# NocoDB (slim) > NocoDB is a database of typed records in bases, tables and views, run on NocoDB Cloud or self-hosted. Agents reach it through a REST API and a built-in MCP server, using scoped API tokens or OAuth. - Full: https://www.anchorterminal.com/tools/nocodb.md (~8,200 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/nocodb.json · canonical https://www.anchorterminal.com/tools/nocodb - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 75.7/100 · rank #37 of 722 · #2 in Spreadsheets & operational tables · agent-ready · confidence medium** Assessment: API tokens and MCP connections are limited by permission category and by base, and an MCP connection registers only the tools it is allowed. The v3 REST API has a public OpenAPI file. Requests are capped at 5 a second per user, REST writes take 10 records a call, and the Free plan stops at 1,000 API calls a month. ## Facts - Kind: HTTP API · vendor: NocoDB Inc · category: Spreadsheets & operational tables · legal entity: NocoDB Inc (doing business as NocoDB) · provenance 86/100 - Endpoint: `https://app.nocodb.com` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Sustainable Use License 1.0 since January 2026 (source-available, not OSI-approved; AGPL-3.0 before). NocoDB Cloud is a proprietary service under NocoDB's Terms of Service - Probe metrics: not measured yet (probes haven't run) - Surfaces graded: NocoDB Cloud. The v3 REST API at https://app.nocodb.com/api/v3 and the built-in MCP server at https://app.nocodb.com/mcp. The self-hosted Community Edition has the same REST API and a 13-tool MCP server - Free tier: Free plan, no card required per the pricing page. 3 editor seats, 1,000 records, 1 GB storage, 1,000 API calls a month, 100 automation runs - Rate limits: 5 requests a second per user on all plans, shared by that user's tokens. A 429 carries Retry-After per the OpenAPI file, and the docs say to wait 30 seconds (vendor's figures) - Monthly API calls: 1,000 on Free, 100,000 on Plus, 1,000,000 on Business, 5,000,000 on Scale, unlimited on Enterprise. Over a limit, a 2-week grace period applies before access may be restricted - Batch size: 10 records per REST create, update or upsert by default. MCP record tools take up to 100 records a call, and `queryRecords` returns up to 200 a page - Auth and scopes: Fine-grained API tokens (`nc_pat_` prefix) with eight categories (Records, Comments, Tables, Fields, Views, Webhooks, Base, Users) at Read or Read and write, chosen bases, and expiry. OAuth authorisation code grant with PKCE (S256), refresh tokens, revocation and dynamic client registration for MCP clients - Read and write: Records (list, get, create, update, upsert, delete, count), links, attachment upload, tables, fields, views, filters, sorts, webhooks, members, scripts, dashboards and workflows in the v3 API - Filtering: `where` in NocoDB's own syntax, `fields`, `sort`, `viewId`, `page` and `pageSize` on list records, with `next` and `prev` page URLs in the response - MCP server: Built into the product, streamable HTTP. 199 tools on NocoDB Cloud per the 2026.09.1 changelog (llms.txt says 149). Per-connection allowlist by section. Token in `x-api-key` or `xc-mcp-token`, or OAuth at https://app.nocodb.com/mcp - Errors: v3 errors return `{error, message}` with optional `details`, and a `requestId` matching the `x-request-id` header outside the Community Edition. Some older paths return a bare `msg` - SDKs: nocodb-sdk 0.301.3 on npm (JavaScript and TypeScript), under the Sustainable Use License. The `nocodb` package on PyPI is community-built - Audit: Workspace audit logs with user, time, base, event, IP address and JSON payload, on the Scale plan and above. Per-record change history. The MCP tools can read both - Status and SLA: status.nocodb.com (Kener) with two components and 90-day availability. 99.9 per cent monthly uptime commitment for Enterprise plans - Sub-processors: 16 listed with countries, 15 in the USA and one in Germany. AWS for infrastructure. Anthropic, OpenAI and Braintrust only for customers using NocoAI - Self-hosting: Docker image nocodb/nocodb, free for internal use under the Sustainable Use License. Rate limits are set by environment variables. Telemetry is on unless `NC_DISABLE_TELE` is set - Prices: Plus $12 per seat per month; Business $24 per seat per month; Scale $45 per seat per month - Scores: Reliability 97, Performance pending, Schema & documentation 85, Agent ergonomics 74, Security & auth 71, Payments & pricing 30, Task success pending, Maintenance & community 87, Transparency & trust 76 · total over the 7 assessed categories - Why: Reliability, Graded on NocoDB Cloud (the v3 REST API and the built-in MCP server) with the hosted lines. · Schema & documentation, Public OpenAPI 3.1 file for the v3 REST API with 57 paths and 114 operations. · Agent ergonomics, The MCP server has 199 tools on NocoDB Cloud per the 2026.09.1 changelog, so 5 of 25, plus 10 back because a connection registers only the t… · Security & auth, Fine-grained tokens limited to eight permission categories and chosen bases, with expiry, an on-off switch and SHA-256 storage, or OAuth wit… · Payments & pricing, No x402, MPP or L402 found (0). · Maintenance & community, Release 2026.09.1 was tagged on 29 September 2026, 9 days before the check (30). · Transparency & trust, Source is public under the Sustainable Use License since January 2026, with clear terms but not an OSI licence. - Sources: 24, open questions: 11, both in the full twin - Capabilities: sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas - JSON: https://www.anchorterminal.com/api/v1/tools/nocodb.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/nocodb.svg` or a link to https://www.anchorterminal.com/tools/nocodb from a page on nocodb.com or one of its subdomains, or the README of github.com/nocodb/nocodb, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Create a fine-grained token limited to the bases and categories the task needs. Send it as `xc-token` or as a Bearer token 2. Stay under 5 requests a second across all tokens of one user. After a 429, honour `Retry-After` or wait 30 seconds 3. Send REST writes in batches of 10 records. The MCP record tools take up to 100, counted as one API call per 10 records 4. Write date filters with a sub-operator, such as `(due_date,eq,exactDate,2026-06-01)`, and put no space after `~and` or `~or` 5. Use `/records/upsert` with a merge key so a repeated write updates the record instead of adding a duplicate ## Connect ```bash docker run -d \ --name noco \ -v "$(pwd)"/nocodb:/usr/app/data/ \ -p 8080:8080 \ nocodb/nocodb:latest ``` ```bash curl -H "xc-token: nc_pat_..." https://your-nocodb.com/api/v3/... ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/nocodb ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Airtable | BB | 70.9 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/airtable.min.md | | SeaTable | B | 66.3 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/seatable.min.md | | Coda (Superhuman Docs) | B | 64.8 | sheets.read, sheets.write, sheets.tables, sheets.records, sheets.formulas | https://www.anchorterminal.com/tools/coda.min.md | | Baserow | B | 63.6 | sheets.records, sheets.read, sheets.write, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/baserow.min.md | | Teable | C | 61 | sheets.read, sheets.write, sheets.records, sheets.tables, sheets.formulas | https://www.anchorterminal.com/tools/teable.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)