Meteomatics Weather API

by Meteomatics AG HTTP API in Weather & climate data

Hosted

Meteomatics AG · meteomatics.com since 2011 · who's behind it

Meteomatics Weather API returns forecasts, current observations, history back to 1940 and climate scenarios for points, routes, grids and polygons. It is a REST API with a hosted MCP server in beta, sold by contract to businesses.

Good for Companies in energy, aviation, insurance and logistics that need many models, long history, polygon and route queries and an SLA, and will buy by contract.

Is this your product? Claim this listing or verify it

Assessment. A public OpenAPI file, a hosted MCP server whose nine tools are all marked read-only, a published SLA with compensation and ISO 27001 certification suit company use. Access needs a sales contract, with no public price, free tier or self-serve signup found, no status page, and REST calls that authenticate with a username and password.

Facts

Transport
HTTP
Endpoint
https://api.meteomatics.com
Auth
OAuth or key
Pricing
Paid · Paid
x402
No
Licence
Proprietary service under Meteomatics' general terms and conditions. The Python connector on GitHub is MIT
Tools exposed
9
Packages
pypi meteomatics
llms.txt
published
Last release
GitHub stars
56
PyPI / week
16k
Surface graded
The public REST API at https://api.meteomatics.com, with the hosted MCP server noted beside it
Request pattern
api.meteomatics.com/validdatetime/parameters/locations/format?optionals, by GET or POST. Locations are coordinates, lines, grids, polygons, postal codes or station identifiers
Endpoints
OpenAPI 3.0.0 file, 31 paths and 31 operations. Time series and grids, polygons, /find_station, /get_init_date, /get_time_range, lightning lists, isolines and isobands, fronts, jet streams, UK flood alerts, earthquakes, aviation bulletins, /user_stats, WMS, WFS and vector tile styles
MCP tools
get_weather_for_location, get_weather_for_locations, get_weather_for_polygon, get_weather_map, get_weather_map_legend, get_opmet, get_opmet_history, find_station, find_nearby_stations
Credentials
Username and password by email after a contract. HTTP Basic, or a 2-hour token from login.meteomatics.com. OAuth with dynamic client registration, PKCE and the weather:read scope on the MCP server
Limits
10 locations and 10 parameters a query (10,000 locations with the area option), 2,000 characters recommended on a GET, 300-second timeout. Query count by contract, shown at /user_stats_json. No request rate published
Errors
Plain-text messages with HTTP codes. 206 partial content, 400, 401, 402, 403, 404, 408, 413, 414, 429 (licence limits reached), 500, 501, 503, 504 and 505
Formats
JSON, CSV, XML, HTML, NetCDF, PNG, WebP and GeoTIFF, plus WMS, WFS and vector tiles
Data range
History back to 1940, current observations, forecasts and climate scenarios to 2100, per the vendor. /get_time_range returns the dates available for a model and parameter
Alerts and marine
Warning index parameters for frost, rain, snow, wind, fog and thunderstorms, UK flood alerts from Defra, national weather alert tiles, and marine parameters for waves, currents, tides, salinity and sea ice
SLA
Standard aims for 99 per cent a month with no compensation. Extended Support guarantees 99.5 per cent and Priority Support 99.9 per cent, compensated with 1 to 3 free months. Dated 7 May 2025
Connectors
Python meteomatics 4.0.0 on PyPI (29 April 2026, MIT, Python 3.9 or later). Repositories for R, Go, Java, C++, Kotlin and Julia, and guides for Excel, Power BI, Tableau, QGIS and ArcGIS
Certifications
ISO 27001 (announced 23 June 2026) and Cyber Essentials, per the information security page
Status
No status page found

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Hosted MCP server at https://mcp.meteomatics.com/mcp with nine tools, each annotated readOnlyHint true and destructiveHint false
  • Published SLA dated 7 May 2025 with 99.5 and 99.9 per cent uptime guarantees on the two paid support levels, compensated in free months
  • Public OpenAPI 3.0.0 file with 31 operations, plus llms.txt and llms-full.txt indexes of the site and docs
  • ISO 27001 certification announced 23 June 2026, Cyber Essentials, and a named security contact for vulnerability reports
  • One URL pattern covers history from 1940, forecasts and climate scenarios, in JSON, CSV, XML, NetCDF or image formats

Weaknesses

  • No public price, free tier or self-serve signup found. Credentials arrive by email after a sales conversation
  • No status page found. meteomatics.statuspage.io redirects to an inactive notice and the site links none
  • REST calls use HTTP Basic with the account username and password, and the two-hour token may travel as an access_token query parameter
  • No request rate is published. The query count is set by contract, and 429 carries no documented Retry-After
  • No API changelog or deprecation policy found. Product update posts appear every two to three months
  • The MCP server is described as beta in the vendor's 4 May 2026 guide and isn't in the official MCP registry

Before you call it notes for agents

  1. Ask the account owner for credentials first. There is no signup, and both the REST API and the MCP server need a Meteomatics account with API access
  2. Build REST URLs as validdatetime/parameters/location/format, for example 2026-10-08T00:00:00Z/t_2m:C/52.52,13.40/json. Parameter names carry their unit after a colon
  3. Keep each query to 10 locations and 10 parameters unless the contract says otherwise, and use POST when a GET URL passes 2,000 characters
  4. Send credentials or the token in the Authorization header. Avoid the documented access_token query parameter, which puts the token in URLs and logs
  5. Read /user_stats_json before a large job. It reports queries sent and the contract's limits, and 429 means a limit is spent
  6. Treat reserved values such as -888 and -999 as invalid or missing data, and shrink the request when a 408 arrives after the 300-second timeout

Who's behind it provenance 68/100

  • Legal entity namedMeteomatics AG20/20
  • Domain agemeteomatics.com, registered 2011-09-21 (15 years)15/15
  • Endpoint on the vendor's domainapi.meteomatics.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects9.1/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagenot found0/10
  • Changelognot found0/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 6 of 7

TL;DR Gives no date. States 6 of the 7 things a reader expects. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts
All disputes arising out of or in connection to the contractual relationship between Meteomatics and the Customer shall be exclusive jurisdiction of the courts at the registered seat of Meteomatics.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the fees paid in the 12 months before the claim
…relationship between Meteomatics and the Customer (thus, including tort or any other legal basis) shall not exceed the lesser of (i) the aggregate amount paid or payable by the Customer to Meteomatics in the last 12 months or (ii) the yearly value of the Agreement, as of the date of the events or circumstances giving…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If the invoice will not be paid by the Customer within 10 calendar days, Meteomatics has the right to suspend its services until the outstanding amount will be paid by the Customer in full incl.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Changes are posted, with no other notice named
However, Meteomatics may amend these GTCs at any time by posting them at Meteomatics designated website, currently located at meteomatics.com, and all such amended terms and conditions shall be deemed effective and binding as of the new effective date specified in the amended terms and conditions.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
3.2.1 The Customer shall not undertake any of the following actions with respect to the Services and/or Documentation of Meteomatics:

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
”Agreement”, means the Offer, these GTC, the Service Level Agreement, Documentation and/or any other written or electronic agreement between Meteomatics and the Customer for the use of the Services and/or Equipment provided by Meteomatics and any other document that is governing the contractual relationship between Me…

Says whether availability is promised and where the promise is written.

The agreement renews automatically for further terms unless the customer gives notice of termination at least three months before the current term ends.
15.2 The Initial Term shall renew automatically for subsequent terms (each referred to as the ‘’Renewal Term’’) unless the Customer gives a notice of termination to Meteomatics not later than 3 (in words: three) months before the expiration of the Initial Period or Renewal Term.

Noted by a second reader on 2026-10-08.

Meteomatics may adjust fees each year and at the start of each renewal term.
8.5 Meteomatics has the right to adjust the Fees annually and/or at the beginning of each Renewal Term.

Noted by a second reader on 2026-10-08.

The customer must use the services only for internal business purposes or the purpose stated in the agreement.
9.1.2 use the Services of Meteomatics solely for internal business purpose or the purpose indicated in the Agreement;

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,706 words

Privacy policy gives no date, states 6 of 8

TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
…and Meteomatics AS (companies of the Meteomatics group, hereinafter Meteomatics, we or us), explain how we collect and otherwise process personal data when you visit our website https://www.meteomatics.com, purchase our products or services, when we enter into or conclude a business transaction with you as a business…

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 3 months
We generally retain technical data for 3 months, after which they get either deleted or anonymised.

Says when data sent to the service is deleted.

Says who else receives the data
Website, cookies, third-party technologies and other business service providers used

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
If you have given us your consent to process your personal data for specific purposes (for example, when you register to receive newsletters or carry out a background check), we will process your personal data within the scope of and based on this consent, unless we have another legal basis and we require one (if the…

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact
In principle, we process personal data that we receive from our customers and other business partners (in particular suppliers) as part of our business relationship with them and other persons involved or that we collect from the users when operating our websites, services (e.g.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
…the recipient to comply with the applicable data protection laws and regulations (we use the revised standard contractual clauses of the European Commission, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?), unless they already are subject to a legally recognised set of rules to ensure data protection…

The countries data goes to and the safeguard used.

Meteomatics states it does not use personal data to train or improve general-purpose AI models unless the data subject expressly authorises it.
Where we use artificial intelligence systems in connection with our services or internal operations, we do not use personal data to train, retrain, fine-tune, or otherwise improve general-purpose artificial intelligence models unless expressly authorised by the relevant data subject.

Noted by a second reader on 2026-10-08.

The privacy notice carries SMS terms under which the customer must keep records of each user's consent to text messages and hand them to the vendor on request.
(e) that it will maintain records of all User consent and revocation and will provide such records to the Service Provider promptly upon request.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 9,468 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The imprint names Meteomatics AG, Unterstrasse 12, 9000 St. Gallen, Switzerland, company number CHE-375.414.829, with group companies in England, Norway, Germany and the United States.

The terms are the General Terms and Conditions for Enterprise Customers of Meteomatics AG, dated August 2026. Separate versions exist for Meteomatics GmbH, Meteomatics Limited and Meteomatics Inc.

The privacy notice (latest update 20 August 2026) covers the group, names the Weather API and names Meteomatics AG as controller. A Data Processing Agreement is published beside it.

The REST API answers at api.meteomatics.com, tokens at login.meteomatics.com and the MCP server at mcp.meteomatics.com.

No status page was found. meteomatics.statuspage.io redirects to an inactive notice, and status.meteomatics.com didn't connect for us.

No API changelog was found. Product updates are posted as news articles at www.meteomatics.com/en/news/.

www.meteomatics.com, mcp.meteomatics.com and login.meteomatics.com return 404 for /.well-known/security.txt. The information security page gives a contact address for vulnerability reports.

RDAP gives a registration date of 2011-09-21 for meteomatics.com.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:12 UTC

Right nowUpHTTP 200 · 222 ms · under a minute ago
Uptime 24h100.0%21 probes
Uptime 30 days100.0%21 probes
p50 24h241 msget
p95 24h447 msopen endpoint

Probed every five minutes at https://api.meteomatics.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/meteomatics.json

Notable

  • The hosted MCP server at https://mcp.meteomatics.com/mcp lists nine tools for point, multi-point and polygon time series, WMS map images and legends, aviation reports and station search, all annotated read-only source
  • The vendor's guide of 4 May 2026 calls the MCP server a beta and says not every API function is supported through it source
  • Each query is limited to 10 locations and 10 parameters, or 10,000 locations with the area option, and is cut off after 5 minutes with a 408. The query count is set by contract source
  • The Service Level Agreement of 7 May 2025 has three levels, a 99 per cent monthly aim with no compensation, and 99.5 and 99.9 per cent guarantees compensated with 1 to 3 free months source
  • The general terms limit use to internal business purposes or the purpose in the agreement, and bar passing the services or documentation to third parties without written consent source
  • Meteomatics says the API draws on more than 110 models and 1,800 parameters, with history back to 1940, climate scenarios to 2100 and downscaling to 90 metres source
  • ISO 27001 certification was announced on 23 June 2026, with the certificate published, alongside Cyber Essentials source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 6.8
Graded as a hosted service. No status page was found. The site and legal pages link none, meteomatics.statuspage.io redirects to an inactive notice, and status.meteomatics.com didn't connect for us (0), so there is no incident record to read (0). The docs give per-query limits with numbers, 10 locations and 10 parameters a query, 2,000 characters on a GET and a 5-minute cut-off, and say the query count is set by contract and readable at /user_stats_json. No request rate is published (8 of 15). 429 is documented as licence limits reached and 408 comes with advice to shrink the query. No Retry-After or backoff guidance was found, and every call is a read (6 of 15). The Service Level Agreement of 7 May 2025 aims for 99 per cent a month on Standard and guarantees 99.5 and 99.9 per cent on Extended and Priority Support, compensated in free months (10). The REST API has been online since May 2015 per the docs. The MCP server is described as beta in the vendor's 4 May 2026 guide (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 11.5
OpenAPI 3.0.0 file at swagger-ui.meteomatics.com/meteomatics_swagger_definition.yaml with 31 paths and 31 operations. The docs say it is documentation only and doesn't list every weather parameter. The MCP server gives JSON Schema inputs for all nine tools (22 of 25). llms.txt and llms-full.txt at www.meteomatics.com index the site and the API docs (10). MCP tool descriptions say when to use each tool and what not to put in a field, and the docs explain each URL segment and option (15 of 20). The OpenAPI file has 43 enums, but the core request is a URL grammar of free strings, more than 1,800 parameter names aren't enumerated, and MCP inputs such as parameters, aggregation and crs are plain strings with allowed values in prose (8 of 15). Example URLs and responses on every docs page, 149 examples in the OpenAPI file and a table of 17 HTTP codes, with errors returned as plain text (11 of 15). No API version in the path and no API changelog. JSON responses carry version 3.0 and product update posts appear every two to three months (5 of 15).
Agent ergonomics 13%16.2 13.0
The parameter list, time range, step and format in the URL size each response, and the MCP server has nine tools in about 15 KB of definitions (23 of 25). No pagination. Output is bounded by the time range and interval, 10 locations and 10 parameters a query, a timeout option and a choice of JSON, CSV, XML, NetCDF or images (13 of 20). HTTP codes with a plain-text message that says which part of the URL is wrong or what data is available, 206 for partial content, and no machine-readable error key (12 of 20). Every REST call is a read, including the POST form, and all nine MCP tools carry readOnlyHint true and destructiveHint false (20). The default source is the vendor's mix model. A call needs four URL segments and parameter names with units. The Python connector is on PyPI at 4.0.0, and connectors for R, Go, Java, C++, Kotlin and Julia are on GitHub (12 of 15).
Security & auth 14%17.5 9.4
REST calls use HTTP Basic with a username and password sent by email, or a token from login.meteomatics.com that lasts 2 hours and is documented as an access_token query parameter. No key rotation or separate keys were found in the docs. The MCP server uses OAuth with dynamic client registration, the authorisation code grant with PKCE (S256), refresh tokens and one scope, weather:read (12 of 30, after the 10-point deduction for a secret in the URL). The whole API is read-only and the single OAuth scope is a read scope (15 of 20). Responses are mostly numbers. Aviation bulletins and official alerts carry third-party text, and the MCP guide tells users to check model output, with no guidance on untrusted content (9 of 15). /user_stats and /user_stats_json report query counts against contract limits, and the privacy notice says usage logs are kept for 3 months. No per-call log for the customer was found (5 of 15). ISO 27001 certification announced on 23 June 2026 with the certificate published, Cyber Essentials, and a security contact for vulnerability reports. No security.txt (404) and no bug bounty (13 of 20).
Payments & pricing 10%12.5 0.0
No x402, MPP or L402 in the docs or the OpenAPI file. The error table lists 402, with no payment protocol behind it (0). The pricing page says prices are based on usage and gives no figure, only a form to talk to sales (0). No free tier or trial is on the site. The general terms let Meteomatics grant a trial through an individual offer (0). A person talks to sales and receives a username and password by email. The MCP server registers OAuth clients by API but still needs that account (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 3.7
The newest dated product update is 24 August 2026 (an icing warning parameter and radar sources for Australia, Turkey and Japan), 45 days before this check (20 of 30). That is one dated entry in the last 90 days, not three (0). Product update posts on 26 March, 15 June and 24 August 2026, support by email around the clock per the SLA, and a pull request merged on the Python connector on 15 June 2026 (9 of 15). The Python connector reached 4.0.0 on PyPI on 29 April 2026 and needs Python 3.9 or later. The MCP server isn't in the official registry (10 of 15). The connector repository has no CI workflow, tests or changelog file (3 of 10).
Transparency & trusteditorial 50, provenance 68 7%8.8 5.2
Closed service under general terms for enterprise customers dated August 2026, published per group company, with Swiss law and the courts at the vendor's seat. The Python connector is MIT (15 of 30). The privacy notice, last updated 20 August 2026, names the Weather API, says technical data and usage logs are kept for 3 months, and names Meteomatics AG as controller. A published Data Processing Agreement covers breach notice, deletion or return at the end of the contract and 30 days' notice of a new sub-processor (22 of 30). No deprecation policy was found. The terms let the vendor change them by posting a new version, and a commit marked as breaking on the Python connector, dated 29 April 2026, deprecates the ecmwf-ens-cluster source with no notice period stated (3 of 20). The privacy notice names nine services with their countries, among them HubSpot, Stripe, Gong and OpenAI. No hosting provider or data location for the API is named (10 of 20).
Negative events≤15None recorded0
Total49.6 · D

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Meteomatics Weather API, or have the agent fetch /fixes/meteomatics.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Meteomatics Weather API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/meteomatics, the October 2026 research run, assessed 8 October 2026. Grade D, 49.6 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Meteomatics Weather API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 34 out of 100, up to 13.2 more on the total

Why it scored 34: Graded as a hosted service. No status page was found. The site and legal pages link none, meteomatics.statuspage.io redirects to an inactive notice, and status.meteomatics.com didn't connect for us (0), so there is no incident record to read (0). The docs give per-query limits with numbers, 10 locations and 10 parameters a query, 2,000 characters on a GET and a 5-minute cut-off, and say the query count is set by contract and readable at `/user_stats_json`. No request rate is published (8 of 15). 429 is documented as licence limits reached and 408 comes with advice to shrink the query. No `Retry-After` or backoff guidance was found, and every call is a read (6 of 15). The Service Level Agreement of 7 May 2025 aims for 99 per cent a month on Standard and guarantees 99.5 and 99.9 per cent on Extended and Priority Support, compensated in free months (10). The REST API has been online since May 2015 per the docs. The MCP server is described as beta in the vendor's 4 May 2026 guide (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 0 out of 100, up to 12.5 more on the total

Why it scored 0: No x402, MPP or L402 in the docs or the OpenAPI file. The error table lists 402, with no payment protocol behind it (0). The pricing page says prices are based on usage and gives no figure, only a form to talk to sales (0). No free tier or trial is on the site. The general terms let Meteomatics grant a trial through an individual offer (0). A person talks to sales and receives a username and password by email. The MCP server registers OAuth clients by API but still needs that account (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Security & auth, 54 out of 100, up to 8.1 more on the total

Why it scored 54: REST calls use HTTP Basic with a username and password sent by email, or a token from login.meteomatics.com that lasts 2 hours and is documented as an `access_token` query parameter. No key rotation or separate keys were found in the docs. The MCP server uses OAuth with dynamic client registration, the authorisation code grant with PKCE (S256), refresh tokens and one scope, `weather:read` (12 of 30, after the 10-point deduction for a secret in the URL). The whole API is read-only and the single OAuth scope is a read scope (15 of 20). Responses are mostly numbers. Aviation bulletins and official alerts carry third-party text, and the MCP guide tells users to check model output, with no guidance on untrusted content (9 of 15). `/user_stats` and `/user_stats_json` report query counts against contract limits, and the privacy notice says usage logs are kept for 3 months. No per-call log for the customer was found (5 of 15). ISO 27001 certification announced on 23 June 2026 with the certificate published, Cyber Essentials, and a security contact for vulnerability reports. No security.txt (404) and no bug bounty (13 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Maintenance & community, 42 out of 100, up to 5.1 more on the total

Why it scored 42: The newest dated product update is 24 August 2026 (an icing warning parameter and radar sources for Australia, Turkey and Japan), 45 days before this check (20 of 30). That is one dated entry in the last 90 days, not three (0). Product update posts on 26 March, 15 June and 24 August 2026, support by email around the clock per the SLA, and a pull request merged on the Python connector on 15 June 2026 (9 of 15). The Python connector reached 4.0.0 on PyPI on 29 April 2026 and needs Python 3.9 or later. The MCP server isn't in the official registry (10 of 15). The connector repository has no CI workflow, tests or changelog file (3 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 5. Schema & documentation, 71 out of 100, up to 4.7 more on the total

Why it scored 71: OpenAPI 3.0.0 file at swagger-ui.meteomatics.com/meteomatics_swagger_definition.yaml with 31 paths and 31 operations. The docs say it is documentation only and doesn't list every weather parameter. The MCP server gives JSON Schema inputs for all nine tools (22 of 25). `llms.txt` and `llms-full.txt` at www.meteomatics.com index the site and the API docs (10). MCP tool descriptions say when to use each tool and what not to put in a field, and the docs explain each URL segment and option (15 of 20). The OpenAPI file has 43 enums, but the core request is a URL grammar of free strings, more than 1,800 parameter names aren't enumerated, and MCP inputs such as `parameters`, `aggregation` and `crs` are plain strings with allowed values in prose (8 of 15). Example URLs and responses on every docs page, 149 examples in the OpenAPI file and a table of 17 HTTP codes, with errors returned as plain text (11 of 15). No API version in the path and no API changelog. JSON responses carry `version` 3.0 and product update posts appear every two to three months (5 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 59 out of 100, up to 3.6 more on the total

Made of editorial 50, provenance 68.

Why it scored 59: Closed service under general terms for enterprise customers dated August 2026, published per group company, with Swiss law and the courts at the vendor's seat. The Python connector is MIT (15 of 30). The privacy notice, last updated 20 August 2026, names the Weather API, says technical data and usage logs are kept for 3 months, and names Meteomatics AG as controller. A published Data Processing Agreement covers breach notice, deletion or return at the end of the contract and 30 days' notice of a new sub-processor (22 of 30). No deprecation policy was found. The terms let the vendor change them by posting a new version, and a commit marked as breaking on the Python connector, dated 29 April 2026, deprecates the `ecmwf-ens-cluster` source with no notice period stated (3 of 20). The privacy notice names nine services with their countries, among them HubSpot, Stripe, Gong and OpenAI. No hosting provider or data location for the API is named (10 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects (9.1 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- Status page: not found (0 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)

## 7. Agent ergonomics, 80 out of 100, up to 3.3 more on the total

Why it scored 80: The parameter list, time range, step and format in the URL size each response, and the MCP server has nine tools in about 15 KB of definitions (23 of 25). No pagination. Output is bounded by the time range and interval, 10 locations and 10 parameters a query, a `timeout` option and a choice of JSON, CSV, XML, NetCDF or images (13 of 20). HTTP codes with a plain-text message that says which part of the URL is wrong or what data is available, 206 for partial content, and no machine-readable error key (12 of 20). Every REST call is a read, including the POST form, and all nine MCP tools carry `readOnlyHint` true and `destructiveHint` false (20). The default source is the vendor's mix model. A call needs four URL segments and parameter names with units. The Python connector is on PyPI at 4.0.0, and connectors for R, Go, Java, C++, Kotlin and Julia are on GitHub (12 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: whether a status page exists at status.meteomatics.com. The address didn't connect for us, the site links no status page, and meteomatics.statuspage.io redirects to an inactive notice
- unchecked: authenticated behaviour, including response headers on 429, error bodies and the shape of `/user_stats_json`. We had no credentials and called no data endpoint or MCP tool
- unchecked: open issues and pull requests on the connector repositories. The GitHub API refused us for its rate limit, so we read the cloned history only
- Whether a trial or test account is still granted. The terms allow a trial through an individual offer and the Python connector has an example named `12_test_account_options.py`, but the site shows none
- The MCP server answered `initialize` and `tools/list` without a token on 8 October 2026. The docs page doesn't say it is beta, while the 4 May 2026 guide does
- The OpenAPI file lists http://api.meteomatics.com as a second server and one docs example uses http. We didn't test whether plain HTTP answers
- The general terms are published per group company. We used the Meteomatics AG version, dated August 2026, and didn't compare the GmbH, Limited and Inc. versions
- The lead was right. The MCP entry among the data connectors is a hosted server with OAuth, and credentials are issued after a sales conversation

## Weaknesses

- No public price, free tier or self-serve signup found. Credentials arrive by email after a sales conversation
- No status page found. meteomatics.statuspage.io redirects to an inactive notice and the site links none
- REST calls use HTTP Basic with the account username and password, and the two-hour token may travel as an `access_token` query parameter
- No request rate is published. The query count is set by contract, and 429 carries no documented `Retry-After`
- No API changelog or deprecation policy found. Product update posts appear every two to three months
- The MCP server is described as beta in the vendor's 4 May 2026 guide and isn't in the official MCP registry

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Ask the account owner for credentials first. There is no signup, and both the REST API and the MCP server need a Meteomatics account with API access
- Build REST URLs as validdatetime/parameters/location/format, for example `2026-10-08T00:00:00Z/t_2m:C/52.52,13.40/json`. Parameter names carry their unit after a colon
- Keep each query to 10 locations and 10 parameters unless the contract says otherwise, and use POST when a GET URL passes 2,000 characters
- Send credentials or the token in the `Authorization` header. Avoid the documented `access_token` query parameter, which puts the token in URLs and logs
- Read `/user_stats_json` before a large job. It reports queries sent and the contract's limits, and 429 means a limit is spent
- Treat reserved values such as -888 and -999 as invalid or missing data, and shrink the request when a 408 arrives after the 300-second timeout

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: whether a status page exists at status.meteomatics.com. The address didn't connect for us, the site links no status page, and meteomatics.statuspage.io redirects to an inactive notice
  • unchecked: authenticated behaviour, including response headers on 429, error bodies and the shape of /user_stats_json. We had no credentials and called no data endpoint or MCP tool
  • unchecked: open issues and pull requests on the connector repositories. The GitHub API refused us for its rate limit, so we read the cloned history only
  • Whether a trial or test account is still granted. The terms allow a trial through an individual offer and the Python connector has an example named 12_test_account_options.py, but the site shows none
  • The MCP server answered initialize and tools/list without a token on 8 October 2026. The docs page doesn't say it is beta, while the 4 May 2026 guide does
  • The OpenAPI file lists http://api.meteomatics.com as a second server and one docs example uses http. We didn't test whether plain HTTP answers
  • The general terms are published per group company. We used the Meteomatics AG version, dated August 2026, and didn't compare the GmbH, Limited and Inc. versions
  • The lead was right. The MCP entry among the data connectors is a hosted server with OAuth, and credentials are issued after a sales conversation

Sources 30

  1. getting started meteomatics.com · seen 2026-10-08
  2. docs and site index (llms.txt) meteomatics.com · seen 2026-10-08
  3. OpenAPI file swagger-ui.meteomatics.com · seen 2026-10-08
  4. Swagger page meteomatics.com · seen 2026-10-08
  5. MCP server docs meteomatics.com · seen 2026-10-08
  6. MCP OAuth metadata mcp.meteomatics.com · seen 2026-10-08
  7. MCP endpoint (initialize and tools/list) mcp.meteomatics.com · seen 2026-10-08
  8. MCP guide, 4 May 2026 meteomatics.com · seen 2026-10-08
  9. token authentication meteomatics.com · seen 2026-10-08
  10. error codes meteomatics.com · seen 2026-10-08
  11. accounting and limits meteomatics.com · seen 2026-10-08
  12. usage statistics and meta requests meteomatics.com · seen 2026-10-08
  13. optional fields meteomatics.com · seen 2026-10-08
  14. FAQ meteomatics.com · seen 2026-10-08
  15. pricing meteomatics.com · seen 2026-10-08
  16. product page meteomatics.com · seen 2026-10-08
  17. Service Level Agreement meteomatics.com · seen 2026-10-08
  18. general terms, Meteomatics AG meteomatics.com · seen 2026-10-08
  19. privacy notice meteomatics.com · seen 2026-10-08
  20. Data Processing Agreement meteomatics.com · seen 2026-10-08
  21. information security meteomatics.com · seen 2026-10-08
  22. imprint meteomatics.com · seen 2026-10-08
  23. news and product updates meteomatics.com · seen 2026-10-08
  24. product update, August 2026 meteomatics.com · seen 2026-10-08
  25. Python connector repository github.com · seen 2026-10-08
  26. Python connector on PyPI pypi.org · seen 2026-10-08
  27. MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  28. inactive Statuspage address meteomatics.statuspage.io · seen 2026-10-08
  29. security.txt (404) meteomatics.com · seen 2026-10-08
  30. domain registration (RDAP) rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid No public price. The pricing page says prices are based on usage and package and leads to a sales form. No free tier, sandbox or self-serve trial is on the site, so an agent can't start without a contract. The general terms allow a trial through an individual offer, fees are non-refundable and may be adjusted yearly, and the term renews unless ended 3 months ahead (https://www.meteomatics.com/en/pricing/, checked 2026-10-08).

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/meteomatics.xml, or this listing's score history at history.json.

Connect

Install

pip install meteomatics

First request

curl -u USERNAME:PASSWORD 'https://api.meteomatics.com/2026-10-08T00:00:00Z/t_2m:C/52.520551,13.461804/json'

MCP client configuration

{
  "name": "meteomatics",
  "type": "url",
  "url": "https://mcp.meteomatics.com/mcp"
}

Through letme picks today, calling later

GET https://letme.dev/meteomatics

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Xweather Weather API Vaisala OyjB67.1weather.current weather.forecast weather.historical weather.alerts weather.marineno
WeatherAPI.com WeatherAPI.com (Zoomash Ltd)B65.3weather.current weather.forecast weather.historical weather.alerts weather.marineno
meteoblue Weather API meteoblue AGC61.7weather.current weather.forecast weather.historical weather.alerts weather.marineno
The Weather Company Data APIs The Weather Company, LLCD52.6weather.current weather.forecast weather.historical weather.alerts weather.marineno
Tomorrow.io Weather API The Tomorrow Companies Inc.D51.4weather.current weather.forecast weather.historical weather.alerts weather.marineno
Google Weather API (Maps Platform) GoogleB66.8weather.current weather.forecast weather.historical weather.alertsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Meteomatics Weather API on Anchor Terminal, D, 49.6/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/meteomatics"><img src="https://www.anchorterminal.com/badges/meteomatics.svg" alt="Meteomatics Weather API on Anchor Terminal" height="20"></a>
    [![Meteomatics Weather API on Anchor Terminal](https://www.anchorterminal.com/badges/meteomatics.svg)](https://www.anchorterminal.com/tools/meteomatics)

    It counts on a page on meteomatics.com or one of its subdomains, or the README of github.com/meteomatics/python-connector-api.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "meteomatics", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.