# Secoda (slim) > Secoda is a hosted data catalogue with lineage, monitoring and governance, which Atlassian has acquired. Agents use a REST API with a workspace API key, and a local MCP server for search, lineage and SQL. - Full: https://www.anchorterminal.com/tools/secoda.md (~8,600 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/secoda.json · canonical https://www.anchorterminal.com/tools/secoda - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **E · 44.5/100 · rank #875 of 950 · #12 in Company knowledge & data catalogues · not agent-ready · confidence medium** Assessment: The REST API reference embeds OpenAPI 3.0 definitions on every page, with `llms.txt` and Markdown copies, and the subscription agreement carries a 99.9 per cent uptime commitment. No price, trial or sign-up is published, no status page was found, and the public changelog stops at 28 October 2025 although self-hosted releases continue. ## Facts - Kind: HTTP API · vendor: Secoda, Inc. · category: Company knowledge & data catalogues · legal entity: Secoda, Inc. · provenance 59/100 - Local only (HTTP, stdio) - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under the Secoda Master Subscription Agreement. The local MCP server in secoda/secoda-mcp is MIT - Probe metrics: not measured yet (probes haven't run) - API: REST under `/api/v1` (the docs also name `/api/v2`), with create, read, update and delete for catalogue resources, tables, columns, documents, glossary terms, lineage, monitors, users, groups and teams. Base URL `api.secoda.co` (US), `eapi.secoda.co` (EU) or `aapi.secoda.co` (APAC), or the customer's own domain when self-hosted - MCP server: Local server in secoda/secoda-mcp (Python, FastMCP, MIT, version 0.1.0, last commit 26 January 2026) over stdio, or HTTP on port 5012 for Microsoft Copilot Studio. Six tools, `run_sql`, `search_data_assets`, `search_documentation`, `retrieve_entity`, `entity_lineage` and `glossary` - Credentials: Workspace API key as a Bearer token, with the access of the user who created it. No scopes, expiry or OAuth found. Sign-in to the app is by SSO, with SAML and SCIM in the plan table - Rate limits: 30 PUT, PATCH or POST calls a minute on entity endpoints, then a 429. No limit for GET requests found in the reviewed documentation - Pagination: A `page` parameter, with `links`, `meta`, `count` and `total_pages` in each list response. `filter` and `sort` are URL-encoded JSON objects. A list returns at most 10,000 resources across all pages, and bulk update takes 100 entities - Errors: HTTP 400, 403, 404, 429 and 500 with a one-line description for each operation. No error body format or error codes found - Pricing: Sales contract only. Core, Premium and Enterprise plans with no published price, and no trial or sign-up button found - SLA: 99.9 per cent monthly availability. After 60 consecutive minutes of downtime, a 5 per cent credit for each day with 30 minutes or more of unavailability, at most seven credits a month, claimed in writing within 24 hours - Hosting: AWS us-east-1, eu-central-1 or ap-southeast-1 per the subprocessor list. Single-tenant deployment on Premium and self-hosted deployment on Enterprise - Audit: Audit log under workspace settings, filterable by user, date, log type and resource, and `/api/v1/activity_log/audit_logs/` in the API. SIEM logging on Enterprise - Security: SOC 2 stated in the security policy, with documentation on request. A bug bounty by email with a reward for valid findings of CVSS 4 or higher, and a disclosure policy with a reply within 5 business days. No `security.txt` - AI data handling: Secoda AI sends workspace metadata to OpenAI, Google or Anthropic by region, and a sample of data when Run SQL is on. The Secoda AI Terms of 17 July 2025 say customer data is not used to train models without permission - Releases: Self-hosted image tags v2026.2.6 (4 August 2026), v2026.2.7 (9 September), v2026.2.8 (18 September), v2026.3.0 (5 October) and v2026.3.1 (6 October). The public changelog's last entry is v8.21.0 of 28 October 2025 - Status: No status page found on the pages read - Scores: Reliability 40, Performance pending, Schema & documentation 59, Agent ergonomics 44, Security & auth 54, Payments & pricing 0, Task success pending, Maintenance & community 60, Transparency & trust 58 · total over the 7 assessed categories - Why: Reliability, Hosted service, read on the hosted lines and graded on the REST API, with the local MCP server as a second surface. · Schema & documentation, Each API reference page embeds OpenAPI 3.0 definitions at version 8.22.66, with request and response schemas. · Agent ergonomics, Graded on the REST API. · Security & auth, A workspace API key sent as a Bearer header, with the same access as the user who created it. · Payments & pricing, Hosted service sold by contract, so the hosted rubric applies. · Maintenance & community, The docker-compose and Terraform repositories for self-hosted Secoda were tagged v2026.3.1 on 6 October 2026 (30). · Transparency & trust, Closed service with a published Master Subscription Agreement. - Sources: 38, open questions: 12, both in the full twin - Capabilities: data.catalogue, data.lineage, knowledge.search, work.docs - JSON: https://www.anchorterminal.com/api/v1/tools/secoda.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/secoda.svg` or a link to https://www.anchorterminal.com/tools/secoda from a page on secoda.co or one of its subdomains, or the README of github.com/secoda/secoda-mcp, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pick the base URL by workspace region. `app.secoda.co` uses `api.secoda.co`, `eu.secoda.co` uses `eapi.secoda.co` and `apac.secoda.co` uses `aapi.secoda.co` 2. Keep writes under 30 PUT, PATCH or POST calls a minute on entity endpoints, and back off on a 429 3. List with `/api/v1/resource/catalog` and a URL-encoded JSON `filter`. The per-type list endpoints for tables are marked deprecated, and results stop at 10,000 resources 4. Send at most 100 entities to `/api/v1/resource/all/bulk_update/` in one request 5. Add a trailing slash when an endpoint does not behave as expected, as the docs advise 6. Treat an API key as the creating user. `run_sql` in the MCP server works only when an admin has enabled Run SQL and the user has query access to the integration ## Connect ```bash curl 'https://api.secoda.co/api/v1/resource/catalog' -H 'Authorization: Bearer ' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/secoda ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Atlan | B | 62.5 | data.catalogue, data.lineage, knowledge.search, work.docs | https://www.anchorterminal.com/tools/atlan.min.md | | OpenMetadata | B | 66.6 | data.catalogue, data.lineage, work.docs | https://www.anchorterminal.com/tools/openmetadata.min.md | | Collibra | B | 64.6 | data.catalogue, knowledge.search, data.lineage | https://www.anchorterminal.com/tools/collibra.min.md | | Marmot | B | 64.4 | data.catalogue, data.lineage, work.docs | https://www.anchorterminal.com/tools/marmot.min.md | | Alation | C | 60.3 | data.catalogue, knowledge.search, data.lineage | https://www.anchorterminal.com/tools/alation.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)