# Best headless CMS and website publishing for AI agents > DatoCMS (BB), Sanity (BB) and Kontent.ai (BB) lead the 14 ranked headless CMS and website publishing. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Canonical: https://www.anchorterminal.com/best/cms/ - Markdown: https://www.anchorterminal.com/best/cms/index.md (~6,800 tokens) - Slim: https://www.anchorterminal.com/best/cms/index.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/best/cms/index.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 The 10 highest-scoring of 14 headless CMS and website publishing on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 14 · agent-ready (BB or better): 3 · accept x402: 0 · hosted endpoints: 9 - Full ranked table: https://www.anchorterminal.com/categories/cms.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/cms/index.md (91) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [DatoCMS](https://www.anchorterminal.com/tools/datocms.md) | BB | 74.4 | Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment. | Freemium | hosted | | 2 | [Sanity](https://www.anchorterminal.com/tools/sanity.md) | BB | 73.7 | Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish. | $15 / seat-mo | hosted | | 3 | [Kontent.ai](https://www.anchorterminal.com/tools/kontent-ai.md) | BB | 70.5 | A company already on Kontent.ai, or evaluating it on a trial, that wants an agent to draft, localise, move through workflow and publish structured content with a permission-limited key and an audit trail. | Paid | hosted and local | | 4 | [Webflow](https://www.anchorterminal.com/tools/webflow.md) | B | 69.4 | Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets. | $15 / mo | hosted | | 5 | [Hygraph](https://www.anchorterminal.com/tools/hygraph.md) | B | 69.3 | Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP. | $199 / mo | hosted | | 6 | [Storyblok](https://www.anchorterminal.com/tools/storyblok.md) | B | 67.7 | Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions. | $99 / mo | hosted | | 7 | [Directus](https://www.anchorterminal.com/tools/directus.md) | B | 67.1 | Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions. | $499 / mo | local | | 8 | [Strapi](https://www.anchorterminal.com/tools/strapi.md) | B | 65.7 | Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token. | $45 / mo | local | | 9 | [WordPress](https://www.anchorterminal.com/tools/wordpress.md) | B | 64.8 | Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes. | Free · OSS | local | | 10 | [Contentstack](https://www.anchorterminal.com/tools/contentstack.md) | B | 64 | Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail. | $29 / mo | hosted and local | ## Picks by need - Highest score overall: [DatoCMS](https://www.anchorterminal.com/tools/datocms.md), BB, 74.4/100 on the benchmark. Also [Sanity](https://www.anchorterminal.com/tools/sanity.md), BB, 73.7/100. - Reliability: [Hygraph](https://www.anchorterminal.com/tools/hygraph.md), 89/100 on reliability, against 80 for the overall leader. - Schema & documentation: [Sanity](https://www.anchorterminal.com/tools/sanity.md), 87/100 on schema & documentation, against 85 for the overall leader. - Security & auth: [Kontent.ai](https://www.anchorterminal.com/tools/kontent-ai.md), 81/100 on security & auth, against 77 for the overall leader. - Maintenance & community: [Sanity](https://www.anchorterminal.com/tools/sanity.md), 89/100 on maintenance & community, against 81 for the overall leader. - Transparency & trust: [Sanity](https://www.anchorterminal.com/tools/sanity.md), 87/100 on transparency & trust, against 80 for the overall leader. - Lowest paid price per 1,000 requests: [Sanity](https://www.anchorterminal.com/tools/sanity.md), $0.004 per 1,000 requests, the lowest of the 4 listings here with a paid price in this unit (free allowances aside). Also [Storyblok](https://www.anchorterminal.com/tools/storyblok.md), $0.01 per 1,000 requests. - Self-hosting under an open licence: [Directus](https://www.anchorterminal.com/tools/directus.md), self-hosted, MSCL-1 licence. Also [Strapi](https://www.anchorterminal.com/tools/strapi.md), self-hosted, MIT for the Community Edition licence. ## How to choose - Draft and publish as separate steps: Check that a draft can be written and reviewed without going live, since an agent that publishes on every write exposes unfinished content to readers. - Version history and rollback: Check that every revision is kept and can be rolled back through the API, since an agent may need to restore the last good version. - Schema checks on write: Check whether the schema is enforced on write and returns a clear error, since an agent that writes a malformed entry must correct it from the error alone. - Locales and asset links: Check how locales and uploaded images are linked to an entry, since a translated article with a missing image can publish with a broken page in that language. - How the benchmark tests this category: The same article created as a draft with one image and two locales, revised, published and then rolled back through each listing's management API. We check schema validation, the draft and publish states, asset upload and version history. In this run listings are graded from public evidence against the published checklist. ## Each one in detail ### 1. DatoCMS, BB 74.4/100 DatoCMS is a hosted headless CMS from Dato Srl in Milan. Agents write records, assets, locales and schema through the REST Content Management API, the `datocms` CLI or a hosted MCP server, and read through a GraphQL Content Delivery API. - Verdict: The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route. - Choose it for: Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment. - Strength: Machine-readable JSON Hyper-Schema at `https://site-api.datocms.com/docs/site-api-hyperschema.json` covering 53 resources and 202 operations, with 656 examples - Strength: Error bodies carry one of 100 documented codes, a `doc_url` and a `transient` flag, and 429 responses carry `x-ratelimit-reset` - Strength: API tokens bind to custom roles by model, action and environment, and every project starts with a read-only token - Weakness: No idempotency keys in the reviewed documentation. Safe retries rest on optimistic locking and the JavaScript client's automatic retry - Weakness: The only official client library is JavaScript and TypeScript. No Python, Go, PHP or Ruby client appears in the documentation index - Weakness: Audit logs are an Enterprise feature with a default retention of two months - Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/datocms.md ### 2. Sanity, BB 73.7/100 Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io. - Verdict: Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans. - Choose it for: Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish. - Strength: 26 public OpenAPI specs covering 225 operations at www.sanity.io/docs/api/openapi, plus llms.txt and a Markdown copy of every documentation page - Strength: MCP `patch_documents` saves to a draft or release version, never to published content, and `publish_documents` is a separate tool - Strength: Mutations and actions accept `dryRun`, a caller-set `transactionId` and `ifRevisionID` for optimistic locking - Weakness: Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them - Weakness: Custom roles scoped to a dataset or document type are an Enterprise feature. Robot tokens on other plans take a built-in role across the project - Weakness: The MCP OAuth server lists one scope, `global`, and the server documents 53 tools with no toolset or read-only mode - Price: $15 / seat-mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/sanity.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-sanity.md ### 3. Kontent.ai, BB 70.5/100 Kontent.ai is a hosted headless CMS from Kontent CZ s.r.o. in Brno. Its Management API v2 reads and writes content items, language variants, assets, content models and workflow steps, and an open-source MCP server wraps it. - Verdict: Management API keys take per-area permissions, environment limits and an expiry from one minute to two years, and changes made with a key are named in the audit log. Rate limits and Retry-After are documented. No price is published, and no OpenAPI file was found. Access starts with a 30-day trial that a person opens in a browser. - Choose it for: A company already on Kontent.ai, or evaluating it on a trial, that wants an agent to draft, localise, move through workflow and publish structured content with a permission-limited key and an audit trail. - Strength: Management API keys carry selectable permissions (read content, edit content, assets, content model, environment settings), environment limits and an expiry from 1 minute to 2 years - Strength: Rate limits are published (10 requests a second and 400 a minute per environment), and a 429 carries a Retry-After header - Strength: The audit log keeps 90 days of changes and names the API key that made each one. Content item changes were added on 2 October 2026 - Weakness: No price is published. The pricing page shows sliders for seats, content types and items and a form that requests a quote - Weakness: No OpenAPI file was found. The docs link a Postman collection, which we did not read - Weakness: Access needs a person. The 30-day trial needs no card, but sign-up, the Management API toggle and key creation happen in the web app - Price: Paid · Auth: API key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/kontent-ai.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-kontent-ai.md ### 4. Webflow, B 69.4/100 Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools. - Verdict: The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan. - Choose it for: Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets. - Strength: Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page - Strength: OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens - Strength: CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call - Weakness: The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions - Weakness: No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute - Weakness: The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales - Price: $15 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/webflow.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-webflow.md ### 5. Hygraph, B 69.3/100 Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server. - Verdict: Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found. - Choose it for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP. - Strength: Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled - Strength: The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction - Strength: GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100 - Weakness: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After` - Weakness: No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field - Weakness: Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth - Price: $199 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/hygraph.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-hygraph.md ### 6. Storyblok, B 67.7/100 Storyblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools. - Verdict: The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request. - Choose it for: Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions. - Strength: Official hosted MCP server at mcp.storyblok.com/mcp with seven tools (search, describe, three execute tools, two for asset upload) and a `fields` filter that trims responses - Strength: OAuth with PKCE, dynamic client registration and 29 scopes on a read, write and publish hierarchy, chosen per space on a consent screen - Strength: Personal access tokens take scopes, a space list and an expiry date since 27 May 2026, and unscoped tokens are revoked on 30 November 2026 - Weakness: The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations) - Weakness: Management API limit is 3 requests a second on Starter and 6 on paid plans, with no idempotency keys in the reviewed documentation - Weakness: The status page monitors four delivery services and has no Management API or MCP monitor - Price: $99 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/storyblok.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-storyblok.md ### 7. Directus, B 67.1/100 Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server. - Verdict: The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions. - Choose it for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions. - Strength: MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients - Strength: Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default - Strength: Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema` - Weakness: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period - Weakness: The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key - Weakness: Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=` - Price: $499 / mo · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/directus.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-directus.md ### 8. Strapi, B 65.7/100 Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server. - Verdict: The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files. - Choose it for: Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token. - Strength: Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry - Strength: The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields - Strength: Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted - Weakness: Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans - Weakness: Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed - Weakness: A REST POST or PUT publishes immediately unless the request passes `status=draft` - Price: $45 / mo · Auth: API key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/strapi.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-strapi.md ### 9. WordPress, B 64.8/100 WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin. - Verdict: The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026. - Choose it for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes. - Strength: Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed - Strength: Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts//revisions` lists with author and date - Strength: `_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list - Weakness: Application Passwords have no scopes or expiry. Each one carries every capability of its user - Weakness: The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update - Weakness: Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use - Price: Free · OSS · Auth: API key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/wordpress.md - Against #1: https://www.anchorterminal.com/compare/datocms-vs-wordpress.md ### 10. Contentstack, B 64/100 Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents. - Verdict: The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice. - Choose it for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail. - Strength: OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant - Strength: Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits - Strength: Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026 - Weakness: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch - Weakness: On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day - Weakness: The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples - Price: $29 / mo · Auth: OAuth or key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/contentstack.md - Against #1: https://www.anchorterminal.com/compare/contentstack-vs-datocms.md 4 more are ranked in the full table: https://www.anchorterminal.com/categories/cms.md ## Head to head - [DatoCMS vs Sanity](https://www.anchorterminal.com/compare/datocms-vs-sanity.md) - [DatoCMS vs Kontent.ai](https://www.anchorterminal.com/compare/datocms-vs-kontent-ai.md) - [DatoCMS vs Webflow](https://www.anchorterminal.com/compare/datocms-vs-webflow.md) - [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md) - [Kontent.ai vs Sanity](https://www.anchorterminal.com/compare/kontent-ai-vs-sanity.md) - [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md) - [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md) - [Kontent.ai vs Webflow](https://www.anchorterminal.com/compare/kontent-ai-vs-webflow.md) - [Hygraph vs Kontent.ai](https://www.anchorterminal.com/compare/hygraph-vs-kontent-ai.md) - [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md) ## Questions ### What are the highest-rated headless CMS and website publishing for AI agents? DatoCMS has the highest benchmark score of the 14 ranked headless CMS and website publishing, 74.4 (BB). Sanity is second with 73.7 (BB). ### How many headless CMS and website publishing are agent-ready? 3 of the 14 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark. ### Which headless CMS and website publishing accept x402 payments? None of the ranked listings here accepts x402 for its main call yet. ### Which of these headless CMS and website publishing is cheapest? By published paid prices, Sanity, at $0.004 per 1,000 requests, the lowest of the 4 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table. ### How is this list ranked? By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026. ## How this list is made The order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.