NocoDB
by NocoDB Inc HTTP API in Spreadsheets & operational tables
Hosted Agent-ready
NocoDB Inc · nocodb.com since 2021 · status page · who's behind it
NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth.
Good for Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.
Is this your product? Claim this listing or verify it
Assessment. API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://app.nocodb.com- Auth
- OAuth or key
- Pricing
- Freemium · $12 / seat-mo
- x402
- No
- Licence
- Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service
- Tools exposed
- 199
- Packages
npmnocodb-sdk- Source
- github.com/nocodb/nocodb
- llms.txt
- published
- Last release
- GitHub stars
- 65k
- npm / week
- 6.3k
- Surfaces graded
- NocoDB Cloud. The v3 REST API at https://app.nocodb.com/api/v3 and the built-in MCP server at https://app.nocodb.com/mcp. The self-hosted Community Edition has the same REST API and a 13-tool MCP server
- Free tier
- Free plan, no card required per the pricing page. 3 editor seats, 1,000 records, 1 GB storage, 1,000 API calls a month, 100 automation runs
- Rate limits
- 5 requests a second per user on all plans, shared by that user's tokens. A 429 carries Retry-After per the OpenAPI file, and the docs say to wait 30 seconds (vendor's figures)
- Monthly API calls
- 1,000 on Free, 100,000 on Plus, 1,000,000 on Business, 5,000,000 on Scale, unlimited on Enterprise. Over a limit, a 2-week grace period applies before access may be restricted
- Batch size
- 10 records per REST create, update or upsert by default. MCP record tools take up to 100 records a call, and
queryRecordsreturns up to 200 a page - Auth and scopes
- Fine-grained API tokens (
nc_pat_prefix) with eight categories (Records, Comments, Tables, Fields, Views, Webhooks, Base, Users) at Read or Read and write, chosen bases, and expiry. OAuth authorisation code grant with PKCE (S256), refresh tokens, revocation and dynamic client registration for MCP clients - Read and write
- Records (list, get, create, update, upsert, delete, count), links, attachment upload, tables, fields, views, filters, sorts, webhooks, members, scripts, dashboards and workflows in the v3 API
- Filtering
wherein NocoDB's own syntax,fields,sort,viewId,pageandpageSizeon list records, withnextandprevpage URLs in the response- MCP server
- Built into the product, streamable HTTP. 199 tools on NocoDB Cloud per the 2026.09.1 changelog (llms.txt says 149). Per-connection allowlist by section. Token in
x-api-keyorxc-mcp-token, or OAuth at https://app.nocodb.com/mcp - Errors
- v3 errors return
{error, message}with optionaldetails, and arequestIdmatching thex-request-idheader outside the Community Edition. Some older paths return a baremsg - SDKs
- nocodb-sdk 0.301.3 on npm (JavaScript and TypeScript), under the Sustainable Use License. The
nocodbpackage on PyPI is community-built - Audit
- Workspace audit logs with user, time, base, event, IP address and JSON payload, on the Scale plan and above. Per-record change history. The MCP tools can read both
- Status and SLA
- status.nocodb.com (Kener) with two components and 90-day availability. 99.9 per cent monthly uptime commitment for Enterprise plans
- Sub-processors
- 16 listed with countries, 15 in the USA and one in Germany. AWS for infrastructure. Anthropic, OpenAI and Braintrust only for customers using NocoAI
- Self-hosting
- Docker image nocodb/nocodb, free for internal use under the Sustainable Use License. Rate limits are set by environment variables. Telemetry is on unless
NC_DISABLE_TELEis set
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Fine-grained API tokens carry eight permission categories at Read or Read and write, a list of bases, an expiry and an on-off switch
- An MCP connection lists only the tools its owner allowed, by section at Read, Read and write, or Read, write and delete
- Public OpenAPI 3.1 file for the v3 REST API with 114 operations, plus llms.txt and a Markdown copy of every docs page
- The MCP record tools in the source set
readOnlyHintanddestructiveHint, anddeleteRecordsis marked destructive - status.nocodb.com lists no incident from July to October 2026 and shows 99.9907 per cent for the application over 90 days
Weaknesses
- 5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429
- REST create, update and upsert calls take 10 records each by default
- The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan
- The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved
- No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry
Before you call it notes for agents
- Create a fine-grained token limited to the bases and categories the task needs. Send it as
xc-tokenor as a Bearer token - Stay under 5 requests a second across all tokens of one user. After a 429, honour
Retry-Afteror wait 30 seconds - Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records
- Write date filters with a sub-operator, such as
(due_date,eq,exactDate,2026-06-01), and put no space after~andor~or - Use
/records/upsertwith a merge key so a repeated write updates the record instead of adding a duplicate
Who's behind it provenance 86/100
- Legal entity namedNocoDB Inc (doing business as NocoDB)20/20
- Domain agenocodb.com, registered 2021-04-14 (5 years)11/15
- Endpoint on the vendor's domainapp.nocodb.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects10/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.nocodb.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2025-10-14, states 7 of 7, 2 to know
TL;DR Dated 2025-10-14. States all 7 things a reader expects. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.
Says access can be ended without notice or for any reason
We may permanently or temporarily terminate or suspend your access to our Services without notice or liability, without cause or for any reason, including if in our sole discretion you violate any provision of these Terms.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
…OPT OUT PURSUANT TO THE INSTRUCTIONS IN SECTION [14.2](#142-arbitration), THE EXCLUSIVE USE OF FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS ONLY TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS, COLLECTIVE, PRIVATE ATTORNEY GENERAL OR REPRESENTATIVE ACTIONS OR PROCEEDINGS.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2025-10-14
Last updated: 2025-10-14
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
These Terms will be governed by the internal substantive laws of the State of California, without respect to its conflict of laws principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
IN NO EVENT WILL WE OR OUR AFFILIATES, AGENTS, SUPPLIERS, OR LICENSORS (OR OUR OR THEIR EMPLOYEES, CONTRACTORS, AGENTS, OFFICERS, OR DIRECTORS) BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS IN AN AMOUNT EXCEEDING THE AMOUNT OF FEES YOU PAID TO US HEREUNDER DURING THE…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
* (iv) your individual right to access and use our Services may be suspended or terminated (and ownership and administration of your NocoDB Account (defined below) may be transferred) if you cease to be associated with, or cease to use an email address associated with, owned by, or provisioned by, that Organization
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
Any change to a Subscription Plan's pricing or payment terms will become effective in the billing cycle following notice of such change to you as provided in these Terms.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
* (ii) you represent and warrant that you have the authority to bind that Organization to these Terms (and if you do not have the authority, you may not access or use our Services)
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
**TRIAL FEATURES ARE PROVIDED TO YOU FOR TESTING PURPOSES ONLY, ON AN "AS IS" BASIS, WITHOUT ANY WARRANTY, LIABILITY, INDEMNITY, OR PERFORMANCE OBLIGATIONS.** Trial Features are not subject to any service level agreements or support commitments.
Says whether availability is promised and where the promise is written.
The customer grants NocoDB an irrevocable, transferable and sublicensable licence to access, use, copy, store, modify and display its content for the purposes the clause lists.
us an irrevocable, transferable, sublicensable (through multiple tiers), fully paid, royalty-free, and worldwide right and license to access, use, copy, store, modify, and display Your Content solely:
Noted by a second reader on 2026-10-08.
Subscription plans renew automatically for terms equal to the original term, at the price that applies on the renewal date, until the customer cancels.
Unless and until canceled by you, all Subscription Plans will automatically renew for renewal terms equal in length to the original Subscription Term, at the applicable price as of the renewal date.
Noted by a second reader on 2026-10-08.
NocoDB may name the customer in promotional materials and says it will stop on request.
We may identify you as our customer in our promotional materials. We will promptly stop doing so upon your request, which you may send by emailing [legal@nocodb.com](mailto:legal@nocodb.com).
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 8,206 words
Privacy policy dated 2026-03-20, states 8 of 8
TL;DR Dated 2026-03-20. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-03-20
Last updated: 2026-03-20
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Read NocoDB’s Privacy Policy to understand how we collect, use, store, and protect your personal data when you use our services.
The basic statement a privacy policy exists to make.
Says how long data is kept
We store your personal information for no longer than necessary for the purposes for which it was collected, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.
Says when data sent to the service is deleted.
Says who else receives the data
If you create your account using a service provided by a third party such as Google or Apple, or a single-sign-on service provided by a third party such as Okta, we may collect Customer Information about you from the third-party service (such as your username or user ID associated with that third-party service).
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell or share the personal information of consumers we know to be less than 16 years of age.
A plain statement either way.
Says what rights people have over their data
**The Right to Know** any or all of the following information relating to your personal information we have collected and disclosed in the last 12 months, upon verification of your identity:
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@nocodb.com
For instructions on how to permanently delete Content from your NocoDB Account, please contact us at [privacy@nocodb.com](mailto:privacy@nocodb.com).
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
When required by law, we will ensure that we rely on an appropriate legal mechanism for the transfer, such as your consent, standard contractual clauses (or their equivalent), or adequacy decisions.
The countries data goes to and the safeguard used.
Information is disclosed to AI observability and quality assurance providers for NocoAI, and this may include conversation content, inputs and outputs.
With AI observability and quality assurance providers who help us monitor, trace, evaluate, and improve the performance and quality of our AI-powered features (such as NocoAI), which may include the processing of conversation content, inputs, and outputs
Noted by a second reader on 2026-10-08.
Deleted content may be kept in archived or backup copies so that revision history and base snapshots keep working.
Content you delete (including Content containing personal information) may be retained in archived or backup copies in order to enable you to use certain features like revision history and base snapshots.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 4,764 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service (last updated 14 October 2025) and the privacy policy (last updated 5 August 2025) name NocoDB Inc, doing business as NocoDB, and cover the website, the hosted services and the APIs. No postal address was found in the parts we read.
The REST API and the MCP server answer at app.nocodb.com, a nocodb.com subdomain. A self-hosted instance answers on the owner's own domain.
nocodb.com/.well-known/security.txt, nocodb.com/security.txt and app.nocodb.com/.well-known/security.txt return 404. SECURITY.md in the repository sends reports to security@nocodb.com.
RDAP for nocodb.com gives a registration date of 2021-04-14.
Organisations on an order form are governed by the Master Subscription Agreement (last updated 14 October 2025), which states SOC 2 Type II compliance with the report on request. The Service Level Agreement (last updated 6 October 2025) commits to 99.9 per cent monthly uptime for Enterprise plans.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 19:08 UTC
Probed every five minutes at https://app.nocodb.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| nocodb.com/docs/changelog | changelog | 48 minutes ago · 404 | no change seen |
| nocodb.com/docs/legal/privacy | privacy | 48 minutes ago · 200 | no change seen |
| nocodb.com/docs/legal/terms-of-service | terms | 48 minutes ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/nocodb.json
Notable
- The MCP server on NocoDB Cloud has 199 tools per the 2026.09.1 changelog, and one connection reaches every base its owner picks. The Community Edition has the record tools only, 13 in the source source
- An MCP connection registers only the tools on its allowlist, set per section to Read, Read and write, Read, write and delete, or None, and its authority is checked against the owner's role on each call source
- Fine-grained tokens are stored as SHA-256 hashes, shown once, and default to a 1-year expiry. Base selection, categories and expiry are on all Cloud plans, while Community Edition tokens reach all resources and never expire source
- Rate limit of 5 requests a second per user on all plans, with a 429 and a 30-second wait source
- MCP tool calls count against the workspace's monthly API calls as the same work would over REST, so creating 100 records counts as 10 calls source
- The licence changed from AGPL-3.0 to the Sustainable Use License on 9 January 2026. Internal self-hosting stays free, and selling hosted access needs a commercial licence source
- The pricing page labels the v2 APIs 'will deprecate soon' with no date. Creating legacy org-wide tokens through the API was blocked on Cloud from v2026.08.1 source
- status.nocodb.com lists no incident for July, August, September or October 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 19.4 | |
| Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.8 | |
Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus .md (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on queryRecords and a generateSkillGuide tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15). | |||
| Agent ergonomics | 13%16.2 | 12.0 | |
The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with next and prev URLs, where, sort, fields and viewId (20). v3 errors return a stable error code with a message and a request id, though some older paths return a bare msg (16). The record tools in the source set readOnlyHint, destructiveHint and in places idempotentHint, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8). | |||
| Security & auth | 14%17.5 | 12.4 | |
| Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.6 | |
| Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10). | |||
| Transparency & trusteditorial 66, provenance 86 | 7%8.8 | 6.7 | |
Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented NC_DISABLE_TELE switch (18 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 75.7 · BB | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on NocoDB, or have the agent fetch /fixes/nocodb.md. A fix counts at the next check, once it's public.
Show it
# Fix list: NocoDB From Anchor Terminal's listing at https://www.anchorterminal.com/tools/nocodb, the October 2026 research run, assessed 8 October 2026. Grade BB, 75.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on NocoDB: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 71 out of 100, up to 5.1 more on the total Why it scored 71: Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Agent ergonomics, 74 out of 100, up to 4.2 more on the total Why it scored 74: The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with `next` and `prev` URLs, `where`, `sort`, `fields` and `viewId` (20). v3 errors return a stable `error` code with a message and a request id, though some older paths return a bare `msg` (16). The record tools in the source set `readOnlyHint`, `destructiveHint` and in places `idempotentHint`, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Schema & documentation, 85 out of 100, up to 2.4 more on the total Why it scored 85: Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus `.md` (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on `queryRecords` and a `generateSkillGuide` tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Transparency & trust, 76 out of 100, up to 2.1 more on the total Made of editorial 66, provenance 86. Why it scored 76: Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented `NC_DISABLE_TELE` switch (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: nocodb.com, registered 2021-04-14 (5 years) (11 of 15) - security.txt: not found (0 of 10) ## 6. Maintenance & community, 87 out of 100, up to 1.1 more on the total Why it scored 87: Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Reliability, 97 out of 100, up to 0.6 more on the total Why it scored 97: Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - The lead called NocoDB open source. Since January 2026 it is under the Sustainable Use License, which the vendor's own licence page says is not OSI-approved - The lead's docs link (nocodb.com/docs/product-docs/mcp) now redirects to nocodb.com/docs/apis-and-mcp/mcp, and the vendor's documents name it NocoDB Inc, without a comma - The tool count differs between vendor pages. llms.txt says 149 tools and the 2026.09.1 changelog says 199. The listing uses 199 - unchecked: the input schemas, descriptions and annotations of the Cloud-only MCP tools, which need a signed-in account and aren't in the public repository. Only the 13 record tools were read in the source - unchecked: whether signup for the Free plan asks for a card. The pricing page says no card is required and we didn't complete a signup - unchecked: reply times on GitHub issues and the results of the CI workflows - unchecked: the first release date, left empty - The pricing cards show Plus at $12 and Business at $24 a seat billed annually, while the comparison table on the same page shows 15 and 30. The listing uses the card prices - No security.txt, bug bounty, separate DPA, API deprecation policy or prompt-injection guidance was found in the reviewed pages - The docs give 30 seconds as the wait after a 429 and the OpenAPI file says the response carries Retry-After. We didn't trigger one - GitHub advisories from May and June 2026 include two rated High (stored cross-site scripting through a form redirect URL, and an attachment size limit bypass). They are published by the maintainers and no deduction was taken ## Weaknesses - 5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429 - REST create, update and upsert calls take 10 records each by default - The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan - The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved - No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token - Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds - Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records - Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or` - Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The lead called NocoDB open source. Since January 2026 it is under the Sustainable Use License, which the vendor's own licence page says is not OSI-approved
- The lead's docs link (nocodb.com/docs/product-docs/mcp) now redirects to nocodb.com/docs/apis-and-mcp/mcp, and the vendor's documents name it NocoDB Inc, without a comma
- The tool count differs between vendor pages. llms.txt says 149 tools and the 2026.09.1 changelog says 199. The listing uses 199
- unchecked: the input schemas, descriptions and annotations of the Cloud-only MCP tools, which need a signed-in account and aren't in the public repository. Only the 13 record tools were read in the source
- unchecked: whether signup for the Free plan asks for a card. The pricing page says no card is required and we didn't complete a signup
- unchecked: reply times on GitHub issues and the results of the CI workflows
- unchecked: the first release date, left empty
- The pricing cards show Plus at $12 and Business at $24 a seat billed annually, while the comparison table on the same page shows 15 and 30. The listing uses the card prices
- No security.txt, bug bounty, separate DPA, API deprecation policy or prompt-injection guidance was found in the reviewed pages
- The docs give 30 seconds as the wait after a 429 and the OpenAPI file says the response carries Retry-After. We didn't trigger one
- GitHub advisories from May and June 2026 include two rated High (stored cross-site scripting through a form redirect URL, and an attachment size limit bypass). They are published by the maintainers and no deduction was taken
Sources 24
- MCP server docs (Markdown) nocodb.com · seen 2026-10-08
- REST API docs, rate limits and query parameters nocodb.com · seen 2026-10-08
- API tokens nocodb.com · seen 2026-10-08
- v3 OpenAPI file nocodb.com · seen 2026-10-08
- llms.txt nocodb.com · seen 2026-10-08
- changelog 2026.09.1 nocodb.com · seen 2026-10-08
- pricing nocodb.com · seen 2026-10-08
- status page status.nocodb.com · seen 2026-10-08
- status incidents, September 2026 status.nocodb.com · seen 2026-10-08
- Service Level Agreement nocodb.com · seen 2026-10-08
- Terms of Service nocodb.com · seen 2026-10-08
- privacy policy nocodb.com · seen 2026-10-08
- Master Subscription Agreement nocodb.com · seen 2026-10-08
- sub-processors nocodb.com · seen 2026-10-08
- AI terms nocodb.com · seen 2026-10-08
- workspace audit logs nocodb.com · seen 2026-10-08
- self-hosting licence page nocodb.com · seen 2026-10-08
- environment variables (rate limits, telemetry) nocodb.com · seen 2026-10-08
- OAuth authorisation server metadata app.nocodb.com · seen 2026-10-08
- repository (clone of 8 October 2026: LICENSE.md, SECURITY.md, tags, packages/nocodb/src/mcp) github.com · seen 2026-10-08
- GitHub security advisories github.com · seen 2026-10-08
- npm, nocodb-sdk registry.npmjs.org · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- RDAP for nocodb.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $12 / seat-mo Free plan with 1,000 API calls a month, 1,000 records and 3 editor seats, no card required per the pricing page, so an agent can start without a contract. Plus is $12 a seat a month billed annually, Business $24 and Scale $45, with Plus and Business capped at 9 paid seats. Enterprise through sales. API calls aren't priced separately. The self-hosted Community Edition is free for internal use (checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Plus | $12 | per seat per month | billed annually, at most 9 paid seats ($108 a month), 100,000 API calls a month |
| Business | $24 | per seat per month | billed annually, at most 9 paid seats ($216 a month), 1,000,000 API calls a month |
| Scale | $45 | per seat per month | billed annually, 3 seats minimum, 5,000,000 API calls a month |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/nocodb.xml, or this listing's score history at history.json.
Connect
Install
docker run -d \
--name noco \
-v "$(pwd)"/nocodb:/usr/app/data/ \
-p 8080:8080 \
nocodb/nocodb:latest
First request
curl -H "xc-token: nc_pat_..." https://your-nocodb.com/api/v3/...
MCP client configuration
{
"mcpServers": {
"NocoDB MCP": {
"args": [
"mcp-remote",
"https://your-domain.com/mcp/\u003cncId\u003e",
"--header",
"x-api-key: \u003cncToken\u003e"
],
"command": "npx"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/nocodb
letme picks this listing for sheets.records, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Airtable BBCoda (Superhuman Docs) BBaserow BGoogle Sheets API BBSmartsheet API + MCP BMicrosoft Excel (Microsoft Graph workbook API) C
Head to head Coda (Superhuman Docs) vs NocoDB · Google Sheets API vs NocoDB · Microsoft Excel (Microsoft Graph workbook API) vs NocoDB · Airtable vs NocoDB · Baserow vs NocoDB · NocoDB vs Smartsheet API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Airtable Formagrid Inc (Airtable) | BB | 70.9 | sheets.records sheets.read sheets.write sheets.tables sheets.formulas | no |
| Coda (Superhuman Docs) Superhuman Platform Inc. | B | 64.8 | sheets.read sheets.write sheets.tables sheets.records sheets.formulas | no |
| Baserow Baserow B.V. | B | 63.6 | sheets.records sheets.read sheets.write sheets.tables sheets.formulas | no |
| Google Sheets API Google | BB | 76.3 | sheets.read sheets.write sheets.formulas sheets.tables | no |
| Smartsheet API + MCP Smartsheet Inc. | B | 67.6 | sheets.read sheets.write sheets.records sheets.formulas | no |
| Microsoft Excel (Microsoft Graph workbook API) Microsoft | C | 58.5 | sheets.read sheets.write sheets.tables sheets.formulas | no |
Machine-readable
- JSON
/api/v1/tools/nocodb.json· historyhistory.json· badge/badges/nocodb.svg· changes feed/feeds/tools/nocodb.xml - Markdown
/tools/nocodb.md· slim/tools/nocodb.min.md(or sendAccept: text/markdown) - Fix list
/fixes/nocodb.md·/fixes/nocodb.json - From a terminal
anchor tool nocodb --md(the CLI) · over MCPget_tool {"slug": "nocodb"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/nocodb"><img src="https://www.anchorterminal.com/badges/nocodb.svg" alt="NocoDB on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/nocodb)<a href="https://www.anchorterminal.com/tools/nocodb">NocoDB on Anchor Terminal</a>It counts on a page on nocodb.com or one of its subdomains, or the README of github.com/nocodb/nocodb.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "nocodb", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


