HERE Location Services
by HERE Technologies HTTP API in Maps, geocoding & places
Hosted
HERE Europe B.V. · here.com since 1995 · status page · who's behind it
HERE Technologies' REST APIs for geocoding, place search, routing, matrix and isoline routing, traffic, transit and map tiles, called with an API key or OAuth token. A hosted MCP server, HERE Location Reasoning, exposes 13 of these operations as tools.
Good for Fleet and logistics work that needs truck routing, large matrices, isolines, traffic and transit from one vendor with an SLA.
Is this your product? Claim this listing or verify it
Assessment. Each endpoint page carries an OpenAPI 3.0 definition as Markdown, and HERE publishes 99.9 per cent monthly availability targets and a six-month deprecation policy. The Platform Terms of September 2023 forbid using HERE Materials in connection with a machine learning or AI system, and the price table could not be read.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://geocode.search.hereapi.com/v1- Auth
- OAuth or key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- Proprietary service under the HERE Platform Terms
- Tools exposed
- 13
- Docs
- docs.here.com
- llms.txt
- published
- Last release
- APIs
- Geocoding and Search v7 (geocode, reverse geocode, autocomplete, autosuggest, discover, browse, lookup, batch), Routing v8, Matrix Routing v8, Isoline Routing v8, Waypoints Sequence, Route Matching, Traffic, Public Transit, raster and vector tiles
- MCP server
- HERE Location Reasoning, hosted at https://hlr.here.ai/mcp. 13 tools in the docs, two marked experimental. Needs an account entitlement
- Credentials
- API key in the
apiKeyquery parameter, OAuth 2.0 client credentials, or OAuth 2.1private_key_jwt. Two keys or two JWKs an app, and up to 20 trusted domains in the console - Storage
- Results may be cached or stored outside the platform for at most 30 days (24 hours for Positioning), and only as HTTP caching headers allow, per the Platform Terms
- AI clause
- Platform Terms forbid using HERE Materials in connection with a machine learning or AI system, generative AI included
- Availability target
- 99.9 per cent a month for Geocoding and Search v7 and Routing v8. Service credits need the Essential support plan or above
- Errors
- JSON body with
status,title,code,cause,action,correlationIdandrequestId. 429 or 503 when a quota is exceeded - Deprecations
- Six months' notice before a product is discontinued, 6 to 12 months for a deprecated feature
- Data use
- HERE uses anonymised or aggregated findings from platform use to develop its products. Essential Data Processing domains such as
subp-router.hereapi.comswitch that off - Certifications
- ISO/IEC 27001:2022, 27701, 27017, 27018, 42001, TISAX AL3, CSA STAR Level 2, SOC 2 Type 2 for Platform Foundation and Workspace
- Support
- Developer plan $50 a month with 72-hour response, Essential from $525, Advanced from $2,200
- Capabilities
- geo.geocode geo.reverse geo.places geo.routing geo.tiles
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Every endpoint page has a Markdown twin holding its OpenAPI 3.0 definition, indexed from
llms.txtfiles per product - 99.9 per cent monthly availability targets published for Geocoding and Search v7 and Routing v8
- Lifecycle policy promises six months' notice before a product is discontinued and 6 to 12 months for a deprecated feature
- OAuth 2.1
private_key_jwtcredentials alongside API keys, with two keys an app for rotation and trusted-domain limits - ISO 27001, 27701, 27017, 27018 and 42001 certificates, TISAX AL3, and SOC 2 Type 2 for Platform Foundation and Workspace
Weaknesses
- Platform Terms section f forbids using HERE Materials in connection with a machine learning or AI system, generative AI included. This matters before any probe is run
- The Base Plan price table is drawn by script, so per-request prices, free allowances and rate limits were not read
- API keys travel in the
apiKeyquery parameter - Results may be cached or stored outside the platform for 30 days at most, and only as HTTP caching headers allow
- Location Reasoning returns 403 unless the account is entitled, and the docs send the reader to an account representative or AWS Marketplace
- The acceptable use policy of January 2022 lists benchmarking and scraping among prohibited activities
Before you call it notes for agents
- Send
Authorization: Bearerwith an OAuth token where logs are kept. TheapiKeyquery parameter puts the secret in every URL - Do not store results for more than 30 days, and follow the HTTP caching headers on each response
- Treat 429 and 503 as throttling. HERE says a traffic surge can be throttled for about 10 minutes below the account's quota
- Read
code,causeandactionin the error body, and quotecorrelationIdto support - For Location Reasoning, send
initialize, keep theMcp-Session-Idheader on later calls, and send a bearer token ontools/call
Who's behind it provenance 73/100
- Legal entity namedHERE Europe B.V.20/20
- Domain agehere.com, registered 1995-06-11 (31 years)15/15
- Endpoint on the vendor's domaingeocode.search.hereapi.com is not on here.com0/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 1 clause that costs points8/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.here.com/status10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2023-09-18, states 7 of 7, 3 to know
TL;DR Dated 2023-09-18. States all 7 things a reader expects. To know before relying on it, limits on benchmarking, cut-off without notice or for any reason and no update in three years.
Restricts benchmarking or competitive usecosts points
g) Use HERE Materials for: (i) benchmarking of third-party data sets, or (ii) a reference to create, enhance, or improve a product or service competitive to HERE;
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
HERE may suspend or terminate your access to HERE Materials without notice if you choose not to accept the updated Terms.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Has not been updated for three years or more
Effective date: Monday, 18 September, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-09-18
Effective date: Monday, 18 September, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Illinois
is the HERE Contracting Party in accordance with Section 1, it will be construed and governed by the substantive laws of the State of Illinois, USA, without giving effect to any conflict of law provisions.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 24 months before the claim
…aggregate, cumulative, and total liability of each Party, its employees, licensors, and Affiliates will in no event exceed the amount of fees paid by you under these Terms in the twenty-four (24) months preceding the first incident from which the claim arose.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
HERE may suspend or terminate your access to HERE Materials without notice if you choose not to accept the updated Terms.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
HERE reserves the right to change these Terms at any time and will provide reasonable notice to you of material changes on the Platform, in your account, via email, or via other means of communication as determined appropriate by HERE.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You may not access or use the HERE Materials or accept these Terms if (i) you are not of legal age in the country in which you reside;
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
The service levels and scope of support services are available at https://www.here.com/docs/bundle/service-level-agreement-policies/page/README.html.
Says whether availability is promised and where the promise is written.
The list of things a customer may not do includes using HERE Materials in connection with a machine learning or AI system, generative AI among them.
f) Use HERE Materials in connection with a machine learning or artificial intelligence (“AI”) system, including but not limited to, models used in connection with natural language processing, algorithm optimization and training
Noted by a second reader on 2026-10-08.
Results may not be cached or stored outside the platform for more than 30 days, or 24 hours for HERE Positioning services, with stated exceptions.
j) Cache or store outside of the Platform any Results that include anything from the use of HERE Content or Location Services for more than 30 days, except HERE Positioning services which cannot be cached or stored outside the Platform for more than 24 hours
Noted by a second reader on 2026-10-08.
HERE deletes the customer's content, applications and other account materials after a subscription plan or the terms end.
HERE will delete Your Content, Applications, and other materials in your Platform account after the termination of your Subscription Plan or these Terms.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 13,344 words
Privacy policy dated 2024-08-29, states 8 of 8
TL;DR Dated 2024-08-29. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2024-08-29
Effective date: Thursday, 29 August, 2024
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This privacy policy (“Policy”) describes how we collect and use personal data where HERE is the data controller or where we refer to the applicability of this Policy.
The basic statement a privacy policy exists to make.
Says how long data is kept
We endeavor to only collect personal data that are necessary for the purposes for which they are collected, and to retain such data for no longer than is necessary for such purposes.
Says when data sent to the service is deleted.
Says who else receives the data
This might include linking to this Policy and the relevant Supplements, or providing the transparency in integrated and embedded notices which identify us as the service provider or controller.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell, lease, rent or otherwise disclose your personal data to third parties unless otherwise stated below.
A plain statement either way.
Says what rights people have over their data
You may exercise your rights by contacting us through our request submission webform at https://www.here.com/en-gb/privacy/here-data-subject-request or by managing your account and choices through available profile management tools on your device and our services.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@HERE.com
You may contact the HERE Privacy Office at privacy@HERE.com to obtain additional information about retention of your personal data.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…protection for your personal data is provided as required by applicable law, for example, by using standard contractual clauses approved by the European Commission or relevant authorities (where necessary) and by requiring the use of other appropriate technical and organizational information security measures.
The countries data goes to and the safeguard used.
The policy does not cover personal data HERE processes on behalf of customers when supplying a service, which the terms for that service govern.
This Policy does not apply to the processing of personal data that we carry out on behalf of our customers for the purpose of service provisioning.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 3,222 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The HERE Platform Terms, effective 18 September 2023, name HERE Europe B.V., Kennedyplein 222-226, 5611 ZT Eindhoven, as contracting party, and HERE North America, LLC, Chicago, for customers in the Americas.
The privacy policy, effective 29 August 2024, names HERE Global B.V. as controller and says it does not apply to personal data processed on behalf of customers. The Platform Terms incorporate it and a Data Processing Agreement published as a PDF.
The APIs answer on hereapi.com (for example geocode.search.hereapi.com and router.hereapi.com) and the MCP server on hlr.here.ai, both second domains of the vendor.
www.here.com/.well-known/security.txt returned the site's error page. The security page gives security@here.com and a 90-day disclosure window.
RDAP for here.com gives a registration date of 1995-06-11.
legal.here.com/en-gb/terms/here-platform redirects to the September 2023 terms on www.here.com.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://geocode.search.hereapi.com/v1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 3 minutes ago
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| docs.here.com/routing/docs/routing-v8-changelog | changelog | 6 hours ago · 200 | no change seen |
| www.here.com/en-gb/privacy | privacy | 6 hours ago · 200 | no change seen |
| www.here.com/en-gb/terms/here-platform-terms-september-2023 | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/here-location-services.json
Notable
- Each endpoint page has a Markdown twin holding its OpenAPI 3.0.0 definition, and the geocode definition is at version 7.157 source
- HERE Location Reasoning is a hosted MCP server at https://hlr.here.ai/mcp with 13 documented tools, among them
geocode,calculate-route,matrix-routing,discover,traffic-flowandisoline-routesource - The Platform Terms forbid using HERE Materials in connection with a machine learning or AI system, including generative AI source
- Results may be cached or stored outside the platform for at most 30 days, and only as the HTTP caching headers allow source
- Monthly availability targets of 99.9 per cent are published for Geocoding and Search v7 and Routing v8 source
- Routing v8 reached 8.162.0 on 7 September 2026, with dated changelog entries for each release source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 11.4 | |
| Graded on the REST APIs (Geocoding and Search v7, Routing v8) with the hosted lines. HERE's docs describe a public status page at status.here.com/status with current status, a status history tab and scheduled maintenance (20). The page is drawn by script and showed only a loading message, so the 90-day record is unread (5). No rate limit with a number was found in the docs. A Rate Limit Rules API returns an account's own rules, and the Base Plan limits sit on the unread price page (5 of 15). The Limits and Quotas page says an exceeded quota returns 429 or 503 and that a surge can be throttled for about 10 minutes, and the OpenAPI definition lists 429. No Retry-After header or backoff guidance was found, and the calls are reads (7 of 15). Monthly availability targets of 99.9 per cent are published for Geocoding and Search v7 and Routing v8, with service credits only for the Essential support plan and above (10). Both APIs are in the Active lifecycle stage (10). Total 57. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.1 | |
Each endpoint page has a Markdown twin holding an OpenAPI 3.0.0 definition, read for /geocode at version 7.157 (25). docs.here.com has a site llms.txt and one for each product and section (10). Endpoint descriptions state the purpose, and parameter descriptions are long, with ALPHA, BETA and RESTRICTED maturity tags. Little says when not to use an endpoint (14 of 20). Parameters are typed with 34 enums in the geocode definition, ranges such as limit 1 to 100 and defaults (13 of 15). 400, 405, 429 and 503 share an ErrorResponse schema, and the developer guide has code examples for each endpoint (12 of 15). The Routing v8 changelog is dated by entry up to 8.162.0 on 7 September 2026. The Geocoding and Search release notes are numbered by release without dates (13 of 15). The Location Reasoning tool schemas come only from tools/list and were not read. Total 87. | |||
| Agent ergonomics | 13%16.2 | 12.0 | |
limit sizes geocoding responses (1 to 100, default 20), and show and return parameters add optional blocks only when asked for. The MCP server lists 13 tools, two of them experimental, and passes cached route and isoline IDs between tools so geometry is not returned twice (18 of 25). Filters by country, result type, position and bounding area are documented. No offset or cursor paging was found for geocoding (15 of 20). Errors carry status, title, code, cause, action and correlationId, and the routing changelog names error codes such as E605502 (17). Calls are reads and safe to repeat. MCP annotations were not read (14 of 20). A geocode needs only q and a credential. The SDKs in the docs are for maps on JavaScript, Android, iOS and Flutter, and no server-side REST client was found in the reviewed documentation (10 of 15). Total 74. | |||
| Security & auth | 14%17.5 | 11.4 | |
Credentials are API keys, OAuth 2.0 client credentials and OAuth 2.1 private_key_jwt with a registered JWK, where the private key stays with the customer. Tokens are short-lived and can be scoped to a project, and an app holds two API keys or two JWKs for rotation (30). Less 10 because the documented API key method is the apiKey query parameter (20). The location services only read. Trusted domains limit where a key works, and app credentials do not inherit the user's permissions (15 of 20). Results carry place names from third-party sources. The Location Reasoning examples load a guardrails://location-reasoning-usage-policy resource and a hlr___secure_location_reasoning prompt, whose text was not read (7 of 15). A Usage API reports billable usage by app and project. Per-call logs were not found (6 of 15). ISO/IEC 27001:2022, 27701, 27017, 27018 and 42001 certificates, SOC 2 Type 2 scoped to Platform Foundation and Workspace, TISAX AL3 and CSA STAR Level 2 are listed. A disclosure policy of 13 July 2023 names security@here.com with a 90-day window. No bug bounty and no security.txt were found (17 of 20). Total 65. | |||
| Payments & pricing | 10%12.5 | 1.2 | |
| No x402, MPP or L402 was found in the docs index or the terms (0). The Base Plan price page is public, but its table is drawn by script and showed no prices to our reader, so per-request prices score as absent. This is a limit of our reading and not a finding that prices are hidden (0 of 20). HERE's docs say a new organisation can get started for free. Whether a card is asked for was not established (10 of 20). Sign-up is a browser flow with email verification (0). Support plans are priced in public, from $50 a month for the Developer plan. Total 10. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.2 | |
| The newest dated API entries are Matrix Routing 8.49.0 on 9 September 2026 and Routing 8.162.0 on 7 September 2026, 30 and 32 days before the check. The Matrix entry is a documentation change, so we scored the 90-day band (20 of 30). Routing v8 had releases 8.160.0, 8.161.0 and 8.162.0 between 16 July and 7 September (20). Changelogs are public for each API, and paid support plans state response times from 72 hours down to 4. A free community channel was not checked (10 of 15). HERE SDK and Maps API for JavaScript changelogs are indexed, but their dates were not read, and no HERE entry was found in the official MCP registry (5 of 15). Package health is not visible for a closed service (5 of 10). Total 60. | |||
| Transparency & trusteditorial 52, provenance 73 | 7%8.8 | 5.5 | |
| Closed service under public, dated terms. The HERE Platform Terms, effective 18 September 2023, name the contracting entity by region and govern the Base Plan (15 of 30). The terms say HERE analyses use of the platform and uses anonymised or aggregated findings to develop its products, and Essential Data Processing domains switch that off. The privacy policy of 29 August 2024 says it does not cover processing done on behalf of customers and gives no retention periods. The DPA is a PDF we did not read (14 of 30). The Product Lifecycle Policy gives six months' notice before discontinuation and 6 to 12 months for a deprecated feature, and changelogs mark deprecations with dates (20). No sub-processor list or data location was found on the pages read (3 of 20). Total 52. | |||
| Negative events | ≤15 |
| -3 |
| Total | 58 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on HERE Location Services, or have the agent fetch /fixes/here-location-services.md. A fix counts at the next check, once it's public.
Show it
# Fix list: HERE Location Services From Anchor Terminal's listing at https://www.anchorterminal.com/tools/here-location-services, the October 2026 research run, assessed 9 October 2026. Grade C, 58 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on HERE Location Services: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 10 out of 100, up to 11.3 more on the total Why it scored 10: No x402, MPP or L402 was found in the docs index or the terms (0). The Base Plan price page is public, but its table is drawn by script and showed no prices to our reader, so per-request prices score as absent. This is a limit of our reading and not a finding that prices are hidden (0 of 20). HERE's docs say a new organisation can get started for free. Whether a card is asked for was not established (10 of 20). Sign-up is a browser flow with email verification (0). Support plans are priced in public, from $50 a month for the Developer plan. Total 10. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Reliability, 57 out of 100, up to 8.6 more on the total Why it scored 57: Graded on the REST APIs (Geocoding and Search v7, Routing v8) with the hosted lines. HERE's docs describe a public status page at status.here.com/status with current status, a status history tab and scheduled maintenance (20). The page is drawn by script and showed only a loading message, so the 90-day record is unread (5). No rate limit with a number was found in the docs. A Rate Limit Rules API returns an account's own rules, and the Base Plan limits sit on the unread price page (5 of 15). The Limits and Quotas page says an exceeded quota returns 429 or 503 and that a surge can be throttled for about 10 minutes, and the OpenAPI definition lists 429. No Retry-After header or backoff guidance was found, and the calls are reads (7 of 15). Monthly availability targets of 99.9 per cent are published for Geocoding and Search v7 and Routing v8, with service credits only for the Essential support plan and above (10). Both APIs are in the Active lifecycle stage (10). Total 57. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Security & auth, 65 out of 100, up to 6.1 more on the total Why it scored 65: Credentials are API keys, OAuth 2.0 client credentials and OAuth 2.1 `private_key_jwt` with a registered JWK, where the private key stays with the customer. Tokens are short-lived and can be scoped to a project, and an app holds two API keys or two JWKs for rotation (30). Less 10 because the documented API key method is the `apiKey` query parameter (20). The location services only read. Trusted domains limit where a key works, and app credentials do not inherit the user's permissions (15 of 20). Results carry place names from third-party sources. The Location Reasoning examples load a `guardrails://location-reasoning-usage-policy` resource and a `hlr___secure_location_reasoning` prompt, whose text was not read (7 of 15). A Usage API reports billable usage by app and project. Per-call logs were not found (6 of 15). ISO/IEC 27001:2022, 27701, 27017, 27018 and 42001 certificates, SOC 2 Type 2 scoped to Platform Foundation and Workspace, TISAX AL3 and CSA STAR Level 2 are listed. A disclosure policy of 13 July 2023 names security@here.com with a 90-day window. No bug bounty and no security.txt were found (17 of 20). Total 65. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 74 out of 100, up to 4.2 more on the total Why it scored 74: `limit` sizes geocoding responses (1 to 100, default 20), and `show` and `return` parameters add optional blocks only when asked for. The MCP server lists 13 tools, two of them experimental, and passes cached route and isoline IDs between tools so geometry is not returned twice (18 of 25). Filters by country, result type, position and bounding area are documented. No offset or cursor paging was found for geocoding (15 of 20). Errors carry `status`, `title`, `code`, `cause`, `action` and `correlationId`, and the routing changelog names error codes such as `E605502` (17). Calls are reads and safe to repeat. MCP annotations were not read (14 of 20). A geocode needs only `q` and a credential. The SDKs in the docs are for maps on JavaScript, Android, iOS and Flutter, and no server-side REST client was found in the reviewed documentation (10 of 15). Total 74. The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Maintenance & community, 60 out of 100, up to 3.5 more on the total Why it scored 60: The newest dated API entries are Matrix Routing 8.49.0 on 9 September 2026 and Routing 8.162.0 on 7 September 2026, 30 and 32 days before the check. The Matrix entry is a documentation change, so we scored the 90-day band (20 of 30). Routing v8 had releases 8.160.0, 8.161.0 and 8.162.0 between 16 July and 7 September (20). Changelogs are public for each API, and paid support plans state response times from 72 hours down to 4. A free community channel was not checked (10 of 15). HERE SDK and Maps API for JavaScript changelogs are indexed, but their dates were not read, and no HERE entry was found in the official MCP registry (5 of 15). Package health is not visible for a closed service (5 of 10). Total 60. The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Transparency & trust, 63 out of 100, up to 3.2 more on the total Made of editorial 52, provenance 73. Why it scored 63: Closed service under public, dated terms. The HERE Platform Terms, effective 18 September 2023, name the contracting entity by region and govern the Base Plan (15 of 30). The terms say HERE analyses use of the platform and uses anonymised or aggregated findings to develop its products, and Essential Data Processing domains switch that off. The privacy policy of 29 August 2024 says it does not cover processing done on behalf of customers and gives no retention periods. The DPA is a PDF we did not read (14 of 30). The Product Lifecycle Policy gives six months' notice before discontinuation and 6 to 12 months for a deprecated feature, and changelogs mark deprecations with dates (20). No sub-processor list or data location was found on the pages read (3 of 20). Total 52. The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Endpoint on the vendor's domain: geocode.search.hereapi.com is not on here.com (0 of 15) - Terms of service: read, states 7 of the 7 things a reader expects, and has 1 clause that costs points (8 of 10) - security.txt: not found (0 of 10) ## 7. Schema & documentation, 87 out of 100, up to 2.1 more on the total Why it scored 87: Each endpoint page has a Markdown twin holding an OpenAPI 3.0.0 definition, read for `/geocode` at version 7.157 (25). docs.here.com has a site `llms.txt` and one for each product and section (10). Endpoint descriptions state the purpose, and parameter descriptions are long, with ALPHA, BETA and RESTRICTED maturity tags. Little says when not to use an endpoint (14 of 20). Parameters are typed with 34 enums in the geocode definition, ranges such as `limit` 1 to 100 and defaults (13 of 15). 400, 405, 429 and 503 share an `ErrorResponse` schema, and the developer guide has code examples for each endpoint (12 of 15). The Routing v8 changelog is dated by entry up to 8.162.0 on 7 September 2026. The Geocoding and Search release notes are numbered by release without dates (13 of 15). The Location Reasoning tool schemas come only from `tools/list` and were not read. Total 87. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 10 July 2026. The Routing v8 changelog marks `mlDuration` as Deprecated and says `return=mlDuration` is still accepted but no longer returns a value. HERE's lifecycle policy says a deprecated feature continues to operate for 6 to 12 months after notice. Three points (https://docs.here.com/routing/docs/routing-v8-changelog.md) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: Base Plan prices, free monthly allowances, rate limits and whether a card is needed. https://www.here.com/get-started/pricing is drawn by script and showed only headings. - unchecked: the 90-day incident record. https://status.here.com/status is drawn by script, and robots.txt on that host disallows `/status`. - unchecked: Location Reasoning tool schemas, descriptions and annotations. They are published only through `tools/list` on https://hlr.here.ai/mcp, which we did not call. The count of 13 tools comes from the docs table. - unchecked: the HERE Platform Data Processing Agreement, a PDF, and with it any sub-processor list, data locations and retention periods. - unchecked: release dates of the HERE SDK and Maps API for JavaScript, and any GitHub repositories or server-side client libraries. - The Platform Terms forbid use of HERE Materials in connection with a machine learning or AI system, while HERE sells Location Reasoning for AI agents. Which terms govern Location Reasoning, and whether they lift that clause, was not established. This matters before any probe is run. - The acceptable use policy of 18 January 2022 lists benchmarking, scraping and data mining as prohibited. Recorded as a fact with no deduction. It matters before any probe is run. - The lead was right about the APIs and the MCP server. It did not say the MCP server runs on hlr.here.ai, needs an account entitlement and is also sold through AWS Marketplace. - The APIs answer on hereapi.com and the MCP server on here.ai, both off here.com, so `endpointOnVendorDomain` is false. ## Weaknesses - Platform Terms section f forbids using HERE Materials in connection with a machine learning or AI system, generative AI included. This matters before any probe is run - The Base Plan price table is drawn by script, so per-request prices, free allowances and rate limits were not read - API keys travel in the `apiKey` query parameter - Results may be cached or stored outside the platform for 30 days at most, and only as HTTP caching headers allow - Location Reasoning returns 403 unless the account is entitled, and the docs send the reader to an account representative or AWS Marketplace - The acceptable use policy of January 2022 lists benchmarking and scraping among prohibited activities ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send `Authorization: Bearer` with an OAuth token where logs are kept. The `apiKey` query parameter puts the secret in every URL - Do not store results for more than 30 days, and follow the HTTP caching headers on each response - Treat 429 and 503 as throttling. HERE says a traffic surge can be throttled for about 10 minutes below the account's quota - Read `code`, `cause` and `action` in the error body, and quote `correlationId` to support - For Location Reasoning, send `initialize`, keep the `Mcp-Session-Id` header on later calls, and send a bearer token on `tools/call` ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: Base Plan prices, free monthly allowances, rate limits and whether a card is needed. https://www.here.com/get-started/pricing is drawn by script and showed only headings.
- unchecked: the 90-day incident record. https://status.here.com/status is drawn by script, and robots.txt on that host disallows
/status. - unchecked: Location Reasoning tool schemas, descriptions and annotations. They are published only through
tools/liston https://hlr.here.ai/mcp, which we did not call. The count of 13 tools comes from the docs table. - unchecked: the HERE Platform Data Processing Agreement, a PDF, and with it any sub-processor list, data locations and retention periods.
- unchecked: release dates of the HERE SDK and Maps API for JavaScript, and any GitHub repositories or server-side client libraries.
- The Platform Terms forbid use of HERE Materials in connection with a machine learning or AI system, while HERE sells Location Reasoning for AI agents. Which terms govern Location Reasoning, and whether they lift that clause, was not established. This matters before any probe is run.
- The acceptable use policy of 18 January 2022 lists benchmarking, scraping and data mining as prohibited. Recorded as a fact with no deduction. It matters before any probe is run.
- The lead was right about the APIs and the MCP server. It did not say the MCP server runs on hlr.here.ai, needs an account entitlement and is also sold through AWS Marketplace.
- The APIs answer on hereapi.com and the MCP server on here.ai, both off here.com, so
endpointOnVendorDomainis false.
Sources 28
- docs index for agents docs.here.com · seen 2026-10-09
- Geocode endpoint page with its OpenAPI 3.0 definition (Markdown twin) docs.here.com · seen 2026-10-09
- Geocoding and Search release notes, API changes docs.here.com · seen 2026-10-09
- Routing API v8 changelog docs.here.com · seen 2026-10-09
- Matrix Routing API v8 changelog docs.here.com · seen 2026-10-09
- API key authorisation, rotation and trusted domains docs.here.com · seen 2026-10-09
- OAuth 2.1 machine-to-machine guide docs.here.com · seen 2026-10-09
- rate limit rules docs.here.com · seen 2026-10-09
- Limits and Quotas policy docs.here.com · seen 2026-10-09
- service availability targets docs.here.com · seen 2026-10-09
- SLA introduction docs.here.com · seen 2026-10-09
- Product Lifecycle Policy docs.here.com · seen 2026-10-09
- Essential Data Processing domains docs.here.com · seen 2026-10-09
- Location Reasoning overview docs.here.com · seen 2026-10-09
- Location Reasoning connection and authentication docs.here.com · seen 2026-10-09
- Location Reasoning tools reference docs.here.com · seen 2026-10-09
- Location Reasoning integration examples docs.here.com · seen 2026-10-09
- status page description docs.here.com · seen 2026-10-09
- status page (drawn by script, unreadable) status.here.com · seen 2026-10-09
- Base Plan pricing (table drawn by script, unreadable) here.com · seen 2026-10-09
- support plans and prices here.com · seen 2026-10-09
- HERE Platform Terms, September 2023 here.com · seen 2026-10-09
- Acceptable Use Policy, January 2022 here.com · seen 2026-10-09
- privacy policy here.com · seen 2026-10-09
- security and disclosure page here.com · seen 2026-10-09
- certifications and attestations here.com · seen 2026-10-09
- MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
- RDAP record for here.com rdap.verisign.com · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium Freemium HERE's docs say a new organisation can get started for free on the Base Plan. The price table at here.com/get-started/pricing is drawn by script and was not read, so no allowance or per-request price is quoted. Support plans run from $50 a month (Developer). Location Reasoning is also sold through AWS Marketplace (checked 2026-10-09).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/here-location-services.xml, or this listing's score history at history.json.
Connect
First request
curl "https://geocode.search.hereapi.com/v1/geocode?q=240+Washington+St.%2C+Boston&limit=4&apiKey=$HERE_API_KEY"
Through letme picks today, calling later
GET https://letme.dev/here-location-services
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to HERE Location Services
#9 of 13 in Best maps, geocoding and places APIs for AI agents · All 78 maps comparisons
Mapbox APIs + MCP BBAmazon Location Service BBGoogle Maps Platform + Grounding Lite MCP BAzure Maps BArcGIS Location Platform BStadia Maps B
Head to head Amazon Location Service vs HERE Location Services · ArcGIS Location Platform vs HERE Location Services · Azure Maps vs HERE Location Services · Geoapify Location Platform + MCP vs HERE Location Services · Google Maps Platform + Grounding Lite MCP vs HERE Location Services · HERE Location Services vs LocationIQ · HERE Location Services vs Mapbox APIs + MCP · HERE Location Services vs MapQuest · HERE Location Services vs OpenCage Geocoding API · HERE Location Services vs Radar · HERE Location Services vs Stadia Maps · HERE Location Services vs TomTom Maps APIs + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Mapbox APIs + MCP Mapbox | BB | 75 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
| Amazon Location Service Amazon Web Services | BB | 74.1 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
| Google Maps Platform + Grounding Lite MCP Google | B | 68.2 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
| Azure Maps Microsoft Azure | B | 67.9 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
| ArcGIS Location Platform Esri | B | 65.4 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
| Stadia Maps Stadia Maps | B | 65.2 | geo.geocode geo.reverse geo.places geo.routing geo.tiles | no |
Machine-readable
- JSON
/api/v1/tools/here-location-services.json· historyhistory.json· badge/badges/here-location-services.svg· changes feed/feeds/tools/here-location-services.xml - Markdown
/tools/here-location-services.md· slim/tools/here-location-services.min.md(or sendAccept: text/markdown) - Fix list
/fixes/here-location-services.md·/fixes/here-location-services.json - From a terminal
anchor tool here-location-services --md(the CLI) · over MCPget_tool {"slug": "here-location-services"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/here-location-services"><img src="https://www.anchorterminal.com/badges/here-location-services.svg" alt="HERE Location Services on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/here-location-services)<a href="https://www.anchorterminal.com/tools/here-location-services">HERE Location Services on Anchor Terminal</a>It counts on a page on here.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "here-location-services", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


