{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/dataforseo.json",
        "name": "DataForSEO",
        "score": 64.9,
        "shared": [
          "seo.keywords",
          "seo.backlinks",
          "seo.serp",
          "seo.rankings",
          "seo.traffic"
        ],
        "slug": "dataforseo"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/manifold-mcp.json",
        "name": "Manifold",
        "score": 56.2,
        "shared": [
          "seo.keywords",
          "seo.backlinks",
          "seo.serp",
          "seo.rankings",
          "seo.traffic"
        ],
        "slug": "manifold-mcp"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/ahrefs.json",
        "name": "Ahrefs",
        "score": 49.8,
        "shared": [
          "seo.keywords",
          "seo.backlinks",
          "seo.serp",
          "seo.rankings",
          "seo.traffic"
        ],
        "slug": "ahrefs"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/similarweb.json",
        "name": "Similarweb",
        "score": 46,
        "shared": [
          "seo.traffic",
          "seo.keywords",
          "seo.serp",
          "seo.rankings"
        ],
        "slug": "similarweb"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/moz-api.json",
        "name": "Moz API",
        "score": 45.3,
        "shared": [
          "seo.keywords",
          "seo.backlinks",
          "seo.serp",
          "seo.rankings"
        ],
        "slug": "moz-api"
      }
    ],
    "tool": {
      "slug": "semrush",
      "name": "Semrush API + MCP",
      "vendor": "Semrush Inc. (an Adobe company)",
      "vendorUrl": "https://www.semrush.com",
      "kind": "http-api",
      "category": "seo",
      "summary": "Semrush is a search marketing data platform, owned by Adobe since April 2026. Agents reach its keyword, backlink, ranking and traffic data through REST APIs with API keys or a hosted MCP server that spends the same API units.",
      "url": "https://www.anchorterminal.com/tools/semrush",
      "markdownUrl": "https://www.anchorterminal.com/tools/semrush.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/semrush.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/semrush.json",
      "license": "Proprietary service under the Semrush terms of service",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.semrush.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Version 4 methods take an API key in `Authorization: Apikey \u003ckey\u003e`, created in the profile with a read-only or read and write permission and an optional expiry. Version 3 methods take the account's single key as the `key` query parameter. The MCP server signs in by OAuth 2.1 against the user's Semrush account, or takes the API key header. Access is self-serve for a paying account, with no app review. Trends Premium and custom plans go through sales.",
      "pricing": "paid",
      "pricingNotes": "Every API needs a paid subscription, and calls spend API units. The Standard API needs the SEO Business plan plus a unit package of 2 to 20 million units, whose prices aren't on a public page. The MCP page says Semrush One Starter and Pro+ and SEO Classic Pro and Guru include 50,000 units. Our request saw plan prices in pounds, from £113 a month for SEO to £444 for Advanced. The free plan (no card, 10 reports a day) has no API units, and the 7-day trial's card requirement wasn't checked.",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the MCP page or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 14,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.semrush.com/api/",
      "llmsTxt": "https://developer.semrush.com/api/llms.txt",
      "capabilities": [
        "seo.keywords",
        "seo.backlinks",
        "seo.rankings",
        "seo.traffic",
        "seo.serp"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "api-key",
        "llms-txt",
        "closed-source",
        "subscription",
        "usage-units",
        "bug-bounty",
        "adobe"
      ],
      "lastRelease": "2026-09-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.1,
        "grade": "D",
        "agentReady": false,
        "rank": 487,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 57,
          "payments": 17,
          "reliability": 34,
          "schema": 70,
          "security": 54,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 34,
            "points": 6.8,
            "reason": "Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 77,
            "points": 12.51,
            "reason": "The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 54,
            "points": 9.45,
            "reason": "Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 17,
            "points": 2.13,
            "reason": "No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 57,
            "points": 4.99,
            "reason": "The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 67,
            "points": 5.86,
            "note": "editorial 59, provenance 75",
            "reason": "Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77.",
            "maintenance": "The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57.",
            "payments": "No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17.",
            "reliability": "Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34.",
            "schema": "No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70.",
            "security": "Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54.",
            "transparency": "Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59."
          },
          "sources": [
            {
              "what": "API docs index for agents",
              "url": "https://developer.semrush.com/api/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server guide",
              "url": "https://developer.semrush.com/api/introduction/semrush-mcp/",
              "seen": "2026-10-08"
            },
            {
              "what": "version 4 authorisation",
              "url": "https://developer.semrush.com/api/v4/get-started/authorization/",
              "seen": "2026-10-08"
            },
            {
              "what": "version 3 authorisation",
              "url": "https://developer.semrush.com/api/v3/get-started/authorization/",
              "seen": "2026-10-08"
            },
            {
              "what": "API versions and keys",
              "url": "https://developer.semrush.com/api/v4/introduction/api-versions/",
              "seen": "2026-10-08"
            },
            {
              "what": "API access and plans",
              "url": "https://developer.semrush.com/api/v4/get-started/api-access/",
              "seen": "2026-10-08"
            },
            {
              "what": "usage restrictions",
              "url": "https://developer.semrush.com/api/v4/introduction/api-usage-restrictions/",
              "seen": "2026-10-08"
            },
            {
              "what": "API unit balance and query log",
              "url": "https://developer.semrush.com/api/v4/get-started/api-units-balance/",
              "seen": "2026-10-08"
            },
            {
              "what": "SEO API overview, errors and filtering",
              "url": "https://developer.semrush.com/api/v4/seo/overview/",
              "seen": "2026-10-08"
            },
            {
              "what": "Backlinks API v4",
              "url": "https://developer.semrush.com/api/v4/seo/backlinks/",
              "seen": "2026-10-08"
            },
            {
              "what": "Keyword reports API v4",
              "url": "https://developer.semrush.com/api/v4/seo/keyword-reports/",
              "seen": "2026-10-08"
            },
            {
              "what": "Domain reports API v3",
              "url": "https://developer.semrush.com/api/v3/seo/domain-reports/",
              "seen": "2026-10-08"
            },
            {
              "what": "release notes",
              "url": "https://developer.semrush.com/api/v4/introduction/release-notes/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.semrush.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=semrush",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.semrush.com/pricing/seo-ai-search/",
              "seen": "2026-10-08"
            },
            {
              "what": "API knowledge base article",
              "url": "https://www.semrush.com/kb/5-api",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.semrush.com/company/legal/terms-of-service/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.semrush.com/company/legal/privacy-policy/",
              "seen": "2026-10-08"
            },
            {
              "what": "DPA",
              "url": "https://www.semrush.com/company/legal/dpa/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.semrush.com/company/legal/sub-processors/",
              "seen": "2026-10-08"
            },
            {
              "what": "AI services terms",
              "url": "https://www.semrush.com/company/legal/semrush-artificial-intelligence-services-terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.semrush.com/company/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "Adobe acquisition press release",
              "url": "https://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/semrush.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account",
            "unchecked: prices of API unit packages and of the Trends API, which the public pages don't show",
            "unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty",
            "unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access",
            "unchecked: the HackerOne programme page, which needs JavaScript",
            "No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points",
            "The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both",
            "Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition"
          ]
        },
        "negative": 0,
        "verdict": "The hosted MCP server exposes 14 tools that load a report's parameters on demand, and version 4 API keys can be read-only, time-limited and revoked. Most reports still sit in version 3, whose single key travels in the URL and can't be revoked. No status page, OpenAPI file or API unit price was found.",
        "bestFor": "Teams already paying for Semrush who want an agent to pull keyword, backlink, ranking and traffic estimates in one place, mainly through the MCP server.",
        "strengths": [
          "Hosted MCP server at mcp.semrush.com/v2/mcp with OAuth 2.1, dynamic client registration and 14 named tools, limited to reads",
          "Version 4 keys can be read-only or read and write, carry an expiry, and be revoked. An account can hold up to 100",
          "Every method page states its cost in API units, and `limit`, `fields` and `filter` cap what a call spends",
          "llms.txt indexes for the developer site and for each API version, with dated release notes since March 2026",
          "API Query log records time, IP address, report type and units spent for SEO API and Projects v4 calls, with CSV export"
        ],
        "weaknesses": [
          "Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked",
          "Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change",
          "No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages",
          "API unit package prices aren't published, and every API needs a paid subscription",
          "When units run short, per-line SEO and Trends reports return fewer lines instead of an error"
        ],
        "agentNotes": [
          "Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report`",
          "Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50",
          "Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error",
          "Send the version 4 key as `Authorization: Apikey \u003ckey\u003e`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs",
          "Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.1
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 57,
          "payments": 17,
          "reliability": 34,
          "schema": 70,
          "security": 54,
          "transparency": 59
        },
        "provenanceScore": 75
      },
      "connect": {
        "http": "curl -H 'Authorization: Apikey YOUR_API_KEY' \"https://api.semrush.com/apis/v4/keywords/v1/metrics?keyword=seo%20tools\u0026country=US\"",
        "claudeCode": "claude mcp add semrush https://mcp.semrush.com/v2/mcp -t http",
        "config": {
          "mcpServers": {
            "semrush": {
              "url": "https://mcp.semrush.com/v2/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/seo.keywords",
        "tool": "https://letme.dev/semrush"
      },
      "notable": [
        "The MCP server uses streamable HTTP only at https://mcp.semrush.com/v2/mcp and covers all Trends API and SEO API methods plus the read-only Projects API v3 methods (https://developer.semrush.com/api/introduction/semrush-mcp/)",
        "Version 4 keys are per integration, up to 100 an account, each read-only or read and write with an optional expiry. The version 3 key is single, automatic and can't be revoked or deleted (https://developer.semrush.com/api/v4/introduction/api-versions/)",
        "The Keyword and Backlinks reports in version 4 carry an Early Access notice, billed at version 3 rates until general availability (https://developer.semrush.com/api/v4/seo/backlinks/)",
        "All API methods are limited to 10 requests a second and 10 simultaneous requests per account, and responses may be cached for one month at most (https://developer.semrush.com/api/v4/introduction/api-usage-restrictions/)",
        "Adobe completed its acquisition of Semrush Holdings, Inc. on 28 April 2026 (https://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/)",
        "The terms bar use of the Services or their data as input to, or for training, any artificial intelligence or machine learning technology, which we read as a limit an agent builder should check (https://www.semrush.com/company/legal/terms-of-service/)"
      ],
      "area": "web-data",
      "details": [
        {
          "label": "Surfaces graded",
          "value": "The public REST APIs at api.semrush.com (version 3 and version 4) and the official hosted MCP server, which the vendor's llms.txt recommends for agents"
        },
        {
          "label": "APIs",
          "value": "SEO API (version 4 Backlinks and Keyword reports; version 3 Domain, Overview, URL, subdomain and subfolder reports), Trends API (version 3), Projects API (folders in version 4; Position Tracking and Site Audit in version 3), Local API (version 4)"
        },
        {
          "label": "MCP server",
          "value": "Hosted, streamable HTTP, https://mcp.semrush.com/v2/mcp. 12 discovery tools (domain_overview, organic_research, keyword_research, competitors_research, backlinks_research, audience_research, traffic_overview, paid_search_research, shopping_research, position_tracking, site_audit, projects) plus get_report_schema and execute_report"
        },
        {
          "label": "Credentials",
          "value": "Version 4 API key in `Authorization: Apikey \u003ckey\u003e` or `?key=`; version 3 key in `?key=` only; MCP by OAuth 2.1 (scope mcp.access, dynamic client registration, PKCE) or the API key header. OAuth 2.0 device flow remains for deprecated methods"
        },
        {
          "label": "Access",
          "value": "Standard API needs the SEO Business plan plus an API unit package, per the API access page. The MCP page lists Semrush One Starter and Pro+ and SEO Classic Pro and Guru with 50,000 units included. Trends API is a separate subscription, Premium through sales"
        },
        {
          "label": "Unit costs",
          "value": "Keyword metrics 20 units a request; backlinks overview 45 a request; backlinks and referring domains 40 to 45 a line; domain organic keywords 10 a line, 50 for historical data. Empty responses cost nothing. Local API calls use no units"
        },
        {
          "label": "Unit packages",
          "value": "2, 5, 10 or 20 million units, renewed with the subscription, unused units expire. Package prices are shown in the account, not on a public page"
        },
        {
          "label": "Rate limits",
          "value": "10 requests a second and 10 simultaneous requests per account. Trends API 10,000 requests a month by default. Listing Management Get Categories 10 a minute"
        },
        {
          "label": "Errors",
          "value": "Version 4 returns JSON with meta.request_id, error.code, error.message and error.retryable, and lists 400, 401, 403, 404, 409, 429, 499, 500, 501, 503 and 504. Version 3 returns text codes such as `ERROR 132 :: API UNITS BALANCE IS ZERO`"
        },
        {
          "label": "Response control",
          "value": "Version 4 has `fields`, `limit`, `offset`, `order_by`, `direction`, a `filter` expression language and JSON or CSV. Version 3 has `export_columns`, `display_limit`, `display_offset`, `display_filter`, `display_sort` and CSV"
        },
        {
          "label": "Audit",
          "value": "API Query log in the profile with query, time, IP address, database, report type, rows, cost and remaining balance, exportable to CSV up to 50,000 rows. SEO API and Projects v4 only"
        },
        {
          "label": "Security programme",
          "value": "PCI DSS Level 1, annual penetration tests, a bug bounty on HackerOne, SAML SSO and two-factor sign-in per the security page. No SOC 2 or ISO 27001 statement on that page. No security.txt"
        },
        {
          "label": "Data locations",
          "value": "Data centres in the United States on Amazon Web Services, Google Cloud Platform and Digital Realty, per the security page. Sub-processor list last updated November 2025"
        },
        {
          "label": "Ownership",
          "value": "Semrush Inc., Boston, is the contracting entity in the terms of 25 August 2026. Adobe completed the acquisition of Semrush Holdings, Inc. on 28 April 2026"
        }
      ],
      "provenance": {
        "legalEntity": "Semrush Inc.",
        "domain": "semrush.com",
        "domainRegistered": "2008-10-03",
        "endpointOnVendorDomain": true,
        "terms": "https://www.semrush.com/company/legal/terms-of-service/",
        "privacy": "https://www.semrush.com/company/legal/privacy-policy/",
        "statusPage": "",
        "changelog": "https://developer.semrush.com/api/v4/introduction/release-notes/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 25 August 2026) name Semrush Inc., a Delaware corporation at 800 Boylston Street, Suite 2475, Boston, MA 02199. The site footer reads © 2026 Semrush Holdings and carries an Adobe logo.",
          "Adobe announced completion of its acquisition of Semrush Holdings, Inc. on 28 April 2026, in a press release on semrush.com. The terms and the privacy policy (last modified 13 October 2025) don't mention Adobe.",
          "The APIs answer at api.semrush.com and the MCP server at mcp.semrush.com, with OAuth metadata pointing to oauth.semrush.com and api.semrush.com.",
          "www.semrush.com/.well-known/security.txt returns 404. The security page gives security@semrush.com and links to a HackerOne programme.",
          "No status page is linked from the developer docs, the home page or the security page. status.semrush.com doesn't resolve in DNS.",
          "RDAP for semrush.com gives a registration date of 2008-10-03 and MarkMonitor Inc. as registrar."
        ],
        "score": 75,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Semrush Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "semrush.com, registered 2008-10-03 (18 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.semrush.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.semrush.com/company/legal/terms-of-service/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-25",
            "words": 9558,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: August 25, 2026",
                "says": "Last updated 2026-08-25"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Subject to Section 2 (Dispute Resolution by Binding Arbitration), if you are located in the European Economic Area (EEA), Switzerland or the United Kingdom, this Agreement is governed by the laws of the Republic of Ireland and jurisdiction and venue shall be Dublin, Ireland.",
                "says": "The law of the Republic of Ireland"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "Our maximum aggregate liability to you for any damages arising from or related to this Agreement is limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises.",
                "says": "Capped at the greater of fifty dollars and the fees paid in the 3 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Semrush may suspend, limit or terminate access to a Beta Version at any time."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We will notify you of changes to this arbitration provision by posting the amended terms on the Site or by email, in each case at least thirty (30) days before the effective date of the changes.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not have such authority, or if you do not agree with the terms of this Agreement, you must not accept this Agreement and may not use the Services."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(k) use or launch any automated system, including, “robots,” “spiders,” or “offline readers,” that sends more request messages to our servers in a given period of time than a human can reasonably produce in the same period by using a conventional browser",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(i) access the Services if you are a competitor of ours or use the Services to build a similar or competitive work",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Notwithstanding anything contrary herein, Semrush reserves the right to cancel your subscription upon notice immediately for any reasons"
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "You agree to arbitrate all Claims between you and us, that cannot be amicably resolved in accordance with the foregoing paragraph."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Customers may not use Semrush outputs as inputs or prompts to, or to train or improve, any AI system, except through Semrush's official integrations embedded into an AI system.",
                "quote": "use, access, copy, or process any Semrush intellectual property (including insights, analyses, suggestions, graphs and other outputs from the Services, including generative AI outputs) or Semrush Confidential Information as inputs/prompts into"
              },
              {
                "date": "2026-10-08",
                "text": "Semrush API subscribers may not send more than ten inquiries a second from one IP address, or cache information from the service for more than one month without written consent.",
                "quote": "(i) not to forward more than ten (10) inquiries per one (1) second from one unique IP address or more than ten (10) simultaneous inquiries from one (1) Authorized User; and (ii) not to cache the information received from the Services for more than one (1) month"
              },
              {
                "date": "2026-10-08",
                "text": "Semrush limits its total liability to the greater of 50 US dollars or the amount paid in the three months before the cause of action arose.",
                "quote": "limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.semrush.com/company/legal/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-13",
            "words": 5434,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Modified Date: October 13, 2025",
                "says": "Last updated 2025-10-13"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "…Policy explains how Semrush collects, uses, stores, discloses and otherwise processes the personal data we collect when you use and interact with our websites and apps that display or link to this Privacy Policy, register for an account and use our Services, visit our branded social media pages, register for, attend o…"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain your personal data for as long as reasonably necessary to provide the Services and fulfil the transactions you have requested, complying with our legal obligations or for other legitimate business purposes, such as maintaining business and financial records, resolving disputes, maintaining security, detectin…",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers as a service provider or processor."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Semrush will not sell, rent, lease or otherwise provide your personal data to others, except in order to provide you with the products and services you request and as further described below, or with your permission or as required by applicable law.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "It also tells you about your rights and choices with respect to your personal data, and how you can contact us if you have any questions or concerns."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you wish to update or delete your testimonial, you can contact us at privacy@semrush.com.",
                "says": "privacy@semrush.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…continue to be protected pursuant to the applicable data protection law, including through the use of Standard Contractual Clauses approved by the European Commission.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "limited personal data about you, such as your email address, to hash it and to share it with social network"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy does not cover personal data that Semrush processes on behalf of business customers as a service provider or processor.",
                "quote": "This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/semrush.json",
      "live": {
        "slug": "semrush",
        "probe": {
          "target": "https://api.semrush.com",
          "method": "get",
          "lastAt": "2026-10-08T17:36:45.121650763Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 130,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 133,
          "p95ms24h": 189,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "securityTxt": {
          "url": "https://semrush.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:05.730669338Z"
        },
        "updatedAt": "2026-10-08T17:36:45.121650763Z"
      }
    },
    "verify": {
      "accepts": "a page on semrush.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/semrush.svg",
      "body": {
        "slug": "semrush",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/semrush",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/semrush\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/semrush.svg\" alt=\"Semrush API + MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Semrush API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/semrush.svg)](https://www.anchorterminal.com/tools/semrush)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/semrush\"\u003eSemrush API + MCP on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/semrush",
    "json": "https://www.anchorterminal.com/tools/semrush.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/semrush.md",
    "slim": "https://www.anchorterminal.com/tools/semrush.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 53.1/100 · rank #487 of 629 · #3 in SEO \u0026 search visibility · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe hosted MCP server exposes 14 tools that load a report's parameters on demand, and version 4 API keys can be read-only, time-limited and revoked. Most reports still sit in version 3, whose single key travels in the URL and can't be revoked. No status page, OpenAPI file or API unit price was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Semrush Inc. (an Adobe company) (https://www.semrush.com) |\n| Kind | HTTP API |\n| Category | SEO \u0026 search visibility (https://www.anchorterminal.com/categories/seo) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://api.semrush.com` |\n| Auth | OAuth or key · Version 4 methods take an API key in `Authorization: Apikey \u003ckey\u003e`, created in the profile with a read-only or read and write permission and an optional expiry. Version 3 methods take the account's single key as the `key` query parameter. The MCP server signs in by OAuth 2.1 against the user's Semrush account, or takes the API key header. Access is self-serve for a paying account, with no app review. Trends Premium and custom plans go through sales. |\n| Pricing | Paid (Paid) · Every API needs a paid subscription, and calls spend API units. The Standard API needs the SEO Business plan plus a unit package of 2 to 20 million units, whose prices aren't on a public page. The MCP page says Semrush One Starter and Pro+ and SEO Classic Pro and Guru include 50,000 units. Our request saw plan prices in pounds, from £113 a month for SEO to £444 for Advanced. The free plan (no card, 10 reports a day) has no API units, and the 7-day trial's card requirement wasn't checked. |\n| x402 | No · No x402, MPP or L402 in the developer docs, the MCP page or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under the Semrush terms of service |\n| Tools exposed | 14 |\n| Docs | https://developer.semrush.com/api/ |\n| llms.txt | https://developer.semrush.com/api/llms.txt |\n| Last release | 2026-09-04 |\n| Surfaces graded | The public REST APIs at api.semrush.com (version 3 and version 4) and the official hosted MCP server, which the vendor's llms.txt recommends for agents |\n| APIs | SEO API (version 4 Backlinks and Keyword reports; version 3 Domain, Overview, URL, subdomain and subfolder reports), Trends API (version 3), Projects API (folders in version 4; Position Tracking and Site Audit in version 3), Local API (version 4) |\n| MCP server | Hosted, streamable HTTP, https://mcp.semrush.com/v2/mcp. 12 discovery tools (domain_overview, organic_research, keyword_research, competitors_research, backlinks_research, audience_research, traffic_overview, paid_search_research, shopping_research, position_tracking, site_audit, projects) plus get_report_schema and execute_report |\n| Credentials | Version 4 API key in `Authorization: Apikey \u003ckey\u003e` or `?key=`; version 3 key in `?key=` only; MCP by OAuth 2.1 (scope mcp.access, dynamic client registration, PKCE) or the API key header. OAuth 2.0 device flow remains for deprecated methods |\n| Access | Standard API needs the SEO Business plan plus an API unit package, per the API access page. The MCP page lists Semrush One Starter and Pro+ and SEO Classic Pro and Guru with 50,000 units included. Trends API is a separate subscription, Premium through sales |\n| Unit costs | Keyword metrics 20 units a request; backlinks overview 45 a request; backlinks and referring domains 40 to 45 a line; domain organic keywords 10 a line, 50 for historical data. Empty responses cost nothing. Local API calls use no units |\n| Unit packages | 2, 5, 10 or 20 million units, renewed with the subscription, unused units expire. Package prices are shown in the account, not on a public page |\n| Rate limits | 10 requests a second and 10 simultaneous requests per account. Trends API 10,000 requests a month by default. Listing Management Get Categories 10 a minute |\n| Errors | Version 4 returns JSON with meta.request_id, error.code, error.message and error.retryable, and lists 400, 401, 403, 404, 409, 429, 499, 500, 501, 503 and 504. Version 3 returns text codes such as `ERROR 132 :: API UNITS BALANCE IS ZERO` |\n| Response control | Version 4 has `fields`, `limit`, `offset`, `order_by`, `direction`, a `filter` expression language and JSON or CSV. Version 3 has `export_columns`, `display_limit`, `display_offset`, `display_filter`, `display_sort` and CSV |\n| Audit | API Query log in the profile with query, time, IP address, database, report type, rows, cost and remaining balance, exportable to CSV up to 50,000 rows. SEO API and Projects v4 only |\n| Security programme | PCI DSS Level 1, annual penetration tests, a bug bounty on HackerOne, SAML SSO and two-factor sign-in per the security page. No SOC 2 or ISO 27001 statement on that page. No security.txt |\n| Data locations | Data centres in the United States on Amazon Web Services, Google Cloud Platform and Digital Realty, per the security page. Sub-processor list last updated November 2025 |\n| Ownership | Semrush Inc., Boston, is the contracting entity in the terms of 25 August 2026. Adobe completed the acquisition of Semrush Holdings, Inc. on 28 April 2026 |\n| Capabilities | seo.keywords, seo.backlinks, seo.rankings, seo.traffic, seo.serp |\n| Tags | official, hosted, mcp, oauth, api-key, llms-txt, closed-source, subscription, usage-units, bug-bounty, adobe |\n| JSON | https://www.anchorterminal.com/api/v1/tools/semrush.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 34 | 6.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 70 | 11.4 |\n| Agent ergonomics | 13% | 16.2 | 77 | 12.5 |\n| Security \u0026 auth | 14% | 17.5 | 54 | 9.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 17 | 2.1 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 57 | 5.0 |\n| Transparency \u0026 trust (editorial 59, provenance 75) | 7% | 8.8 | 67 | 5.9 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **53.1 → D** |\n\n### Why each score\n\n- Reliability 34: Graded on the hosted lines for the REST APIs and the MCP server. No public status page was found. None is linked from the developer docs, the home page or the security page, and status.semrush.com doesn't resolve (0). With no page there is no incident history to read (5). Limits are published as 10 requests a second and 10 simultaneous requests per account, with per-method limits for Listing Management (15). Version 4 documents 429 and an `error.retryable` flag, and version 3 lists `ERROR 429`, but no Retry-After header, backoff guidance or idempotency key for Projects and Local writes was found (6). The pricing page lists an Enterprise SLA without terms or a figure, and the security page cites only the infrastructure providers' 99.9 per cent target (2). Version 3 and the MCP server carry no preview label, but the version 4 Keyword and Backlinks reports the docs recommend for new work are marked Early Access (6). Total 34.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 70: No OpenAPI or similar file was found on the developer site, and the guessed paths return 404. The MCP server's `get_report_schema` tool returns a report's parameters at run time, which we count as a partial contract we couldn't read without an account (8). llms.txt at the site root, for the API and for each version, though no Markdown twins of the pages (10). Each method page describes every parameter, and the API llms.txt says which API and version to pick for each task. MCP tool descriptions weren't read (14). Version 4 parameters state type, required status and allowed values such as country codes, scope and intent, while version 3 uses coded column names like Ph and Po with CSV output (10). Every method has a request example and a response sample, version 4 documents its error object and 11 status codes, and version 3 lists its numbered errors (13). Versions 3 and 4 are documented separately with dated release notes back to March 2026 (15). Total 70.\n- Agent ergonomics 77: The MCP server names 14 tools, 12 for discovery plus `get_report_schema` and `execute_report`, so a report's parameters load only when asked for. 15 for 11 to 30 tools plus 7 for that on-demand design (22). Version 4 has `limit`, `offset`, `order_by`, `fields` and a `filter` language, and version 3 has `display_limit`, `display_offset`, `display_filter` and `export_columns` (20). Version 4 errors carry a request id and a retryable flag, version 3 answers with text codes, and a per-line report returns fewer lines without an error when units run short (15). Report calls are reads and empty responses cost nothing, but no idempotency key was found for Projects or Local writes and MCP annotations weren't read (12). Few required parameters and sensible defaults, with no official SDK found (8). Total 77.\n- Security \u0026 auth 54: Version 4 keys can be read-only or read and write, expire, and be revoked, up to 100 an account, and the MCP server uses OAuth 2.1 with PKCE and one scope, `mcp.access` (26). Version 3, which holds the Domain, Trends, Position Tracking and Site Audit reports, has one key that can't be revoked and travels only as a `key` query parameter, and version 4 also documents `?key=` (minus 10, leaving 16). We took one more point because the unit balance endpoint is documented over plain http (15). Read-only keys exist and the MCP server exposes only read methods, with no approval step for deleting a project by API (15). Responses carry third-party page titles, anchor text and ad copy, and no prompt-injection guidance was found (0). The API Query log shows time, IP address, report and cost per call for the SEO API and Projects v4, not for Trends or Local (11). The security page lists PCI DSS Level 1, annual penetration tests, a HackerOne bug bounty and security@semrush.com. No security.txt, SOC 2 or ISO 27001 statement was found (13). Total 54.\n- Payments \u0026 pricing 17: No x402, MPP or L402 (0). Plan prices are public and each method page states its cost in API units, but the price of a unit package is shown only inside the account, so 12 of 20. The free plan needs no card but has no API units, the docs say every API needs an eligible subscription, and only the Map Rank Tracker API is open to all users. We didn't check whether the 7-day trial takes a card (5). A person signs in to Semrush in a browser to create a key or approve the MCP connection (0). Total 17.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 57: The newest dated release note is 4 September 2026, 34 days before the check, for the Review Management reply endpoints (20). Four dated entries in the last 90 days, on 15 July, 19 August, 1 September and 4 September (20). A public changelog and a tech support form, with no public developer forum or issue tracker found (9). The official MCP registry lists only third-party Semrush servers, none under a Semrush namespace, and there's no official SDK. Semrush says its apps are in the Claude, ChatGPT and Perplexity directories (3). Doc pages carry update dates from August and September 2026 (5). Total 57.\n- Transparency \u0026 trust 67: Closed service with terms updated on 25 August 2026 that include API clauses on rate, caching and AI use (15). A privacy policy, a DPA, a sub-processor list and AI terms that say Semrush doesn't train models on user input. Retention is stated as long as reasonably necessary, with deletion no sooner than 30 days after termination, and the privacy policy of 13 October 2025 doesn't mention Adobe (20). Release notes mark methods deprecated on dated entries but say only that they remain operational temporarily, with no removal date or notice policy (8). Nine sub-processors listed with countries and data centres stated as in the United States. The list names Equinix where the security page names Digital Realty (16). Total 59.\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/semrush.md (JSON https://www.anchorterminal.com/fixes/semrush.json)\n\n### What we couldn't check\n\n- unchecked: the MCP server's tool definitions, input schemas and annotations, which need a signed-in Semrush account\n- unchecked: prices of API unit packages and of the Trends API, which the public pages don't show\n- unchecked: plan prices in US dollars. Our request was shown pounds, so unitPrices is empty\n- unchecked: whether the 7-day trial needs a card and whether it includes API units or MCP access\n- unchecked: the HackerOne programme page, which needs JavaScript\n- No public status page was found. If Semrush has one under another address, the reliability score is understated by up to 45 points\n- The API access page says the Standard API needs the SEO Business plan plus a unit package, while the MCP page lists four other plans with 50,000 units included and the pricing page puts MCP access on Starter. We recorded both\n- Adobe has owned Semrush since 28 April 2026. The terms still name Semrush Inc. and the privacy policy predates the acquisition\n\n### Sources\n\n- API docs index for agents: \u003chttps://developer.semrush.com/api/llms.txt\u003e (seen 2026-10-08)\n- MCP server guide: \u003chttps://developer.semrush.com/api/introduction/semrush-mcp/\u003e (seen 2026-10-08)\n- version 4 authorisation: \u003chttps://developer.semrush.com/api/v4/get-started/authorization/\u003e (seen 2026-10-08)\n- version 3 authorisation: \u003chttps://developer.semrush.com/api/v3/get-started/authorization/\u003e (seen 2026-10-08)\n- API versions and keys: \u003chttps://developer.semrush.com/api/v4/introduction/api-versions/\u003e (seen 2026-10-08)\n- API access and plans: \u003chttps://developer.semrush.com/api/v4/get-started/api-access/\u003e (seen 2026-10-08)\n- usage restrictions: \u003chttps://developer.semrush.com/api/v4/introduction/api-usage-restrictions/\u003e (seen 2026-10-08)\n- API unit balance and query log: \u003chttps://developer.semrush.com/api/v4/get-started/api-units-balance/\u003e (seen 2026-10-08)\n- SEO API overview, errors and filtering: \u003chttps://developer.semrush.com/api/v4/seo/overview/\u003e (seen 2026-10-08)\n- Backlinks API v4: \u003chttps://developer.semrush.com/api/v4/seo/backlinks/\u003e (seen 2026-10-08)\n- Keyword reports API v4: \u003chttps://developer.semrush.com/api/v4/seo/keyword-reports/\u003e (seen 2026-10-08)\n- Domain reports API v3: \u003chttps://developer.semrush.com/api/v3/seo/domain-reports/\u003e (seen 2026-10-08)\n- release notes: \u003chttps://developer.semrush.com/api/v4/introduction/release-notes/\u003e (seen 2026-10-08)\n- MCP OAuth metadata: \u003chttps://mcp.semrush.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=semrush\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.semrush.com/pricing/seo-ai-search/\u003e (seen 2026-10-08)\n- API knowledge base article: \u003chttps://www.semrush.com/kb/5-api\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.semrush.com/company/legal/terms-of-service/\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.semrush.com/company/legal/privacy-policy/\u003e (seen 2026-10-08)\n- DPA: \u003chttps://www.semrush.com/company/legal/dpa/\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.semrush.com/company/legal/sub-processors/\u003e (seen 2026-10-08)\n- AI services terms: \u003chttps://www.semrush.com/company/legal/semrush-artificial-intelligence-services-terms/\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.semrush.com/company/security/\u003e (seen 2026-10-08)\n- Adobe acquisition press release: \u003chttps://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.org/domain/semrush.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 75/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Semrush Inc. | 20/20 |\n| Domain age | semrush.com, registered 2008-10-03 (18 years) | 15/15 |\n| Endpoint on the vendor's domain | api.semrush.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe terms of service (last updated 25 August 2026) name Semrush Inc., a Delaware corporation at 800 Boylston Street, Suite 2475, Boston, MA 02199. The site footer reads © 2026 Semrush Holdings and carries an Adobe logo.\n\nAdobe announced completion of its acquisition of Semrush Holdings, Inc. on 28 April 2026, in a press release on semrush.com. The terms and the privacy policy (last modified 13 October 2025) don't mention Adobe.\n\nThe APIs answer at api.semrush.com and the MCP server at mcp.semrush.com, with OAuth metadata pointing to oauth.semrush.com and api.semrush.com.\n\nwww.semrush.com/.well-known/security.txt returns 404. The security page gives security@semrush.com and links to a HackerOne programme.\n\nNo status page is linked from the developer docs, the home page or the security page. status.semrush.com doesn't resolve in DNS.\n\nRDAP for semrush.com gives a registration date of 2008-10-03 and MarkMonitor Inc. as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.semrush.com/company/legal/terms-of-service/), read 2026-10-08, dated 2026-08-25, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(k) use or launch any automated system, including, “robots,” “spiders,” or “offline readers,” that sends more request messages to our servers in a given period of time than a human can reasonably produce in the same period by using a conventional browser\"\n- To know. Restricts benchmarking or competitive use (costs points). \"(i) access the Services if you are a competitor of ours or use the Services to build a similar or competitive work\"\n- To know. Says access can be ended without notice or for any reason. \"Notwithstanding anything contrary herein, Semrush reserves the right to cancel your subscription upon notice immediately for any reasons\"\n- To know. Requires arbitration or waives class actions. \"You agree to arbitrate all Claims between you and us, that cannot be amicably resolved in accordance with the foregoing paragraph.\"\n- Gives the date it was last updated. Last updated 2026-08-25.\n- Names the governing law or courts. The law of the Republic of Ireland.\n- States a limit on its liability. Capped at the greater of fifty dollars and the fees paid in the 3 months before the claim.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Customers may not use Semrush outputs as inputs or prompts to, or to train or improve, any AI system, except through Semrush's official integrations embedded into an AI system. \"use, access, copy, or process any Semrush intellectual property (including insights, analyses, suggestions, graphs and other outputs from the Services, including generative AI outputs) or Semrush Confidential Information as inputs/prompts into\"\n- Also in the text (2026-10-08). Semrush API subscribers may not send more than ten inquiries a second from one IP address, or cache information from the service for more than one month without written consent. \"(i) not to forward more than ten (10) inquiries per one (1) second from one unique IP address or more than ten (10) simultaneous inquiries from one (1) Authorized User; and (ii) not to cache the information received from the Services for more than one (1) month\"\n- Also in the text (2026-10-08). Semrush limits its total liability to the greater of 50 US dollars or the amount paid in the three months before the cause of action arose. \"limited to the greater of (a) fifty dollars (US $50) or (b) the aggregate amount you have paid to us under this Agreement within the three (3) month period preceding the date that applicable cause of action arises.\"\n\n**Privacy policy** (https://www.semrush.com/company/legal/privacy-policy/), read 2026-10-08, dated 2025-10-13, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"limited personal data about you, such as your email address, to hash it and to share it with social network\"\n- Gives the date it was last updated. Last updated 2025-10-13.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@semrush.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The policy does not cover personal data that Semrush processes on behalf of business customers as a service provider or processor. \"This Privacy Policy does not apply to our handling of personal data that we process on behalf of our business customers\"\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 400, 130 ms, checked 2026-10-08 17:36 UTC (get on `https://api.semrush.com`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 133 ms · p95 189 ms\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/semrush.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Hosted MCP server at mcp.semrush.com/v2/mcp with OAuth 2.1, dynamic client registration and 14 named tools, limited to reads\n- Version 4 keys can be read-only or read and write, carry an expiry, and be revoked. An account can hold up to 100\n- Every method page states its cost in API units, and `limit`, `fields` and `filter` cap what a call spends\n- llms.txt indexes for the developer site and for each API version, with dated release notes since March 2026\n- API Query log records time, IP address, report type and units spent for SEO API and Projects v4 calls, with CSV export\n\n## Weaknesses\n\n- Domain, URL, Trends, Position Tracking and Site Audit reports are version 3 only, where the one key is a URL parameter and can't be revoked\n- Version 4 Keyword and Backlinks reports are labelled Early Access, with endpoints, formats and pricing subject to change\n- No public status page, SLA terms, OpenAPI file or official SDK found in the reviewed pages\n- API unit package prices aren't published, and every API needs a paid subscription\n- When units run short, per-line SEO and Trends reports return fewer lines instead of an error\n\n## Before you call it (notes for agents)\n\n1. Use the MCP server at https://mcp.semrush.com/v2/mcp where the host supports it. Call a discovery tool, then `get_report_schema`, then `execute_report`\n2. Set `limit` or `display_limit` on every per-line report. A backlinks row costs 40 to 45 units and a historical keyword row 50\n3. Check the unit balance before large pulls. A per-line report returns only the lines the balance covers, with no error\n4. Send the version 4 key as `Authorization: Apikey \u003ckey\u003e`, never as `?key=`. Version 3 accepts only the query parameter, so keep those URLs out of logs\n5. Stay under 10 requests a second and 10 concurrent requests per account, and retry only when `error.retryable` is true\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -H 'Authorization: Apikey YOUR_API_KEY' \"https://api.semrush.com/apis/v4/keywords/v1/metrics?keyword=seo%20tools\u0026country=US\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add semrush https://mcp.semrush.com/v2/mcp -t http\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"semrush\": {\n      \"url\": \"https://mcp.semrush.com/v2/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/semrush. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| DataForSEO | B | 64.9 | 244 | seo.keywords, seo.backlinks, seo.serp, seo.rankings, seo.traffic | no | https://www.anchorterminal.com/tools/dataforseo.md |\n| Manifold | C | 56.2 | 438 | seo.keywords, seo.backlinks, seo.serp, seo.rankings, seo.traffic | no | https://www.anchorterminal.com/tools/manifold-mcp.md |\n| Ahrefs | D | 49.8 | 526 | seo.keywords, seo.backlinks, seo.serp, seo.rankings, seo.traffic | no | https://www.anchorterminal.com/tools/ahrefs.md |\n| Similarweb | D | 46 | 566 | seo.traffic, seo.keywords, seo.serp, seo.rankings | no | https://www.anchorterminal.com/tools/similarweb.md |\n| Moz API | E | 45.3 | 571 | seo.keywords, seo.backlinks, seo.serp, seo.rankings | no | https://www.anchorterminal.com/tools/moz-api.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server uses streamable HTTP only at https://mcp.semrush.com/v2/mcp and covers all Trends API and SEO API methods plus the read-only Projects API v3 methods (source: \u003chttps://developer.semrush.com/api/introduction/semrush-mcp/\u003e)\n- Version 4 keys are per integration, up to 100 an account, each read-only or read and write with an optional expiry. The version 3 key is single, automatic and can't be revoked or deleted (source: \u003chttps://developer.semrush.com/api/v4/introduction/api-versions/\u003e)\n- The Keyword and Backlinks reports in version 4 carry an Early Access notice, billed at version 3 rates until general availability (source: \u003chttps://developer.semrush.com/api/v4/seo/backlinks/\u003e)\n- All API methods are limited to 10 requests a second and 10 simultaneous requests per account, and responses may be cached for one month at most (source: \u003chttps://developer.semrush.com/api/v4/introduction/api-usage-restrictions/\u003e)\n- Adobe completed its acquisition of Semrush Holdings, Inc. on 28 April 2026 (source: \u003chttps://www.semrush.com/news/455953-adobe-completes-semrush-acquisition-strengthening-cx-enterprise-with-enhanced-brand-visibility-capabilities/\u003e)\n- The terms bar use of the Services or their data as input to, or for training, any artificial intelligence or machine learning technology, which we read as a limit an agent builder should check (source: \u003chttps://www.semrush.com/company/legal/terms-of-service/\u003e)\n\n## Compare\n\n- [Ahrefs vs Semrush API + MCP](https://www.anchorterminal.com/compare/ahrefs-vs-semrush.md): D 49.8 vs D 53.1\n- [DataForSEO vs Semrush API + MCP](https://www.anchorterminal.com/compare/dataforseo-vs-semrush.md): B 64.9 vs D 53.1\n- [Manifold vs Semrush API + MCP](https://www.anchorterminal.com/compare/manifold-mcp-vs-semrush.md): C 56.2 vs D 53.1\n- [Moz API vs Semrush API + MCP](https://www.anchorterminal.com/compare/moz-api-vs-semrush.md): E 45.3 vs D 53.1\n- [Semrush API + MCP vs Similarweb](https://www.anchorterminal.com/compare/semrush-vs-similarweb.md): D 53.1 vs D 46\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on semrush.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"semrush\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/semrush\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/semrush.svg\" alt=\"Semrush API + MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Semrush API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/semrush.svg)](https://www.anchorterminal.com/tools/semrush)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/semrush\"\u003eSemrush API + MCP on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Semrush API + MCP is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/semrush-dark.png\n- Light: https://www.anchorterminal.com/assets/share/semrush-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "SEO \u0026 search visibility",
        "url": "https://www.anchorterminal.com/categories/seo"
      },
      {
        "name": "Semrush API + MCP",
        "url": ""
      }
    ],
    "description": "Semrush is a search marketing data platform, owned by Adobe since April 2026. Agents reach its keyword, backlink, ranking and traffic data through REST APIs with API keys or a hosted MCP server that spends the same API units.",
    "facts": [
      "rank #487 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Semrush API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/tools-semrush.png",
    "path": "/tools/semrush",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Semrush API + MCP review for AI agents, grade D (53.1/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/semrush"
  },
  "tokens": {
    "markdown": 7750,
    "slim": 2030
  },
  "version": 1
}
