# Xweather Weather API > Xweather Weather API from Vaisala returns current conditions, forecasts to 15 days, history from 2004, official alerts, lightning, hail, air quality, maritime and road weather. Agents reach it as a REST API or a hosted MCP server. - Canonical: https://www.anchorterminal.com/tools/xweather - Markdown: https://www.anchorterminal.com/tools/xweather.md (~8,900 tokens) - Slim: https://www.anchorterminal.com/tools/xweather.min.md (~2,230 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/xweather.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 67.1/100 · rank #219 of 722 · #1 in Weather & climate data · not agent-ready · confidence medium** ## Assessment A public OpenAPI file with 236 operations, a hosted MCP server in the official registry and a free tier of 15,000 accesses a month suit agents. REST credentials travel only in the query string, per-minute limits are unpublished, and the group terms bar commercial use of free plans and passing data to third parties unless a service description allows it. ## Facts | Field | Value | | --- | --- | | Vendor | Vaisala Oyj (https://www.xweather.com) | | Kind | HTTP API | | Category | Weather & climate data (https://www.anchorterminal.com/categories/weather) | | Transport | HTTP | | Endpoint | `https://data.api.xweather.com` | | Auth | OAuth or key · A person signs up in a browser, registers an app in the account portal and receives a `client_id` and `client_secret` tied to a domain or app bundle namespace. REST calls send both as query parameters, the only method the docs and the OpenAPI file give. The MCP server takes `Authorization: Bearer _`, an `api_key` query parameter, or OAuth with dynamic client registration, where the person enters the same two values on Xweather's sign-in page. Keys are regenerated in the dashboard. | | Pricing | Freemium (Freemium) · Free Developer tier of 15,000 accesses a month with no card and no expiry, so an agent's owner can start without a contract. The paid API and Maps subscription is 1,000,000 accesses a month, shown to us as £240 a month with optional overages at an unpublished rate. Enterprise is by quote. One request can cost 1 to 25 accesses or more. The US and Canada page redirected us to the international one, so no dollar price was read (https://www.xweather.com/pricing/weather-api-subscription, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under the General Conditions of Subscription Services of Vaisala Group. The OpenAPI files and the agent skills on GitHub are MIT | | Tools exposed | 19 | | Packages | npm: `@aerisweather/javascript-sdk` | | MCP registry name | `com.xweather/weather` | | Source | https://github.com/vaisala-xweather/openapi | | Docs | https://www.xweather.com/docs/weather-api | | llms.txt | https://www.xweather.com/llms.txt | | Last release | 2026-09-14 | | GitHub stars | 0 (as of 2026-10-08) | | npm downloads / week | 1,403 | | Surface graded | The public REST API at https://data.api.xweather.com (version 1.43.5), with the hosted MCP server at https://mcp.api.xweather.com/mcp (version 1.2.2) noted beside it | | Endpoints | OpenAPI 3.2.0 and 3.1.0 files, 58 endpoint groups, 213 paths and 236 operations (213 GET, 23 POST). Conditions, forecasts, observations, alerts, lightning, hail, air quality, maritime, tides, tropical cyclones, road weather, storm reports, normals, irradiance and places | | MCP tools | 19 documented, all named `xweather_get_*`. General 7, forecast 2, air quality 2, lightning 1, tropical 4, maps 1, road weather 2. Filters `include_tags`, `exclude_tags`, `include_tools` and `exclude_tools` on the server URL | | Forecast range | Up to 15 days, in daily, day and night, 3-hour or 1-hour intervals. Maritime forecasts reach 7 days | | History | Conditions from January 2004 to today. Archive endpoints for observations, air quality, lightning, hail, maritime and tropical cyclones, some as paid add-ons | | Credentials | `client_id` and `client_secret` per registered app, limited to a domain or app bundle namespace, sent as query parameters. MCP takes `Authorization: Bearer _`, `?api_key=`, or OAuth with dynamic client registration and PKCE | | Plans | Developer, free, 15,000 accesses a month, no card, service pauses at the limit. API and Maps subscription, 1,000,000 accesses a month, shown to us as £240 a month with optional overages. Enterprise from 2 million accesses by quote | | Access cost | Accesses = endpoint multiplier × time intervals. `/impacts` 25, `/hail/threats` and `/lightning/analytics` 12, `/lightning` 10, `/airquality` 5, conditions, forecasts, alerts and observations 1. Each request inside `/batch` counts separately. 4xx and 5xx are free | | Rate limits | A per-minute limit and a per-period limit by plan. No per-minute number in the docs. `X-RateLimit-Limit-Minute`, `-Remaining-Minute`, `-Reset-Minute` and the `-Period` equivalents on responses. 429 with `maxhits_min` or `maxhits`, and `Retry-After` per the OpenAPI file | | Errors | JSON envelope `success`, `error`, `response`. 16 error codes such as `invalid_client`, `invalid_location`, `insufficient_scope` and `maxhits_min`, plus `warn_*` warnings. Application errors can arrive with HTTP 200 | | Output | JSON, GeoJSON, CSV and TSV through `format`. `fields`, `limit`, `plimit`, `skip`, `pskip`, `sort`, `filter` and `query` shape the response | | Webhooks | Pushed data is a separate paid subscription arranged through sales. The agent skill says deliveries are retried two or three times with no replay | | SDKs and skills | JavaScript `@aerisweather/javascript-sdk` 1.8.6 (October 2024), iOS and Android SDKs, Python notebooks. Six agent skills under MIT in vaisala-xweather/xweather-agent-skills, release 0.15.1 on 5 October 2026 | | Attribution | Required on all products. A link to https://www.xweather.com/ reading Powered by Vaisala Xweather, or the logo | | Status | status.xweather.com on Atlassian Statuspage, 21 components, among them API General, Conditions Endpoint, Forecasts Endpoint, Alerts Endpoint, Lightning Endpoints and MCP Server | | Certifications | The security page lists ISO 27001 and TISAX and says Xweather aligns with SOC 2. No report or certificate is linked | | Capabilities | weather.current, weather.forecast, weather.historical, weather.alerts, weather.marine, data.weather | | Tags | hosted, freemium, free-tier, closed-source, openapi, llms-txt, mcp, mcp-registry, oauth, agent-skills, webhooks, status-page, lightning, finland | | JSON | https://www.anchorterminal.com/api/v1/tools/xweather.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 74 | 14.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 83 | 13.5 | | Agent ergonomics | 13% | 16.2 | 78 | 12.7 | | Security & auth | 14% | 17.5 | 52 | 9.1 | | Payments & pricing | 10% | 12.5 | 32 | 4.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 81 | 7.1 | | Transparency & trust (editorial 51, provenance 85) | 7% | 8.8 | 68 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **67.1 → B** | ### Why each score - Reliability 74: Graded as a hosted service. Status page at status.xweather.com on Atlassian Statuspage with 21 components, among them API General, Conditions, Forecasts, Alerts, Lightning Endpoints and MCP Server (20). It lists three incidents between 10 July and 8 October 2026. Two on 24 July are marked major and report reduced data rates from the lightning network for 33 and 72 minutes, and one on 15 July relays an upstream GOES-East satellite outage. None names the general API, conditions or forecasts components (20 of 30). Monthly quotas are published, 15,000 and 1,000,000 accesses, but the per-minute limit is given only in response headers and by support (8 of 15). 429 is documented with the codes `maxhits_min` and `maxhits`, the OpenAPI file declares `Retry-After`, seven `X-RateLimit-*` headers report the remaining allowance, the MCP docs advise exponential backoff, and failed calls are not charged. The API is read-only, so no idempotency keys are needed (13 of 15). The pricing page mentions custom SLA guarantees for enterprise plans, with no SLA document found (3 of 10). The REST API at 1.43.5 and the MCP server at 1.2.2 are generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 83: OpenAPI 3.2.0 and 3.1.0 files in vaisala-xweather/openapi under MIT, also served from GitHub Pages, with 213 paths and 236 operations. They were first published on 30 September 2026. The MCP tools' input schemas need a key to list and were not read (25). llms.txt at www.xweather.com/llms.txt indexes the site and docs pages. The docs pages have no Markdown copies (a .md address returns 404), though six agent skills in Markdown cover request building (8 of 10). Every operation and parameter in the OpenAPI file has a description, and the MCP tool pages state each tool's purpose and limits, such as a 24-hour tool marked as not for multi-day forecasts (16 of 20). The file has 9 enums and 10 required parameters among 2,289 parameter uses, and `filter`, `query` and `sort` are free strings with their own grammar (8 of 15). Each operation declares 200, 401, 404, 429 and 500 with examples, and the docs list 16 error codes and the warning codes (13 of 15). Dated, numbered changelogs for the API and the MCP server. The API path carries no version (13 of 15). - Agent ergonomics 78: `fields`, `limit` and `plimit` size a REST response, and the docs give a 15-day hourly forecast as about 600 KB, or 25 KB with three fields. The MCP server documents 19 tools, with `include_tags`, `exclude_tags`, `include_tools` and `exclude_tools` filters on the server URL (22 of 25). `limit`, `skip`, `plimit`, `pskip`, `sort`, `filter`, `query`, `from` and `to` cover paging and filtering, and `/batch` combines requests (18 of 20). Errors carry a code and description, but application errors such as `invalid_location` arrive with HTTP 200 and `success` false, so the status code alone misleads (15 of 20). All calls are reads and safe to repeat, and failed calls cost nothing. The MCP tools' annotations could not be read without a key (14 of 20). A location is the only required input and accepts a place name, coordinates or a postal code. Official SDKs are client-side, namely JavaScript (last released October 2024), iOS and Android, with Python notebooks and no server-side library (9 of 15). - Security & auth 52: Credentials are a `client_id` and `client_secret` per registered app, limited to a domain or app bundle namespace and regenerated in the dashboard. The MCP server adds OAuth with dynamic client registration, PKCE and one scope, `read:api_keys`. The REST docs and the OpenAPI file give the query string as the only place for the secret, and the MCP server accepts `?api_key=` (22 less 10, 12 of 30). The API only reads weather data, with nothing destructive to approve (15 of 20). Responses are mostly numeric. Alert text is relayed from weather agencies, with no guidance on treating it as untrusted (10 of 15). Cost and quota headers come back on each call. No per-call log for the account holder was found in the docs (4 of 15). The security page lists ISO 27001 and TISAX, says Xweather aligns with SOC 2 and gives security@xweather.com, with no report linked and no bounty. xweather.com has no security.txt, while the parent vaisala.com has one with a policy link (11 of 20). - Payments & pricing 32: No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (0). Plan prices are public without a login, and the cost of each endpoint in accesses is published. The overage rate is not, and the page showed us pounds only, £240 a month for 1,000,000 accesses (12 of 20). A free Developer tier of 15,000 accesses a month, with no card and no expiry per the pricing page (20). A person signs up in a browser. The MCP OAuth flow registers clients by API but still needs a human to enter the key (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 81: The newest API release is 1.43.5 on 14 September 2026, 24 days before this check (30). Three API releases fall in the last 90 days, 1.43.3 on 29 July, 1.43.4 on 31 August and 1.43.5 on 14 September, and the agent skills repository had releases 0.14.1 to 0.15.1 between 1 September and 5 October (20). Public changelogs, a ticket form and support@xweather.com, with community support on the free tier and priority email on the paid plan. Response times were not tested (10 of 15). The MCP server is in the official registry as com.xweather/weather, active since 2 September 2026 (15). The JavaScript SDK `@aerisweather/javascript-sdk` was last released in October 2024, while the OpenAPI and skills repositories carry CI and recent commits (6 of 10). - Transparency & trust 68: Closed service under Vaisala's group subscription terms, dated 1 January 2023, which set a liability cap of twelve months' fees and ICC arbitration. They are written for annual, invoiced contracts and leave the product's own rules to service descriptions that were not found in public. The OpenAPI files and agent skills are MIT (15 of 30). The privacy policy is the group policy effective 1 June 2020. It covers online services, keeps data for a period it calls reasonable with no figure, and still cites the US Privacy Shield. No DPA was found (12 of 30). The changelog marks deprecations with dates, the API has `deprecated` and `warn_deprecated` codes, and the terms promise notice of modifications with a 30-day right to end the contract after a material reduction. No notice period is stated (8 of 20). A data processors page names about 40 processors with a location for each, with a caveat that it may be incomplete (16 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/xweather.md (JSON https://www.anchorterminal.com/fixes/xweather.json) ### What we couldn't check - unchecked: the US dollar plan price. The US and Canada pricing page redirected us to the international page, which showed £240 a month, so unitPrices is empty - unchecked: the overage rate beyond 1,000,000 accesses, which the pricing page does not state - unchecked: the MCP tools' input schemas and annotations, which need a key to list. The count of 19 is from the docs pages - unchecked: whether the free Developer tier includes MCP access. The docs say a 403 means the subscription lacks it - unchecked: per-minute rate limits by plan. The docs give headers and refer callers to support - unchecked: whether signup asks for a card. The pricing page says none is required for the Developer tier, and we did not open the checkout - Whether a Weather API service description permits commercial use or redistribution. The group terms prohibit commercial use of freemiums and bar passing data to third parties unless a service description allows it, and no such description was found in public - Which Vaisala company contracts for Xweather. The terms say the company named on the quotation or invoice, and the privacy policy names Vaisala Oyj, which we used as the legal entity - The security page says Xweather maintains ISO 27001 practices and aligns with SOC 2. No certificate or report was linked, so the scope is unknown - The docs' authentication page calls the scheme OAuth 2.0, but REST calls send a static ID and secret in the query string - The lead was right about the MCP server, agent skills and SDKs. The SDKs are client-side (JavaScript, iOS, Android), and the docs link the old status address status.aerisweather.com, which redirects to status.xweather.com ### Sources - API docs: (seen 2026-10-08) - authentication: (seen 2026-10-08) - rate limiting: (seen 2026-10-08) - cost headers: (seen 2026-10-08) - responses, headers and errors: (seen 2026-10-08) - reducing output: (seen 2026-10-08) - scripting best practices: (seen 2026-10-08) - API changelog: (seen 2026-10-08) - forecasts endpoint: (seen 2026-10-08) - conditions endpoint: (seen 2026-10-08) - toolkits: (seen 2026-10-08) - attribution guide: (seen 2026-10-08) - MCP server docs: (seen 2026-10-08) - MCP authentication: (seen 2026-10-08) - MCP filtering and tool scoping: (seen 2026-10-08) - MCP tool catalogue: (seen 2026-10-08) - MCP changelog: (seen 2026-10-08) - MCP OAuth metadata: (seen 2026-10-08) - MCP registry entry: (seen 2026-10-08) - OpenAPI repository: (seen 2026-10-08) - OpenAPI 3.1 file: (seen 2026-10-08) - agent skills repository: (seen 2026-10-08) - pricing, as served to us: (seen 2026-10-08) - product page: (seen 2026-10-08) - subscription terms (PDF): (seen 2026-10-08) - legal index: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - security page: (seen 2026-10-08) - data processors: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - status components: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - JavaScript SDK on npm: (seen 2026-10-08) - parent security.txt: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 85/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Vaisala Oyj | 20/20 | | Domain age | xweather.com, registered 2004-05-31 (22 years) | 15/15 | | Endpoint on the vendor's domain | data.api.xweather.com | 15/15 | | Terms of service | published, but our reader couldn't read it | 7/10 | | Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 | | Status page | status.xweather.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms are the General Conditions of Subscription Services of Vaisala Group, DOC250754-B, dated 1 January 2023, a nine-page PDF. www.xweather.com/terms and the legal page redirect to a script-drawn viewer on docs.vaisala.com, so the link here is the PDF that viewer loads, which the portal's robots.txt allows. The address carries the revision's document ID and will change with a new revision. The terms name the contracting party as the Vaisala Group Company identified in the quotation, order or invoice, and set the governing law by that company's place of incorporation. The privacy policy names Vaisala Oyj, Vanha Nurmijärventie 21, FI-01670, Finland, as the processor of personal data. The privacy policy at www.xweather.com/privacy is Vaisala's group policy (effective 2020-06-01, Ref. DOC229710-D). It covers online services supplied for a fee or as a free trial. The API answers at data.api.xweather.com, the MCP server at mcp.api.xweather.com and its authorisation server at oauth.api.xweather.com. www.xweather.com/.well-known/security.txt returns 404 and data.api.xweather.com answers 401 for it. The parent's www.vaisala.com/.well-known/security.txt exists, with security@vaisala.com and a policy link but no Expires field. RDAP gives a registration date of 2004-05-31 for xweather.com, with GoDaddy as registrar. The status page runs on Atlassian Statuspage, and status.aerisweather.com redirects to it. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://docs.vaisala.com/api/khub/documents/_2cuASo637CBKluQEurbLA/content), read 2026-10-08. Our reader couldn't read it (not a text document (application/pdf)). **Privacy policy** (https://www.xweather.com/privacy), read 2026-10-08, dated 2020-06-01, states 5 of the 8 things a reader expects. - To know. Has not been updated for three years or more. "(Effective as of 2020-06-01, Ref. DOC229710-D)" - Gives the date it was last updated. Last updated 2020-06-01. - Not found in the text. Says how long data is kept. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Not found in the text. Says what rights people have over their data. - Not found in the text. Gives a privacy contact. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Vaisala may share contact details and online behaviour data with sales channel partners for sales and marketing of its own products and services. "Additionally, Vaisala may share your contact details and online behaviour data, such as Site visits, with sales channel partners for the purpose of sales and marketing of Vaisala’s products and services." - Also in the text (2026-10-08). Vaisala may receive names and email addresses from third-party marketing databases and public sources such as Google and LinkedIn. "Vaisala may receive and collect personal data (including e.g. name and email) from marketing databases provided to Vaisala by third parties or public sources such as Google, LinkedIn" ## Live (updated 2026-10-08 21:58 UTC) - Right now: up, HTTP 401, 279 ms, checked 2026-10-08 21:53 UTC (get on `https://data.api.xweather.com`, asks for auth) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 273 ms · p95 315 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/xweather.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OpenAPI 3.2 and 3.1 files under MIT, published 30 September 2026, with 213 paths, 236 operations and 401, 404, 429 and 500 responses on each - Hosted MCP server at `https://mcp.api.xweather.com/mcp` with 19 documented tools, tag and tool filters, and an active entry in the official MCP registry - Free Developer tier of 15,000 accesses a month with no card and no expiry, per the pricing page - Every 2xx response carries `X-Cost-Tokens` and `X-RateLimit-*` headers, and 4xx and 5xx responses are not charged - Dated changelogs for the API (1.43.5 on 14 September 2026) and the MCP server (1.2.2 on 22 June 2026) ## Weaknesses - The REST API documents `client_id` and `client_secret` only as query parameters, and the MCP server also accepts the key as `?api_key=` - Per-minute rate limits are not published. The docs refer callers to response headers, support or an account executive - The group subscription terms prohibit commercial use of freemium plans and bar making data available to third parties unless a service description allows it - One access is not one request. `/impacts` costs 25 accesses, `/lightning` 10 and air quality 5, multiplied by the time intervals requested - No overage price or US dollar price was readable. The pricing page served us pounds, £240 a month for 1,000,000 accesses - The privacy policy is Vaisala's group policy effective 1 June 2020, with no retention period stated and no DPA found ## Before you call it (notes for agents) 1. Check `success` and `error.code` on every response. Application errors such as `invalid_location` return HTTP 200 with `success` false 2. Send `fields`, `limit` and `plimit`. The docs put a 15-day hourly forecast at about 600 KB, and about 25 KB with three fields 3. Read `X-Cost-Tokens` after each call. Cost is the endpoint multiplier times the intervals requested, so narrow `from` and `to` 4. For MCP, send `Authorization: Bearer _` and avoid the `api_key` query parameter, which puts the secret in the URL 5. Add `include_tags` or `include_tools` to the MCP URL to load only the tool groups the task needs 6. On 429 read `Retry-After` and the `X-RateLimit-Reset-*` headers. `maxhits_min` clears at the next minute, `maxhits` at the period reset ## Connect First request: ```bash curl 'https://data.api.xweather.com/places/98109?client_id={client_id}&client_secret={client_secret}' ``` Claude Code: ```bash claude mcp add --transport http xweather https://mcp.api.xweather.com/mcp --header "Authorization: Bearer CLIENT_ID_CLIENT_SECRET" ``` MCP client configuration: ```json { "mcpServers": { "Xweather": { "headers": { "Authorization": "Bearer ${env:XWEATHER_API_KEY}" }, "url": "https://mcp.api.xweather.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/xweather (letme picks it for data.weather, the top-graded tool for the job, letme picks it for weather.alerts, the top-graded tool for the job, letme picks it for weather.historical, the top-graded tool for the job, letme picks it for weather.marine, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | WeatherAPI.com | B | 65.3 | 260 | weather.current, weather.forecast, weather.historical, weather.alerts, weather.marine, data.weather | no | https://www.anchorterminal.com/tools/weatherapi-com.md | | meteoblue Weather API | C | 61.7 | 360 | weather.current, weather.forecast, weather.historical, weather.alerts, weather.marine, data.weather | no | https://www.anchorterminal.com/tools/meteoblue.md | | The Weather Company Data APIs | D | 52.6 | 565 | weather.current, weather.forecast, weather.historical, weather.alerts, weather.marine, data.weather | no | https://www.anchorterminal.com/tools/weather-company.md | | Tomorrow.io Weather API | D | 51.4 | 578 | weather.current, weather.forecast, weather.historical, weather.alerts, weather.marine, data.weather | no | https://www.anchorterminal.com/tools/tomorrow-io.md | | Google Weather API (Maps Platform) | B | 66.8 | 226 | weather.current, weather.forecast, weather.historical, weather.alerts, data.weather | no | https://www.anchorterminal.com/tools/google-weather-api.md | | Pirate Weather | B | 65.9 | 249 | weather.current, weather.forecast, weather.historical, weather.alerts, data.weather | no | https://www.anchorterminal.com/tools/pirate-weather.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The OpenAPI repository was published on 30 September 2026 with 3.2.0 and 3.1.0 files of 58 endpoint groups and 236 operations, generated from the docs, the API source and recorded responses per its README (source: ) - The MCP server is listed in the official MCP registry as com.xweather/weather, version 1.2.2, status active, published 2 September 2026 (source: ) - The MCP endpoint's live metadata advertises an authorisation server at oauth.api.xweather.com with dynamic client registration, PKCE (S256 and plain) and one scope, `read:api_keys`, and lists both header and query as bearer methods (source: ) - The group subscription terms prohibit commercial use of freemiums and trials (section 17.1), limit paid use to internal business purposes and bar making data available to third parties unless a service description allows it (sections 2.2 and 2.3) (source: ) - Under the same terms Vaisala may use analyses of a customer's use of the service for training machine learning algorithms and for benchmarking (section 12.2) - A request's cost in accesses is the endpoint multiplier times the time intervals covered, reported in `X-Cost-Tokens`, and only 2xx responses are charged (source: ) - The status page lists three incidents between 10 July and 8 October 2026. Two on 24 July, marked major, were reduced data rates from the lightning network for 33 and 72 minutes. The third was an upstream GOES-East satellite outage (source: ) - The data processors page names OpenAI as an LLM processor in the USA, with AWS, Hetzner, Equinix, MongoDB, Sentry, Auth0, Stripe and others, each with a location (source: ) ## Compare - [AccuWeather Core Weather API + MCP vs Xweather Weather API](https://www.anchorterminal.com/compare/accuweather-api-vs-xweather.md): D 48.4 vs B 67.1 - [Google Weather API (Maps Platform) vs Xweather Weather API](https://www.anchorterminal.com/compare/google-weather-api-vs-xweather.md): B 66.8 vs B 67.1 - [Met Office Weather DataHub (Site Specific) vs Xweather Weather API](https://www.anchorterminal.com/compare/met-office-datahub-vs-xweather.md): E 45.5 vs B 67.1 - [meteoblue Weather API vs Xweather Weather API](https://www.anchorterminal.com/compare/meteoblue-vs-xweather.md): C 61.7 vs B 67.1 - [Meteomatics Weather API vs Xweather Weather API](https://www.anchorterminal.com/compare/meteomatics-vs-xweather.md): D 49.6 vs B 67.1 - [NOAA National Weather Service API (api.weather.gov) vs Xweather Weather API](https://www.anchorterminal.com/compare/nws-api-vs-xweather.md): D 49.6 vs B 67.1 - [OpenWeather One Call API vs Xweather Weather API](https://www.anchorterminal.com/compare/openweather-one-call-vs-xweather.md): C 57.4 vs B 67.1 - [Pirate Weather vs Xweather Weather API](https://www.anchorterminal.com/compare/pirate-weather-vs-xweather.md): B 65.9 vs B 67.1 - [Tomorrow.io Weather API vs Xweather Weather API](https://www.anchorterminal.com/compare/tomorrow-io-vs-xweather.md): D 51.4 vs B 67.1 - [Visual Crossing Weather API vs Xweather Weather API](https://www.anchorterminal.com/compare/visual-crossing-vs-xweather.md): C 59.9 vs B 67.1 - [The Weather Company Data APIs vs Xweather Weather API](https://www.anchorterminal.com/compare/weather-company-vs-xweather.md): D 52.6 vs B 67.1 - [WeatherAPI.com vs Xweather Weather API](https://www.anchorterminal.com/compare/weatherapi-com-vs-xweather.md): B 65.3 vs B 67.1 - [Weatherbit API vs Xweather Weather API](https://www.anchorterminal.com/compare/weatherbit-vs-xweather.md): C 57.7 vs B 67.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on xweather.com or one of its subdomains, or the README of github.com/vaisala-xweather/openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "xweather", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Xweather Weather API on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Xweather Weather API on Anchor Terminal](https://www.anchorterminal.com/badges/xweather.svg)](https://www.anchorterminal.com/tools/xweather) ``` Plain link: ```html Xweather Weather API on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Xweather Weather API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/xweather-dark.png - Light: https://www.anchorterminal.com/assets/share/xweather-light.png