# Grist (slim) > Grist is a spreadsheet-database hybrid from Grist Labs with typed columns and Python formulas, sold as a hosted service and as open-source software to self-host. Agents reach it through a REST API and an MCP server with OAuth. - Full: https://www.anchorterminal.com/tools/grist.md (~8,450 tokens) · this version ~2,130 tokens · JSON https://www.anchorterminal.com/tools/grist.json · canonical https://www.anchorterminal.com/tools/grist - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 50.1/100 · rank #597 of 722 · #10 in Spreadsheets & operational tables · not agent-ready · confidence medium** Assessment: OAuth tokens carry seven scopes, can be limited to chosen documents and expire after an hour, and the REST API has a public OpenAPI file with an add-or-update call. No status page, SLA terms, DPA or security.txt was found, and the docs say the hosted service has no SOC 2 or ISO 27001 audit. ## Facts - Kind: HTTP API · vendor: Grist Labs Inc. · category: Spreadsheets & operational tables · legal entity: Grist Labs Inc. · provenance 71/100 - Endpoint: `https://docs.getgrist.com/api` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 for the community edition in gristlabs/grist-core. The full edition, which adds the MCP server, the OAuth server and audit log streaming, is proprietary and needs an activation key after a 30-day trial. Docs are CC BY-SA 4.0 - Probe metrics: not measured yet (probes haven't run) - Surfaces graded: Hosted Grist's REST API at https://docs.getgrist.com/api (or https://.getgrist.com/api) and its MCP server at https://docs.getgrist.com/api/mcp. The same API can be self-hosted, and the MCP server needs the full edition there - Free tier: 5,000 rows a document, 10 team members, 1 GB of attachments a document, 3,000 API calls a month per site with REST and MCP calls sharing the pool - Rate limits: Free 3,000 calls a month per site and 5 requests a second per document. Pro 40,000 and Business 60,000 calls per document per day. 10 concurrent requests per document on all plans, 429 beyond that. 1 MB per request body, 50 MB per upload - Auth and scopes: API key (`Authorization: Bearer`), one per account, full account access. OAuth 2.0 with PKCE and scopes `doc:read`, `doc:write`, `doc.schema:write`, `doc:download`, `doc:webhooks`, `user.profile:read`, `offline_access`, limited to chosen sites, workspaces or documents - Tokens: Access tokens prefixed `grist_at_` last 1 hour, refresh tokens prefixed `grist_rt_` last 60 days and rotate. Revocation at `/oidc/revocation` or from the Authorised apps page - Read and write: Records (list, add, modify, add or update, delete), tables and columns, attachments, webhooks, read-only SQL, downloads as CSV, TSV, XLSX or the whole document, plus sites, workspaces, access and service accounts - Filtering: `filter` (JSON object of column to allowed values), `sort`, `limit`, `hidden` and `cellFormat` on list records, also as `X-Sort` and `X-Limit` headers. No offset or cursor. `/sql` runs a SELECT with parameters and a timeout - MCP server: Remote, streamable HTTP, 34 tools listed in the docs for discovery, reading, writing, schema, pages and widgets, and attachments. OAuth, API key or service account. Tool schemas aren't public - Change events: Webhooks per table on rows added or updated, with a ready column as a condition, an optional `Authorization` header, a batched queue and periodic retries - SDKs: `grist-api` on npm (0.1.7, February 2022) and PyPI (0.1.1, October 2024), both by Grist Labs. Community clients for Go, Rust, R and others are linked from the docs - Deprecations: No policy found. The OpenAPI file marks the four `/data` operations deprecated in favour of `/records`, and release notes list API changes - Certifications: None. The data security page says hosted Grist has not gone through SOC 2, ISO 27001, HIPAA or GDPR certification. No bug bounty or security.txt found - Advisories: 10 published on GitHub, 5 in the last 12 months, 2 of them critical (21 January and 13 September 2026), all fixed - Status and SLA: No status page found. SLAs are named among Enterprise services on the pricing page, with no terms published - Data location: AWS in the United States, with S3 for encrypted storage. A dedicated server in a chosen AWS region on Enterprise. Deleted documents stay 30 days in the trash - Open source: Community edition under Apache-2.0 with the REST API, webhooks and access rules. The MCP server, OAuth server, AI Assistant and audit log streaming are in the proprietary full edition - Prices: Pro (hosted) $10 per seat per month; Business (hosted) $30 per seat per month - Scores: Reliability 39, Performance pending, Schema & documentation 63, Agent ergonomics 57, Security & auth 62, Payments & pricing 30, Task success pending, Maintenance & community 78, Transparency & trust 61 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Graded on hosted Grist's REST API and MCP server at docs.getgrist.com, with the hosted lines. · Schema & documentation, The OpenAPI 3.0.0 file in the public docs repository has 101 paths and 120 operations and is rendered at support.getgrist.com/api. · Agent ergonomics, The MCP docs list 34 tools, more than 30, which earns 5. We added 8 because OAuth scopes limit a connection to reading and the client can as… · Security & auth, OAuth 2.0 authorisation code flow with PKCE, seven scopes, grants limited to chosen sites, workspaces or documents, access tokens of 1 hour… · Payments & pricing, Graded on hosted Grist. · Maintenance & community, Release v1.7.20 was tagged on 28 September 2026, 10 days before the check (30). · Transparency & trust, The core in gristlabs/grist-core is Apache-2.0. The MCP server, the OAuth server and audit log streaming are in the proprietary full edition… - Sources: 34, open questions: 9, both in the full twin - Capabilities: sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas - JSON: https://www.anchorterminal.com/api/v1/tools/grist.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/grist.svg` or a link to https://www.anchorterminal.com/tools/grist from a page on getgrist.com or one of its subdomains, or the README of github.com/gristlabs/grist-core, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect through OAuth, not an API key. Ask for `doc:read` alone for reading, and have the user pick Selected resources on the consent screen 2. Keep `doc.schema:write` off unless needed. The docs say formula editing lets its holder read any data in the document whatever the access rules 3. Send requests for one document one at a time. The eleventh concurrent request gets 429, and no Retry-After header is documented 4. Use `PUT /api/docs/{docId}/tables/{tableId}/records` with `require` to add or update by key, so a retried write doesn't create a duplicate row 5. Use the `/records` endpoints, not the deprecated `/data` ones, and split large writes to stay under the 1 MB body limit ## Connect ```bash pip install grist-api ``` ```bash curl -H "Authorization: Bearer " https://docs.getgrist.com/api/orgs ``` ```bash claude mcp add --transport http grist https://docs.getgrist.com/api/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/grist ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | NocoDB | BB | 75.7 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/nocodb.min.md | | Airtable | BB | 70.9 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/airtable.min.md | | SeaTable | B | 66.3 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/seatable.min.md | | Coda (Superhuman Docs) | B | 64.8 | sheets.read, sheets.write, sheets.tables, sheets.records, sheets.formulas | https://www.anchorterminal.com/tools/coda.min.md | | Baserow | B | 63.6 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/baserow.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)