Semrush API + MCP
by Semrush Inc. (an Adobe company) HTTP API in SEO & search visibility
Hosted
Semrush Inc. · semrush.com since 2008 · who's behind it
Semrush is a search marketing data platform, owned by Adobe since April 2026. Agents reach its keyword, backlink, ranking and traffic data through REST APIs with API keys or a hosted MCP server that spends the same API units.
Good for Teams already paying for Semrush who want an agent to pull keyword, backlink, ranking and traffic estimates in one place, mainly through the MCP server.
Is this your product? Claim this listing or verify it
Assessment. The hosted MCP server exposes 14 tools that load a report's parameters on demand, and version 4 API keys can be read-only, time-limited and revoked. Most reports still sit in version 3, whose single key travels in the URL and can't be revoked. No status page, OpenAPI file or API unit price was found.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.semrush.com- Auth
- OAuth or key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under the Semrush terms of service
- Tools exposed
- 14
- llms.txt
- published
- Last release
- Surfaces graded
- The public REST APIs at api.semrush.com (version 3 and version 4) and the official hosted MCP server, which the vendor's llms.txt recommends for agents
- APIs
- SEO API (version 4 Backlinks and Keyword reports; version 3 Domain, Overview, URL, subdomain and subfolder reports), Trends API (version 3), Projects API (folders in version 4; Position Tracking and Site Audit in version 3), Local API (version 4)
- MCP server
- Hosted, streamable HTTP, https://mcp.semrush.com/v2/mcp. 12 discovery tools (domain_overview, organic_research, keyword_research, competitors_research, backlinks_research, audience_research, traffic_overview, paid_search_research, shopping_research, position_tracking, site_audit, projects) plus get_report_schema and execute_report
- Credentials
- Version 4 API key in
Authorization: Apikey <key>or?key=; version 3 key in?key=only; MCP by OAuth 2.1 (scope mcp.access, dynamic client registration, PKCE) or the API key header. OAuth 2.0 device flow remains for deprecated methods - Access
- Standard API needs the SEO Business plan plus an API unit package, per the API access page. The MCP page lists Semrush One Starter and Pro+ and SEO Classic Pro and Guru with 50,000 units included. Trends API is a separate subscription, Premium through sales
- Unit costs
- Keyword metrics 20 units a request; backlinks overview 45 a request; backlinks and referring domains 40 to 45 a line; domain organic keywords 10 a line, 50 for historical data. Empty responses cost nothing. Local API calls use no units
- Unit packages
- 2, 5, 10 or 20 million units, renewed with the subscription, unused units expire. Package prices are shown in the account, not on a public page
- Rate limits
- 10 requests a second and 10 simultaneous requests per account. Trends API 10,000 requests a month by default. Listing Management Get Categories 10 a minute
- Errors
- Version 4 returns JSON with meta.request_id, error.code, error.message and error.retryable, and lists 400, 401, 403, 404, 409, 429, 499, 500, 501, 503 and 504. Version 3 returns text codes such as
ERROR 132 :: API UNITS BALANCE IS ZERO - Response control
- Version 4 has
fields,limit,offset,order_by,direction, afilterexpression language and JSON or CSV. Version 3 hasexport_columns,display_limit,display_offset,display_filter,display_sortand CSV - Audit
- API Query log in the profile with query, time, IP address, database, report type, rows, cost and remaining balance, exportable to CSV up to 50,000 rows. SEO API and Projects v4 only
- Security programme
- PCI DSS Level 1, annual penetration tests, a bug bounty on HackerOne, SAML SSO and two-factor sign-in per the security page. No SOC 2 or ISO 27001 statement on that page. No security.txt
- Data locations
- Data centres in the United States on Amazon Web Services, Google Cloud Platform and Digital Realty, per the security page. Sub-processor list last updated November 2025
- Ownership
- Semrush Inc., Boston, is the contracting entity in the terms of 25 August 2026. Adobe completed the acquisition of Semrush Holdings, Inc. on 28 April 2026
- Capabilities
- seo.keywords seo.backlinks seo.rankings seo.traffic seo.serp
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Hosted MCP server at mcp.semrush.com/v2/mcp with OAuth 2.1, dynamic client registration and 14 named tools, limited to reads
- Version 4 keys can be read-only or read and write, carry an expiry, and be revoked. An account can hold up to 100
- Every method page states its cost in API units, and
limit,fieldsandfiltercap what a call spends - llms.txt indexes for the developer site and for each API version, with dated release notes since March 2026
- API Query log records time, IP address, report type and units spent for SEO API and Projects v4 calls, with CSV export
Weaknesses
- Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked
- Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change
- No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages
- API unit package prices aren't published, and every API needs a paid subscription
- When units run short, per-line SEO and Trends reports return fewer lines instead of an error
Before you call it notes for agents
- Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then
get_report_schema, thenexecute_report - Set
limitordisplay_limiton every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50 - Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error
- Send the version 4 key as
Authorization: Apikey <key>, never as?key=. Version 3 accepts only the query parameter, so keep those URLs out of logs - Stay under 10 requests a second and 10 concurrent requests per account, and retry only when
error.retryableis true
Who's behind it provenance 75/100
- Legal entity namedSemrush Inc.20/20
- Domain agesemrush.com, registered 2008-10-03 (18 years)15/15
- Endpoint on the vendor's domainapi.semrush.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-08-25, states 6 of 7, 4 to know
TL;DR Dated 2026-08-25. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
(k) use or launch any automated system, including, “robots,” “spiders,” or “offline readers,” that sends more request messages to our servers in a given period of time than a human can reasonably produce in the same period by using a conventional browser
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(i) access the Services if you are a competitor of ours or use the Services to build a similar or competitive work
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
Notwithstanding anything contrary herein, Semrush reserves the right to cancel your subscription upon notice immediately for any reasons
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
You agree to arbitrate all Claims between you and us, that cannot be amicably resolved in accordance with the foregoing paragraph.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-08-25
Last Updated: August 25, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the Republic of Ireland
Subject to Section 2 (Dispute Resolution by Binding Arbitration), if you are located in the European Economic Area (EEA), Switzerland or the United Kingdom, this Agreement is governed by the laws of the Republic of Ireland and jurisdiction and venue shall be Dublin, Ireland.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the greater of fifty dollars and the fees paid in the 3 months before the claim
Our maximum aggregate liability to you for any damages arising from or related to this Agreement is limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Semrush may suspend, limit or terminate access to a Beta Version at any time.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives thirty days of notice before a change
We will notify you of changes to this arbitration provision by posting the amended terms on the Site or by email, in each case at least thirty (30) days before the effective date of the changes.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you do not have such authority, or if you do not agree with the terms of this Agreement, you must not accept this Agreement and may not use the Services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Customers may not use Semrush outputs as inputs or prompts to, or to train or improve, any AI system, except through Semrush's official integrations embedded into an AI system.
use, access, copy, or process any Semrush intellectual property (including insights, analyses, suggestions, graphs and other outputs from the Services, including generative AI outputs) or Semrush Confidential Information as inputs/prompts into
Noted by a second reader on 2026-10-08.
Semrush API subscribers may not send more than ten inquiries a second from one IP address, or cache information from the service for more than one month without written consent.
(i) not to forward more than ten (10) inquiries per one (1) second from one unique IP address or more than ten (10) simultaneous inquiries from one (1) Authorized User; and (ii) not to cache the information received from the Services for more than one (1) month
Noted by a second reader on 2026-10-08.
Semrush limits its total liability to the greater of 50 US dollars or the amount paid in the three months before the cause of action arose.
limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 9,558 words
Privacy policy dated 2025-10-13, states 8 of 8, 1 to know
TL;DR Dated 2025-10-13. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
limited personal data about you, such as your email address, to hash it and to share it with social network
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2025-10-13
Last Modified Date: October 13, 2025
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
…Policy explains how Semrush collects, uses, stores, discloses and otherwise processes the personal data we collect when you use and interact with our websites and apps that display or link to this Privacy Policy, register for an account and use our Services, visit our branded social media pages, register for, attend o…
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain your personal data for as long as reasonably necessary to provide the Services and fulfil the transactions you have requested, complying with our legal obligations or for other legitimate business purposes, such as maintaining business and financial records, resolving disputes, maintaining security, detectin…
Says when data sent to the service is deleted.
Says who else receives the data
This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers as a service provider or processor.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Semrush will not sell, rent, lease or otherwise provide your personal data to others, except in order to provide you with the products and services you request and as further described below, or with your permission or as required by applicable law.
A plain statement either way.
Says what rights people have over their data
It also tells you about your rights and choices with respect to your personal data, and how you can contact us if you have any questions or concerns.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@semrush.com
If you wish to update or delete your testimonial, you can contact us at privacy@semrush.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…continue to be protected pursuant to the applicable data protection law, including through the use of Standard Contractual Clauses approved by the European Commission.
The countries data goes to and the safeguard used.
The policy does not cover personal data that Semrush processes on behalf of business customers as a service provider or processor.
This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,434 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (last updated 25 August 2026) name Semrush Inc., a Delaware corporation at 800 Boylston Street, Suite 2475, Boston, MA 02199. The site footer reads © 2026 Semrush Holdings and carries an Adobe logo.
Adobe announced completion of its acquisition of Semrush Holdings, Inc. on 28 April 2026, in a press release on semrush.com. The terms and the privacy policy (last modified 13 October 2025) don't mention Adobe.
The APIs answer at api.semrush.com and the MCP server at mcp.semrush.com, with OAuth metadata pointing to oauth.semrush.com and api.semrush.com.
www.semrush.com/.well-known/security.txt returns 404. The security page gives security@semrush.com and links to a HackerOne programme.
No status page is linked from the developer docs, the home page or the security page. status.semrush.com doesn't resolve in DNS.
RDAP for semrush.com gives a registration date of 2008-10-03 and MarkMonitor Inc. as registrar.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.semrush.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/semrush.json
Notable
- The MCP server uses streamable HTTP only at https://mcp.semrush.com/v2/mcp and covers all Trends API and SEO API methods plus the read-only Projects API v3 methods source
- Version 4 keys are per integration, up to 100 an account, each read-only or read and write with an optional expiry. The version 3 key is single, automatic and can't be revoked or deleted source
- The Keyword and Backlinks reports in version 4 carry an Early Access notice, billed at version 3 rates until general availability source
- All API methods are limited to 10 requests a second and 10 simultaneous requests per account, and responses may be cached for one month at most source
- Adobe completed its acquisition of Semrush Holdings, Inc. on 28 April 2026 source
- The terms bar use of the Services or their data as input to, or for training, any artificial intelligence or machine learning technology, which we read as a limit an agent builder should check source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 6.8 | |
Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an error.retryable flag, and version 3 lists ERROR 429, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.4 | |
No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's get_report_schema tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70. | |||
| Agent ergonomics | 13%16.2 | 12.5 | |
The MCP server names 14 tools, 12 for discovery plus get_report_schema and execute_report, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has limit, offset, order_by, fields and a filter language, and version 3 has display_limit, display_offset, display_filter and export_columns (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77. | |||
| Security & auth | 14%17.5 | 9.4 | |
Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, mcp.access (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a key query parameter, and version 4 also documents ?key= (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54. | |||
| Payments & pricing | 10%12.5 | 2.1 | |
| No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.0 | |
| The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57. | |||
| Transparency & trusteditorial 59, provenance 75 | 7%8.8 | 5.9 | |
| Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59. | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 53.1 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Semrush API + MCP, or have the agent fetch /fixes/semrush.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Semrush API + MCP From Anchor Terminal's listing at https://www.anchorterminal.com/tools/semrush, the October 2026 research run, assessed 8 October 2026. Grade D, 53.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Semrush API + MCP: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 34 out of 100, up to 13.2 more on the total Why it scored 34: Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 17 out of 100, up to 10.4 more on the total Why it scored 17: No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 54 out of 100, up to 8.1 more on the total Why it scored 54: Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Schema & documentation, 70 out of 100, up to 4.9 more on the total Why it scored 70: No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Maintenance & community, 57 out of 100, up to 3.8 more on the total Why it scored 57: The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57. The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Agent ergonomics, 77 out of 100, up to 3.7 more on the total Why it scored 77: The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77. The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 7. Transparency & trust, 67 out of 100, up to 2.9 more on the total Made of editorial 59, provenance 75. Why it scored 67: Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59. The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account - unchecked: prices of API unit packages and of the Trends API, which the public pages don't show - unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty - unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access - unchecked: the HackerOne programme page, which needs JavaScript - No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points - The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both - Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition ## Weaknesses - Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked - Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change - No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages - API unit package prices aren't published, and every API needs a paid subscription - When units run short, per-line SEO and Trends reports return fewer lines instead of an error ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report` - Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50 - Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error - Send the version 4 key as `Authorization: Apikey <key>`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs - Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account
- unchecked: prices of API unit packages and of the Trends API, which the public pages don't show
- unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty
- unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access
- unchecked: the HackerOne programme page, which needs JavaScript
- No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points
- The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both
- Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition
Sources 25
- API docs index for agents developer.semrush.com · seen 2026-10-08
- MCP server guide developer.semrush.com · seen 2026-10-08
- version 4 authorisation developer.semrush.com · seen 2026-10-08
- version 3 authorisation developer.semrush.com · seen 2026-10-08
- API versions and keys developer.semrush.com · seen 2026-10-08
- API access and plans developer.semrush.com · seen 2026-10-08
- usage restrictions developer.semrush.com · seen 2026-10-08
- API unit balance and query log developer.semrush.com · seen 2026-10-08
- SEO API overview, errors and filtering developer.semrush.com · seen 2026-10-08
- Backlinks API v4 developer.semrush.com · seen 2026-10-08
- Keyword reports API v4 developer.semrush.com · seen 2026-10-08
- Domain reports API v3 developer.semrush.com · seen 2026-10-08
- release notes developer.semrush.com · seen 2026-10-08
- MCP OAuth metadata mcp.semrush.com · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- pricing semrush.com · seen 2026-10-08
- API knowledge base article semrush.com · seen 2026-10-08
- terms of service semrush.com · seen 2026-10-08
- privacy policy semrush.com · seen 2026-10-08
- DPA semrush.com · seen 2026-10-08
- sub-processors semrush.com · seen 2026-10-08
- AI services terms semrush.com · seen 2026-10-08
- security page semrush.com · seen 2026-10-08
- Adobe acquisition press release semrush.com · seen 2026-10-08
- domain registration rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid Every API needs a paid subscription, and calls spend API units. The Standard API needs the SEO Business plan plus a unit package of 2 to 20 million units, whose prices aren't on a public page. The MCP page says Semrush One Starter and Pro+ and SEO Classic Pro and Guru include 50,000 units. Our request saw plan prices in pounds, from £113 a month for SEO to £444 for Advanced. The free plan (no card, 10 reports a day) has no API units, and the 7-day trial's card requirement wasn't checked.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/semrush.xml, or this listing's score history at history.json.
Connect
First request
curl -H 'Authorization: Apikey YOUR_API_KEY' "https://api.semrush.com/apis/v4/keywords/v1/metrics?keyword=seo%20tools&country=US"
Claude Code
claude mcp add semrush https://mcp.semrush.com/v2/mcp -t http
MCP client configuration
{
"mcpServers": {
"semrush": {
"url": "https://mcp.semrush.com/v2/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/semrush
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
DataForSEO BManifold CAhrefs DSimilarweb DMoz API E
Head to head Ahrefs vs Semrush API + MCP · DataForSEO vs Semrush API + MCP · Manifold vs Semrush API + MCP · Moz API vs Semrush API + MCP · Semrush API + MCP vs Similarweb
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| DataForSEO DataForSEO OÜ | B | 64.9 | seo.keywords seo.backlinks seo.serp seo.rankings seo.traffic | no |
| Manifold Manifold (Jesse Sibley, sole trader) | C | 56.2 | seo.keywords seo.backlinks seo.serp seo.rankings seo.traffic | no |
| Ahrefs Ahrefs Pte. Ltd. | D | 49.8 | seo.keywords seo.backlinks seo.serp seo.rankings seo.traffic | no |
| Similarweb Similarweb Ltd. | D | 46 | seo.traffic seo.keywords seo.serp seo.rankings | no |
| Moz API SEOmoz, Inc. | E | 45.3 | seo.keywords seo.backlinks seo.serp seo.rankings | no |
Machine-readable
- JSON
/api/v1/tools/semrush.json· historyhistory.json· badge/badges/semrush.svg· changes feed/feeds/tools/semrush.xml - Markdown
/tools/semrush.md· slim/tools/semrush.min.md(or sendAccept: text/markdown) - Fix list
/fixes/semrush.md·/fixes/semrush.json - From a terminal
anchor tool semrush --md(the CLI) · over MCPget_tool {"slug": "semrush"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/semrush"><img src="https://www.anchorterminal.com/badges/semrush.svg" alt="Semrush API + MCP on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/semrush)<a href="https://www.anchorterminal.com/tools/semrush">Semrush API + MCP on Anchor Terminal</a>It counts on a page on semrush.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "semrush", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
