# Smithery > Smithery is a hosted registry and connection service for MCP servers, part of Arcade.dev since August 2026. Agents search the registry, create connections and call tools through a REST API, a per-namespace MCP endpoint, a TypeScript client or a CLI. - Canonical: https://www.anchorterminal.com/tools/smithery - Markdown: https://www.anchorterminal.com/tools/smithery.md (~7,050 tokens) - Slim: https://www.anchorterminal.com/tools/smithery.min.md (~1,730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/smithery.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## Overview **Grade D · 50.7/100 · rank #766 of 950 · #7 in Agent tool access · not agent-ready · confidence medium** ## Assessment Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026. ## Facts | Field | Value | | --- | --- | | Vendor | Smithery (Arcade.dev) (https://smithery.ai) | | Kind | HTTP API | | Category | Agent tool access (https://www.anchorterminal.com/categories/aggregator) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://api.smithery.ai` | | Auth | OAuth or key · A person signs in at smithery.ai and creates an API key, which has full access to the namespace and is sent as a Bearer token. `POST /tokens` mints service tokens limited by namespace, resource (connections, servers, namespaces, skills), operation (read, write, execute) and connection metadata, with a default lifetime of one hour and a maximum of 24. Organisation admins can create, list and revoke team API keys. The CLI signs in with OAuth in a browser. Upstream services are authorised by each end user on a hosted setup page, and Smithery stores and refreshes those credentials. Token Scoping is marked preview. | | Pricing | Freemium (Freemium) · Prices were not established. smithery.ai/pricing is drawn by script and showed our reader only the navigation. Arcade's announcement of 5 August 2026 says people can sign up for free. Whether a card is needed, what a paid plan costs and whether tool calls are metered were not read (checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI file or the CLI source. The pricing page is drawn by script and was not read (checked 2026-10-09). | | Licence | Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT | | Packages | npm: `@smithery/api`; npm: `smithery` | | Source | https://github.com/smithery-ai/cli | | Docs | https://smithery.ai/docs | | llms.txt | https://smithery.ai/docs/llms.txt | | Last release | 2026-07-20 | | GitHub stars | 840 (as of 2026-10-09) | | npm downloads / week | 2,729 | | Surfaces | REST API at `https://api.smithery.ai` (55 operations in the OpenAPI 3.1 file), connection calls at `https://smithery.run/{namespace}/{connectionId}`, a namespace MCP endpoint at `https://mcp.smithery.run/{namespace}`, the `@smithery/api` TypeScript client and the `smithery` CLI | | Connections | A long-lived session to one MCP server, named by `server` (a registry name) or `mcpUrl`, with free-form `metadata` for filtering by user. States are `connected`, `disconnected`, `auth_required`, `input_required` and `error` | | Credentials | API key with full namespace access, team API keys an organisation admin can revoke, and service tokens scoped by namespace, resource, operation and metadata, one hour by default and 24 at most. Token Scoping is in preview | | End-user authorisation | Smithery keeps OAuth apps for popular integrations and returns a hosted `setupUrl`. Tokens refresh automatically, and a failed refresh sets the connection to `auth_required` | | Registry | `GET /servers` and `GET /skills` search by full text and meaning, with `page`, `pageSize` (maximum 100), `topK` and `fields`. A server record carries `security.scanPassed` | | Triggers | Connections can expose trigger types, and subscriptions deliver events to a webhook URL with a secret and a TTL | | Uplink | The CLI can expose a local MCP server as a Smithery connection over `wss://uplink.smithery.run` without deploying it | | Errors | JSON with `error` and `message`. Declared statuses are 400, 401, 403, 404, 409, 422, 500 and 502. No 429 is declared | | Client | `@smithery/api` 0.68.0 of 20 July 2026, generated by Stainless, Apache-2.0. It retries connection errors, 408, 409, 429 and 5xx twice with backoff and times out after one minute | | CLI | `smithery` 1.2.0 of 31 May 2026, AGPL-3.0, Node.js 20 or later. `--json` output is chosen automatically outside a terminal | | Status | status.smithery.ai on Better Stack, three components (smithery.ai, Smithery API, Smithery Gateway), each at 100 per cent over 90 days on 9 October 2026 | | Ownership | Clavia, Inc. doing business as Smithery, per the privacy notice of 20 June 2025. Acquired by Arcade.dev, announced 5 August 2026 | | Capabilities | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | | Tags | hosted, mcp, registry, freemium, api-key, oauth, openapi, llms-txt, typescript, cli, status-page, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/smithery.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 60 | 12.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 76 | 12.3 | | Agent ergonomics | 13% | 16.2 | 65 | 10.6 | | Security & auth | 14% | 17.5 | 50 | 8.8 | | Payments & pricing | 10% | 12.5 | 10 | 1.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 43 | 3.8 | | Transparency & trust (editorial 27, provenance 65) | 7% | 8.8 | 46 | 4.0 | | Negative events | up to −15 | up to −15 | 22 May 2026. CLI release 1.1.1 removed the `smithery skill` subcommand, and on 9 October 2026 the CLI docs page and the repository README still tell users to run `smithery skill search` and `smithery skill add`. A stale claim in the docs, so 2 points (https://github.com/smithery-ai/cli/blob/main/CHANGELOG.md, https://smithery.ai/docs/concepts/cli.md). | -2 | | **Total** | | | | **50.7 → D** | ### Why each score - Reliability 60: Read with the hosted lines. status.smithery.ai on Better Stack lists the site, the API and the gateway (20). Each shows 100 per cent uptime over 90 days. The page's incident list is a script-drawn tab and was not read, so 25 of 30 (25). No rate limits were found in the docs index or the API description (0). The API description declares no 429. The TypeScript client retries 408, 409, 429 and 5xx twice with backoff, and the `PUT` endpoints are described as idempotent upserts. No retry guidance for tool calls was found (8). No SLA was found (0). The connection API carries no beta label, while Token Scoping and the typed SDKs are marked preview and the client is at 0.68 (7). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 76: An OpenAPI 3.1 file with 35 paths and 55 operations is linked from the docs index. We read the description file, not the rendered reference (25). `/docs/llms.txt`, a Markdown twin of every page and a docs MCP server (10). Every operation has a description, mostly one line, some naming the scope needed or the replacement for a deprecated call. None says when not to use it (12). 24 enums, length limits and patterns on names, and `additionalProperties: false` on most objects. Tool arguments and results are open objects, as a pass-through must be (10). 161 examples in the file, curl, TypeScript and CLI samples in the guides, and declared 400, 401, 403, 404, 409 and 422 responses. No error catalogue was found (11). The API states version 1.0.0 with no version in the path and no API changelog. The client and CLI changelogs are dated, and three operations are marked deprecated (8). - Agent ergonomics 65: Graded as an API. Registry lists take `fields`, the CLI has `tool find` and `tool get`, and one call lists tools across a namespace. The namespace MCP endpoint loads every connection's tools, so context grows with the number of connections (15). `page` and `pageSize` up to 100, `cursor` and `limit` on connections, and metadata filters (16). Errors carry `error` and `message`, and a connection that needs action returns `auth_required` or `input_required` with `setupUrl` and the missing fields (15). Upserts are idempotent and the client retries safely. Tool calls take no idempotency key, and whether upstream MCP annotations are passed through was not established (10). A namespace and connection ID are created when omitted. One official client language, TypeScript, plus the CLI (9). - Security & auth 50: An API key has full namespace access. Service tokens are scoped by namespace, resource, operation and metadata, last 24 hours at most and can be narrowed, and team keys can be revoked. Token Scoping is in preview (26). Read-only and execute-only tokens are documented. No approval step for destructive tools was found (12). Connected servers return third-party content. A registry record carries `security.scanPassed`, and no prompt-injection guidance was found (4). Runtime logs by invocation exist for people who publish a server. No call log for connection users was found (5). The docs say stored credentials are encrypted and write-only. security.txt answered 404, and no certification, bounty or disclosure policy was found beyond a contact address (3). - Payments & pricing 10: No x402, MPP or L402 (0). The pricing page is drawn by script and was not read, so no price is scored. This is a limit of our reading and not a finding about the vendor (0). Arcade's announcement says sign-up is free. Whether a card is needed was not established, so half marks (10). A person signs in through a browser to get an API key or to log the CLI in (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 43: The newest release found is `@smithery/api` 0.68.0 on 20 July 2026, 81 days before the check. The CLI's last release and last commit are 1.2.0 on 31 May 2026 (20). One release in the last 90 days (0). The CLI repository, now under arcadeai-labs, shows 51 open issues and no push since 31 May. The issues themselves were not read, and a Discord server is linked for support (6). One current official client, in TypeScript (10). Both repositories carry CI workflows, lockfiles and release automation (7). - Transparency & trust 46: The editorial half. The hosted service is closed and no terms of service were found. The CLI is AGPL-3.0, the client Apache-2.0 and the credential layer MIT (12). The privacy notice of 20 June 2025 gives no retention periods, says customer content is used to improve products, describes targeted advertising, and links a Data Policy that answers 404. A data processing agreement is available on request (8). Deprecated operations are marked in the API description with their replacements, with no dates and no policy (5). Stripe is the only processor named, and no hosting location or sub-processor list was found (2). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/smithery.md (JSON https://www.anchorterminal.com/fixes/smithery.json) ### What we couldn't check - unchecked: the pricing page, which is drawn by script. Plans, unit prices, the free allowance and whether a card is needed are unknown, and Payments is scored without them. - unchecked: the status page's incident list, a script-drawn tab. - unchecked: the open issues in the CLI repository, the Uplink, Triggers and Publish guides, and the second API description hosted by Stainless. - No terms of service were found for the hosted service. Whether Arcade's terms now govern Smithery accounts was not established. - The privacy notice's Data Policy link answers 404, so how Smithery handles data passing through connections is not stated anywhere we read. - Whether Smithery will remain a separate product under Arcade. The announcement says to keep using smithery.ai and gives no plan or date. - The lead was right about the interface. It did not mention the acquisition by Arcade.dev, and data/tools/arcade.json is a separate listing with its own domain, API and terms. - `githubStars` is the CLI repository's count. The number of servers in the registry was not established. ### Sources - robots.txt, which disallows `/api/`, `/_next/`, `/admin/`, `/settings/` and `/deploy/` and nothing we read: (seen 2026-10-09) - home page: (seen 2026-10-09) - docs index: (seen 2026-10-09) - Connect to MCPs guide: (seen 2026-10-09) - Token Scoping guide: (seen 2026-10-09) - CLI docs: (seen 2026-10-09) - OpenAPI description, read as the file and not the rendered reference: (seen 2026-10-09) - Call tool reference page: (seen 2026-10-09) - privacy notice, last updated 20 June 2025: (seen 2026-10-09) - pricing page, navigation only: (seen 2026-10-09) - about page: (seen 2026-10-09) - status page (its robots.txt answered 200 with an empty body): (seen 2026-10-09) - Arcade's acquisition announcement of 5 August 2026: (seen 2026-10-09) - CLI source, changelog and tags, read from a shallow clone: (seen 2026-10-09) - TypeScript client README, changelog, tags and SECURITY.md, read from a shallow clone: (seen 2026-10-09) - agent.pw README and licence, read from a shallow clone: (seen 2026-10-09) - CLI repository record, which redirects to arcadeai-labs/smithery-cli: (seen 2026-10-09) - npm package records and weekly downloads: (seen 2026-10-09) - RDAP record for smithery.ai: (seen 2026-10-09) ## Who's behind it (provenance 65/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Clavia, Inc. (doing business as Smithery) | 20/20 | | Domain age | smithery.ai, registered 2024-12-10 (1 year) | 3/15 | | Endpoint on the vendor's domain | api.smithery.ai | 15/15 | | Terms of service | not found | 0/10 | | Privacy policy | read, states 4 of the 8 things a reader expects | 7/10 | | Status page | status.smithery.ai | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Smithery Privacy Notice, last updated 20 June 2025, names Clavia, Inc. doing business as Smithery and covers the Smithery platform and the smithery.ai website. It predates the acquisition and does not name Arcade. No terms of service were found. The home page, the pricing page, the about page and the docs link only the privacy notice, so `terms` is left out. The privacy notice links a Data Policy at https://smithery.ai/docs/use/data-policy, which answered 404 on 9 October 2026. Arcade.dev announced the acquisition of Smithery on 5 August 2026. The acquiring company's legal name was not read. The management API answers at api.smithery.ai. Connection calls, the namespace MCP endpoint and Uplink use a second domain, smithery.run. smithery.ai/.well-known/security.txt answered 404. The client repository's SECURITY.md sends reports about the service to contact@smithery.ai. RDAP gives a registration date of 2024-12-10 for smithery.ai, a transfer on 10 September 2026 and Cloudflare as registrar. The changelog link is the TypeScript client's. No dated changelog for the hosted service was found. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy** (https://smithery.ai/privacy), read 2026-10-09, dated 2025-06-20, states 4 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "We may share a common account identifier (such as a hashed email address or user ID) with our third-party advertising partners to help link the personal data we and our third-party partners collect to the same person, or otherwise target advertising to an individual on a third-party website or platform." - Gives the date it was last updated. Last updated 2025-06-20. - Not found in the text. Says how long data is kept. - Not found in the text. Says what rights people have over their data. - Not found in the text. Gives a privacy contact. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Smithery's business partners may use personal data for their own business and commercial purposes, including marketing their own products. "Our business partners may use your personal data for their own business and commercial purposes, including to improve their products and services and to send you information about their products and services." - Also in the text (2026-10-08). Third-party technologies on the service may record mouse movements, clicks and keystrokes, and what a user enters into the products or chat. "These third-party technologies may also record information you enter when you interact with our products or services, or engage in chat features or other communication platforms we provide." - Also in the text (2026-10-08). Customer content sent to the products, including content about a customer's servers, is used to improve the products as well as to run them. "We use this content primarily to provide you with our products and services, to facilitate your requests, and to improve our products and services." ## Live (updated 2026-10-10 05:39 UTC) - Right now: up, HTTP 404, 190 ms, checked 2026-10-10 05:39 UTC (get on `https://api.smithery.ai`) - Uptime 24h 100.0% (143 probes) · 30 days 100.0% (143 probes) · p50 194 ms · p95 316 ms - Vendor status page: unknown, no machine-readable status found - github `smithery-ai/cli` v1.2.0, released 2026-05-31 - npm `@smithery/api` 0.68.0 - npm `smithery` 1.2.0 - Watching changelog - Watching privacy - Always current: https://www.anchorterminal.com/api/v1/live/smithery.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Service tokens are scoped by namespace, resource, operation (read, write, execute) and connection metadata, expire within 24 hours and can be narrowed further - An OpenAPI 3.1 file with 55 operations, `/docs/llms.txt` and a Markdown twin of every docs page - Connections report `auth_required` or `input_required` with a hosted `setupUrl` and the list of missing fields - Stored credentials are write-only per the docs, and the credential layer, agent.pw, is published under MIT - The status page shows 100 per cent uptime over 90 days for the site, the API and the gateway ## Weaknesses - No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found - The privacy notice links a Data Policy at `/docs/use/data-policy`, which answers 404 - No rate limits, 429 response or SLA appear in the docs or the API description - The CLI repository has had no commit since 31 May 2026 and the API client's last release is 0.68.0 of 20 July 2026 - The CLI docs and README still list `smithery skill` commands that release 1.1.1 removed on 22 May 2026 - Token Scoping and the typed SDKs are marked preview, with breaking changes possible without notice ## Before you call it (notes for agents) 1. Keep the API key on the backend and hand an agent a service token limited to `connections` with `read` and `execute` and a `metadata` match 2. Create connections with `PUT /connect/{namespace}/{connectionId}`, which is an upsert, and check `status.state` before calling a tool 3. On `auth_required` or `input_required`, send the person to `setupUrl`, then retry with the same `connectionId` 4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as `user-123-github.search_repositories` 5. Do not rely on `smithery skill` commands. Version 1.1.1 of the CLI removed them ## Connect Install: ```bash npm install -g smithery@latest ``` First request: ```bash curl -X PUT "https://smithery.run/my-app/my-browserbase" \ -H "Authorization: Bearer $SMITHERY_API_KEY" \ -H "Content-Type: application/json" \ -d '{"mcpUrl": "https://mcp.browserbase.com/mcp"}' ``` Through letme (picks today, calling later): https://letme.dev/smithery. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Composio (API + MCP) | BB | 75.1 | 55 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | no | https://www.anchorterminal.com/tools/composio-rube.md | | Unified.to MCP Server | C | 61.9 | 455 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | no | https://www.anchorterminal.com/tools/unified-to-mcp.md | | Merge Agent Handler | B | 69.5 | 183 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/merge-agent-handler.md | | StackOne | B | 69.1 | 198 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/stackone.md | | One | B | 66.6 | 282 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/one.md | | Pipedream API + MCP | B | 65.5 | 315 | automation.apps, automation.webhooks, automation.auth, agent.tools | no | https://www.anchorterminal.com/tools/pipedream.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Arcade.dev announced on 5 August 2026 that it had acquired Smithery, and every smithery.ai page carries a banner saying so (source: ) - A namespace URL, `https://mcp.smithery.run/{namespace}`, puts every connection in a namespace behind one MCP endpoint, with tool names prefixed by connection ID (source: ) - The docs say credentials are encrypted and write-only, and that the auth and credential layer is the open-source agent.pw (source: ) - The CLI repository now answers at arcadeai-labs/smithery-cli, with 840 stars, 51 open issues and a last push on 31 May 2026 (source: ) - The CLI asks for consent before sending analytics, and consent defaults to off in its settings file (source: ) - npm counted 2,729 downloads of `@smithery/api` and 770 of `smithery` in the week to 7 October 2026 (source: ) - #7 of 8 in Best agent tool access platforms: https://www.anchorterminal.com/best/aggregator/index.md - All 28 tool access comparisons: https://www.anchorterminal.com/compare/aggregator/index.md ## Compare - [Composio (API + MCP) vs Smithery](https://www.anchorterminal.com/compare/composio-rube-vs-smithery.md): BB 75.1 vs D 50.7 - [Merge Agent Handler vs Smithery](https://www.anchorterminal.com/compare/merge-agent-handler-vs-smithery.md): B 69.5 vs D 50.7 - [One vs Smithery](https://www.anchorterminal.com/compare/one-vs-smithery.md): B 66.6 vs D 50.7 - [Smithery vs StackOne](https://www.anchorterminal.com/compare/smithery-vs-stackone.md): D 50.7 vs B 69.1 - [Smithery vs Unified.to MCP Server](https://www.anchorterminal.com/compare/smithery-vs-unified-to-mcp.md): D 50.7 vs C 61.9 - [Smithery vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/smithery-vs-zapier-mcp.md): D 50.7 vs C 58.1 - [letme vs Smithery](https://www.anchorterminal.com/compare/letme-vs-smithery.md): F 36.4 vs D 50.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on smithery.ai or one of its subdomains, or the README of github.com/smithery-ai/cli. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "smithery", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Smithery on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Smithery on Anchor Terminal](https://www.anchorterminal.com/badges/smithery.svg)](https://www.anchorterminal.com/tools/smithery) ``` Plain link: ```html Smithery on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Smithery is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/smithery-dark.png - Light: https://www.anchorterminal.com/assets/share/smithery-light.png