Head to head · Cms content · October 2026 research run

Directus vs Hygraph

Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security & auth, payments & pricing and maintenance & community. Both do cms content.

Which one, for what

Directus B

Good for Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.

Ahead on

  • Security & auth, 68 against 63
  • Payments & pricing, 55 against 35
  • Maintenance & community, 86 against 74

Watch for

Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period

Hygraph B

Good for Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.

Ahead on

  • Reliability, 89 against 82

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where Directus loses 6 points for them

Watch for

GraphQL error bodies carry a message and a requestId with no machine-readable code, and only asset transformation 429 responses are documented with Retry-After

Score by category

CategoryWeight this runDirectusHygraphEdge
Reliability16%208289Hygraph +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28178Directus +3
Agent ergonomics13%16.27372Directus +1
Security & auth14%17.56863Directus +5
Payments & pricing10%12.55535Directus +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88674Directus +12
Transparency & trust7%8.86160Directus +1
Negative events≤15-60
Total67.1 · B69.3 · B

Facts side by side

FactDirectusHygraph
KindHTTP APIHTTP API
VendorMonospace Inc. (Directus)Hygraph GmbH
Hosted endpointno (local only)https://mcp.hygraph.com/mcp
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. @directus/sdk is MITProprietary service under Hygraph GmbH's Terms of Service. The @hygraph/management-sdk package is MIT
Tools exposed1217
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-09-30
Terms last updatedno date givenno date given
Privacy policy last updated2026-06-09no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textnot found in the text
Popularity38k stars, 23k npm/wk52 stars, 8.6k npm/wk

Verdicts

Directus

The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.

Hygraph

Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.

Before you call either

Directus

  1. Connect with OAuth or an Authorization: Bearer header. Don't put the token in the URL as ?access_token=, where it can be logged
  2. Use /mcp?tool_mode=registry when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total
  3. Read the schema tool before writing. Item payloads are untyped objects, so field names and types come only from the data model
  4. Publish a version with POST /versions/{id}/promote over REST. The MCP items tool refuses system collections such as directus_versions
  5. Count translation and junction tables against the 25-collection Core limit before creating collections

Hygraph

  1. Send the Permanent Auth Token as Authorization: Bearer <token> to https://<region>.hygraph.com/v2/<projectId>/<environment>. Read the schema by introspection first, because every type is generated from the project's models
  2. Mutations write to DRAFT. Call publish<Model> with to: [PUBLISHED] as a separate mutation, and pass locales to write or publish a localisation
  3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429
  4. Upload an asset with createAsset, then POST the file to the returned pre-signed URL, or pass uploadUrl for a remote file. The asset stays ASSET_CREATE_PENDING until processed
  5. Schema changes go to the Management API through @hygraph/management-sdk or the MCP tool submit_batch_migration. Version restore has no documented mutation, so read <model>Version and write the old values back

Questions

Which is better for AI agents, Directus or Hygraph?

Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security & auth, payments & pricing and maintenance & community.

Do Directus and Hygraph need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Directus and Hygraph without installing anything?

No hosted endpoint is listed for Directus. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.

Other comparisons with Directus or Hygraph

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.