# Coda (Superhuman Docs) (slim) > Coda, renamed Superhuman Docs in July 2026, is a document workspace whose pages hold typed tables, formulas and automations. Agents reach it through a REST API with a public OpenAPI description, or a hosted MCP server in beta. - Full: https://www.anchorterminal.com/tools/coda.md (~8,050 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/coda.json · canonical https://www.anchorterminal.com/tools/coda - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 64.8/100 · rank #247 of 629 · #5 in Spreadsheets & operational tables · not agent-ready · confidence medium** Assessment: API tokens can be limited to one doc or one table and to read or write, and the OpenAPI description covers 125 operations with 429 on almost all. Writes are queued and answered with 202, so each needs a status check. The REST API has no idempotency keys or official client libraries, and the MCP server is in beta. ## Facts - Kind: HTTP API · vendor: Superhuman Platform Inc. · category: Spreadsheets & operational tables · legal entity: Superhuman Platform Inc. (parent of Coda Project LLC) · provenance 90/100 - Endpoint: `https://coda.io/apis/v1` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Superhuman's terms of service and developer terms. The Packs SDK on GitHub is MIT - Probe metrics: not measured yet (probes haven't run) - Surface graded: REST API v1 (generally available, OpenAPI 1.6.0). The hosted MCP server is described alongside it and is in beta - Tables: List tables and columns, list rows with one `column:value` filter, sort, `limit`, `pageToken` and `syncToken`, insert or upsert rows with `keyColumns`, update one row, delete rows by ID, push a button column - Formulas: REST reads named formulas and controls only. The MCP server adds formula columns through `table_columns_manage` and evaluates Coda Formula Language with `formula_execute` - Consistency: Writes return 202 and apply within a few seconds. Reads come from the latest snapshot, and `X-Coda-Doc-Version: latest` returns 400 when the snapshot is behind - Rate limits: Per user across all docs. 100 reads per 6 seconds, 10 writes per 6 seconds, 5 doc content writes per 10 seconds, 4 doc listings per 6 seconds, 100 analytics reads per 6 seconds. Subject to change without notice - Credentials: Bearer API token, optionally restricted to one doc or one table and to read or write. MCP takes OAuth with PKCE and dynamic client registration (scope `mcp:all`) or an API token with the MCP restriction - MCP server: https://coda.io/apis/mcp, hosted, 34 tools, beta. Paid plans, with read-only access on Free capped at 30 requests a week. Batch sizes are 100 rows per add, 500 per delete, 20 columns per call - Change events: No outbound webhooks in the API. `syncToken` on row listings returns changes since an earlier call, and `POST /docs/{docId}/hooks/automation/{ruleId}` triggers an automation inside a doc - Client libraries: None official apart from a Google Apps Script library. The docs list six community libraries as unsupported. The Packs SDK (@codahq/packs-sdk 1.18.0, MIT) builds extensions and is not an API client - Audit: Audit APIs with 12 months of events for Enterprise workspaces, per the security page. Enterprise admins can control who may use API tokens with MCP - Certifications: ISO 27001, 27017 and 27018, SOC 2 Type 2 (report for enterprise customers), SOC 3, annual penetration test, public HackerOne bug bounty - Status: status.coda.io on Statuspage with API, Coda MCP, Docs, Doc Processing, Packs, Search and Login components. 99.9 per cent uptime commitment for Enterprise customers - Sub-processors: Published list covering Coda with each processor's purpose and country, all listed as USA, among them AWS, Anthropic, OpenAI, Azure and Google - Scores: Reliability 81, Performance pending, Schema & documentation 76, Agent ergonomics 61, Security & auth 71, Payments & pricing 30, Task success pending, Maintenance & community 72, Transparency & trust 78 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted REST API, with the MCP server noted, using the hosted lines. · Schema & documentation, Public OpenAPI 3.0 description in JSON and YAML, version 1.6.0, 125 operations. · Agent ergonomics, Row listings take `limit` (default 25), `visibleOnly` and three `valueFormat` levels, with no column selection on REST. · Security & auth, API tokens can be restricted to one doc or one table and to read or write. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The MCP changelog's newest entries are dated 24 September 2026, and Packs SDK 1.18.0 followed on 7 October (30). · Transparency & trust, Closed service with published terms, developer terms and an MIT Packs SDK (15). - Sources: 25, open questions: 8, both in the full twin - Capabilities: sheets.read, sheets.write, sheets.tables, sheets.records, sheets.formulas, work.docs - JSON: https://www.anchorterminal.com/api/v1/tools/coda.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/coda.svg` or a link to https://www.anchorterminal.com/tools/coda from a page on coda.io or one of its subdomains, or the README of github.com/coda/packs-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Poll `/mutationStatus/{requestId}` after every row write. A 202 means queued, and the edit can still fail 2. Send `X-Coda-Doc-Version: latest` when a read must reflect recent edits, and handle the 400 it returns when the snapshot is behind 3. Use `keyColumns` on `POST .../rows` so a retried insert updates the same row instead of adding a duplicate 4. Ask for a token restricted to the one doc or table and to read access where the task allows. An unrestricted token can do anything its owner can 5. Read MCP tool names from the tool list at run time. The vendor says names and parameters can change during the beta ## Connect ```bash curl -s -H "Authorization: Bearer $CODA_API_TOKEN" "https://coda.io/apis/v1/docs/$DOC_ID/tables/$TABLE_ID/rows?limit=25&valueFormat=simpleWithArrays" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/coda ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | NocoDB | BB | 75.7 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/nocodb.min.md | | Airtable | BB | 70.9 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/airtable.min.md | | Baserow | B | 63.6 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/baserow.min.md | | Google Sheets API | BB | 76.3 | sheets.read, sheets.write, sheets.formulas, sheets.tables | https://www.anchorterminal.com/tools/google-sheets-api.min.md | | Smartsheet API + MCP | B | 67.6 | sheets.read, sheets.write, sheets.records, sheets.formulas | https://www.anchorterminal.com/tools/smartsheet.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)