{
  "data": {
    "a": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 264,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T19:08:44.104830955Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 575,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 540,
          "p95ms24h": 611,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:32.569528883Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "pages": [
          {
            "url": "https://www.contentstack.com/docs/changelog",
            "kind": "changelog",
            "status": 404,
            "checkedAt": "2026-10-08T18:27:09.968657878Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.contentstack.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:17.384677543Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5dd89e546041"
          },
          {
            "url": "https://www.contentstack.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:12.602685857Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "999e1b8c6308"
          },
          {
            "url": "https://www.contentstack.com/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:16.022719984Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9cc98c875af"
          }
        ],
        "updatedAt": "2026-10-08T19:08:44.104830955Z"
      }
    },
    "answer": "Contentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing.",
    "b": {
      "slug": "ghost",
      "name": "Ghost",
      "vendor": "Ghost Foundation",
      "vendorUrl": "https://ghost.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
      "url": "https://www.anchorterminal.com/tools/ghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
      "repo": "https://github.com/TryGhost/Ghost",
      "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "ghost"
        },
        {
          "registry": "npm",
          "name": "@tryghost/admin-api"
        },
        {
          "registry": "npm",
          "name": "ghost-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
      "pricing": "freemium",
      "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
      "priceSummary": "$18 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 55500,
        "npmWeekly": 23628,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ghost.org/admin-api",
      "llmsTxt": "https://docs.ghost.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "rest",
        "llms-txt",
        "webhooks",
        "newsletter",
        "memberships",
        "nodejs",
        "status-page"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 404,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
        ],
        "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
        "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "strengths": [
          "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
          "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
          "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
          "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
          "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
          "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
          "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
          "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
          "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
        ],
        "agentNotes": [
          "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
          "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
          "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
          "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
          "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 76
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npm install @tryghost/admin-api",
        "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/ghost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Ghost",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and email delivery"
        },
        {
          "item": "Ghost(Pro) Starter",
          "unit": "month",
          "usd": 18,
          "note": "billed yearly, up to 1,000 members, no Admin API"
        },
        {
          "item": "Ghost(Pro) Publisher",
          "unit": "month",
          "usd": 29,
          "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
        },
        {
          "item": "Ghost(Pro) Business",
          "unit": "month",
          "usd": 199,
          "note": "billed yearly, up to 1,000 members, 15 staff users"
        }
      ],
      "provenance": {
        "legalEntity": "Ghost Foundation Ltd",
        "domain": "ghost.org",
        "domainRegistered": "2005-06-25",
        "endpointOnVendorDomain": false,
        "terms": "https://ghost.org/terms/",
        "privacy": "https://ghost.org/privacy/",
        "statusPage": "https://ghoststatus.org",
        "changelog": "https://github.com/TryGhost/Ghost/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
          "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
          "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
          "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
          "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
          "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
      "live": {
        "slug": "ghost",
        "vendorStatus": {
          "page": "https://ghoststatus.org",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:40.232515614Z"
        },
        "pages": [
          {
            "url": "https://ghost.org/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:39.9398284Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de86a225cdd"
          },
          {
            "url": "https://ghost.org/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:42.180060747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "673039b71aa4"
          }
        ],
        "updatedAt": "2026-10-08T19:06:40.232515614Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentstack Inc.",
        "b": "Ghost Foundation",
        "name": "Vendor"
      },
      {
        "a": "https://api.contentstack.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "b": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "name": "Licence"
      },
      {
        "a": "206",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2022-08-01",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-30",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "44k npm/wk, 1.5k PyPI/wk",
        "b": "56k stars, 24k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Contentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Contentstack or Ghost?"
      },
      {
        "answer": "Contentstack takes an API key or an OAuth sign-in. Ghost needs an API key.",
        "question": "Do Contentstack and Ghost need an API key?"
      },
      {
        "answer": "Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Ghost.",
        "question": "Can an agent call Contentstack and Ghost without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Contentstack. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms).",
        "question": "Are Contentstack and Ghost open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 77 against 51",
          "Security \u0026 auth, 69 against 56"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "slug": "contentstack",
        "watchFor": "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch"
      },
      {
        "aheadOn": [
          "Reliability, 80 against 71",
          "Payments \u0026 pricing, 50 against 30"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "slug": "ghost",
        "watchFor": "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 9,
        "contentstack": 71,
        "edge": "ghost",
        "ghost": 80,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 26,
        "contentstack": 77,
        "edge": "contentstack",
        "ghost": 51,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 2,
        "contentstack": 67,
        "edge": "ghost",
        "ghost": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 13,
        "contentstack": 69,
        "edge": "contentstack",
        "ghost": 56,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 20,
        "contentstack": 30,
        "edge": "ghost",
        "ghost": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "contentstack": 82,
        "edge": "ghost",
        "ghost": 85,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 1,
        "contentstack": 73,
        "edge": "contentstack",
        "ghost": 72,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Contentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "contentstack": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
      "ghost": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/contentstack-vs-ghost",
    "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.md",
    "slim": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.min.md"
  },
  "markdown": "Contentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing. Both do cms content.\n\n- Contentstack: grade B, 64/100, rank #264 of 629. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- Ghost: grade C, 58.3/100, rank #404 of 629. Markdown https://www.anchorterminal.com/tools/ghost.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost.json\n\n## Which one, for what\n\n### Contentstack (B)\n\nGood for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.\n\nAhead on:\n- Schema \u0026 documentation, 77 against 51\n- Security \u0026 auth, 69 against 56\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n\n### Ghost (C)\n\nGood for: A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.\n\nAhead on:\n- Reliability, 80 against 71\n- Payments \u0026 pricing, 50 against 30\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository\n\n\n## Score by category\n\n| Category | Weight | Contentstack | Ghost | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 80 | Ghost +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 51 | Contentstack +26 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 69 | Ghost +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 56 | Contentstack +13 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 50 | Ghost +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 85 | Ghost +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 72 | Contentstack +1 |\n| Negative events | ≤15 | -3 | -7 | |\n| **Total** | | **64 · B** | **58.3 · C** | |\n\n## Facts side by side\n\n| Fact | Contentstack | Ghost |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentstack Inc. | Ghost Foundation |\n| Hosted endpoint | `https://api.contentstack.io` | no (local only) |\n| Transports | HTTP, stdio | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms |\n| Tools exposed | 206 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-10-07 |\n| Terms last updated | 2022-08-01 | no date given |\n| Privacy policy last updated | 2026-06-30 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 44k npm/wk, 1.5k PyPI/wk | 56k stars, 24k npm/wk |\n\n## Verdicts\n\n**Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n**Ghost.** A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n## Before you call either\n\n### Contentstack\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n### Ghost\n\n1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead\n2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`\n3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists\n4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card\n5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error\n\n## Questions\n\n### Which is better for AI agents, Contentstack or Ghost?\n\nContentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing.\n\n### Do Contentstack and Ghost need an API key?\n\nContentstack takes an API key or an OAuth sign-in. Ghost needs an API key.\n\n### Can an agent call Contentstack and Ghost without installing anything?\n\nContentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Ghost.\n\n### Are Contentstack and Ghost open source?\n\nNo open-source release is listed for Contentstack. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-ghost.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-ghost.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"contentstack\", \"b\": \"ghost\"}`. From a terminal: `anchor compare contentstack ghost`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/ghost.json\n\n## Other comparisons with Contentstack or Ghost\n\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Contentstack vs Ghost",
        "url": ""
      }
    ],
    "description": "Contentstack scores 64 (B) on agent readiness against Ghost's 58.3 (C), and leads in 3 of 7 scored categories. Ghost leads on reliability and payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Contentstack B 64",
      "Ghost C 58.3",
      "scores"
    ],
    "h1": "Contentstack vs Ghost",
    "image": "https://www.anchorterminal.com/assets/og/compare-contentstack-vs-ghost.png",
    "path": "/compare/contentstack-vs-ghost",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack vs Ghost for AI agents, B 64 vs C 58.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
