{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "webflow",
    "name": "Webflow",
    "vendor": "Webflow, Inc.",
    "vendorUrl": "https://webflow.com",
    "kind": "http-api",
    "category": "cms",
    "summary": "Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.",
    "url": "https://www.anchorterminal.com/tools/webflow",
    "markdownUrl": "https://www.anchorterminal.com/tools/webflow.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/webflow.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/webflow.json",
    "repo": "https://github.com/webflow/openapi-spec",
    "license": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.webflow.com/v2",
    "packages": [
      {
        "registry": "npm",
        "name": "webflow-api"
      },
      {
        "registry": "pypi",
        "name": "webflow"
      },
      {
        "registry": "npm",
        "name": "webflow-mcp-server"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps \u0026 integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens.",
    "pricing": "freemium",
    "pricingNotes": "The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).",
    "priceSummary": "$15 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 34,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 85160,
      "pypiWeekly": 121246,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.webflow.com/data/docs",
    "llmsTxt": "https://developers.webflow.com/llms.txt",
    "openapi": "https://raw.githubusercontent.com/webflow/openapi-spec/main/openapi/v2.yml",
    "registryName": "com.webflow/mcp",
    "capabilities": [
      "cms.content",
      "cms.publish",
      "cms.assets",
      "cms.schema",
      "cms.localisation"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "closed-source",
      "free-tier",
      "webhooks",
      "typescript",
      "python",
      "status-page",
      "soc2",
      "iso27001"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 69.4,
      "grade": "B",
      "agentReady": false,
      "rank": 150,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 80,
        "payments": 30,
        "reliability": 79,
        "schema": 87,
        "security": 74,
        "transparency": 81
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 79,
          "points": 15.8,
          "reason": "Graded on the Data API v2 and the hosted MCP server. Public status page at status.webflow.com with components for the Data API and the MCP server and a full incident history (20). Since 10 July 2026 the graded surface had four incidents, all marked minor (MCP tools missing from 9 to 16 July, outgoing webhooks on 28 July, 503 errors on the MCP server for about two hours on 25 August, MCP authorisation for client workspaces on 17 September). Two major incidents and one critical one in the same period were on hosted site pages and form emails, outside the graded surface. We read that as 15 of 30, between minor only and one major, because the July incident ran for a week. Rate limits published, 60 requests a minute on Starter and Basic and 120 on higher site plans (15). 429 carries Retry-After and the SDKs back off, but no idempotency keys were found for Data API writes (11). An SLA page dated 1 September 2026 exists and the pricing page lists enhanced SLAs on Enterprise. The terms sit in a PDF we didn't read (8 of 10). The /v2 namespace is described as production and the MCP server has a separate beta URL (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 87,
          "points": 14.14,
          "reason": "Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. The hosted MCP server's v2.1 tool schemas aren't in the public repository, whose last commit is 10 April 2026 (23 of 25). A root llms.txt, section indexes and a Markdown copy of every page at the URL plus .md (10). The MCP data tools reference says for each tool whether it reads or writes, when to use it and what each action needs (16). The spec types parameters with enums and required fields. Item content in `fieldData` is an object checked against the collection's own schema (11). Request and response examples throughout, an error format with `code`, `message` and `details`, and an enumerated list of about 100 error codes (13). /v2 and /beta in the path and a dated changelog with a full index, though some changes land in place on the day (14)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for `get_more_tools`, which loads specialised tools on request, and for tools labelled read or write (11 of 25). `limit` up to 100 and `offset` on lists, and custom-field filters and sorts on collection items with up to 10 filter terms (20). Errors carry a machine-readable code from a published list, and the MCP server returns `ModeForbidden` when a tool can't run in the current Designer mode (16). No idempotency keys on Data API writes. The open-source server sets `readOnlyHint` on its tools, and the hosted server has a dry run and an idempotency key for Webflow Cloud deploys only (10 of 20). Few required parameters, and official SDKs for JavaScript and Python (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 74,
          "points": 12.95,
          "reason": "OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days without use. The MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint. Tokens travel in the Authorization header. We took 2 off because the MCP metadata also accepts the `plain` challenge method and site-token rotation isn't described (28). Scopes split read from write, the person picks sites or a workspace at authorisation, and the MCP server follows the user's role. A granted tool grants all its actions and no confirmation step for deletes was found (14). Agent Instructions stored on a site are given to every connected agent automatically, and the docs give no guidance on treating site content as untrusted beyond limiting authorised sites and reviewing generated drafts (5). Agent changes are recorded in the site activity log, which the pricing page lists on Team and Enterprise, with an Audit Logs API on Enterprise (9). A valid security.txt pointing to a Bugcrowd disclosure programme, SOC 2 Type II, ISO 27001, 27017, 27018 and 42001, and an annual penetration test report in the trust centre (18)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public (Basic $15 and Premium $25 a month billed yearly, Team $2,500 a month on an annual contract), with Enterprise through sales and no per-call price (10). The Starter site plan is free and includes the CMS APIs at 60 requests a minute and the MCP server. The pricing page doesn't say whether signup needs a card (20, with that caveat). A person signs up in a browser and creates the token or approves the OAuth screen (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "The newest developer changelog entry is dated 7 October 2026 (30). Sixteen dated entries since 10 July 2026, among them MCP v2.0.1 on 21 July and MCP v2.1 on 21 September (20). Public changelog, a support site and a community forum. We couldn't read the GitHub issue trackers, and the open-source MCP repository has had no commits since 10 April 2026 while the hosted server moved to v2.1 (8 of 15). The server is in the official MCP registry as com.webflow/mcp, and the JavaScript SDK (3.3.4, 16 March 2026) and Python SDK (2.0.0, 12 March 2026) are current (15). The JavaScript SDK repository has CI and a dependency patch merged on 6 October 2026. The MCP repository pins webflow-api 3.2.1 (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "note": "editorial 65, provenance 97",
          "reason": "Closed service with published Terms of Service and Developer Terms. The OpenAPI spec, both SDKs and the older open-source MCP server are MIT (17). Privacy policy effective 17 March 2025 and a DPA effective 15 November 2023 with deletion or return of personal data at termination. Retention is stated as for as long as necessary, with no periods (20). A dated v1 deprecation notice (31 March 2025) and a removal notice for the User Accounts APIs, but no written deprecation policy, and two breaking changes in the last 90 days landed on the day of their changelog entry (11). Sub-processor list updated 9 July 2026 with each company's country, nearly all in the USA. No choice of data region was found (17)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for `get_more_tools`, which loads specialised tools on request, and for tools labelled read or write (11 of 25). `limit` up to 100 and `offset` on lists, and custom-field filters and sorts on collection items with up to 10 filter terms (20). Errors carry a machine-readable code from a published list, and the MCP server returns `ModeForbidden` when a tool can't run in the current Designer mode (16). No idempotency keys on Data API writes. The open-source server sets `readOnlyHint` on its tools, and the hosted server has a dry run and an idempotency key for Webflow Cloud deploys only (10 of 20). Few required parameters, and official SDKs for JavaScript and Python (15).",
          "maintenance": "The newest developer changelog entry is dated 7 October 2026 (30). Sixteen dated entries since 10 July 2026, among them MCP v2.0.1 on 21 July and MCP v2.1 on 21 September (20). Public changelog, a support site and a community forum. We couldn't read the GitHub issue trackers, and the open-source MCP repository has had no commits since 10 April 2026 while the hosted server moved to v2.1 (8 of 15). The server is in the official MCP registry as com.webflow/mcp, and the JavaScript SDK (3.3.4, 16 March 2026) and Python SDK (2.0.0, 12 March 2026) are current (15). The JavaScript SDK repository has CI and a dependency patch merged on 6 October 2026. The MCP repository pins webflow-api 3.2.1 (7).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public (Basic $15 and Premium $25 a month billed yearly, Team $2,500 a month on an annual contract), with Enterprise through sales and no per-call price (10). The Starter site plan is free and includes the CMS APIs at 60 requests a minute and the MCP server. The pricing page doesn't say whether signup needs a card (20, with that caveat). A person signs up in a browser and creates the token or approves the OAuth screen (0).",
          "reliability": "Graded on the Data API v2 and the hosted MCP server. Public status page at status.webflow.com with components for the Data API and the MCP server and a full incident history (20). Since 10 July 2026 the graded surface had four incidents, all marked minor (MCP tools missing from 9 to 16 July, outgoing webhooks on 28 July, 503 errors on the MCP server for about two hours on 25 August, MCP authorisation for client workspaces on 17 September). Two major incidents and one critical one in the same period were on hosted site pages and form emails, outside the graded surface. We read that as 15 of 30, between minor only and one major, because the July incident ran for a week. Rate limits published, 60 requests a minute on Starter and Basic and 120 on higher site plans (15). 429 carries Retry-After and the SDKs back off, but no idempotency keys were found for Data API writes (11). An SLA page dated 1 September 2026 exists and the pricing page lists enhanced SLAs on Enterprise. The terms sit in a PDF we didn't read (8 of 10). The /v2 namespace is described as production and the MCP server has a separate beta URL (10).",
          "schema": "Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. The hosted MCP server's v2.1 tool schemas aren't in the public repository, whose last commit is 10 April 2026 (23 of 25). A root llms.txt, section indexes and a Markdown copy of every page at the URL plus .md (10). The MCP data tools reference says for each tool whether it reads or writes, when to use it and what each action needs (16). The spec types parameters with enums and required fields. Item content in `fieldData` is an object checked against the collection's own schema (11). Request and response examples throughout, an error format with `code`, `message` and `details`, and an enumerated list of about 100 error codes (13). /v2 and /beta in the path and a dated changelog with a full index, though some changes land in place on the day (14).",
          "security": "OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days without use. The MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint. Tokens travel in the Authorization header. We took 2 off because the MCP metadata also accepts the `plain` challenge method and site-token rotation isn't described (28). Scopes split read from write, the person picks sites or a workspace at authorisation, and the MCP server follows the user's role. A granted tool grants all its actions and no confirmation step for deletes was found (14). Agent Instructions stored on a site are given to every connected agent automatically, and the docs give no guidance on treating site content as untrusted beyond limiting authorised sites and reviewing generated drafts (5). Agent changes are recorded in the site activity log, which the pricing page lists on Team and Enterprise, with an Audit Logs API on Enterprise (9). A valid security.txt pointing to a Bugcrowd disclosure programme, SOC 2 Type II, ISO 27001, 27017, 27018 and 42001, and an annual penetration test report in the trust centre (18).",
          "transparency": "Closed service with published Terms of Service and Developer Terms. The OpenAPI spec, both SDKs and the older open-source MCP server are MIT (17). Privacy policy effective 17 March 2025 and a DPA effective 15 November 2023 with deletion or return of personal data at termination. Retention is stated as for as long as necessary, with no periods (20). A dated v1 deprecation notice (31 March 2025) and a removal notice for the User Accounts APIs, but no written deprecation policy, and two breaking changes in the last 90 days landed on the day of their changelog entry (11). Sub-processor list updated 9 July 2026 with each company's country, nearly all in the USA. No choice of data region was found (17)."
        },
        "sources": [
          {
            "what": "developer docs index (llms.txt)",
            "url": "https://developers.webflow.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server overview and limitations",
            "url": "https://developers.webflow.com/mcp/reference/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server, how it works",
            "url": "https://developers.webflow.com/mcp/reference/how-it-works",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP data tools reference",
            "url": "https://developers.webflow.com/mcp/tools/data-tools",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP utility tools reference",
            "url": "https://developers.webflow.com/mcp/tools/utility-tools",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP install for Claude Code",
            "url": "https://developers.webflow.com/mcp/installing/claude-code",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth authorisation server metadata",
            "url": "https://mcp.webflow.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://developers.webflow.com/data/reference/rate-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "error handling",
            "url": "https://developers.webflow.com/data/reference/error-handling",
            "seen": "2026-10-08"
          },
          {
            "what": "scopes",
            "url": "https://developers.webflow.com/data/reference/scopes",
            "seen": "2026-10-08"
          },
          {
            "what": "site tokens",
            "url": "https://developers.webflow.com/data/v2.0.0/reference/authentication/site-token",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth and token revocation",
            "url": "https://developers.webflow.com/data/v2.0.0/reference/oauth-app",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning",
            "url": "https://developers.webflow.com/data/reference/versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "publishing with the CMS API",
            "url": "https://developers.webflow.com/data/docs/working-with-the-cms/publishing",
            "seen": "2026-10-08"
          },
          {
            "what": "List Collection Items reference",
            "url": "https://developers.webflow.com/data/reference/cms/collection-items/staged-items/list-items",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog index",
            "url": "https://developers.webflow.com/home/changelog/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog entry, Get Site Plan breaking change",
            "url": "https://developers.webflow.com/home/changelog/2026/10/7",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog entry, translatable parameter change",
            "url": "https://developers.webflow.com/home/changelog/2026/7/29",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec repository",
            "url": "https://github.com/webflow/openapi-spec",
            "seen": "2026-10-08"
          },
          {
            "what": "open-source MCP server repository",
            "url": "https://github.com/webflow/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript SDK repository",
            "url": "https://github.com/webflow/js-webflow-api",
            "seen": "2026-10-08"
          },
          {
            "what": "status page incident history",
            "url": "https://status.webflow.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://webflow.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://webflow.com/legal/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "Developer Terms of Service",
            "url": "https://webflow.com/legal/developer-terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://webflow.com/legal/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing addendum",
            "url": "https://webflow.com/legal/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://webflow.com/legal/subprocessors",
            "seen": "2026-10-08"
          },
          {
            "what": "service level agreement page",
            "url": "https://webflow.com/legal/sla",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://webflow.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://trust.webflow.com",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://webflow.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=webflow",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, webflow-api",
            "url": "https://registry.npmjs.org/webflow-api/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI, webflow",
            "url": "https://pypi.org/pypi/webflow/json",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: GitHub stars and open issues for webflow/mcp-server and webflow/js-webflow-api. The GitHub API refused us for its rate limit, so responsiveness on issues wasn't read",
          "unchecked: the SLA terms and uptime figure, which sit in a PDF linked from webflow.com/legal/sla",
          "unchecked: the hosted MCP server's v2.1 tool input schemas and annotations, which need a signed-in session. The public repository stops at v1.2 (10 April 2026)",
          "unchecked: whether CI passes on the default branches of the SDK and MCP repositories",
          "Not established whether signup for the free Starter plan needs a card. The pricing page lists it as free and doesn't say",
          "Not established which price belongs to monthly billing. The pricing text shows yearly-billed prices, and the page's price attributes suggest $25 a month for Basic and $39 for Premium billed monthly",
          "Not established whether the Starter plan can publish a single CMS item. The pricing table marks per-item publishing as absent on Starter and Basic",
          "Not established when MCP v2.0 shipped or how much notice its tool renames had. The migration guide lists renames across v1.3, v2.0, v2.0.1 and v2.1",
          "The rate limits page still uses older plan names (CMS, eCommerce, Business), while the pricing page lists Starter, Basic and Premium",
          "The lead's docs URL (data/docs/ai-tools) is an older page that still describes the Bridge App as required and remote authorisation as experimental. The current MCP docs are under developers.webflow.com/mcp"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7)."
      ],
      "verdict": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
      "bestFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
      "strengths": [
        "Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page",
        "OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens",
        "CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call",
        "429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically",
        "Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page"
      ],
      "weaknesses": [
        "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions",
        "No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute",
        "The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales",
        "The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise",
        "On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day"
      ],
      "agentNotes": [
        "Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes",
        "Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes",
        "Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429",
        "Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms",
        "Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 69.4
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 80,
        "payments": 30,
        "reliability": 79,
        "schema": 87,
        "security": 74,
        "transparency": 65
      },
      "provenanceScore": 97
    },
    "connect": {
      "install": "npm install webflow-api",
      "http": "curl --request GET \\\n  --url https://api.webflow.com/v2/sites \\\n  --header 'accept: application/json' \\\n  --header 'authorization: Bearer YOUR_API_TOKEN'",
      "claudeCode": "claude mcp add --transport http webflow https://mcp.webflow.com/mcp"
    },
    "letme": {
      "capability": "https://letme.dev/cms.content",
      "tool": "https://letme.dev/webflow"
    },
    "notable": [
      "The MCP server is hosted at https://mcp.webflow.com/mcp and since v2.0 most tools run through the Data API with no Designer session. Only snapshots, selection and canvas navigation need the Bridge App open (https://developers.webflow.com/mcp/reference/how-it-works)",
      "MCP v2.1 shipped on 21 September 2026 with tools for interactions, Webflow Cloud and Campaigns, and custom-field filters on `list_collection_items` (https://developers.webflow.com/home/changelog/2026/9/21)",
      "The official MCP registry lists com.webflow/mcp with the remote https://mcp.webflow.com/mcp, published 27 October 2025 (https://registry.modelcontextprotocol.io/v0/servers?search=webflow)",
      "CMS items are created and updated as drafts, and `publish_collection_items` or Publish Site makes them live (https://developers.webflow.com/data/docs/working-with-the-cms/publishing)",
      "The MCP server can't create new localised CMS items or change a site's access settings, and each authorisation covers one workspace (https://developers.webflow.com/mcp/reference/overview)",
      "Rate limits are 60 requests a minute on Starter and Basic and 120 on higher site plans, per token, with Retry-After on 429 (https://developers.webflow.com/data/reference/rate-limits)",
      "The open-source server in webflow/mcp-server is at v1.2 with its last commit on 10 April 2026, behind the hosted v2.1 (https://github.com/webflow/mcp-server)",
      "Status history since 10 July 2026 shows four minor incidents on the Data API and MCP server, one of them a week of missing MCP tools from 9 to 16 July (https://status.webflow.com/history)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "Data API v2 (REST, JSON) at https://api.webflow.com/v2, a /beta namespace for new endpoints, and the official hosted MCP server over the same API. A read-only content delivery API serves cached CMS data"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.webflow.com/mcp (streamable HTTP), beta at https://mcp.webflow.com/beta/mcp. Version 2.1 since 21 September 2026. 27 data tools, 3 Designer session tools and 4 utility tools. OAuth only, one workspace per authorisation"
      },
      {
        "label": "CMS actions",
        "value": "Collections, static, option and reference fields, field groups, items created and updated as drafts, publish and unpublish (unpublish up to 100 a call), delete, and site publish"
      },
      {
        "label": "Credentials",
        "value": "OAuth apps and site tokens with read and write scope pairs (assets, cms, pages, sites, forms, components, comments, custom_code, ecommerce and others). At most 5 site tokens a site, expiring after 365 days unused. Custom code endpoints need an OAuth app"
      },
      {
        "label": "Rate limits",
        "value": "60 requests a minute on Starter and Basic, 120 on higher site plans, custom on Enterprise, counted per token. Site publish once a minute. Asset compression 10 calls a minute per site"
      },
      {
        "label": "Errors",
        "value": "JSON body with `code`, `message`, `externalReference` and `details`. 429 with Retry-After, and X-RateLimit-Limit and X-RateLimit-Remaining on every response"
      },
      {
        "label": "Pagination",
        "value": "`limit` (maximum 100) and `offset`. Collection items filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]` (up to 10 terms) and sort on up to 3 custom fields"
      },
      {
        "label": "Drafts and versions",
        "value": "`isDraft` and `lastPublished` give the item state. A live item can hold staged changes. Scheduled publishing can't be set through the CMS API. No version history or rollback endpoint was found in the reviewed pages"
      },
      {
        "label": "Assets",
        "value": "Two-step upload (create the asset with a file hash, then POST the bytes to a presigned URL). Folders can't be deleted through the API. Asset delete is a soft delete that the API can't restore"
      },
      {
        "label": "Localisation",
        "value": "Items and pages carry a locale id (`cmsLocaleId`). The MCP server reads and updates content in secondary locales and can't create new localised CMS items. Localisation is a priced add-on"
      },
      {
        "label": "Free tier",
        "value": "Starter site plan. 50 CMS items, 20 collections, 2 static pages, 1 GB bandwidth, CMS APIs at 60 requests a minute, MCP server included"
      },
      {
        "label": "SDKs",
        "value": "webflow-api 3.3.4 for JavaScript (16 March 2026) and webflow 2.0.0 for Python (12 March 2026), both MIT. The SDKs don't call beta endpoints"
      },
      {
        "label": "Audit",
        "value": "Agent changes are recorded in the site activity log. The pricing page lists the activity log and its API on Team and Enterprise, and an Audit Logs API on Enterprise"
      },
      {
        "label": "Certifications",
        "value": "SOC 1 Type 2, SOC 2 Type 2, ISO 27001, 27017, 27018 and 42001, PCI DSS per the trust centre. Bugcrowd disclosure programme named in security.txt"
      },
      {
        "label": "Sub-processors",
        "value": "List updated 9 July 2026 with countries, nearly all in the USA. AWS for hosting, Cloudflare for delivery, MongoDB for the database, Anthropic and OpenAI for AI services"
      },
      {
        "label": "Open source",
        "value": "No. The OpenAPI spec, both SDKs and an older local MCP server (webflow/mcp-server, last commit 10 April 2026) are MIT"
      }
    ],
    "unitPrices": [
      {
        "item": "Basic site plan",
        "unit": "month",
        "usd": 15,
        "note": "billed yearly, per site, no CMS"
      },
      {
        "item": "Premium site plan",
        "unit": "month",
        "usd": 25,
        "note": "billed yearly, per site, 20,000 CMS items and 120 requests a minute"
      },
      {
        "item": "Team platform plan",
        "unit": "month",
        "usd": 2500,
        "note": "annual contract, 5 full and 5 limited seats included"
      }
    ],
    "provenance": {
      "legalEntity": "Webflow, Inc.",
      "domain": "webflow.com",
      "domainRegistered": "2003-03-31",
      "endpointOnVendorDomain": true,
      "terms": "https://webflow.com/legal/terms",
      "privacy": "https://webflow.com/legal/privacy",
      "statusPage": "https://status.webflow.com",
      "changelog": "https://developers.webflow.com/home/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.",
        "The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.",
        "The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.",
        "The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.",
        "webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.",
        "RDAP for webflow.com gives a registration date of 2003-03-31.",
        "status.webflow.com runs on Statuspage with components for the Data API and the MCP server."
      ],
      "score": 97,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Webflow, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "webflow.com, registered 2003-03-31 (23 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.webflow.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.webflow.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://webflow.com/legal/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-11-15",
          "words": 11369,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last modified date: November 15, 2023",
              "says": "Last updated 2023-11-15"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Agreement will be governed by and construed in accordance with the internal laws of the State of California, without regard to its conflicts of law provisions.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT SHALL WEBFLOW, ITS AFFILIATES, AGENTS, DIRECTORS, EMPLOYEES, SUPPLIERS, OR LICENSORS BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS RELATED TO THIS AGREEMENT IN AN AMOUNT EXCEEDING $100.",
              "says": "Capped at $100"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "and ( 2 ) the “Subscription Term” of the Agreement shall be as of the Effective Date until you terminate your Account and/or the expiration or termination of the last outstanding Order Form, as applicable."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may need to send you notices about important updates (like changes to these Terms or our Privacy Policy), or to inform you of legal inquiries we receive about your use of the Platform so you can make informed choices in response.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT AGREE TO THE TERMS AND CONDITIONS OF THE AGREEMENT, YOU MAY NOT USE THE PLATFORM OR ANY RELATED WEBFLOW OFFERINGS."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Therefore, we may, without prior notice, change the Platform, add features, stop providing the Platform or features of the Platform to you or to customers generally, or create usage limits for the Platform.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Webflow may terminate this license at any time for any reason or no reason."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "If you and Webflow are unable to resolve a Dispute through informal negotiations, all claims arising from use of the Platform (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration, unless otherwise prohibited by applicable law."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Webflow's liability for any claim related to the agreement is capped at 100 US dollars.",
              "quote": "IN NO EVENT SHALL WEBFLOW, ITS AFFILIATES, AGENTS, DIRECTORS, EMPLOYEES, SUPPLIERS, OR LICENSORS BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS RELATED TO THIS AGREEMENT IN AN AMOUNT EXCEEDING $100."
            },
            {
              "date": "2026-10-08",
              "text": "The licence the customer grants over website content covers improving, testing and promoting the platform as well as running it, and is transferable and sub-licensable.",
              "quote": "create derivative works (e.g., those resulting from you enabling localization translations and adaptations) of your Website Content for the purposes of providing, improving, testing, promoting, and securing the Platform."
            },
            {
              "date": "2026-10-08",
              "text": "Annual plans are billed up front, are non-refundable and renew automatically for a further year unless cancelled before the term ends.",
              "quote": "Your annual plan will automatically renew for successive one (1) year subscription periods, and you will be charged the applicable Fees on each annual anniversary of your purchase, unless you cancel the plan(s) on your Account prior to the end of the then-current annual term."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://webflow.com/legal/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-03-17",
          "words": 5648,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: March 17, 2025",
              "says": "Last updated 2025-03-17"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Global Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect visitors’ and users’ information as part of the Platform."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Webflow will retain Personal Information we process on your behalf for as long as necessary to provide the Platform to you, subject to our compliance with this Policy, or as required or permitted under applicable law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "In addition to collecting and using De-identified Data ourselves, we may share De-identified Data with third parties, including our customers, partners and service providers, for various purposes, including to help us better understand our customers’ needs and improve the Platform as well as for advertising and market…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "If you would like us to no longer share your Personal Information in this way, you can opt-out by visiting the following web page: Do Not Sell My Info.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "We will not discriminate against you for exercising your right to know, delete or opt-out of sales."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you ever receive such an email, please forward it to privacy@webflow.com.",
              "says": "privacy@webflow.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "As described in this Privacy Policy, in certain situations we may share your Personal Information with certain third parties for our marketing or other purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Webflow may store credentials for third-party applications the customer connects, in encrypted form, and use them to access those accounts on the customer's behalf.",
              "quote": "To facilitate the exchange of data between third-party SaaS applications, we may need to store certain information (“App Credentials”) that helps us access these third-party SaaS application accounts on your behalf."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/webflow.json",
    "live": {
      "slug": "webflow",
      "probe": {
        "target": "https://api.webflow.com/v2",
        "method": "get",
        "lastAt": "2026-10-08T19:09:02.226742748Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 324,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 268,
        "p95ms24h": 617,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.webflow.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:07:04.499232802Z"
      },
      "pages": [
        {
          "url": "https://developers.webflow.com/home/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:18:03.444775017Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "26398a0d385c"
        },
        {
          "url": "https://webflow.com/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:48.086194416Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "1895a791460c"
        },
        {
          "url": "https://webflow.com/legal/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:43.849393456Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "1dc949e66fd3"
        },
        {
          "url": "https://webflow.com/legal/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:46.083572378Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "fab4ea21138a"
        }
      ],
      "updatedAt": "2026-10-08T19:09:02.226742748Z"
    }
  }
}
