{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/langsmith.json",
        "name": "LangSmith API + MCP",
        "score": 71.1,
        "shared": [
          "obs.traces",
          "obs.evals",
          "obs.prompts",
          "obs.datasets",
          "obs.gateway"
        ],
        "slug": "langsmith"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/respan.json",
        "name": "Respan API + MCP",
        "score": 65.5,
        "shared": [
          "obs.traces",
          "obs.evals",
          "obs.prompts",
          "obs.gateway",
          "obs.datasets"
        ],
        "slug": "respan"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/braintrust.json",
        "name": "Braintrust API + MCP",
        "score": 61.1,
        "shared": [
          "obs.traces",
          "obs.evals",
          "obs.prompts",
          "obs.gateway",
          "obs.datasets"
        ],
        "slug": "braintrust"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/helicone.json",
        "name": "Helicone AI Gateway + MCP",
        "score": 46.9,
        "shared": [
          "obs.traces",
          "obs.gateway",
          "obs.prompts",
          "obs.datasets",
          "obs.evals"
        ],
        "slug": "helicone"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/arize-phoenix.json",
        "name": "Arize Phoenix",
        "score": 75.4,
        "shared": [
          "obs.traces",
          "obs.evals",
          "obs.prompts",
          "obs.datasets"
        ],
        "slug": "arize-phoenix"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/langfuse.json",
        "name": "Langfuse API + MCP",
        "score": 72.7,
        "shared": [
          "obs.traces",
          "obs.evals",
          "obs.prompts",
          "obs.datasets"
        ],
        "slug": "langfuse"
      }
    ],
    "tool": {
      "slug": "langwatch",
      "name": "LangWatch",
      "vendor": "Reasoning Engine B.V. (LangWatch)",
      "vendorUrl": "https://langwatch.ai",
      "kind": "http-api",
      "category": "agent-observability",
      "summary": "LangWatch is an open-source platform for tracing, evaluating and testing LLM applications and agents, with prompt management, datasets and an AI gateway. It runs hosted or self-hosted, with a REST API, SDKs, a CLI and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/langwatch",
      "markdownUrl": "https://www.anchorterminal.com/tools/langwatch.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/langwatch.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/langwatch.json",
      "repo": "https://github.com/langwatch/langwatch",
      "license": "Apache 2.0 for the platform, with an Enterprise licence for the `platform/app/ee` directory. The SDKs and the MCP server are MIT",
      "transports": [
        "http",
        "streamable-http",
        "sse",
        "stdio"
      ],
      "remoteUrl": "https://app.langwatch.ai",
      "packages": [
        {
          "registry": "npm",
          "name": "langwatch"
        },
        {
          "registry": "npm",
          "name": "@langwatch/mcp-server"
        },
        {
          "registry": "pypi",
          "name": "langwatch"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person signs up at app.langwatch.ai and creates keys under Settings, API Keys, with no review step. API keys (`sk-lw-`) go in `X-Auth-Token` or as a Bearer token. A personal key never exceeds its owner's permissions, a service key belongs to the organisation and only admins create one. Either can be All or Restricted to read or write per permission category, scoped to projects, teams or the organisation, given an expiry and revoked. Ingestion keys (`ik-lw-`) can only write traces to one project. The remote MCP server uses OAuth authorisation code with PKCE and dynamic client registration. The CLI logs in with a device code approved in a browser.",
      "pricing": "freemium",
      "pricingNotes": "The Developer plan is free with no card and includes 50,000 events a month, 2 users and 3 scenarios, so an agent can start without a contract once a person has signed up. Growth is 29 euros per core seat a month with 200,000 events, then 5 euros per 100,000 events and 3 euros per GB kept beyond the included retention. Enterprise is sold through sales. Instant Evals cost $0.0546 per million input tokens, with a $1 budget on unpaid organisations. The pricing page has a currency switch and we read the euro prices only. Self-hosting under Apache 2.0 is free with no volume cap, and an Enterprise licence is priced per seat (https://langwatch.ai/pricing, https://langwatch.ai/docs/pricing.md).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI document or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 101,
      "popularity": {
        "githubStars": 4925,
        "npmWeekly": 50105,
        "pypiWeekly": 87325,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://langwatch.ai/docs/introduction",
      "llmsTxt": "https://langwatch.ai/docs/llms.txt",
      "openapi": "https://app.langwatch.ai/api/gateway/v1/openapi.json",
      "capabilities": [
        "obs.traces",
        "obs.evals",
        "obs.prompts",
        "obs.datasets",
        "obs.gateway"
      ],
      "tags": [
        "hosted",
        "freemium",
        "no-card",
        "open-source",
        "self-hosted",
        "mcp",
        "oauth",
        "llms-txt",
        "openapi",
        "opentelemetry",
        "python",
        "typescript",
        "go",
        "cli",
        "status-page",
        "eu-hosted"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.5,
        "grade": "B",
        "agentReady": false,
        "rank": 291,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 90,
          "payments": 40,
          "reliability": 53,
          "schema": 87,
          "security": 71,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 53,
            "points": 10.6,
            "reason": "Graded as a hosted service (LangWatch Cloud). Better Stack status page with 9 components and 90 days of history (20). In that window the App had one 20-minute downtime on 19 July and the Collector 23 minutes that day and 5 minutes on 13 August, but the Processor was degraded on 17 days, for 14 hours 44 minutes on 31 July, and Scenarios was down on 7 days, for 9 hours 34 minutes on 8 September. The core API stayed under an hour and other components had several long incidents (10). No request rate limit for the platform API was found in the reviewed documentation. The only numbers are customer-set limits on AI Gateway virtual keys (0). Retries are partly covered. Events carry an idempotency key and are deduplicated, `evaluation_id` makes an evaluation call idempotent, and two operations declare a 429, one with `Retry-After`. No general backoff guidance for the platform API was found (8). The pricing page lists a contractual uptime and support SLA on Enterprise, with no published terms (5). The REST API, MCP server 2.1.0 and the 1.x SDKs are generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 87,
            "points": 14.14,
            "reason": "A public OpenAPI 3.1 document of 215 paths and 328 operations, served without a key, and typed zod inputs on every MCP tool (25). llms.txt and a Markdown twin of each docs page (10). Every operation has a summary or description, and MCP descriptions say when to pick a tool, for example `run_query` for counts and rates and `discover_schema` before a search. 158 operations carry no tag (16). 540 enums in the document, with trace filters still accepted as a free-form map alongside the query language (12). Docs pages carry request examples, and the gateway error list gives 34 codes with cause and remedy. Most platform operations document errors only as an `error` and `message` string pair (11). Dated public changelog, release notes per package and a document version of 1.0.0, with `/api/v1` paths mixed among unversioned ones (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "The MCP server registers 101 tools in the 2.1.0 source, with no toolsets or dynamic loading found. Trace tools return a compact digest by default, which earns 3 back (8). Cursor paging with `next_cursor`, `limit` and `pageSize`, filters, a projection DSL on trace search and a `digest` or `json` format switch (20). Gateway errors carry a stable code, tips, a docs link and a `fault` field, and the MCP client passes them on. Platform errors are plainer (16). No `readOnlyHint` or `destructiveHint` in the MCP source. Idempotency exists for evaluations and ingested events, and several delete tools archive instead of removing (8). Python, TypeScript and Go SDKs, a CLI, and few required parameters (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 71,
            "points": 12.43,
            "reason": "OAuth authorisation code with PKCE and dynamic client registration on the remote MCP server, and API keys with read or write per category, a project, team or organisation scope, expiry and revocation, plus write-only ingestion keys. The `apiKey` query parameter on `/sse` was removed in MCP server 2.0.0 (30). Restricted keys and lite members give read-only access, but no tool asks for confirmation before a delete and the MCP tools carry no annotations (14). Traces hold whatever the application logged, and we found no prompt-injection guidance for agents reading them (3). The audit log is Enterprise only and leaves out sign-ins and reads of product data. The key list shows a last-used date (9). SECURITY.md sets response targets and a safe harbour, one advisory was published in August 2026, and CodeQL runs in CI. ISO 27001 and a CREST penetration test are stated, with reports on request. No security.txt and no bug bounty found (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Per-unit prices are public without a login, 29 euros per core seat a month, 5 euros per 100,000 events and $0.0546 per million judge input tokens (20). The Developer plan is free with no card (20). A person signs up in a browser and creates the first key. The CLI's device-code login also needs a browser approval, and `platform_create_project` returns a key only to a caller that already holds an organisation key. Free self-hosting is not an agent route (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 90,
            "points": 7.88,
            "reason": "Platform 3.20.1 on 2 October 2026, seven days before the check (30). 21 platform releases dated since 11 July in CHANGELOG.md (20). 52 open issues and 222 open pull requests, with new issues filed, labelled and prioritised by maintainers within the past week, and support by email, Discord and GitHub. Reply times were not visible to us (17). Current official SDKs, Python 1.4.0 on 6 September, TypeScript 1.19.0 on 30 September and Go 1.0.0 on 9 September. The MCP server was not found in the official MCP registry (15). CI workflows for the app, each SDK and the MCP server, CodeQL, code scanners and dependency bumps in the changelog. We could not confirm the pass state (8)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 73, provenance 77",
            "reason": "Apache 2.0 platform with the `platform/app/ee` directory under a separate Enterprise licence, and MIT SDKs and MCP server (27). The privacy policy of 29 September 2026 names its processors and the retention docs are detailed, but the documents disagree in places. The pricing page says 30-day retention is included where the docs say 49 days, the terms describe a 14-day free trial where the pricing page says free forever, and the terms give two addresses and two spellings of the entity. The terms also grant LangWatch a perpetual licence to use client data to improve the platform, while saying it will not train on it (18). Deprecated endpoints are marked in the OpenAPI document and the docs, and breaking changes are flagged in the changelogs, but no removal dates or notice period were found (10). EU hosting on AWS is stated and processors are named in the privacy policy. Self-hosted telemetry is documented connection by connection with an off switch. The public sub-processor list is on a host we could not read (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server registers 101 tools in the 2.1.0 source, with no toolsets or dynamic loading found. Trace tools return a compact digest by default, which earns 3 back (8). Cursor paging with `next_cursor`, `limit` and `pageSize`, filters, a projection DSL on trace search and a `digest` or `json` format switch (20). Gateway errors carry a stable code, tips, a docs link and a `fault` field, and the MCP client passes them on. Platform errors are plainer (16). No `readOnlyHint` or `destructiveHint` in the MCP source. Idempotency exists for evaluations and ingested events, and several delete tools archive instead of removing (8). Python, TypeScript and Go SDKs, a CLI, and few required parameters (15).",
            "maintenance": "Platform 3.20.1 on 2 October 2026, seven days before the check (30). 21 platform releases dated since 11 July in CHANGELOG.md (20). 52 open issues and 222 open pull requests, with new issues filed, labelled and prioritised by maintainers within the past week, and support by email, Discord and GitHub. Reply times were not visible to us (17). Current official SDKs, Python 1.4.0 on 6 September, TypeScript 1.19.0 on 30 September and Go 1.0.0 on 9 September. The MCP server was not found in the official MCP registry (15). CI workflows for the app, each SDK and the MCP server, CodeQL, code scanners and dependency bumps in the changelog. We could not confirm the pass state (8).",
            "payments": "No x402, MPP or L402 (0). Per-unit prices are public without a login, 29 euros per core seat a month, 5 euros per 100,000 events and $0.0546 per million judge input tokens (20). The Developer plan is free with no card (20). A person signs up in a browser and creates the first key. The CLI's device-code login also needs a browser approval, and `platform_create_project` returns a key only to a caller that already holds an organisation key. Free self-hosting is not an agent route (0).",
            "reliability": "Graded as a hosted service (LangWatch Cloud). Better Stack status page with 9 components and 90 days of history (20). In that window the App had one 20-minute downtime on 19 July and the Collector 23 minutes that day and 5 minutes on 13 August, but the Processor was degraded on 17 days, for 14 hours 44 minutes on 31 July, and Scenarios was down on 7 days, for 9 hours 34 minutes on 8 September. The core API stayed under an hour and other components had several long incidents (10). No request rate limit for the platform API was found in the reviewed documentation. The only numbers are customer-set limits on AI Gateway virtual keys (0). Retries are partly covered. Events carry an idempotency key and are deduplicated, `evaluation_id` makes an evaluation call idempotent, and two operations declare a 429, one with `Retry-After`. No general backoff guidance for the platform API was found (8). The pricing page lists a contractual uptime and support SLA on Enterprise, with no published terms (5). The REST API, MCP server 2.1.0 and the 1.x SDKs are generally available (10).",
            "schema": "A public OpenAPI 3.1 document of 215 paths and 328 operations, served without a key, and typed zod inputs on every MCP tool (25). llms.txt and a Markdown twin of each docs page (10). Every operation has a summary or description, and MCP descriptions say when to pick a tool, for example `run_query` for counts and rates and `discover_schema` before a search. 158 operations carry no tag (16). 540 enums in the document, with trace filters still accepted as a free-form map alongside the query language (12). Docs pages carry request examples, and the gateway error list gives 34 codes with cause and remedy. Most platform operations document errors only as an `error` and `message` string pair (11). Dated public changelog, release notes per package and a document version of 1.0.0, with `/api/v1` paths mixed among unversioned ones (13).",
            "security": "OAuth authorisation code with PKCE and dynamic client registration on the remote MCP server, and API keys with read or write per category, a project, team or organisation scope, expiry and revocation, plus write-only ingestion keys. The `apiKey` query parameter on `/sse` was removed in MCP server 2.0.0 (30). Restricted keys and lite members give read-only access, but no tool asks for confirmation before a delete and the MCP tools carry no annotations (14). Traces hold whatever the application logged, and we found no prompt-injection guidance for agents reading them (3). The audit log is Enterprise only and leaves out sign-ins and reads of product data. The key list shows a last-used date (9). SECURITY.md sets response targets and a safe harbour, one advisory was published in August 2026, and CodeQL runs in CI. ISO 27001 and a CREST penetration test are stated, with reports on request. No security.txt and no bug bounty found (15).",
            "transparency": "Apache 2.0 platform with the `platform/app/ee` directory under a separate Enterprise licence, and MIT SDKs and MCP server (27). The privacy policy of 29 September 2026 names its processors and the retention docs are detailed, but the documents disagree in places. The pricing page says 30-day retention is included where the docs say 49 days, the terms describe a 14-day free trial where the pricing page says free forever, and the terms give two addresses and two spellings of the entity. The terms also grant LangWatch a perpetual licence to use client data to improve the platform, while saying it will not train on it (18). Deprecated endpoints are marked in the OpenAPI document and the docs, and breaking changes are flagged in the changelogs, but no removal dates or notice period were found (10). EU hosting on AWS is stated and processors are named in the privacy policy. Self-hosted telemetry is documented connection by connection with an off switch. The public sub-processor list is on a host we could not read (18)."
          },
          "sources": [
            {
              "what": "robots.txt, allows every path, no Content-Signal line",
              "url": "https://langwatch.ai/robots.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "docs index for agents, with the note addressed to AI agents",
              "url": "https://langwatch.ai/docs/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "API introduction, authentication and conventions",
              "url": "https://langwatch.ai/docs/api-reference/introduction.md",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI 3.1 document, 215 paths and 328 operations",
              "url": "https://app.langwatch.ai/api/gateway/v1/openapi.json",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server setup, modes and tool reference",
              "url": "https://langwatch.ai/docs/integration/mcp.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server source, 101 tool registrations, no annotations",
              "url": "https://github.com/langwatch/langwatch/tree/main/mcp/typescript/src",
              "seen": "2026-10-09"
            },
            {
              "what": "API key types, permission categories and expiry",
              "url": "https://langwatch.ai/docs/platform/api-keys.md",
              "seen": "2026-10-09"
            },
            {
              "what": "audit log scope and plan",
              "url": "https://langwatch.ai/docs/platform/audit-log.md",
              "seen": "2026-10-09"
            },
            {
              "what": "CLI install and login modes",
              "url": "https://langwatch.ai/docs/integration/cli.md",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing page, plans in euros",
              "url": "https://langwatch.ai/pricing",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing docs, events, Instant Evals and retention",
              "url": "https://langwatch.ai/docs/pricing.md",
              "seen": "2026-10-09"
            },
            {
              "what": "billable events and deduplication",
              "url": "https://langwatch.ai/docs/pricing/billable-events.md",
              "seen": "2026-10-09"
            },
            {
              "what": "data retention periods and scopes",
              "url": "https://langwatch.ai/docs/platform/data-retention.md",
              "seen": "2026-10-09"
            },
            {
              "what": "gateway error envelope and codes",
              "url": "https://langwatch.ai/docs/ai-gateway/api/errors.md",
              "seen": "2026-10-09"
            },
            {
              "what": "status page, 90-day component history",
              "url": "https://status.langwatch.ai/",
              "seen": "2026-10-09"
            },
            {
              "what": "security advisory GHSA-h25p-f8f6-2ccf",
              "url": "https://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf",
              "seen": "2026-10-09"
            },
            {
              "what": "security policy, response targets and safe harbour",
              "url": "https://github.com/langwatch/langwatch/blob/main/SECURITY.md",
              "seen": "2026-10-09"
            },
            {
              "what": "platform changelog, 3.20.1 on 2 October 2026",
              "url": "https://github.com/langwatch/langwatch/blob/main/CHANGELOG.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server changelog, 2.0.0 breaking changes",
              "url": "https://github.com/langwatch/langwatch/blob/main/mcp/typescript/CHANGELOG.md",
              "seen": "2026-10-09"
            },
            {
              "what": "repository home, stars and open issue count",
              "url": "https://github.com/langwatch/langwatch",
              "seen": "2026-10-09"
            },
            {
              "what": "open issues",
              "url": "https://github.com/langwatch/langwatch/issues",
              "seen": "2026-10-09"
            },
            {
              "what": "public changelog",
              "url": "https://langwatch.ai/changelog",
              "seen": "2026-10-09"
            },
            {
              "what": "editions and licences for self-hosting",
              "url": "https://langwatch.ai/docs/self-hosting/licensing.md",
              "seen": "2026-10-09"
            },
            {
              "what": "self-hosted outbound connections and telemetry",
              "url": "https://langwatch.ai/docs/self-hosting/data-and-telemetry.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Terms of Service, last updated 22 September 2026",
              "url": "https://langwatch.ai/legal/terms-conditions",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy, last updated 29 September 2026",
              "url": "https://langwatch.ai/legal/privacy-policy",
              "seen": "2026-10-09"
            },
            {
              "what": "trust centre",
              "url": "https://langwatch.ai/trust-center",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt, returns the site's HTML shell",
              "url": "https://langwatch.ai/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "npm package langwatch, version 1.19.0",
              "url": "https://registry.npmjs.org/langwatch/latest",
              "seen": "2026-10-09"
            },
            {
              "what": "npm weekly downloads, 50,105",
              "url": "https://api.npmjs.org/downloads/point/last-week/langwatch",
              "seen": "2026-10-09"
            },
            {
              "what": "PyPI weekly downloads, 87,325",
              "url": "https://pypistats.org/api/packages/langwatch/recent",
              "seen": "2026-10-09"
            },
            {
              "what": "official MCP registry search, no result",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=langwatch",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration, 2023-09-17",
              "url": "https://rdap.identitydigital.services/rdap/domain/langwatch.ai",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: the trust report and public sub-processor list on app.eu.vanta.com, whose robots.txt disallows every path",
            "unchecked: the PyPI project page for `langwatch`, which answered with a client challenge. The Python SDK version comes from the repository",
            "unchecked: dollar prices for the Growth plan. The pricing page has a currency switch and we read the euro figures only",
            "unchecked: whether a Restricted key shortens the MCP tool list or only refuses calls. We read the source and did not run the server",
            "No rate limit for the platform API and no published SLA terms were found in the reviewed documentation",
            "Whether the terms clause against automated or non-human access is meant to cover API and MCP use is not stated",
            "The DPA is available to Enterprise customers on request and was not read",
            "We cloned the GitHub repository before reading github.com/robots.txt. The pages later fetched from github.com are not disallowed by it"
          ]
        },
        "negative": -2,
        "negativeNotes": [
          "2026-08-19. Advisory GHSA-h25p-f8f6-2ccf, rated moderate. The standalone HTTP mode of `@langwatch/mcp-server` 0.7.0 to 1.0.0 authorised requests by session id alone and accepted an API key in the URL. Fixed in 2.0.0 on 7 August 2026 and flagged as a breaking change. The advisory says the default stdio mode and the hosted handler were never affected, so -2 (https://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf)"
        ],
        "verdict": "API keys can be limited to read or write per permission category, expire, and be revoked, and the remote MCP server uses OAuth with PKCE. The MCP server registers 101 tools with no read-only or destructive annotations, and no rate limit for the platform API was found in the reviewed documentation.",
        "bestFor": "Teams that want tracing, evaluations and simulated-user agent tests in one open-source product, hosted in the EU or self-hosted, and that drive it from a coding assistant through MCP or the CLI.",
        "strengths": [
          "API keys take read or write per permission category, a project, team or organisation scope and an expiry. Ingestion keys can only write traces",
          "A public OpenAPI 3.1 document covers 328 operations and is served without a key, with llms.txt and a Markdown twin of every docs page",
          "Apache 2.0 platform with MIT SDKs and MCP server. Self-hosting has no volume cap, and every outbound call is documented with its off switch",
          "The free Developer plan needs no card and includes 50,000 events a month. Paid usage is published at 5 euros per 100,000 events",
          "Platform 3.20.1 shipped on 2 October 2026, with 21 platform releases dated since 11 July in the repository changelog"
        ],
        "weaknesses": [
          "The MCP server registers 101 tools, deletes and key creation among them, with no toolsets and no `readOnlyHint` or `destructiveHint` annotations in the source",
          "No request rate limit for the platform API was found in the reviewed documentation. Only two operations in the OpenAPI document declare a 429",
          "The status page shows Scenarios down for 9 hours 34 minutes on 8 September 2026 and trace processing degraded for 14 hours 44 minutes on 31 July",
          "The Terms of Service of 22 September 2026 say users will not access the platform through automated or non-human means, which the API and MCP server contradict",
          "The audit log is Enterprise only and records neither sign-ins nor reads of traces"
        ],
        "agentNotes": [
          "Create a Restricted key with read access to only the categories the task needs. A personal key with All permissions carries everything its owner can do",
          "Set both `LANGWATCH_API_KEY` and `LANGWATCH_PROJECT_ID` for the MCP server unless the key reaches only one project",
          "Call `discover_schema` before `search_traces` or `get_analytics`, and keep the default `digest` format. `json` returns the full raw trace",
          "Allowlist MCP tools in the client. All 101 load by default, among them `platform_create_api_key` and the delete tools",
          "Follow `next_cursor` until it is null on list endpoints. A full page does not mean more rows exist"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.5
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 90,
          "payments": 40,
          "reliability": 53,
          "schema": 87,
          "security": 71,
          "transparency": 73
        },
        "provenanceScore": 77
      },
      "connect": {
        "install": "npm install -g langwatch",
        "http": "curl https://app.langwatch.ai/api/gateway/v1/openapi.json",
        "claudeCode": "claude mcp add langwatch --env LANGWATCH_API_KEY=sk-lw-... --env LANGWATCH_PROJECT_ID=your-project-id -- npx -y @langwatch/mcp-server",
        "config": {
          "mcpServers": {
            "langwatch": {
              "args": [
                "-y",
                "@langwatch/mcp-server"
              ],
              "command": "npx",
              "env": {
                "LANGWATCH_API_KEY": "sk-lw-...",
                "LANGWATCH_PROJECT_ID": "your-project-id"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/obs.traces",
        "tool": "https://letme.dev/langwatch"
      },
      "notable": [
        "The whole REST API is one OpenAPI 3.1 document of 215 paths and 328 operations, served without a key at `/api/gateway/v1/openapi.json` on app.langwatch.ai (https://langwatch.ai/docs/api-reference/introduction.md)",
        "The MCP server runs locally over stdio as `@langwatch/mcp-server`, or remotely at https://app.langwatch.ai/mcp and `/sse` with OAuth authorisation code, PKCE and dynamic client registration (https://langwatch.ai/docs/integration/mcp.md)",
        "Version 2.1.0 of the MCP server source registers 101 tools, from `search_traces` and `run_query` to `platform_create_api_key`, with no tool annotations (https://github.com/langwatch/langwatch/tree/main/mcp/typescript/src)",
        "API keys are personal or service keys with an All or Restricted mode across 21 permission categories. An ingestion key (`ik-lw-`) holds `traces:create` only (https://langwatch.ai/docs/platform/api-keys.md)",
        "Advisory GHSA-h25p-f8f6-2ccf, published 19 August 2026 and rated moderate, covers the standalone HTTP mode of `@langwatch/mcp-server` 0.7.0 to 1.0.0. It is fixed in 2.0.0 and says the hosted handler was never affected (https://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf)",
        "A self-hosted install sends LangWatch one usage report a day of counts and metadata. `DISABLE_USAGE_STATS=true` stops it (https://langwatch.ai/docs/self-hosting/data-and-telemetry.md)",
        "The docs index and each docs page carry a note addressed to AI agents asking them to seek the user's permission and run `npx langwatch report`. We did not act on it (https://langwatch.ai/docs/llms.txt)",
        "The Terms of Service list among user representations that the user will not access the platform through automated or non-human means, whether through a bot, script or otherwise (https://langwatch.ai/legal/terms-conditions)"
      ],
      "area": "developer",
      "details": [
        {
          "label": "Surface graded",
          "value": "LangWatch Cloud at https://app.langwatch.ai, through the REST API and the MCP server. The same image runs self-hosted under Apache 2.0"
        },
        {
          "label": "REST API",
          "value": "OpenAPI 3.1, 215 paths and 328 operations, 9 marked deprecated. Fields in lower_snake_case, cursor paging with `next_cursor`, errors with a stable `error.code`"
        },
        {
          "label": "MCP server",
          "value": "`@langwatch/mcp-server` 2.1.0 (12 September 2026), MIT. stdio by default, or hosted at https://app.langwatch.ai/mcp (Streamable HTTP) and `/sse`. 101 tools in the source, no toolsets, no annotations"
        },
        {
          "label": "Credentials",
          "value": "API keys `sk-lw-` (personal or service, All or Restricted per category, scope of projects, teams or organisation, optional expiry, revocable), write-only ingestion keys `ik-lw-`, OAuth with PKCE for remote MCP, device-code login for the CLI"
        },
        {
          "label": "Headers",
          "value": "`X-Auth-Token: sk-lw-...` or `Authorization: Bearer sk-lw-...`. AI Gateway inference endpoints take a virtual key on the gateway host"
        },
        {
          "label": "Rate limits",
          "value": "No platform API rate limit found in the reviewed documentation. Virtual keys on the AI Gateway take customer-set requests per minute and per day"
        },
        {
          "label": "SDKs and CLI",
          "value": "Python `langwatch` 1.4.0 (6 September 2026), TypeScript `langwatch` 1.19.0 on npm (also the CLI, Node 20 or newer per the package), Go SDK 1.0.0 (9 September 2026). OpenTelemetry ingestion"
        },
        {
          "label": "Free tier",
          "value": "Developer plan, no card. 50,000 events a month, 2 users, 3 scenarios, 3 simulations and 3 custom evaluations. Trace content older than 14 days is redacted"
        },
        {
          "label": "Retention",
          "value": "49 days by default per the docs. Paid plans set 35 or 63 days, Enterprise any whole number of weeks from 49 days. The pricing page says 30-day retention is included on Growth"
        },
        {
          "label": "Audit",
          "value": "Enterprise plan or licence only. Logs settings, API key, member and gateway changes with user and IP address. Sign-ins and reads of product data are not logged"
        },
        {
          "label": "Status",
          "value": "status.langwatch.ai on Better Stack, 9 components with 90 days of history. App 99.983 per cent, Collector 99.977 per cent and Scenarios 96.488 per cent over the period shown on 9 October 2026"
        },
        {
          "label": "Data location",
          "value": "LangWatch Cloud stores data in the EU on AWS per the pricing FAQ and trust centre. Other regions on request. Self-hosted and hybrid deployments keep data on the customer's side"
        },
        {
          "label": "Certifications",
          "value": "ISO 27001 and GDPR compliance stated on the trust centre and in the docs, with reports and a CREST penetration test on request. The trust centre lists SOC 2 as via AWS"
        }
      ],
      "unitPrices": [
        {
          "item": "Instant Evals, judge input tokens",
          "unit": "1m-tokens",
          "usd": 0.0546,
          "note": "Output is free. Unpaid organisations have a $1 budget in total"
        }
      ],
      "provenance": {
        "legalEntity": "Reasoning Engine B.V. (doing business as LangWatch)",
        "domain": "langwatch.ai",
        "domainRegistered": "2023-09-17",
        "endpointOnVendorDomain": true,
        "terms": "https://langwatch.ai/legal/terms-conditions",
        "privacy": "https://langwatch.ai/legal/privacy-policy",
        "statusPage": "https://status.langwatch.ai",
        "changelog": "https://langwatch.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The privacy policy (last updated 29 September 2026) applies to Reasoning Engine B.V., doing business as LangWatch, and covers the website and the Cloud Service. The Terms of Service (last updated 22 September 2026) cover the platform and the on-premise product.",
          "The terms page names the entity as Reasoning Engines B.V. in its heading and Reasoning Engine B.V. in its definitions, gives Singel 126, Amsterdam as the registered office and Herengracht 551, Amsterdam as the contact address. The site footer reads LangWatch B.V.",
          "The API, the hosted MCP server and the OpenAPI document are served from app.langwatch.ai. Hosted services for self-hosted installs with a licence use connect.langwatch.ai and gateway.langwatch.ai.",
          "https://langwatch.ai/.well-known/security.txt returns the website's HTML shell, not a security.txt file. SECURITY.md in the repository gives security@langwatch.ai and GitHub private reporting.",
          "RDAP for langwatch.ai gives a registration date of 2023-09-17 and GoDaddy.com, LLC as registrar.",
          "The trust report and sub-processor list are on app.eu.vanta.com, whose robots.txt disallows every path, so we did not read them."
        ],
        "score": 77,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Reasoning Engine B.V. (doing business as LangWatch)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "langwatch.ai, registered 2023-09-17 (3 years)",
            "points": 7,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "app.langwatch.ai",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.langwatch.ai",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://langwatch.ai/legal/terms-conditions",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-22",
            "words": 5004,
            "points": 6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated September 22, 2026",
                "says": "Last updated 2026-09-22"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Any disputes that may arise from these Terms and Services, Agreements or any future (legal) relationships between LangWatch and the Client will be submitted to the competent court in Amsterdam, the Netherlands.",
                "says": "Disputes go to the courts of Amsterdam"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "The maximum aggregate liability of LangWatch under this Agreement shall not exceed the total amount invoiced to the Client for the six (6) months immediately preceding the event giving rise to the claim with a maximum of €6.000,00 (six thousand euros).",
                "says": "Capped at €6.000"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "The account will not be charged and the subscription will be suspended until upgraded to a paid package at the end of the free trial."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "LangWatch shall provide the Client with at least 30 days' written notice before implementing any price change.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "(6) you will not access the Platform through automated or non-human means, whether through a bot, script or otherwise;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Given the nature of the services we cannot guarantee this unless the guarantee is separately agreed in a service level agreement."
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(6) you will not access the Platform through automated or non-human means, whether through a bot, script or otherwise;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We reserve the right to change, revise, update, suspend, discontinue, or otherwise modify the Platform at any time or for any reason without notice to you.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Liability is capped at the amount invoiced in the six months before the claim, with a maximum of 6,000 euros.",
                "quote": "The maximum aggregate liability of LangWatch under this Agreement shall not exceed the total amount invoiced to the Client for the six (6) months immediately preceding the event giving rise to the claim with a maximum of €6.000,00 (six thousand euros)."
              },
              {
                "date": "2026-10-08",
                "text": "The client grants LangWatch a perpetual, worldwide licence to use client data to improve the platform and services.",
                "quote": "Client grants LangWatch a non-exclusive, worldwide, perpetual, royalty-free license to use Clients’ data for the improvement of the Platform and Services."
              },
              {
                "date": "2026-10-08",
                "text": "The client cannot end the agreement early during the agreed period.",
                "quote": "The Client cannot (partially) terminate (opzeggen/ontbinden) the Agreement early, in derogation from article 7:408 DCC."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://langwatch.ai/legal/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-29",
            "words": 5272,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated September 29th, 2026",
                "says": "Last updated 2026-09-29"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This privacy notice applies to Reasoning Engine B.V., doing business as LangWatch (“we,” “us,” or “our”), and explains how and why we collect, store, use, and share your information (“process”) when you use our services (“Services”)."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain each daily usage report described in section 1 for 24 months from the date we receive it, and the record of an installation for as long as it continues to report, plus 24 months.",
                "says": "Names a period of 24 months"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may share personal information in limited circumstances and only with specific third parties."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We may also share or transfer your personal information in connection with, or during negotiations relating to, a merger, sale of company assets, financing, or acquisition of all or part of our business by another company."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You can exercise your rights by submitting a data subject access request or by contacting us directly."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions or concerns, you can contact us at privacy@langwatch.ai.",
                "says": "privacy@langwatch.ai"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "TypeSafe, which receives trace text for Instant Eval runs, processes it on LangWatch's instructions and does not use it to train its models.",
                "quote": "TypeSafe processes this data on our instructions under a data processing agreement and does not use it to train its models."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/langwatch.json",
      "live": {
        "slug": "langwatch",
        "probe": {
          "target": "https://app.langwatch.ai",
          "method": "get",
          "lastAt": "2026-10-09T09:26:54.599795486Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 145,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 85,
          "p95ms24h": 135,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.langwatch.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:07.342247188Z"
        },
        "updatedAt": "2026-10-09T09:26:54.599795486Z"
      }
    },
    "verify": {
      "accepts": "a page on langwatch.ai or one of its subdomains, or the README of github.com/langwatch/langwatch",
      "badgeUrl": "https://www.anchorterminal.com/badges/langwatch.svg",
      "body": {
        "slug": "langwatch",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/langwatch",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/langwatch\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/langwatch.svg\" alt=\"LangWatch on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![LangWatch on Anchor Terminal](https://www.anchorterminal.com/badges/langwatch.svg)](https://www.anchorterminal.com/tools/langwatch)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/langwatch\"\u003eLangWatch on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/langwatch",
    "json": "https://www.anchorterminal.com/tools/langwatch.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/langwatch.md",
    "slim": "https://www.anchorterminal.com/tools/langwatch.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 65.5/100 · rank #291 of 842 · #7 in Agent observability \u0026 evals · not agent-ready · confidence medium**\n\n\n## Assessment\n\nAPI keys can be limited to read or write per permission category, expire, and be revoked, and the remote MCP server uses OAuth with PKCE. The MCP server registers 101 tools with no read-only or destructive annotations, and no rate limit for the platform API was found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Reasoning Engine B.V. (LangWatch) (https://langwatch.ai) |\n| Kind | HTTP API |\n| Category | Agent observability \u0026 evals (https://www.anchorterminal.com/categories/agent-observability) |\n| Transport | HTTP, Streamable HTTP, SSE (legacy), stdio |\n| Endpoint | `https://app.langwatch.ai` |\n| Auth | OAuth or key · A person signs up at app.langwatch.ai and creates keys under Settings, API Keys, with no review step. API keys (`sk-lw-`) go in `X-Auth-Token` or as a Bearer token. A personal key never exceeds its owner's permissions, a service key belongs to the organisation and only admins create one. Either can be All or Restricted to read or write per permission category, scoped to projects, teams or the organisation, given an expiry and revoked. Ingestion keys (`ik-lw-`) can only write traces to one project. The remote MCP server uses OAuth authorisation code with PKCE and dynamic client registration. The CLI logs in with a device code approved in a browser. |\n| Pricing | Freemium (Freemium) · The Developer plan is free with no card and includes 50,000 events a month, 2 users and 3 scenarios, so an agent can start without a contract once a person has signed up. Growth is 29 euros per core seat a month with 200,000 events, then 5 euros per 100,000 events and 3 euros per GB kept beyond the included retention. Enterprise is sold through sales. Instant Evals cost $0.0546 per million input tokens, with a $1 budget on unpaid organisations. The pricing page has a currency switch and we read the euro prices only. Self-hosting under Apache 2.0 is free with no volume cap, and an Enterprise licence is priced per seat (https://langwatch.ai/pricing, https://langwatch.ai/docs/pricing.md). |\n| x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI document or the pricing page (checked 2026-10-09). |\n| Licence | Apache 2.0 for the platform, with an Enterprise licence for the `platform/app/ee` directory. The SDKs and the MCP server are MIT |\n| Tools exposed | 101 |\n| Packages | npm: `langwatch`; npm: `@langwatch/mcp-server`; pypi: `langwatch` |\n| Source | https://github.com/langwatch/langwatch |\n| Docs | https://langwatch.ai/docs/introduction |\n| llms.txt | https://langwatch.ai/docs/llms.txt |\n| Last release | 2026-10-02 |\n| GitHub stars | 4,925 (as of 2026-10-09) |\n| npm downloads / week | 50,105 |\n| PyPI downloads / week | 87,325 |\n| Surface graded | LangWatch Cloud at https://app.langwatch.ai, through the REST API and the MCP server. The same image runs self-hosted under Apache 2.0 |\n| REST API | OpenAPI 3.1, 215 paths and 328 operations, 9 marked deprecated. Fields in lower_snake_case, cursor paging with `next_cursor`, errors with a stable `error.code` |\n| MCP server | `@langwatch/mcp-server` 2.1.0 (12 September 2026), MIT. stdio by default, or hosted at https://app.langwatch.ai/mcp (Streamable HTTP) and `/sse`. 101 tools in the source, no toolsets, no annotations |\n| Credentials | API keys `sk-lw-` (personal or service, All or Restricted per category, scope of projects, teams or organisation, optional expiry, revocable), write-only ingestion keys `ik-lw-`, OAuth with PKCE for remote MCP, device-code login for the CLI |\n| Headers | `X-Auth-Token: sk-lw-...` or `Authorization: Bearer sk-lw-...`. AI Gateway inference endpoints take a virtual key on the gateway host |\n| Rate limits | No platform API rate limit found in the reviewed documentation. Virtual keys on the AI Gateway take customer-set requests per minute and per day |\n| SDKs and CLI | Python `langwatch` 1.4.0 (6 September 2026), TypeScript `langwatch` 1.19.0 on npm (also the CLI, Node 20 or newer per the package), Go SDK 1.0.0 (9 September 2026). OpenTelemetry ingestion |\n| Free tier | Developer plan, no card. 50,000 events a month, 2 users, 3 scenarios, 3 simulations and 3 custom evaluations. Trace content older than 14 days is redacted |\n| Retention | 49 days by default per the docs. Paid plans set 35 or 63 days, Enterprise any whole number of weeks from 49 days. The pricing page says 30-day retention is included on Growth |\n| Audit | Enterprise plan or licence only. Logs settings, API key, member and gateway changes with user and IP address. Sign-ins and reads of product data are not logged |\n| Status | status.langwatch.ai on Better Stack, 9 components with 90 days of history. App 99.983 per cent, Collector 99.977 per cent and Scenarios 96.488 per cent over the period shown on 9 October 2026 |\n| Data location | LangWatch Cloud stores data in the EU on AWS per the pricing FAQ and trust centre. Other regions on request. Self-hosted and hybrid deployments keep data on the customer's side |\n| Certifications | ISO 27001 and GDPR compliance stated on the trust centre and in the docs, with reports and a CREST penetration test on request. The trust centre lists SOC 2 as via AWS |\n| Capabilities | obs.traces, obs.evals, obs.prompts, obs.datasets, obs.gateway |\n| Tags | hosted, freemium, no-card, open-source, self-hosted, mcp, oauth, llms-txt, openapi, opentelemetry, python, typescript, go, cli, status-page, eu-hosted |\n| JSON | https://www.anchorterminal.com/api/v1/tools/langwatch.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 53 | 10.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 87 | 14.1 |\n| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |\n| Security \u0026 auth | 14% | 17.5 | 71 | 12.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 90 | 7.9 |\n| Transparency \u0026 trust (editorial 73, provenance 77) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | 2026-08-19. Advisory GHSA-h25p-f8f6-2ccf, rated moderate. The standalone HTTP mode of `@langwatch/mcp-server` 0.7.0 to 1.0.0 authorised requests by session id alone and accepted an API key in the URL. Fixed in 2.0.0 on 7 August 2026 and flagged as a breaking change. The advisory says the default stdio mode and the hosted handler were never affected, so -2 (https://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf)  | -2 |\n| **Total** | | | | **65.5 → B** |\n\n### Why each score\n\n- Reliability 53: Graded as a hosted service (LangWatch Cloud). Better Stack status page with 9 components and 90 days of history (20). In that window the App had one 20-minute downtime on 19 July and the Collector 23 minutes that day and 5 minutes on 13 August, but the Processor was degraded on 17 days, for 14 hours 44 minutes on 31 July, and Scenarios was down on 7 days, for 9 hours 34 minutes on 8 September. The core API stayed under an hour and other components had several long incidents (10). No request rate limit for the platform API was found in the reviewed documentation. The only numbers are customer-set limits on AI Gateway virtual keys (0). Retries are partly covered. Events carry an idempotency key and are deduplicated, `evaluation_id` makes an evaluation call idempotent, and two operations declare a 429, one with `Retry-After`. No general backoff guidance for the platform API was found (8). The pricing page lists a contractual uptime and support SLA on Enterprise, with no published terms (5). The REST API, MCP server 2.1.0 and the 1.x SDKs are generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 87: A public OpenAPI 3.1 document of 215 paths and 328 operations, served without a key, and typed zod inputs on every MCP tool (25). llms.txt and a Markdown twin of each docs page (10). Every operation has a summary or description, and MCP descriptions say when to pick a tool, for example `run_query` for counts and rates and `discover_schema` before a search. 158 operations carry no tag (16). 540 enums in the document, with trace filters still accepted as a free-form map alongside the query language (12). Docs pages carry request examples, and the gateway error list gives 34 codes with cause and remedy. Most platform operations document errors only as an `error` and `message` string pair (11). Dated public changelog, release notes per package and a document version of 1.0.0, with `/api/v1` paths mixed among unversioned ones (13).\n- Agent ergonomics 67: The MCP server registers 101 tools in the 2.1.0 source, with no toolsets or dynamic loading found. Trace tools return a compact digest by default, which earns 3 back (8). Cursor paging with `next_cursor`, `limit` and `pageSize`, filters, a projection DSL on trace search and a `digest` or `json` format switch (20). Gateway errors carry a stable code, tips, a docs link and a `fault` field, and the MCP client passes them on. Platform errors are plainer (16). No `readOnlyHint` or `destructiveHint` in the MCP source. Idempotency exists for evaluations and ingested events, and several delete tools archive instead of removing (8). Python, TypeScript and Go SDKs, a CLI, and few required parameters (15).\n- Security \u0026 auth 71: OAuth authorisation code with PKCE and dynamic client registration on the remote MCP server, and API keys with read or write per category, a project, team or organisation scope, expiry and revocation, plus write-only ingestion keys. The `apiKey` query parameter on `/sse` was removed in MCP server 2.0.0 (30). Restricted keys and lite members give read-only access, but no tool asks for confirmation before a delete and the MCP tools carry no annotations (14). Traces hold whatever the application logged, and we found no prompt-injection guidance for agents reading them (3). The audit log is Enterprise only and leaves out sign-ins and reads of product data. The key list shows a last-used date (9). SECURITY.md sets response targets and a safe harbour, one advisory was published in August 2026, and CodeQL runs in CI. ISO 27001 and a CREST penetration test are stated, with reports on request. No security.txt and no bug bounty found (15).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Per-unit prices are public without a login, 29 euros per core seat a month, 5 euros per 100,000 events and $0.0546 per million judge input tokens (20). The Developer plan is free with no card (20). A person signs up in a browser and creates the first key. The CLI's device-code login also needs a browser approval, and `platform_create_project` returns a key only to a caller that already holds an organisation key. Free self-hosting is not an agent route (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 90: Platform 3.20.1 on 2 October 2026, seven days before the check (30). 21 platform releases dated since 11 July in CHANGELOG.md (20). 52 open issues and 222 open pull requests, with new issues filed, labelled and prioritised by maintainers within the past week, and support by email, Discord and GitHub. Reply times were not visible to us (17). Current official SDKs, Python 1.4.0 on 6 September, TypeScript 1.19.0 on 30 September and Go 1.0.0 on 9 September. The MCP server was not found in the official MCP registry (15). CI workflows for the app, each SDK and the MCP server, CodeQL, code scanners and dependency bumps in the changelog. We could not confirm the pass state (8).\n- Transparency \u0026 trust 75: Apache 2.0 platform with the `platform/app/ee` directory under a separate Enterprise licence, and MIT SDKs and MCP server (27). The privacy policy of 29 September 2026 names its processors and the retention docs are detailed, but the documents disagree in places. The pricing page says 30-day retention is included where the docs say 49 days, the terms describe a 14-day free trial where the pricing page says free forever, and the terms give two addresses and two spellings of the entity. The terms also grant LangWatch a perpetual licence to use client data to improve the platform, while saying it will not train on it (18). Deprecated endpoints are marked in the OpenAPI document and the docs, and breaking changes are flagged in the changelogs, but no removal dates or notice period were found (10). EU hosting on AWS is stated and processors are named in the privacy policy. Self-hosted telemetry is documented connection by connection with an off switch. The public sub-processor list is on a host we could not read (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/langwatch.md (JSON https://www.anchorterminal.com/fixes/langwatch.json)\n\n### What we couldn't check\n\n- unchecked: the trust report and public sub-processor list on app.eu.vanta.com, whose robots.txt disallows every path\n- unchecked: the PyPI project page for `langwatch`, which answered with a client challenge. The Python SDK version comes from the repository\n- unchecked: dollar prices for the Growth plan. The pricing page has a currency switch and we read the euro figures only\n- unchecked: whether a Restricted key shortens the MCP tool list or only refuses calls. We read the source and did not run the server\n- No rate limit for the platform API and no published SLA terms were found in the reviewed documentation\n- Whether the terms clause against automated or non-human access is meant to cover API and MCP use is not stated\n- The DPA is available to Enterprise customers on request and was not read\n- We cloned the GitHub repository before reading github.com/robots.txt. The pages later fetched from github.com are not disallowed by it\n\n### Sources\n\n- robots.txt, allows every path, no Content-Signal line: \u003chttps://langwatch.ai/robots.txt\u003e (seen 2026-10-09)\n- docs index for agents, with the note addressed to AI agents: \u003chttps://langwatch.ai/docs/llms.txt\u003e (seen 2026-10-09)\n- API introduction, authentication and conventions: \u003chttps://langwatch.ai/docs/api-reference/introduction.md\u003e (seen 2026-10-09)\n- OpenAPI 3.1 document, 215 paths and 328 operations: \u003chttps://app.langwatch.ai/api/gateway/v1/openapi.json\u003e (seen 2026-10-09)\n- MCP server setup, modes and tool reference: \u003chttps://langwatch.ai/docs/integration/mcp.md\u003e (seen 2026-10-09)\n- MCP server source, 101 tool registrations, no annotations: \u003chttps://github.com/langwatch/langwatch/tree/main/mcp/typescript/src\u003e (seen 2026-10-09)\n- API key types, permission categories and expiry: \u003chttps://langwatch.ai/docs/platform/api-keys.md\u003e (seen 2026-10-09)\n- audit log scope and plan: \u003chttps://langwatch.ai/docs/platform/audit-log.md\u003e (seen 2026-10-09)\n- CLI install and login modes: \u003chttps://langwatch.ai/docs/integration/cli.md\u003e (seen 2026-10-09)\n- pricing page, plans in euros: \u003chttps://langwatch.ai/pricing\u003e (seen 2026-10-09)\n- pricing docs, events, Instant Evals and retention: \u003chttps://langwatch.ai/docs/pricing.md\u003e (seen 2026-10-09)\n- billable events and deduplication: \u003chttps://langwatch.ai/docs/pricing/billable-events.md\u003e (seen 2026-10-09)\n- data retention periods and scopes: \u003chttps://langwatch.ai/docs/platform/data-retention.md\u003e (seen 2026-10-09)\n- gateway error envelope and codes: \u003chttps://langwatch.ai/docs/ai-gateway/api/errors.md\u003e (seen 2026-10-09)\n- status page, 90-day component history: \u003chttps://status.langwatch.ai/\u003e (seen 2026-10-09)\n- security advisory GHSA-h25p-f8f6-2ccf: \u003chttps://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf\u003e (seen 2026-10-09)\n- security policy, response targets and safe harbour: \u003chttps://github.com/langwatch/langwatch/blob/main/SECURITY.md\u003e (seen 2026-10-09)\n- platform changelog, 3.20.1 on 2 October 2026: \u003chttps://github.com/langwatch/langwatch/blob/main/CHANGELOG.md\u003e (seen 2026-10-09)\n- MCP server changelog, 2.0.0 breaking changes: \u003chttps://github.com/langwatch/langwatch/blob/main/mcp/typescript/CHANGELOG.md\u003e (seen 2026-10-09)\n- repository home, stars and open issue count: \u003chttps://github.com/langwatch/langwatch\u003e (seen 2026-10-09)\n- open issues: \u003chttps://github.com/langwatch/langwatch/issues\u003e (seen 2026-10-09)\n- public changelog: \u003chttps://langwatch.ai/changelog\u003e (seen 2026-10-09)\n- editions and licences for self-hosting: \u003chttps://langwatch.ai/docs/self-hosting/licensing.md\u003e (seen 2026-10-09)\n- self-hosted outbound connections and telemetry: \u003chttps://langwatch.ai/docs/self-hosting/data-and-telemetry.md\u003e (seen 2026-10-09)\n- Terms of Service, last updated 22 September 2026: \u003chttps://langwatch.ai/legal/terms-conditions\u003e (seen 2026-10-09)\n- privacy policy, last updated 29 September 2026: \u003chttps://langwatch.ai/legal/privacy-policy\u003e (seen 2026-10-09)\n- trust centre: \u003chttps://langwatch.ai/trust-center\u003e (seen 2026-10-09)\n- security.txt, returns the site's HTML shell: \u003chttps://langwatch.ai/.well-known/security.txt\u003e (seen 2026-10-09)\n- npm package langwatch, version 1.19.0: \u003chttps://registry.npmjs.org/langwatch/latest\u003e (seen 2026-10-09)\n- npm weekly downloads, 50,105: \u003chttps://api.npmjs.org/downloads/point/last-week/langwatch\u003e (seen 2026-10-09)\n- PyPI weekly downloads, 87,325: \u003chttps://pypistats.org/api/packages/langwatch/recent\u003e (seen 2026-10-09)\n- official MCP registry search, no result: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=langwatch\u003e (seen 2026-10-09)\n- domain registration, 2023-09-17: \u003chttps://rdap.identitydigital.services/rdap/domain/langwatch.ai\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 77/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Reasoning Engine B.V. (doing business as LangWatch) | 20/20 |\n| Domain age | langwatch.ai, registered 2023-09-17 (3 years) | 7/15 |\n| Endpoint on the vendor's domain | app.langwatch.ai | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.langwatch.ai | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe privacy policy (last updated 29 September 2026) applies to Reasoning Engine B.V., doing business as LangWatch, and covers the website and the Cloud Service. The Terms of Service (last updated 22 September 2026) cover the platform and the on-premise product.\n\nThe terms page names the entity as Reasoning Engines B.V. in its heading and Reasoning Engine B.V. in its definitions, gives Singel 126, Amsterdam as the registered office and Herengracht 551, Amsterdam as the contact address. The site footer reads LangWatch B.V.\n\nThe API, the hosted MCP server and the OpenAPI document are served from app.langwatch.ai. Hosted services for self-hosted installs with a licence use connect.langwatch.ai and gateway.langwatch.ai.\n\nhttps://langwatch.ai/.well-known/security.txt returns the website's HTML shell, not a security.txt file. SECURITY.md in the repository gives security@langwatch.ai and GitHub private reporting.\n\nRDAP for langwatch.ai gives a registration date of 2023-09-17 and GoDaddy.com, LLC as registrar.\n\nThe trust report and sub-processor list are on app.eu.vanta.com, whose robots.txt disallows every path, so we did not read them.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://langwatch.ai/legal/terms-conditions), read 2026-10-08, dated 2026-09-22, states 7 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(6) you will not access the Platform through automated or non-human means, whether through a bot, script or otherwise;\"\n- To know. Says the terms or the service can change without notice (costs points). \"We reserve the right to change, revise, update, suspend, discontinue, or otherwise modify the Platform at any time or for any reason without notice to you.\"\n- Gives the date it was last updated. Last updated 2026-09-22.\n- Names the governing law or courts. Disputes go to the courts of Amsterdam.\n- States a limit on its liability. Capped at €6.000.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Also in the text (2026-10-08). Liability is capped at the amount invoiced in the six months before the claim, with a maximum of 6,000 euros. \"The maximum aggregate liability of LangWatch under this Agreement shall not exceed the total amount invoiced to the Client for the six (6) months immediately preceding the event giving rise to the claim with a maximum of €6.000,00 (six thousand euros).\"\n- Also in the text (2026-10-08). The client grants LangWatch a perpetual, worldwide licence to use client data to improve the platform and services. \"Client grants LangWatch a non-exclusive, worldwide, perpetual, royalty-free license to use Clients’ data for the improvement of the Platform and Services.\"\n- Also in the text (2026-10-08). The client cannot end the agreement early during the agreed period. \"The Client cannot (partially) terminate (opzeggen/ontbinden) the Agreement early, in derogation from article 7:408 DCC.\"\n\n**Privacy policy** (https://langwatch.ai/legal/privacy-policy), read 2026-10-08, dated 2026-09-29, states 7 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-09-29.\n- Says how long data is kept. Names a period of 24 months.\n- Gives a privacy contact. privacy@langwatch.ai.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). TypeSafe, which receives trace text for Instant Eval runs, processes it on LangWatch's instructions and does not use it to train its models. \"TypeSafe processes this data on our instructions under a data processing agreement and does not use it to train its models.\"\n\n## Live (updated 2026-10-09 09:26 UTC)\n\n- Right now: up, HTTP 200, 145 ms, checked 2026-10-09 09:26 UTC (get on `https://app.langwatch.ai`)\n- Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 85 ms · p95 135 ms\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/langwatch.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Instant Evals, judge input tokens | $0.0546 | per 1M tokens | Output is free. Unpaid organisations have a $1 budget in total |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- API keys take read or write per permission category, a project, team or organisation scope and an expiry. Ingestion keys can only write traces\n- A public OpenAPI 3.1 document covers 328 operations and is served without a key, with llms.txt and a Markdown twin of every docs page\n- Apache 2.0 platform with MIT SDKs and MCP server. Self-hosting has no volume cap, and every outbound call is documented with its off switch\n- The free Developer plan needs no card and includes 50,000 events a month. Paid usage is published at 5 euros per 100,000 events\n- Platform 3.20.1 shipped on 2 October 2026, with 21 platform releases dated since 11 July in the repository changelog\n\n## Weaknesses\n\n- The MCP server registers 101 tools, deletes and key creation among them, with no toolsets and no `readOnlyHint` or `destructiveHint` annotations in the source\n- No request rate limit for the platform API was found in the reviewed documentation. Only two operations in the OpenAPI document declare a 429\n- The status page shows Scenarios down for 9 hours 34 minutes on 8 September 2026 and trace processing degraded for 14 hours 44 minutes on 31 July\n- The Terms of Service of 22 September 2026 say users will not access the platform through automated or non-human means, which the API and MCP server contradict\n- The audit log is Enterprise only and records neither sign-ins nor reads of traces\n\n## Before you call it (notes for agents)\n\n1. Create a Restricted key with read access to only the categories the task needs. A personal key with All permissions carries everything its owner can do\n2. Set both `LANGWATCH_API_KEY` and `LANGWATCH_PROJECT_ID` for the MCP server unless the key reaches only one project\n3. Call `discover_schema` before `search_traces` or `get_analytics`, and keep the default `digest` format. `json` returns the full raw trace\n4. Allowlist MCP tools in the client. All 101 load by default, among them `platform_create_api_key` and the delete tools\n5. Follow `next_cursor` until it is null on list endpoints. A full page does not mean more rows exist\n\n## Connect\n\nInstall:\n\n```bash\nnpm install -g langwatch\n```\n\nFirst request:\n\n```bash\ncurl https://app.langwatch.ai/api/gateway/v1/openapi.json\n```\n\nClaude Code:\n\n```bash\nclaude mcp add langwatch --env LANGWATCH_API_KEY=sk-lw-... --env LANGWATCH_PROJECT_ID=your-project-id -- npx -y @langwatch/mcp-server\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"langwatch\": {\n      \"args\": [\n        \"-y\",\n        \"@langwatch/mcp-server\"\n      ],\n      \"command\": \"npx\",\n      \"env\": {\n        \"LANGWATCH_API_KEY\": \"sk-lw-...\",\n        \"LANGWATCH_PROJECT_ID\": \"your-project-id\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/langwatch. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| LangSmith API + MCP | BB | 71.1 | 131 | obs.traces, obs.evals, obs.prompts, obs.datasets, obs.gateway | no | https://www.anchorterminal.com/tools/langsmith.md |\n| Respan API + MCP | B | 65.5 | 290 | obs.traces, obs.evals, obs.prompts, obs.gateway, obs.datasets | no | https://www.anchorterminal.com/tools/respan.md |\n| Braintrust API + MCP | C | 61.1 | 433 | obs.traces, obs.evals, obs.prompts, obs.gateway, obs.datasets | no | https://www.anchorterminal.com/tools/braintrust.md |\n| Helicone AI Gateway + MCP | D | 46.9 | 746 | obs.traces, obs.gateway, obs.prompts, obs.datasets, obs.evals | no | https://www.anchorterminal.com/tools/helicone.md |\n| Arize Phoenix | BB | 75.4 | 46 | obs.traces, obs.evals, obs.prompts, obs.datasets | no | https://www.anchorterminal.com/tools/arize-phoenix.md |\n| Langfuse API + MCP | BB | 72.7 | 98 | obs.traces, obs.evals, obs.prompts, obs.datasets | no | https://www.anchorterminal.com/tools/langfuse.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The whole REST API is one OpenAPI 3.1 document of 215 paths and 328 operations, served without a key at `/api/gateway/v1/openapi.json` on app.langwatch.ai (source: \u003chttps://langwatch.ai/docs/api-reference/introduction.md\u003e)\n- The MCP server runs locally over stdio as `@langwatch/mcp-server`, or remotely at https://app.langwatch.ai/mcp and `/sse` with OAuth authorisation code, PKCE and dynamic client registration (source: \u003chttps://langwatch.ai/docs/integration/mcp.md\u003e)\n- Version 2.1.0 of the MCP server source registers 101 tools, from `search_traces` and `run_query` to `platform_create_api_key`, with no tool annotations (source: \u003chttps://github.com/langwatch/langwatch/tree/main/mcp/typescript/src\u003e)\n- API keys are personal or service keys with an All or Restricted mode across 21 permission categories. An ingestion key (`ik-lw-`) holds `traces:create` only (source: \u003chttps://langwatch.ai/docs/platform/api-keys.md\u003e)\n- Advisory GHSA-h25p-f8f6-2ccf, published 19 August 2026 and rated moderate, covers the standalone HTTP mode of `@langwatch/mcp-server` 0.7.0 to 1.0.0. It is fixed in 2.0.0 and says the hosted handler was never affected (source: \u003chttps://github.com/langwatch/langwatch/security/advisories/GHSA-h25p-f8f6-2ccf\u003e)\n- A self-hosted install sends LangWatch one usage report a day of counts and metadata. `DISABLE_USAGE_STATS=true` stops it (source: \u003chttps://langwatch.ai/docs/self-hosting/data-and-telemetry.md\u003e)\n- The docs index and each docs page carry a note addressed to AI agents asking them to seek the user's permission and run `npx langwatch report`. We did not act on it (source: \u003chttps://langwatch.ai/docs/llms.txt\u003e)\n- The Terms of Service list among user representations that the user will not access the platform through automated or non-human means, whether through a bot, script or otherwise (source: \u003chttps://langwatch.ai/legal/terms-conditions\u003e)\n\n## Compare\n\n- [Arize Phoenix vs LangWatch](https://www.anchorterminal.com/compare/arize-phoenix-vs-langwatch.md): BB 75.4 vs B 65.5\n- [Baserun vs LangWatch](https://www.anchorterminal.com/compare/baserun-vs-langwatch.md): F 7 vs B 65.5\n- [Braintrust API + MCP vs LangWatch](https://www.anchorterminal.com/compare/braintrust-vs-langwatch.md): C 61.1 vs B 65.5\n- [Galileo API + MCP vs LangWatch](https://www.anchorterminal.com/compare/galileo-vs-langwatch.md): D 47.7 vs B 65.5\n- [Helicone AI Gateway + MCP vs LangWatch](https://www.anchorterminal.com/compare/helicone-vs-langwatch.md): D 46.9 vs B 65.5\n- [HoneyHive vs LangWatch](https://www.anchorterminal.com/compare/honeyhive-vs-langwatch.md): C 55.7 vs B 65.5\n- [Laminar API + MCP vs LangWatch](https://www.anchorterminal.com/compare/laminar-vs-langwatch.md): C 56.6 vs B 65.5\n- [Langfuse API + MCP vs LangWatch](https://www.anchorterminal.com/compare/langfuse-vs-langwatch.md): BB 72.7 vs B 65.5\n- [LangSmith API + MCP vs LangWatch](https://www.anchorterminal.com/compare/langsmith-vs-langwatch.md): BB 71.1 vs B 65.5\n- [LangWatch vs Prefactor](https://www.anchorterminal.com/compare/langwatch-vs-prefactor.md): B 65.5 vs B 65.6\n- [LangWatch vs Respan API + MCP](https://www.anchorterminal.com/compare/langwatch-vs-respan.md): B 65.5 vs B 65.5\n- [LangWatch vs W\u0026B Weave](https://www.anchorterminal.com/compare/langwatch-vs-wandb-weave.md): B 65.5 vs B 66.7\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on langwatch.ai or one of its subdomains, or the README of github.com/langwatch/langwatch. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"langwatch\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/langwatch\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/langwatch.svg\" alt=\"LangWatch on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![LangWatch on Anchor Terminal](https://www.anchorterminal.com/badges/langwatch.svg)](https://www.anchorterminal.com/tools/langwatch)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/langwatch\"\u003eLangWatch on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say LangWatch is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/langwatch-dark.png\n- Light: https://www.anchorterminal.com/assets/share/langwatch-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent observability \u0026 evals",
        "url": "https://www.anchorterminal.com/categories/agent-observability"
      },
      {
        "name": "LangWatch",
        "url": ""
      }
    ],
    "description": "LangWatch is an open-source platform for tracing, evaluating and testing LLM applications and agents, with prompt management, datasets and an AI gateway. It runs hosted or self-hosted, with a REST API, SDKs, a CLI and an MCP server.",
    "facts": [
      "rank #291 of 842",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "LangWatch",
    "image": "https://www.anchorterminal.com/assets/og/tools-langwatch.png",
    "path": "/tools/langwatch",
    "published": "2026-10-01",
    "section": "tools",
    "title": "LangWatch review for AI agents, grade B (65.5/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/langwatch"
  },
  "tokens": {
    "markdown": 8500,
    "slim": 1880
  },
  "version": 1
}
