# Collibra (slim) > Collibra is a hosted data governance platform with a catalogue, business glossary, lineage and data quality. Agents use REST and GraphQL APIs, a bulk Import API, a hosted MCP server on each cloud instance and an open-source local one. - Full: https://www.anchorterminal.com/tools/collibra.md (~8,800 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/collibra.json · canonical https://www.anchorterminal.com/tools/collibra - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 64.6/100 · rank #346 of 950 · #4 in Company knowledge & data catalogues · not agent-ready · confidence medium** Assessment: Each REST API has an OpenAPI 3.0 definition, the developer portal publishes llms.txt and Markdown pages, and every MCP tool carries read-only and destructive annotations. Access needs a sales contract, since no price, trial or self-serve sign-up is published, and no general API rate limit was found in the reviewed documentation. ## Facts - Kind: HTTP API · vendor: Collibra · category: Company knowledge & data catalogues · legal entity: Collibra Inc. · provenance 89/100 - Local only (HTTP, Streamable HTTP, stdio) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under the Master Collibra Agreement, with the Developer Terms for the REST APIs and CLI. The local MCP server (chip) is Apache-2.0, and the CLI binary ships under a Binary Code Licence Agreement - Probe metrics: not measured yet (probes haven't run) - APIs: Core REST API under `/rest/2.0` for assets, domains, communities, relations, responsibilities, workflows and activities, plus Import, Search, Catalogue, Technical Lineage, Data Quality, Protect, Edge and OAuth APIs. GraphQL Knowledge Graph API at `/graphql/knowledgeGraph/v1` and a Data Access GraphQL API - MCP server: Hosted at `https://.collibra.com/rest/mcp` on commercial cloud instances, streamable HTTP with OAuth 2.0. Local server `chip` (Go, Apache-2.0, v0.0.62 of 5 October 2026) over stdio or HTTP, 30 tools by default and 18 data quality tools behind a flag - Credentials: OAuth 2.0 client credentials for integration applications, authorisation code flow with PKCE for user applications, 5-minute tokens. HTTP Basic with a username and password, or a JWT Bearer token from the customer's identity provider - Rate limits: No general request limit found in the reviewed documentation. OAuth token requests draw on a pool of 100 for each client, refilled at 30 a minute. Knowledge Graph queries stop at 100,000 nodes, and up to 8 imports run concurrently - Errors: HTTP 400, 401, 403, 404 and 500 with a description in each OpenAPI definition, and four JWT error codes such as `expiredToken` with a suggested action - Pagination: `offset` and `limit` with a `total`, or `cursor` and `nextCursor` sorted by `ID`. The two cannot be combined. Search allows a `limit` of 1,000 and `limit` plus `offset` up to 10,000. GraphQL collections default to 10 items - Pricing: Sales contract only. No published price, trial or self-serve sign-up found. AI functions draw on Collibra Units, 70,000 or 100,000 included in each contract - SLA and support: 99.5 per cent monthly uptime target with service credits of 1 to 15 per cent, or 5 to 20 per cent with Premium Support. Standard support answers an urgent incident within 2 hours, 24 hours a day - CLI: `collibra` binary v2.1.1 of 10 August 2026 for Windows, Linux and macOS, with `ai-gov` and `data-contract` command groups. The macOS build is not yet signed with an Apple key, per the docs - Hosting: AWS and Google Cloud in the United States, European Union, Canada, United Kingdom, Australia or Singapore, per the subprocessor list of 8 September 2026. Instances answer on `.collibra.com` - Certifications: SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, FedRAMP Moderate, HIPAA and TISAX, per the trust centre. Annual third-party penetration tests, per the Security Policy - Status: status.collibra.com with six components for each of AMER, APAC, EMEA and GovCloud, and an incident history - Scores: Reliability 66, Performance pending, Schema & documentation 83, Agent ergonomics 75, Security & auth 68, Payments & pricing 0, Task success pending, Maintenance & community 76, Transparency & trust 82 · total over the 7 assessed categories - Why: Reliability, Hosted service, read on the hosted lines and graded on the REST and GraphQL APIs of a Collibra cloud instance, with the MCP server as a seco… · Schema & documentation, Each REST API has an OpenAPI 3.0 definition, printed in the Markdown copy of every reference page and served by each instance at… · Agent ergonomics, The local MCP server registers 30 tools by default and keeps 18 data quality tools behind a flag, with allow and deny lists for tool names. · Security & auth, OAuth 2.0 client credentials for integration applications, which act as an application-specific system user, and an authorisation code flow… · Payments & pricing, Hosted service, so the hosted rubric applies. · Maintenance & community, The release calendar shows 2026.09 reaching commercial production on 4 October 2026, and the local MCP server tagged v0.0.62 on 5 October (3… · Transparency & trust, Closed service under the published Master Collibra Agreement and Developer Terms. - Sources: 43, open questions: 10, both in the full twin - Capabilities: data.catalogue, knowledge.search, data.lineage - JSON: https://www.anchorterminal.com/api/v1/tools/collibra.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/collibra.svg` or a link to https://www.anchorterminal.com/tools/collibra from a page on collibra.com or one of its subdomains, or the README of github.com/collibra/chip, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask a Collibra administrator to register an OAuth application. Integration applications use client credentials, and MCP clients need a user application with a redirect URI 2. Reuse each access token for its 5 minutes. The token endpoint answers 429 once a client drains its pool of 100 tokens, refilled at 30 a minute 3. Page large reads with `cursor=` and `sortField=ID`. Cursor and offset parameters cannot be combined, and Search API `limit` plus `offset` cannot exceed 10,000 4. Keep Import API files to 10,000 assets or fewer and run at most 8 imports at once. Retry a job that fails on a concurrency error 5. Expect `discover_data_assets` and `discover_business_glossary` to consume Collibra Units and to need the `dgc.ai-copilot` permission. Use `search_asset_keyword` for free keyword search ## Connect ```bash curl -H 'Authorization: Bearer ' https://.collibra.com/rest/2.0/communities ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/collibra ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Atlan | B | 62.5 | data.catalogue, data.lineage, knowledge.search | https://www.anchorterminal.com/tools/atlan.min.md | | Alation | C | 60.3 | data.catalogue, knowledge.search, data.lineage | https://www.anchorterminal.com/tools/alation.min.md | | Secoda | E | 44.5 | data.catalogue, data.lineage, knowledge.search | https://www.anchorterminal.com/tools/secoda.min.md | | OpenMetadata | B | 66.6 | data.catalogue, data.lineage | https://www.anchorterminal.com/tools/openmetadata.min.md | | Marmot | B | 64.4 | data.catalogue, data.lineage | https://www.anchorterminal.com/tools/marmot.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)