|
Thirteen thousand requests bounced off the paywall last
week, spread across twenty-seven different resources —
and the one they wanted most was not a lookup. It was a
ranking.
Week of August 31 – September 6, 2026 · 27,497
providers · 133,203 APIs
Every Monday I read what people and agents actually typed
into apis.io — the search box and the MCP server — as a demand signal
for the API economy. Nobody else has this data, so nobody
else can send you this email.
📈 The Demand Report
Searching apis.io is free. So is reading a provider, an
API, a tag, an artifact — the whole catalog, no key
required. What costs money is everything
that synthesises across it: ratings, cohorts,
comparisons, gap analysis, stack design.
Last week, 13,090 requests hit that line and
bounced. Up from 8,426, across 27 distinct resources where last week reached 19 — and nine of them had never been touched once in the entire
history of this report.
|
Gated resource
|
Aug 24–30
|
Aug 31–Sep 6
|
|
cohorts
|
0
|
7,187
|
|
security
|
7,242
|
4,481
|
|
scopes
|
196
|
331
|
|
ratings
|
86
|
123
|
|
operations
|
0
|
65
|
|
insights
|
0
|
47
|
|
vcs
|
45
|
35
|
|
resolve
|
0
|
33
|
|
checks
|
0
|
24
|
|
agent-readiness
|
3
|
16
|
|
stack
|
0
|
11
|
|
playground
|
0
|
9
|
cohorts went from never-touched to the single most reached-for
resource on the platform. It is not a lookup endpoint. It scores
a group of providers together — everyone in an
industry, a region, a capability — and ranks them against
each other. /cohorts answers a plain refusal today:
{"error":"upgrade_required", "detail":"The cohorts endpoint requires the Understanding or Influence plan."}
Read the nine first-timers as a list and they are all the
same kind of verb: cohorts, operations, insights, resolve, checks, stack,
playground, enrich, countries. Rank this group. Break this provider into operations.
Tell me what the landscape looks like. Resolve this name
to a real thing. Check this claim. Design me a stack.
Nobody spent last week asking the catalog
to find something. They asked it
to decide something.
That is a distinction I think the whole discovery category
gets wrong. The free part of this business is the index.
The part somebody will pay for is the judgement — and the
demand log now says so in its own numbers rather than in
mine.
And for the first time, some of it paid
Every request in this log carries the plan its key was
issued under. Here is the authenticated end of the table
across the run:
|
Tier
|
Aug 17–23
|
Aug 24–30
|
Aug 31–Sep 6
|
|
owner
|
48
|
260
|
495
|
|
starter
|
79
|
98
|
26
|
|
pro
|
0
|
0
|
289
|
|
business
|
0
|
0
|
303
|
pro and business requests appear in the log for the first time. Authenticated traffic went 358 → 1,113,
and owner set a record.
I want to be precise about what that is and is not. These
are hundreds of requests, not thousands, and a tier label
means the key presented carried that plan — it is not a
revenue number and I am not going to dress it up as one.
What it does settle is a question I could not answer
before: 175 accounts have signed up since July, 57 of them
in the first six days of September, and the sign-up mail
could never tell me whether anybody used the key
afterwards. Now something has, on the two plans that
unlock exactly the resources 13,090 requests were bouncing
off.
The agent spike did not hold
Last issue's lead was MCP searches at an all-time
high of 4,533. Seven days later they read 1,591, down 65% — the sharpest fall in the series and a share
of 0.52%, the lowest since July.
The series now reads 35 → 42 → 310 → 1,027 → 518 → 1,924 →
2,768 → 2,508 → 4,533 → 1,591.
Read honestly, that makes 4,533 a spike rather than a
step, and the 29-vertical MCP shopping run I wrote about
last week a single visit rather than a new baseline. The
durable range for agent traffic is still the 1,500–2,800
band this series has occupied since early August. I would
rather correct the read one week later than let a record
stand as a trend.
The volume, and the crawler inside it
|
|
This week vs last: total searches +67% to 304.1k,
keyless API +74% to 266.7k, unique terms −2.7% to
5,363, MCP searches −65% to 1,591. Footnote: three
panels moved on one crawler; the red one is the real
number
|
Total requests went 182,192 → 304,091 and
keyless callers 153,634 → 266,651.
Distinct search terms went 5,514 → 5,363, down 2.7% — the fifth consecutive week of a rising volume line
over a flat-to-falling vocabulary line, and the fifth time
the honest answer is the small number.
This week the crawler changed its wordlist to something
more interesting than a dictionary: it is walking our own catalog. Thirty-eight terms in the top hundred sit at six to
eight hits each, in alphabetical order, and every one of
them is the exact name of an API we publish —
Aggregated sales (Toast) · Asset Usage V2 (Bynder) · AVM Report (REA Group) · Data management data store (Orange Business) · Dealer Categories (Optimizely) · Fraud Notification Events (Silverflow) · Instance Settings (Clerk) · Menu Groups (Toast) · Network Tokens Events (Silverflow) · Pre-chargeback Alerts (Justt) · Rep Conversations (Qualified) · Track Segments (Customer.io) · VDV 463 (The Mobility House) …
Straight down the alphabet
from Aggregated to Carbon, one resource
per provider. Somebody is reading the index back to
itself. It is noise, and I am pointing at it because it is
the third distinct machine to arrive in eight weeks
wearing a different costume — a wordlist, then a vertical
template, now our own table of contents.
Concentration is at another all-time low: the top 100 terms are 1,189 of 304,091 requests — 0.39%. Strip the crawler and the human vocabulary above it is
the usual short list: weather (28), payments (27), SMS (25), Bloomberg (13), football (12), webhooks (12), RAG (9), Taiwan (9).
🕳️ The Gaps (demand we couldn't answer)
The pipeline saw 732 raw unmet terms,
dropped 280 as noise, and kept 113 — the
lowest genuine unmet count of the run, against 328, 390
and 366 in the weeks before. Volume tripled since
mid-August while the number of questions the catalog
cannot answer fell by two thirds.
I re-probed all 100 published zero-result terms against
the live API this morning. All 100 still return nothing — the first clean sweep in eight issues, where previous
weeks recovered 14, 19 and 52.
Three candidates were dropped from the list below before
it was drawn, because the provider turns out to already be
indexed under a spaced name: homedepot (3×), africastalking (1×) and the provider half of planradar mcp. A zero-result is not automatically a gap, and this is
the second week running that the squashed no-space domain
form is how people type a company they are looking for.
These eight are the real ones, each checked against the
live catalog by hand:
|
|
The Gaps — top zero-result searches: signalqub and
tripexpert at 4×, schneider m221 at 3×, then
planradar mcp, zammad, viessman, labdaq and artfol
at 2× each
|
-
signalqub (4×) — the sharpest row.
SignalQub sells a "zero-auth social media
scraping API" — Reddit, Google Maps, YouTube and
TikTok as clean JSON, no login, no proxies. A company
whose entire product is an API, searched for by
product name, and we have nothing. Third week running
that a row like this has led the list.
-
tripexpert (4×) — TripExpert distills
hotel, restaurant and attraction reviews out of 70+
travel guides and magazines into one rating. A data
product, and data products get looked for.
-
schneider m221 (3×) — the honest one.
Schneider Electric is in the catalog, with
four EcoStruxure APIs — IT Expert, Facility Expert,
Transformer Expert, contextualized energy data. The
M221 is a Modicon programmable logic controller.
Somebody wanted the interface to a piece of equipment
on a factory floor, and what we hold is the cloud tier
above it. Modicon returns zero across the whole index.
-
planradar mcp (2×) — PlanRadar is listed, scores 45.1, and publishes an OpenAPI, a
security artifact and a reference. It does not publish
an MCP server. The search was right to come back empty
on the thing that was actually asked for.
-
zammad (2×) — open-source helpdesk
and ticketing out of Germany, self-hostable, with a
documented REST API.
-
viessman (2×) — Viessmann, the German
heating and climate group. Typed one 'n'
short, and worth flagging because they run a live
developer portal with an IoT API and OAuth behind it.
That is not a company hoping to have an API.
-
labdaq (2×) — CGM LABDAQ, a
laboratory information system running in US clinical
labs.
-
artfol (2×) — an art portfolio and
social network for artists.
Two patterns. The first is now a standing
one: companies whose product is an API keep
turning up in the zero-result list. The second is new
— schneider m221 and viessman are both requests for the
machine layer: a PLC and a heating system, not a SaaS.
Industrial and building equipment vendors ship real
interfaces, and this catalog is thin there.
A correction to last week, while I am here. I reported that publishing the gap list appeared to
create demand for it — all eight of issue #06's names
rose four- to eight-fold the following week. That did not
repeat. Of issue #07's eight names, seven are flat or
gone this week and only apifootball rose (2 → 6). One re-crawl of a published list, not a
standing effect. The policy of discounting
previously-published terms stays, because it costs nothing
and it caught abivax and fireapp returning for a third week.
If you build in one of these lanes, this is your
invitation. Add your API in about two minutes: apis.io/add — or point your agent at the apis.io MCP server and let it submit for you.
🆕 New to the Index
The catalog stands at 27,497 providers and 133,203 APIs. Both numbers are down on the week — providers
by 371, APIs by 1,311 — the second Monday-over-Monday
provider decline of the run. Merges, retirements and
delistings ran ahead of arrivals. The build and the
deployed index agree exactly this week, so every number
here is one you can check right now.
|
|
Last Monday
|
Today
|
|
|
MCP entries (all)
|
4,507
|
4,801
|
+294
|
|
— of those, hosted endpoints
|
1,203
|
1,254
|
+51
|
|
Security artifacts
|
42,654
|
43,795
|
+1,141
|
|
Scopes artifacts
|
2,661
|
2,852
|
+191
|
Follow-through on last issue. The MCP
inventory grew 6.5% and the usable slice of it — an
endpoint an agent can actually open — grew 4.3%. Hosted
share fell from 26.7% to 26.1%; the
candidate-descriptor pile went 2,131 → 2,305. Growth in
the MCP count is still mostly growth in declarations.
And the catalog moved its own line, mid-week
Last issue argued that the MCP number everyone quotes and
the MCP number an agent can use are different numbers. On
Wednesday the index started saying so itself, and it cost
us the headline.
A provider used to earn the MCP artifact type by having a folder in the MCP collection
at all. That collection also holds candidate manifests — tool lists derived from a crosswalk, self-describing
as status: candidate, not servers anybody operates. Presence of a folder was
never evidence of a server. As of 3 September the credit
requires at least one page that is a real server
page and not a candidate. The pointer type in a
provider's own apis.yml was renamed alongside it, MCPServer → X-MCPServerCandidate, so the declaration says what it is.
The effect on the number:
|
Providers matching artifact_types=MCP
|
|
|
Last Monday
|
4,432
|
|
Today
|
2,476
|
Nothing was deleted and nothing broke. Of
4,746 provider folders in the MCP collection, 2,279 now earn nothing — 2,242 of them hold only candidate manifests, and the
remaining 37 hold only redirect tombstones from pages that
were retired. That leaves 2,467 earning the credit, which
is the deployed figure to within nine records. The pages
stay browsable; the credit is what got gated, and find_mcp rows now carry status so a candidate says so on its own row.
I am publishing the before-and-after rather than quietly
using the new number, because 1,956 providers stopped being counted as MCP publishers
in a week and none of them changed anything. If you have quoted an apis.io MCP figure in the last
month, that is which one you had.
Which also re-cuts the row above, and I would rather
say it than let it sit in a table. The same change split the summary the artifact line is
built from: of 4,801 MCP entries, 2,560 are a real server and 2,242
are a candidate manifest. So the honest reading of that "+294" is a
count of entries, not of servers. When this newsletter has
written "4,507 MCP servers" — I wrote exactly
that last week — the number included the candidate
half. 2,560 is the figure that means what the phrase
says, and it is the one I will use from here.
Two axes are now in play and they are not the same cut, so
it is worth being exact about which is which. Of 4,801 MCP
pages: 2,242 carry status: candidate (the flag the artifact credit reads) and 2,305 are classified Candidate descriptor by install method (the endpoint-shape
read from last issue's table). They overlap on 1,984.
The remainder is the interesting part — 245 documentation links and 13 things classified as a
hosted endpoint self-describe as candidates. A URL that looks live and a provider that says
"this is a guess" are different claims, and
until this week only one of them was being counted.
One number moved the right way. Providers
publishing scopes went 2,660 → 2,824,
from 9.7% to 10.3% of the catalog. It is
the largest weekly move that line has made, and the first
time it has cleared ten percent. Security sits at 24,328
providers, 88.5%. The permission gap is still nine to one,
but for one week it narrowed.
Published on the blog last week:
All on the apis.io blog.
⭐ Rated This Week: Archive — the second list
This week's angle: in a week when demand was for
judgement, the provider worth reading is the one that
made itself judgeable.
Archive Technologies scores 51.0, developing, with Agent Readiness 47.8, agent-ready. It runs a creator-marketing platform — social content,
engagement metrics, creator profiles, campaign
collections.
It also published a help page that lists what its
API cannot do.
After the reads and the writes, the page turns around and
states plainly that the API cannot create or delete
content or creators, cannot send messages, cannot write
custom attributes, cannot create or modify workspaces or
campaigns, cannot send webhooks, and cannot pull content
Archive has not already captured. Nothing is being sold in
that second list. It is a page that makes the product look
smaller.
It is also the single most useful thing on the site,
because a boundary is what an integrator otherwise
discovers at 2am — and it is the thing a buyer comparing
four vendors actually needs. Most providers publish a
surface. Publishing the edge of it is rare.
I checked the agent surface at the source rather than
taking the catalog's word. An anonymous initialize against app.archive.com/api/v2/mcp returns 401 carrying both halves
of a good refusal:
www-authenticate: Bearer resource_metadata="https://app.archive.com/.well-known/oauth-protected-resource" {"jsonrpc":"2.0","id":1,"error":{"code":-32001,"message":"Authentication required"}}
An HTTP client gets a header telling it where to
authenticate; a protocol client gets a typed JSON-RPC
error it can branch on. Most servers manage one or the
other. And the metadata URL is honest: I asked for a .well-known path that cannot exist and got a 404,
where last week's provider served the same document
from a catch-all.
The API itself is a GraphQL surface at a single POST endpoint — 53 operations, 29 queries and 24 mutations, over 135
types, behind a workspace-scoped bearer token. Runtime
introspection is disabled, which is a defensible security
posture and also means the published
reference is the schema. The MCP server maps 53
tools one-to-one onto those operations against the same
credit budget, so the agent door and the developer door
are demonstrably the same door.
|
Facet
|
Score
|
|
Discoverability
|
75.9
|
|
Access Clarity
|
69.7
|
|
Developer Ergonomics
|
58.9
|
|
Contract Quality
|
46.8
|
|
Operational Transparency
|
42.1
|
|
Contract Governance
|
4.5
|
The cheapest points on the table are the twenty-four
mutations. delegated_identity, protected_resource_metadata and dynamic_client_registration are all lit, which almost nothing in this catalog can
say — they are lit because the MCP server was built on
OAuth instead of a pasted key. What is dark is everything
about what happens after an agent walks through
that door: agentic_access unlit, reversibility_documented unlit, idempotency unlit. Twenty-four write operations, agent-accessible,
with nothing published about undo or replay.
Contract governance at 4.5 is the lowest facet on the card
and the largest single lift on the composite. And event_surface_described is unlit — which Archive already told us, on the page
this section is about. When a provider's own boundary
list and our rubric agree about a gap, the gap is real and
the provider is not the problem.
Kin Score rubric 0.19.0, scored 2026-09-06. Bands:
exemplar 66.5+ · strong 54.3–66.4 · developing 39.3–54.2
· thin 26.2–39.2 · emerging 11–26.1 · minimal 0–10.9.
Agent Readiness 0.2: agent-native 38.7+ (gated on
idempotency AND error semantics) · agent-ready 28.6–38.6
· agent-aware 5.1–28.5 · human-only 0–5. 0.18 and 0.19 were structural releases that move no
scores, so unlike most weeks these numbers are directly
comparable to last issue's.
🤖 Reproduce this yourself
The gate is one call, and the refusal is the point:
curl -s "https://apis.io/api/v1/cohorts?limit=1"
You get upgrade_required and a pointer to the plans page — the same answer 7,187
requests got last week. Everything the free
tier does answer is one call away too:
find_providers(artifact_types=["Scopes"], limit=1, fields=["slug"]) find_mcp(install_method="Hosted endpoint", limit=1)
Read meta.total: 2,824 providers publish scopes out of
27,497, and 1,254 of the 4,801 MCP
entries are an endpoint you can open.
And the re-cut number from this week, which is the one to
quote from here on:
find_providers(artifact_types=["MCP"], limit=1, fields=["slug"])
2,476, not 4,432. Same catalog, a
definition that now requires a server.
Then check this week's provider without trusting me
or the catalog:
curl -s -D - -o /dev/null -X POST https://app.archive.com/api/v2/mcp \ -H 'Content-Type: application/json' \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}' \ | grep -i www-authenticate
Or read the demand data directly: apis.io/search-terms/, refreshed every Monday.
27,497 providers. 133,203 APIs. 13,090 requests last
week for the one thing the index doesn't do for
free — tell you which of them is better. See a gap that's yours? → apis.io/add
The Demand Report is a weekly read of apis.io's
own search + discovery signal. Forward it to someone who
ships an API.
|