{
  "data": {
    "a": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 217,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:59.495414141Z"
        },
        "updatedAt": "2026-10-08T21:05:59.495414141Z"
      }
    },
    "answer": "Directus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust.",
    "b": {
      "slug": "ghost",
      "name": "Ghost",
      "vendor": "Ghost Foundation",
      "vendorUrl": "https://ghost.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
      "url": "https://www.anchorterminal.com/tools/ghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
      "repo": "https://github.com/TryGhost/Ghost",
      "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "ghost"
        },
        {
          "registry": "npm",
          "name": "@tryghost/admin-api"
        },
        {
          "registry": "npm",
          "name": "ghost-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
      "pricing": "freemium",
      "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
      "priceSummary": "$18 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 55500,
        "npmWeekly": 23628,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ghost.org/admin-api",
      "llmsTxt": "https://docs.ghost.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "rest",
        "llms-txt",
        "webhooks",
        "newsletter",
        "memberships",
        "nodejs",
        "status-page"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 455,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
        ],
        "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
        "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "strengths": [
          "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
          "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
          "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
          "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
          "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
          "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
          "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
          "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
          "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
        ],
        "agentNotes": [
          "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
          "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
          "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
          "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
          "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 76
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npm install @tryghost/admin-api",
        "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/ghost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Ghost",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and email delivery"
        },
        {
          "item": "Ghost(Pro) Starter",
          "unit": "month",
          "usd": 18,
          "note": "billed yearly, up to 1,000 members, no Admin API"
        },
        {
          "item": "Ghost(Pro) Publisher",
          "unit": "month",
          "usd": 29,
          "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
        },
        {
          "item": "Ghost(Pro) Business",
          "unit": "month",
          "usd": 199,
          "note": "billed yearly, up to 1,000 members, 15 staff users"
        }
      ],
      "provenance": {
        "legalEntity": "Ghost Foundation Ltd",
        "domain": "ghost.org",
        "domainRegistered": "2005-06-25",
        "endpointOnVendorDomain": false,
        "terms": "https://ghost.org/terms/",
        "privacy": "https://ghost.org/privacy/",
        "statusPage": "https://ghoststatus.org",
        "changelog": "https://github.com/TryGhost/Ghost/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
          "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
          "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
          "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
          "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
          "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
      "live": {
        "slug": "ghost",
        "vendorStatus": {
          "page": "https://ghoststatus.org",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:06.632212839Z"
        },
        "pages": [
          {
            "url": "https://ghost.org/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:39.9398284Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de86a225cdd"
          },
          {
            "url": "https://ghost.org/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:42.180060747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "673039b71aa4"
          }
        ],
        "updatedAt": "2026-10-08T21:06:06.632212839Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Monospace Inc. (Directus)",
        "b": "Ghost Foundation",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
        "b": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "name": "Licence"
      },
      {
        "a": "12",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-09",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "38k stars, 23k npm/wk",
        "b": "56k stars, 24k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Directus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Directus or Ghost?"
      },
      {
        "answer": "Directus takes an API key or an OAuth sign-in. Ghost needs an API key.",
        "question": "Do Directus and Ghost need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Directus. No hosted endpoint is listed for Ghost.",
        "question": "Can an agent call Directus and Ghost without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Directus. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms).",
        "question": "Are Directus and Ghost open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 81 against 51",
          "Security \u0026 auth, 68 against 56",
          "Payments \u0026 pricing, 55 against 50"
        ],
        "also": null,
        "goodFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "slug": "directus",
        "watchFor": "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period"
      },
      {
        "aheadOn": [
          "Transparency \u0026 trust, 72 against 61"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "slug": "ghost",
        "watchFor": "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
        "title": "Contentstack vs Directus",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-ghost.json",
        "title": "DatoCMS vs Ghost",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 2,
        "directus": 82,
        "edge": "directus",
        "ghost": 80,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 30,
        "directus": 81,
        "edge": "directus",
        "ghost": 51,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 4,
        "directus": 73,
        "edge": "directus",
        "ghost": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 12,
        "directus": 68,
        "edge": "directus",
        "ghost": 56,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 5,
        "directus": 55,
        "edge": "directus",
        "ghost": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "directus": 86,
        "edge": "directus",
        "ghost": 85,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 11,
        "directus": 61,
        "edge": "ghost",
        "ghost": 72,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Directus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "directus": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
      "ghost": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/directus-vs-ghost",
    "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/directus-vs-ghost.md",
    "slim": "https://www.anchorterminal.com/compare/directus-vs-ghost.min.md"
  },
  "markdown": "Directus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust. Both do cms content.\n\n- Directus: grade B, 67.1/100, rank #217 of 722. Markdown https://www.anchorterminal.com/tools/directus.md · JSON https://www.anchorterminal.com/api/v1/tools/directus.json\n- Ghost: grade C, 58.3/100, rank #455 of 722. Markdown https://www.anchorterminal.com/tools/ghost.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost.json\n\n## Which one, for what\n\n### Directus (B)\n\nGood for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.\n\nAhead on:\n- Schema \u0026 documentation, 81 against 51\n- Security \u0026 auth, 68 against 56\n- Payments \u0026 pricing, 55 against 50\n\nWatch for: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n\n### Ghost (C)\n\nGood for: A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.\n\nAhead on:\n- Transparency \u0026 trust, 72 against 61\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository\n\n\n## Score by category\n\n| Category | Weight | Directus | Ghost | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 80 | Directus +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 51 | Directus +30 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 69 | Directus +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 56 | Directus +12 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 55 | 50 | Directus +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 85 | Directus +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 72 | Ghost +11 |\n| Negative events | ≤15 | -6 | -7 | |\n| **Total** | | **67.1 · B** | **58.3 · C** | |\n\n## Facts side by side\n\n| Fact | Directus | Ghost |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Monospace Inc. (Directus) | Ghost Foundation |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms |\n| Tools exposed | 12 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-10-07 |\n| Terms last updated | no date given | no date given |\n| Privacy policy last updated | 2026-06-09 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 38k stars, 23k npm/wk | 56k stars, 24k npm/wk |\n\n## Verdicts\n\n**Directus.** The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n**Ghost.** A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n## Before you call either\n\n### Directus\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n### Ghost\n\n1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead\n2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`\n3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists\n4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card\n5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error\n\n## Questions\n\n### Which is better for AI agents, Directus or Ghost?\n\nDirectus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust.\n\n### Do Directus and Ghost need an API key?\n\nDirectus takes an API key or an OAuth sign-in. Ghost needs an API key.\n\n### Can an agent call Directus and Ghost without installing anything?\n\nNo hosted endpoint is listed for Directus. No hosted endpoint is listed for Ghost.\n\n### Are Directus and Ghost open source?\n\nNo open-source release is listed for Directus. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/directus-vs-ghost.json, and with the fewest tokens: https://www.anchorterminal.com/compare/directus-vs-ghost.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"directus\", \"b\": \"ghost\"}`. From a terminal: `anchor compare directus ghost`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/directus.json and https://www.anchorterminal.com/api/v1/tools/ghost.json\n\n## Other comparisons with Directus or Ghost\n\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md)\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [DatoCMS vs Ghost](https://www.anchorterminal.com/compare/datocms-vs-ghost.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Directus vs Ghost",
        "url": ""
      }
    ],
    "description": "Directus scores 67.1 (B) on agent readiness against Ghost's 58.3 (C), and leads in 6 of 7 scored categories. Ghost leads on transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Directus B 67.1",
      "Ghost C 58.3",
      "scores"
    ],
    "h1": "Directus vs Ghost",
    "image": "https://www.anchorterminal.com/assets/og/compare-directus-vs-ghost.png",
    "path": "/compare/directus-vs-ghost",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Directus vs Ghost for AI agents, B 67.1 vs C 58.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 630
  },
  "version": 1
}
