{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "ghost",
    "name": "Ghost",
    "vendor": "Ghost Foundation",
    "vendorUrl": "https://ghost.org",
    "kind": "http-api",
    "category": "cms",
    "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
    "url": "https://www.anchorterminal.com/tools/ghost",
    "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
    "repo": "https://github.com/TryGhost/Ghost",
    "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "ghost"
      },
      {
        "registry": "npm",
        "name": "@tryghost/admin-api"
      },
      {
        "registry": "npm",
        "name": "ghost-cli"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
    "pricing": "freemium",
    "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
    "priceSummary": "$18 / mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 55500,
      "npmWeekly": 23628,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.ghost.org/admin-api",
    "llmsTxt": "https://docs.ghost.org/llms.txt",
    "capabilities": [
      "cms.content",
      "cms.publish",
      "cms.assets"
    ],
    "tags": [
      "open-source",
      "self-hosted",
      "hosted",
      "rest",
      "llms-txt",
      "webhooks",
      "newsletter",
      "memberships",
      "nodejs",
      "status-page"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 58.3,
      "grade": "C",
      "agentReady": false,
      "rank": 404,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 69,
        "maintenance": 85,
        "payments": 50,
        "reliability": 80,
        "schema": 51,
        "security": 56,
        "transparency": 72
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Read with the local-software lines, since the graded surface is the open-source release its owner hosts. Ghost(Pro)'s status page isn't scored here. Official `ghost` package on npm, Node.js ^22.23.1 or ^24.20.0 in `engines`, and a supported stack named in the hosting guide (20). A public CI workflow runs the test suites, and its badge for main read failing when we checked on 8 October 2026 (12 of 25). The repository showed 33 open issues and 140 open pull requests against weekly releases. We didn't read individual threads (20 of 25). Semver version numbers, release notes per version and a breaking changes page per major, with the 6.0 removal of `limit=all` documented there (13 of 15). 6.x is the current stable line (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 51,
          "points": 8.29,
          "reason": "No OpenAPI or similar file was found in the docs index or the repository (0 of 25). llms.txt with 177 links, llms-full.txt and a Markdown copy of every page (10). The reference states what each endpoint does and which fields are required, with little on when not to use one (10 of 20). No published schemas. Required fields are named (`title` on create, `updated_at` on edit), and post content is one Lexical JSON string (6 of 15). Request and response examples on each page and token generation in Bash, JavaScript, Ruby and Python. The errors page lists five status codes and the `errorType` and `message` fields, without a list per endpoint (10 of 15). `Accept-Version` header, a stability index per endpoint, a breaking changes page and release notes (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 69,
          "points": 11.21,
          "reason": "`fields`, `include` and `formats` size a response, and lists return 15 records by default (20 of 25). `page`, `limit` up to 100, `order` and a `filter` query language, with `meta.pagination` on every list (20). Errors are JSON with `message` and `errorType`, and the documented list is short (13 of 20). No idempotency keys. A PUT must carry the current `updated_at` and is refused on a collision, and a repeated POST creates a second post (8 of 20). A create needs only `title`. The one official client is JavaScript, @tryghost/admin-api (8 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 56,
          "points": 9.8,
          "reason": "An Admin API key belongs to one custom integration, can be regenerated, and signs tokens that last at most 5 minutes and travel in the Authorization header. Integrations have one fixed permission set and no scopes, so we scored plain revocable keys plus 2 for role-bound staff tokens (22 of 30). The Content API key is sent as a query parameter. It reads published content only and isn't the graded credential, so no deduction. A Contributor's staff token can add and edit drafts but not change status, per the post model. No read-only Admin key and no approval step for a publish or delete (12 of 20). Posts, members and comments hold text written by other people, and no prompt-injection guidance was found (3 of 15). An actions log is readable at `GET /actions`. No per-call log was found (8 of 15). A disclosure policy with response times, security@ghost.org and advisories published on GitHub with credits. No bug bounty or certification was found, and ghost.org/.well-known/security.txt returned 404 (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 50,
          "points": 6.25,
          "reason": "Scored with the self-hosted rule, taking prices from Ghost(Pro) beside the free software. No x402, MPP or L402 found (0). The software is free under MIT, and Ghost(Pro) lists $18, $29 and $199 a month billed yearly at up to 1,000 members (20). Self-hosting needs no card or account. Whether the Ghost(Pro) trial asks for a card wasn't readable (20). The docs create Admin API keys in the Ghost Admin screens, so a person sets up the integration. Install is scriptable, so half (10)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "6.69.0 was tagged and published to npm on 7 October 2026, the day before this check (30). 19 versions reached npm between 10 July and 8 October (20). 33 open issues on a repository with about 55,500 stars, and 20 advisories fixed and published with reporter credits in five weeks. We didn't read reply times on individual issues (18 of 25). @tryghost/admin-api 1.14.13 was published on 21 September 2026. The official MCP registry lists third-party Ghost servers only (10 of 15). A Renovate workflow keeps dependencies current. The CI badge on main read failing on 8 October (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "note": "editorial 76, provenance 68",
          "reason": "MIT, copyright Ghost Foundation, with the source public (30). A self-hosted site keeps content on its owner's server. For Ghost(Pro) the privacy policy places servers in Amsterdam and a DPA lists subprocessors in an annex, while retention is stated only as kept where necessary and the terms make the customer responsible for backups (18 of 30). A table dates each major's end of life (5.x in January 2026, 6.x to be confirmed), endpoints carry a stability index and breaking changes are catalogued per major. No notice period in days was found (15 of 20). The configuration page documents Gravatar, structured data and IndexNow calls with a switch for each and `useTinfoil` for all. The default configuration also names an update service at updates.ghost.org, which that section doesn't list (13 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`fields`, `include` and `formats` size a response, and lists return 15 records by default (20 of 25). `page`, `limit` up to 100, `order` and a `filter` query language, with `meta.pagination` on every list (20). Errors are JSON with `message` and `errorType`, and the documented list is short (13 of 20). No idempotency keys. A PUT must carry the current `updated_at` and is refused on a collision, and a repeated POST creates a second post (8 of 20). A create needs only `title`. The one official client is JavaScript, @tryghost/admin-api (8 of 15).",
          "maintenance": "6.69.0 was tagged and published to npm on 7 October 2026, the day before this check (30). 19 versions reached npm between 10 July and 8 October (20). 33 open issues on a repository with about 55,500 stars, and 20 advisories fixed and published with reporter credits in five weeks. We didn't read reply times on individual issues (18 of 25). @tryghost/admin-api 1.14.13 was published on 21 September 2026. The official MCP registry lists third-party Ghost servers only (10 of 15). A Renovate workflow keeps dependencies current. The CI badge on main read failing on 8 October (7 of 10).",
          "payments": "Scored with the self-hosted rule, taking prices from Ghost(Pro) beside the free software. No x402, MPP or L402 found (0). The software is free under MIT, and Ghost(Pro) lists $18, $29 and $199 a month billed yearly at up to 1,000 members (20). Self-hosting needs no card or account. Whether the Ghost(Pro) trial asks for a card wasn't readable (20). The docs create Admin API keys in the Ghost Admin screens, so a person sets up the integration. Install is scriptable, so half (10).",
          "reliability": "Read with the local-software lines, since the graded surface is the open-source release its owner hosts. Ghost(Pro)'s status page isn't scored here. Official `ghost` package on npm, Node.js ^22.23.1 or ^24.20.0 in `engines`, and a supported stack named in the hosting guide (20). A public CI workflow runs the test suites, and its badge for main read failing when we checked on 8 October 2026 (12 of 25). The repository showed 33 open issues and 140 open pull requests against weekly releases. We didn't read individual threads (20 of 25). Semver version numbers, release notes per version and a breaking changes page per major, with the 6.0 removal of `limit=all` documented there (13 of 15). 6.x is the current stable line (15).",
          "schema": "No OpenAPI or similar file was found in the docs index or the repository (0 of 25). llms.txt with 177 links, llms-full.txt and a Markdown copy of every page (10). The reference states what each endpoint does and which fields are required, with little on when not to use one (10 of 20). No published schemas. Required fields are named (`title` on create, `updated_at` on edit), and post content is one Lexical JSON string (6 of 15). Request and response examples on each page and token generation in Bash, JavaScript, Ruby and Python. The errors page lists five status codes and the `errorType` and `message` fields, without a list per endpoint (10 of 15). `Accept-Version` header, a stability index per endpoint, a breaking changes page and release notes (15).",
          "security": "An Admin API key belongs to one custom integration, can be regenerated, and signs tokens that last at most 5 minutes and travel in the Authorization header. Integrations have one fixed permission set and no scopes, so we scored plain revocable keys plus 2 for role-bound staff tokens (22 of 30). The Content API key is sent as a query parameter. It reads published content only and isn't the graded credential, so no deduction. A Contributor's staff token can add and edit drafts but not change status, per the post model. No read-only Admin key and no approval step for a publish or delete (12 of 20). Posts, members and comments hold text written by other people, and no prompt-injection guidance was found (3 of 15). An actions log is readable at `GET /actions`. No per-call log was found (8 of 15). A disclosure policy with response times, security@ghost.org and advisories published on GitHub with credits. No bug bounty or certification was found, and ghost.org/.well-known/security.txt returned 404 (11 of 20).",
          "transparency": "MIT, copyright Ghost Foundation, with the source public (30). A self-hosted site keeps content on its owner's server. For Ghost(Pro) the privacy policy places servers in Amsterdam and a DPA lists subprocessors in an annex, while retention is stated only as kept where necessary and the terms make the customer responsible for backups (18 of 30). A table dates each major's end of life (5.x in January 2026, 6.x to be confirmed), endpoints carry a stability index and breaking changes are catalogued per major. No notice period in days was found (15 of 20). The configuration page documents Gravatar, structured data and IndexNow calls with a switch for each and `useTinfoil` for all. The default configuration also names an update service at updates.ghost.org, which that section doesn't list (13 of 20)."
        },
        "sources": [
          {
            "what": "Admin API overview, authentication and endpoints",
            "url": "https://docs.ghost.org/admin-api",
            "seen": "2026-10-08"
          },
          {
            "what": "creating a post",
            "url": "https://docs.ghost.org/admin-api/posts/creating-a-post",
            "seen": "2026-10-08"
          },
          {
            "what": "updating a post and revisions",
            "url": "https://docs.ghost.org/admin-api/posts/updating-a-post",
            "seen": "2026-10-08"
          },
          {
            "what": "publishing a post",
            "url": "https://docs.ghost.org/admin-api/posts/publishing-a-post",
            "seen": "2026-10-08"
          },
          {
            "what": "image upload",
            "url": "https://docs.ghost.org/admin-api/images/uploading-an-image",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript client",
            "url": "https://docs.ghost.org/admin-api/javascript",
            "seen": "2026-10-08"
          },
          {
            "what": "query parameters",
            "url": "https://docs.ghost.org/content-api/parameters",
            "seen": "2026-10-08"
          },
          {
            "what": "errors",
            "url": "https://docs.ghost.org/content-api/errors",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning and stability index",
            "url": "https://docs.ghost.org/faq/api-versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "breaking changes by major version",
            "url": "https://docs.ghost.org/changes",
            "seen": "2026-10-08"
          },
          {
            "what": "major versions and end of life",
            "url": "https://docs.ghost.org/faq/major-versions-lts",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy and practices",
            "url": "https://docs.ghost.org/security",
            "seen": "2026-10-08"
          },
          {
            "what": "configuration, privacy section",
            "url": "https://docs.ghost.org/config",
            "seen": "2026-10-08"
          },
          {
            "what": "hosting guide and supported stack",
            "url": "https://docs.ghost.org/hosting",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.ghost.org/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "repository, licence, routes, role fixtures and post model (clone)",
            "url": "https://github.com/TryGhost/Ghost",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/TryGhost/Ghost/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory, remote code execution via bookmark card images",
            "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp",
            "seen": "2026-10-08"
          },
          {
            "what": "CI badge for main",
            "url": "https://github.com/TryGhost/Ghost/actions/workflows/ci.yml/badge.svg?branch=main",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package and version",
            "url": "https://registry.npmjs.org/ghost/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "Admin API client on npm",
            "url": "https://registry.npmjs.org/@tryghost/admin-api",
            "seen": "2026-10-08"
          },
          {
            "what": "Ghost(Pro) pricing and plan comparison",
            "url": "https://ghost.org/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://ghost.org/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://ghost.org/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement",
            "url": "https://ghost.org/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "fair use policy",
            "url": "https://ghost.org/fair-use/",
            "seen": "2026-10-08"
          },
          {
            "what": "Ghost(Pro) status page incidents",
            "url": "https://ghoststatus.org/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=ghost",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: api.github.com refused us for its rate limit, so the star count (55.5k) and issue counts come from the repository's web pages and reply times on issues weren't read",
          "unchecked: monthly-billed Ghost(Pro) prices and prices above 1,000 members, which the pricing page computes in the browser",
          "unchecked: whether the Ghost(Pro) free trial asks for a card",
          "unchecked: what the update service at updates.ghost.org receives and whether it still runs by default. We saw only its URL in the default configuration",
          "unchecked: why the CI badge on main read failing on 8 October 2026, and for how long",
          "unchecked: advisories before 3 September 2026. We read the two newest of eight pages",
          "We didn't run an instance. Role behaviour, the 25-revision cap and the actions route come from the source at commit 8914a05 and the docs",
          "The docs name Ghost Admin as the place to create an Admin API key. The routes file has a `POST /integrations` route for signed-in users, which we didn't test as a way to script it",
          "The dossier grades the self-hosted software. A reader on Ghost(Pro) should weigh the plan requirement, the fair use policy and the status history noted for reviewers",
          "The lead was right about the interface. It didn't say that Ghost(Pro) withholds the Admin API from the Starter plan"
        ]
      },
      "negative": -7,
      "negativeNotes": [
        "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
      ],
      "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
      "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
      "strengths": [
        "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
        "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
        "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
        "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
        "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
      ],
      "weaknesses": [
        "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
        "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
        "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
        "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
        "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
      ],
      "agentNotes": [
        "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
        "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
        "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
        "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
        "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 58.3
        }
      ],
      "editorialScores": {
        "ergonomics": 69,
        "maintenance": 85,
        "payments": 50,
        "reliability": 80,
        "schema": 51,
        "security": 56,
        "transparency": 76
      },
      "provenanceScore": 68
    },
    "connect": {
      "install": "npm install @tryghost/admin-api",
      "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
    },
    "letme": {
      "capability": "https://letme.dev/cms.content",
      "tool": "https://letme.dev/ghost"
    },
    "notable": [
      "Integrations can browse, read, add, edit, copy and delete posts and pages, manage tag, tier, newsletter, offer, member, label and webhook records, upload images and upload or activate themes, all marked stable (https://docs.ghost.org/admin-api)",
      "Editing a post requires its current `updated_at`, used for collision detection, and `save_revision=true` stores a revision with the update (https://docs.ghost.org/admin-api/posts/updating-a-post)",
      "Ghost 6.0 removed `limit=all`. Any list request now returns at most 100 items, without an error (https://docs.ghost.org/changes)",
      "20 security advisories were published between 3 September and 1 October 2026, one critical and ten high (https://github.com/TryGhost/Ghost/security/advisories)",
      "On Ghost(Pro) the Admin API, custom integrations and custom themes start at the Publisher plan (https://ghost.org/pricing/)",
      "The official MCP registry lists third-party Ghost servers only, and no MCP server was found in the Ghost repository or docs (https://registry.modelcontextprotocol.io/v0/servers?search=ghost)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Graded surface",
        "value": "Self-hosted Ghost 6.69.0 through the Admin API, authenticated as a custom integration. Ghost(Pro) runs the same software and API at a `*.ghost.io` admin domain. No official MCP server was found"
      },
      {
        "label": "Admin API",
        "value": "REST and JSON at https://{admin_domain}/ghost/api/admin/. Requests and responses wrap resources in an array under the resource name. Documented stable resources are post, page, tag, tier, newsletter, offer, member, label, user (read only), image, theme, site and webhook. More routes exist for user sessions and aren't documented"
      },
      {
        "label": "Credentials",
        "value": "Admin API key per custom integration (id and hex secret), regenerable, used to sign HS256 tokens valid for at most 5 minutes. Staff access tokens per user with that user's role. Email and password sessions with device verification or two-factor codes"
      },
      {
        "label": "Permissions",
        "value": "One fixed permission set for every integration, with no scopes. Staff roles are Contributor, Author, Editor, Administrator and Owner. Staff tokens can't transfer ownership or delete all content"
      },
      {
        "label": "Draft and publish",
        "value": "`status` on the post. Publish with a PUT that sets `status` to `published`. Contributors can add and edit drafts but can't change status (post model in the repository)"
      },
      {
        "label": "Content format",
        "value": "Lexical JSON as a string, or HTML with `?source=html`, converted to Lexical with possible loss. `formats=html,lexical` returns both"
      },
      {
        "label": "Assets",
        "value": "`POST /images/upload/` as multipart form data with `file`, `purpose` (image, profile_image or icon) and an optional `ref`. WEBP, JPEG, GIF, PNG and SVG. The routes file also holds media and file upload routes that the reference doesn't document"
      },
      {
        "label": "Version history",
        "value": "`save_revision=true` on an update stores a revision. The post model keeps up to 25 revisions per post. No documented Admin API route restores one"
      },
      {
        "label": "Localisation and content types",
        "value": "None. Posts and pages have fixed fields and no locales"
      },
      {
        "label": "Pagination and filtering",
        "value": "`page`, `limit` (default 15, maximum 100), `order`, `filter`, `fields`, `include` and `formats`"
      },
      {
        "label": "Versioning",
        "value": "`Accept-Version: v{major}.{minor}` states the minimum version a client works with, and Ghost answers with `Content-Version`. Endpoints are marked stable, experimental or deprecated"
      },
      {
        "label": "Rate limits",
        "value": "No Admin API rate limit was found in the docs. Staff logins and password resets are limited to 5 an hour per IP address. Ghost(Pro) applies a fair use policy with 50 GB to 500 GB a month of bandwidth for headless use"
      },
      {
        "label": "Audit",
        "value": "An actions log readable at `GET /actions` with user authentication or an integration's `action` permission. No per-call log was found"
      },
      {
        "label": "Machine-readable docs",
        "value": "llms.txt (177 links), llms-full.txt and a .md copy of every page. No OpenAPI file"
      },
      {
        "label": "Runtime",
        "value": "Node.js ^22.23.1 or ^24.20.0. The supported stack is Ubuntu 22.04, 24.04 or 26.04, MySQL 8.0 or 8.4, NGINX and systemd, installed with Ghost-CLI. A Docker Compose install is in preview"
      },
      {
        "label": "Client library",
        "value": "@tryghost/admin-api 1.14.13 for JavaScript (21 September 2026)"
      },
      {
        "label": "Ghost(Pro)",
        "value": "Starter $18, Publisher $29, Business $199 a month billed yearly at up to 1,000 members, and Custom with a 99.9 per cent uptime SLA. File size limits of 5 MB, 100 MB, 250 MB and 1 GB"
      }
    ],
    "unitPrices": [
      {
        "item": "Self-hosted Ghost",
        "unit": "month",
        "usd": 0,
        "note": "MIT, you pay for your own hosting and email delivery"
      },
      {
        "item": "Ghost(Pro) Starter",
        "unit": "month",
        "usd": 18,
        "note": "billed yearly, up to 1,000 members, no Admin API"
      },
      {
        "item": "Ghost(Pro) Publisher",
        "unit": "month",
        "usd": 29,
        "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
      },
      {
        "item": "Ghost(Pro) Business",
        "unit": "month",
        "usd": 199,
        "note": "billed yearly, up to 1,000 members, 15 staff users"
      }
    ],
    "provenance": {
      "legalEntity": "Ghost Foundation Ltd",
      "domain": "ghost.org",
      "domainRegistered": "2005-06-25",
      "endpointOnVendorDomain": false,
      "terms": "https://ghost.org/terms/",
      "privacy": "https://ghost.org/privacy/",
      "statusPage": "https://ghoststatus.org",
      "changelog": "https://github.com/TryGhost/Ghost/releases",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
        "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
        "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
        "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
        "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
        "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
      ],
      "score": 68,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Ghost Foundation Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "ghost.org, registered 2005-06-25 (21 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on ghost.org",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 3 of the 8 things a reader expects",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "ghoststatus.org",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://ghost.org/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 5011,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Agreement and these conditions shall be governed by and construed in accordance with the law of England and Wales.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Without prejudice to the above and to the extent permitted by law, in the event that Ghost Foundation is found to be liable to you in any way, such liability will be limited to the amount of fees paid by you to Ghost Foundation under this agreement during the twelve (12) month period prior to the cause of action.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Ghost Foundation will terminate a user's access to and use of our Services if the user is determined, at Ghost Foundation’s sole and unfettered discretion, to be a repeat infringer of the copyrights or other intellectual property rights of Ghost Foundation or others."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Your continued use of or access to the Website following the posting of any changes to this Agreement constitutes acceptance of those changes.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to all the terms and conditions of this Agreement, then you may not access the Website or use any Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Guaranteed minimum uptime: The Ghost Foundation hosted services and platform (collectively, the “System”) shall have a minimum of 98% uptime, excluding any scheduled maintenance, calculated on a monthly basis.",
              "says": "Names 98% availability"
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Accounts registered by \"bots\" or other automated methods are not permitted.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Terminate or deny access to and use of the Services to any individual or entity at any time and for any reason."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers grant Ghost Foundation a perpetual, irrevocable and sublicensable licence over their content, limited to displaying, distributing and promoting their site.",
              "quote": "you grant Ghost Foundation a perpetual, irrevocable, world-wide, sublicensable, royalty-free, and non-exclusive license to reproduce, modify, adapt and publish Your Content solely for the purpose of displaying, distributing and promoting your site."
            },
            {
              "date": "2026-10-08",
              "text": "Each login may be used by one person only, and the same section says the account holder must be a human.",
              "quote": "Your login may only be used by one person - a single login shared by multiple people is not permitted."
            },
            {
              "date": "2026-10-08",
              "text": "The list of prohibitions bars using any Service or the Content for a commercial purpose or for the benefit of a third party.",
              "quote": "Use any Service or the Content for any commercial purpose or the benefit of any third party or in any manner not permitted by this Agreement;"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://ghost.org/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 1788,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Types of data we collect and how we obtain it"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Ghost Foundation integrates with third party platforms to provide you with a seamless range of features and services."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Where you request integrations with third parties, we may share data with them as required to facilitate and give effect to the integration."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
    "live": {
      "slug": "ghost",
      "vendorStatus": {
        "page": "https://ghoststatus.org",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:06:40.232515614Z"
      },
      "pages": [
        {
          "url": "https://ghost.org/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:20:39.9398284Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "6de86a225cdd"
        },
        {
          "url": "https://ghost.org/terms/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:20:42.180060747Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "673039b71aa4"
        }
      ],
      "updatedAt": "2026-10-08T19:06:40.232515614Z"
    }
  }
}
