Keywords Everywhere API + MCP
by Keywords Everywhere (Axeman Technology Solutions LLP) HTTP API in SEO & search visibility
Hosted
Axeman Technology Solutions LLP · keywordseverywhere.com since 2016 · status page · who's behind it
Keywords Everywhere is a keyword research service whose REST API and hosted MCP server return Google search volume, CPC, competition, keyword ideas, the keywords a site ranks for, traffic estimates and backlinks, paid for with prepaid credits.
Good for An agent that needs Google Keyword Planner volume, CPC and competition for lists of keywords at a low price per keyword, plus keyword ideas and a quick view of a site's ranking keywords, traffic estimate and top backlinks.
Is this your product? Claim this listing or verify it
Assessment. Fourteen read-only lookups with a published credit cost each, available over REST and a hosted MCP server listed in the official registry. Data needs an annual plan from $84, with no trial. No OpenAPI file, no REST rate limit and no API changelog were found, and the status page shows outages on seven of the last 90 days.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.keywordseverywhere.com- Auth
- OAuth or key
- Pricing
- Paid · $7 / mo
- x402
- No
- Licence
- Proprietary service under the Keywords Everywhere Terms of Service. The vendor's n8n community node on npm is MIT
- Tools exposed
- 14
- Packages
npmn8n-nodes-keywords-everywhere-api- MCP registry
com.keywordseverywhere/keywords-everywhere- llms.txt
- not found
- Last release
- npm / week
- 7
- Surfaces graded
- The public REST API at api.keywordseverywhere.com/v1 and the official hosted MCP server at mcp.keywordseverywhere.com/mcp, which serves the same data from the same key and credits. The browser extension is not graded
- REST endpoints
- 14 under
/v1.account/credits, countries and currencies (free),get_keyword_data,get_pasf_keywords,get_related_keywords,get_domain_keywords,get_url_keywords,get_domain_traffic_metrics,get_url_traffic_metrics, and four backlink endpoints for a domain or page, all or unique - MCP server
- Hosted, streamable HTTP only, https://mcp.keywordseverywhere.com/mcp. 14 tools that mirror the REST endpoints, all read-only per the vendor. Registry name com.keywordseverywhere/keywords-everywhere, version 2.0.0, published 10 September 2026
- Credentials
- One API key per account as a Bearer token, shared by all seats and the browser extension, reset by emailed link. MCP also takes OAuth 2.1 with dynamic client registration and PKCE, 3-hour access tokens and refresh for up to 90 days
- Credit costs
- Keyword metrics 1 credit a keyword. Related, People Also Search For, domain and URL keywords 2 a row. Traffic metrics 2 a domain or URL. Backlinks 1 a row, unique backlinks 5 a row. Balance, countries and currencies free
- Rate limits
- MCP server 120 tool calls a minute per account. None found for the REST API
- Request limits
- Up to 100 keywords in one
get_keyword_datacall.numfrom 1 to 10,000 on keyword and backlink lists, capped by plan at the top 1,000 to 10,000 rows per site - Errors
- JSON with a
messageand on some endpoints adescription. 400 invalid request data, 401 missing or invalid key, 402 subscription required or insufficient credits. No 429 in the REST status tables - Data sources
- Google Keyword Planner for volume, CPC and competition, with optional clickstream blending (
dataSource=cli). Country and currency are set per request, and volume is global when no country is sent - Docs
- A docsify site at api.keywordseverywhere.com/docs with 15 Markdown pages, code samples in Bash, PHP, Laravel, Java, Python, Ruby, Node.js and R, and n8n, Make and Postman recipes. No OpenAPI file or llms.txt
- Packages
n8n-nodes-keywords-everywhere-api0.1.5 on npm (MIT, 27 April 2025), an n8n community node published by the vendor. No SDK was found- Hosting and data
- Hetzner (Germany, Finland) and Akamai Linode (United States, EU) behind Cloudflare. Personal data stored mainly in the EU, also the United States, and accessed by staff in India, per the DPA of July 2026
- Capabilities
- seo.keywords seo.backlinks seo.traffic seo.rankings
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Every REST endpoint and MCP tool is read-only, and each one's credit cost is published, from 1 credit a keyword to 5 a unique backlink
- Hosted MCP server at
https://mcp.keywordseverywhere.com/mcp, in the official MCP registry ascom.keywordseverywhere/keywords-everywheresince 10 September 2026 - MCP sign-in is OAuth 2.1 with dynamic client registration and PKCE. Access tokens expire after 3 hours, per the server's docs
- Each response returns the credits consumed, and balance, country and currency lookups cost nothing
- A DPA applies to every customer without signature and names six sub-processors with locations and 30 days' notice of changes
Weaknesses
- No free credits or trial. Data calls need an annual plan, from $84 for 100,000 credits that expire after a year
- No OpenAPI file, llms.txt or official SDK was found. The reference is 15 Markdown pages behind a docsify viewer
- No rate limit is documented for the REST API. The only published limit is 120 MCP tool calls a minute per account
- The status page tracks only the website and marks seven of the last 90 days as Outage, with no incident notes
- One unscoped key per account, shared by up to 20 seats and by the browser extension, with no spending cap per key found
- The Terms of Service date from 30 May 2023 and say nothing about the API, data reuse, rate limits or deprecation
Before you call it notes for agents
- Send the key as
Authorization: Bearer <key>tohttps://api.keywordseverywhere.com/v1. The same key works on the MCP server - Call
GET /v1/account/credits(free) before a large pull. A short balance returns 402 with402 Insufficient Credits - Set
numon domain, URL and backlink lookups. It accepts 1 to 10,000 and every returned row is charged 1, 2 or 5 credits - Batch up to 100 keywords in one
get_keyword_datacall and setcountry. Without it the figures are global - Keep MCP use under 120 tool calls a minute per account, and wait a minute after a Too many requests error
Who's behind it provenance 87/100
- Legal entity namedAxeman Technology Solutions LLP20/20
- Domain agekeywordseverywhere.com, registered 2016-07-01 (10 years)15/15
- Endpoint on the vendor's domainapi.keywordseverywhere.com15/15
- Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.keywordseverywhere.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2023-05-30, states 4 of 7, 2 to know
TL;DR Dated 2023-05-30. States 4 of the 7 things a reader expects, and we didn't find the governing law, how changes are announced or a service level. To know before relying on it, cut-off without notice or for any reason and no update in three years.
Says access can be ended without notice or for any reason
KeywordsEverywhere.com may terminate your access to all or any part of our Services at any time, with or without cause, with or without notice, effective immediately.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Has not been updated for three years or more
Last updated on May 30th, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-05-30
Last updated on May 30th, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
Not found in the text.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
In no event will KeywordsEverywhere.com be liable with respect to any subject matter of this Agreement under any contract, negligence, strict liability or other legal or equitable theory for: (i) any special, incidental or consequential damages;
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
KeywordsEverywhere.com may terminate your access to all or any part of our Services at any time, with or without cause, with or without notice, effective immediately.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced
Not found in the text.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you do not agree to all the terms and conditions of this agreement, then you may not access or use any of our services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Purchased credits expire one year after purchase and are not carried over when a subscription renews.
Credits will always expire one year from the date of purchase. When a subscription renews, the credits will not be carried over to the next year.
Noted by a second reader on 2026-10-08.
The vendor states no obligation to refund, and a refund request must be made within 48 hours of the transaction.
Keywords Everywhere is not obligated to provide you a refund at any time.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 2,193 words
Privacy policy dated 2025-08-15, states 7 of 8, 1 to know
TL;DR Dated 2025-08-15. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
For instance, we may publish aggregate statistics about the use of our Services and we may share a hashed version of your email address to facilitate customized ad campaigns on other platforms.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2025-08-15
Last updated on Aug 15th, 2025
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We are thoughtful about the personal information we ask you to provide and the personal information that we collect about you through the operation of our services.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 30 days
For example, we keep the web server logs that record information about a visitor to one of KeywordsEverywhere.com's websites, such as the visitor's IP address, browser type, and operating system, for approximately 30 days.
Says when data sent to the service is deleted.
Says who else receives the data
Log Information: Like most online service providers, we collect information that web browsers, mobile devices, and servers typically make available, such as the browser type, IP address, unique device identifiers, language preference, referring site, the date and time of access, operating system, and mobile network in…
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell our users' private personal information.
A plain statement either way.
Says what rights people have over their data
If you have a question about this Privacy Policy, or you would like to contact us about any of the rights mentioned in the Your Rights section above, please contact us.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
If you have a question about this Privacy Policy, or you would like to contact us about any of the rights mentioned in the Your Rights section above, please contact us.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
The vendor reserves the right to publish a support request sent to it.
we reserve the right to publish that request in order to help us clarify or respond to your request or to help us support other users.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 2,837 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The privacy policy (15 August 2025), the security overview and the DPA (both July 2026) name Axeman Technology Solutions LLP, a limited liability partnership registered in India, 502 B Anisha Apartments, Yari Road, Versova, Mumbai 400061, as the operator.
The Terms of Service (30 May 2023) are the only terms published and the DPA calls them the Principal Agreement. They name no legal entity and don't mention the API.
The privacy policy describes its scope as the browser add-on and website. The DPA covers the APIs by name.
The REST API answers at api.keywordseverywhere.com and the MCP server at mcp.keywordseverywhere.com.
keywordseverywhere.com/.well-known/security.txt answered 404. The security overview gives privacy@keywordseverywhere.com for security enquiries.
The changelog covers the browser extension only. No changelog for the API or the MCP server was found.
The status page has one component, Keywords Everywhere Website, with a 90-day timeline by day.
Paddle.com Market Limited is the merchant of record for all purchases.
RDAP for keywordseverywhere.com gives a registration date of 2016-07-01.
robots.txt on keywordseverywhere.com disallows /service/ and /ke/ only. On mcp.keywordseverywhere.com it allows /docs and disallows every other path, so the MCP endpoint and its discovery documents were not requested. Neither carries a Content-Signal line.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://api.keywordseverywhere.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 3 minutes ago
- npm
n8n-nodes-keywords-everywhere-api0.1.5 - npm downloads a week 7
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| keywordseverywhere.com/changelog.html | changelog | 6 hours ago · 200 | no change seen |
| keywordseverywhere.com/privacy.html | privacy | 6 hours ago · 200 | no change seen |
| keywordseverywhere.com/terms.html | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/keywords-everywhere.json
Notable
- The MCP server is hosted at https://mcp.keywordseverywhere.com/mcp over streamable HTTP only, with no stdio mode and no SSE stream, and has 14 tools the vendor describes as all read-only source
- The MCP docs state a limit of 120 tool calls a minute per account. No limit was found in the REST API docs source
- A banner on every API docs page says that since 7 June 2025 all API methods are available on all subscription plans, including Bronze source
- Search volume comes from Google Keyword Planner.
dataSource=cliblends in clickstream data, and competition is the Google Ads advertiser metric from 0 to 1, not a ranking difficulty score source - Plans cap the rows returned per site for ranking keywords and backlinks at the top 1,000 on Bronze, 2,000 on Silver, 5,000 on Gold and 10,000 on Platinum source
- The security overview of July 2026 says the vendor holds no SOC 2 or ISO 27001 certification of its own and runs on Hetzner and Akamai (Linode) behind Cloudflare source
- The status page shows one component, the website, with seven days marked Outage between 12 July and 9 October 2026 and a 90-day figure of 92.22 per cent source
- A site banner on 9 October 2026 announced a server migration on Saturday 10 October, 04:30 to 10:30 UTC, during which the website and the extension would be unavailable source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.4 | |
| Graded on the hosted lines for the REST API and the MCP server. status.keywordseverywhere.com is the vendor's own page with a 90-day timeline by day. It has one component, the website, and none for the API or the MCP server (12 of 20). Seven days between 12 July and 9 October 2026 are marked Outage (1 and 11 August, 1, 8, 12, 16 and 17 September) and the page gives 92.22 per cent for the period. It has no incident notes or durations, so the outages can't be sized (5 of 30). The MCP docs state 120 tool calls a minute per account. No limit was found for the REST API (10 of 15). The MCP docs say to wait a minute and retry after a Too many requests error. No Retry-After header and no 429 entry appear in the REST status tables. Every call is a read (5 of 15). No SLA was found, and the terms disclaim continuous or uninterrupted access (0). The API is V1 and neither it nor the MCP server carries a beta label (10). Total 42. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 7.8 | |
No OpenAPI file or other machine-readable contract was found for the REST API. The MCP server's input schemas weren't read, because its robots.txt closes the endpoint (5 of 25). keywordseverywhere.com/llms.txt answered 404. The API reference is a docsify site whose pages are plain Markdown files, which a model can read directly (5 of 10). Each page states the endpoint's purpose and credit cost in a line or two, and the API overview says the service is not a rank tracker and that competition is an advertiser metric (11 of 20). Parameter tables give type, examples, options (gkp or cli), a range of 1 to 10,000 for num and a 100-keyword ceiling. Required status isn't stated (9 of 15). Every endpoint has request samples in eight languages, a sample response, a status code table and sample 401 and 402 bodies. There is no sample for 400 (13 of 15). Paths are versioned under /v1 and the MCP registry entry carries a version. The only changelog is for the browser extension (5 of 15). Total 48. | |||
| Agent ergonomics | 13%16.2 | 8.8 | |
The MCP server has 14 tools, which is 15 on the MCP line. The size of the definitions wasn't read (15 of 25). num caps the rows returned by keyword and backlink lists and get_keyword_data takes up to 100 keywords a call. No offset, cursor, filter or field selection was found, so a second page of results can't be requested (9 of 20). Errors are JSON with a message such as 402 Insufficient Credits and, on some endpoints, a description. 400 is documented only as invalid request data (11 of 20). Every endpoint and tool is a read, so a retry changes nothing in the account, though a repeated call spends credits again. The vendor says every tool is read-only. Tool annotations weren't read (12 of 20). Most parameters are optional and volume is global when country is omitted. No SDK was found. The vendor publishes an n8n node and code samples in eight languages (7 of 15). Total 54. | |||
| Security & auth | 14%17.5 | 8.2 | |
One API key per account, sent as a Bearer token and reset through an emailed link. It has no scopes and is shared by every seat on the plan and by the browser extension. The MCP server adds OAuth 2.1 with dynamic client registration, PKCE and 3-hour access tokens, and its docs say the key is stored encrypted with AES-256-GCM. Links on the vendor's own site carry the key as an apiKey query parameter to the subscription pages. The API docs show only the header (18 of 30). Every endpoint and tool is read-only and nothing in the account can be changed. A key can spend the whole credit balance, and no cap per key was found (14 of 20). Responses carry third-party anchor text, URLs and keywords, and no prompt-injection guidance was found (3 of 15). Each response returns credits_consumed and the account has a stats page. No per-call log for the customer is documented (5 of 15). A security overview of July 2026 describes access control, patching and 72-hour breach notice, and states that the vendor holds no SOC 2 or ISO 27001 certification. No security.txt, disclosure policy or bug bounty was found (7 of 20). Total 47. | |||
| Payments & pricing | 10%12.5 | 2.5 | |
| No x402, MPP or L402 (0). Four annual plans are priced in public with their credit amounts, and the docs give a credit cost for every endpoint, so a keyword lookup works out at $0.00084 on Bronze and $0.00018 on Platinum (20). The API key is free, but data calls need a paid plan and no trial or free credits were found. Only balance, country and currency lookups cost nothing (0). A person enters an email address in a browser form and follows an emailed link to get the key, and buys a plan through Paddle (0). Total 20. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.5 | |
The official MCP registry dates version 2.0.0 of com.keywordseverywhere/keywords-everywhere at 10 September 2026, 29 days before the check, and the security overview and DPA were updated in July 2026 (30). The only dated changelog is the browser extension's, with three versions in the last 90 days (15 July, 2 and 16 September). One dated entry was found for the API or the MCP server in that time (8 of 20). A product news page lists known issues with fix dates, and support is by email. No forum or public issue tracker was found (8 of 15). The server is in the official registry under the com.keywordseverywhere namespace (15). No SDK or public repository was found, and the vendor's n8n node on npm has been at 0.1.5 since 27 April 2025 (2 of 10). Total 63. | |||
| Transparency & trusteditorial 49, provenance 87 | 7%8.8 | 6.0 | |
| Closed service. The Terms of Service date from 30 May 2023, are adapted from the WordPress terms, and don't mention the API, reuse or resale of the data, or the legal entity. The vendor's n8n node is MIT (8 of 30). A privacy policy of 15 August 2025, a DPA of July 2026 that applies to every customer without signature, and a security overview give retention figures of about 30 days for web server logs and no more than 90 days for backups, and the MCP docs say the server keeps request counters and short-lived logs only. The privacy policy describes its scope as the browser add-on and says only an email address is required, while the DPA lists names, keyword queries and usage data (19 of 30). No deprecation policy was found. The terms allow termination of access at any time without notice, and the only dated API notice is the banner of 7 June 2025 (3 of 20). Six sub-processors are named with purpose and location, with 30 days' notice of changes, and the DPA says data is stored mainly in the EU, also in the United States, and accessed from India (19 of 20). Total 49. | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 47.2 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Keywords Everywhere API + MCP, or have the agent fetch /fixes/keywords-everywhere.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Keywords Everywhere API + MCP From Anchor Terminal's listing at https://www.anchorterminal.com/tools/keywords-everywhere, the October 2026 research run, assessed 9 October 2026. Grade D, 47.2 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Keywords Everywhere API + MCP: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 42 out of 100, up to 11.6 more on the total Why it scored 42: Graded on the hosted lines for the REST API and the MCP server. status.keywordseverywhere.com is the vendor's own page with a 90-day timeline by day. It has one component, the website, and none for the API or the MCP server (12 of 20). Seven days between 12 July and 9 October 2026 are marked Outage (1 and 11 August, 1, 8, 12, 16 and 17 September) and the page gives 92.22 per cent for the period. It has no incident notes or durations, so the outages can't be sized (5 of 30). The MCP docs state 120 tool calls a minute per account. No limit was found for the REST API (10 of 15). The MCP docs say to wait a minute and retry after a Too many requests error. No Retry-After header and no 429 entry appear in the REST status tables. Every call is a read (5 of 15). No SLA was found, and the terms disclaim continuous or uninterrupted access (0). The API is V1 and neither it nor the MCP server carries a beta label (10). Total 42. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 20 out of 100, up to 10 more on the total Why it scored 20: No x402, MPP or L402 (0). Four annual plans are priced in public with their credit amounts, and the docs give a credit cost for every endpoint, so a keyword lookup works out at $0.00084 on Bronze and $0.00018 on Platinum (20). The API key is free, but data calls need a paid plan and no trial or free credits were found. Only balance, country and currency lookups cost nothing (0). A person enters an email address in a browser form and follows an emailed link to get the key, and buys a plan through Paddle (0). Total 20. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 47 out of 100, up to 9.3 more on the total Why it scored 47: One API key per account, sent as a Bearer token and reset through an emailed link. It has no scopes and is shared by every seat on the plan and by the browser extension. The MCP server adds OAuth 2.1 with dynamic client registration, PKCE and 3-hour access tokens, and its docs say the key is stored encrypted with AES-256-GCM. Links on the vendor's own site carry the key as an `apiKey` query parameter to the subscription pages. The API docs show only the header (18 of 30). Every endpoint and tool is read-only and nothing in the account can be changed. A key can spend the whole credit balance, and no cap per key was found (14 of 20). Responses carry third-party anchor text, URLs and keywords, and no prompt-injection guidance was found (3 of 15). Each response returns `credits_consumed` and the account has a stats page. No per-call log for the customer is documented (5 of 15). A security overview of July 2026 describes access control, patching and 72-hour breach notice, and states that the vendor holds no SOC 2 or ISO 27001 certification. No security.txt, disclosure policy or bug bounty was found (7 of 20). Total 47. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Schema & documentation, 48 out of 100, up to 8.5 more on the total Why it scored 48: No OpenAPI file or other machine-readable contract was found for the REST API. The MCP server's input schemas weren't read, because its robots.txt closes the endpoint (5 of 25). keywordseverywhere.com/llms.txt answered 404. The API reference is a docsify site whose pages are plain Markdown files, which a model can read directly (5 of 10). Each page states the endpoint's purpose and credit cost in a line or two, and the API overview says the service is not a rank tracker and that competition is an advertiser metric (11 of 20). Parameter tables give type, examples, options (`gkp` or `cli`), a range of 1 to 10,000 for `num` and a 100-keyword ceiling. Required status isn't stated (9 of 15). Every endpoint has request samples in eight languages, a sample response, a status code table and sample 401 and 402 bodies. There is no sample for 400 (13 of 15). Paths are versioned under `/v1` and the MCP registry entry carries a version. The only changelog is for the browser extension (5 of 15). Total 48. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Agent ergonomics, 54 out of 100, up to 7.5 more on the total Why it scored 54: The MCP server has 14 tools, which is 15 on the MCP line. The size of the definitions wasn't read (15 of 25). `num` caps the rows returned by keyword and backlink lists and `get_keyword_data` takes up to 100 keywords a call. No offset, cursor, filter or field selection was found, so a second page of results can't be requested (9 of 20). Errors are JSON with a `message` such as `402 Insufficient Credits` and, on some endpoints, a `description`. 400 is documented only as invalid request data (11 of 20). Every endpoint and tool is a read, so a retry changes nothing in the account, though a repeated call spends credits again. The vendor says every tool is read-only. Tool annotations weren't read (12 of 20). Most parameters are optional and volume is global when `country` is omitted. No SDK was found. The vendor publishes an n8n node and code samples in eight languages (7 of 15). Total 54. The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Maintenance & community, 63 out of 100, up to 3.2 more on the total Why it scored 63: The official MCP registry dates version 2.0.0 of `com.keywordseverywhere/keywords-everywhere` at 10 September 2026, 29 days before the check, and the security overview and DPA were updated in July 2026 (30). The only dated changelog is the browser extension's, with three versions in the last 90 days (15 July, 2 and 16 September). One dated entry was found for the API or the MCP server in that time (8 of 20). A product news page lists known issues with fix dates, and support is by email. No forum or public issue tracker was found (8 of 15). The server is in the official registry under the `com.keywordseverywhere` namespace (15). No SDK or public repository was found, and the vendor's n8n node on npm has been at 0.1.5 since 27 April 2025 (2 of 10). Total 63. The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 68 out of 100, up to 2.8 more on the total Made of editorial 49, provenance 87. Why it scored 68: Closed service. The Terms of Service date from 30 May 2023, are adapted from the WordPress terms, and don't mention the API, reuse or resale of the data, or the legal entity. The vendor's n8n node is MIT (8 of 30). A privacy policy of 15 August 2025, a DPA of July 2026 that applies to every customer without signature, and a security overview give retention figures of about 30 days for web server logs and no more than 90 days for backups, and the MCP docs say the server keeps request counters and short-lived logs only. The privacy policy describes its scope as the browser add-on and says only an email address is required, while the DPA lists names, keyword queries and usage data (19 of 30). No deprecation policy was found. The terms allow termination of access at any time without notice, and the only dated API notice is the banner of 7 June 2025 (3 of 20). Six sub-processors are named with purpose and location, with 30 days' notice of changes, and the DPA says data is stored mainly in the EU, also in the United States, and accessed from India (19 of 20). Total 49. The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the MCP server's tool definitions, input schemas and annotations. robots.txt on mcp.keywordseverywhere.com disallows every path but /docs, so the endpoint and its OAuth discovery documents were not requested. The tool list and the read-only claim are the vendor's - unchecked: ten of the 15 API reference pages (countries, currencies, related and PASF keywords, URL keywords, URL traffic and three backlink pages). Five endpoint pages, the README and the MCP page were read, and the others are assumed to follow the same layout - unchecked: top-up credit prices and any Enterprise price, which sit behind the account page or an email address - Whether the status page's Outage days reflect the API and the MCP server. It has one component, the website, and gives no durations - Whether a REST rate limit exists. None was found in the pages read - Whether a failed or empty call is charged credits. The docs say cost is per result returned and don't address errors - The Terms of Service say nothing on automated access, storing or reselling the data. They also don't name the contracting entity, which the DPA and privacy policy give as Axeman Technology Solutions LLP - The main site's MCP page says Windsurf can't use the remote HTTP transport, while the MCP host's docs list Windsurf among clients that can - The lead was right about the interfaces and the docs link. It gave the vendor as Keywords Everywhere. The operator is Axeman Technology Solutions LLP of Mumbai ## Weaknesses - No free credits or trial. Data calls need an annual plan, from $84 for 100,000 credits that expire after a year - No OpenAPI file, llms.txt or official SDK was found. The reference is 15 Markdown pages behind a docsify viewer - No rate limit is documented for the REST API. The only published limit is 120 MCP tool calls a minute per account - The status page tracks only the website and marks seven of the last 90 days as Outage, with no incident notes - One unscoped key per account, shared by up to 20 seats and by the browser extension, with no spending cap per key found - The Terms of Service date from 30 May 2023 and say nothing about the API, data reuse, rate limits or deprecation ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send the key as `Authorization: Bearer <key>` to `https://api.keywordseverywhere.com/v1`. The same key works on the MCP server - Call `GET /v1/account/credits` (free) before a large pull. A short balance returns 402 with `402 Insufficient Credits` - Set `num` on domain, URL and backlink lookups. It accepts 1 to 10,000 and every returned row is charged 1, 2 or 5 credits - Batch up to 100 keywords in one `get_keyword_data` call and set `country`. Without it the figures are global - Keep MCP use under 120 tool calls a minute per account, and wait a minute after a Too many requests error ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the MCP server's tool definitions, input schemas and annotations. robots.txt on mcp.keywordseverywhere.com disallows every path but /docs, so the endpoint and its OAuth discovery documents were not requested. The tool list and the read-only claim are the vendor's
- unchecked: ten of the 15 API reference pages (countries, currencies, related and PASF keywords, URL keywords, URL traffic and three backlink pages). Five endpoint pages, the README and the MCP page were read, and the others are assumed to follow the same layout
- unchecked: top-up credit prices and any Enterprise price, which sit behind the account page or an email address
- Whether the status page's Outage days reflect the API and the MCP server. It has one component, the website, and gives no durations
- Whether a REST rate limit exists. None was found in the pages read
- Whether a failed or empty call is charged credits. The docs say cost is per result returned and don't address errors
- The Terms of Service say nothing on automated access, storing or reselling the data. They also don't name the contracting entity, which the DPA and privacy policy give as Axeman Technology Solutions LLP
- The main site's MCP page says Windsurf can't use the remote HTTP transport, while the MCP host's docs list Windsurf among clients that can
- The lead was right about the interfaces and the docs link. It gave the vendor as Keywords Everywhere. The operator is Axeman Technology Solutions LLP of Mumbai
Sources 23
- API overview and FAQ keywordseverywhere.com · seen 2026-10-09
- API reference, read as the Markdown files the docsify viewer loads (sidebar, README, MCP integration and five endpoint pages), not the rendered pages api.keywordseverywhere.com · seen 2026-10-09
- MCP setup guide on the main site keywordseverywhere.com · seen 2026-10-09
- MCP server documentation (tools, credit costs, rate limit, token lifetimes) mcp.keywordseverywhere.com · seen 2026-10-09
- MCP docs for other clients (transport, OAuth, discovery documents) mcp.keywordseverywhere.com · seen 2026-10-09
- official MCP registry entry registry.modelcontextprotocol.io · seen 2026-10-09
- pricing page keywordseverywhere.com · seen 2026-10-09
- plan comparison keywordseverywhere.com · seen 2026-10-09
- Terms of Service, 30 May 2023 keywordseverywhere.com · seen 2026-10-09
- privacy policy, 15 August 2025 keywordseverywhere.com · seen 2026-10-09
- Data Processing Agreement, July 2026 keywordseverywhere.com · seen 2026-10-09
- security overview, July 2026 keywordseverywhere.com · seen 2026-10-09
- status page, 90-day timeline status.keywordseverywhere.com · seen 2026-10-09
- extension changelog keywordseverywhere.com · seen 2026-10-09
- product news and known issues keywordseverywhere.com · seen 2026-10-09
- FAQ keywordseverywhere.com · seen 2026-10-09
- API key sign-up page keywordseverywhere.com · seen 2026-10-09
- API key reset page keywordseverywhere.com · seen 2026-10-09
- security.txt, answered 404 keywordseverywhere.com · seen 2026-10-09
- llms.txt, answered 404 keywordseverywhere.com · seen 2026-10-09
- n8n node on npm, version and dates registry.npmjs.org · seen 2026-10-09
- npm downloads, 1 to 7 October 2026 api.npmjs.org · seen 2026-10-09
- RDAP record for the domain rdap.verisign.com · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid $7 / mo Data calls spend prepaid credits from an annual plan. Bronze is $84 a year for 100,000 credits, Silver $168 for 400,000, Gold $480 for 2 million and Platinum $1,440 for 8 million. There is no monthly plan, and credits expire a year after purchase. Each endpoint's credit cost is published, from 1 credit a keyword to 5 a unique backlink. The API and the MCP server are on every plan with no separate fee. No free credits or trial were found, so an agent can't pull data without a purchase. Only balance, country and currency lookups are free. Top-up prices sit behind the account page.
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Bronze plan, 100,000 credits a year | $7 | per month (plan) | $84 billed annually. No monthly billing. Credits expire a year after purchase |
| Credit, Bronze plan | $0.0008 | per credit | $84 for 100,000. $0.00042 on Silver, $0.00024 on Gold and $0.00018 on Platinum |
| Keyword metrics (volume, CPC, competition, trend), per keyword | $0.0008 | per record | 1 credit at the Bronze rate |
| Ranking keyword, related keyword or People Also Search For row | $0.0017 | per record | 2 credits a row at the Bronze rate |
| Backlink row | $0.0008 | per record | 1 credit at the Bronze rate. A unique backlink (one per source domain) is 5 credits, $0.0042 |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/keywords-everywhere.xml, or this listing's score history at history.json.
Connect
First request
curl -X POST "https://api.keywordseverywhere.com/v1/get_keyword_data" -H "Authorization: Bearer YOUR_API_KEY" -H "Accept: application/json" -d "dataSource=gkp" -d "country=us" -d "currency=usd" -d "kw[]=digital marketing"
Claude Code
claude mcp add --transport http keywords-everywhere https://mcp.keywordseverywhere.com/mcp -H "Authorization: Bearer YOUR_KE_API_KEY"
MCP client configuration
{
"mcpServers": {
"keywords-everywhere": {
"headers": {
"Authorization": "Bearer YOUR_KE_API_KEY"
},
"url": "https://mcp.keywordseverywhere.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/keywords-everywhere
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Keywords Everywhere API + MCP
#7 of 10 in Best SEO and search visibility data for AI agents · All 45 seo comparisons
DataForSEO BManifold CSemrush API + MCP DSE Ranking API + MCP DAhrefs DGoogle Search Console API C
Head to head Ahrefs vs Keywords Everywhere API + MCP · DataForSEO vs Keywords Everywhere API + MCP · Keywords Everywhere API + MCP vs Majestic API · Keywords Everywhere API + MCP vs Manifold · Keywords Everywhere API + MCP vs Moz API · Keywords Everywhere API + MCP vs SE Ranking API + MCP · Keywords Everywhere API + MCP vs Semrush API + MCP · Keywords Everywhere API + MCP vs Similarweb · Google Search Console API vs Keywords Everywhere API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| DataForSEO DataForSEO OÜ | B | 64.9 | seo.keywords seo.backlinks seo.rankings seo.traffic | no |
| Manifold Manifold (Jesse Sibley, sole trader) | C | 56.2 | seo.keywords seo.backlinks seo.rankings seo.traffic | no |
| Semrush API + MCP Semrush Inc. (an Adobe company) | D | 53.1 | seo.keywords seo.backlinks seo.rankings seo.traffic | no |
| SE Ranking API + MCP SE Ranking (SER Acquisition Inc.) | D | 50.9 | seo.keywords seo.backlinks seo.rankings seo.traffic | no |
| Ahrefs Ahrefs Pte. Ltd. | D | 49.8 | seo.keywords seo.backlinks seo.rankings seo.traffic | no |
| Google Search Console API Google | C | 59 | seo.rankings seo.keywords seo.traffic | no |
Machine-readable
- JSON
/api/v1/tools/keywords-everywhere.json· historyhistory.json· badge/badges/keywords-everywhere.svg· changes feed/feeds/tools/keywords-everywhere.xml - Markdown
/tools/keywords-everywhere.md· slim/tools/keywords-everywhere.min.md(or sendAccept: text/markdown) - Fix list
/fixes/keywords-everywhere.md·/fixes/keywords-everywhere.json - From a terminal
anchor tool keywords-everywhere --md(the CLI) · over MCPget_tool {"slug": "keywords-everywhere"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/keywords-everywhere"><img src="https://www.anchorterminal.com/badges/keywords-everywhere.svg" alt="Keywords Everywhere API + MCP on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/keywords-everywhere)<a href="https://www.anchorterminal.com/tools/keywords-everywhere">Keywords Everywhere API + MCP on Anchor Terminal</a>It counts on a page on keywordseverywhere.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "keywords-everywhere", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


