# Ref > Ref Context is a hosted MCP server from Ref Software, Inc. Its two tools search public documentation and a user's private repositories and PDFs, then read a page as Markdown trimmed to the relevant sections. - Canonical: https://www.anchorterminal.com/tools/ref - Markdown: https://www.anchorterminal.com/tools/ref.md (~6,250 tokens) - Slim: https://www.anchorterminal.com/tools/ref.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/ref.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 59.4/100 · rank #431 of 722 · #5 in Code & developer platforms · not agent-ready · confidence medium** ## Assessment Two read-only tools with short definitions, OAuth with separate scopes for public and private documentation, and an activity log of every tool call. The API key may be passed in the URL query string, no rate limit or 429 guidance is documented, and the free allowance is 200 one-time credits. ## Facts | Field | Value | | --- | --- | | Vendor | Ref Software, Inc (https://ref.tools) | | Kind | MCP server | | Category | Code & developer platforms (https://www.anchorterminal.com/categories/code) | | Transport | Streamable HTTP, stdio | | Endpoint | `https://api.ref.tools/mcp` | | Auth | OAuth or key · An account is required. The hosted endpoint takes an API key in the `x-ref-api-key` header, the same key as an `?apiKey=` query parameter, or OAuth when neither is sent. OAuth runs through Scalekit, and `/.well-known/oauth-protected-resource/mcp` lists the scopes `public_docs:read` and `private_docs:read`. Keys come from ref.tools/keys after a browser sign-up with Google, GitHub or email. Teams have Admin, Writer and Reader roles, and SAML or OIDC single sign-on is a $200 a month add-on. The stdio package reads `REF_API_KEY`. | | Pricing | Freemium ($10 / 1k calls) · Free: 200 one-time credits that never expire. Each `ref_search_documentation` or `ref_read_url` call costs one credit. Pro is $50 a month with 6,000 credits, Max $200 a month with 30,000, and extra credits cost $10 per 1,000 on Pro and above. Credits are shared with Ref Plans. The docs do not say whether sign-up needs a card (https://docs.ref.tools/usage/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs, the pricing page or the MCP server source (checked 2026-10-08). | | Licence | Proprietary hosted service under Ref's terms of service. The stdio MCP server in ref-tools/ref-tools-mcp is MIT | | Tools exposed | 2 | | Packages | npm: `ref-tools-mcp` | | MCP registry name | `tools.ref/ref-tools-mcp` | | Source | https://github.com/ref-tools/ref-tools-mcp | | Docs | https://docs.ref.tools | | llms.txt | https://docs.ref.tools/llms.txt | | Last release | 2025-11-04 | | GitHub stars | 1,179 (as of 2026-10-08) | | npm downloads / week | 596 | | Endpoint | https://api.ref.tools/mcp, streamable HTTP. Health check at `api.ref.tools/ping`. An unauthenticated request answers 401 with a JSON `error` message | | Tools | `ref_search_documentation` (`query`) and `ref_read_url` (`url`), both `readOnlyHint: true`. OpenAI deep research clients see them as `search` and `fetch` | | Prompts | `search_docs` for public documentation and `my_docs` for private resources | | Credentials | `x-ref-api-key` header, `?apiKey=` query parameter, or OAuth through Scalekit with scopes `public_docs:read` and `private_docs:read`. `?scope=user` or a team id picks the workspace | | Private sources | GitHub repositories through the Ref GitHub App or a personal access token, and uploaded PDF and Markdown files. Free: 3 small repositories, 1 large, 100 PDF pages | | Rate limits | None documented. A response on 8 October 2026 carried `ratelimit-policy: "500-in-1min"; q=500; w=60` | | Credits | One credit per search or read. Free 200 one-time, Pro 6,000 a month, Max 30,000 a month, $10 per 1,000 extra on Pro and above | | Team roles | Admin, Writer and Reader for the shared index. SAML and OIDC single sign-on for $200 a month on top of a team plan | | Audit | ref.tools/activity logs user identity, tool calls and arguments for users and teams, per the security page | | Status | ref.tools/status, eight components with 30-day bars. Four incidents listed, from 20 August to 29 November 2025 | | Sub-processors | 19 named on the security page, among them Turbopuffer (search store), Firebase, Google Cloud Run, Vertex AI, VoyageAI and OpenAI, the model providers under zero-data-retention terms. Locations not stated | | Support | help@ref.tools and hello@ref.tools, 9am to 5pm Pacific on weekdays, a reply within one business day per the docs | | Capabilities | code.docs, web.fetch | | Tags | official, mcp, hosted, local, docs, freemium, oauth, read-only, llms-txt, status-page | | JSON | https://www.anchorterminal.com/api/v1/tools/ref.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 58 | 11.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 68 | 11.1 | | Agent ergonomics | 13% | 16.2 | 67 | 10.9 | | Security & auth | 14% | 17.5 | 64 | 11.2 | | Payments & pricing | 10% | 12.5 | 35 | 4.4 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 50 | 4.4 | | Transparency & trust (editorial 53, provenance 82) | 7% | 8.8 | 68 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **59.4 → C** | ### Why each score - Reliability 58: Scored as a hosted MCP server. ref.tools/status is Ref's own page with eight components and 30-day bars, but the components and incidents are written into the site's script by hand, with no monitoring feed behind them (15 of 20). It lists four incidents, the latest from 28 to 29 November 2025, and none in the last 90 days. A hand-kept list can't be verified, so 25 of 30. No rate limit is documented. Credit allowances are published, and a response on 8 October 2026 carried `ratelimit-policy: "500-in-1min"` (5). No 429 or retry guidance was found in the reviewed documentation, though responses carry `ratelimit` headers (3). No SLA found (0). The hosted endpoint is generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 68: Both tools have typed JSON Schema inputs in the open-source server (25). docs.ref.tools/llms.txt, llms-full.txt and a Markdown copy of every docs page exist (10). The descriptions say what each tool does and that a read takes the exact URL from a search, with nothing on when not to use them (12). Each tool takes one required string with no enums or bounds, and private search is switched on by writing `ref_src=private` inside the query text (7). The README shows two worked search-and-read sequences with token counts. No error responses are documented (6). The npm package follows semver, but the repository has no changelog file and no GitHub releases, and product changes appear only in monthly newsletters (8). - Agent ergonomics 67: Two tools whose definitions and server instructions total under 1,000 characters (25). There are no size or paging parameters. The README says a session never returns the same search result twice and a read returns the most relevant sections, about 5,000 tokens at most (12). In the open-source server, failures come back as ordinary text without `isError`, and any 401 from the API becomes a message to verify an email address. No error list is documented, and the hosted server's code is closed (6). Both tools carry `readOnlyHint: true`, with no `destructiveHint` or `idempotentHint`. Both only read, so retries are safe (16). One required parameter per tool. No SDK was found (8). - Security & auth 64: OAuth through Scalekit with two scopes, `public_docs:read` and `private_docs:read`, or an API key. Key rotation and revocation aren't described in the docs (26). Less 10 because the install docs give `?apiKey=YOUR_API_KEY` in the URL as a documented option (16). Both tools are read-only, the scopes separate public from private search, and team roles limit who can add to the index (16). `ref_read_url` returns third-party web content. Ref's comparison page says Centure.ai detects and blocks prompt injection in scraped and uploaded content, which we can't test (11). ref.tools/activity logs user identity, tool calls and arguments (13). A valid security.txt and a security@ref.tools contact. SOC 2 is in progress, not complete. No bug bounty or published advisories found, and the repository has no SECURITY.md (8). - Payments & pricing 35: No x402, MPP or L402 (0). One credit per tool call and $10 per 1,000 extra credits are published without a login (20). The free plan is 200 one-time credits that never expire, not a recurring allowance, and the docs don't say whether sign-up needs a card (15). A person has to sign up in a browser to get a key (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 50: The hosted service's dated updates on 31 July and 30 September 2026 cover Ref Plans. For Ref Context, the `ref-tools-mcp` package was last published on 4 November 2025 (3.0.3), and the repository's last commits, on 28 September 2026, are dependency updates (15 of 30). Two dated updates in the last 90 days, short of three (0). Closed issues show two to five comments each, September's open pull requests have one comment each, and the docs promise a reply within one business day (15). The official MCP registry lists `tools.ref/ref-tools-mcp` under Ref's own domain, at 3.0.1 from 28 October 2025 (15). Dependabot alerts were cleared on 28 September 2026. The only workflow builds a bundle on release, with no tests (5). - Transparency & trust 68: The stdio server is MIT, and it is a thin client. The search service is closed under terms of service that forbid automated access, which the product itself needs (18). The security page describes encryption, tenant isolation, zero-data-retention terms at model providers and a seven-day limit on agent transcripts. The privacy policy of 27 May 2025 gives no retention period for queries or activity logs, no DPA was found, and Centure.ai is named on the comparison page but not in the subprocessor table (18). No deprecation policy found. The pricing page says legacy $9 and $19 subscriptions continue unchanged (3). 19 subprocessors are named with what each can see. Data locations aren't stated (14). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/ref.md (JSON https://www.anchorterminal.com/fixes/ref.json) ### What we couldn't check - unchecked: trust.ref.tools returned only its page title to our reader, so the canonical subprocessor list and any policies there were unread - unchecked: the hosted server's live tool definitions and error behaviour, which need an account. The tool definitions and errors described are from the open-source stdio server - unchecked: whether sign-up for the 200 free credits needs a card, and whether keys can be rotated or revoked at ref.tools/keys - Whether the `ratelimit-policy: "500-in-1min"` header seen on an unauthenticated response is the limit for authenticated calls - Whether Centure.ai processes customer content as a subprocessor, since the security page's table doesn't list it - Whether the terms' ban on automated or non-human access is meant to apply to MCP use - How long search queries and activity logs are kept - The comparison page still quotes a $9 a month plan for 1,000 queries, which the pricing page lists as a legacy subscription ### Sources - docs index for agents: (seen 2026-10-08) - tools reference: (seen 2026-10-08) - installation and authentication: (seen 2026-10-08) - pricing and plans: (seen 2026-10-08) - credit cost per tool: (seen 2026-10-08) - privacy, security and subprocessors: (seen 2026-10-08) - team roles: (seen 2026-10-08) - enterprise single sign-on: (seen 2026-10-08) - comparison page with the prompt-injection claim: (seen 2026-10-08) - changelog index: (seen 2026-10-08) - 30 September 2026 update: (seen 2026-10-08) - 31 July 2026 update: (seen 2026-10-08) - status page (text read from the page's script file): (seen 2026-10-08) - terms of service (text read from the page's script file): (seen 2026-10-08) - privacy policy (text read from the page's script file): (seen 2026-10-08) - security.txt: (seen 2026-10-08) - OAuth protected-resource metadata and scopes: (seen 2026-10-08) - MCP server source, tool definitions and README: (seen 2026-10-08) - issues and pull requests: (seen 2026-10-08) - npm package versions and dates: (seen 2026-10-08) - official MCP registry entries: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 82/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Ref Software, Inc | 20/20 | | Domain age | ref.tools, registered 2025-01-20 (1 year) | 3/15 | | Endpoint on the vendor's domain | api.ref.tools | 15/15 | | Terms of service | published, but our reader couldn't read it | 7/10 | | Privacy policy | published, but our reader couldn't read it | 7/10 | | Status page | ref.tools/status | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms of service name Ref Software, Inc, a Delaware corporation doing business as Ref and ref.tools, at 2261 Market Street, STE 86969, San Francisco, CA 94114. ref.tools is a single-page application. The terms, privacy policy and status page are drawn by script, and we read their text from the script files the pages load. The privacy policy is dated 27 May 2025 and defines the company only as Ref. ref.tools/.well-known/security.txt gives security@ref.tools and expires on 1 July 2027. RDAP for ref.tools gives a registration date of 2025-01-20. The changelog page is an index of monthly newsletters hosted on mailchi.mp. Its last entry is July 2026, though a 30 September 2026 update exists at mailchi.mp/ref/september2026. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://ref.tools/terms), read 2026-10-08. Our reader couldn't read it (the page has 0 words of text without a browser, so the document is drawn by script or sits elsewhere). **Privacy policy** (https://ref.tools/privacy), read 2026-10-08. Our reader couldn't read it (the page has 0 words of text without a browser, so the document is drawn by script or sits elsewhere). ## Live (updated 2026-10-08 21:53 UTC) - Right now: up, HTTP 401, 160 ms, checked 2026-10-08 21:53 UTC (mcp-initialize on `https://api.ref.tools/mcp`, asks for auth) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 173 ms · p95 270 ms - Vendor status page: unknown, no machine-readable status found - Tools: the endpoint asks for credentials before listing them (checked 2026-10-08 21:34 UTC) - Always current: https://www.anchorterminal.com/api/v1/live/ref.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Additional credits, Pro and above | $10 | per 1,000 tool calls | One credit per search or read call | | Pro plan | $50 | per month (plan) | 6,000 credits a month | | Max plan | $200 | per month (plan) | 30,000 credits a month | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Two tools, `ref_search_documentation` and `ref_read_url`, each with one required string and `readOnlyHint: true` - OAuth at `https://api.ref.tools/mcp` advertises two scopes, `public_docs:read` and `private_docs:read` - The activity log at ref.tools/activity records user identity, tool calls and arguments, per the security page - Each tool call costs one credit, and extra credits cost $10 per 1,000 on Pro and above, on a public page - The security page names 19 subprocessors with what each can see, and says model providers run under zero-data-retention terms ## Weaknesses - The install docs give `?apiKey=YOUR_API_KEY` in the URL as a documented way to authenticate - No rate limit, 429 handling or SLA was found in the reviewed documentation - The free plan is 200 one-time credits, and an account needs a browser sign-up - The `ref-tools-mcp` npm package was last published on 4 November 2025, and the changelog index stops at July 2026 - The terms of service forbid access "through automated or non-human means", which the MCP product itself requires ## Before you call it (notes for agents) 1. Send the key in the `x-ref-api-key` header, not the `?apiKey=` query parameter, so it stays out of URLs and logs 2. Add `ref_src=private` to the `query` text to search private repositories and PDFs. Searches cover public documentation only by default 3. Pass `ref_read_url` the exact URL from a search result. Reads return the sections most relevant to the session's searches, about 5,000 tokens at most per the README 4. Keep one MCP session per task. Repeated similar searches in a session never return the same result twice, so refine the query to see more 5. Treat tool errors as text. The open-source server returns failures as ordinary content without `isError` ## Connect Claude Code: ```bash claude mcp add --transport http Ref https://api.ref.tools/mcp --header "x-ref-api-key: " ``` MCP client configuration: ```json { "mcpServers": { "Ref": { "args": [ "ref-tools-mcp@latest" ], "command": "npx", "env": { "REF_API_KEY": "\u003cYOUR_API_KEY\u003e" } } } } ``` Through letme (picks today, calling later): https://letme.dev/ref. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Tavily API + MCP | BB | 76.8 | 24 | web.fetch | no | https://www.anchorterminal.com/tools/tavily-mcp.md | | You.com APIs | BB | 76.5 | 29 | web.fetch | no | https://www.anchorterminal.com/tools/you-com-api.md | | Browserbase | BB | 76.2 | 35 | web.fetch | yes | https://www.anchorterminal.com/tools/browserbase.md | | Firecrawl MCP | BB | 75.3 | 44 | web.fetch | no | https://www.anchorterminal.com/tools/firecrawl-mcp.md | | Spider | BB | 74.1 | 67 | web.fetch | yes | https://www.anchorterminal.com/tools/spider-cloud.md | | Parallel Search and Task APIs | BB | 74 | 69 | web.fetch | no | https://www.anchorterminal.com/tools/parallel-search-api.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Ref sells two products on one credit pool. Ref Context is the documentation search MCP server graded here, and Ref Plans is a plan-review workspace with its own MCP server at `api.plan.ref.tools/mcp`. The home page and the July and September 2026 updates are about Plans (source: ) - The official MCP registry lists `tools.ref/ref-tools-mcp` 3.0.1, published 28 October 2025, with the remote `https://api.ref.tools/mcp`, and `io.github.ref-tools/ref-tools-mcp` 3.0.1 for the npm package (source: ) - The README calls the repository's stdio server legacy and recommends the hosted endpoint. The search index and API behind both are closed (source: ) - The status page lists four incidents, the latest a run of search timeouts from 28 to 29 November 2025. The component list and incidents are written into the site's script, not drawn from a monitoring feed (source: ) - The terms of service say users "will not access the Services through automated or non-human means, whether through a bot, script or otherwise" and forbid using "a buying agent or purchasing agent" (source: ) - Ref's comparison page says Centure.ai screens scraped and uploaded content for prompt injection. Centure.ai is not in the subprocessor table on the security page (source: ) - SOC 2 is in progress with Vanta, not complete, per the security page (source: ) ## Compare - [Context7 vs Ref](https://www.anchorterminal.com/compare/context7-vs-ref.md): BB 73 vs C 59.4 - [Microsoft Learn MCP Server vs Ref](https://www.anchorterminal.com/compare/microsoft-learn-mcp-vs-ref.md): D 47.9 vs C 59.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on ref.tools or one of its subdomains, or the README of github.com/ref-tools/ref-tools-mcp. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "ref", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Ref on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Ref on Anchor Terminal](https://www.anchorterminal.com/badges/ref.svg)](https://www.anchorterminal.com/tools/ref) ``` Plain link: ```html Ref on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Ref is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/ref-dark.png - Light: https://www.anchorterminal.com/assets/share/ref-light.png