NocoDB

by NocoDB Inc HTTP API in Spreadsheets & operational tables

Hosted Agent-ready

NocoDB Inc · nocodb.com since 2021 · status page · who's behind it

NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth.

Good for Teams that want Airtable-style typed records with the option to self-host, and an agent that reads, filters and writes records or builds schema through MCP with a narrow allowlist.

Is this your product? Claim this listing or verify it

Assessment. API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://app.nocodb.com
Auth
OAuth or key
Pricing
Freemium · $12 / seat-mo
x402
No
Licence
Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service
Tools exposed
199
Packages
npm nocodb-sdk
llms.txt
published
Last release
GitHub stars
65k
npm / week
6.3k
Surfaces graded
NocoDB Cloud. The v3 REST API at https://app.nocodb.com/api/v3 and the built-in MCP server at https://app.nocodb.com/mcp. The self-hosted Community Edition has the same REST API and a 13-tool MCP server
Free tier
Free plan, no card required per the pricing page. 3 editor seats, 1,000 records, 1 GB storage, 1,000 API calls a month, 100 automation runs
Rate limits
5 requests a second per user on all plans, shared by that user's tokens. A 429 carries Retry-After per the OpenAPI file, and the docs say to wait 30 seconds (vendor's figures)
Monthly API calls
1,000 on Free, 100,000 on Plus, 1,000,000 on Business, 5,000,000 on Scale, unlimited on Enterprise. Over a limit, a 2-week grace period applies before access may be restricted
Batch size
10 records per REST create, update or upsert by default. MCP record tools take up to 100 records a call, and queryRecords returns up to 200 a page
Auth and scopes
Fine-grained API tokens (nc_pat_ prefix) with eight categories (Records, Comments, Tables, Fields, Views, Webhooks, Base, Users) at Read or Read and write, chosen bases, and expiry. OAuth authorisation code grant with PKCE (S256), refresh tokens, revocation and dynamic client registration for MCP clients
Read and write
Records (list, get, create, update, upsert, delete, count), links, attachment upload, tables, fields, views, filters, sorts, webhooks, members, scripts, dashboards and workflows in the v3 API
Filtering
where in NocoDB's own syntax, fields, sort, viewId, page and pageSize on list records, with next and prev page URLs in the response
MCP server
Built into the product, streamable HTTP. 199 tools on NocoDB Cloud per the 2026.09.1 changelog (llms.txt says 149). Per-connection allowlist by section. Token in x-api-key or xc-mcp-token, or OAuth at https://app.nocodb.com/mcp
Errors
v3 errors return {error, message} with optional details, and a requestId matching the x-request-id header outside the Community Edition. Some older paths return a bare msg
SDKs
nocodb-sdk 0.301.3 on npm (JavaScript and TypeScript), under the Sustainable Use License. The nocodb package on PyPI is community-built
Audit
Workspace audit logs with user, time, base, event, IP address and JSON payload, on the Scale plan and above. Per-record change history. The MCP tools can read both
Status and SLA
status.nocodb.com (Kener) with two components and 90-day availability. 99.9 per cent monthly uptime commitment for Enterprise plans
Sub-processors
16 listed with countries, 15 in the USA and one in Germany. AWS for infrastructure. Anthropic, OpenAI and Braintrust only for customers using NocoAI
Self-hosting
Docker image nocodb/nocodb, free for internal use under the Sustainable Use License. Rate limits are set by environment variables. Telemetry is on unless NC_DISABLE_TELE is set

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Fine-grained API tokens carry eight permission categories at Read or Read and write, a list of bases, an expiry and an on-off switch
  • An MCP connection lists only the tools its owner allowed, by section at Read, Read and write, or Read, write and delete
  • Public OpenAPI 3.1 file for the v3 REST API with 114 operations, plus llms.txt and a Markdown copy of every docs page
  • The MCP record tools in the source set readOnlyHint and destructiveHint, and deleteRecords is marked destructive
  • status.nocodb.com lists no incident from July to October 2026 and shows 99.9907 per cent for the application over 90 days

Weaknesses

  • 5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429
  • REST create, update and upsert calls take 10 records each by default
  • The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan
  • The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved
  • No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry

Before you call it notes for agents

  1. Create a fine-grained token limited to the bases and categories the task needs. Send it as xc-token or as a Bearer token
  2. Stay under 5 requests a second across all tokens of one user. After a 429, honour Retry-After or wait 30 seconds
  3. Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records
  4. Write date filters with a sub-operator, such as (due_date,eq,exactDate,2026-06-01), and put no space after ~and or ~or
  5. Use /records/upsert with a merge key so a repeated write updates the record instead of adding a duplicate

Who's behind it provenance 86/100

  • Legal entity namedNocoDB Inc (doing business as NocoDB)20/20
  • Domain agenocodb.com, registered 2021-04-14 (5 years)11/15
  • Endpoint on the vendor's domainapp.nocodb.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects10/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagestatus.nocodb.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2025-10-14, states 7 of 7, 2 to know

TL;DR Dated 2025-10-14. States all 7 things a reader expects. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.

Says access can be ended without notice or for any reason
We may permanently or temporarily terminate or suspend your access to our Services without notice or liability, without cause or for any reason, including if in our sole discretion you violate any provision of these Terms.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
…OPT OUT PURSUANT TO THE INSTRUCTIONS IN SECTION [14.2](#142-arbitration), THE EXCLUSIVE USE OF FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS ONLY TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS, COLLECTIVE, PRIVATE ATTORNEY GENERAL OR REPRESENTATIVE ACTIONS OR PROCEEDINGS.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2025-10-14
Last updated: 2025-10-14

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of California
These Terms will be governed by the internal substantive laws of the State of California, without respect to its conflict of laws principles.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the fees paid in the 12 months before the claim
IN NO EVENT WILL WE OR OUR AFFILIATES, AGENTS, SUPPLIERS, OR LICENSORS (OR OUR OR THEIR EMPLOYEES, CONTRACTORS, AGENTS, OFFICERS, OR DIRECTORS) BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS IN AN AMOUNT EXCEEDING THE AMOUNT OF FEES YOU PAID TO US HEREUNDER DURING THE…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
* (iv) your individual right to access and use our Services may be suspended or terminated (and ownership and administration of your NocoDB Account (defined below) may be transferred) if you cease to be associated with, or cease to use an email address associated with, owned by, or provisioned by, that Organization

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
Any change to a Subscription Plan's pricing or payment terms will become effective in the billing cycle following notice of such change to you as provided in these Terms.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
* (ii) you represent and warrant that you have the authority to bind that Organization to these Terms (and if you do not have the authority, you may not access or use our Services)

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
**TRIAL FEATURES ARE PROVIDED TO YOU FOR TESTING PURPOSES ONLY, ON AN "AS IS" BASIS, WITHOUT ANY WARRANTY, LIABILITY, INDEMNITY, OR PERFORMANCE OBLIGATIONS.** Trial Features are not subject to any service level agreements or support commitments.

Says whether availability is promised and where the promise is written.

The customer grants NocoDB an irrevocable, transferable and sublicensable licence to access, use, copy, store, modify and display its content for the purposes the clause lists.
us an irrevocable, transferable, sublicensable (through multiple tiers), fully paid, royalty-free, and worldwide right and license to access, use, copy, store, modify, and display Your Content solely:

Noted by a second reader on 2026-10-08.

Subscription plans renew automatically for terms equal to the original term, at the price that applies on the renewal date, until the customer cancels.
Unless and until canceled by you, all Subscription Plans will automatically renew for renewal terms equal in length to the original Subscription Term, at the applicable price as of the renewal date.

Noted by a second reader on 2026-10-08.

NocoDB may name the customer in promotional materials and says it will stop on request.
We may identify you as our customer in our promotional materials. We will promptly stop doing so upon your request, which you may send by emailing [legal@nocodb.com](mailto:legal@nocodb.com).

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 8,206 words

Privacy policy dated 2026-03-20, states 8 of 8

TL;DR Dated 2026-03-20. States all 8 things a reader expects. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-03-20
Last updated: 2026-03-20

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
Read NocoDB’s Privacy Policy to understand how we collect, use, store, and protect your personal data when you use our services.

The basic statement a privacy policy exists to make.

Says how long data is kept
We store your personal information for no longer than necessary for the purposes for which it was collected, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.

Says when data sent to the service is deleted.

Says who else receives the data
If you create your account using a service provided by a third party such as Google or Apple, or a single-sign-on service provided by a third party such as Okta, we may collect Customer Information about you from the third-party service (such as your username or user ID associated with that third-party service).

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell or share the personal information of consumers we know to be less than 16 years of age.

A plain statement either way.

Says what rights people have over their data
**The Right to Know** any or all of the following information relating to your personal information we have collected and disclosed in the last 12 months, upon verification of your identity:

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@nocodb.com
For instructions on how to permanently delete Content from your NocoDB Account, please contact us at [privacy@nocodb.com](mailto:privacy@nocodb.com).

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
When required by law, we will ensure that we rely on an appropriate legal mechanism for the transfer, such as your consent, standard contractual clauses (or their equivalent), or adequacy decisions.

The countries data goes to and the safeguard used.

Information is disclosed to AI observability and quality assurance providers for NocoAI, and this may include conversation content, inputs and outputs.
With AI observability and quality assurance providers who help us monitor, trace, evaluate, and improve the performance and quality of our AI-powered features (such as NocoAI), which may include the processing of conversation content, inputs, and outputs

Noted by a second reader on 2026-10-08.

Deleted content may be kept in archived or backup copies so that revision history and base snapshots keep working.
Content you delete (including Content containing personal information) may be retained in archived or backup copies in order to enable you to use certain features like revision history and base snapshots.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 4,764 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Terms of Service (last updated 14 October 2025) and the privacy policy (last updated 5 August 2025) name NocoDB Inc, doing business as NocoDB, and cover the website, the hosted services and the APIs. No postal address was found in the parts we read.

The REST API and the MCP server answer at app.nocodb.com, a nocodb.com subdomain. A self-hosted instance answers on the owner's own domain.

nocodb.com/.well-known/security.txt, nocodb.com/security.txt and app.nocodb.com/.well-known/security.txt return 404. SECURITY.md in the repository sends reports to security@nocodb.com.

RDAP for nocodb.com gives a registration date of 2021-04-14.

Organisations on an order form are governed by the Master Subscription Agreement (last updated 14 October 2025), which states SOC 2 Type II compliance with the report on request. The Service Level Agreement (last updated 6 October 2025) commits to 99.9 per cent monthly uptime for Enterprise plans.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 19:08 UTC

Right nowUpHTTP 200 · 289 ms · 2 minutes ago
Uptime 24h100.0%19 probes
Uptime 30 days100.0%19 probes
p50 24h298 msget
p95 24h423 msopen endpoint

Probed every five minutes at https://app.nocodb.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 1 hour ago

Pages we watch

PageKindLast checkedLast changed
nocodb.com/docs/changelogchangelog48 minutes ago · 404no change seen
nocodb.com/docs/legal/privacyprivacy48 minutes ago · 200no change seen
nocodb.com/docs/legal/terms-of-serviceterms48 minutes ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/nocodb.json

Notable

  • The MCP server on NocoDB Cloud has 199 tools per the 2026.09.1 changelog, and one connection reaches every base its owner picks. The Community Edition has the record tools only, 13 in the source source
  • An MCP connection registers only the tools on its allowlist, set per section to Read, Read and write, Read, write and delete, or None, and its authority is checked against the owner's role on each call source
  • Fine-grained tokens are stored as SHA-256 hashes, shown once, and default to a 1-year expiry. Base selection, categories and expiry are on all Cloud plans, while Community Edition tokens reach all resources and never expire source
  • Rate limit of 5 requests a second per user on all plans, with a 429 and a 30-second wait source
  • MCP tool calls count against the workspace's monthly API calls as the same work would over REST, so creating 100 records counts as 10 calls source
  • The licence changed from AGPL-3.0 to the Sustainable Use License on 9 January 2026. Internal self-hosting stays free, and selling hosted access needs a commercial licence source
  • The pricing page labels the v2 APIs 'will deprecate soon' with no date. Creating legacy org-wide tokens through the API was blocked on Cloud from v2026.08.1 source
  • status.nocodb.com lists no incident for July, August, September or October 2026 source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 19.4
Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.8
Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus .md (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on queryRecords and a generateSkillGuide tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15).
Agent ergonomics 13%16.2 12.0
The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with next and prev URLs, where, sort, fields and viewId (20). v3 errors return a stable error code with a message and a request id, though some older paths return a bare msg (16). The record tools in the source set readOnlyHint, destructiveHint and in places idempotentHint, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8).
Security & auth 14%17.5 12.4
Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20).
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored.
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.6
Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10).
Transparency & trusteditorial 66, provenance 86 7%8.8 6.7
Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented NC_DISABLE_TELE switch (18 of 20).
Negative events≤15None recorded0
Total75.7 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on NocoDB, or have the agent fetch /fixes/nocodb.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: NocoDB

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/nocodb, the October 2026 research run, assessed 8 October 2026. Grade BB, 75.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on NocoDB: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 found (0). Plan prices are public, Plus $12, Business $24 and Scale $45 a seat a month billed annually, with monthly API call allowances and no per-call price (10). A Free plan with 1,000 API calls a month, marked 'no credit card required' on the pricing page. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth. Dynamic client registration exists, but a person still authorises (0). The self-hosted Community Edition is free, and the paid Cloud is what was scored.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 71 out of 100, up to 5.1 more on the total

Why it scored 71: Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth with PKCE, refresh tokens, revocation and dynamic client registration. Secrets travel in headers (30). Read levels per category, an MCP allowlist with separate write and delete levels, and the owner's role checked on each call. No server-side confirmation before a delete was found, though the MCP tools include trash restore (15 of 20). Records and comments can hold text written by others, and no prompt-injection guidance was found (3 of 15). Workspace audit logs record user, IP address, event and payload, API token events included, but only on the Scale plan and above. Record history is on every record (10 of 15). SECURITY.md gives a reporting address and advisories are published on GitHub, ten on the first of five pages, the latest in June 2026. The Master Subscription Agreement states SOC 2 Type II with the report on request. No security.txt and no bug bounty found (13 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 74 out of 100, up to 4.2 more on the total

Why it scored 74: The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the tools on its allowlist, set by section and access level (15). Page-based pagination with `next` and `prev` URLs, `where`, `sort`, `fields` and `viewId` (20). v3 errors return a stable `error` code with a message and a request id, though some older paths return a bare `msg` (16). The record tools in the source set `readOnlyHint`, `destructiveHint` and in places `idempotentHint`, and the API has an upsert on merge keys. No idempotency keys (15). Few required parameters. nocodb-sdk for JavaScript and TypeScript is the only official client, and the PyPI package is community-built (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Schema & documentation, 85 out of 100, up to 2.4 more on the total

Why it scored 85: Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. In the source every MCP record tool declares a zod input schema. The input schemas of the Cloud-only tools weren't read (23 of 25). llms.txt at nocodb.com and a Markdown copy of every docs page at the same URL plus `.md` (10). REST operations describe behaviour and limits in prose. The 13 record tools have one-line descriptions, with a long manual of the filter syntax on `queryRecords` and a `generateSkillGuide` tool outside the Community Edition (14 of 20). Parameters are typed with enums and array limits, but record values are objects keyed by field and filters are strings in NocoDB's own syntax (11 of 15). Examples on 70 operations, and responses declared for 400, 401, 403, 404 and 422, with 429 on one operation (12 of 15). Versions in the path (v2, v3) and a changelog page per release (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Transparency & trust, 76 out of 100, up to 2.1 more on the total

Made of editorial 66, provenance 86.

Why it scored 76: Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. It was AGPL-3.0 before (20 of 30). Privacy policy of 5 August 2025, AI terms that rule out model training on inputs, and a Master Subscription Agreement that allows export for 30 days after termination and removal within 90 days of a request. No retention periods for content on self-serve plans, deleted content may stay in backups, and no separate DPA was found (20 of 30). The docs give the version from which legacy tokens were blocked and mark webhook v2 deprecated, but the v2 APIs are 'will deprecate soon' with no date and no policy was found (8 of 20). Sub-processor list of 16 with countries, last updated 14 October 2025. Self-hosted telemetry is on by default with a documented `NC_DISABLE_TELE` switch (18 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: nocodb.com, registered 2021-04-14 (5 years) (11 of 15)
- security.txt: not found (0 of 10)

## 6. Maintenance & community, 87 out of 100, up to 1.1 more on the total

Why it scored 87: Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). Six release tags in the last 90 days, from 2026.07.0 on 13 July to 2026.09.1 (20). 387 open issues on GitHub, the 25 newest opened between 11 July and 7 October 2026. We didn't read reply times (14 of 25). Not in the official MCP registry, where a search for nocodb returns nothing. nocodb-sdk 0.301.3 on npm matches the repository (15). The repository has unit test, build check and dependency review workflows and a Renovate config, with commits on 8 October 2026. We didn't read the workflow results (8 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Reliability, 97 out of 100, up to 0.6 more on the total

Why it scored 97: Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. Status page at status.nocodb.com on Kener, with two components and 90-day availability (20). No incident is listed for July, August, September or October 2026, and the application shows 99.9907 per cent over 90 days (30). 5 requests a second per user on all plans, monthly API call allowances per plan, 10 records per REST write and 100 per MCP record call (15). A 429 means waiting 30 seconds per the docs and carries Retry-After per the OpenAPI file, and upsert on a merge key makes a repeated write safe. No idempotency keys (12). A 99.9 per cent monthly uptime commitment is published for Enterprise plans (10). The v3 API and the MCP server carry no beta label, while the pricing page marks the v2 APIs 'will deprecate soon' (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- The lead called NocoDB open source. Since January 2026 it is under the Sustainable Use License, which the vendor's own licence page says is not OSI-approved
- The lead's docs link (nocodb.com/docs/product-docs/mcp) now redirects to nocodb.com/docs/apis-and-mcp/mcp, and the vendor's documents name it NocoDB Inc, without a comma
- The tool count differs between vendor pages. llms.txt says 149 tools and the 2026.09.1 changelog says 199. The listing uses 199
- unchecked: the input schemas, descriptions and annotations of the Cloud-only MCP tools, which need a signed-in account and aren't in the public repository. Only the 13 record tools were read in the source
- unchecked: whether signup for the Free plan asks for a card. The pricing page says no card is required and we didn't complete a signup
- unchecked: reply times on GitHub issues and the results of the CI workflows
- unchecked: the first release date, left empty
- The pricing cards show Plus at $12 and Business at $24 a seat billed annually, while the comparison table on the same page shows 15 and 30. The listing uses the card prices
- No security.txt, bug bounty, separate DPA, API deprecation policy or prompt-injection guidance was found in the reviewed pages
- The docs give 30 seconds as the wait after a 429 and the OpenAPI file says the response carries Retry-After. We didn't trigger one
- GitHub advisories from May and June 2026 include two rated High (stored cross-site scripting through a form redirect URL, and an attachment size limit bypass). They are published by the maintainers and no deduction was taken

## Weaknesses

- 5 requests a second per user on every plan, shared by all of that user's tokens, with a 30-second block after a 429
- REST create, update and upsert calls take 10 records each by default
- The Free plan allows 1,000 API calls a month and 1,000 records, and workspace audit logs start at the Scale plan
- The licence changed from AGPL-3.0 to the Sustainable Use License in January 2026, which is not OSI-approved
- No security.txt and no bug bounty were found, and the MCP server is not in the official MCP registry

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token
- Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds
- Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records
- Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or`
- Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • The lead called NocoDB open source. Since January 2026 it is under the Sustainable Use License, which the vendor's own licence page says is not OSI-approved
  • The lead's docs link (nocodb.com/docs/product-docs/mcp) now redirects to nocodb.com/docs/apis-and-mcp/mcp, and the vendor's documents name it NocoDB Inc, without a comma
  • The tool count differs between vendor pages. llms.txt says 149 tools and the 2026.09.1 changelog says 199. The listing uses 199
  • unchecked: the input schemas, descriptions and annotations of the Cloud-only MCP tools, which need a signed-in account and aren't in the public repository. Only the 13 record tools were read in the source
  • unchecked: whether signup for the Free plan asks for a card. The pricing page says no card is required and we didn't complete a signup
  • unchecked: reply times on GitHub issues and the results of the CI workflows
  • unchecked: the first release date, left empty
  • The pricing cards show Plus at $12 and Business at $24 a seat billed annually, while the comparison table on the same page shows 15 and 30. The listing uses the card prices
  • No security.txt, bug bounty, separate DPA, API deprecation policy or prompt-injection guidance was found in the reviewed pages
  • The docs give 30 seconds as the wait after a 429 and the OpenAPI file says the response carries Retry-After. We didn't trigger one
  • GitHub advisories from May and June 2026 include two rated High (stored cross-site scripting through a form redirect URL, and an attachment size limit bypass). They are published by the maintainers and no deduction was taken

Sources 24

  1. MCP server docs (Markdown) nocodb.com · seen 2026-10-08
  2. REST API docs, rate limits and query parameters nocodb.com · seen 2026-10-08
  3. API tokens nocodb.com · seen 2026-10-08
  4. v3 OpenAPI file nocodb.com · seen 2026-10-08
  5. llms.txt nocodb.com · seen 2026-10-08
  6. changelog 2026.09.1 nocodb.com · seen 2026-10-08
  7. pricing nocodb.com · seen 2026-10-08
  8. status page status.nocodb.com · seen 2026-10-08
  9. status incidents, September 2026 status.nocodb.com · seen 2026-10-08
  10. Service Level Agreement nocodb.com · seen 2026-10-08
  11. Terms of Service nocodb.com · seen 2026-10-08
  12. privacy policy nocodb.com · seen 2026-10-08
  13. Master Subscription Agreement nocodb.com · seen 2026-10-08
  14. sub-processors nocodb.com · seen 2026-10-08
  15. AI terms nocodb.com · seen 2026-10-08
  16. workspace audit logs nocodb.com · seen 2026-10-08
  17. self-hosting licence page nocodb.com · seen 2026-10-08
  18. environment variables (rate limits, telemetry) nocodb.com · seen 2026-10-08
  19. OAuth authorisation server metadata app.nocodb.com · seen 2026-10-08
  20. repository (clone of 8 October 2026: LICENSE.md, SECURITY.md, tags, packages/nocodb/src/mcp) github.com · seen 2026-10-08
  21. GitHub security advisories github.com · seen 2026-10-08
  22. npm, nocodb-sdk registry.npmjs.org · seen 2026-10-08
  23. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  24. RDAP for nocodb.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $12 / seat-mo Free plan with 1,000 API calls a month, 1,000 records and 3 editor seats, no card required per the pricing page, so an agent can start without a contract. Plus is $12 a seat a month billed annually, Business $24 and Scale $45, with Plus and Business capped at 9 paid seats. Enterprise through sales. API calls aren't priced separately. The self-hosted Community Edition is free for internal use (checked 2026-10-08).

Prices

ItemPriceUnitNote
Plus$12per seat per monthbilled annually, at most 9 paid seats ($108 a month), 100,000 API calls a month
Business$24per seat per monthbilled annually, at most 9 paid seats ($216 a month), 1,000,000 API calls a month
Scale$45per seat per monthbilled annually, 3 seats minimum, 5,000,000 API calls a month

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/nocodb.xml, or this listing's score history at history.json.

Connect

Install

docker run -d \
  --name noco \
  -v "$(pwd)"/nocodb:/usr/app/data/ \
  -p 8080:8080 \
  nocodb/nocodb:latest

First request

curl -H "xc-token: nc_pat_..." https://your-nocodb.com/api/v3/...

MCP client configuration

{
  "mcpServers": {
    "NocoDB MCP": {
      "args": [
        "mcp-remote",
        "https://your-domain.com/mcp/\u003cncId\u003e",
        "--header",
        "x-api-key: \u003cncToken\u003e"
      ],
      "command": "npx"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/nocodb

letme picks this listing for sheets.records, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Airtable Formagrid Inc (Airtable)BB70.9sheets.records sheets.read sheets.write sheets.tables sheets.formulasno
Coda (Superhuman Docs) Superhuman Platform Inc.B64.8sheets.read sheets.write sheets.tables sheets.records sheets.formulasno
Baserow Baserow B.V.B63.6sheets.records sheets.read sheets.write sheets.tables sheets.formulasno
Google Sheets API GoogleBB76.3sheets.read sheets.write sheets.formulas sheets.tablesno
Smartsheet API + MCP Smartsheet Inc.B67.6sheets.read sheets.write sheets.records sheets.formulasno
Microsoft Excel (Microsoft Graph workbook API) MicrosoftC58.5sheets.read sheets.write sheets.tables sheets.formulasno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    NocoDB on Anchor Terminal, BB, 75.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/nocodb"><img src="https://www.anchorterminal.com/badges/nocodb.svg" alt="NocoDB on Anchor Terminal" height="20"></a>
    [![NocoDB on Anchor Terminal](https://www.anchorterminal.com/badges/nocodb.svg)](https://www.anchorterminal.com/tools/nocodb)

    It counts on a page on nocodb.com or one of its subdomains, or the README of github.com/nocodb/nocodb.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "nocodb", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.