Head to head · Cms content · October 2026 research run

Contentstack vs Hygraph

Hygraph scores 69.3 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories. Contentstack leads on security & auth, maintenance & community and transparency & trust. Both do cms content.

Which one, for what

Contentstack B

Good for Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.

Ahead on

  • Security & auth, 69 against 63
  • Maintenance & community, 82 against 74
  • Transparency & trust, 73 against 60

Also in its favour

  • Runs on your own machine

Watch for

The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch

Hygraph B

Good for Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.

Ahead on

  • Reliability, 89 against 71
  • Agent ergonomics, 72 against 67
  • Payments & pricing, 35 against 30

Also in its favour

  • No incidents deducted, where Contentstack loses 3 points for them

Watch for

GraphQL error bodies carry a message and a requestId with no machine-readable code, and only asset transformation 429 responses are documented with Retry-After

Score by category

CategoryWeight this runContentstackHygraphEdge
Reliability16%207189Hygraph +18
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27778Hygraph +1
Agent ergonomics13%16.26772Hygraph +5
Security & auth14%17.56963Contentstack +6
Payments & pricing10%12.53035Hygraph +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88274Contentstack +8
Transparency & trust7%8.87360Contentstack +13
Negative events≤15-30
Total64 · B69.3 · B

Facts side by side

FactContentstackHygraph
KindHTTP APIHTTP API
VendorContentstack Inc.Hygraph GmbH
Hosted endpointhttps://api.contentstack.iohttps://mcp.hygraph.com/mcp
TransportsHTTP, stdioHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MITProprietary service under Hygraph GmbH's Terms of Service. The @hygraph/management-sdk package is MIT
Tools exposed20617
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-222026-09-30
Terms last updated2022-08-01no date given
Privacy policy last updated2026-06-30no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesnot found in the text
Popularity44k npm/wk, 1.5k PyPI/wk52 stars, 8.6k npm/wk

Verdicts

Contentstack

The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the limit=0 behaviour changed on 11 September 2026 without advance notice.

Hygraph

Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.

Before you call either

Contentstack

  1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts
  2. Send api_key and authorization headers on every Content Management API call. Ask for a read-only management token when the task only reads
  3. Page with limit (100 at most), skip and include_count=true. limit=0 no longer returns everything
  4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch X-RateLimit-Remaining and back off on 429
  5. Start the MCP server with --groups cma only, and add cma-extended when the task needs audit logs or version history. Publishing and deleting need no confirmation

Hygraph

  1. Send the Permanent Auth Token as Authorization: Bearer <token> to https://<region>.hygraph.com/v2/<projectId>/<environment>. Read the schema by introspection first, because every type is generated from the project's models
  2. Mutations write to DRAFT. Call publish<Model> with to: [PUBLISHED] as a separate mutation, and pass locales to write or publish a localisation
  3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429
  4. Upload an asset with createAsset, then POST the file to the returned pre-signed URL, or pass uploadUrl for a remote file. The asset stays ASSET_CREATE_PENDING until processed
  5. Schema changes go to the Management API through @hygraph/management-sdk or the MCP tool submit_batch_migration. Version restore has no documented mutation, so read <model>Version and write the old values back

Questions

Which is better for AI agents, Contentstack or Hygraph?

Hygraph scores 69.3 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories. Contentstack leads on security & auth, maintenance & community and transparency & trust.

Do Contentstack and Hygraph need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Contentstack and Hygraph without installing anything?

Yes. Contentstack has a hosted endpoint at https://api.contentstack.io and Hygraph at https://mcp.hygraph.com/mcp.

Other comparisons with Contentstack or Hygraph

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.