# Vespa > Vespa is an open-source search engine from Vespa.ai AS for vector, text and hybrid retrieval with ranking, run self-hosted or on Vespa Cloud. Agents reach it through HTTP query and document APIs, the Vespa CLI and a Python client. - Canonical: https://www.anchorterminal.com/tools/vespa - Markdown: https://www.anchorterminal.com/tools/vespa.md (~6,800 tokens) - Slim: https://www.anchorterminal.com/tools/vespa.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/vespa.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade BB · 70/100 · rank #157 of 842 · #4 in Retrieval & vector search · agent-ready · confidence medium** ## Assessment Vespa Cloud publishes hourly unit prices, a 99.5% uptime agreement for paying customers and a trial with $300 of credits and no card. Every call needs an application package deployed first, no OpenAPI file was found in the reviewed documentation, and Vespa.ai says it has no official public MCP server. ## Facts | Field | Value | | --- | --- | | Vendor | Vespa.ai AS (https://vespa.ai) | | Kind | HTTP API | | Category | Retrieval & vector search (https://www.anchorterminal.com/categories/vector-search) | | Transport | HTTP | | Auth | OAuth or key · Vespa Cloud data-plane requests use mutual TLS with a client certificate placed in the application package, or a bearer token on a separate token endpoint. Each client is limited to `read`, `write` or both. Tokens are created in the console, have versions for rotation, expire (30 days by default) and can be revoked. The control plane uses a browser login through Auth0 (`vespa auth login`) or an application key pair for CI. Access is self-serve after a browser sign-up. A self-hosted Vespa has no authentication until the operator configures mTLS. | | Pricing | Pay per use ($0.05 / vCPU-hr) · Vespa Cloud charges by the hour for allocated resources. Startup is $0.05 a vCPU-hour, $0.005 a GB-hour of memory and $0.0002 a GB-hour of disk, on dev zones with community support and no SLA. Basic starts at $0.10 a vCPU-hour, Commercial at $0.145 and Enterprise at $0.18 with a $20,000 monthly minimum. Unit prices fall with volume by up to 50 per cent. The trial has $300 of credits, needs no card and stops the application when credits run out. Self-hosting the Apache-2.0 engine is free (https://cloud.vespa.ai/price-calculator-content, checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the docs index, the pricing page or the price calculator (checked 2026-10-09). | | Licence | Apache-2.0 for the engine, the Vespa CLI and pyvespa. Vespa Cloud is a paid hosted service | | Packages | pypi: `pyvespa` | | Source | https://github.com/vespa-engine/vespa | | Docs | https://docs.vespa.ai/ | | llms.txt | https://docs.vespa.ai/llms.txt | | Last release | 2026-10-01 | | GitHub stars | 7,100 (as of 2026-10-09) | | PyPI downloads / week | 180,440 | | Surface graded | Vespa Cloud's data-plane HTTP APIs (the query API at `/search/` and `/document/v1`) and the Vespa CLI. The same engine can be self-hosted under Apache-2.0 | | Search modes | Approximate nearest-neighbour search on HNSW, text search with BM25 and other ranking signals, and both in one YQL query with multi-phase ranking, per the docs | | Filters | Structured filters in YQL combined with nearest-neighbour and text operators in the same query | | Update delay | The docs index says data is searchable in milliseconds after being fed. This is the vendor's statement, not measured by us | | Setup | An application package with a schema and `services.xml` must be deployed before any feed or query. `vespa deploy` targets a dev zone by default | | Auth | mTLS client certificates or bearer tokens on the data plane, each client limited to `read`, `write` or both. Tokens expire after 30 days by default | | Limits | No request rate limit published for Vespa Cloud. Tenant quota of $2 an hour on trial and $10 an hour on other plans. Query timeout defaults to 0.5s, `hits` is capped at 400 by default, document requests time out at 180s | | Errors | `/document/v1` documents 400, 404, 405, 412, 413, 429, 500, 503, 504 and 507. The query API documents its status codes and an error code mapping | | MCP server | No official public server. An optional component in the engine serves `/mcp/` from the user's own application with three search tools | | Clients | Vespa CLI (Go, Homebrew `vespa-cli`), pyvespa 1.2.8 for Python 3.10 to 3.13, and a Java feed client | | Hosted cost | Startup $0.05 a vCPU-hour, $0.005 a GB-hour of memory, $0.0002 a GB-hour of disk. Basic from $0.10, Commercial from $0.145, Enterprise from $0.18 a vCPU-hour | | Self-hosted cost | Free software. The owner pays for compute, memory and disk. A paid Self Managed support plan is priced on request | | SLA | 99.5% monthly uptime for paying customers, with service credits of 90 to 100 per cent of monthly fees. Claims must be filed within 7 days | | Status | status.vespa.ai on Instatus, with components for the console, infrastructure, enclave and each zone | | Sub-processors | AWS and Google for application data in customer-chosen zones, Auth0, Grafana, HubSpot and Atlassian, with Stripe for billing. List updated 12 August 2026 | | Capabilities | db.vector, db.hybrid, db.fulltext, db.filters | | Tags | open-source, self-hosted, hosted, usage-based, free-trial, no-card, cli, llms-txt, python, java, status-page, sla, soc2, enterprise | | JSON | https://www.anchorterminal.com/api/v1/tools/vespa.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 80 | 16.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 58 | 9.4 | | Agent ergonomics | 13% | 16.2 | 80 | 13.0 | | Security & auth | 14% | 17.5 | 75 | 13.1 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 91 | 8.0 | | Transparency & trust (editorial 86, provenance 84) | 7% | 8.8 | 85 | 7.4 | | Negative events | up to −15 | up to −15 | GHSA-v86h-xr9p-pgm5, moderate severity (CVSS 6.8), published 4 September 2026. Two local file inclusion flaws in the deployment API let an authorised deployer read files readable by the config server process, in versions up to 8.746.22. Patched in 8.748.3 and disclosed in public, so a small deduction (https://github.com/vespa-engine/vespa/security/advisories/GHSA-v86h-xr9p-pgm5). | -2 | | **Total** | | | | **70 → BB** | ### Why each score - Reliability 80: Graded as a hosted service, on Vespa Cloud. Instatus status page at status.vespa.ai with components for the console, infrastructure, enclave and every zone, and a history feed (20). In the 90 days to 9 October 2026 the feed shows one incident, failing staging tests in AWS us-east-1c for 7 hours 27 minutes on 19 August, scoped to test and staging zones, with production zones at 100.0% on the page. Minor only (20). No request rate limit is published. The tenant quota is $2 an hour on trial and $10 an hour on other plans, the query timeout defaults to 0.5s and `hits` is capped at 400, so limits with numbers but none on request rate (7 of 15). `/document/v1` returns 429 when too many feed operations are in flight, the HTTP best practices page asks for capped exponential backoff with jitter and no retry on client errors, and writes by document ID with a `condition` are safe to repeat. No `Retry-After` header is documented (13 of 15). SLA of 99.5% monthly uptime for paying customers (10). Generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 58: No OpenAPI file or other machine-readable contract was found in the docs index of 384 pages (0). `llms.txt`, `llms-full.txt` and a Markdown twin of every page at `.html.md` (10). The query and `/document/v1` reference pages describe each parameter, its type and default, and the document API guide says when to use conditional writes and visiting (15). Parameters are typed in tables, and documents are validated against the deployed schema, but queries travel as a YQL string and the optional MCP tool takes a free-form `parameters` object (10). Examples on most pages and status code tables for both APIs (13). Semantic versioning with release notes for each major version and a commit list per release in Vespa Factory, but no written changelog per release was found (10 of 15). - Agent ergonomics 80: Responses can be sized with `hits`, `offset`, `presentation.summary` document summaries and `fieldSet` on document reads (20). Paging by `hits` and `offset`, continuation tokens when visiting, and structured filters in YQL (20). Both APIs document their status codes, and errors carry a `message` field, but the query API's errors are Java error codes mapped to HTTP codes (15). Puts by document ID repeat safely, `condition` gives test-and-set with 412 on failure, and `dryRun` exists on document writes. No idempotency key (15). Official clients in Python and Java plus the Go CLI, but nothing answers until an application package with a schema is deployed, and the default credential is a client certificate (10 of 15). - Security & auth 75: Data-plane clients authenticate with mTLS certificates or bearer tokens, each limited to `read`, `write` or both in `services.xml`. Tokens have versions for rotation, expire after 30 days by default and can be revoked, and are sent in a header (30). Read-only clients are supported. No confirmation step for deletes was found in the reviewed pages (13). Queries return stored documents as written, and no prompt-injection guidance was found (5). Control-plane operations go to an audit log that is available on request from support, and data-plane access logs are JSON, kept for at most 30 days (10 of 15). A valid security.txt, a disclosure programme on Intigriti with no public bounty, a SOC 2 attestation per the security guide, and one advisory published on GitHub in September 2026 (17). - Payments & pricing 40: Scored on Vespa Cloud, the paid hosted option. No x402, MPP or L402 (0). Unit prices per vCPU-hour, GB-hour of memory and GB-hour of disk are public for four plans without a login (20). The trial has $300 of credits and needs no card (20). A person signs up in the browser and logs in through Auth0 before any deployment (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 91: Tag v8.763.13 is dated 29 September 2026 and pyvespa 1.2.8 reached PyPI on 1 October 2026, both within 30 days (30). 16 release tags between 12 July and 29 September 2026 (20). The repository showed 225 open issues and 42 open pull requests, the master branch took merges on 8 October, and recent issues carry replies, though we did not read who replied or how fast (18 of 25). pyvespa, the Java feed client and the CLI are current (15). `renovate.json` and 11 GitHub workflows are in the repository. The main build runs on Buildkite and its state was not read (8 of 10). - Transparency & trust 85: Apache-2.0 for the engine and clients (30). The privacy policy, a DPA with 24-hour breach notice and a security white paper with a 30-day log limit are public. The DPA dates from 18 October 2023, names Vespa.AI Norway AS where the privacy policy names Vespa.ai AS, and refers to a Service Agreement not found on the site. The privacy policy states no retention period (22). Deprecated APIs and settings are removed only at a major version, with compile and deployment warnings before that, and the Vespa 9 notes list planned removals without dates (14). Sub-processors are listed with data, purpose and location, updated 12 August 2026, and logs stay in the application's region (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/vespa.md (JSON https://www.anchorterminal.com/fixes/vespa.json) ### What we couldn't check - unchecked: the trust centre at trust.vespa.ai, which is drawn by script, so the SOC 2 attestation rests on the security guide's statement - unchecked: the Vespa Service Agreement or terms of use, which the DPA refers to and which was not linked from the product terms page - unchecked: exact GitHub star count and issue reply times, because the GitHub API answered with a rate limit. The 7,100 stars figure is the rounded count on the repository page - unchecked: whether the main Buildkite build passes on the default branch - unchecked: whether Vespa Cloud was affected by GHSA-v86h-xr9p-pgm5, which the advisory does not say - Whether self-hosted Vespa sends any usage telemetry. No statement was found in the pages reviewed - Whether a written changelog per release exists outside the commit lists in Vespa Factory - The lead named a Java feed client and no MCP server. Both hold, with the addition that the engine ships an optional MCP component for a user's own application ### Sources - docs index for agents: (seen 2026-10-09) - LLM help page, MCP statement: (seen 2026-10-09) - security guide, mTLS, tokens and control plane: (seen 2026-10-09) - security white paper, audit logs and log retention: (seen 2026-10-09) - document API reference: (seen 2026-10-09) - query API reference: (seen 2026-10-09) - HTTP best practices, retries and 429: (seen 2026-10-09) - releases and versioning: (seen 2026-10-09) - Vespa 9 release notes: (seen 2026-10-09) - quota: (seen 2026-10-09) - Vespa CLI and skills command: (seen 2026-10-09) - plans and unit prices: (seen 2026-10-09) - free trial: (seen 2026-10-09) - service level agreement: (seen 2026-10-09) - data processing agreement: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - sub-processors: (seen 2026-10-09) - product terms page: (seen 2026-10-09) - responsible disclosure: (seen 2026-10-09) - security.txt: (seen 2026-10-09) - status page: (seen 2026-10-09) - status history feed: (seen 2026-10-09) - repository, tags, licence, SECURITY.md and MCP source: (seen 2026-10-09) - security advisory: (seen 2026-10-09) - open issues: (seen 2026-10-09) - pyvespa releases: (seen 2026-10-09) - pyvespa downloads: (seen 2026-10-09) - domain registration: (seen 2026-10-09) ## Who's behind it (provenance 84/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Vespa.ai AS | 20/20 | | Domain age | vespa.ai, registered 2017-12-16 (8 years) | 11/15 | | Endpoint on the vendor's domain | vespa.ai | 15/15 | | Terms of service | not found | 0/10 | | Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 | | Status page | status.vespa.ai | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The privacy policy names Vespa.ai AS, Prinsens gate 49, 7011 Trondheim, Norway, as controller for vespa.ai and console.vespa-cloud.com. No terms document is set. The product terms page links only the privacy policy, the DPA and the SLA, and the Service Agreement the DPA refers to was not found on the site. The DPA, last updated 18 October 2023, names Vespa.AI Norway AS as processor, a different name from the privacy policy's. Application endpoints answer on vespa-app.cloud and the console and control plane on vespa-cloud.com, both second domains of the vendor's. security.txt at vespa.ai expires on 31 December 2026 and points to a vulnerability disclosure programme on Intigriti. RDAP for vespa.ai gives a registration date of 2017-12-16. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy** (https://vespa.ai/privacy-policy/), read 2026-10-08, gives no date, states 5 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Not found in the text. Says how long data is kept. - Not found in the text. Says whether personal data is sold or shared for advertising. - Says where data is transferred or stored. Relies on standard contractual clauses. ## Live (updated 2026-10-09 07:58 UTC) - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/vespa.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Startup plan, one vCPU for an hour | $0.05 | per vCPU-hour | Memory $0.005 and disk $0.0002 a GB-hour are charged as well | | Commercial plan, one vCPU for an hour (initial price) | $0.145 | per vCPU-hour | Memory $0.0145 and disk $0.0005 a GB-hour are charged as well. Prices fall with volume | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Data-plane clients use mTLS certificates or tokens, each limited to `read`, `write` or both, with token versions, expiry and revocation - Unit prices are public, from $0.05 a vCPU-hour on Startup, and the trial gives $300 of credits with no card - Every docs page has a Markdown twin, with `llms.txt` and `llms-full.txt` on docs.vespa.ai - 16 release tags between 12 July and 29 September 2026, and pyvespa 1.2.8 on 1 October 2026 - Sub-processor list updated 12 August 2026 with locations, and logs are kept for at most 30 days in the application's region ## Weaknesses - No OpenAPI file was found in the docs index. The APIs are described in reference pages only - Vespa.ai states it has no official public MCP server. An MCP endpoint must be added to the user's own application - No call works until a schema and `services.xml` are deployed as an application package - The Service Agreement named in the DPA is not on the product terms page, which links only the privacy policy, DPA and SLA - Advisory GHSA-v86h-xr9p-pgm5 (moderate, 4 September 2026) let authorised deployers read config server files before 8.748.3 ## Before you call it (notes for agents) 1. Deploy an application package with a schema before feeding or querying. Use `vespa deploy` and wait for the endpoint to report ready 2. Send a token as `Authorization: Bearer` only to the endpoint marked Token. The mTLS endpoint needs the client certificate and key 3. Set `hits`, `offset` and `presentation.summary` on queries. `hits` is capped at 400 by default and the query timeout defaults to 0.5s 4. On 429 from `/document/v1` reduce the feed rate and back off. On 507 stop feeding, because the cluster is out of memory or disk 5. Use the `condition` parameter for test-and-set writes and expect 412 when it fails or the document is missing ## Connect Install: ```bash brew install vespa-cli ``` First request: ```bash curl -H "Authorization: Bearer $TOKEN" $ENDPOINT ``` Through letme (picks today, calling later): https://letme.dev/vespa. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Pinecone API + MCP | BB | 76.2 | 37 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/pinecone.md | | Supabase API + MCP | BB | 75.6 | 44 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/supabase-mcp.md | | Qdrant API + MCP | BB | 75.3 | 50 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/qdrant.md | | Typesense API + MCP | BB | 70.7 | 141 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/typesense.md | | Weaviate API + MCP | B | 67.9 | 218 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/weaviate.md | | Elasticsearch | B | 67.7 | 224 | db.vector, db.hybrid, db.fulltext, db.filters | no | https://www.anchorterminal.com/tools/elasticsearch.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Vespa.ai says it has no official public MCP server. An application can expose one at `/mcp/` by adding `McpRequestHandler` and `McpSearchSpecProvider` to `services.xml`, with three tools (`getSchemas`, `executeQuery`, `readQueryExamples`) (source: ) - `vespa skills install` downloads skills from vespa-engine/skills for Claude Code, Codex, Cursor and Antigravity CLI (source: ) - Vespa Cloud bills allocated vCPU, memory, disk and GPU memory by the hour, with a tenant quota of $2 an hour on trial and $10 an hour on other plans (source: ) - Releases are made Monday to Thursday and Vespa Cloud applications are upgraded to each one automatically (source: ) - Advisory GHSA-v86h-xr9p-pgm5, published 4 September 2026, covers local file inclusion through the deployment API in versions up to 8.746.22, patched in 8.748.3 (source: ) - The status page showed one incident in the 90 days to 9 October 2026, failing staging tests in AWS us-east-1c for 7 hours 27 minutes on 19 August (source: ) ## Compare - [Chroma API + MCP vs Vespa](https://www.anchorterminal.com/compare/chroma-vs-vespa.md): E 45.2 vs BB 70 - [Elasticsearch vs Vespa](https://www.anchorterminal.com/compare/elasticsearch-vs-vespa.md): B 67.7 vs BB 70 - [Epsilla Vector Database vs Vespa](https://www.anchorterminal.com/compare/epsilla-vs-vespa.md): F 35.7 vs BB 70 - [LanceDB vs Vespa](https://www.anchorterminal.com/compare/lancedb-vs-vespa.md): B 65.4 vs BB 70 - [Milvus and Zilliz Cloud API + MCP vs Vespa](https://www.anchorterminal.com/compare/milvus-zilliz-vs-vespa.md): C 57.3 vs BB 70 - [Pinecone API + MCP vs Vespa](https://www.anchorterminal.com/compare/pinecone-vs-vespa.md): BB 76.2 vs BB 70 - [Qdrant API + MCP vs Vespa](https://www.anchorterminal.com/compare/qdrant-vs-vespa.md): BB 75.3 vs BB 70 - [Typesense API + MCP vs Vespa](https://www.anchorterminal.com/compare/typesense-vs-vespa.md): BB 70.7 vs BB 70 - [Upstash Vector API + MCP vs Vespa](https://www.anchorterminal.com/compare/upstash-vector-vs-vespa.md): B 62.4 vs BB 70 - [Vespa vs Weaviate API + MCP](https://www.anchorterminal.com/compare/vespa-vs-weaviate.md): BB 70 vs B 67.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on vespa.ai or one of its subdomains, or the README of github.com/vespa-engine/vespa. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "vespa", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Vespa on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Vespa on Anchor Terminal](https://www.anchorterminal.com/badges/vespa.svg)](https://www.anchorterminal.com/tools/vespa) ``` Plain link: ```html Vespa on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Vespa is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/vespa-dark.png - Light: https://www.anchorterminal.com/assets/share/vespa-light.png