject to change without notice"
        },
        {
          "label": "Credentials",
          "value": "Bearer API token, optionally restricted to one doc or one table and to read or write. MCP takes OAuth with PKCE and dynamic client registration (scope `mcp:all`) or an API token with the MCP restriction"
        },
        {
          "label": "MCP server",
          "value": "https://coda.io/apis/mcp, hosted, 34 tools, beta. Paid plans, with read-only access on Free capped at 30 requests a week. Batch sizes are 100 rows per add, 500 per delete, 20 columns per call"
        },
        {
          "label": "Change events",
          "value": "No outbound webhooks in the API. `syncToken` on row listings returns changes since an earlier call, and `POST /docs/{docId}/hooks/automation/{ruleId}` triggers an automation inside a doc"
        },
        {
          "label": "Client libraries",
          "value": "None official apart from a Google Apps Script library. The docs list six community libraries as unsupported. The Packs SDK (@codahq/packs-sdk 1.18.0, MIT) builds extensions and is not an API client"
        },
        {
          "label": "Audit",
          "value": "Audit APIs with 12 months of events for Enterprise workspaces, per the security page. Enterprise admins can control who may use API tokens with MCP"
        },
        {
          "label": "Certifications",
          "value": "ISO 27001, 27017 and 27018, SOC 2 Type 2 (report for enterprise customers), SOC 3, annual penetration test, public HackerOne bug bounty"
        },
        {
          "label": "Status",
          "value": "status.coda.io on Statuspage with API, Coda MCP, Docs, Doc Processing, Packs, Search and Login components. 99.9 per cent uptime commitment for Enterprise customers"
        },
        {
          "label": "Sub-processors",
          "value": "Published list covering Coda with each processor's purpose and country, all listed as USA, among them AWS, Anthropic, OpenAI, Azure and Google"
        }
      ],
      "provenance": {
        "legalEntity": "Superhuman Platform Inc. (parent of Coda Project LLC)",
        "domain": "coda.io",
        "domainRegistered": "2012-05-22",
        "endpointOnVendorDomain": true,
        "terms": "https://superhuman.com/legal/terms",
        "privacy": "https://superhuman.com/legal/privacy-policy",
        "statusPage": "https://status.coda.io",
        "changelog": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 29 October 2025) are an agreement with Superhuman Platform Inc., 2261 Market Street STE 85232, San Francisco, CA 94114, and call it the parent company of Coda Project LLC and Superhuman Labs LLC.",
          "The privacy policy (effective 6 July 2026) describes Superhuman Platform Inc. as formerly Grammarly, with Grammarly Inc. and Coda Project LLC as subsidiaries.",
          "coda.io/trust/tos, /trust/privacy, /trust/dpa and /trust/subprocessor redirect to superhuman.com/legal. coda.io/developers/apis/v1 redirects to docs.superhuman.com.",
          "The API and the MCP server answer on coda.io and on docs.superhuman.com. The OAuth metadata names https://coda.io as issuer.",
          "coda.io/.well-known/security.txt points to the HackerOne programme and carries Expires 2024-12-31. superhuman.com/.well-known/security.txt returns 404.",
          "The registry's RDAP record for coda.io gives a registration date of 2012-05-22 and Gandi SAS as registrar.",
          "The changelog link is the MCP server's. The REST API's update log at docs.superhuman.com/api-updates needs JavaScript and was not read."
        ],
        "score": 90,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Superhuman Platform Inc. (parent of Coda Project LLC)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "coda.io, registered 2012-05-22 (14 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "coda.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.coda.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://superhuman.com/legal/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-29",
            "words": 9200,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of October 29, 2025",
                "says": "Last updated 2025-10-29"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "…request for relief will be severed from the arbitration and may be litigated in in the state or federal courts located in San Francisco County, California (but only after the arbitrator issues an award on the arbitrable claims and remedies).",
                "says": "Disputes go to the courts of San Francisco County, California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL SUPERHUMAN AND THE SUPERHUMAN ENTITIES' TOTAL AGGREGATE LIABILITY TO YOU UNDER THESE TERMS EXCEED THE AMOUNT THAT YOU HAVE PAID IN FEES TO SUPERHUMAN OR THE SUPERHUMAN ENTITIES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT(S) GIVING RI…",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "As such, you acknowledge that the Organization may access, view, restrict, merge, or terminate your Account (each, an “Account Control Action”)."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Superhuman will notify you of material changes to this Arbitration Agreement at least 30 days before they become effective.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Please note that once you delete your Account, you will not be able to reactivate it or retrieve any content or information associated with it."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "You also must not use our generative AI features i) in a way that infringes, violates, or misappropriates any of our rights or the rights of any third party, or ii) to develop foundation or large language models that compete with our Services.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may terminate these Terms at any time without liability to you."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "AMONG OTHER THINGS, SECTION 12 INCLUDES AN AGREEMENT TO ARBITRATE (“ARBITRATION AGREEMENT”) WHICH REQUIRES, WITH LIMITED EXCEPTIONS, THAT ALL DISPUTES BETWEEN YOU AND US WILL BE RESOLVED BY BINDING AND FINAL ARBITRATION."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Liability to a customer on a free subscription is capped at 100 US dollars, and otherwise at the fees paid in the preceding twelve months.",
                "quote": "HOWEVER, IF THAT AMOUNT IS ZERO BECAUSE YOU HAVE A FREE SUBSCRIPTION, SUPERHUMAN AND THE SUPERHUMAN ENTITIES’ TOTAL AGGREGATE LIABILITY WILL NOT EXCEED ONE HUNDRED DOLLARS ($100)."
              },
              {
                "date": "2026-10-08",
                "text": "The licence over user content lasts as long as intellectual property laws protect that content and extends to the vendor's service providers.",
                "quote": "The above license lasts as long as intellectual property laws protect your User Content, and it also permits our service providers to assist us in performing these limited purposes."
              },
              {
                "date": "2026-10-08",
                "text": "On termination the vendor may delete user content from its live databases.",
                "quote": "Upon termination of the Services or the applicable feature or functionality thereof, your right to use the Services or the applicable feature or functionality will automatically terminate, and we may delete User Content from our live databases."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://superhuman.com/legal/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-07-06",
            "words": 5814,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of July 6, 2026",
                "says": "Last updated 2026-07-06"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "The information we collect depends on how you use our products and how you manage your privacy settings."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain personal data for as long as necessary to provide our products to you, to complete the transactions you have requested, to comply with our legal obligations, to resolve disputes, and for other legitimate business purposes.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "If you purchase our products through a third-party app store or payment processor, you may provide your payment information directly to those providers—not to us."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "These activities–disclosing unique IDs and disclosing data through Cookies–may constitute “targeted advertising”, “sharing”, or “selling” under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You have the right not to be discriminated against for exercising any of your privacy rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You can unsubscribe from our marketing emails by following the instructions in those emails, adjusting the marketing communications preferences in your settings, or emailing us at privacy@superhuman.com.",
                "says": "privacy@superhuman.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Data Privacy Framework, the UK Extension of the EU-U.S.",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings."
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "These activities–disclosing unique IDs and disclosing data through Cookies–may constitute “targeted advertising”, “sharing”, or “selling” under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy does not cover content uploaded to or output from accounts managed by an organisation, which the organisation's contract governs.",
                "quote": "This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization."
              },
              {
                "date": "2026-10-08",
                "text": "The vendor says it restricts its AI service providers from training their models on customers' user content.",
                "quote": "For example, we restrict our AI service providers from training their models on user content of Superhuman customers."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/coda.json",
      "live": {
        "slug": "coda",
        "probe": {
          "target": "https://coda.io/apis/v1",
          "method": "get",
          "lastAt": "2026-10-08T19:08:43.604504809Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 258,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 186,
          "p95ms24h": 229,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.coda.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:31.303588244Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "coda/packs-sdk",
            "version": "v1.18.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:06:05.16888764Z"
          },
          {
            "registry": "npm",
            "name": "@codahq/packs-sdk",
            "version": "1.18.0",
            "seenAt": "2026-10-08T16:06:01.042367623Z"
          }
        ],
        "githubStars": 112,
        "npmWeekly": 10270,
        "securityTxt": {
          "url": "https://coda.io/.well-known/security.txt",
          "state": "expired",
          "expires": "2024-12-31T20:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:55.777108046Z"
        },
        "pages": [
          {
            "url": "https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3",
            "kind": "changelog",
            "status": 0,
            "checkedAt": "2026-10-08T18:19:33.846152714Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          },
          {
            "url": "https://superhuman.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:58.353462251Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "247a8f92d92b"
          },
          {
            "url": "https://superhuman.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:00.904608476Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b95766421539"
          }
        ],
        "updatedAt": "2026-10-08T19:08:43.604504809Z"
      }
    },
    "verify": {
      "accepts": "a page on coda.io or one of its subdomains, or the README of github.com/coda/packs-sdk",
      "badgeUrl": "https://www.anchorterminal.com/badges/coda.svg",
      "body": {
        "slug": "coda",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/coda",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/coda\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/coda.svg\" alt=\"Coda (Superhuman Docs) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Coda (Superhuman Docs) on Anchor Terminal](https://www.anchorterminal.com/badges/coda.svg)](https://www.anchorterminal.com/tools/coda)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/coda\"\u003eCoda (Superhuman Docs) on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/coda",
    "json": "https://www.anchorterminal.com/tools/coda.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/coda.md",
    "slim": "https://www.anchorterminal.com/tools/coda.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 64.8/100 · rank #247 of 629 · #5 in Spreadsheets \u0026 operational tables · not agent-ready · confidence medium**\n\n\n## Assessment\n\nAPI tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Superhuman Platform Inc. (https://coda.io) |\n| Kind | HTTP API |\n| Category | Spreadsheets \u0026 operational tables (https://www.anchorterminal.com/categories/spreadsheets) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://coda.io/apis/v1` |\n| Auth | OAuth or key · REST API takes `Authorization: Bearer \u003capi_token\u003e`, a token a signed-in user creates under account settings. A token can do everything its owner can unless it is created with restrictions, which limit it to one doc or one table and to read, write or both. The MCP server at https://coda.io/apis/mcp takes OAuth (authorisation code grant with PKCE S256, dynamic client registration, one scope `mcp:all`) or an API token created with the MCP restriction, per a staff reply on the vendor's community forum. Access is self-serve with no app review. |\n| Pricing | Freemium (Freemium) · The API is free on free and paid workspaces, so an agent can start on the Free plan without a contract. Suite prices as shown to our UK request on 8 October 2026 were Free £0, Pro £10 a member a month billed yearly (£12 monthly), Business £28 (£33 monthly) and Enterprise by quote (https://superhuman.com/plans). MCP is included on paid plans, and Free accounts get read-only MCP access capped at 30 requests a week and 60 a month. US dollar prices and the Docs-only plan table were not readable. |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI description or the plans page (checked 2026-10-08). |\n| Licence | Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT |\n| Tools exposed | 34 |\n| Packages | npm: `@codahq/packs-sdk` |\n| Source | https://github.com/coda/packs-sdk |\n| Docs | https://coda.io/developers/apis/v1 |\n| llms.txt | not found |\n| Last release | 2026-09-24 |\n| npm downloads / week | 10,270 |\n| Surface graded | REST API v1 (generally available, OpenAPI 1.6.0). The hosted MCP server is described alongside it and is in beta |\n| Tables | List tables and columns, list rows with one `column:value` filter, sort, `limit`, `pageToken` and `syncToken`, insert or upsert rows with `keyColumns`, update one row, delete rows by ID, push a button column |\n| Formulas | REST reads named formulas and controls only. The MCP server adds formula columns through `table_columns_manage` and evaluates Coda Formula Language with `formula_execute` |\n| Consistency | Writes return 202 and apply within a few seconds. Reads come from the latest snapshot, and `X-Coda-Doc-Version: latest` returns 400 when the snapshot is behind |\n| Rate limits | Per user across all docs. 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds, 4 doc listings per 6 seconds, 100 analytics reads per 6 seconds. Subject to change without notice |\n| Credentials | Bearer API token, optionally restricted to one doc or one table and to read or write. MCP takes OAuth with PKCE and dynamic client registration (scope `mcp:all`) or an API token with the MCP restriction |\n| MCP server | https://coda.io/apis/mcp, hosted, 34 tools, beta. Paid plans, with read-only access on Free capped at 30 requests a week. Batch sizes are 100 rows per add, 500 per delete, 20 columns per call |\n| Change events | No outbound webhooks in the API. `syncToken` on row listings returns changes since an earlier call, and `POST /docs/{docId}/hooks/automation/{ruleId}` triggers an automation inside a doc |\n| Client libraries | None official apart from a Google Apps Script library. The docs list six community libraries as unsupported. The Packs SDK (@codahq/packs-sdk 1.18.0, MIT) builds extensions and is not an API client |\n| Audit | Audit APIs with 12 months of events for Enterprise workspaces, per the security page. Enterprise admins can control who may use API tokens with MCP |\n| Certifications | ISO 27001, 27017 and 27018, SOC 2 Type 2 (report for enterprise customers), SOC 3, annual penetration test, public HackerOne bug bounty |\n| Status | status.coda.io on Statuspage with API, Coda MCP, Docs, Doc Processing, Packs, Search and Login components. 99.9 per cent uptime commitment for Enterprise customers |\n| Sub-processors | Published list covering Coda with each processor's purpose and country, all listed as USA, among them AWS, Anthropic, OpenAI, Azure and Google |\n| Capabilities | sheets.read, sheets.write, sheets.tables, sheets.records, sheets.formulas, work.docs |\n| Tags | official, hosted, closed-source, freemium, free-tier, api-key, oauth, mcp, openapi, status-page, bug-bounty, soc2, iso27001 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/coda.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 81 | 16.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 76 | 12.3 |\n| Agent ergonomics | 13% | 16.2 | 61 | 9.9 |\n| Security \u0026 auth | 14% | 17.5 | 71 | 12.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 72 | 6.3 |\n| Transparency \u0026 trust (editorial 65, provenance 90) | 7% | 8.8 | 78 | 6.8 |\n| Negative events | up to −15 | up to −15 | 24 September 2026 (date approximate per the vendor). The MCP changelog records chart `viewLayout` values renamed so the old ones are no longer valid, and `table_columns_manage` restructured, both marked as documented after shipping. The MCP server is in beta and its tools page warns that names can change, so the deduction is the minimum, 3 (https://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3).  | -3 |\n| **Total** | | | | **64.8 → B** |\n\n### Why each score\n\n- Reliability 81: Graded on the hosted REST API, with the MCP server noted, using the hosted lines. Statuspage site at status.coda.io with API, Coda MCP, Docs, Doc Processing and Login among its components (20). Three incidents since 10 July 2026. Access to coda.io was affected for 4 hours 19 minutes on 16 July during a CloudFront outage (minor), docs were slow for 38 minutes on 29 July (marked major), and the coda.new shortcut was down on 13 and 14 August (minor). None was an hour or more of the API down (20). Limits are published per user, 100 reads and 10 writes per 6 seconds (15). The docs tell scripts to back off and retry on 429 and upserts take `keyColumns`, but no Retry-After header or idempotency key is documented (9). The trust page states a 99.9 per cent uptime commitment for Enterprise customers (10). The REST API is generally available and the MCP server is in beta (7).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 76: Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. MCP tool schemas need a signed-in session and were not read (25). No llms.txt on coda.io, docs.superhuman.com or superhuman.com, all 404, and no Markdown docs found (0). All 125 operations carry descriptions, with guidance such as preferring IDs over names, and the vendor's MCP page gives each of 34 tools a purpose, use cases and key parameters (15). 411 schemas and 175 enums with `additionalProperties: false` on request bodies. Cell values are loosely typed (13). 651 examples, code samples in Python, shell and Google Apps Script, and 429 documented on 124 operations. Error bodies are generic (13). The API is versioned at v1 with a three-month removal notice, and the MCP server has a dated changelog. The REST update log needs JavaScript and was not read, which is our limitation (10).\n- Agent ergonomics 61: Row listings take `limit` (default 25), `visibleOnly` and three `valueFormat` levels, with no column selection on REST. The MCP server has 34 tools, `columnsToInclude` on row reads and a `tool_guide` tool that loads guidance by topic (15). `pageToken` paging, `sortBy`, `syncToken` for changes since an earlier call, and a `query` filter limited to one column and value (17). Errors return `statusCode`, `statusMessage` and `message` with no machine codes beyond the HTTP status (12). Upserts by `keyColumns` and `/mutationStatus/{requestId}` allow safe retries. No idempotency keys, writes are asynchronous with 202, and MCP annotations were unchecked (10). Few required parameters and sensible defaults. No official client libraries apart from Google Apps Script (7).\n- Security \u0026 auth 71: API tokens can be restricted to one doc or one table and to read or write. Unrestricted tokens carry all of the owner's access, and the docs say a token can't be viewed or changed after creation. MCP uses OAuth with PKCE S256 and dynamic client registration but one scope, `mcp:all` (26). Read-only tokens per doc or table, read-only MCP on the Free plan, and page locking enforced on MCP writes. The MCP product page says read-only and write-only controls are coming soon, and no confirmation step was found for `document_delete` or `table_delete` (13). The vendor has a help centre article titled Security recommendations for the Coda MCP, which a bot check stopped us reading, so only its existence is counted (4). Audit APIs with 12 months of events for Enterprise workspaces, and admin control over API tokens used with MCP (10). Public HackerOne bug bounty, ISO 27001, 27017 and 27018, SOC 2 Type 2, SOC 3 and annual penetration tests. security.txt expired on 31 December 2024 (18).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Plan prices are public per member a month, shown to us in pounds (Pro £10, Business £28 billed yearly), with nothing per call, and the API itself is free (10). A Free plan exists and the API works on free workspaces. No card requirement was found (20). A person signs up in a browser and creates a token or approves OAuth (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 72: The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). The MCP changelog has nine dated entries in July and three in September (20). Staff answer on the developer forum within a day in the threads we read, and the MCP server has a public changelog (12). No vendor entry in the official MCP registry, where a search for coda and superhuman returned only community servers, and no official API client libraries. The Packs SDK is current (4). Packs SDK CI and dependency updates are public, but it is not the API surface (6).\n- Transparency \u0026 trust 78: Closed service with published terms, developer terms and an MIT Packs SDK (15). Privacy policy effective 6 July 2026, DPA effective 8 July 2026 and a sub-processor list. Retention is stated as as long as necessary with no periods, user content can be used to train the vendor's AI models subject to an account setting whose default we did not establish, and enterprise customers sit under a separate agreement (19). The API docs promise three months' notice before removals and the developer terms 30 days before term changes. MCP tools changed in September 2026 with no advance notice (14). Sub-processors are listed with purpose and country, all USA (17).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/coda.md (JSON https://www.anchorterminal.com/fixes/coda.json)\n\n### What we couldn't check\n\n- unchecked: help.superhuman.com answers with a bot check, so the MCP connection guide and the article Security recommendations for the Coda MCP were not read. Supported clients, admin controls and injection guidance may be better than scored\n- unchecked: the REST API update log at docs.superhuman.com/api-updates needs JavaScript, so the date of the last REST API change is unknown. lastRelease uses the MCP changelog date of 24 September 2026\n- unchecked: the Docs plan table at superhuman.com/plans/docs renders in the browser only. Prices come from superhuman.com/plans as shown in pounds to a UK request, and US dollar prices were not seen\n- unchecked: MCP tool input schemas and annotations, which need a signed-in session\n- Whether user content is used for AI training by default was not established. The privacy policy says an account setting controls it\n- Whether the Free plan needs a card at signup was not tested. No requirement is stated on the pages read\n- The MCP guides call the server available to everyone while the tools page still calls it beta. We treated it as beta\n- API timeouts on 26 March 2026 were confirmed by staff on the forum but are missing from status.coda.io. Not deducted, since the rubric has no line for it\n\n### Sources\n\n- API reference, rate limits, consistency and deprecation notice: \u003chttps://coda.io/developers/apis/v1\u003e (seen 2026-10-08)\n- OpenAPI description, version 1.6.0: \u003chttps://coda.io/apis/v1/openapi.json\u003e (seen 2026-10-08)\n- MCP tools and endpoints: \u003chttps://coda.io/resources/mcp/tools-and-endpoints\u003e (seen 2026-10-08)\n- MCP changelog: \u003chttps://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3\u003e (seen 2026-10-08)\n- MCP OAuth resource metadata: \u003chttps://coda.io/.well-known/oauth-protected-resource/apis/mcp\u003e (seen 2026-10-08)\n- OAuth authorisation server metadata: \u003chttps://coda.io/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- Docs MCP product page, plans and limits: \u003chttps://superhuman.com/docs/features/docs-mcp\u003e (seen 2026-10-08)\n- MCP getting started guide: \u003chttps://coda.io/resources/guides/getting_started_with_coda_mcp\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://status.coda.io/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status components: \u003chttps://status.coda.io/api/v2/components.json\u003e (seen 2026-10-08)\n- plans and prices: \u003chttps://superhuman.com/plans\u003e (seen 2026-10-08)\n- trust centre, uptime commitment: \u003chttps://coda.io/trust\u003e (seen 2026-10-08)\n- security and compliance: \u003chttps://coda.io/trust/security\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://coda.io/.well-known/security.txt\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://superhuman.com/legal/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://superhuman.com/legal/privacy-policy\u003e (seen 2026-10-08)\n- data privacy addendum: \u003chttps://superhuman.com/legal/dpa\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://superhuman.com/legal/subprocessors\u003e (seen 2026-10-08)\n- developer terms: \u003chttps://coda.io/trust/developer\u003e (seen 2026-10-08)\n- rename announcement: \u003chttps://blog.superhuman.com/introducing-superhuman-docs/\u003e (seen 2026-10-08)\n- forum thread, MCP auth for server-side agents (staff reply): \u003chttps://connect.superhuman.com/t/60859\u003e (seen 2026-10-08)\n- forum thread, API timeouts in March 2026 (staff reply): \u003chttps://connect.superhuman.com/t/60264\u003e (seen 2026-10-08)\n- Packs SDK repository and changelog: \u003chttps://github.com/coda/packs-sdk\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=coda\u003e (seen 2026-10-08)\n- RDAP for coda.io: \u003chttps://rdap.identitydigital.services/rdap/domain/coda.io\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 90/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Superhuman Platform Inc. (parent of Coda Project LLC) | 20/20 |\n| Domain age | coda.io, registered 2012-05-22 (14 years) | 15/15 |\n| Endpoint on the vendor's domain | coda.io | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.coda.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe terms of service (effective 29 October 2025) are an agreement with Superhuman Platform Inc., 2261 Market Street STE 85232, San Francisco, CA 94114, and call it the parent company of Coda Project LLC and Superhuman Labs LLC.\n\nThe privacy policy (effective 6 July 2026) describes Superhuman Platform Inc. as formerly Grammarly, with Grammarly Inc. and Coda Project LLC as subsidiaries.\n\ncoda.io/trust/tos, /trust/privacy, /trust/dpa and /trust/subprocessor redirect to superhuman.com/legal. coda.io/developers/apis/v1 redirects to docs.superhuman.com.\n\nThe API and the MCP server answer on coda.io and on docs.superhuman.com. The OAuth metadata names https://coda.io as issuer.\n\ncoda.io/.well-known/security.txt points to the HackerOne programme and carries Expires 2024-12-31. superhuman.com/.well-known/security.txt returns 404.\n\nThe registry's RDAP record for coda.io gives a registration date of 2012-05-22 and Gandi SAS as registrar.\n\nThe changelog link is the MCP server's. The REST API's update log at docs.superhuman.com/api-updates needs JavaScript and was not read.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://superhuman.com/legal/terms), read 2026-10-08, dated 2025-10-29, states 6 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);\"\n- To know. Restricts benchmarking or competitive use (costs points). \"You also must not use our generative AI features i) in a way that infringes, violates, or misappropriates any of our rights or the rights of any third party, or ii) to develop foundation or large language models that compete with our Services.\"\n- To know. Says access can be ended without notice or for any reason. \"We may terminate these Terms at any time without liability to you.\"\n- To know. Requires arbitration or waives class actions. \"AMONG OTHER THINGS, SECTION 12 INCLUDES AN AGREEMENT TO ARBITRATE (“ARBITRATION AGREEMENT”) WHICH REQUIRES, WITH LIMITED EXCEPTIONS, THAT ALL DISPUTES BETWEEN YOU AND US WILL BE RESOLVED BY BINDING AND FINAL ARBITRATION.\"\n- Gives the date it was last updated. Last updated 2025-10-29.\n- Names the governing law or courts. Disputes go to the courts of San Francisco County, California.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Liability to a customer on a free subscription is capped at 100 US dollars, and otherwise at the fees paid in the preceding twelve months. \"HOWEVER, IF THAT AMOUNT IS ZERO BECAUSE YOU HAVE A FREE SUBSCRIPTION, SUPERHUMAN AND THE SUPERHUMAN ENTITIES’ TOTAL AGGREGATE LIABILITY WILL NOT EXCEED ONE HUNDRED DOLLARS ($100).\"\n- Also in the text (2026-10-08). The licence over user content lasts as long as intellectual property laws protect that content and extends to the vendor's service providers. \"The above license lasts as long as intellectual property laws protect your User Content, and it also permits our service providers to assist us in performing these limited purposes.\"\n- Also in the text (2026-10-08). On termination the vendor may delete user content from its live databases. \"Upon termination of the Services or the applicable feature or functionality thereof, your right to use the Services or the applicable feature or functionality will automatically terminate, and we may delete User Content from our live databases.\"\n\n**Privacy policy** (https://superhuman.com/legal/privacy-policy), read 2026-10-08, dated 2026-07-06, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.\"\n- To know. Says it sells personal data or shares it for advertising. \"These activities–disclosing unique IDs and disclosing data through Cookies–may constitute “targeted advertising”, “sharing”, or “selling” under certain privacy laws, and depending on where you live, we may require your consent or you may be able to opt out of such activities.\"\n- Gives the date it was last updated. Last updated 2026-07-06.\n- Says how long data is kept. For as long as needed, with no period named.\n- Gives a privacy contact. privacy@superhuman.com.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). The policy does not cover content uploaded to or output from accounts managed by an organisation, which the organisation's contract governs. \"This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization.\"\n- Also in the text (2026-10-08). The vendor says it restricts its AI service providers from training their models on customers' user content. \"For example, we restrict our AI service providers from training their models on user content of Superhuman customers.\"\n\n## Live (updated 2026-10-08 19:08 UTC)\n\n- Right now: up, HTTP 401, 258 ms, checked 2026-10-08 19:08 UTC (get on `https://coda.io/apis/v1`, asks for auth)\n- Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 186 ms · p95 229 ms\n- Vendor status page: none, All Systems Operational\n- github `coda/packs-sdk` v1.18.0, released 2026-10-07\n- npm `@codahq/packs-sdk` 1.18.0\n- security.txt: expired, expires 2024-12-31T20:00:00.000Z\n- Watching changelog \u003chttps://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3\u003e\n- Watching privacy \u003chttps://superhuman.com/legal/privacy-policy\u003e\n- Watching terms \u003chttps://superhuman.com/legal/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/coda.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- API tokens can be restricted to one doc or one table, and to read or write access\n- Public OpenAPI 3.0 description in JSON and YAML, 125 operations, all with descriptions and 429 documented on 124\n- Rate limits are published with numbers, 100 reads and 10 writes per 6 seconds per user\n- Hosted MCP server with 34 tools, OAuth with PKCE and dynamic client registration, and a dated changelog\n- Public bug bounty on HackerOne, ISO 27001, 27017 and 27018 certificates, SOC 2 Type 2 and a SOC 3 report\n\n## Weaknesses\n\n- Row writes return 202 and take a few seconds to apply, and reads come from a snapshot that can be stale\n- No idempotency keys and no Retry-After header documented, and error bodies carry only a status and a message\n- No official client libraries apart from a Google Apps Script library\n- The MCP server is in beta, and its changelog records renamed tools and parameters documented after they shipped\n- MCP OAuth has one scope, `mcp:all`, and no confirmation step was found for `document_delete` or `table_delete`\n- security.txt on coda.io expired on 31 December 2024\n\n## Before you call it (notes for agents)\n\n1. Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail\n2. Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind\n3. Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate\n4. Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can\n5. Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -s -H \"Authorization: Bearer $CODA_API_TOKEN\" \"https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25\u0026valueFormat=simpleWithArrays\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"coda\": {\n      \"url\": \"https://coda.io/apis/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/coda. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| NocoDB | BB | 75.7 | 37 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/nocodb.md |\n| Airtable | BB | 70.9 | 118 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/airtable.md |\n| Baserow | B | 63.6 | 276 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/baserow.md |\n| Google Sheets API | BB | 76.3 | 33 | sheets.read, sheets.write, sheets.formulas, sheets.tables | no | https://www.anchorterminal.com/tools/google-sheets-api.md |\n| Smartsheet API + MCP | B | 67.6 | 190 | sheets.read, sheets.write, sheets.records, sheets.formulas | no | https://www.anchorterminal.com/tools/smartsheet.md |\n| Microsoft Excel (Microsoft Graph workbook API) | C | 58.5 | 399 | sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/microsoft-excel-graph.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Coda was renamed Superhuman Docs on 8 July 2026. The terms name Superhuman Platform Inc. (formerly Grammarly) as the parent of Coda Project LLC (source: \u003chttps://blog.superhuman.com/introducing-superhuman-docs/, https://superhuman.com/legal/terms\u003e)\n- The API answers at both https://coda.io/apis/v1 and https://docs.superhuman.com/apis/v1, and the spec is version 1.6.0 with 125 operations, 60 of them for Packs (source: \u003chttps://coda.io/apis/v1/openapi.json\u003e)\n- Limits per user are 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds and 4 doc listings per 6 seconds (source: \u003chttps://coda.io/developers/apis/v1\u003e)\n- Row inserts, updates and deletes return 202 with a `requestId`, and status is kept for about a day at `/mutationStatus/{requestId}` (source: \u003chttps://coda.io/developers/apis/v1\u003e)\n- The MCP server lists 34 tools for search, documents, pages, tables, content, comments and formulas, and its vendor page says tool names can change during the beta (source: \u003chttps://coda.io/resources/mcp/tools-and-endpoints\u003e)\n- The MCP changelog's 24 September 2026 entries rename chart layout values and restructure `table_columns_manage`, marked as documented after shipping (source: \u003chttps://docs.superhuman.com/@bharat-batra/tools-and-endpoints/changelog-3\u003e)\n- The API docs promise three months' notice before older APIs or functions are removed (source: \u003chttps://coda.io/developers/apis/v1\u003e)\n- A staff reply on 27 March 2026 attributed a day of API timeouts and 504 errors to reduced memory on the API servers. status.coda.io lists no incident for that date (source: \u003chttps://connect.superhuman.com/t/60264\u003e)\n\n## Compare\n\n- [Coda (Superhuman Docs) vs Google Sheets API](https://www.anchorterminal.com/compare/coda-vs-google-sheets-api.md): B 64.8 vs BB 76.3\n- [Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.md): B 64.8 vs C 58.5\n- [Coda (Superhuman Docs) vs NocoDB](https://www.anchorterminal.com/compare/coda-vs-nocodb.md): B 64.8 vs BB 75.7\n- [Coda (Superhuman Docs) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/coda-vs-smartsheet.md): B 64.8 vs B 67.6\n- [Airtable vs Coda (Superhuman Docs)](https://www.anchorterminal.com/compare/airtable-vs-coda.md): BB 70.9 vs B 64.8\n- [Baserow vs Coda (Superhuman Docs)](https://www.anchorterminal.com/compare/baserow-vs-coda.md): B 63.6 vs B 64.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on coda.io or one of its subdomains, or the README of github.com/coda/packs-sdk. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"coda\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/coda\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/coda.svg\" alt=\"Coda (Superhuman Docs) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Coda (Superhuman Docs) on Anchor Terminal](https://www.anchorterminal.com/badges/coda.svg)](https://www.anchorterminal.com/tools/coda)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/coda\"\u003eCoda (Superhuman Docs) on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Coda (Superhuman Docs) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/coda-dark.png\n- Light: https://www.anchorterminal.com/assets/share/coda-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Spreadsheets \u0026 operational tables",
        "url": "https://www.anchorterminal.com/categories/spreadsheets"
      },
      {
        "name": "Coda (Superhuman Docs)",
        "url": ""
      }
    ],
    "description": "Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta.",
    "facts": [
      "rank #247 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Coda (Superhuman Docs)",
    "image": "https://www.anchorterminal.com/assets/og/tools-coda.png",
    "path": "/tools/coda",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Coda (Superhuman Docs) review for AI agents, grade B (64.8/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/coda"
  },
  "tokens": {
    "markdown": 8100,
    "slim": 1830
  },
  "version": 1
}
