{
  "data": {
    "category": {
      "area": "business",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "description": "Content management systems an agent can write to. Entries, assets, locales and the publish step, through an API or an MCP server. Compared on write access, content modelling, drafts and versions, and how a change is reviewed before it goes live.",
      "json": "https://www.anchorterminal.com/categories/cms.json",
      "name": "CMS \u0026 website publishing",
      "slug": "cms",
      "test": "The same article created as a draft with one image and two locales, revised, published and then rolled back through each listing's management API. We check schema validation, the draft and publish states, asset upload and version history. In this run listings are graded from public evidence against the published checklist.",
      "title": "Headless CMS and website publishing for AI agents",
      "toolCount": 7,
      "tools": [
        "sanity",
        "webflow",
        "storyblok",
        "strapi",
        "wordpress",
        "contentstack",
        "ghost"
      ],
      "url": "https://www.anchorterminal.com/categories/cms"
    },
    "tools": [
      {
        "slug": "sanity",
        "name": "Sanity",
        "vendor": "Sanity US Inc. and Sanity AS",
        "vendorUrl": "https://www.sanity.io",
        "kind": "http-api",
        "category": "cms",
        "summary": "Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io.",
        "url": "https://www.anchorterminal.com/tools/sanity",
        "markdownUrl": "https://www.anchorterminal.com/tools/sanity.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sanity.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sanity.json",
        "repo": "https://github.com/sanity-io/sanity",
        "license": "Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.sanity.io",
        "packages": [
          {
            "registry": "npm",
            "name": "@sanity/client"
          },
          {
            "registry": "npm",
            "name": "sanity"
          },
          {
            "registry": "packagist",
            "name": "sanity/sanity-php"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. The HTTP API takes a Bearer token. Robot tokens are created in sanity.io/manage, with the CLI or through the Access API, carry a role (Viewer and Editor tokens on every plan), last until deleted unless given an expiry, and are shown once. Personal tokens last a year and act as the user. The MCP server at mcp.sanity.io uses OAuth with PKCE and dynamic client registration by default, with one scope named `global` and sessions of about 7 days, or accepts a token in the `Authorization` header. Custom roles that limit a token to a dataset or document type are Enterprise only. No app review or sales approval is needed.",
        "pricing": "freemium",
        "pricingNotes": "Free plan at $0 with no card, 20 seats, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, and hard caps that answer 402 when reached. Growth is $15 a seat a month with overage billed per unit. Enterprise is priced by sales. New projects get a Growth trial with Free plan quotas. An agent can start on the Free plan once a person has created the account (checked 2026-10-07).",
        "priceSummary": "$15 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the documentation (llms-full.txt) or on the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": 53,
        "popularity": {
          "githubStars": 6352,
          "npmWeekly": 4069926,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://www.sanity.io/docs",
        "llmsTxt": "https://www.sanity.io/docs/llms.txt",
        "openapi": "https://www.sanity.io/docs/api/openapi",
        "registryName": "io.sanity.www/mcp",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "tags": [
          "hosted",
          "headless-cms",
          "mcp",
          "oauth",
          "openapi",
          "llms-txt",
          "groq",
          "graphql",
          "javascript",
          "php",
          "free-tier",
          "status-page",
          "soc2",
          "open-source-studio"
        ],
        "lastRelease": "2026-10-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 73.7,
          "grade": "BB",
          "agentReady": true,
          "rank": 69,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 1,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 89,
            "payments": 40,
            "reliability": 77,
            "schema": 87,
            "security": 67,
            "transparency": 87
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": 0,
          "verdict": "Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.",
          "bestFor": "Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.",
          "strengths": [
            "26 public OpenAPI specs covering 225 operations at www.sanity.io/docs/api/openapi, plus llms.txt and a Markdown copy of every documentation page",
            "MCP `patch_documents` saves to a draft or release version, never to published content, and `publish_documents` is a separate tool",
            "Mutations and actions accept `dryRun`, a caller-set `transactionId` and `ifRevisionID` for optimistic locking",
            "Free plan with 10,000 documents and 250,000 API requests a month, with Growth overage rates published per unit",
            "MCP server listed in the official MCP registry as io.sanity.www/mcp, with 30 versions published there between 15 July and 2 October 2026"
          ],
          "weaknesses": [
            "Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them",
            "Custom roles scoped to a dataset or document type are an Enterprise feature. Robot tokens on other plans take a built-in role across the project",
            "The MCP OAuth server lists one scope, `global`, and the server documents 53 tools with no toolset or read-only mode",
            "A status incident on 22 July 2026, marked major on api.sanity.io, stayed open for 6 hours 20 minutes with two recurrences",
            "The vulnerability disclosure page says the bug bounty pilot has closed and no rewards are paid"
          ],
          "agentNotes": [
            "Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`.",
            "Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules.",
            "Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.",
            "Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`.",
            "Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`."
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 73.7
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 89,
            "payments": 40,
            "reliability": 77,
            "schema": 87,
            "security": 67,
            "transparency": 79
          },
          "provenanceScore": 95
        },
        "connect": {
          "install": "npx sanity@latest mcp configure",
          "http": "curl -H \"Authorization: Bearer \u003ctoken\u003e\" \"https://\u003cproject\u003e.api.sanity.io/v2021-06-07/data/query/production?query=*\"",
          "claudeCode": "claude mcp add Sanity -t http https://mcp.sanity.io --scope user",
          "config": {
            "mcpServers": {
              "Sanity": {
                "type": "http",
                "url": "https://mcp.sanity.io"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/sanity"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Growth",
            "unit": "seat-month",
            "usd": 15,
            "note": "up to 50 seats"
          },
          {
            "item": "API requests over quota (Growth)",
            "unit": "1k-requests",
            "usd": 0.04,
            "note": "$1 per 25,000, after 250,000 a month included"
          },
          {
            "item": "API CDN requests over quota (Growth)",
            "unit": "1k-requests",
            "usd": 0.004,
            "note": "$1 per 250,000, after 1 million a month included"
          },
          {
            "item": "Bandwidth over quota (Growth)",
            "unit": "gb",
            "usd": 0.3,
            "note": "after 100 GB a month included"
          },
          {
            "item": "Increased quota add-on (Growth)",
            "unit": "month",
            "usd": 299,
            "note": "50,000 documents, 1 million API requests, 5 million API CDN requests"
          },
          {
            "item": "Extra dataset (Growth)",
            "unit": "month",
            "usd": 999,
            "note": "per dataset"
          }
        ],
        "provenance": {
          "legalEntity": "Sanity US Inc. (with Sanity AS)",
          "domain": "sanity.io",
          "domainRegistered": "2015-01-07",
          "endpointOnVendorDomain": true,
          "terms": "https://www.sanity.io/legal/tos",
          "privacy": "https://www.sanity.io/legal/privacy",
          "statusPage": "https://www.sanity-status.com",
          "changelog": "https://www.sanity.io/docs/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-07",
          "notes": [
            "The terms of service dated 12 August 2026 are entered into with Sanity US Inc. The privacy policy dated 4 May 2026 is that of Sanity AS and Sanity US Inc. Growth has its own terms at sanity.io/legal/tos-growth, dated 26 March 2026.",
            "The API answers at https://\u003cprojectId\u003e.api.sanity.io and https://api.sanity.io, and the MCP server at https://mcp.sanity.io.",
            "www.sanity.io/.well-known/security.txt names security@sanity.io and the disclosure policy at sanity.io/responsible-disclosure, and has no Expires field.",
            "status.sanity.io answers with the same Statuspage as www.sanity-status.com.",
            "RDAP for sanity.io gives a registration date of 2015-01-07."
          ],
          "score": 95
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/sanity.json",
        "live": {
          "slug": "sanity",
          "probe": {
            "target": "https://api.sanity.io",
            "method": "get",
            "lastAt": "2026-10-08T17:36:44.890728007Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 43,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 39,
            "p95ms24h": 82,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://www.sanity-status.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:25:38.650666301Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "sanity-io/sanity",
              "version": "v6.18.0",
              "released": "2026-10-06",
              "seenAt": "2026-10-08T16:28:11.279439468Z"
            },
            {
              "registry": "npm",
              "name": "@sanity/client",
              "version": "8.9.0",
              "seenAt": "2026-10-08T16:28:08.05519452Z"
            },
            {
              "registry": "npm",
              "name": "sanity",
              "version": "6.18.0",
              "seenAt": "2026-10-08T16:28:09.308419229Z"
            }
          ],
          "githubStars": 6352,
          "npmWeekly": 4069926,
          "securityTxt": {
            "url": "https://sanity.io/.well-known/security.txt",
            "state": "valid",
            "checkedAt": "2026-10-08T15:38:50.777207368Z"
          },
          "updatedAt": "2026-10-08T17:36:44.890728007Z"
        }
      },
      {
        "slug": "webflow",
        "name": "Webflow",
        "vendor": "Webflow, Inc.",
        "vendorUrl": "https://webflow.com",
        "kind": "http-api",
        "category": "cms",
        "summary": "Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.",
        "url": "https://www.anchorterminal.com/tools/webflow",
        "markdownUrl": "https://www.anchorterminal.com/tools/webflow.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/webflow.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/webflow.json",
        "repo": "https://github.com/webflow/openapi-spec",
        "license": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.webflow.com/v2",
        "packages": [
          {
            "registry": "npm",
            "name": "webflow-api"
          },
          {
            "registry": "pypi",
            "name": "webflow"
          },
          {
            "registry": "npm",
            "name": "webflow-mcp-server"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps \u0026 integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens.",
        "pricing": "freemium",
        "pricingNotes": "The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).",
        "priceSummary": "$15 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 34,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 85160,
          "pypiWeekly": 121246,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developers.webflow.com/data/docs",
        "llmsTxt": "https://developers.webflow.com/llms.txt",
        "openapi": "https://raw.githubusercontent.com/webflow/openapi-spec/main/openapi/v2.yml",
        "registryName": "com.webflow/mcp",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "tags": [
          "official",
          "hosted",
          "mcp",
          "oauth",
          "openapi",
          "llms-txt",
          "closed-source",
          "free-tier",
          "webhooks",
          "typescript",
          "python",
          "status-page",
          "soc2",
          "iso27001"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 69.4,
          "grade": "B",
          "agentReady": false,
          "rank": 150,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 2,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 72,
            "maintenance": 80,
            "payments": 30,
            "reliability": 79,
            "schema": 87,
            "security": 74,
            "transparency": 81
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -3,
          "negativeNotes": [
            "7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7)."
          ],
          "verdict": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
          "bestFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
          "strengths": [
            "Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page",
            "OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens",
            "CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call",
            "429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically",
            "Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page"
          ],
          "weaknesses": [
            "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions",
            "No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute",
            "The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales",
            "The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise",
            "On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day"
          ],
          "agentNotes": [
            "Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes",
            "Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes",
            "Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429",
            "Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms",
            "Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 69.4
            }
          ],
          "editorialScores": {
            "ergonomics": 72,
            "maintenance": 80,
            "payments": 30,
            "reliability": 79,
            "schema": 87,
            "security": 74,
            "transparency": 65
          },
          "provenanceScore": 97
        },
        "connect": {
          "install": "npm install webflow-api",
          "http": "curl --request GET \\\n  --url https://api.webflow.com/v2/sites \\\n  --header 'accept: application/json' \\\n  --header 'authorization: Bearer YOUR_API_TOKEN'",
          "claudeCode": "claude mcp add --transport http webflow https://mcp.webflow.com/mcp"
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/webflow"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Basic site plan",
            "unit": "month",
            "usd": 15,
            "note": "billed yearly, per site, no CMS"
          },
          {
            "item": "Premium site plan",
            "unit": "month",
            "usd": 25,
            "note": "billed yearly, per site, 20,000 CMS items and 120 requests a minute"
          },
          {
            "item": "Team platform plan",
            "unit": "month",
            "usd": 2500,
            "note": "annual contract, 5 full and 5 limited seats included"
          }
        ],
        "provenance": {
          "legalEntity": "Webflow, Inc.",
          "domain": "webflow.com",
          "domainRegistered": "2003-03-31",
          "endpointOnVendorDomain": true,
          "terms": "https://webflow.com/legal/terms",
          "privacy": "https://webflow.com/legal/privacy",
          "statusPage": "https://status.webflow.com",
          "changelog": "https://developers.webflow.com/home/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.",
            "The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.",
            "The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.",
            "The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.",
            "webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.",
            "RDAP for webflow.com gives a registration date of 2003-03-31.",
            "status.webflow.com runs on Statuspage with components for the Data API and the MCP server."
          ],
          "score": 97
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/webflow.json",
        "live": {
          "slug": "webflow",
          "probe": {
            "target": "https://api.webflow.com/v2",
            "method": "get",
            "lastAt": "2026-10-08T17:36:49.165910206Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 269,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 269,
            "p95ms24h": 350,
            "samples24h": 2,
            "samples30d": 2,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 2,
                "ok": 2
              }
            ]
          },
          "updatedAt": "2026-10-08T17:36:49.165910206Z"
        }
      },
      {
        "slug": "storyblok",
        "name": "Storyblok",
        "vendor": "Storyblok GmbH",
        "vendorUrl": "https://www.storyblok.com",
        "kind": "http-api",
        "category": "cms",
        "summary": "Storyblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools.",
        "url": "https://www.anchorterminal.com/tools/storyblok",
        "markdownUrl": "https://www.anchorterminal.com/tools/storyblok.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/storyblok.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/storyblok.json",
        "repo": "https://github.com/storyblok/monoblok",
        "license": "Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://mapi.storyblok.com/v1",
        "packages": [
          {
            "registry": "npm",
            "name": "@storyblok/management-api-client"
          },
          {
            "registry": "npm",
            "name": "storyblok-js-client"
          },
          {
            "registry": "npm",
            "name": "storyblok"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. The Management API takes a personal access token or an OAuth token in the request header. A person creates the token in account settings and picks scopes (16 groups such as stories, assets and components, on a read, write and publish hierarchy), the spaces it covers and an expiry date. The MCP server uses browser OAuth with PKCE and dynamic client registration, where the person picks permissions and spaces on a consent screen, or the same token as a Bearer header. No app review or sales approval is needed. The changelog describes OAuth scoped grants for custom integrations as a Premium and Enterprise feature. Content Delivery API tokens are read-only and travel in the `token` query parameter.",
        "pricing": "freemium",
        "pricingNotes": "Starter is free with no card and includes the Management API, 100,000 API requests a month, 1 seat and 2 locales. Growth is $99 a month and Growth Plus $349 a month billed monthly. Premium and Elite are sold through sales. New spaces start with a 45-day Growth Plus trial. On Growth, extra API requests cost $10 per million and extra seats $15 each (https://www.storyblok.com/pricing, checked 2026-10-07).",
        "priceSummary": "$99 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Management API docs, the MCP server docs or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": 7,
        "popularity": {
          "githubStars": 68,
          "npmWeekly": 432535,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://www.storyblok.com/docs/api/management",
        "llmsTxt": "https://www.storyblok.com/llms.txt",
        "openapi": "https://www.storyblok.com/docs/openapi-spec/cdn-v2.openapi.yaml",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "tags": [
          "official",
          "hosted",
          "mcp",
          "oauth",
          "closed-source",
          "no-card",
          "free-tier",
          "llms-txt",
          "webhooks",
          "typescript",
          "php",
          "status-page",
          "iso27001"
        ],
        "lastRelease": "2026-10-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 67.7,
          "grade": "B",
          "agentReady": false,
          "rank": 188,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 3,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 78,
            "maintenance": 80,
            "payments": 35,
            "reliability": 79,
            "schema": 68,
            "security": 73,
            "transparency": 80
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": -3,
          "negativeNotes": [
            "8 April 2026. Storyblok fixed a flaw where the Webhook and Webhook Logs endpoints of the Management API didn't enforce the Admin and Owner restriction the UI applies, so Editor and Restricted roles could manage webhooks by API. It was fixed and disclosed in the changelog, so the deduction is small (https://www.storyblok.com/cl/2026-april-security-fix-webhook-api-now-aligned-with-ui-access-controls)."
          ],
          "verdict": "The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.",
          "bestFor": "Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.",
          "strengths": [
            "Official hosted MCP server at mcp.storyblok.com/mcp with seven tools (search, describe, three execute tools, two for asset upload) and a `fields` filter that trims responses",
            "OAuth with PKCE, dynamic client registration and 29 scopes on a read, write and publish hierarchy, chosen per space on a consent screen",
            "Personal access tokens take scopes, a space list and an expiry date since 27 May 2026, and unscoped tokens are revoked on 30 November 2026",
            "Free Starter plan with no card, 100,000 API requests a month and Management API access on every plan",
            "Every docs page is served as Markdown by adding .md, with request examples in nine languages"
          ],
          "weaknesses": [
            "The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)",
            "Management API limit is 3 requests a second on Starter and 6 on paid plans, with no idempotency keys in the reviewed documentation",
            "The status page monitors four delivery services and has no Management API or MCP monitor",
            "On 8 April 2026 Storyblok fixed webhook endpoints that had let Editor and Restricted roles manage webhooks through the API",
            "Version history is kept for 1 day on Starter and 30 days on Growth, so a rollback depends on the plan"
          ],
          "agentNotes": [
            "Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails",
            "Create stories without `publish` to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it",
            "Write translations as `field__i18n__\u003ccode\u003e` keys inside the same content object, and set the component field to translatable first",
            "Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl",
            "Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 67.7
            }
          ],
          "editorialScores": {
            "ergonomics": 78,
            "maintenance": 80,
            "payments": 35,
            "reliability": 79,
            "schema": 68,
            "security": 73,
            "transparency": 73
          },
          "provenanceScore": 87
        },
        "connect": {
          "install": "npm install @storyblok/management-api-client",
          "http": "curl \"https://mapi.storyblok.com/v1/spaces/$SPACE_ID/stories/\" \\\n  -H \"Authorization: $STORYBLOK_PERSONAL_ACCESS_TOKEN\"",
          "claudeCode": "claude mcp add --transport http Storyblok https://mcp.storyblok.com/mcp",
          "config": {
            "mcpServers": {
              "Storyblok": {
                "type": "http",
                "url": "https://mcp.storyblok.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/storyblok"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Growth",
            "unit": "month",
            "usd": 99,
            "note": "billed monthly, $90.75 billed yearly, 5 seats and 1M API requests included"
          },
          {
            "item": "Growth Plus",
            "unit": "month",
            "usd": 349,
            "note": "billed monthly, $319.91 billed yearly, 15 seats and 4M API requests included"
          },
          {
            "item": "Additional seat",
            "unit": "seat-month",
            "usd": 15,
            "note": "Starter (up to 2 seats) and Growth (up to 10)"
          },
          {
            "item": "Additional API requests on Growth",
            "unit": "1k-requests",
            "usd": 0.01,
            "note": "sold as $10 per 1M, up to 5M a month"
          }
        ],
        "provenance": {
          "legalEntity": "Storyblok GmbH",
          "domain": "storyblok.com",
          "domainRegistered": "2015-08-15",
          "endpointOnVendorDomain": true,
          "terms": "https://www.storyblok.com/legal/terms",
          "privacy": "https://www.storyblok.com/legal/privacy-policy",
          "statusPage": "https://uptime.storyblok.com",
          "changelog": "https://www.storyblok.com/changelog",
          "securityTxt": "none",
          "checked": "2026-10-07",
          "notes": [
            "The legal notice names Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria, company register number FN 479743 f, Regional Court Linz.",
            "The Management API answers on storyblok.com subdomains and the MCP server at mcp.storyblok.com. Spaces in China use app.storyblokchina.cn.",
            "security.txt returns 404 on www.storyblok.com, storyblok.com and mapi.storyblok.com. The privacy policy gives security@storyblok.com for security matters.",
            "The terms page was last updated on 2 October 2026 and links separate self-service and enterprise terms. The self-service terms are governed by Austrian law.",
            "RDAP for storyblok.com gives a registration date of 2015-08-15.",
            "The status page runs on UptimeRobot with four monitors (Content Delivery API v1 and v2, GraphQL API, Image Service)."
          ],
          "score": 87
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/storyblok.json",
        "live": {
          "slug": "storyblok",
          "probe": {
            "target": "https://mapi.storyblok.com/v1",
            "method": "get",
            "lastAt": "2026-10-08T17:36:46.374836846Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 62,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 55,
            "p95ms24h": 76,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://uptime.storyblok.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T15:37:17.306741083Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "storyblok/monoblok",
              "version": "storyblok@4.23.4",
              "released": "2026-10-02",
              "seenAt": "2026-10-08T16:30:30.68015309Z"
            },
            {
              "registry": "npm",
              "name": "@storyblok/management-api-client",
              "version": "0.9.1",
              "seenAt": "2026-10-08T16:30:26.446005464Z"
            },
            {
              "registry": "npm",
              "name": "storyblok",
              "version": "4.23.4",
              "seenAt": "2026-10-08T16:30:28.73366054Z"
            },
            {
              "registry": "npm",
              "name": "storyblok-js-client",
              "version": "7.7.7",
              "seenAt": "2026-10-08T16:30:27.249684993Z"
            }
          ],
          "githubStars": 68,
          "npmWeekly": 94500,
          "securityTxt": {
            "url": "https://storyblok.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:38:51.218593751Z"
          },
          "updatedAt": "2026-10-08T17:36:46.374836846Z"
        }
      },
      {
        "slug": "strapi",
        "name": "Strapi",
        "vendor": "Strapi, Inc.",
        "vendorUrl": "https://strapi.io",
        "kind": "http-api",
        "category": "cms",
        "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
        "url": "https://www.anchorterminal.com/tools/strapi",
        "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
        "repo": "https://github.com/strapi/strapi",
        "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
        "transports": [
          "http",
          "streamable-http"
        ],
        "packages": [
          {
            "registry": "npm",
            "name": "@strapi/strapi"
          },
          {
            "registry": "npm",
            "name": "@strapi/client"
          }
        ],
        "auth": "api-key",
        "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
        "pricing": "freemium",
        "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
        "priceSummary": "$45 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 73289,
          "npmWeekly": 258813,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://docs.strapi.io",
        "llmsTxt": "https://docs.strapi.io/llms.txt",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.localisation",
          "cms.assets",
          "cms.schema"
        ],
        "tags": [
          "open-source",
          "self-hosted",
          "hosted",
          "mcp",
          "llms-txt",
          "webhooks",
          "graphql",
          "typescript",
          "status-page",
          "soc2"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 65.7,
          "grade": "B",
          "agentReady": false,
          "rank": 231,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 4,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 87,
            "payments": 50,
            "reliability": 82,
            "schema": 80,
            "security": 66,
            "transparency": 72
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": -6,
          "negativeNotes": [
            "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
          ],
          "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
          "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
          "strengths": [
            "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
            "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
            "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
            "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
            "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
          ],
          "weaknesses": [
            "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
            "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
            "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
            "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
            "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
          ],
          "agentNotes": [
            "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
            "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
            "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
            "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
            "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 65.7
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 87,
            "payments": 50,
            "reliability": 82,
            "schema": 80,
            "security": 66,
            "transparency": 75
          },
          "provenanceScore": 68
        },
        "connect": {
          "install": "npx create-strapi@latest",
          "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
          "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
          "config": {
            "mcpServers": {
              "strapi-mcp": {
                "headers": {
                  "Authorization": "Bearer YOUR_ADMIN_TOKEN"
                },
                "type": "streamable-http",
                "url": "http://localhost:1337/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/strapi"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Community Edition, self-hosted",
            "unit": "month",
            "usd": 0,
            "note": "MIT, unlimited seats, you pay for your own hosting"
          },
          {
            "item": "Growth, self-hosted",
            "unit": "month",
            "usd": 45,
            "note": "3 seats included, $15 per extra seat"
          },
          {
            "item": "Strapi Cloud Starter",
            "unit": "month",
            "usd": 35,
            "note": "per project, 100,000 API requests"
          },
          {
            "item": "Strapi Cloud Pro",
            "unit": "month",
            "usd": 90,
            "note": "per project, 1 million API requests"
          },
          {
            "item": "Strapi Cloud Business",
            "unit": "month",
            "usd": 450,
            "note": "per project, 10 million API requests"
          },
          {
            "item": "Strapi Cloud API requests over the plan",
            "unit": "1k-requests",
            "usd": 0.06,
            "note": "$1.50 per 25,000"
          }
        ],
        "provenance": {
          "legalEntity": "Strapi, Inc.",
          "domain": "strapi.io",
          "domainRegistered": "2015-09-21",
          "endpointOnVendorDomain": false,
          "terms": "https://strapi.io/cloud-legal",
          "privacy": "https://strapi.io/privacy",
          "statusPage": "https://status.strapi.io",
          "changelog": "https://github.com/strapi/strapi/releases",
          "securityTxt": "none",
          "checked": "2026-10-07",
          "notes": [
            "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
            "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
            "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
            "RDAP for strapi.io gives a registration date of 2015-09-21.",
            "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
          ],
          "score": 68
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
        "live": {
          "slug": "strapi",
          "vendorStatus": {
            "page": "https://status.strapi.io",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T15:37:17.41184558Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "strapi/strapi",
              "version": "v5.57.0",
              "released": "2026-10-07",
              "seenAt": "2026-10-08T16:30:39.413193839Z"
            },
            {
              "registry": "npm",
              "name": "@strapi/client",
              "version": "1.6.2",
              "seenAt": "2026-10-08T16:30:37.897146773Z"
            },
            {
              "registry": "npm",
              "name": "@strapi/strapi",
              "version": "5.57.0",
              "seenAt": "2026-10-08T16:30:37.072939352Z"
            }
          ],
          "githubStars": 73292,
          "npmWeekly": 258813,
          "securityTxt": {
            "url": "https://strapi.io/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:39:07.890617672Z"
          },
          "updatedAt": "2026-10-08T16:30:39.413193839Z"
        }
      },
      {
        "slug": "wordpress",
        "name": "WordPress",
        "vendor": "WordPress.org (open-source project)",
        "vendorUrl": "https://wordpress.org",
        "kind": "http-api",
        "category": "cms",
        "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
        "url": "https://www.anchorterminal.com/tools/wordpress",
        "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
        "repo": "https://github.com/WordPress/wordpress-develop",
        "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "transports": [
          "http",
          "stdio"
        ],
        "packages": [],
        "auth": "api-key",
        "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
        "pricing": "free",
        "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
        "priceSummary": "Free · OSS",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 21460,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developer.wordpress.org/rest-api/",
        "llmsTxt": "https://wordpress.org/llms.txt",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "tags": [
          "open-source",
          "self-hosted",
          "rest",
          "mcp",
          "cli",
          "php",
          "llms-txt",
          "security-txt",
          "bug-bounty"
        ],
        "lastRelease": "2026-10-06",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 64.8,
          "grade": "B",
          "agentReady": false,
          "rank": 249,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 5,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 83,
            "payments": 60,
            "reliability": 78,
            "schema": 65,
            "security": 62,
            "transparency": 68
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -5,
          "negativeNotes": [
            "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
          ],
          "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
          "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
          "strengths": [
            "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
            "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
            "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
            "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
            "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
          ],
          "weaknesses": [
            "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
            "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
            "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
            "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
            "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
          ],
          "agentNotes": [
            "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
            "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
            "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
            "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
            "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 64.8
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 83,
            "payments": 60,
            "reliability": 78,
            "schema": 65,
            "security": 62,
            "transparency": 72
          },
          "provenanceScore": 63
        },
        "connect": {
          "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
          "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
          "config": {
            "mcpServers": {
              "wordpress": {
                "args": [
                  "--path=/path/to/your/wordpress/site",
                  "mcp-adapter",
                  "serve",
                  "--server=mcp-adapter-default-server",
                  "--user=admin"
                ],
                "command": "wp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/wordpress"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "WordPress, self-hosted",
            "unit": "month",
            "usd": 0,
            "note": "GPL, you pay for your own hosting"
          }
        ],
        "provenance": {
          "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
          "domain": "wordpress.org",
          "domainRegistered": "2003-03-28",
          "endpointOnVendorDomain": false,
          "terms": "",
          "privacy": "https://wordpress.org/about/privacy/",
          "statusPage": "",
          "changelog": "https://wordpress.org/news/category/releases/",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
            "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
            "The REST API answers on each owner's own domain.",
            "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
            "RDAP for wordpress.org gives a registration date of 2003-03-28.",
            "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
            "No status page applies to self-hosted software."
          ],
          "score": 63
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json"
      },
      {
        "slug": "contentstack",
        "name": "Contentstack",
        "vendor": "Contentstack Inc.",
        "vendorUrl": "https://www.contentstack.com",
        "kind": "http-api",
        "category": "cms",
        "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
        "url": "https://www.anchorterminal.com/tools/contentstack",
        "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
        "repo": "https://github.com/contentstack/contentstack-openapi",
        "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "transports": [
          "http",
          "stdio"
        ],
        "remoteUrl": "https://api.contentstack.io",
        "packages": [
          {
            "registry": "npm",
            "name": "@contentstack/mcp"
          },
          {
            "registry": "npm",
            "name": "@contentstack/management"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management"
          }
        ],
        "auth": "mixed",
        "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
        "pricing": "freemium",
        "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
        "priceSummary": "$29 / mo",
        "where": "both",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": 206,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 43992,
          "pypiWeekly": 1504,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
        "llmsTxt": "https://www.contentstack.com/llms.txt",
        "openapi": "https://github.com/contentstack/contentstack-openapi",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "tags": [
          "hosted",
          "official",
          "mcp",
          "openapi",
          "llms-txt",
          "oauth",
          "free-tier",
          "no-card",
          "closed-source",
          "webhooks",
          "typescript",
          "python",
          "java",
          "dotnet",
          "status-page",
          "soc2",
          "sla"
        ],
        "lastRelease": "2026-09-22",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 64,
          "grade": "B",
          "agentReady": false,
          "rank": 264,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 6,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 67,
            "maintenance": 82,
            "payments": 30,
            "reliability": 71,
            "schema": 77,
            "security": 69,
            "transparency": 73
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": -3,
          "negativeNotes": [
            "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
          ],
          "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
          "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
          "strengths": [
            "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
            "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
            "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
            "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
            "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
            "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
          ],
          "weaknesses": [
            "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
            "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
            "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
            "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
            "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
            "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
          ],
          "agentNotes": [
            "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
            "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
            "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
            "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
            "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 64
            }
          ],
          "editorialScores": {
            "ergonomics": 67,
            "maintenance": 82,
            "payments": 30,
            "reliability": 71,
            "schema": 77,
            "security": 69,
            "transparency": 59
          },
          "provenanceScore": 87
        },
        "connect": {
          "install": "npx -y @contentstack/mcp",
          "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
          "config": {
            "mcpServers": {
              "contentstack": {
                "args": [
                  "-y",
                  "@contentstack/mcp"
                ],
                "command": "npx",
                "env": {
                  "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                  "GROUPS": "cma"
                }
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/contentstack"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Build",
            "unit": "month",
            "usd": 29,
            "note": "3 users, 250,000 API calls a month"
          },
          {
            "item": "Growth",
            "unit": "month",
            "usd": 299,
            "note": "10 users, 1M API calls a month"
          },
          {
            "item": "Growth, each extra user",
            "unit": "seat-month",
            "usd": 25,
            "note": "beyond the 10 included"
          }
        ],
        "provenance": {
          "legalEntity": "Contentstack Inc.",
          "domain": "contentstack.com",
          "domainRegistered": "2011-10-29",
          "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
          "endpointOnVendorDomain": true,
          "terms": "https://www.contentstack.com/legal/terms-of-service",
          "privacy": "https://www.contentstack.com/legal/privacy",
          "statusPage": "https://status.contentstack.com",
          "changelog": "https://www.contentstack.com/docs/changelog",
          "securityTxt": "none",
          "checked": "2026-10-07",
          "notes": [
            "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
            "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
            "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
            "RDAP for contentstack.com gives a registration date of 2011-10-29.",
            "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
          ],
          "score": 87
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
        "live": {
          "slug": "contentstack",
          "probe": {
            "target": "https://api.contentstack.io",
            "method": "get",
            "lastAt": "2026-10-08T17:36:33.652239638Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 535,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 541,
            "p95ms24h": 636,
            "samples24h": 25,
            "samples30d": 25,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 25,
                "ok": 25
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.contentstack.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:38:36.151379976Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@contentstack/management",
              "version": "1.31.2",
              "seenAt": "2026-10-08T16:06:51.377892172Z"
            },
            {
              "registry": "npm",
              "name": "@contentstack/mcp",
              "version": "0.9.0",
              "seenAt": "2026-10-08T16:06:47.529272792Z"
            },
            {
              "registry": "pypi",
              "name": "contentstack-management",
              "version": "1.11.2",
              "released": "2026-08-12",
              "seenAt": "2026-10-08T16:06:51.588548545Z"
            }
          ],
          "githubStars": 8,
          "npmWeekly": 380,
          "pypiWeekly": 1518,
          "securityTxt": {
            "url": "https://contentstack.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:38:44.745635489Z"
          },
          "updatedAt": "2026-10-08T17:38:36.151379976Z"
        }
      },
      {
        "slug": "ghost",
        "name": "Ghost",
        "vendor": "Ghost Foundation",
        "vendorUrl": "https://ghost.org",
        "kind": "http-api",
        "category": "cms",
        "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
        "url": "https://www.anchorterminal.com/tools/ghost",
        "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
        "repo": "https://github.com/TryGhost/Ghost",
        "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "transports": [
          "http"
        ],
        "packages": [
          {
            "registry": "npm",
            "name": "ghost"
          },
          {
            "registry": "npm",
            "name": "@tryghost/admin-api"
          },
          {
            "registry": "npm",
            "name": "ghost-cli"
          }
        ],
        "auth": "api-key",
        "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
        "pricing": "freemium",
        "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
        "priceSummary": "$18 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 55500,
          "npmWeekly": 23628,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://docs.ghost.org/admin-api",
        "llmsTxt": "https://docs.ghost.org/llms.txt",
        "capabilities": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "tags": [
          "open-source",
          "self-hosted",
          "hosted",
          "rest",
          "llms-txt",
          "webhooks",
          "newsletter",
          "memberships",
          "nodejs",
          "status-page"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 58.3,
          "grade": "C",
          "agentReady": false,
          "rank": 404,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 7,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 69,
            "maintenance": 85,
            "payments": 50,
            "reliability": 80,
            "schema": 51,
            "security": 56,
            "transparency": 72
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -7,
          "negativeNotes": [
            "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
          ],
          "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
          "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
          "strengths": [
            "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
            "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
            "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
            "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
            "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
          ],
          "weaknesses": [
            "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
            "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
            "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
            "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
            "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
          ],
          "agentNotes": [
            "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
            "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
            "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
            "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
            "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 58.3
            }
          ],
          "editorialScores": {
            "ergonomics": 69,
            "maintenance": 85,
            "payments": 50,
            "reliability": 80,
            "schema": 51,
            "security": 56,
            "transparency": 76
          },
          "provenanceScore": 68
        },
        "connect": {
          "install": "npm install @tryghost/admin-api",
          "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
        },
        "letme": {
          "capability": "https://letme.dev/cms.content",
          "tool": "https://letme.dev/ghost"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Self-hosted Ghost",
            "unit": "month",
            "usd": 0,
            "note": "MIT, you pay for your own hosting and email delivery"
          },
          {
            "item": "Ghost(Pro) Starter",
            "unit": "month",
            "usd": 18,
            "note": "billed yearly, up to 1,000 members, no Admin API"
          },
          {
            "item": "Ghost(Pro) Publisher",
            "unit": "month",
            "usd": 29,
            "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
          },
          {
            "item": "Ghost(Pro) Business",
            "unit": "month",
            "usd": 199,
            "note": "billed yearly, up to 1,000 members, 15 staff users"
          }
        ],
        "provenance": {
          "legalEntity": "Ghost Foundation Ltd",
          "domain": "ghost.org",
          "domainRegistered": "2005-06-25",
          "endpointOnVendorDomain": false,
          "terms": "https://ghost.org/terms/",
          "privacy": "https://ghost.org/privacy/",
          "statusPage": "https://ghoststatus.org",
          "changelog": "https://github.com/TryGhost/Ghost/releases",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
            "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
            "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
            "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
            "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
            "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
          ],
          "score": 68
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
        "live": {
          "slug": "ghost",
          "vendorStatus": {
            "page": "https://ghoststatus.org",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T17:39:08.058758309Z"
          },
          "updatedAt": "2026-10-08T17:39:08.058758309Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/cms",
    "json": "https://www.anchorterminal.com/categories/cms.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/cms.md",
    "slim": "https://www.anchorterminal.com/categories/cms.min.md"
  },
  "markdown": "Content management systems an agent can write to. Entries, assets, locales and the publish step, through an API or an MCP server. Compared on write access, content modelling, drafts and versions, and how a change is reviewed before it goes live.\n\n- Tools ranked: 7 · agent-ready (BB or better): 1 · accept x402: 0 · hosted endpoints: 4 · desk reviews by the panel: 0\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema\n- https://letme.dev/cms.content picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 69 | Sanity | Sanity US Inc. and Sanity AS | HTTP API | CMS | BB | 73.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/sanity.md |\n| 150 | Webflow | Webflow, Inc. | HTTP API | CMS | B | 69.4 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/webflow.md |\n| 188 | Storyblok | Storyblok GmbH | HTTP API | CMS | B | 67.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/storyblok.md |\n| 231 | Strapi | Strapi, Inc. | HTTP API | CMS | B | 65.7 | medium | no | API key | local | none | https://www.anchorterminal.com/tools/strapi.md |\n| 249 | WordPress | WordPress.org (open-source project) | HTTP API | CMS | B | 64.8 | medium | no | API key | local | none | https://www.anchorterminal.com/tools/wordpress.md |\n| 264 | Contentstack | Contentstack Inc. | HTTP API | CMS | B | 64 | medium | no | OAuth or key | hosted + local | none | https://www.anchorterminal.com/tools/contentstack.md |\n| 404 | Ghost | Ghost Foundation | HTTP API | CMS | C | 58.3 | medium | no | API key | local | none | https://www.anchorterminal.com/tools/ghost.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 69. Sanity, BB (73.7)\n\nSanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io. Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.\n\n- Page: https://www.anchorterminal.com/tools/sanity · Markdown: https://www.anchorterminal.com/tools/sanity.md · JSON: https://www.anchorterminal.com/api/v1/tools/sanity.json\n- Capabilities: cms.content, cms.publish, cms.assets, cms.schema, cms.localisation · endpoint: `https://api.sanity.io`\n\n### 150. Webflow, B (69.4)\n\nWebflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools. The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.\n\n- Page: https://www.anchorterminal.com/tools/webflow · Markdown: https://www.anchorterminal.com/tools/webflow.md · JSON: https://www.anchorterminal.com/api/v1/tools/webflow.json\n- Capabilities: cms.content, cms.publish, cms.assets, cms.schema, cms.localisation · endpoint: `https://api.webflow.com/v2`\n\n### 188. Storyblok, B (67.7)\n\nStoryblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools. The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.\n\n- Page: https://www.anchorterminal.com/tools/storyblok · Markdown: https://www.anchorterminal.com/tools/storyblok.md · JSON: https://www.anchorterminal.com/api/v1/tools/storyblok.json\n- Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema · endpoint: `https://mapi.storyblok.com/v1`\n\n### 231. Strapi, B (65.7)\n\nStrapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server. The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n- Page: https://www.anchorterminal.com/tools/strapi · Markdown: https://www.anchorterminal.com/tools/strapi.md · JSON: https://www.anchorterminal.com/api/v1/tools/strapi.json\n- Capabilities: cms.content, cms.publish, cms.localisation, cms.assets, cms.schema\n\n### 249. WordPress, B (64.8)\n\nWordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin. The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n- Page: https://www.anchorterminal.com/tools/wordpress · Markdown: https://www.anchorterminal.com/tools/wordpress.md · JSON: https://www.anchorterminal.com/api/v1/tools/wordpress.json\n- Capabilities: cms.content, cms.publish, cms.assets\n\n### 264. Contentstack, B (64)\n\nContentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents. The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n- Page: https://www.anchorterminal.com/tools/contentstack · Markdown: https://www.anchorterminal.com/tools/contentstack.md · JSON: https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema · endpoint: `https://api.contentstack.io`\n\n### 404. Ghost, C (58.3)\n\nGhost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API. A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n- Page: https://www.anchorterminal.com/tools/ghost · Markdown: https://www.anchorterminal.com/tools/ghost.md · JSON: https://www.anchorterminal.com/api/v1/tools/ghost.json\n- Capabilities: cms.content, cms.publish, cms.assets\n\n## How we test this category\n\nThe same article created as a draft with one image and two locales, revised, published and then rolled back through each listing's management API. We check schema validation, the draft and publish states, asset upload and version history. In this run listings are graded from public evidence against the published checklist. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CMS \u0026 website publishing",
        "url": ""
      }
    ],
    "description": "7 CMS \u0026 website publishing listings ranked by the Anchor benchmark. Leader Sanity (BB). Content management systems an agent can write to. Entries, assets, locales and the publish step, through an API or an MCP server. Compared on write access, content modelling, drafts and versions, and how a change is reviewed before it goes live.",
    "facts": [
      "Sanity BB",
      "Webflow B",
      "Storyblok B"
    ],
    "h1": "Headless CMS and website publishing for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-cms.png",
    "path": "/categories/cms",
    "published": "",
    "section": "tools",
    "title": "Headless CMS and website publishing for AI agents, ranked",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/categories/cms"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 430
  },
  "version": 1
}
