# Smithery (slim) > Smithery is a hosted registry and connection service for MCP servers, part of Arcade.dev since August 2026. Agents search the registry, create connections and call tools through a REST API, a per-namespace MCP endpoint, a TypeScript client or a CLI. - Full: https://www.anchorterminal.com/tools/smithery.md (~7,050 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/smithery.json · canonical https://www.anchorterminal.com/tools/smithery - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **D · 50.7/100 · rank #766 of 950 · #7 in Agent tool access · not agent-ready · confidence medium** Assessment: Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026. ## Facts - Kind: HTTP API · vendor: Smithery (Arcade.dev) · category: Agent tool access · legal entity: Clavia, Inc. (doing business as Smithery) · provenance 65/100 - Endpoint: `https://api.smithery.ai` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: REST API at `https://api.smithery.ai` (55 operations in the OpenAPI 3.1 file), connection calls at `https://smithery.run/{namespace}/{connectionId}`, a namespace MCP endpoint at `https://mcp.smithery.run/{namespace}`, the `@smithery/api` TypeScript client and the `smithery` CLI - Connections: A long-lived session to one MCP server, named by `server` (a registry name) or `mcpUrl`, with free-form `metadata` for filtering by user. States are `connected`, `disconnected`, `auth_required`, `input_required` and `error` - Credentials: API key with full namespace access, team API keys an organisation admin can revoke, and service tokens scoped by namespace, resource, operation and metadata, one hour by default and 24 at most. Token Scoping is in preview - End-user authorisation: Smithery keeps OAuth apps for popular integrations and returns a hosted `setupUrl`. Tokens refresh automatically, and a failed refresh sets the connection to `auth_required` - Registry: `GET /servers` and `GET /skills` search by full text and meaning, with `page`, `pageSize` (maximum 100), `topK` and `fields`. A server record carries `security.scanPassed` - Triggers: Connections can expose trigger types, and subscriptions deliver events to a webhook URL with a secret and a TTL - Uplink: The CLI can expose a local MCP server as a Smithery connection over `wss://uplink.smithery.run` without deploying it - Errors: JSON with `error` and `message`. Declared statuses are 400, 401, 403, 404, 409, 422, 500 and 502. No 429 is declared - Client: `@smithery/api` 0.68.0 of 20 July 2026, generated by Stainless, Apache-2.0. It retries connection errors, 408, 409, 429 and 5xx twice with backoff and times out after one minute - CLI: `smithery` 1.2.0 of 31 May 2026, AGPL-3.0, Node.js 20 or later. `--json` output is chosen automatically outside a terminal - Status: status.smithery.ai on Better Stack, three components (smithery.ai, Smithery API, Smithery Gateway), each at 100 per cent over 90 days on 9 October 2026 - Ownership: Clavia, Inc. doing business as Smithery, per the privacy notice of 20 June 2025. Acquired by Arcade.dev, announced 5 August 2026 - Scores: Reliability 60, Performance pending, Schema & documentation 76, Agent ergonomics 65, Security & auth 50, Payments & pricing 10, Task success pending, Maintenance & community 43, Transparency & trust 46 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines. · Schema & documentation, An OpenAPI 3.1 file with 35 paths and 55 operations is linked from the docs index. · Agent ergonomics, Graded as an API. · Security & auth, An API key has full namespace access. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest release found is `@smithery/api` 0.68.0 on 20 July 2026, 81 days before the check. · Transparency & trust, The editorial half. - Sources: 19, open questions: 8, both in the full twin - Capabilities: automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks - JSON: https://www.anchorterminal.com/api/v1/tools/smithery.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/smithery.svg` or a link to https://www.anchorterminal.com/tools/smithery from a page on smithery.ai or one of its subdomains, or the README of github.com/smithery-ai/cli, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Keep the API key on the backend and hand an agent a service token limited to `connections` with `read` and `execute` and a `metadata` match 2. Create connections with `PUT /connect/{namespace}/{connectionId}`, which is an upsert, and check `status.state` before calling a tool 3. On `auth_required` or `input_required`, send the person to `setupUrl`, then retry with the same `connectionId` 4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as `user-123-github.search_repositories` 5. Do not rely on `smithery skill` commands. Version 1.1.1 of the CLI removed them ## Connect ```bash npm install -g smithery@latest ``` ```bash curl -X PUT "https://smithery.run/my-app/my-browserbase" \ -H "Authorization: Bearer $SMITHERY_API_KEY" \ -H "Content-Type: application/json" \ -d '{"mcpUrl": "https://mcp.browserbase.com/mcp"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/smithery ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Composio (API + MCP) | BB | 75.1 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | https://www.anchorterminal.com/tools/composio-rube.min.md | | Unified.to MCP Server | C | 61.9 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | https://www.anchorterminal.com/tools/unified-to-mcp.min.md | | Merge Agent Handler | B | 69.5 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/merge-agent-handler.min.md | | StackOne | B | 69.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/stackone.min.md | | One | B | 66.6 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/one.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)