{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "storyblok",
    "name": "Storyblok",
    "vendor": "Storyblok GmbH",
    "vendorUrl": "https://www.storyblok.com",
    "kind": "http-api",
    "category": "cms",
    "summary": "Storyblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools.",
    "url": "https://www.anchorterminal.com/tools/storyblok",
    "markdownUrl": "https://www.anchorterminal.com/tools/storyblok.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/storyblok.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/storyblok.json",
    "repo": "https://github.com/storyblok/monoblok",
    "license": "Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://mapi.storyblok.com/v1",
    "packages": [
      {
        "registry": "npm",
        "name": "@storyblok/management-api-client"
      },
      {
        "registry": "npm",
        "name": "storyblok-js-client"
      },
      {
        "registry": "npm",
        "name": "storyblok"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. The Management API takes a personal access token or an OAuth token in the request header. A person creates the token in account settings and picks scopes (16 groups such as stories, assets and components, on a read, write and publish hierarchy), the spaces it covers and an expiry date. The MCP server uses browser OAuth with PKCE and dynamic client registration, where the person picks permissions and spaces on a consent screen, or the same token as a Bearer header. No app review or sales approval is needed. The changelog describes OAuth scoped grants for custom integrations as a Premium and Enterprise feature. Content Delivery API tokens are read-only and travel in the `token` query parameter.",
    "pricing": "freemium",
    "pricingNotes": "Starter is free with no card and includes the Management API, 100,000 API requests a month, 1 seat and 2 locales. Growth is $99 a month and Growth Plus $349 a month billed monthly. Premium and Elite are sold through sales. New spaces start with a 45-day Growth Plus trial. On Growth, extra API requests cost $10 per million and extra seats $15 each (https://www.storyblok.com/pricing, checked 2026-10-07).",
    "priceSummary": "$99 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Management API docs, the MCP server docs or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": 7,
    "popularity": {
      "githubStars": 68,
      "npmWeekly": 432535,
      "pypiWeekly": null,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://www.storyblok.com/docs/api/management",
    "llmsTxt": "https://www.storyblok.com/llms.txt",
    "openapi": "https://www.storyblok.com/docs/openapi-spec/cdn-v2.openapi.yaml",
    "capabilities": [
      "cms.content",
      "cms.publish",
      "cms.assets",
      "cms.localisation",
      "cms.schema"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "closed-source",
      "no-card",
      "free-tier",
      "llms-txt",
      "webhooks",
      "typescript",
      "php",
      "status-page",
      "iso27001"
    ],
    "lastRelease": "2026-10-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.7,
      "grade": "B",
      "agentReady": false,
      "rank": 188,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 80,
        "payments": 35,
        "reliability": 79,
        "schema": 68,
        "security": 73,
        "transparency": 80
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 79,
          "points": 15.8,
          "reason": "Graded on the Management API and the hosted MCP server. Public status page at uptime.storyblok.com with 90 days of daily history for four monitors (Content Delivery API v1 and v2, GraphQL API, Image Service), but none for the Management API or the MCP server (15 of 20). All four show 100 per cent over 90 days and no status updates in the last seven days. With the graded surface unmonitored we read that as 20 of 30. Rate limits published, 3 requests a second on Starter and 6 on paid plans (15). The docs advise slowing down on 429 and retrying with exponential backoff, and the official client retries on 429. No Retry-After header in the API docs and no idempotency keys found (9). SLA of 97 per cent on Growth and Growth Plus, 99.9 on Premium and 99.99 on Elite, stated for the Content Delivery API (10). Management API v1 is generally available and the MCP docs carry no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "The only public OpenAPI spec is for the Content Delivery API (3.1, 14 operations). The Management API spec that the official client is generated from sits in the private storyblok/openapi-wdx repository, per the monoblok README. The MCP `describe` tool returns parameter and body schemas per operation to a signed-in client, which we couldn't read (12 of 25). A root llms.txt and a Markdown copy of every docs page at the same URL plus .md (10). The MCP page says when to use the server and when to use the CLI, and names each tool's purpose (16). The reference types every parameter and marks required ones, but story content is a free-form object checked against the space's component schemas (8). Request examples in nine languages on each endpoint. Errors are covered by one line on standard HTTP codes (9). The /v1 path, a dated changelog with an RSS feed, and changes to v1 made in place (13)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Seven MCP tools cover the whole Management API through search, describe and execute, and a `fields` filter trims responses before they return (25). `page` and `per_page` up to 1,000 with a `total` header, and about 30 filters on the story list (20). Error bodies aren't documented beyond HTTP status codes. Validation failures return 422 with the limit and the current value (8). No idempotency keys. Publish, unpublish and restore are GET requests that change state. MCP splits calls into read-only, mutating and destructive tools, and we couldn't read the tool annotations (10). Few required parameters, and official Management API clients for JavaScript and PHP plus universal clients for Swift and Kotlin (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 73,
          "points": 12.78,
          "reason": "OAuth with PKCE S256, dynamic client registration, refresh tokens, revocation and 29 scopes on a read, write and publish hierarchy, or personal access tokens with scopes, a space list and an expiry date (30). Less 5 because Content Delivery API tokens travel in the `token` query parameter. That is a judgement call. Those tokens are read-only and not the graded surface, so we took half the checklist's 10. Scopes separate read, write and publish per space, and `execute_destructive` needs explicit user confirmation. Unscoped legacy tokens work until 30 November 2026 (18). The changelog names prompt-injected tokens as a risk that scoping limits, and the MCP page asks users to read plans back before writes. No guidance on treating stored content as untrusted (8). Activity log on every plan with an Activities endpoint, kept 1 day on Starter and 30 days on Growth (11). ISO 27001, TISAX, third-party penetration tests and a security contact address. No security.txt, bug bounty or SOC 2 report found (11)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 (0). Plan prices are public ($99 and $349 a month) with unit prices for overage on Growth ($10 per million API requests, $15 a seat, $20 a locale). Premium and Elite are priced through sales (15). Starter is free with no card and includes the Management API (20). A person signs up in a browser and creates the token or approves the OAuth consent screen (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "The changelog has entries on 5 October 2026 and the Management API client 0.9.1 was tagged on 1 October 2026 (30). Eight dated changelog entries and more than ten client releases in the last 90 days (20). Public changelog with RSS, a help centre and a Discord community. Of the five newest GitHub issues, two were closed within a week and three had no reply after 9 to 14 days (10 of 15). Current official SDKs and CLI, though no Storyblok entry in the official MCP registry (13). The monoblok repository has CI, release and commit-lint workflows and 170 commits in 90 days. We didn't check that CI passes (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "note": "editorial 73, provenance 87",
          "reason": "Closed service with published self-service and enterprise terms, and MIT client libraries (17). DPA effective 22 April 2026, privacy policy effective 6 October 2025, customer content kept up to 90 days after termination, log files 30 days, and AI terms saying input isn't used for training. We found no contradiction between them (25). No written deprecation policy, but dated notices, such as six months for unscoped tokens (30 November 2026) and about a month for Management API validation (13). Sub-processors with locations in DPA Annex 3 and data residency in the EU, US, Canada and Australia (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Seven MCP tools cover the whole Management API through search, describe and execute, and a `fields` filter trims responses before they return (25). `page` and `per_page` up to 1,000 with a `total` header, and about 30 filters on the story list (20). Error bodies aren't documented beyond HTTP status codes. Validation failures return 422 with the limit and the current value (8). No idempotency keys. Publish, unpublish and restore are GET requests that change state. MCP splits calls into read-only, mutating and destructive tools, and we couldn't read the tool annotations (10). Few required parameters, and official Management API clients for JavaScript and PHP plus universal clients for Swift and Kotlin (15).",
          "maintenance": "The changelog has entries on 5 October 2026 and the Management API client 0.9.1 was tagged on 1 October 2026 (30). Eight dated changelog entries and more than ten client releases in the last 90 days (20). Public changelog with RSS, a help centre and a Discord community. Of the five newest GitHub issues, two were closed within a week and three had no reply after 9 to 14 days (10 of 15). Current official SDKs and CLI, though no Storyblok entry in the official MCP registry (13). The monoblok repository has CI, release and commit-lint workflows and 170 commits in 90 days. We didn't check that CI passes (7).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public ($99 and $349 a month) with unit prices for overage on Growth ($10 per million API requests, $15 a seat, $20 a locale). Premium and Elite are priced through sales (15). Starter is free with no card and includes the Management API (20). A person signs up in a browser and creates the token or approves the OAuth consent screen (0).",
          "reliability": "Graded on the Management API and the hosted MCP server. Public status page at uptime.storyblok.com with 90 days of daily history for four monitors (Content Delivery API v1 and v2, GraphQL API, Image Service), but none for the Management API or the MCP server (15 of 20). All four show 100 per cent over 90 days and no status updates in the last seven days. With the graded surface unmonitored we read that as 20 of 30. Rate limits published, 3 requests a second on Starter and 6 on paid plans (15). The docs advise slowing down on 429 and retrying with exponential backoff, and the official client retries on 429. No Retry-After header in the API docs and no idempotency keys found (9). SLA of 97 per cent on Growth and Growth Plus, 99.9 on Premium and 99.99 on Elite, stated for the Content Delivery API (10). Management API v1 is generally available and the MCP docs carry no beta label (10).",
          "schema": "The only public OpenAPI spec is for the Content Delivery API (3.1, 14 operations). The Management API spec that the official client is generated from sits in the private storyblok/openapi-wdx repository, per the monoblok README. The MCP `describe` tool returns parameter and body schemas per operation to a signed-in client, which we couldn't read (12 of 25). A root llms.txt and a Markdown copy of every docs page at the same URL plus .md (10). The MCP page says when to use the server and when to use the CLI, and names each tool's purpose (16). The reference types every parameter and marks required ones, but story content is a free-form object checked against the space's component schemas (8). Request examples in nine languages on each endpoint. Errors are covered by one line on standard HTTP codes (9). The /v1 path, a dated changelog with an RSS feed, and changes to v1 made in place (13).",
          "security": "OAuth with PKCE S256, dynamic client registration, refresh tokens, revocation and 29 scopes on a read, write and publish hierarchy, or personal access tokens with scopes, a space list and an expiry date (30). Less 5 because Content Delivery API tokens travel in the `token` query parameter. That is a judgement call. Those tokens are read-only and not the graded surface, so we took half the checklist's 10. Scopes separate read, write and publish per space, and `execute_destructive` needs explicit user confirmation. Unscoped legacy tokens work until 30 November 2026 (18). The changelog names prompt-injected tokens as a risk that scoping limits, and the MCP page asks users to read plans back before writes. No guidance on treating stored content as untrusted (8). Activity log on every plan with an Activities endpoint, kept 1 day on Starter and 30 days on Growth (11). ISO 27001, TISAX, third-party penetration tests and a security contact address. No security.txt, bug bounty or SOC 2 report found (11).",
          "transparency": "Closed service with published self-service and enterprise terms, and MIT client libraries (17). DPA effective 22 April 2026, privacy policy effective 6 October 2025, customer content kept up to 90 days after termination, log files 30 days, and AI terms saying input isn't used for training. We found no contradiction between them (25). No written deprecation policy, but dated notices, such as six months for unscoped tokens (30 November 2026) and about a month for Management API validation (13). Sub-processors with locations in DPA Annex 3 and data residency in the EU, US, Canada and Australia (18)."
        },
        "sources": [
          {
            "what": "Management API introduction, rate limits and pagination",
            "url": "https://www.storyblok.com/docs/api/management",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP server overview and tools",
            "url": "https://www.storyblok.com/docs/tooling/mcp-server",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP server setup",
            "url": "https://www.storyblok.com/docs/tooling/mcp-server/setup",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP OAuth authorisation server metadata",
            "url": "https://mcp.storyblok.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-07"
          },
          {
            "what": "access tokens",
            "url": "https://www.storyblok.com/docs/concepts/access-tokens",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing and plan comparison",
            "url": "https://www.storyblok.com/pricing",
            "seen": "2026-10-07"
          },
          {
            "what": "technical limits",
            "url": "https://www.storyblok.com/pricing/technical-limits",
            "seen": "2026-10-07"
          },
          {
            "what": "status page",
            "url": "https://uptime.storyblok.com/",
            "seen": "2026-10-07"
          },
          {
            "what": "changelog RSS feed",
            "url": "https://www.storyblok.com/rss/changelog",
            "seen": "2026-10-07"
          },
          {
            "what": "scoped personal access tokens",
            "url": "https://www.storyblok.com/cl/scoped-personal-access-tokens",
            "seen": "2026-10-07"
          },
          {
            "what": "webhook API security fix",
            "url": "https://www.storyblok.com/cl/2026-april-security-fix-webhook-api-now-aligned-with-ui-access-controls",
            "seen": "2026-10-07"
          },
          {
            "what": "Management API validation enforcement",
            "url": "https://www.storyblok.com/cl/we-re-enforcing-field-validation-rules-on-the-management-api",
            "seen": "2026-10-07"
          },
          {
            "what": "Content Delivery API OpenAPI spec",
            "url": "https://www.storyblok.com/docs/openapi-spec/cdn-v2.openapi.yaml",
            "seen": "2026-10-07"
          },
          {
            "what": "monoblok repository (clients, CLI, spec tooling)",
            "url": "https://github.com/storyblok/monoblok",
            "seen": "2026-10-07"
          },
          {
            "what": "trust centre",
            "url": "https://www.storyblok.com/trust-center",
            "seen": "2026-10-07"
          },
          {
            "what": "service levels",
            "url": "https://www.storyblok.com/trust-center/service-level",
            "seen": "2026-10-07"
          },
          {
            "what": "data processing agreement",
            "url": "https://www.storyblok.com/legal/dpa",
            "seen": "2026-10-07"
          },
          {
            "what": "self-service terms",
            "url": "https://www.storyblok.com/legal/self-service-terms",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy policy",
            "url": "https://www.storyblok.com/legal/privacy-policy",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=storyblok",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: MCP tool input schemas and annotations, which need a signed-in session",
          "unchecked: the Management API's OpenAPI spec, which sits in the private storyblok/openapi-wdx repository",
          "unchecked: written incident history on the status page beyond the last seven days. The 90-day uptime bars were readable",
          "unchecked: whether CI passes on the default branch of storyblok/monoblok",
          "Not established whether the MCP server's OAuth flow works on every plan. The 5 August 2026 changelog entry describes OAuth scoped grants for custom integrations as Premium and Enterprise, and the MCP setup page names no plan",
          "Not established whether 429 responses carry a Retry-After header. The official client's README says it honours one, and the API docs don't mention it",
          "Not established when the MCP server launched. Its docs page was last updated on 29 September 2026 and the changelog feed has no entry for it"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "8 April 2026. Storyblok fixed a flaw where the Webhook and Webhook Logs endpoints of the Management API didn't enforce the Admin and Owner restriction the UI applies, so Editor and Restricted roles could manage webhooks by API. It was fixed and disclosed in the changelog, so the deduction is small (https://www.storyblok.com/cl/2026-april-security-fix-webhook-api-now-aligned-with-ui-access-controls)."
      ],
      "verdict": "The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.",
      "bestFor": "Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.",
      "strengths": [
        "Official hosted MCP server at mcp.storyblok.com/mcp with seven tools (search, describe, three execute tools, two for asset upload) and a `fields` filter that trims responses",
        "OAuth with PKCE, dynamic client registration and 29 scopes on a read, write and publish hierarchy, chosen per space on a consent screen",
        "Personal access tokens take scopes, a space list and an expiry date since 27 May 2026, and unscoped tokens are revoked on 30 November 2026",
        "Free Starter plan with no card, 100,000 API requests a month and Management API access on every plan",
        "Every docs page is served as Markdown by adding .md, with request examples in nine languages"
      ],
      "weaknesses": [
        "The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)",
        "Management API limit is 3 requests a second on Starter and 6 on paid plans, with no idempotency keys in the reviewed documentation",
        "The status page monitors four delivery services and has no Management API or MCP monitor",
        "On 8 April 2026 Storyblok fixed webhook endpoints that had let Editor and Restricted roles manage webhooks through the API",
        "Version history is kept for 1 day on Starter and 30 days on Growth, so a rollback depends on the plan"
      ],
      "agentNotes": [
        "Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails",
        "Create stories without `publish` to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it",
        "Write translations as `field__i18n__\u003ccode\u003e` keys inside the same content object, and set the component field to translatable first",
        "Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl",
        "Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.7
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 80,
        "payments": 35,
        "reliability": 79,
        "schema": 68,
        "security": 73,
        "transparency": 73
      },
      "provenanceScore": 87
    },
    "connect": {
      "install": "npm install @storyblok/management-api-client",
      "http": "curl \"https://mapi.storyblok.com/v1/spaces/$SPACE_ID/stories/\" \\\n  -H \"Authorization: $STORYBLOK_PERSONAL_ACCESS_TOKEN\"",
      "claudeCode": "claude mcp add --transport http Storyblok https://mcp.storyblok.com/mcp",
      "config": {
        "mcpServers": {
          "Storyblok": {
            "type": "http",
            "url": "https://mcp.storyblok.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/cms.content",
      "tool": "https://letme.dev/storyblok"
    },
    "notable": [
      "The MCP server is hosted and stateless at https://mcp.storyblok.com/mcp and exposes the Management API only, through `search`, `describe`, `execute_readonly`, `execute_mutating`, `execute_destructive`, `upload_asset` and `upload_asset_finish` (https://www.storyblok.com/docs/tooling/mcp-server)",
      "The MCP authorisation server metadata lists authorisation code and refresh token grants, PKCE S256, a registration endpoint, a revocation endpoint and 29 resource scopes plus offline_access (https://mcp.storyblok.com/.well-known/oauth-authorization-server)",
      "Scoped personal access tokens shipped on 27 May 2026. Existing unscoped tokens are in a six-month transition and are revoked on 30 November 2026 (https://www.storyblok.com/cl/scoped-personal-access-tokens)",
      "Since 6 May 2026 for new spaces and 8 June 2026 for existing ones, the Management API rejects content over a field's max_length or a bloks field's maximum with 422 (https://www.storyblok.com/cl/we-re-enforcing-field-validation-rules-on-the-management-api)",
      "Management API rate limit is 3 calls a second on Starter and 6 on Growth, Growth Plus, Premium and Elite (https://www.storyblok.com/pricing/technical-limits)",
      "Storyblok recommends its CLI over the MCP server for repeatable, high-volume work, citing dry runs and idempotency guarantees in the CLI (https://www.storyblok.com/docs/tooling/mcp-server)",
      "The official MCP registry has no Storyblok-published entry. The one result for storyblok is a third-party stdio server (https://registry.modelcontextprotocol.io/v0/servers?search=storyblok)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "Management API v1 (REST, JSON) for writes, official hosted MCP server over the same API, Content Delivery API v2 and GraphQL (Premium and Elite) for reads, Storyblok CLI for scripted work"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.storyblok.com/mcp, streamable HTTP, POST only. Seven tools in a search, describe, execute pattern. OAuth or a personal access token as a Bearer header"
      },
      {
        "label": "Regions",
        "value": "EU mapi.storyblok.com, US api-us.storyblok.com, Canada api-ca.storyblok.com, Australia api-ap.storyblok.com, China app.storyblokchina.cn, each under /v1"
      },
      {
        "label": "Credentials",
        "value": "OAuth with PKCE and dynamic client registration, 29 scopes on a read, write and publish hierarchy, per-space selection, refresh tokens and revocation. Personal access tokens with 16 scope groups, a space list and an expiry date"
      },
      {
        "label": "Rate limits",
        "value": "Management API 3 requests a second on Starter, 6 on paid plans. Content Delivery API up to 1,000 a second cached, 50 a second for single entries uncached"
      },
      {
        "label": "Free tier",
        "value": "Starter is free with no card. 1 space, 1 seat, 100,000 API requests a month, 2 locales, 20,000 stories, 2,000 assets. New spaces get a 45-day trial of Growth Plus"
      },
      {
        "label": "Drafts and versions",
        "value": "Stories are drafts unless created with publish true. Publish, unpublish, version list, version compare and restore endpoints. Version retention 1 day on Starter, 30 days on Growth and Growth Plus, 180 days on Premium, unlimited on Elite"
      },
      {
        "label": "Assets",
        "value": "Three-step upload (signed response, POST to S3, finish upload). Maximum file size 500 MB on Starter, 1 GB on Growth and Growth Plus, 5 GB on Premium and Elite"
      },
      {
        "label": "Localisation",
        "value": "Field-level translations written as `field__i18n__\u003ccode\u003e` keys in the story content, and folder-level translation. 2 locales on Starter and Growth, 10 on Growth Plus"
      },
      {
        "label": "Pagination",
        "value": "`page` and `per_page` (default 25, maximum 1,000 on the Management API), with `total` and `per_page` response headers. The MCP execute tools take a `fields` filter"
      },
      {
        "label": "SDKs",
        "value": "@storyblok/management-api-client 0.9.1 (1 October 2026) and storyblok-js-client 7.7.7 for JavaScript, php-management-api-client, storyblok-swift and storyblok-kotlin. The CLI is the npm package storyblok, 4.23.4"
      },
      {
        "label": "Audit",
        "value": "Activity log on every plan, readable through the Activities endpoints. Activity and webhook log retention follows version retention (1 day to unlimited)"
      },
      {
        "label": "SLA",
        "value": "97 per cent annual average on Growth and Growth Plus, 99.9 per cent on Premium, 99.99 per cent on Elite, none on Starter. The service level page states it for the Content Delivery API"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001 and TISAX per the trust centre. No SOC 2 report or bug bounty found in the reviewed pages"
      },
      {
        "label": "Sub-processors",
        "value": "DPA Annex 3 (effective 22 April 2026) lists AWS for hosting in the EU, US, Canada and Australia, Tiptap, and OpenAI, Google Cloud and Anthropic for AI tools"
      },
      {
        "label": "Open source",
        "value": "No. The SDKs, API clients and CLI in storyblok/monoblok are MIT"
      }
    ],
    "unitPrices": [
      {
        "item": "Growth",
        "unit": "month",
        "usd": 99,
        "note": "billed monthly, $90.75 billed yearly, 5 seats and 1M API requests included"
      },
      {
        "item": "Growth Plus",
        "unit": "month",
        "usd": 349,
        "note": "billed monthly, $319.91 billed yearly, 15 seats and 4M API requests included"
      },
      {
        "item": "Additional seat",
        "unit": "seat-month",
        "usd": 15,
        "note": "Starter (up to 2 seats) and Growth (up to 10)"
      },
      {
        "item": "Additional API requests on Growth",
        "unit": "1k-requests",
        "usd": 0.01,
        "note": "sold as $10 per 1M, up to 5M a month"
      }
    ],
    "provenance": {
      "legalEntity": "Storyblok GmbH",
      "domain": "storyblok.com",
      "domainRegistered": "2015-08-15",
      "endpointOnVendorDomain": true,
      "terms": "https://www.storyblok.com/legal/terms",
      "privacy": "https://www.storyblok.com/legal/privacy-policy",
      "statusPage": "https://uptime.storyblok.com",
      "changelog": "https://www.storyblok.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-07",
      "notes": [
        "The legal notice names Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria, company register number FN 479743 f, Regional Court Linz.",
        "The Management API answers on storyblok.com subdomains and the MCP server at mcp.storyblok.com. Spaces in China use app.storyblokchina.cn.",
        "security.txt returns 404 on www.storyblok.com, storyblok.com and mapi.storyblok.com. The privacy policy gives security@storyblok.com for security matters.",
        "The terms page was last updated on 2 October 2026 and links separate self-service and enterprise terms. The self-service terms are governed by Austrian law.",
        "RDAP for storyblok.com gives a registration date of 2015-08-15.",
        "The status page runs on UptimeRobot with four monitors (Content Delivery API v1 and v2, GraphQL API, Image Service)."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Storyblok GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "storyblok.com, registered 2015-08-15 (11 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mapi.storyblok.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "uptime.storyblok.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.storyblok.com/legal/terms",
          "state": "unreadable",
          "reason": "the page at this address is a list of links to several documents, not the document itself",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.storyblok.com/legal/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-06",
          "words": 13214,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective October 06, 2025",
              "says": "Last updated 2025-10-06"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "To work with these partners, we collect business contact information and other related data from relevant employees of those business partners."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Financial records have to be kept 7 years according to applicable law (e.g.",
              "says": "Names a period of 7 years"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We use Segment to handle implementation of and data transfers to analytics and marketing service providers detailed below."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell, rent, or share your personal data for money or anything else of value, and have not done so within the last 12 months.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to object to the processing of your personal data for this purpose at any time."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Alternatively you can also contact our data protection officer (DPO) of Storyblok GmbH: Dr.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "For the transfer of Personal Data to the United States, Storyblok relies on the EU-US Data Privacy Framework, and the UK Extension to the EU-U.S.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "After an administrator asserts control over an account, the user may be unable to withdraw membership or change the account email address without administrator approval.",
              "quote": "Once an administrator asserts control over your account or use of the Storyblok Services, you may no longer be able to withdraw membership or change the email address associated with your account without administrator approval."
            },
            {
              "date": "2026-10-08",
              "text": "Deactivating access to a space does not delete the user's information from it, and content the user added stays visible to other users.",
              "quote": "Please be aware that deactivating access to a space does not delete your information from that space; your added content remains visible to other Storyblok Service users based on your past participation within the Services."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/storyblok.json",
    "live": {
      "slug": "storyblok",
      "probe": {
        "target": "https://mapi.storyblok.com/v1",
        "method": "get",
        "lastAt": "2026-10-08T19:08:59.399751867Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 103,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 55,
        "p95ms24h": 99,
        "samples24h": 42,
        "samples30d": 42,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 42,
            "ok": 42
          }
        ]
      },
      "vendorStatus": {
        "page": "https://uptime.storyblok.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:51:13.801607821Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "storyblok/monoblok",
          "version": "storyblok@4.23.4",
          "released": "2026-10-02",
          "seenAt": "2026-10-08T16:30:30.68015309Z"
        },
        {
          "registry": "npm",
          "name": "@storyblok/management-api-client",
          "version": "0.9.1",
          "seenAt": "2026-10-08T16:30:26.446005464Z"
        },
        {
          "registry": "npm",
          "name": "storyblok",
          "version": "4.23.4",
          "seenAt": "2026-10-08T16:30:28.73366054Z"
        },
        {
          "registry": "npm",
          "name": "storyblok-js-client",
          "version": "7.7.7",
          "seenAt": "2026-10-08T16:30:27.249684993Z"
        }
      ],
      "githubStars": 68,
      "npmWeekly": 94500,
      "securityTxt": {
        "url": "https://storyblok.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:51.218593751Z"
      },
      "pages": [
        {
          "url": "https://www.storyblok.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:42.335720318Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "5ca6efffc344"
        },
        {
          "url": "https://www.storyblok.com/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:48.641769602Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "f2ecb91f1df2"
        },
        {
          "url": "https://www.storyblok.com/legal/privacy-policy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:44.809888853Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "24506da32465"
        },
        {
          "url": "https://www.storyblok.com/legal/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:46.89854338Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b848b65d0369"
        }
      ],
      "updatedAt": "2026-10-08T19:08:59.399751867Z"
    }
  }
}
