{
  "data": {
    "a": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 288,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T21:12:08.044941607Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 535,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 540,
          "p95ms24h": 611,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:57.5636666Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "pages": [
          {
            "url": "https://www.contentstack.com/docs/changelog",
            "kind": "changelog",
            "status": 404,
            "checkedAt": "2026-10-08T18:27:09.968657878Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.contentstack.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:17.384677543Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5dd89e546041"
          },
          {
            "url": "https://www.contentstack.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:12.602685857Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "999e1b8c6308"
          },
          {
            "url": "https://www.contentstack.com/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:16.022719984Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9cc98c875af"
          }
        ],
        "updatedAt": "2026-10-08T21:12:08.044941607Z"
      }
    },
    "answer": "Directus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust.",
    "b": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 217,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:59.495414141Z"
        },
        "updatedAt": "2026-10-08T21:05:59.495414141Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentstack Inc.",
        "b": "Monospace Inc. (Directus)",
        "name": "Vendor"
      },
      {
        "a": "https://api.contentstack.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "b": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
        "name": "Licence"
      },
      {
        "a": "206",
        "b": "12",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2022-08-01",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-30",
        "b": "2026-06-09",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "44k npm/wk, 1.5k PyPI/wk",
        "b": "38k stars, 23k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Directus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Contentstack or Directus?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Contentstack and Directus need an API key?"
      },
      {
        "answer": "Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Directus.",
        "question": "Can an agent call Contentstack and Directus without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Transparency \u0026 trust, 73 against 61"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "slug": "contentstack",
        "watchFor": "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch"
      },
      {
        "aheadOn": [
          "Reliability, 82 against 71",
          "Agent ergonomics, 73 against 67",
          "Payments \u0026 pricing, 55 against 30"
        ],
        "also": null,
        "goodFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "slug": "directus",
        "watchFor": "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-datocms.json",
        "title": "Contentstack vs DatoCMS",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-datocms"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 11,
        "contentstack": 71,
        "directus": 82,
        "edge": "directus",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "contentstack": 77,
        "directus": 81,
        "edge": "directus",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 6,
        "contentstack": 67,
        "directus": 73,
        "edge": "directus",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 1,
        "contentstack": 69,
        "directus": 68,
        "edge": "contentstack",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 25,
        "contentstack": 30,
        "directus": 55,
        "edge": "directus",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "contentstack": 82,
        "directus": 86,
        "edge": "directus",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 12,
        "contentstack": 73,
        "directus": 61,
        "edge": "contentstack",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Directus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "contentstack": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
      "directus": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/contentstack-vs-directus",
    "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/contentstack-vs-directus.md",
    "slim": "https://www.anchorterminal.com/compare/contentstack-vs-directus.min.md"
  },
  "markdown": "Directus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust. Both do cms content.\n\n- Contentstack: grade B, 64/100, rank #288 of 722. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- Directus: grade B, 67.1/100, rank #217 of 722. Markdown https://www.anchorterminal.com/tools/directus.md · JSON https://www.anchorterminal.com/api/v1/tools/directus.json\n\n## Which one, for what\n\n### Contentstack (B)\n\nGood for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.\n\nAhead on:\n- Transparency \u0026 trust, 73 against 61\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n\n### Directus (B)\n\nGood for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.\n\nAhead on:\n- Reliability, 82 against 71\n- Agent ergonomics, 73 against 67\n- Payments \u0026 pricing, 55 against 30\n\nWatch for: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n\n\n## Score by category\n\n| Category | Weight | Contentstack | Directus | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 82 | Directus +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 81 | Directus +4 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 73 | Directus +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 68 | Contentstack +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 55 | Directus +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 86 | Directus +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 61 | Contentstack +12 |\n| Negative events | ≤15 | -3 | -6 | |\n| **Total** | | **64 · B** | **67.1 · B** | |\n\n## Facts side by side\n\n| Fact | Contentstack | Directus |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentstack Inc. | Monospace Inc. (Directus) |\n| Hosted endpoint | `https://api.contentstack.io` | no (local only) |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT |\n| Tools exposed | 206 | 12 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-10-07 |\n| Terms last updated | 2022-08-01 | no date given |\n| Privacy policy last updated | 2026-06-30 | 2026-06-09 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 44k npm/wk, 1.5k PyPI/wk | 38k stars, 23k npm/wk |\n\n## Verdicts\n\n**Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n**Directus.** The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n## Before you call either\n\n### Contentstack\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n### Directus\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n## Questions\n\n### Which is better for AI agents, Contentstack or Directus?\n\nDirectus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust.\n\n### Do Contentstack and Directus need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Contentstack and Directus without installing anything?\n\nContentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Directus.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-directus.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-directus.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"contentstack\", \"b\": \"directus\"}`. From a terminal: `anchor compare contentstack directus`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/directus.json\n\n## Other comparisons with Contentstack or Directus\n\n- [Contentstack vs DatoCMS](https://www.anchorterminal.com/compare/contentstack-vs-datocms.md)\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Contentstack vs Directus",
        "url": ""
      }
    ],
    "description": "Directus scores 67.1 (B) on agent readiness against Contentstack's 64 (B), and leads in 5 of 7 scored categories. Contentstack leads on transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Contentstack B 64",
      "Directus B 67.1",
      "scores"
    ],
    "h1": "Contentstack vs Directus",
    "image": "https://www.anchorterminal.com/assets/og/compare-contentstack-vs-directus.png",
    "path": "/compare/contentstack-vs-directus",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack vs Directus for AI agents, B 64 vs B 67.1",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 730
  },
  "version": 1
}
