{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/atlan.json",
        "name": "Atlan",
        "score": 62.5,
        "shared": [
          "data.catalogue",
          "data.lineage",
          "knowledge.search"
        ],
        "slug": "atlan"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/alation.json",
        "name": "Alation",
        "score": 60.3,
        "shared": [
          "data.catalogue",
          "knowledge.search",
          "data.lineage"
        ],
        "slug": "alation"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/secoda.json",
        "name": "Secoda",
        "score": 44.5,
        "shared": [
          "data.catalogue",
          "data.lineage",
          "knowledge.search"
        ],
        "slug": "secoda"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/openmetadata.json",
        "name": "OpenMetadata",
        "score": 66.6,
        "shared": [
          "data.catalogue",
          "data.lineage"
        ],
        "slug": "openmetadata"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/marmot.json",
        "name": "Marmot",
        "score": 64.4,
        "shared": [
          "data.catalogue",
          "data.lineage"
        ],
        "slug": "marmot"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/datahub.json",
        "name": "DataHub",
        "score": 59.4,
        "shared": [
          "data.catalogue",
          "data.lineage"
        ],
        "slug": "datahub"
      }
    ],
    "tool": {
      "slug": "collibra",
      "name": "Collibra",
      "vendor": "Collibra",
      "vendorUrl": "https://www.collibra.com",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Collibra is a hosted data governance platform with a catalogue, business glossary, lineage and data quality. Agents use REST and GraphQL APIs, a bulk Import API, a hosted MCP server on each cloud instance and an open-source local one.",
      "url": "https://www.anchorterminal.com/tools/collibra",
      "markdownUrl": "https://www.anchorterminal.com/tools/collibra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/collibra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/collibra.json",
      "repo": "https://github.com/collibra/chip",
      "license": "Proprietary service under the Master Collibra Agreement, with the Developer Terms for the REST APIs and CLI. The local MCP server (chip) is Apache-2.0, and the CLI binary ships under a Binary Code Licence Agreement",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted inside a customer's Collibra environment. An administrator with the System administration permission registers an OAuth application under Settings. Integration applications use the client credentials flow at `/rest/oauth/v2/token` and act as an application-specific system user, and user applications use the authorisation code flow with PKCE for MCP clients. Tokens are valid for 5 minutes, and the settings page says Collibra assigns all scopes to the client. The APIs also accept HTTP Basic authentication with a Collibra username and password, and a JWT Bearer token issued by the customer's identity provider. The local MCP server accepts a username and password only. Permissions follow the user's Collibra roles.",
      "pricing": "paid",
      "pricingNotes": "No prices are published. www.collibra.com/pricing returns 404, and the site links a demo request and a product tour. We found no trial or self-serve sign-up, so an agent cannot start without a contract. An Evaluation Agreement is published for evaluations arranged with Collibra. The MCP server is free to use, and AI functions such as the natural-language discovery tools consume Collibra Units, with 70,000 or 100,000 units included in each contract depending on the package (checked 2026-10-09).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer portal, the MCP server source or the legal documents (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 30,
      "popularity": {
        "githubStars": 37,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developer.collibra.com/",
      "llmsTxt": "https://developer.collibra.com/llms.txt",
      "capabilities": [
        "data.catalogue",
        "knowledge.search",
        "data.lineage"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "enterprise",
        "official",
        "mcp",
        "oauth",
        "openapi",
        "graphql",
        "sales-led",
        "status-page",
        "sla",
        "soc2"
      ],
      "lastRelease": "2026-10-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 346,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 76,
          "payments": 0,
          "reliability": 66,
          "schema": 83,
          "security": 68,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 66,
            "points": 13.2,
            "reason": "Hosted service, read on the hosted lines and graded on the REST and GraphQL APIs of a Collibra cloud instance, with the MCP server as a second surface. status.collibra.com lists six components for each of four regions with an incident history (20). In the 90 days to 9 October 2026 the page shows a lineage and integrations disruption from 24 July to 14 August in all regions, where two ingestion methods created duplicate mapping IDs, and the close on 5 August of a UAE region disruption that began on 1 March. The page reported all systems normal for the 55 days before our check (15 of 30). No general request rate limit was found. The OAuth settings page gives a pool of 100 token requests for each client refilled at 30 a minute, Knowledge Graph queries stop at 100,000 nodes, and 8 imports run concurrently (7 of 15). A 429 is documented for the token endpoint with its causes, and the Import API guide says to retry a job that fails on a concurrency error. No `Retry-After` header or idempotency key was found (6 of 15). The Service Level Agreement of 1 October 2023 sets a 99.5 per cent monthly uptime target with service credits (10). The REST APIs are generally available. The hosted MCP documentation states no status, and the local server is at v0.0.62 (8 of 10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 83,
            "points": 13.49,
            "reason": "Each REST API has an OpenAPI 3.0 definition, printed in the Markdown copy of every reference page and served by each instance at `/docs/index.html`, and the GraphQL schema is open to introspection. MCP tools take typed inputs and declare an output schema. We found no single public file to download (22 of 25). developer.collibra.com publishes `llms.txt`, a Markdown copy of each page and an MCP server for the documentation (10). MCP tool descriptions state purpose, required permissions and the tool to call next, and the server ships an instructions file. REST operations carry a one-line summary (15 of 20). Request schemas use enums, defaults, minimum and maximum values and required fields. The Output Module takes a query document of its own (13 of 15). Tutorials cover authentication, pagination and import with examples. Error responses are generic descriptions for 400, 401, 403, 404 and 500, plus a table of four JWT error codes (10 of 15). Paths carry a version (`/rest/2.0`, `/v1`), release notes appear monthly and the Output Module guide keeps a dated list of changes. The API compatibility page showed our reader no content (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "The local MCP server registers 30 tools by default and keeps 18 data quality tools behind a flag, with allow and deny lists for tool names. GraphQL queries select fields, and REST lists take `limit` (21 of 25). REST paging is by `offset` and `limit` or by `cursor` with `nextCursor`, with filters on most list operations and a `countLimit` switch to skip the total. GraphQL takes `where`, `order`, `limit` and `offset` (19 of 20). Errors are standard HTTP codes with short descriptions, and the MCP source returns messages that list the valid options when a name does not resolve. No catalogue of API error codes was found (13 of 20). Every MCP tool declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the destructive data quality tools return a preview until called with `confirm=true`. The Import API matches resources by identifier, so a repeated import updates in place. No idempotency keys on the REST APIs (15 of 20). Defaults are sensible (20 search results, 10 GraphQL items). We found no official SDK. The portal has a tutorial on generating a client from the OpenAPI definition, and a CLI binary with two command groups (7 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 68,
            "points": 11.9,
            "reason": "OAuth 2.0 client credentials for integration applications, which act as an application-specific system user, and an authorisation code flow with PKCE for MCP clients. Tokens are valid for 5 minutes. The OAuth settings page says Collibra assigns all scopes to the client, so permissions follow Collibra roles. HTTP Basic with a username and password remains the first method in the tutorials and the only one in the local MCP server (22 of 30). The MCP server respects the signed-in account's permissions, names the permission each tool needs, keeps write-heavy data quality tools off by default and asks for `confirm=true` before a delete. `create_asset` and `edit_asset` write without a confirmation step (15 of 20). Tools return descriptions, comments and definitions written by catalogue users, and we found no prompt-injection guidance (3 of 15). An Activities API and asset history record changes, OAuth actions are attributed to the application's system user, and the Security Policy keeps logs for up to a year (11 of 15). SOC 1, SOC 2, ISO 27001, 27017, 27018 and 42001, FedRAMP Moderate and TISAX per the trust centre, annual third-party penetration tests, and a bug bounty paying 10 to 500 US dollars. `security.txt` expired on 31 December 2025 and no public advisory page was found (17 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 0,
            "points": 0,
            "reason": "Hosted service, so the hosted rubric applies. No x402, MPP or L402 (0). No published prices. www.collibra.com/pricing returns 404 and the site links a demo request and a product tour (0). No free tier or self-serve trial was found. The Collibra Units included in a contract are an allowance inside a paid subscription (0). An agent needs a customer's administrator to register an OAuth application after a sales contract (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 76,
            "points": 6.65,
            "reason": "The release calendar shows 2026.09 reaching commercial production on 4 October 2026, and the local MCP server tagged v0.0.62 on 5 October (30). Releases 2026.07, 2026.08 and 2026.09 reached production on 26 July, 30 August and 4 October, and the MCP repository tagged 15 versions between 11 August and 5 October (20). Closed service, scored on the 15-point scale. Monthly release notes, an announcements page, a community site and a support policy with a 2-hour first response for urgent incidents. The MCP repository's 19 open items on GitHub are all pull requests, most from Collibra staff (11 of 15). No official SDKs and no entry in the official MCP registry. The CLI was last tagged v2.1.1 on 10 August 2026 (7 of 15). The MCP repository runs tests with the race detector and a linter on every push, uses Renovate and builds on Go 1.25 with the official MCP Go SDK 1.7.0 (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "note": "editorial 75, provenance 89",
            "reason": "Closed service under the published Master Collibra Agreement and Developer Terms. The local MCP server is Apache-2.0 and the CLI ships under a Binary Code Licence Agreement (15 of 30). The agreement allows export for 30 days after the term and then deletion on Collibra's standard schedule, and the Data Processing Addendum of 1 October 2026 sets deletion within 120 days of termination and breach notice without undue delay. The agreement bars sending customer data to a third party to train generative AI without written consent. The Privacy Policy says it does not cover data processed for customers. No retention period for a live subscription was found (24 of 30). An announcements page gives end-of-life dates, an 18-month deprecation period for retired REST properties and removal of the Metric feature in 2027.01. The API tutorial says breaks happen only in a major release after a deprecation message, and a supported versions policy is published (17 of 20). The subprocessor list of 8 September 2026 names each processor with its purpose and hosting location, and the addendum gives 30 days' notice of additions (19 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The local MCP server registers 30 tools by default and keeps 18 data quality tools behind a flag, with allow and deny lists for tool names. GraphQL queries select fields, and REST lists take `limit` (21 of 25). REST paging is by `offset` and `limit` or by `cursor` with `nextCursor`, with filters on most list operations and a `countLimit` switch to skip the total. GraphQL takes `where`, `order`, `limit` and `offset` (19 of 20). Errors are standard HTTP codes with short descriptions, and the MCP source returns messages that list the valid options when a name does not resolve. No catalogue of API error codes was found (13 of 20). Every MCP tool declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the destructive data quality tools return a preview until called with `confirm=true`. The Import API matches resources by identifier, so a repeated import updates in place. No idempotency keys on the REST APIs (15 of 20). Defaults are sensible (20 search results, 10 GraphQL items). We found no official SDK. The portal has a tutorial on generating a client from the OpenAPI definition, and a CLI binary with two command groups (7 of 15).",
            "maintenance": "The release calendar shows 2026.09 reaching commercial production on 4 October 2026, and the local MCP server tagged v0.0.62 on 5 October (30). Releases 2026.07, 2026.08 and 2026.09 reached production on 26 July, 30 August and 4 October, and the MCP repository tagged 15 versions between 11 August and 5 October (20). Closed service, scored on the 15-point scale. Monthly release notes, an announcements page, a community site and a support policy with a 2-hour first response for urgent incidents. The MCP repository's 19 open items on GitHub are all pull requests, most from Collibra staff (11 of 15). No official SDKs and no entry in the official MCP registry. The CLI was last tagged v2.1.1 on 10 August 2026 (7 of 15). The MCP repository runs tests with the race detector and a linter on every push, uses Renovate and builds on Go 1.25 with the official MCP Go SDK 1.7.0 (8 of 10).",
            "payments": "Hosted service, so the hosted rubric applies. No x402, MPP or L402 (0). No published prices. www.collibra.com/pricing returns 404 and the site links a demo request and a product tour (0). No free tier or self-serve trial was found. The Collibra Units included in a contract are an allowance inside a paid subscription (0). An agent needs a customer's administrator to register an OAuth application after a sales contract (0).",
            "reliability": "Hosted service, read on the hosted lines and graded on the REST and GraphQL APIs of a Collibra cloud instance, with the MCP server as a second surface. status.collibra.com lists six components for each of four regions with an incident history (20). In the 90 days to 9 October 2026 the page shows a lineage and integrations disruption from 24 July to 14 August in all regions, where two ingestion methods created duplicate mapping IDs, and the close on 5 August of a UAE region disruption that began on 1 March. The page reported all systems normal for the 55 days before our check (15 of 30). No general request rate limit was found. The OAuth settings page gives a pool of 100 token requests for each client refilled at 30 a minute, Knowledge Graph queries stop at 100,000 nodes, and 8 imports run concurrently (7 of 15). A 429 is documented for the token endpoint with its causes, and the Import API guide says to retry a job that fails on a concurrency error. No `Retry-After` header or idempotency key was found (6 of 15). The Service Level Agreement of 1 October 2023 sets a 99.5 per cent monthly uptime target with service credits (10). The REST APIs are generally available. The hosted MCP documentation states no status, and the local server is at v0.0.62 (8 of 10).",
            "schema": "Each REST API has an OpenAPI 3.0 definition, printed in the Markdown copy of every reference page and served by each instance at `/docs/index.html`, and the GraphQL schema is open to introspection. MCP tools take typed inputs and declare an output schema. We found no single public file to download (22 of 25). developer.collibra.com publishes `llms.txt`, a Markdown copy of each page and an MCP server for the documentation (10). MCP tool descriptions state purpose, required permissions and the tool to call next, and the server ships an instructions file. REST operations carry a one-line summary (15 of 20). Request schemas use enums, defaults, minimum and maximum values and required fields. The Output Module takes a query document of its own (13 of 15). Tutorials cover authentication, pagination and import with examples. Error responses are generic descriptions for 400, 401, 403, 404 and 500, plus a table of four JWT error codes (10 of 15). Paths carry a version (`/rest/2.0`, `/v1`), release notes appear monthly and the Output Module guide keeps a dated list of changes. The API compatibility page showed our reader no content (13 of 15).",
            "security": "OAuth 2.0 client credentials for integration applications, which act as an application-specific system user, and an authorisation code flow with PKCE for MCP clients. Tokens are valid for 5 minutes. The OAuth settings page says Collibra assigns all scopes to the client, so permissions follow Collibra roles. HTTP Basic with a username and password remains the first method in the tutorials and the only one in the local MCP server (22 of 30). The MCP server respects the signed-in account's permissions, names the permission each tool needs, keeps write-heavy data quality tools off by default and asks for `confirm=true` before a delete. `create_asset` and `edit_asset` write without a confirmation step (15 of 20). Tools return descriptions, comments and definitions written by catalogue users, and we found no prompt-injection guidance (3 of 15). An Activities API and asset history record changes, OAuth actions are attributed to the application's system user, and the Security Policy keeps logs for up to a year (11 of 15). SOC 1, SOC 2, ISO 27001, 27017, 27018 and 42001, FedRAMP Moderate and TISAX per the trust centre, annual third-party penetration tests, and a bug bounty paying 10 to 500 US dollars. `security.txt` expired on 31 December 2025 and no public advisory page was found (17 of 20).",
            "transparency": "Closed service under the published Master Collibra Agreement and Developer Terms. The local MCP server is Apache-2.0 and the CLI ships under a Binary Code Licence Agreement (15 of 30). The agreement allows export for 30 days after the term and then deletion on Collibra's standard schedule, and the Data Processing Addendum of 1 October 2026 sets deletion within 120 days of termination and breach notice without undue delay. The agreement bars sending customer data to a third party to train generative AI without written consent. The Privacy Policy says it does not cover data processed for customers. No retention period for a live subscription was found (24 of 30). An announcements page gives end-of-life dates, an 18-month deprecation period for retired REST properties and removal of the Metric feature in 2027.01. The API tutorial says breaks happen only in a major release after a deprecation message, and a supported versions policy is published (17 of 20). The subprocessor list of 8 September 2026 names each processor with its purpose and hosting location, and the addendum gives 30 days' notice of additions (19 of 20)."
          },
          "sources": [
            {
              "what": "developer portal index (llms.txt)",
              "url": "https://developer.collibra.com/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "API overview",
              "url": "https://developer.collibra.com/api/api.md",
              "seen": "2026-10-09"
            },
            {
              "what": "API visibility and compatibility statement",
              "url": "https://developer.collibra.com/tutorials/collibra-apis.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Basic authentication tutorial",
              "url": "https://developer.collibra.com/tutorials/collibra-rest-api-authentication.md",
              "seen": "2026-10-09"
            },
            {
              "what": "JWT authentication tutorial and error codes",
              "url": "https://developer.collibra.com/tutorials/collibra-rest-api-authentication-with-json-web-token.md",
              "seen": "2026-10-09"
            },
            {
              "what": "OAuth 2.0 authorisation API reference",
              "url": "https://developer.collibra.com/api/references/oauth/oauth-2-authorization.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Core REST API assets reference with OpenAPI",
              "url": "https://developer.collibra.com/api/references/data-governance/assets.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Search API reference",
              "url": "https://developer.collibra.com/api/references/search/search.md",
              "seen": "2026-10-09"
            },
            {
              "what": "cursor-based pagination",
              "url": "https://developer.collibra.com/tutorials/cursor-based-pagination.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Knowledge Graph limits",
              "url": "https://developer.collibra.com/api/guides/knowledge-graph/limits.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Import API concurrent import",
              "url": "https://developer.collibra.com/api/guides/import-api/concurrent-import.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Output Module list of changes",
              "url": "https://developer.collibra.com/api/guides/output-module/whats-new.md",
              "seen": "2026-10-09"
            },
            {
              "what": "CLI documentation",
              "url": "https://developer.collibra.com/cli/cli.md",
              "seen": "2026-10-09"
            },
            {
              "what": "documentation MCP server",
              "url": "https://developer.collibra.com/tutorials/connect-ai-tools-to-the-developer-portal-with-mcp.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Collibra MCP server overview",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_mcp.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP integration and authentication",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_integrating-with-collibra-mcp.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP tools reference",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ref_mcp-tools.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "hosted MCP URL and Claude set-up",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ta_claude-desktop-mcp.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "OAuth applications settings",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/Settings/OAuth/co_oauth-settings.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "release calendar",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_release-calendar.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "announcements and deprecations",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_announcements.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "supported versions policy",
              "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/co_supported-versions-policy.htm",
              "seen": "2026-10-09"
            },
            {
              "what": "local MCP server source, README and tags",
              "url": "https://github.com/collibra/chip",
              "seen": "2026-10-09"
            },
            {
              "what": "CLI release repository and tags",
              "url": "https://github.com/collibra/collibra-cli-releases",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://status.collibra.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "incident history",
              "url": "https://status.collibra.com/incidents",
              "seen": "2026-10-09"
            },
            {
              "what": "customer agreements index",
              "url": "https://www.collibra.com/legal/agreements",
              "seen": "2026-10-09"
            },
            {
              "what": "Master Collibra Agreement",
              "url": "https://www.collibra.com/legal/documents/master-collibra-agreement",
              "seen": "2026-10-09"
            },
            {
              "what": "Developer Terms",
              "url": "https://www.collibra.com/legal/documents/collibra-developer-terms",
              "seen": "2026-10-09"
            },
            {
              "what": "Service Level Agreement",
              "url": "https://www.collibra.com/legal/documents/collibra-service-level-agreement",
              "seen": "2026-10-09"
            },
            {
              "what": "Data Processing Addendum",
              "url": "https://www.collibra.com/legal/documents/collibra-data-processing-addendum",
              "seen": "2026-10-09"
            },
            {
              "what": "subprocessor list",
              "url": "https://www.collibra.com/legal/documents/collibra-subprocessors",
              "seen": "2026-10-09"
            },
            {
              "what": "Security Policy",
              "url": "https://www.collibra.com/legal/documents/collibra-security-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "Support Policy",
              "url": "https://www.collibra.com/legal/documents/collibra-support-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "Collibra Units factsheet",
              "url": "https://www.collibra.com/legal/documents/collibra-units",
              "seen": "2026-10-09"
            },
            {
              "what": "bug bounty rules",
              "url": "https://www.collibra.com/legal/documents/collibra-bug-bounty-program-rules",
              "seen": "2026-10-09"
            },
            {
              "what": "Privacy Policy",
              "url": "https://www.collibra.com/legal/documents/collibra-privacy-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "Website Terms of Use",
              "url": "https://www.collibra.com/legal/documents/collibra-website-terms-of-use",
              "seen": "2026-10-09"
            },
            {
              "what": "trust centre",
              "url": "https://www.collibra.com/company/trust-center",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt",
              "url": "https://www.collibra.com/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing address (404)",
              "url": "https://www.collibra.com/pricing",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/collibra.com",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP registry search, no result",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=collibra",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "The lead said the only MCP server serves the documentation. Collibra also documents a hosted catalogue MCP server at `/rest/mcp` and publishes a local one, and both are graded here as a second surface.",
            "unchecked: the API compatibility page at productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_compatibility-api.htm showed only navigation to our reader, so the list of API changes by release is unread.",
            "No general REST or GraphQL request rate limit and no `Retry-After` guidance were found in the developer portal or the product documentation pages we read. A limit may be documented on a page we did not open.",
            "Whether the hosted MCP server is generally available or in preview is not stated on the pages read. The overview page is dated 26 June 2026.",
            "The hosted MCP server's tool definitions were read from the documentation table and the open-source repository, not from a live `tools/list`, so the count on a given instance may differ.",
            "No self-serve trial was found. The subprocessor list names a vendor for trial and beta testing and an Evaluation Agreement is published, so evaluations may exist through sales.",
            "The Developer Terms and the Master Collibra Agreement forbid publishing benchmarks or performance information, and the Developer Terms forbid testing the toolkit's capabilities. This matters before our probes run.",
            "The legal documents are PDFs behind cover pages, which the site's terms and privacy reader may not fetch.",
            "One request went to rdap.verisign.com before its robots.txt was fetched. The robots.txt request answered 400, so nothing was disallowed.",
            "The year Collibra first released the platform was not established from the pages read, so `firstReleased` is null."
          ]
        },
        "negative": 0,
        "verdict": "Each REST API has an OpenAPI 3.0 definition, the developer portal publishes llms.txt and Markdown pages, and every MCP tool carries read-only and destructive annotations. Access needs a sales contract, since no price, trial or self-serve sign-up is published, and no general API rate limit was found in the reviewed documentation.",
        "bestFor": "An organisation that already runs Collibra and wants an agent to look up assets, glossary terms, lineage and data quality, or to write assets and classifications under a governed role.",
        "strengths": [
          "OpenAPI 3.0 definitions for each REST API, printed on every reference page of developer.collibra.com and served by each instance at `/docs/index.html`",
          "The developer portal publishes `llms.txt`, a Markdown copy of every page and an MCP server for searching the documentation",
          "Every tool in the open-source MCP server declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the 18 data quality tools stay unregistered until a flag is set",
          "OAuth 2.0 client credentials for integrations and an authorisation code flow with PKCE for MCP clients, with access tokens valid for 5 minutes",
          "A 99.5 per cent monthly uptime target with service credits of 1 to 15 per cent, and an 18-month deprecation period announced for retired REST properties"
        ],
        "weaknesses": [
          "No published price, trial or self-serve sign-up. The pricing address returns 404 and the site links a demo request and a product tour",
          "No general request rate limit or `Retry-After` guidance found. Only the OAuth token endpoint has numbers, a pool of 100 tokens refilled at 30 a minute",
          "The Developer Terms of 22 August 2023 forbid publishing benchmarks and calls not driven by bona fide end user requests, except reasonable testing",
          "No prompt-injection guidance found, although tools return descriptions and comments written by catalogue users",
          "The local MCP server signs in with a Collibra username and password only, and `security.txt` expired on 31 December 2025"
        ],
        "agentNotes": [
          "Ask a Collibra administrator to register an OAuth application. Integration applications use client credentials, and MCP clients need a user application with a redirect URI",
          "Reuse each access token for its 5 minutes. The token endpoint answers 429 once a client drains its pool of 100 tokens, refilled at 30 a minute",
          "Page large reads with `cursor=` and `sortField=ID`. Cursor and offset parameters cannot be combined, and Search API `limit` plus `offset` cannot exceed 10,000",
          "Keep Import API files to 10,000 assets or fewer and run at most 8 imports at once. Retry a job that fails on a concurrency error",
          "Expect `discover_data_assets` and `discover_business_glossary` to consume Collibra Units and to need the `dgc.ai-copilot` permission. Use `search_asset_keyword` for free keyword search"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 76,
          "payments": 0,
          "reliability": 66,
          "schema": 83,
          "security": 68,
          "transparency": 75
        },
        "provenanceScore": 89
      },
      "connect": {
        "http": "curl -H 'Authorization: Bearer \u003ctoken\u003e' https://\u003cinstance\u003e.collibra.com/rest/2.0/communities",
        "config": {
          "mcpServers": {
            "collibra": {
              "command": "/path/to/chip-...",
              "type": "stdio"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/data.catalogue",
        "tool": "https://letme.dev/collibra"
      },
      "notable": [
        "The developer portal documents a Core REST API under `/rest/2.0`, Import, Search, Catalogue, Data Quality, Protect and OAuth APIs, and two GraphQL APIs, Knowledge Graph and Data Access (https://developer.collibra.com/llms.txt)",
        "A hosted MCP server answers on each commercial cloud instance at `https://\u003ctenant\u003e.collibra.com/rest/mcp` over streamable HTTP with OAuth 2.0. It is not available for Collibra Platform for Government or self-hosted deployments (https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ta_claude-desktop-mcp.htm)",
        "The open-source local MCP server lists 48 tools in its README. 30 are registered by default (22 read, 8 write), and 18 data quality tools need the `--data-quality` flag (https://github.com/collibra/chip)",
        "The lead for this listing said the only MCP server serves the documentation. That server exists at `https://developer.collibra.com/~gitbook/mcp`, and Collibra also documents the catalogue MCP server above (https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_mcp.htm)",
        "Access tokens are valid for 5 minutes, and each OAuth client has a pool of 100 token requests refilled at 30 a minute, with a 429 beyond it (https://productresources.collibra.com/docs/collibra/latest/Content/Settings/OAuth/co_oauth-settings.htm)",
        "The Developer Terms of 22 August 2023 forbid publishing benchmarks or performance information, testing the capabilities of the toolkit, and calls not driven by bona fide end user requests except reasonable testing (https://www.collibra.com/legal/documents/collibra-developer-terms)",
        "status.collibra.com showed all systems normal for 55 days on 9 October 2026. A lineage and integrations disruption ran from 24 July to 14 August 2026 in all regions (https://status.collibra.com/incidents)",
        "Release 2026.09 reached commercial production on 4 October 2026, and monthly releases reach production three weeks after pre-production (https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_release-calendar.htm)",
        "Each page of developer.collibra.com ends with a block headed Agent Instructions that tells AI agents how to query the documentation with an `ask` parameter. We did not act on it"
      ],
      "area": "business",
      "details": [
        {
          "label": "APIs",
          "value": "Core REST API under `/rest/2.0` for assets, domains, communities, relations, responsibilities, workflows and activities, plus Import, Search, Catalogue, Technical Lineage, Data Quality, Protect, Edge and OAuth APIs. GraphQL Knowledge Graph API at `/graphql/knowledgeGraph/v1` and a Data Access GraphQL API"
        },
        {
          "label": "MCP server",
          "value": "Hosted at `https://\u003ctenant\u003e.collibra.com/rest/mcp` on commercial cloud instances, streamable HTTP with OAuth 2.0. Local server `chip` (Go, Apache-2.0, v0.0.62 of 5 October 2026) over stdio or HTTP, 30 tools by default and 18 data quality tools behind a flag"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 client credentials for integration applications, authorisation code flow with PKCE for user applications, 5-minute tokens. HTTP Basic with a username and password, or a JWT Bearer token from the customer's identity provider"
        },
        {
          "label": "Rate limits",
          "value": "No general request limit found in the reviewed documentation. OAuth token requests draw on a pool of 100 for each client, refilled at 30 a minute. Knowledge Graph queries stop at 100,000 nodes, and up to 8 imports run concurrently"
        },
        {
          "label": "Errors",
          "value": "HTTP 400, 401, 403, 404 and 500 with a description in each OpenAPI definition, and four JWT error codes such as `expiredToken` with a suggested action"
        },
        {
          "label": "Pagination",
          "value": "`offset` and `limit` with a `total`, or `cursor` and `nextCursor` sorted by `ID`. The two cannot be combined. Search allows a `limit` of 1,000 and `limit` plus `offset` up to 10,000. GraphQL collections default to 10 items"
        },
        {
          "label": "Pricing",
          "value": "Sales contract only. No published price, trial or self-serve sign-up found. AI functions draw on Collibra Units, 70,000 or 100,000 included in each contract"
        },
        {
          "label": "SLA and support",
          "value": "99.5 per cent monthly uptime target with service credits of 1 to 15 per cent, or 5 to 20 per cent with Premium Support. Standard support answers an urgent incident within 2 hours, 24 hours a day"
        },
        {
          "label": "CLI",
          "value": "`collibra` binary v2.1.1 of 10 August 2026 for Windows, Linux and macOS, with `ai-gov` and `data-contract` command groups. The macOS build is not yet signed with an Apple key, per the docs"
        },
        {
          "label": "Hosting",
          "value": "AWS and Google Cloud in the United States, European Union, Canada, United Kingdom, Australia or Singapore, per the subprocessor list of 8 September 2026. Instances answer on `\u003cinstance\u003e.collibra.com`"
        },
        {
          "label": "Certifications",
          "value": "SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, FedRAMP Moderate, HIPAA and TISAX, per the trust centre. Annual third-party penetration tests, per the Security Policy"
        },
        {
          "label": "Status",
          "value": "status.collibra.com with six components for each of AMER, APAC, EMEA and GovCloud, and an incident history"
        }
      ],
      "provenance": {
        "legalEntity": "Collibra Inc.",
        "domain": "collibra.com",
        "domainRegistered": "2007-06-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.collibra.com/legal/documents/master-collibra-agreement",
        "privacy": "https://www.collibra.com/legal/documents/collibra-privacy-policy",
        "statusPage": "https://status.collibra.com",
        "changelog": "https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/to_release-notes.htm",
        "securityTxt": "expired",
        "checked": "2026-10-09",
        "notes": [
          "The Master Collibra Agreement (click-through version of 6 August 2026) is with Collibra Inc., 28 Liberty Street, Suite 4050, New York, NY 10005 for orders shipped to North America, and with Collibra UK Limited, Broadgate Tower, 20 Primrose Street, London for all others. The second is governed by the law of England and Wales.",
          "The Developer Terms (22 August 2023) and the Privacy Policy (24 September 2026) name Collibra Belgium BV and its affiliates.",
          "Each legal page on www.collibra.com is a cover page that links a PDF on images.collibracloud.com. We read the PDFs.",
          "The Privacy Policy covers Collibra's websites and says it does not apply to personal information Collibra processes for customers. That is governed by the Data Processing Addendum of 1 October 2026 at https://www.collibra.com/legal/documents/collibra-data-processing-addendum.",
          "www.collibra.com/.well-known/security.txt carries `Expires: 2025-12-31T00:00:00Z`. It names a security requests page and the bug bounty rules.",
          "RDAP gives collibra.com a registration date of 2007-06-30."
        ],
        "score": 89,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Collibra Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "collibra.com, registered 2007-06-30 (19 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "collibra.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.collibra.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.collibra.com/legal/documents/master-collibra-agreement",
            "state": "unreadable",
            "reason": "the page is a cover page that links the document as a PDF, not the document itself",
            "readAt": "2026-10-09",
            "points": 7,
            "max": 10
          },
          {
            "kind": "privacy",
            "url": "https://www.collibra.com/legal/documents/collibra-privacy-policy",
            "state": "unreadable",
            "reason": "the page is a cover page that links the document as a PDF, not the document itself",
            "readAt": "2026-10-09",
            "points": 7,
            "max": 10
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/collibra.json",
      "live": {
        "slug": "collibra",
        "vendorStatus": {
          "page": "https://status.collibra.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:22.042462941Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "collibra/chip",
            "version": "v0.0.47",
            "released": "2026-08-07",
            "seenAt": "2026-10-09T16:46:58.350732285Z"
          }
        ],
        "githubStars": 37,
        "pages": [
          {
            "url": "https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/to_release-notes.htm",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:44:00.442312281Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "306e62e3e48e"
          },
          {
            "url": "https://www.collibra.com/legal/documents/collibra-privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:49:10.565608247Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f8dfb358e1c5"
          },
          {
            "url": "https://www.collibra.com/legal/documents/master-collibra-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:49:12.714609966Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "036a1ac5712a"
          }
        ],
        "updatedAt": "2026-10-10T00:50:22.042462941Z"
      }
    },
    "verify": {
      "accepts": "a page on collibra.com or one of its subdomains, or the README of github.com/collibra/chip",
      "badgeUrl": "https://www.anchorterminal.com/badges/collibra.svg",
      "body": {
        "slug": "collibra",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/collibra",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/collibra\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/collibra.svg\" alt=\"Collibra on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Collibra on Anchor Terminal](https://www.anchorterminal.com/badges/collibra.svg)](https://www.anchorterminal.com/tools/collibra)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/collibra\"\u003eCollibra on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/collibra",
    "json": "https://www.anchorterminal.com/tools/collibra.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/collibra.md",
    "slim": "https://www.anchorterminal.com/tools/collibra.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 64.6/100 · rank #346 of 950 · #4 in Company knowledge \u0026 data catalogues · not agent-ready · confidence medium**\n\n\n## Assessment\n\nEach REST API has an OpenAPI 3.0 definition, the developer portal publishes llms.txt and Markdown pages, and every MCP tool carries read-only and destructive annotations. Access needs a sales contract, since no price, trial or self-serve sign-up is published, and no general API rate limit was found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Collibra (https://www.collibra.com) |\n| Kind | HTTP API |\n| Category | Company knowledge \u0026 data catalogues (https://www.anchorterminal.com/categories/company-knowledge) |\n| Transport | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key · Access is granted inside a customer's Collibra environment. An administrator with the System administration permission registers an OAuth application under Settings. Integration applications use the client credentials flow at `/rest/oauth/v2/token` and act as an application-specific system user, and user applications use the authorisation code flow with PKCE for MCP clients. Tokens are valid for 5 minutes, and the settings page says Collibra assigns all scopes to the client. The APIs also accept HTTP Basic authentication with a Collibra username and password, and a JWT Bearer token issued by the customer's identity provider. The local MCP server accepts a username and password only. Permissions follow the user's Collibra roles. |\n| Pricing | Paid (Paid) · No prices are published. www.collibra.com/pricing returns 404, and the site links a demo request and a product tour. We found no trial or self-serve sign-up, so an agent cannot start without a contract. An Evaluation Agreement is published for evaluations arranged with Collibra. The MCP server is free to use, and AI functions such as the natural-language discovery tools consume Collibra Units, with 70,000 or 100,000 units included in each contract depending on the package (checked 2026-10-09). |\n| x402 | No · No x402, MPP or L402 in the developer portal, the MCP server source or the legal documents (checked 2026-10-09). |\n| Licence | Proprietary service under the Master Collibra Agreement, with the Developer Terms for the REST APIs and CLI. The local MCP server (chip) is Apache-2.0, and the CLI binary ships under a Binary Code Licence Agreement |\n| Tools exposed | 30 |\n| Source | https://github.com/collibra/chip |\n| Docs | https://developer.collibra.com/ |\n| llms.txt | https://developer.collibra.com/llms.txt |\n| Last release | 2026-10-04 |\n| GitHub stars | 37 (as of 2026-10-09) |\n| APIs | Core REST API under `/rest/2.0` for assets, domains, communities, relations, responsibilities, workflows and activities, plus Import, Search, Catalogue, Technical Lineage, Data Quality, Protect, Edge and OAuth APIs. GraphQL Knowledge Graph API at `/graphql/knowledgeGraph/v1` and a Data Access GraphQL API |\n| MCP server | Hosted at `https://\u003ctenant\u003e.collibra.com/rest/mcp` on commercial cloud instances, streamable HTTP with OAuth 2.0. Local server `chip` (Go, Apache-2.0, v0.0.62 of 5 October 2026) over stdio or HTTP, 30 tools by default and 18 data quality tools behind a flag |\n| Credentials | OAuth 2.0 client credentials for integration applications, authorisation code flow with PKCE for user applications, 5-minute tokens. HTTP Basic with a username and password, or a JWT Bearer token from the customer's identity provider |\n| Rate limits | No general request limit found in the reviewed documentation. OAuth token requests draw on a pool of 100 for each client, refilled at 30 a minute. Knowledge Graph queries stop at 100,000 nodes, and up to 8 imports run concurrently |\n| Errors | HTTP 400, 401, 403, 404 and 500 with a description in each OpenAPI definition, and four JWT error codes such as `expiredToken` with a suggested action |\n| Pagination | `offset` and `limit` with a `total`, or `cursor` and `nextCursor` sorted by `ID`. The two cannot be combined. Search allows a `limit` of 1,000 and `limit` plus `offset` up to 10,000. GraphQL collections default to 10 items |\n| Pricing | Sales contract only. No published price, trial or self-serve sign-up found. AI functions draw on Collibra Units, 70,000 or 100,000 included in each contract |\n| SLA and support | 99.5 per cent monthly uptime target with service credits of 1 to 15 per cent, or 5 to 20 per cent with Premium Support. Standard support answers an urgent incident within 2 hours, 24 hours a day |\n| CLI | `collibra` binary v2.1.1 of 10 August 2026 for Windows, Linux and macOS, with `ai-gov` and `data-contract` command groups. The macOS build is not yet signed with an Apple key, per the docs |\n| Hosting | AWS and Google Cloud in the United States, European Union, Canada, United Kingdom, Australia or Singapore, per the subprocessor list of 8 September 2026. Instances answer on `\u003cinstance\u003e.collibra.com` |\n| Certifications | SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, FedRAMP Moderate, HIPAA and TISAX, per the trust centre. Annual third-party penetration tests, per the Security Policy |\n| Status | status.collibra.com with six components for each of AMER, APAC, EMEA and GovCloud, and an incident history |\n| Capabilities | data.catalogue, knowledge.search, data.lineage |\n| Tags | hosted, closed-source, enterprise, official, mcp, oauth, openapi, graphql, sales-led, status-page, sla, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/collibra.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 66 | 13.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 83 | 13.5 |\n| Agent ergonomics | 13% | 16.2 | 75 | 12.2 |\n| Security \u0026 auth | 14% | 17.5 | 68 | 11.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 0 | 0.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 76 | 6.7 |\n| Transparency \u0026 trust (editorial 75, provenance 89) | 7% | 8.8 | 82 | 7.2 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **64.6 → B** |\n\n### Why each score\n\n- Reliability 66: Hosted service, read on the hosted lines and graded on the REST and GraphQL APIs of a Collibra cloud instance, with the MCP server as a second surface. status.collibra.com lists six components for each of four regions with an incident history (20). In the 90 days to 9 October 2026 the page shows a lineage and integrations disruption from 24 July to 14 August in all regions, where two ingestion methods created duplicate mapping IDs, and the close on 5 August of a UAE region disruption that began on 1 March. The page reported all systems normal for the 55 days before our check (15 of 30). No general request rate limit was found. The OAuth settings page gives a pool of 100 token requests for each client refilled at 30 a minute, Knowledge Graph queries stop at 100,000 nodes, and 8 imports run concurrently (7 of 15). A 429 is documented for the token endpoint with its causes, and the Import API guide says to retry a job that fails on a concurrency error. No `Retry-After` header or idempotency key was found (6 of 15). The Service Level Agreement of 1 October 2023 sets a 99.5 per cent monthly uptime target with service credits (10). The REST APIs are generally available. The hosted MCP documentation states no status, and the local server is at v0.0.62 (8 of 10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 83: Each REST API has an OpenAPI 3.0 definition, printed in the Markdown copy of every reference page and served by each instance at `/docs/index.html`, and the GraphQL schema is open to introspection. MCP tools take typed inputs and declare an output schema. We found no single public file to download (22 of 25). developer.collibra.com publishes `llms.txt`, a Markdown copy of each page and an MCP server for the documentation (10). MCP tool descriptions state purpose, required permissions and the tool to call next, and the server ships an instructions file. REST operations carry a one-line summary (15 of 20). Request schemas use enums, defaults, minimum and maximum values and required fields. The Output Module takes a query document of its own (13 of 15). Tutorials cover authentication, pagination and import with examples. Error responses are generic descriptions for 400, 401, 403, 404 and 500, plus a table of four JWT error codes (10 of 15). Paths carry a version (`/rest/2.0`, `/v1`), release notes appear monthly and the Output Module guide keeps a dated list of changes. The API compatibility page showed our reader no content (13 of 15).\n- Agent ergonomics 75: The local MCP server registers 30 tools by default and keeps 18 data quality tools behind a flag, with allow and deny lists for tool names. GraphQL queries select fields, and REST lists take `limit` (21 of 25). REST paging is by `offset` and `limit` or by `cursor` with `nextCursor`, with filters on most list operations and a `countLimit` switch to skip the total. GraphQL takes `where`, `order`, `limit` and `offset` (19 of 20). Errors are standard HTTP codes with short descriptions, and the MCP source returns messages that list the valid options when a name does not resolve. No catalogue of API error codes was found (13 of 20). Every MCP tool declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the destructive data quality tools return a preview until called with `confirm=true`. The Import API matches resources by identifier, so a repeated import updates in place. No idempotency keys on the REST APIs (15 of 20). Defaults are sensible (20 search results, 10 GraphQL items). We found no official SDK. The portal has a tutorial on generating a client from the OpenAPI definition, and a CLI binary with two command groups (7 of 15).\n- Security \u0026 auth 68: OAuth 2.0 client credentials for integration applications, which act as an application-specific system user, and an authorisation code flow with PKCE for MCP clients. Tokens are valid for 5 minutes. The OAuth settings page says Collibra assigns all scopes to the client, so permissions follow Collibra roles. HTTP Basic with a username and password remains the first method in the tutorials and the only one in the local MCP server (22 of 30). The MCP server respects the signed-in account's permissions, names the permission each tool needs, keeps write-heavy data quality tools off by default and asks for `confirm=true` before a delete. `create_asset` and `edit_asset` write without a confirmation step (15 of 20). Tools return descriptions, comments and definitions written by catalogue users, and we found no prompt-injection guidance (3 of 15). An Activities API and asset history record changes, OAuth actions are attributed to the application's system user, and the Security Policy keeps logs for up to a year (11 of 15). SOC 1, SOC 2, ISO 27001, 27017, 27018 and 42001, FedRAMP Moderate and TISAX per the trust centre, annual third-party penetration tests, and a bug bounty paying 10 to 500 US dollars. `security.txt` expired on 31 December 2025 and no public advisory page was found (17 of 20).\n- Payments \u0026 pricing 0: Hosted service, so the hosted rubric applies. No x402, MPP or L402 (0). No published prices. www.collibra.com/pricing returns 404 and the site links a demo request and a product tour (0). No free tier or self-serve trial was found. The Collibra Units included in a contract are an allowance inside a paid subscription (0). An agent needs a customer's administrator to register an OAuth application after a sales contract (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 76: The release calendar shows 2026.09 reaching commercial production on 4 October 2026, and the local MCP server tagged v0.0.62 on 5 October (30). Releases 2026.07, 2026.08 and 2026.09 reached production on 26 July, 30 August and 4 October, and the MCP repository tagged 15 versions between 11 August and 5 October (20). Closed service, scored on the 15-point scale. Monthly release notes, an announcements page, a community site and a support policy with a 2-hour first response for urgent incidents. The MCP repository's 19 open items on GitHub are all pull requests, most from Collibra staff (11 of 15). No official SDKs and no entry in the official MCP registry. The CLI was last tagged v2.1.1 on 10 August 2026 (7 of 15). The MCP repository runs tests with the race detector and a linter on every push, uses Renovate and builds on Go 1.25 with the official MCP Go SDK 1.7.0 (8 of 10).\n- Transparency \u0026 trust 82: Closed service under the published Master Collibra Agreement and Developer Terms. The local MCP server is Apache-2.0 and the CLI ships under a Binary Code Licence Agreement (15 of 30). The agreement allows export for 30 days after the term and then deletion on Collibra's standard schedule, and the Data Processing Addendum of 1 October 2026 sets deletion within 120 days of termination and breach notice without undue delay. The agreement bars sending customer data to a third party to train generative AI without written consent. The Privacy Policy says it does not cover data processed for customers. No retention period for a live subscription was found (24 of 30). An announcements page gives end-of-life dates, an 18-month deprecation period for retired REST properties and removal of the Metric feature in 2027.01. The API tutorial says breaks happen only in a major release after a deprecation message, and a supported versions policy is published (17 of 20). The subprocessor list of 8 September 2026 names each processor with its purpose and hosting location, and the addendum gives 30 days' notice of additions (19 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/collibra.md (JSON https://www.anchorterminal.com/fixes/collibra.json)\n\n### What we couldn't check\n\n- The lead said the only MCP server serves the documentation. Collibra also documents a hosted catalogue MCP server at `/rest/mcp` and publishes a local one, and both are graded here as a second surface.\n- unchecked: the API compatibility page at productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_compatibility-api.htm showed only navigation to our reader, so the list of API changes by release is unread.\n- No general REST or GraphQL request rate limit and no `Retry-After` guidance were found in the developer portal or the product documentation pages we read. A limit may be documented on a page we did not open.\n- Whether the hosted MCP server is generally available or in preview is not stated on the pages read. The overview page is dated 26 June 2026.\n- The hosted MCP server's tool definitions were read from the documentation table and the open-source repository, not from a live `tools/list`, so the count on a given instance may differ.\n- No self-serve trial was found. The subprocessor list names a vendor for trial and beta testing and an Evaluation Agreement is published, so evaluations may exist through sales.\n- The Developer Terms and the Master Collibra Agreement forbid publishing benchmarks or performance information, and the Developer Terms forbid testing the toolkit's capabilities. This matters before our probes run.\n- The legal documents are PDFs behind cover pages, which the site's terms and privacy reader may not fetch.\n- One request went to rdap.verisign.com before its robots.txt was fetched. The robots.txt request answered 400, so nothing was disallowed.\n- The year Collibra first released the platform was not established from the pages read, so `firstReleased` is null.\n\n### Sources\n\n- developer portal index (llms.txt): \u003chttps://developer.collibra.com/llms.txt\u003e (seen 2026-10-09)\n- API overview: \u003chttps://developer.collibra.com/api/api.md\u003e (seen 2026-10-09)\n- API visibility and compatibility statement: \u003chttps://developer.collibra.com/tutorials/collibra-apis.md\u003e (seen 2026-10-09)\n- Basic authentication tutorial: \u003chttps://developer.collibra.com/tutorials/collibra-rest-api-authentication.md\u003e (seen 2026-10-09)\n- JWT authentication tutorial and error codes: \u003chttps://developer.collibra.com/tutorials/collibra-rest-api-authentication-with-json-web-token.md\u003e (seen 2026-10-09)\n- OAuth 2.0 authorisation API reference: \u003chttps://developer.collibra.com/api/references/oauth/oauth-2-authorization.md\u003e (seen 2026-10-09)\n- Core REST API assets reference with OpenAPI: \u003chttps://developer.collibra.com/api/references/data-governance/assets.md\u003e (seen 2026-10-09)\n- Search API reference: \u003chttps://developer.collibra.com/api/references/search/search.md\u003e (seen 2026-10-09)\n- cursor-based pagination: \u003chttps://developer.collibra.com/tutorials/cursor-based-pagination.md\u003e (seen 2026-10-09)\n- Knowledge Graph limits: \u003chttps://developer.collibra.com/api/guides/knowledge-graph/limits.md\u003e (seen 2026-10-09)\n- Import API concurrent import: \u003chttps://developer.collibra.com/api/guides/import-api/concurrent-import.md\u003e (seen 2026-10-09)\n- Output Module list of changes: \u003chttps://developer.collibra.com/api/guides/output-module/whats-new.md\u003e (seen 2026-10-09)\n- CLI documentation: \u003chttps://developer.collibra.com/cli/cli.md\u003e (seen 2026-10-09)\n- documentation MCP server: \u003chttps://developer.collibra.com/tutorials/connect-ai-tools-to-the-developer-portal-with-mcp.md\u003e (seen 2026-10-09)\n- Collibra MCP server overview: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_mcp.htm\u003e (seen 2026-10-09)\n- MCP integration and authentication: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_integrating-with-collibra-mcp.htm\u003e (seen 2026-10-09)\n- MCP tools reference: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ref_mcp-tools.htm\u003e (seen 2026-10-09)\n- hosted MCP URL and Claude set-up: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ta_claude-desktop-mcp.htm\u003e (seen 2026-10-09)\n- OAuth applications settings: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/Settings/OAuth/co_oauth-settings.htm\u003e (seen 2026-10-09)\n- release calendar: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_release-calendar.htm\u003e (seen 2026-10-09)\n- announcements and deprecations: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_announcements.htm\u003e (seen 2026-10-09)\n- supported versions policy: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/co_supported-versions-policy.htm\u003e (seen 2026-10-09)\n- local MCP server source, README and tags: \u003chttps://github.com/collibra/chip\u003e (seen 2026-10-09)\n- CLI release repository and tags: \u003chttps://github.com/collibra/collibra-cli-releases\u003e (seen 2026-10-09)\n- status page: \u003chttps://status.collibra.com/\u003e (seen 2026-10-09)\n- incident history: \u003chttps://status.collibra.com/incidents\u003e (seen 2026-10-09)\n- customer agreements index: \u003chttps://www.collibra.com/legal/agreements\u003e (seen 2026-10-09)\n- Master Collibra Agreement: \u003chttps://www.collibra.com/legal/documents/master-collibra-agreement\u003e (seen 2026-10-09)\n- Developer Terms: \u003chttps://www.collibra.com/legal/documents/collibra-developer-terms\u003e (seen 2026-10-09)\n- Service Level Agreement: \u003chttps://www.collibra.com/legal/documents/collibra-service-level-agreement\u003e (seen 2026-10-09)\n- Data Processing Addendum: \u003chttps://www.collibra.com/legal/documents/collibra-data-processing-addendum\u003e (seen 2026-10-09)\n- subprocessor list: \u003chttps://www.collibra.com/legal/documents/collibra-subprocessors\u003e (seen 2026-10-09)\n- Security Policy: \u003chttps://www.collibra.com/legal/documents/collibra-security-policy\u003e (seen 2026-10-09)\n- Support Policy: \u003chttps://www.collibra.com/legal/documents/collibra-support-policy\u003e (seen 2026-10-09)\n- Collibra Units factsheet: \u003chttps://www.collibra.com/legal/documents/collibra-units\u003e (seen 2026-10-09)\n- bug bounty rules: \u003chttps://www.collibra.com/legal/documents/collibra-bug-bounty-program-rules\u003e (seen 2026-10-09)\n- Privacy Policy: \u003chttps://www.collibra.com/legal/documents/collibra-privacy-policy\u003e (seen 2026-10-09)\n- Website Terms of Use: \u003chttps://www.collibra.com/legal/documents/collibra-website-terms-of-use\u003e (seen 2026-10-09)\n- trust centre: \u003chttps://www.collibra.com/company/trust-center\u003e (seen 2026-10-09)\n- security.txt: \u003chttps://www.collibra.com/.well-known/security.txt\u003e (seen 2026-10-09)\n- pricing address (404): \u003chttps://www.collibra.com/pricing\u003e (seen 2026-10-09)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/collibra.com\u003e (seen 2026-10-09)\n- MCP registry search, no result: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=collibra\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 89/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Collibra Inc. | 20/20 |\n| Domain age | collibra.com, registered 2007-06-30 (19 years) | 15/15 |\n| Endpoint on the vendor's domain | collibra.com | 15/15 |\n| Terms of service | published, but our reader couldn't read it | 7/10 |\n| Privacy policy | published, but our reader couldn't read it | 7/10 |\n| Status page | status.collibra.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe Master Collibra Agreement (click-through version of 6 August 2026) is with Collibra Inc., 28 Liberty Street, Suite 4050, New York, NY 10005 for orders shipped to North America, and with Collibra UK Limited, Broadgate Tower, 20 Primrose Street, London for all others. The second is governed by the law of England and Wales.\n\nThe Developer Terms (22 August 2023) and the Privacy Policy (24 September 2026) name Collibra Belgium BV and its affiliates.\n\nEach legal page on www.collibra.com is a cover page that links a PDF on images.collibracloud.com. We read the PDFs.\n\nThe Privacy Policy covers Collibra's websites and says it does not apply to personal information Collibra processes for customers. That is governed by the Data Processing Addendum of 1 October 2026 at https://www.collibra.com/legal/documents/collibra-data-processing-addendum.\n\nwww.collibra.com/.well-known/security.txt carries `Expires: 2025-12-31T00:00:00Z`. It names a security requests page and the bug bounty rules.\n\nRDAP gives collibra.com a registration date of 2007-06-30.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.collibra.com/legal/documents/master-collibra-agreement), read 2026-10-09. Our reader couldn't read it (the page is a cover page that links the document as a PDF, not the document itself).\n\n\n**Privacy policy** (https://www.collibra.com/legal/documents/collibra-privacy-policy), read 2026-10-09. Our reader couldn't read it (the page is a cover page that links the document as a PDF, not the document itself).\n\n\n## Live (updated 2026-10-10 00:50 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- github `collibra/chip` v0.0.47, released 2026-08-07\n- Watching changelog \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/to_release-notes.htm\u003e\n- Watching privacy \u003chttps://www.collibra.com/legal/documents/collibra-privacy-policy\u003e\n- Watching terms \u003chttps://www.collibra.com/legal/documents/master-collibra-agreement\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/collibra.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- OpenAPI 3.0 definitions for each REST API, printed on every reference page of developer.collibra.com and served by each instance at `/docs/index.html`\n- The developer portal publishes `llms.txt`, a Markdown copy of every page and an MCP server for searching the documentation\n- Every tool in the open-source MCP server declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the 18 data quality tools stay unregistered until a flag is set\n- OAuth 2.0 client credentials for integrations and an authorisation code flow with PKCE for MCP clients, with access tokens valid for 5 minutes\n- A 99.5 per cent monthly uptime target with service credits of 1 to 15 per cent, and an 18-month deprecation period announced for retired REST properties\n\n## Weaknesses\n\n- No published price, trial or self-serve sign-up. The pricing address returns 404 and the site links a demo request and a product tour\n- No general request rate limit or `Retry-After` guidance found. Only the OAuth token endpoint has numbers, a pool of 100 tokens refilled at 30 a minute\n- The Developer Terms of 22 August 2023 forbid publishing benchmarks and calls not driven by bona fide end user requests, except reasonable testing\n- No prompt-injection guidance found, although tools return descriptions and comments written by catalogue users\n- The local MCP server signs in with a Collibra username and password only, and `security.txt` expired on 31 December 2025\n\n## Before you call it (notes for agents)\n\n1. Ask a Collibra administrator to register an OAuth application. Integration applications use client credentials, and MCP clients need a user application with a redirect URI\n2. Reuse each access token for its 5 minutes. The token endpoint answers 429 once a client drains its pool of 100 tokens, refilled at 30 a minute\n3. Page large reads with `cursor=` and `sortField=ID`. Cursor and offset parameters cannot be combined, and Search API `limit` plus `offset` cannot exceed 10,000\n4. Keep Import API files to 10,000 assets or fewer and run at most 8 imports at once. Retry a job that fails on a concurrency error\n5. Expect `discover_data_assets` and `discover_business_glossary` to consume Collibra Units and to need the `dgc.ai-copilot` permission. Use `search_asset_keyword` for free keyword search\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -H 'Authorization: Bearer \u003ctoken\u003e' https://\u003cinstance\u003e.collibra.com/rest/2.0/communities\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"collibra\": {\n      \"command\": \"/path/to/chip-...\",\n      \"type\": \"stdio\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/collibra. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Atlan | B | 62.5 | 426 | data.catalogue, data.lineage, knowledge.search | no | https://www.anchorterminal.com/tools/atlan.md |\n| Alation | C | 60.3 | 521 | data.catalogue, knowledge.search, data.lineage | no | https://www.anchorterminal.com/tools/alation.md |\n| Secoda | E | 44.5 | 875 | data.catalogue, data.lineage, knowledge.search | no | https://www.anchorterminal.com/tools/secoda.md |\n| OpenMetadata | B | 66.6 | 281 | data.catalogue, data.lineage | no | https://www.anchorterminal.com/tools/openmetadata.md |\n| Marmot | B | 64.4 | 350 | data.catalogue, data.lineage | no | https://www.anchorterminal.com/tools/marmot.md |\n| DataHub | C | 59.4 | 549 | data.catalogue, data.lineage | no | https://www.anchorterminal.com/tools/datahub.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The developer portal documents a Core REST API under `/rest/2.0`, Import, Search, Catalogue, Data Quality, Protect and OAuth APIs, and two GraphQL APIs, Knowledge Graph and Data Access (source: \u003chttps://developer.collibra.com/llms.txt\u003e)\n- A hosted MCP server answers on each commercial cloud instance at `https://\u003ctenant\u003e.collibra.com/rest/mcp` over streamable HTTP with OAuth 2.0. It is not available for Collibra Platform for Government or self-hosted deployments (source: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/ta_claude-desktop-mcp.htm\u003e)\n- The open-source local MCP server lists 48 tools in its README. 30 are registered by default (22 read, 8 write), and 18 data quality tools need the `--data-quality` flag (source: \u003chttps://github.com/collibra/chip\u003e)\n- The lead for this listing said the only MCP server serves the documentation. That server exists at `https://developer.collibra.com/~gitbook/mcp`, and Collibra also documents the catalogue MCP server above (source: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_mcp.htm\u003e)\n- Access tokens are valid for 5 minutes, and each OAuth client has a pool of 100 token requests refilled at 30 a minute, with a 429 beyond it (source: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/Settings/OAuth/co_oauth-settings.htm\u003e)\n- The Developer Terms of 22 August 2023 forbid publishing benchmarks or performance information, testing the capabilities of the toolkit, and calls not driven by bona fide end user requests except reasonable testing (source: \u003chttps://www.collibra.com/legal/documents/collibra-developer-terms\u003e)\n- status.collibra.com showed all systems normal for 55 days on 9 October 2026. A lineage and integrations disruption ran from 24 July to 14 August 2026 in all regions (source: \u003chttps://status.collibra.com/incidents\u003e)\n- Release 2026.09 reached commercial production on 4 October 2026, and monthly releases reach production three weeks after pre-production (source: \u003chttps://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/ref_release-calendar.htm\u003e)\n- Each page of developer.collibra.com ends with a block headed Agent Instructions that tells AI agents how to query the documentation with an `ask` parameter. We did not act on it\n\n- #4 of 13 in Best company knowledge search and data catalogues for AI agents: https://www.anchorterminal.com/best/company-knowledge/index.md\n- All 63 knowledge comparisons: https://www.anchorterminal.com/compare/company-knowledge/index.md\n\n## Compare\n\n- [Cohere North vs Collibra](https://www.anchorterminal.com/compare/cohere-north-vs-collibra.md): C 55.1 vs B 64.6\n- [Collibra vs Dust](https://www.anchorterminal.com/compare/collibra-vs-dust.md): B 64.6 vs B 62.8\n- [Collibra vs Glean](https://www.anchorterminal.com/compare/collibra-vs-glean.md): B 64.6 vs B 69.8\n- [Collibra vs Guru](https://www.anchorterminal.com/compare/collibra-vs-guru.md): B 64.6 vs E 45.1\n- [Collibra vs Onyx](https://www.anchorterminal.com/compare/collibra-vs-onyx.md): B 64.6 vs B 65\n- [Collibra vs Overclock](https://www.anchorterminal.com/compare/collibra-vs-overclock.md): B 64.6 vs F 7.5\n- [Alation vs Collibra](https://www.anchorterminal.com/compare/alation-vs-collibra.md): C 60.3 vs B 64.6\n- [Atlan vs Collibra](https://www.anchorterminal.com/compare/atlan-vs-collibra.md): B 62.5 vs B 64.6\n- [Collibra vs DataHub](https://www.anchorterminal.com/compare/collibra-vs-datahub.md): B 64.6 vs C 59.4\n- [Collibra vs Marmot](https://www.anchorterminal.com/compare/collibra-vs-marmot.md): B 64.6 vs B 64.4\n- [Collibra vs OpenMetadata](https://www.anchorterminal.com/compare/collibra-vs-openmetadata.md): B 64.6 vs B 66.6\n- [Collibra vs Secoda](https://www.anchorterminal.com/compare/collibra-vs-secoda.md): B 64.6 vs E 44.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on collibra.com or one of its subdomains, or the README of github.com/collibra/chip. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"collibra\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/collibra\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/collibra.svg\" alt=\"Collibra on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Collibra on Anchor Terminal](https://www.anchorterminal.com/badges/collibra.svg)](https://www.anchorterminal.com/tools/collibra)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/collibra\"\u003eCollibra on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Collibra is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/collibra-dark.png\n- Light: https://www.anchorterminal.com/assets/share/collibra-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Company knowledge \u0026 data catalogues",
        "url": "https://www.anchorterminal.com/categories/company-knowledge"
      },
      {
        "name": "Collibra",
        "url": ""
      }
    ],
    "description": "Collibra is a hosted data governance platform with a catalogue, business glossary, lineage and data quality. Agents use REST and GraphQL APIs, a bulk Import API, a hosted MCP server on each cloud instance and an open-source local one.",
    "facts": [
      "rank #346 of 950",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Collibra",
    "image": "https://www.anchorterminal.com/assets/og/tools-collibra.png",
    "path": "/tools/collibra",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Collibra review (2026): pricing, alternatives and grade B",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/collibra"
  },
  "tokens": {
    "markdown": 8800,
    "slim": 1930
  },
  "version": 1
}
