{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/glean.json",
        "name": "Glean",
        "score": 69.8,
        "shared": [
          "knowledge.search",
          "agent.mcp-client"
        ],
        "slug": "glean"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/onyx.json",
        "name": "Onyx",
        "score": 65,
        "shared": [
          "knowledge.search",
          "agent.mcp-client"
        ],
        "slug": "onyx"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/cohere-north.json",
        "name": "Cohere North",
        "score": 55.1,
        "shared": [
          "knowledge.search",
          "agent.mcp-client"
        ],
        "slug": "cohere-north"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/open-webui.json",
        "name": "Open WebUI",
        "score": 51.8,
        "shared": [
          "agent.mcp-client",
          "knowledge.search"
        ],
        "slug": "open-webui"
      },
      {
        "grade": "AA",
        "json": "https://www.anchorterminal.com/tools/openai-agents-sdk.json",
        "name": "OpenAI Agents SDK",
        "score": 86.2,
        "shared": [
          "agent.mcp-client"
        ],
        "slug": "openai-agents-sdk"
      },
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/pydantic-ai.json",
        "name": "Pydantic AI",
        "score": 83.7,
        "shared": [
          "agent.mcp-client"
        ],
        "slug": "pydantic-ai"
      }
    ],
    "tool": {
      "slug": "dust",
      "name": "Dust",
      "vendor": "Permutation Labs",
      "vendorUrl": "https://dust.tt",
      "kind": "http-api",
      "category": "company-knowledge",
      "summary": "Dust is a platform for building AI agents on a company's documents and connected tools, from Permutation Labs in Paris. Outside agents reach it through a REST API, a JavaScript SDK, a CLI and a remote MCP server with OAuth.",
      "url": "https://www.anchorterminal.com/tools/dust",
      "markdownUrl": "https://www.anchorterminal.com/tools/dust.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dust.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dust.json",
      "repo": "https://github.com/dust-tt/dust",
      "license": "MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli`",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://dust.tt/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@dust-tt/client"
        },
        {
          "registry": "npm",
          "name": "@dust-tt/dust-cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The REST API takes a workspace API key as a Bearer token, created by an admin in the workspace under Developers, API Keys. A key can be limited to chosen spaces and given a spending cap on a rolling 30 days. The remote MCP server takes OAuth only, with dynamic client registration or a client ID metadata document, and the token works as the signed-in user. The client-side MCP server (preview) needs an OAuth personal access token. Sign-in to create a workspace is in a browser.",
      "pricing": "freemium",
      "pricingNotes": "Free seat with 500 lifetime credits. Pro is €30 a seat a month (€24 billed yearly) with 8,000 credits, Max €150 (€120 yearly) with 40,000, and Enterprise is by quote, as dust.tt/home/pricing showed our reader in euros. API and other programmatic usage has no free credits and draws only on the workspace credit pool, bought as top-ups on Business or committed on Enterprise. No price per top-up credit was found (checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1482,
        "npmWeekly": 17225,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.dust.tt",
      "llmsTxt": "https://docs.dust.tt/llms.txt",
      "openapi": "https://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json",
      "capabilities": [
        "knowledge.search",
        "agent.mcp-client"
      ],
      "tags": [
        "hosted",
        "open-source",
        "mit",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "eu-region",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.8,
        "grade": "B",
        "agentReady": false,
        "rank": 378,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 86,
          "payments": 20,
          "reliability": 53,
          "schema": 75,
          "security": 75,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 53,
            "points": 10.6,
            "reason": "Read with the hosted lines, on the REST API and the remote MCP server. status.dust.tt runs on Statuspage with 16 components, among them API, Conversations and Data Sources, and a dated history (20). In the 90 days to 8 October 2026 it lists two major incidents, degraded performance for 2 hours 3 minutes on 16 July covering Conversations, the app platform and the API, and 6 minutes of inaccessible conversations on 18 September, plus seven minor ones, mostly latency. That is one major of over an hour (10). Rate limits carry numbers for document upserts (120 a minute per workspace) and Dust app runs (10,000 a day) only, with none for conversations or search (8 of 15). The OpenAPI document lists 429 on six operations, and no Retry-After or backoff guidance was found in the docs. Upserts by document ID are safe to repeat (5 of 15). No SLA was found on the pricing or security pages, and the terms went unread (0). The REST API carries no beta label, while the MCP server is described as a first version and the client-side MCP server is a preview (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "A public OpenAPI 3.0 document with 54 paths and 68 operations, linked from the docs and from llms.txt (25). llms.txt at docs.dust.tt with a Markdown copy of every page (10). Operation descriptions mostly restate the summary (\"Search for nodes in the workspace\"), six operations have none, and none says when not to use an endpoint (10 of 20). 43 enums and 277 required markers, though ranges such as the search `limit` of 1 to 100 sit in the description text and not in the schema (10 of 15). 186 examples, while most error responses are a status and two words (\"Bad request\") with no body schema (9 of 15). The path carries `/api/v1`, the document a version (1.0.2), and the product changelog is dated and has carried API deprecation notices. There is no changelog for the API alone (11 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "Workspace search takes `limit` (1 to 100, default 25), and data source search takes `top_k` and `target_document_tokens`, so results can be sized. The MCP server's tool list needs a signed-in workspace and was not read (20 of 25). Cursor pagination on search, `limit` and `lastValue` on conversations, and tag, parent and timestamp filters on data source search (20). The source returns errors as a type and a message, such as `rate_limit_error` with the reason a call was blocked, but the docs give no list of error types (12 of 20). No idempotency keys in the OpenAPI document. Document and row upserts by ID can be repeated safely, and MCP tool annotations were not seen (6 of 20). Search needs only a query. One official SDK language, JavaScript, plus a CLI with a non-interactive mode that prints JSON (9 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 75,
            "points": 13.13,
            "reason": "API keys go in the `Authorization` header, can be limited to chosen spaces and capped by spend, and the MCP server takes OAuth with dynamic client registration, client ID metadata documents and a required `resource` parameter, issuing tokens that work only for MCP (28 of 30). An MCP client works as the signed-in user with that user's spaces only, an admin can switch the server off and restrict redirect URIs, and the API has an endpoint to approve or reject an agent's action. No read-only key type was found (16 of 20). Search returns content from connected sources, and no prompt-injection guidance for API or MCP clients was found in the pages read (3 of 15). Audit logs record user, API key and system actors with SIEM streaming, on the Enterprise plan only (12 of 15). SOC 2 Type II and HIPAA support on the security page, a HackerOne disclosure programme with no bounty stated, CodeQL in the public CI, and no security.txt (16 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public per seat with their credit allowances, but no price per top-up credit was found and the Enterprise programmatic rate is by quote (10). A Free seat has 500 lifetime credits, and the pricing page does not say whether a card is needed. Programmatic usage has no free credits and draws only on the workspace pool, which Free seats cannot use, so the free tier does not cover API calls that run agents (10 of 20). A person signs in through a browser to create a workspace and an admin creates the key (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 86,
            "points": 7.53,
            "reason": "The changelog's newest entry is dated 8 October 2026 and the repository had 112 commits that day (30). 49 changelog entries from August to 8 October 2026 (20). Issues are public on GitHub (388 open issues and pull requests by the API's count), with a support email and a community site. We could not read reply times (15 of 25). `@dust-tt/client` 1.2.9 was published on 22 September 2026 and the CLI on 1 September, in one language (12 of 15). Public CI builds and tests each part of the repository, with CodeQL. The SDK and CLI ask for Node 24.16 or later (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 68,
            "points": 5.95,
            "note": "editorial 71, provenance 64",
            "reason": "The platform's source is public under the MIT licence (30). The Platform Privacy Policy gives retention periods (the agreement's length plus five years archived, three years for marketing contacts) and says model providers keep no data and may not train on it, which agrees with the security page. It covers Dust as controller only, and the DPA and terms of service went unread (18 of 30). No written deprecation policy was found. The changelog gave dated notice on 8 April 2026 that two analytics endpoints would be removed on 1 June 2026, under two months ahead (10 of 20). The privacy policy names the model providers (OpenAI, Anthropic, Mistral, Google, Fireworks), Google Cloud and Qdrant Cloud, and hosting is in the US or the EU. The full sub-processor list on the trust centre is drawn by script and was not read (13 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Workspace search takes `limit` (1 to 100, default 25), and data source search takes `top_k` and `target_document_tokens`, so results can be sized. The MCP server's tool list needs a signed-in workspace and was not read (20 of 25). Cursor pagination on search, `limit` and `lastValue` on conversations, and tag, parent and timestamp filters on data source search (20). The source returns errors as a type and a message, such as `rate_limit_error` with the reason a call was blocked, but the docs give no list of error types (12 of 20). No idempotency keys in the OpenAPI document. Document and row upserts by ID can be repeated safely, and MCP tool annotations were not seen (6 of 20). Search needs only a query. One official SDK language, JavaScript, plus a CLI with a non-interactive mode that prints JSON (9 of 15).",
            "maintenance": "The changelog's newest entry is dated 8 October 2026 and the repository had 112 commits that day (30). 49 changelog entries from August to 8 October 2026 (20). Issues are public on GitHub (388 open issues and pull requests by the API's count), with a support email and a community site. We could not read reply times (15 of 25). `@dust-tt/client` 1.2.9 was published on 22 September 2026 and the CLI on 1 September, in one language (12 of 15). Public CI builds and tests each part of the repository, with CodeQL. The SDK and CLI ask for Node 24.16 or later (9 of 10).",
            "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public per seat with their credit allowances, but no price per top-up credit was found and the Enterprise programmatic rate is by quote (10). A Free seat has 500 lifetime credits, and the pricing page does not say whether a card is needed. Programmatic usage has no free credits and draws only on the workspace pool, which Free seats cannot use, so the free tier does not cover API calls that run agents (10 of 20). A person signs in through a browser to create a workspace and an admin creates the key (0).",
            "reliability": "Read with the hosted lines, on the REST API and the remote MCP server. status.dust.tt runs on Statuspage with 16 components, among them API, Conversations and Data Sources, and a dated history (20). In the 90 days to 8 October 2026 it lists two major incidents, degraded performance for 2 hours 3 minutes on 16 July covering Conversations, the app platform and the API, and 6 minutes of inaccessible conversations on 18 September, plus seven minor ones, mostly latency. That is one major of over an hour (10). Rate limits carry numbers for document upserts (120 a minute per workspace) and Dust app runs (10,000 a day) only, with none for conversations or search (8 of 15). The OpenAPI document lists 429 on six operations, and no Retry-After or backoff guidance was found in the docs. Upserts by document ID are safe to repeat (5 of 15). No SLA was found on the pricing or security pages, and the terms went unread (0). The REST API carries no beta label, while the MCP server is described as a first version and the client-side MCP server is a preview (10).",
            "schema": "A public OpenAPI 3.0 document with 54 paths and 68 operations, linked from the docs and from llms.txt (25). llms.txt at docs.dust.tt with a Markdown copy of every page (10). Operation descriptions mostly restate the summary (\"Search for nodes in the workspace\"), six operations have none, and none says when not to use an endpoint (10 of 20). 43 enums and 277 required markers, though ranges such as the search `limit` of 1 to 100 sit in the description text and not in the schema (10 of 15). 186 examples, while most error responses are a status and two words (\"Bad request\") with no body schema (9 of 15). The path carries `/api/v1`, the document a version (1.0.2), and the product changelog is dated and has carried API deprecation notices. There is no changelog for the API alone (11 of 15).",
            "security": "API keys go in the `Authorization` header, can be limited to chosen spaces and capped by spend, and the MCP server takes OAuth with dynamic client registration, client ID metadata documents and a required `resource` parameter, issuing tokens that work only for MCP (28 of 30). An MCP client works as the signed-in user with that user's spaces only, an admin can switch the server off and restrict redirect URIs, and the API has an endpoint to approve or reject an agent's action. No read-only key type was found (16 of 20). Search returns content from connected sources, and no prompt-injection guidance for API or MCP clients was found in the pages read (3 of 15). Audit logs record user, API key and system actors with SIEM streaming, on the Enterprise plan only (12 of 15). SOC 2 Type II and HIPAA support on the security page, a HackerOne disclosure programme with no bounty stated, CodeQL in the public CI, and no security.txt (16 of 20).",
            "transparency": "The platform's source is public under the MIT licence (30). The Platform Privacy Policy gives retention periods (the agreement's length plus five years archived, three years for marketing contacts) and says model providers keep no data and may not train on it, which agrees with the security page. It covers Dust as controller only, and the DPA and terms of service went unread (18 of 30). No written deprecation policy was found. The changelog gave dated notice on 8 April 2026 that two analytics endpoints would be removed on 1 June 2026, under two months ahead (10 of 20). The privacy policy names the model providers (OpenAI, Anthropic, Mistral, Google, Fireworks), Google Cloud and Qdrant Cloud, and hosting is in the US or the EU. The full sub-processor list on the trust centre is drawn by script and was not read (13 of 20)."
          },
          "sources": [
            {
              "what": "docs index (llms.txt)",
              "url": "https://docs.dust.tt/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "developer platform overview",
              "url": "https://docs.dust.tt/docs/developer-platform/overview/developer-platform",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI and Postman page",
              "url": "https://docs.dust.tt/docs/developer-platform/dust-api-documentation/openapi-and-postman",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI document",
              "url": "https://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limits",
              "url": "https://docs.dust.tt/docs/developer-platform/core-concepts/rate-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "Dust MCP server",
              "url": "https://docs.dust.tt/docs/user-documentation/agents/integrations/dust-mcp-server",
              "seen": "2026-10-08"
            },
            {
              "what": "client-side MCP server (preview)",
              "url": "https://docs.dust.tt/docs/user-documentation/developers/client-side-mcp-server",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP endpoint, 401 and resource metadata",
              "url": "https://dust.tt/.well-known/oauth-protected-resource/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "Dust CLI",
              "url": "https://docs.dust.tt/docs/developer-platform/dust-cli/dust-cli",
              "seen": "2026-10-08"
            },
            {
              "what": "JavaScript SDK page",
              "url": "https://docs.dust.tt/docs/developer-platform/overview/javascript-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "credit management and programmatic usage",
              "url": "https://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credit-management",
              "seen": "2026-10-08"
            },
            {
              "what": "credits",
              "url": "https://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credits",
              "seen": "2026-10-08"
            },
            {
              "what": "audit logs",
              "url": "https://docs.dust.tt/docs/user-documentation/admins/audit-logs/audit-logs",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://docs.dust.tt/docs/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://dust.tt/home/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://dust.tt/home/security",
              "seen": "2026-10-08"
            },
            {
              "what": "Platform Privacy Policy",
              "url": "https://dust.tt/home/platform-privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "vulnerability disclosure programme",
              "url": "https://dust.tt/home/vulnerability",
              "seen": "2026-10-08"
            },
            {
              "what": "terms link (redirects to a Notion site, unread)",
              "url": "https://dust.tt/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://dust.statuspage.io/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status components",
              "url": "https://dust.statuspage.io/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "repository (licence, CI workflows, SECURITY.md, API source)",
              "url": "https://github.com/dust-tt/dust",
              "seen": "2026-10-08"
            },
            {
              "what": "repository metadata",
              "url": "https://api.github.com/repos/dust-tt/dust",
              "seen": "2026-10-08"
            },
            {
              "what": "npm, @dust-tt/client",
              "url": "https://registry.npmjs.org/@dust-tt/client",
              "seen": "2026-10-08"
            },
            {
              "what": "npm, @dust-tt/dust-cli",
              "url": "https://registry.npmjs.org/@dust-tt/dust-cli",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@dust-tt/client",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://dust.tt/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "docs robots.txt",
              "url": "https://docs.dust.tt/robots.txt",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the terms of service, any SLA and the DPA. dust.tt/terms redirects to dust-tt.notion.site, which is drawn by script and gave our reader no text. `provenance.terms` is left out for that reason.",
            "unchecked: the trust centre at trust.dust.com (certificates, sub-processor list), which is drawn by script.",
            "unchecked: the remote MCP server's tool count, input schemas and readOnlyHint or destructiveHint annotations, which need a signed-in workspace.",
            "unchecked: whether the official MCP registry lists Dust. The registry did not answer our request.",
            "unchecked: the effective date of the Platform Privacy Policy, which our reader did not find on the page.",
            "unchecked: advisories for Dust at NVD or GitHub, and reply times on GitHub issues.",
            "unchecked: the registration date of dust.tt. No RDAP service answers for .tt.",
            "Not found in the reviewed documentation: a price per top-up credit, numeric rate limits for conversations and search, and whether a Free workspace needs a card.",
            "The pricing page showed our reader prices in euros. Prices in other currencies were not seen, so `unitPrices` is empty.",
            "The lead named the client-side MCP server (preview) and left out the remote MCP server at `https://dust.tt/mcp`, which is the main MCP surface. The legal entity is Permutation Labs."
          ]
        },
        "negative": 0,
        "verdict": "The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.",
        "bestFor": "A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.",
        "strengths": [
          "The platform's source is public under the MIT licence at github.com/dust-tt/dust, with commits on the day of the check",
          "Public OpenAPI 3.0 document with 68 operations, plus llms.txt and a Markdown copy of each docs page",
          "Remote MCP server at `https://dust.tt/mcp` and `https://eu.dust.tt/mcp`, with OAuth, dynamic client registration and the signed-in user's own access",
          "API keys can be limited to chosen spaces and given a spending cap on a rolling 30 days",
          "SOC 2 Type II on the security page, a HackerOne disclosure programme, and US or EU hosting"
        ],
        "weaknesses": [
          "Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use",
          "Rate limits are published for document upserts and app runs only, and no Retry-After guidance was found in the docs",
          "The terms link redirects to a Notion site drawn by script, so the service terms, any SLA and the DPA went unread",
          "Audit logs are an Enterprise feature, and no security.txt is published (404)",
          "Two major incidents on status.dust.tt in the last 90 days, one of 2 hours 3 minutes on 16 July 2026 that covered the API"
        ],
        "agentNotes": [
          "Use `https://eu.dust.tt` for a workspace in the EU region and `https://dust.tt` otherwise, for both the API and the MCP server",
          "Connect an MCP client by OAuth and send the `resource` parameter in authorisation and token requests. API keys do not work on the MCP server",
          "Expect HTTP 429 with type `rate_limit_error` when the credit pool, the programmatic monthly cap or the key's spend cap is exhausted. Retrying will not help",
          "Call `GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25) and `cursor`, or a data source view's search with `top_k`",
          "Keep document upserts under 120 a minute per workspace"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.8
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 86,
          "payments": 20,
          "reliability": 53,
          "schema": 75,
          "security": 75,
          "transparency": 71
        },
        "provenanceScore": 64
      },
      "connect": {
        "install": "npm install @dust-tt/client",
        "config": {
          "mcpServers": {
            "dust": {
              "type": "http",
              "url": "https://dust.tt/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/knowledge.search",
        "tool": "https://letme.dev/dust"
      },
      "notable": [
        "The remote MCP server answers at `https://dust.tt/mcp` (US) and `https://eu.dust.tt/mcp` (EU), takes OAuth only, and its first version lists agents, works with conversations and files, and searches across workspace spaces (https://docs.dust.tt/docs/user-documentation/agents/integrations/dust-mcp-server)",
        "An unauthenticated request to `https://dust.tt/mcp` returns 401 with a `resource_metadata` pointer, and the metadata names `https://signin.dust.tt` as the authorisation server (https://dust.tt/.well-known/oauth-protected-resource/mcp)",
        "The OpenAPI 3.0 document has 54 paths and 68 operations, with servers `https://dust.tt` (us-central1) and `https://eu.dust.tt` (europe-west1) (https://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json)",
        "Programmatic usage, which covers API calls, draws only on the workspace credit pool and has no free credit baseline (https://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credit-management)",
        "API keys can be limited to several spaces since 1 April 2026 and carry an optional spending cap since 29 January 2026 (https://docs.dust.tt/docs/changelog)",
        "The changelog announced on 8 April 2026 that `/api/v1/w/{wId}/usage` and `/api/v1/w/{wId}/workspace-usage` would be removed on 1 June 2026 (https://docs.dust.tt/docs/changelog)",
        "status.dust.tt lists a major incident of 2 hours 3 minutes on 16 July 2026 covering Conversations, the app platform and the API, and one of 6 minutes on 18 September 2026 (https://dust.statuspage.io/api/v2/incidents.json)",
        "The security page states SOC 2 Type II, HIPAA support, AES-256 at rest, no model training on customer data and zero data retention at model providers (https://dust.tt/home/security)"
      ],
      "area": "business",
      "details": [
        {
          "label": "REST API",
          "value": "54 paths and 68 operations under `/api/v1/w/{wId}` on `https://dust.tt` (US) or `https://eu.dust.tt` (EU). Agents, conversations with SSE events, workspace search, data sources, documents, tables, spaces, skills, triggers and analytics export"
        },
        {
          "label": "MCP server",
          "value": "Remote, at `https://dust.tt/mcp` or `https://eu.dust.tt/mcp`, OAuth only. Lists agents, works with conversations, Pods and files, and searches spaces. It does not proxy the third-party tools set up in the workspace. An admin can switch it off"
        },
        {
          "label": "Client-side MCP server",
          "value": "Preview. An application registers its own tools for a conversation through the API. OAuth personal access tokens only"
        },
        {
          "label": "Credentials",
          "value": "Workspace API keys as Bearer tokens, limited to chosen spaces, with an optional spending cap on a rolling 30 days. OAuth with dynamic client registration or client ID metadata documents for MCP"
        },
        {
          "label": "Rate limits",
          "value": "120 document upserts a minute per workspace and 10,000 runs a day per Dust app. No figure published for conversations or search"
        },
        {
          "label": "Search",
          "value": "`GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25), `cursor`, `viewType` and `spaceIds`. Data source search takes `top_k`, `full_text`, `target_document_tokens`, tag, parent and timestamp filters"
        },
        {
          "label": "SDK and CLI",
          "value": "`@dust-tt/client` 1.2.9 (22 September 2026) and `@dust-tt/dust-cli` 0.4.6 (1 September 2026), both on npm and both asking for Node 24.16 or later"
        },
        {
          "label": "Plans",
          "value": "Free seat 500 lifetime credits. Pro €30 a seat a month or €24 yearly, 8,000 credits. Max €150 or €120 yearly, 40,000 credits. Enterprise by quote, with pooled credits and a programmatic rate"
        },
        {
          "label": "Credits",
          "value": "Charged per message by model and actions. Tool actions cost 0, 1 or 3 credits by tier, and knowledge search is 3"
        },
        {
          "label": "Audit",
          "value": "Audit logs on the Enterprise plan only, with user, API key and system actors, CSV export and streaming to Datadog, Splunk, S3, GCS or an HTTPS endpoint"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II, HIPAA support and GDPR compliance stated on dust.tt/home/security. Vulnerability reports go to a HackerOne programme"
        },
        {
          "label": "Status",
          "value": "status.dust.tt on Statuspage, 16 components among them API, Conversations, Data Sources, us-central1 and europe-west1"
        }
      ],
      "provenance": {
        "legalEntity": "Permutation Labs",
        "domain": "dust.tt",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://dust.tt/home/platform-privacy",
        "statusPage": "https://status.dust.tt",
        "changelog": "https://docs.dust.tt/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Privacy Policy names Permutation Labs, 86 avenue de Wagram, 75017 Paris, France. It covers the platform where Dust is the data controller, not customer data Dust handles as a processor.",
          "No terms link is recorded. dust.tt/terms redirects (308) to a Notion site, dust-tt.notion.site, which is drawn by script and gave our reader no text, so we could not tell which document there governs the platform.",
          "The API and the MCP server answer on dust.tt and eu.dust.tt. OAuth for MCP is at signin.dust.tt.",
          "dust.tt/.well-known/security.txt returns 404. The repository's SECURITY.md sends reports to dust.tt/home/vulnerability, a HackerOne programme.",
          "No RDAP service answers for the .tt registry, so the domain's registration date is not recorded.",
          "dust.tt/robots.txt returns 404. docs.dust.tt/robots.txt carries `Content-Signal: ai-train=yes, search=yes, ai-input=yes`."
        ],
        "score": 64,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Permutation Labs",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "dust.tt, no registry record we could read",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "dust.tt",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.dust.tt",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "",
            "state": "none-found",
            "points": 0,
            "max": 10
          },
          {
            "kind": "privacy",
            "url": "https://dust.tt/home/platform-privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 2360,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy explains who we are and spells out how we collect, use, and disclose information that relates to you, as defined under applicable data protection laws (\"Personal Data\") and how to exercise your privacy rights."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may also disclose your Personal Data to third parties to carry out our usual business practices."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We may also disclose your Personal Data if we are a party of a business sale, such as a merger or an acquisition."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "This Privacy Policy explains who we are and spells out how we collect, use, and disclose information that relates to you, as defined under applicable data protection laws (\"Personal Data\") and how to exercise your privacy rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You can also contact our Data Protection Officer at [email protected].",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "or (ii) the transfer is covered by appropriate safeguards, such as the Standard Contractual Clauses published by the EU commission.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The named foundation model providers are prohibited from using customer and personal data for model training.",
                "quote": "Foundational Model Providers (OpenAI, Anthropic, Mistral, Google, Fireworks) are prohibited from using any customer and personal data for model training."
              },
              {
                "date": "2026-10-08",
                "text": "Internal development, one purpose for which Dust processes personal data, is defined to include benchmarking and machine learning.",
                "quote": "\"Internal Development\" means when Dust improves and better develops the Platform including testing, research, reporting, benchmarking, machine learning, performance analyses, predictions and trend analysis."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dust.json",
      "live": {
        "slug": "dust",
        "probe": {
          "target": "https://dust.tt/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:14:13.381150086Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 139,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 151,
          "p95ms24h": 198,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.dust.tt",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:10:52.179385466Z"
        },
        "updatedAt": "2026-10-09T10:14:13.381150086Z"
      }
    },
    "verify": {
      "accepts": "a page on dust.tt or one of its subdomains, or the README of github.com/dust-tt/dust",
      "badgeUrl": "https://www.anchorterminal.com/badges/dust.svg",
      "body": {
        "slug": "dust",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/dust",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/dust\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/dust.svg\" alt=\"Dust on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Dust on Anchor Terminal](https://www.anchorterminal.com/badges/dust.svg)](https://www.anchorterminal.com/tools/dust)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/dust\"\u003eDust on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/dust",
    "json": "https://www.anchorterminal.com/tools/dust.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/dust.md",
    "slim": "https://www.anchorterminal.com/tools/dust.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62.8/100 · rank #378 of 842 · #5 in Company knowledge \u0026 data catalogues · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Permutation Labs (https://dust.tt) |\n| Kind | HTTP API |\n| Category | Company knowledge \u0026 data catalogues (https://www.anchorterminal.com/categories/company-knowledge) |\n| Transport | HTTP |\n| Endpoint | `https://dust.tt/mcp` |\n| Auth | OAuth or key · Self-serve. The REST API takes a workspace API key as a Bearer token, created by an admin in the workspace under Developers, API Keys. A key can be limited to chosen spaces and given a spending cap on a rolling 30 days. The remote MCP server takes OAuth only, with dynamic client registration or a client ID metadata document, and the token works as the signed-in user. The client-side MCP server (preview) needs an OAuth personal access token. Sign-in to create a workspace is in a browser. |\n| Pricing | Freemium (Freemium) · Free seat with 500 lifetime credits. Pro is €30 a seat a month (€24 billed yearly) with 8,000 credits, Max €150 (€120 yearly) with 40,000, and Enterprise is by quote, as dust.tt/home/pricing showed our reader in euros. API and other programmatic usage has no free credits and draws only on the workspace credit pool, bought as top-ups on Business or committed on Enterprise. No price per top-up credit was found (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI document or the pricing page (checked 2026-10-08). |\n| Licence | MIT for the platform's source at github.com/dust-tt/dust. The hosted service is sold under Dust's own terms. The npm page gives ISC for `@dust-tt/client` and MIT for `@dust-tt/dust-cli` |\n| Packages | npm: `@dust-tt/client`; npm: `@dust-tt/dust-cli` |\n| Source | https://github.com/dust-tt/dust |\n| Docs | https://docs.dust.tt |\n| llms.txt | https://docs.dust.tt/llms.txt |\n| Last release | 2026-10-08 |\n| GitHub stars | 1,482 (as of 2026-10-08) |\n| npm downloads / week | 17,225 |\n| REST API | 54 paths and 68 operations under `/api/v1/w/{wId}` on `https://dust.tt` (US) or `https://eu.dust.tt` (EU). Agents, conversations with SSE events, workspace search, data sources, documents, tables, spaces, skills, triggers and analytics export |\n| MCP server | Remote, at `https://dust.tt/mcp` or `https://eu.dust.tt/mcp`, OAuth only. Lists agents, works with conversations, Pods and files, and searches spaces. It does not proxy the third-party tools set up in the workspace. An admin can switch it off |\n| Client-side MCP server | Preview. An application registers its own tools for a conversation through the API. OAuth personal access tokens only |\n| Credentials | Workspace API keys as Bearer tokens, limited to chosen spaces, with an optional spending cap on a rolling 30 days. OAuth with dynamic client registration or client ID metadata documents for MCP |\n| Rate limits | 120 document upserts a minute per workspace and 10,000 runs a day per Dust app. No figure published for conversations or search |\n| Search | `GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25), `cursor`, `viewType` and `spaceIds`. Data source search takes `top_k`, `full_text`, `target_document_tokens`, tag, parent and timestamp filters |\n| SDK and CLI | `@dust-tt/client` 1.2.9 (22 September 2026) and `@dust-tt/dust-cli` 0.4.6 (1 September 2026), both on npm and both asking for Node 24.16 or later |\n| Plans | Free seat 500 lifetime credits. Pro €30 a seat a month or €24 yearly, 8,000 credits. Max €150 or €120 yearly, 40,000 credits. Enterprise by quote, with pooled credits and a programmatic rate |\n| Credits | Charged per message by model and actions. Tool actions cost 0, 1 or 3 credits by tier, and knowledge search is 3 |\n| Audit | Audit logs on the Enterprise plan only, with user, API key and system actors, CSV export and streaming to Datadog, Splunk, S3, GCS or an HTTPS endpoint |\n| Certifications | SOC 2 Type II, HIPAA support and GDPR compliance stated on dust.tt/home/security. Vulnerability reports go to a HackerOne programme |\n| Status | status.dust.tt on Statuspage, 16 components among them API, Conversations, Data Sources, us-central1 and europe-west1 |\n| Capabilities | knowledge.search, agent.mcp-client |\n| Tags | hosted, open-source, mit, mcp, oauth, openapi, llms-txt, typescript, cli, eu-region, status-page, soc2, freemium |\n| JSON | https://www.anchorterminal.com/api/v1/tools/dust.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 53 | 10.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 75 | 12.2 |\n| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |\n| Security \u0026 auth | 14% | 17.5 | 75 | 13.1 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 86 | 7.5 |\n| Transparency \u0026 trust (editorial 71, provenance 64) | 7% | 8.8 | 68 | 6.0 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **62.8 → B** |\n\n### Why each score\n\n- Reliability 53: Read with the hosted lines, on the REST API and the remote MCP server. status.dust.tt runs on Statuspage with 16 components, among them API, Conversations and Data Sources, and a dated history (20). In the 90 days to 8 October 2026 it lists two major incidents, degraded performance for 2 hours 3 minutes on 16 July covering Conversations, the app platform and the API, and 6 minutes of inaccessible conversations on 18 September, plus seven minor ones, mostly latency. That is one major of over an hour (10). Rate limits carry numbers for document upserts (120 a minute per workspace) and Dust app runs (10,000 a day) only, with none for conversations or search (8 of 15). The OpenAPI document lists 429 on six operations, and no Retry-After or backoff guidance was found in the docs. Upserts by document ID are safe to repeat (5 of 15). No SLA was found on the pricing or security pages, and the terms went unread (0). The REST API carries no beta label, while the MCP server is described as a first version and the client-side MCP server is a preview (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 75: A public OpenAPI 3.0 document with 54 paths and 68 operations, linked from the docs and from llms.txt (25). llms.txt at docs.dust.tt with a Markdown copy of every page (10). Operation descriptions mostly restate the summary (\"Search for nodes in the workspace\"), six operations have none, and none says when not to use an endpoint (10 of 20). 43 enums and 277 required markers, though ranges such as the search `limit` of 1 to 100 sit in the description text and not in the schema (10 of 15). 186 examples, while most error responses are a status and two words (\"Bad request\") with no body schema (9 of 15). The path carries `/api/v1`, the document a version (1.0.2), and the product changelog is dated and has carried API deprecation notices. There is no changelog for the API alone (11 of 15).\n- Agent ergonomics 67: Workspace search takes `limit` (1 to 100, default 25), and data source search takes `top_k` and `target_document_tokens`, so results can be sized. The MCP server's tool list needs a signed-in workspace and was not read (20 of 25). Cursor pagination on search, `limit` and `lastValue` on conversations, and tag, parent and timestamp filters on data source search (20). The source returns errors as a type and a message, such as `rate_limit_error` with the reason a call was blocked, but the docs give no list of error types (12 of 20). No idempotency keys in the OpenAPI document. Document and row upserts by ID can be repeated safely, and MCP tool annotations were not seen (6 of 20). Search needs only a query. One official SDK language, JavaScript, plus a CLI with a non-interactive mode that prints JSON (9 of 15).\n- Security \u0026 auth 75: API keys go in the `Authorization` header, can be limited to chosen spaces and capped by spend, and the MCP server takes OAuth with dynamic client registration, client ID metadata documents and a required `resource` parameter, issuing tokens that work only for MCP (28 of 30). An MCP client works as the signed-in user with that user's spaces only, an admin can switch the server off and restrict redirect URIs, and the API has an endpoint to approve or reject an agent's action. No read-only key type was found (16 of 20). Search returns content from connected sources, and no prompt-injection guidance for API or MCP clients was found in the pages read (3 of 15). Audit logs record user, API key and system actors with SIEM streaming, on the Enterprise plan only (12 of 15). SOC 2 Type II and HIPAA support on the security page, a HackerOne disclosure programme with no bounty stated, CodeQL in the public CI, and no security.txt (16 of 20).\n- Payments \u0026 pricing 20: Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public per seat with their credit allowances, but no price per top-up credit was found and the Enterprise programmatic rate is by quote (10). A Free seat has 500 lifetime credits, and the pricing page does not say whether a card is needed. Programmatic usage has no free credits and draws only on the workspace pool, which Free seats cannot use, so the free tier does not cover API calls that run agents (10 of 20). A person signs in through a browser to create a workspace and an admin creates the key (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 86: The changelog's newest entry is dated 8 October 2026 and the repository had 112 commits that day (30). 49 changelog entries from August to 8 October 2026 (20). Issues are public on GitHub (388 open issues and pull requests by the API's count), with a support email and a community site. We could not read reply times (15 of 25). `@dust-tt/client` 1.2.9 was published on 22 September 2026 and the CLI on 1 September, in one language (12 of 15). Public CI builds and tests each part of the repository, with CodeQL. The SDK and CLI ask for Node 24.16 or later (9 of 10).\n- Transparency \u0026 trust 68: The platform's source is public under the MIT licence (30). The Platform Privacy Policy gives retention periods (the agreement's length plus five years archived, three years for marketing contacts) and says model providers keep no data and may not train on it, which agrees with the security page. It covers Dust as controller only, and the DPA and terms of service went unread (18 of 30). No written deprecation policy was found. The changelog gave dated notice on 8 April 2026 that two analytics endpoints would be removed on 1 June 2026, under two months ahead (10 of 20). The privacy policy names the model providers (OpenAI, Anthropic, Mistral, Google, Fireworks), Google Cloud and Qdrant Cloud, and hosting is in the US or the EU. The full sub-processor list on the trust centre is drawn by script and was not read (13 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/dust.md (JSON https://www.anchorterminal.com/fixes/dust.json)\n\n### What we couldn't check\n\n- unchecked: the terms of service, any SLA and the DPA. dust.tt/terms redirects to dust-tt.notion.site, which is drawn by script and gave our reader no text. `provenance.terms` is left out for that reason.\n- unchecked: the trust centre at trust.dust.com (certificates, sub-processor list), which is drawn by script.\n- unchecked: the remote MCP server's tool count, input schemas and readOnlyHint or destructiveHint annotations, which need a signed-in workspace.\n- unchecked: whether the official MCP registry lists Dust. The registry did not answer our request.\n- unchecked: the effective date of the Platform Privacy Policy, which our reader did not find on the page.\n- unchecked: advisories for Dust at NVD or GitHub, and reply times on GitHub issues.\n- unchecked: the registration date of dust.tt. No RDAP service answers for .tt.\n- Not found in the reviewed documentation: a price per top-up credit, numeric rate limits for conversations and search, and whether a Free workspace needs a card.\n- The pricing page showed our reader prices in euros. Prices in other currencies were not seen, so `unitPrices` is empty.\n- The lead named the client-side MCP server (preview) and left out the remote MCP server at `https://dust.tt/mcp`, which is the main MCP surface. The legal entity is Permutation Labs.\n\n### Sources\n\n- docs index (llms.txt): \u003chttps://docs.dust.tt/llms.txt\u003e (seen 2026-10-08)\n- developer platform overview: \u003chttps://docs.dust.tt/docs/developer-platform/overview/developer-platform\u003e (seen 2026-10-08)\n- OpenAPI and Postman page: \u003chttps://docs.dust.tt/docs/developer-platform/dust-api-documentation/openapi-and-postman\u003e (seen 2026-10-08)\n- OpenAPI document: \u003chttps://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json\u003e (seen 2026-10-08)\n- rate limits: \u003chttps://docs.dust.tt/docs/developer-platform/core-concepts/rate-limits\u003e (seen 2026-10-08)\n- Dust MCP server: \u003chttps://docs.dust.tt/docs/user-documentation/agents/integrations/dust-mcp-server\u003e (seen 2026-10-08)\n- client-side MCP server (preview): \u003chttps://docs.dust.tt/docs/user-documentation/developers/client-side-mcp-server\u003e (seen 2026-10-08)\n- MCP endpoint, 401 and resource metadata: \u003chttps://dust.tt/.well-known/oauth-protected-resource/mcp\u003e (seen 2026-10-08)\n- Dust CLI: \u003chttps://docs.dust.tt/docs/developer-platform/dust-cli/dust-cli\u003e (seen 2026-10-08)\n- JavaScript SDK page: \u003chttps://docs.dust.tt/docs/developer-platform/overview/javascript-sdk\u003e (seen 2026-10-08)\n- credit management and programmatic usage: \u003chttps://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credit-management\u003e (seen 2026-10-08)\n- credits: \u003chttps://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credits\u003e (seen 2026-10-08)\n- audit logs: \u003chttps://docs.dust.tt/docs/user-documentation/admins/audit-logs/audit-logs\u003e (seen 2026-10-08)\n- changelog: \u003chttps://docs.dust.tt/docs/changelog\u003e (seen 2026-10-08)\n- pricing: \u003chttps://dust.tt/home/pricing\u003e (seen 2026-10-08)\n- security page: \u003chttps://dust.tt/home/security\u003e (seen 2026-10-08)\n- Platform Privacy Policy: \u003chttps://dust.tt/home/platform-privacy\u003e (seen 2026-10-08)\n- vulnerability disclosure programme: \u003chttps://dust.tt/home/vulnerability\u003e (seen 2026-10-08)\n- terms link (redirects to a Notion site, unread): \u003chttps://dust.tt/terms\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://dust.statuspage.io/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status components: \u003chttps://dust.statuspage.io/api/v2/components.json\u003e (seen 2026-10-08)\n- repository (licence, CI workflows, SECURITY.md, API source): \u003chttps://github.com/dust-tt/dust\u003e (seen 2026-10-08)\n- repository metadata: \u003chttps://api.github.com/repos/dust-tt/dust\u003e (seen 2026-10-08)\n- npm, @dust-tt/client: \u003chttps://registry.npmjs.org/@dust-tt/client\u003e (seen 2026-10-08)\n- npm, @dust-tt/dust-cli: \u003chttps://registry.npmjs.org/@dust-tt/dust-cli\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@dust-tt/client\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://dust.tt/.well-known/security.txt\u003e (seen 2026-10-08)\n- docs robots.txt: \u003chttps://docs.dust.tt/robots.txt\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 64/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Permutation Labs | 20/20 |\n| Domain age | dust.tt, no registry record we could read | 0/15 |\n| Endpoint on the vendor's domain | dust.tt | 15/15 |\n| Terms of service | not found | 0/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.dust.tt | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Platform Privacy Policy names Permutation Labs, 86 avenue de Wagram, 75017 Paris, France. It covers the platform where Dust is the data controller, not customer data Dust handles as a processor.\n\nNo terms link is recorded. dust.tt/terms redirects (308) to a Notion site, dust-tt.notion.site, which is drawn by script and gave our reader no text, so we could not tell which document there governs the platform.\n\nThe API and the MCP server answer on dust.tt and eu.dust.tt. OAuth for MCP is at signin.dust.tt.\n\ndust.tt/.well-known/security.txt returns 404. The repository's SECURITY.md sends reports to dust.tt/home/vulnerability, a HackerOne programme.\n\nNo RDAP service answers for the .tt registry, so the domain's registration date is not recorded.\n\ndust.tt/robots.txt returns 404. docs.dust.tt/robots.txt carries `Content-Signal: ai-train=yes, search=yes, ai-input=yes`.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0.\n\n\n**Privacy policy** (https://dust.tt/home/platform-privacy), read 2026-10-08, gives no date, states 6 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Not found in the text. Says how long data is kept.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The named foundation model providers are prohibited from using customer and personal data for model training. \"Foundational Model Providers (OpenAI, Anthropic, Mistral, Google, Fireworks) are prohibited from using any customer and personal data for model training.\"\n- Also in the text (2026-10-08). Internal development, one purpose for which Dust processes personal data, is defined to include benchmarking and machine learning. \"\"Internal Development\" means when Dust improves and better develops the Platform including testing, research, reporting, benchmarking, machine learning, performance analyses, predictions and trend analysis.\"\n\n## Live (updated 2026-10-09 10:14 UTC)\n\n- Right now: up, HTTP 401, 139 ms, checked 2026-10-09 10:14 UTC (get on `https://dust.tt/mcp`, asks for auth)\n- Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 151 ms · p95 198 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/dust.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- The platform's source is public under the MIT licence at github.com/dust-tt/dust, with commits on the day of the check\n- Public OpenAPI 3.0 document with 68 operations, plus llms.txt and a Markdown copy of each docs page\n- Remote MCP server at `https://dust.tt/mcp` and `https://eu.dust.tt/mcp`, with OAuth, dynamic client registration and the signed-in user's own access\n- API keys can be limited to chosen spaces and given a spending cap on a rolling 30 days\n- SOC 2 Type II on the security page, a HackerOne disclosure programme, and US or EU hosting\n\n## Weaknesses\n\n- Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use\n- Rate limits are published for document upserts and app runs only, and no Retry-After guidance was found in the docs\n- The terms link redirects to a Notion site drawn by script, so the service terms, any SLA and the DPA went unread\n- Audit logs are an Enterprise feature, and no security.txt is published (404)\n- Two major incidents on status.dust.tt in the last 90 days, one of 2 hours 3 minutes on 16 July 2026 that covered the API\n\n## Before you call it (notes for agents)\n\n1. Use `https://eu.dust.tt` for a workspace in the EU region and `https://dust.tt` otherwise, for both the API and the MCP server\n2. Connect an MCP client by OAuth and send the `resource` parameter in authorisation and token requests. API keys do not work on the MCP server\n3. Expect HTTP 429 with type `rate_limit_error` when the credit pool, the programmatic monthly cap or the key's spend cap is exhausted. Retrying will not help\n4. Call `GET /api/v1/w/{wId}/search` with `limit` (1 to 100, default 25) and `cursor`, or a data source view's search with `top_k`\n5. Keep document upserts under 120 a minute per workspace\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @dust-tt/client\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"dust\": {\n      \"type\": \"http\",\n      \"url\": \"https://dust.tt/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/dust. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Glean | B | 69.8 | 159 | knowledge.search, agent.mcp-client | no | https://www.anchorterminal.com/tools/glean.md |\n| Onyx | B | 65 | 303 | knowledge.search, agent.mcp-client | no | https://www.anchorterminal.com/tools/onyx.md |\n| Cohere North | C | 55.1 | 598 | knowledge.search, agent.mcp-client | no | https://www.anchorterminal.com/tools/cohere-north.md |\n| Open WebUI | D | 51.8 | 664 | agent.mcp-client, knowledge.search | no | https://www.anchorterminal.com/tools/open-webui.md |\n| OpenAI Agents SDK | AA | 86.2 | 1 | agent.mcp-client | no | https://www.anchorterminal.com/tools/openai-agents-sdk.md |\n| Pydantic AI | A | 83.7 | 3 | agent.mcp-client | no | https://www.anchorterminal.com/tools/pydantic-ai.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The remote MCP server answers at `https://dust.tt/mcp` (US) and `https://eu.dust.tt/mcp` (EU), takes OAuth only, and its first version lists agents, works with conversations and files, and searches across workspace spaces (source: \u003chttps://docs.dust.tt/docs/user-documentation/agents/integrations/dust-mcp-server\u003e)\n- An unauthenticated request to `https://dust.tt/mcp` returns 401 with a `resource_metadata` pointer, and the metadata names `https://signin.dust.tt` as the authorisation server (source: \u003chttps://dust.tt/.well-known/oauth-protected-resource/mcp\u003e)\n- The OpenAPI 3.0 document has 54 paths and 68 operations, with servers `https://dust.tt` (us-central1) and `https://eu.dust.tt` (europe-west1) (source: \u003chttps://raw.githubusercontent.com/dust-tt/dust/refs/heads/main/front-api/public/swagger.json\u003e)\n- Programmatic usage, which covers API calls, draws only on the workspace credit pool and has no free credit baseline (source: \u003chttps://docs.dust.tt/docs/user-documentation/admins/usage-seats-and-credits/credit-management\u003e)\n- API keys can be limited to several spaces since 1 April 2026 and carry an optional spending cap since 29 January 2026 (source: \u003chttps://docs.dust.tt/docs/changelog\u003e)\n- The changelog announced on 8 April 2026 that `/api/v1/w/{wId}/usage` and `/api/v1/w/{wId}/workspace-usage` would be removed on 1 June 2026 (source: \u003chttps://docs.dust.tt/docs/changelog\u003e)\n- status.dust.tt lists a major incident of 2 hours 3 minutes on 16 July 2026 covering Conversations, the app platform and the API, and one of 6 minutes on 18 September 2026 (source: \u003chttps://dust.statuspage.io/api/v2/incidents.json\u003e)\n- The security page states SOC 2 Type II, HIPAA support, AES-256 at rest, no model training on customer data and zero data retention at model providers (source: \u003chttps://dust.tt/home/security\u003e)\n\n## Compare\n\n- [Alation vs Dust](https://www.anchorterminal.com/compare/alation-vs-dust.md): C 60.3 vs B 62.8\n- [Atlan vs Dust](https://www.anchorterminal.com/compare/atlan-vs-dust.md): B 62.5 vs B 62.8\n- [Cohere North vs Dust](https://www.anchorterminal.com/compare/cohere-north-vs-dust.md): C 55.1 vs B 62.8\n- [Dust vs Glean](https://www.anchorterminal.com/compare/dust-vs-glean.md): B 62.8 vs B 69.8\n- [Dust vs Guru](https://www.anchorterminal.com/compare/dust-vs-guru.md): B 62.8 vs E 45.1\n- [Dust vs Onyx](https://www.anchorterminal.com/compare/dust-vs-onyx.md): B 62.8 vs B 65\n- [Dust vs Overclock](https://www.anchorterminal.com/compare/dust-vs-overclock.md): B 62.8 vs F 7.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on dust.tt or one of its subdomains, or the README of github.com/dust-tt/dust. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"dust\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/dust\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/dust.svg\" alt=\"Dust on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Dust on Anchor Terminal](https://www.anchorterminal.com/badges/dust.svg)](https://www.anchorterminal.com/tools/dust)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/dust\"\u003eDust on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Dust is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/dust-dark.png\n- Light: https://www.anchorterminal.com/assets/share/dust-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Company knowledge \u0026 data catalogues",
        "url": "https://www.anchorterminal.com/categories/company-knowledge"
      },
      {
        "name": "Dust",
        "url": ""
      }
    ],
    "description": "Dust is a platform for building AI agents on a company's documents and connected tools, from Permutation Labs in Paris. Outside agents reach it through a REST API, a JavaScript SDK, a CLI and a remote MCP server with OAuth.",
    "facts": [
      "rank #378 of 842",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Dust",
    "image": "https://www.anchorterminal.com/assets/og/tools-dust.png",
    "path": "/tools/dust",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Dust review for AI agents, grade B (62.8/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/dust"
  },
  "tokens": {
    "markdown": 7050,
    "slim": 1680
  },
  "version": 1
}
