{
  "data": {
    "a": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 264,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T17:36:33.652239638Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 535,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 541,
          "p95ms24h": 636,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:38:36.151379976Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "updatedAt": "2026-10-08T17:38:36.151379976Z"
      }
    },
    "answer": "Strapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories.",
    "b": {
      "slug": "strapi",
      "name": "Strapi",
      "vendor": "Strapi, Inc.",
      "vendorUrl": "https://strapi.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/strapi",
      "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
      "repo": "https://github.com/strapi/strapi",
      "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@strapi/strapi"
        },
        {
          "registry": "npm",
          "name": "@strapi/client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
      "priceSummary": "$45 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 73289,
        "npmWeekly": 258813,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.strapi.io",
      "llmsTxt": "https://docs.strapi.io/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "llms-txt",
        "webhooks",
        "graphql",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.7,
        "grade": "B",
        "agentReady": false,
        "rank": 231,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -6,
        "negativeNotes": [
          "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
        ],
        "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
        "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "strengths": [
          "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
          "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
          "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
          "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
          "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
          "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
          "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
          "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
          "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
        ],
        "agentNotes": [
          "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
          "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
          "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
          "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
          "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 75
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx create-strapi@latest",
        "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
        "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
        "config": {
          "mcpServers": {
            "strapi-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_ADMIN_TOKEN"
              },
              "type": "streamable-http",
              "url": "http://localhost:1337/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/strapi"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT, unlimited seats, you pay for your own hosting"
        },
        {
          "item": "Growth, self-hosted",
          "unit": "month",
          "usd": 45,
          "note": "3 seats included, $15 per extra seat"
        },
        {
          "item": "Strapi Cloud Starter",
          "unit": "month",
          "usd": 35,
          "note": "per project, 100,000 API requests"
        },
        {
          "item": "Strapi Cloud Pro",
          "unit": "month",
          "usd": 90,
          "note": "per project, 1 million API requests"
        },
        {
          "item": "Strapi Cloud Business",
          "unit": "month",
          "usd": 450,
          "note": "per project, 10 million API requests"
        },
        {
          "item": "Strapi Cloud API requests over the plan",
          "unit": "1k-requests",
          "usd": 0.06,
          "note": "$1.50 per 25,000"
        }
      ],
      "provenance": {
        "legalEntity": "Strapi, Inc.",
        "domain": "strapi.io",
        "domainRegistered": "2015-09-21",
        "endpointOnVendorDomain": false,
        "terms": "https://strapi.io/cloud-legal",
        "privacy": "https://strapi.io/privacy",
        "statusPage": "https://status.strapi.io",
        "changelog": "https://github.com/strapi/strapi/releases",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
          "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
          "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
          "RDAP for strapi.io gives a registration date of 2015-09-21.",
          "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
      "live": {
        "slug": "strapi",
        "vendorStatus": {
          "page": "https://status.strapi.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:37:17.41184558Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "strapi/strapi",
            "version": "v5.57.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:30:39.413193839Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/client",
            "version": "1.6.2",
            "seenAt": "2026-10-08T16:30:37.897146773Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/strapi",
            "version": "5.57.0",
            "seenAt": "2026-10-08T16:30:37.072939352Z"
          }
        ],
        "githubStars": 73292,
        "npmWeekly": 258813,
        "securityTxt": {
          "url": "https://strapi.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:07.890617672Z"
        },
        "updatedAt": "2026-10-08T16:30:39.413193839Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentstack Inc.",
        "b": "Strapi, Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.contentstack.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "b": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
        "name": "Licence"
      },
      {
        "a": "206",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2022-08-01",
        "b": "2026-10-07",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-30",
        "b": "2023-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "44k npm/wk, 1.5k PyPI/wk",
        "b": "73k stars, 259k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Strapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories.",
        "question": "Which is better for AI agents, Contentstack or Strapi?"
      },
      {
        "answer": "Contentstack takes an API key or an OAuth sign-in. Strapi needs an API key.",
        "question": "Do Contentstack and Strapi need an API key?"
      },
      {
        "answer": "Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Strapi.",
        "question": "Can an agent call Contentstack and Strapi without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Contentstack. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).",
        "question": "Are Contentstack and Strapi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "slug": "contentstack",
        "watchFor": "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch"
      },
      {
        "aheadOn": [
          "Reliability, 82 against 71",
          "Payments \u0026 pricing, 50 against 30",
          "Maintenance \u0026 community, 87 against 82"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "slug": "strapi",
        "watchFor": "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-strapi.json",
        "title": "Sanity vs Strapi",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-strapi.json",
        "title": "Storyblok vs Strapi",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 11,
        "contentstack": 71,
        "edge": "strapi",
        "key": "reliability",
        "name": "Reliability",
        "strapi": 82,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "contentstack": 77,
        "edge": "strapi",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "strapi": 80,
        "weight": 13
      },
      {
        "by": 2,
        "contentstack": 67,
        "edge": "contentstack",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "strapi": 65,
        "weight": 13
      },
      {
        "by": 3,
        "contentstack": 69,
        "edge": "contentstack",
        "key": "security",
        "name": "Security \u0026 auth",
        "strapi": 66,
        "weight": 14
      },
      {
        "by": 20,
        "contentstack": 30,
        "edge": "strapi",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "strapi": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "contentstack": 82,
        "edge": "strapi",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "strapi": 87,
        "weight": 7
      },
      {
        "by": 1,
        "contentstack": 73,
        "edge": "contentstack",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "strapi": 72,
        "weight": 7
      }
    ],
    "summary": "Strapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories. Both do cms content.",
    "verdicts": {
      "contentstack": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
      "strapi": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/contentstack-vs-strapi",
    "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.md",
    "slim": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.min.md"
  },
  "markdown": "Strapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories. Both do cms content.\n\n- Contentstack: grade B, 64/100, rank #264 of 629. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- Strapi: grade B, 65.7/100, rank #231 of 629. Markdown https://www.anchorterminal.com/tools/strapi.md · JSON https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Which one, for what\n\n### Contentstack (B)\n\nGood for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n\n### Strapi (B)\n\nGood for: Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.\n\nAhead on:\n- Reliability, 82 against 71\n- Payments \u0026 pricing, 50 against 30\n- Maintenance \u0026 community, 87 against 82\n\nAlso in its favour:\n- Open source\n\nWatch for: Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n\n\n## Score by category\n\n| Category | Weight | Contentstack | Strapi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 82 | Strapi +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 80 | Strapi +3 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 65 | Contentstack +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 66 | Contentstack +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 50 | Strapi +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 87 | Strapi +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 72 | Contentstack +1 |\n| Negative events | ≤15 | -3 | -6 | |\n| **Total** | | **64 · B** | **65.7 · B** | |\n\n## Facts side by side\n\n| Fact | Contentstack | Strapi |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentstack Inc. | Strapi, Inc. |\n| Hosted endpoint | `https://api.contentstack.io` | no (local only) |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms |\n| Tools exposed | 206 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-10-07 |\n| Terms last updated | 2022-08-01 | 2026-10-07 |\n| Privacy policy last updated | 2026-06-30 | 2023-03-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 44k npm/wk, 1.5k PyPI/wk | 73k stars, 259k npm/wk |\n\n## Verdicts\n\n**Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n**Strapi.** The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n## Before you call either\n\n### Contentstack\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n### Strapi\n\n1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## Questions\n\n### Which is better for AI agents, Contentstack or Strapi?\n\nStrapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories.\n\n### Do Contentstack and Strapi need an API key?\n\nContentstack takes an API key or an OAuth sign-in. Strapi needs an API key.\n\n### Can an agent call Contentstack and Strapi without installing anything?\n\nContentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Strapi.\n\n### Are Contentstack and Strapi open source?\n\nNo open-source release is listed for Contentstack. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-strapi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-strapi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"contentstack\", \"b\": \"strapi\"}`. From a terminal: `anchor compare contentstack strapi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Other comparisons with Contentstack or Strapi\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md)\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Contentstack vs Strapi",
        "url": ""
      }
    ],
    "description": "Strapi scores 65.7 (B) on agent readiness against Contentstack's 64 (B), and leads in 4 of 7 scored categories. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Contentstack B 64",
      "Strapi B 65.7",
      "scores"
    ],
    "h1": "Contentstack vs Strapi",
    "image": "https://www.anchorterminal.com/assets/og/compare-contentstack-vs-strapi.png",
    "path": "/compare/contentstack-vs-strapi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack vs Strapi for AI agents, B 64 vs B 65.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 680
  },
  "version": 1
}
