# Moz > Moz is a Seattle-based search-marketing software company (founded 2004 as SEOmoz, part of Ziff > Davis since 2021). Its developer surface is the Moz API: a JSON-RPC 2.0 API served from a single > universal endpoint, https://api.moz.com/jsonrpc, exposing 62 public methods over the Moz Link > Index, site authority metrics, keyword metrics and Moz Local business-listing management. Moz also > runs two beta remote MCP servers. Generated by API Evangelist from the Moz developer surface on 2026-08-26. Moz does not publish an llms.txt of its own (https://moz.com/llms.txt returned 404 on 2026-08-26). ## How to call it - Endpoint: https://api.moz.com/jsonrpc (HTTP POST only; there are methods, not endpoints) - Protocol: JSON-RPC 2.0. Body must carry `jsonrpc: "2.0"`, a client-generated `id` of at least 24 characters (a v4 UUID is recommended - this is NOT your API token), a `method` name in dot notation, and `params.data` holding the method-specific body. - Auth: a secret Moz API token in the custom `x-moz-token` header. Issued at https://moz.com/api/dashboard; up to 5 tokens per account. - Billing: a monthly row quota, not a request count. Consumption is reported in every response body; remaining quota is readable with `quota.lookup` (path `api.limits.data.rows`). ## Documentation - API overview: https://moz.com/products/api - Documentation home: https://moz.com/api/docs - Welcome / method index: https://moz.com/api/docs/welcome - Getting started: https://moz.com/api/docs/guides/getting-started - Authentication: https://moz.com/api/docs/guides/authentication - Error handling: https://moz.com/api/docs/guides/error-handling - MCP servers: https://moz.com/api/docs/guides/mcp-servers - Pricing: https://moz.com/products/api/pricing - API dashboard (token issuance): https://moz.com/api/dashboard ## MCP servers (beta) - Moz Data: https://api.moz.com/mcp/v1/data - suggested client name `moz-mcp-v1-data`; requires a Moz Data API subscription. - Moz Local: https://api.moz.com/mcp/v1/local - suggested client name `moz-mcp-v1-local`; requires a Moz Local subscription. - Auth: OAuth 2.1 (authorization code + PKCE S256, dynamic client registration, scope `mcp`) or an `Authorization: Bearer ` header. Beta access is limited to account owners. - Both are published in the Claude connector directory as "Moz Data" and "Moz Local". ## Method namespaces (62 public methods) - `data.site.metrics.*` - Domain Authority, Page Authority, Brand Authority, Spam Score, link counts, metric distributions and histories, for one or many targets. - `data.site.link.*` - list links, filter by anchor text or domain, link intersect, link status. - `data.site.linking-domain.*` - linking root domains, recently gained, recently lost. - `data.site.anchor-text.list`, `data.site.top-page.list`, `data.site.redirect.fetch`, `data.site.ranking-keyword.list` / `.count`. - `data.keyword.metrics.*` - volume, difficulty, opportunity (CTR), priority, or all at once. - `data.keyword.search.intent.fetch`, `data.keyword.suggestions.list`. - `data.global.top-domain.list`, `data.global.top-page.list`. - `local.location.*` - create, update, lookup, list, cancel, close, listings, categories, levels, filters, Google Business Profile insights, local grid, listing networks, ranking history. - `local.account.*`, `local.group.*` - accounts, groups and group membership. - `metadata.index.fetch` - current Moz Link Index ID. - `quota.lookup` - remaining quota. ## Machine-readable contract Moz publishes no OpenAPI document. It does publish a complete JSON Schema describing every action's payload, result and quota - 74 actions and 930 definitions - which the documentation application serves. API Evangelist has harvested it verbatim. - JSON Schema (harvested): json-schema/moz-api-schema.json - Data model derived from it: data-model/moz-data-model.yml ## API Evangelist artifacts in this repository - authentication/moz-authentication.yml - both auth models, token issuance, OAuth metadata - scopes/moz-scopes.yml - the single `mcp` OAuth scope - conventions/moz-conventions.yml - JSON-RPC conventions, pagination, versioning, reversibility - errors/moz-problem-types.yml - the JSON-RPC error envelope and the -326xx codes observed live - rate-limits/moz-rate-limits.yml - the 4xx penalty limiter, free-tier request rate, row quota - plans/moz-plans-pricing.yml - all seven published tiers with row allowances and overage rates - lifecycle/moz-lifecycle.yml - unversioned API, beta policy, no status page, no changelog - conformance/moz-conformance.yml - JSON-RPC 2.0, MCP, OAuth/RFC 8414/RFC 9728/PKCE, RFC 9116 - mcp/moz-mcp.yml - both MCP endpoints with live probe results - well-known/moz-well-known.yml - every /.well-known/* path probed, with status - security/ - domain security probe, vulnerability disclosure, trust center - packages/moz-packages.yml - no maintained first-party SDK; the finding and the evidence - skills/ - packaged agent skills grounded in real Moz method names ## Known gaps (as of 2026-08-26) - No OpenAPI document; the docs site's own "Export docs" link is behind Cloudflare Access. - No status page, no changelog, no deprecation policy, no SLA. - No maintained first-party SDK; the only one ever published to a registry (the `linkscape` Ruby gem) last released in 2011. - The served security.txt expired 2026-08-25, and its Policy, Encryption and Acknowledgements URLs all return 404. - No rate-limit response headers; quota state is only in the response body. - No idempotency key on the Local namespace write methods.