{
  "data": {
    "a": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 244,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:02.726880939Z"
        },
        "updatedAt": "2026-10-09T09:25:02.726880939Z"
      }
    },
    "answer": "Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "hygraph",
      "name": "Hygraph",
      "vendor": "Hygraph GmbH",
      "vendorUrl": "https://hygraph.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/hygraph",
      "markdownUrl": "https://www.anchorterminal.com/tools/hygraph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hygraph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hygraph.json",
      "repo": "https://github.com/hygraph/management-sdk",
      "license": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.hygraph.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@hygraph/management-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content API and Management API take a Permanent Auth Token as a Bearer header. A person creates the token in Project Settings and sets its content permissions (by model, stage, locale, environment and action) and its Management API permissions. A new token has none enabled. Deleting a token invalidates it, and no expiry or rotation was found. The project MCP endpoint takes the same token. The global MCP endpoint uses a browser login through auth.hygraph.com and follows the user's own permissions. OAuth for third-party apps needs a client ID from Hygraph support. No app review or sales approval is needed for tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Hobby plan is free with no card and includes 500,000 API calls a month, 1,000 entries, 2 locales and 3 API tokens. Usage past the limit is blocked until the next period. Growth is $199 a month with 1,000,000 API calls, and overage of $0.20 per 10,000 API operations and per GB of asset traffic. Enterprise is sold through sales, with a 30-day trial that needs no card (https://hygraph.com/pricing, checked 2026-10-08).",
      "priceSummary": "$199 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 17,
      "popularity": {
        "githubStars": 52,
        "npmWeekly": 8645,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://hygraph.com/docs/api-reference",
      "llmsTxt": "https://hygraph.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.3,
        "grade": "B",
        "agentReady": false,
        "rank": 182,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
        "bestFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "strengths": [
          "Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled",
          "The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction",
          "GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100",
          "The Hobby plan needs no card and includes 500,000 API calls a month, 1,000 entries and 3 API tokens",
          "`llms.txt` links a Markdown copy of every documentation section, and the changelog has dated entries for 30 July, 31 August and 30 September 2026"
        ],
        "weaknesses": [
          "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`",
          "No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field",
          "Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth",
          "No data processing agreement, named sub-processor list, security.txt or disclosure policy was found on hygraph.com. The privacy policy names categories of service provider only",
          "The only official SDK is `@hygraph/management-sdk` for JavaScript and TypeScript, and its public GitHub repository was last pushed on 13 September 2024"
        ],
        "agentNotes": [
          "Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models",
          "Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation",
          "Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429",
          "Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed",
          "Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.3
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 45
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @hygraph/management-sdk",
        "claudeCode": "claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \\\n  --transport http \\\n  --header \"Authorization: Bearer ${HYGRAPH_TOKEN}\"",
        "config": {
          "mcpServers": {
            "hygraph": {
              "args": [
                "mcp-remote",
                "https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/master/mcp",
                "--header",
                "Authorization: Bearer ${HYGRAPH_TOKEN}"
              ],
              "command": "npx",
              "env": {
                "HYGRAPH_TOKEN": "token_here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/hygraph"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 199,
          "note": "10 seats, 1,000,000 API calls and 500 GB of asset traffic included"
        },
        {
          "item": "Additional API operations on Growth",
          "unit": "1k-requests",
          "usd": 0.02,
          "note": "sold as $0.20 per 10,000 API operations"
        },
        {
          "item": "Additional asset traffic on Growth",
          "unit": "gb",
          "usd": 0.2,
          "note": "per GB past the plan's 500 GB"
        }
      ],
      "provenance": {
        "legalEntity": "Hygraph GmbH",
        "domain": "hygraph.com",
        "domainRegistered": "2022-03-04",
        "endpointOnVendorDomain": true,
        "terms": "https://hygraph.com/terms",
        "privacy": "https://hygraph.com/privacy",
        "statusPage": "https://status.hygraph.com",
        "changelog": "https://hygraph.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint and the privacy policy name Hygraph GmbH, Dircksenstraße 47, 10178 Berlin, registered at Amtsgericht Berlin Charlottenburg under HRB 250696 B.",
          "The Terms of Service define the Hygraph Services to include the cloud platform and the Hygraph API. The pricing page lists them as the online terms for Hobby and Growth, with custom terms on Enterprise.",
          "The privacy policy has a section on use of the Hygraph service and was last updated on 19 March 2025. It names categories of service provider and no companies. No data processing agreement was found on hygraph.com.",
          "The Content API answers at \u003cregion\u003e.hygraph.com, the Management API at management.hygraph.com, the MCP server at mcp.hygraph.com and the OAuth server at auth.hygraph.com.",
          "https://hygraph.com/.well-known/security.txt answered 404 on 8 October 2026.",
          "RDAP for hygraph.com gives a registration date of 2022-03-04. The product was named GraphCMS before that, and the older SDK is still on npm as `@graphcms/management`."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hygraph.json",
      "live": {
        "slug": "hygraph",
        "probe": {
          "target": "https://mcp.hygraph.com/mcp",
          "method": "get",
          "lastAt": "2026-10-09T09:26:53.018011399Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 163,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 94,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hygraph.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:14.386503586Z"
        },
        "updatedAt": "2026-10-09T09:26:53.018011399Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Monospace Inc. (Directus)",
        "b": "Hygraph GmbH",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.hygraph.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
        "b": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
        "name": "Licence"
      },
      {
        "a": "12",
        "b": "17",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-09",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "38k stars, 23k npm/wk",
        "b": "52 stars, 8.6k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Directus or Hygraph?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Directus and Hygraph need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Directus. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.",
        "question": "Can an agent call Directus and Hygraph without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 68 against 63",
          "Payments \u0026 pricing, 55 against 35",
          "Maintenance \u0026 community, 86 against 74"
        ],
        "also": null,
        "goodFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "slug": "directus",
        "watchFor": "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 82"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Directus loses 6 points for them"
        ],
        "goodFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "slug": "hygraph",
        "watchFor": "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
        "title": "Contentstack vs Directus",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph.json",
        "title": "Contentstack vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-hygraph.json",
        "title": "DatoCMS vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-prismic.json",
        "title": "Directus vs Prismic",
        "url": "https://www.anchorterminal.com/compare/directus-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.json",
        "title": "Ghost vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-sanity.json",
        "title": "Hygraph vs Sanity",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok.json",
        "title": "Hygraph vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.json",
        "title": "Hygraph vs Strapi",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-webflow.json",
        "title": "Hygraph vs Webflow",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json",
        "title": "Hygraph vs WordPress",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 7,
        "directus": 82,
        "edge": "hygraph",
        "hygraph": 89,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "directus": 81,
        "edge": "directus",
        "hygraph": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 1,
        "directus": 73,
        "edge": "directus",
        "hygraph": 72,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 5,
        "directus": 68,
        "edge": "directus",
        "hygraph": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 20,
        "directus": 55,
        "edge": "directus",
        "hygraph": 35,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "directus": 86,
        "edge": "directus",
        "hygraph": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 1,
        "directus": 61,
        "edge": "directus",
        "hygraph": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community. Both do cms content.",
    "verdicts": {
      "directus": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
      "hygraph": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/directus-vs-hygraph",
    "json": "https://www.anchorterminal.com/compare/directus-vs-hygraph.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/directus-vs-hygraph.md",
    "slim": "https://www.anchorterminal.com/compare/directus-vs-hygraph.min.md"
  },
  "markdown": "Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community. Both do cms content.\n\n- Directus: grade B, 67.1/100, rank #244 of 842. Markdown https://www.anchorterminal.com/tools/directus.md · JSON https://www.anchorterminal.com/api/v1/tools/directus.json\n- Hygraph: grade B, 69.3/100, rank #182 of 842. Markdown https://www.anchorterminal.com/tools/hygraph.md · JSON https://www.anchorterminal.com/api/v1/tools/hygraph.json\n\n## Which one, for what\n\n### Directus (B)\n\nGood for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.\n\nAhead on:\n- Security \u0026 auth, 68 against 63\n- Payments \u0026 pricing, 55 against 35\n- Maintenance \u0026 community, 86 against 74\n\nWatch for: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n\n### Hygraph (B)\n\nGood for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.\n\nAhead on:\n- Reliability, 89 against 82\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Directus loses 6 points for them\n\nWatch for: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`\n\n\n## Score by category\n\n| Category | Weight | Directus | Hygraph | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 89 | Hygraph +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 78 | Directus +3 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 72 | Directus +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 63 | Directus +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 55 | 35 | Directus +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 74 | Directus +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 60 | Directus +1 |\n| Negative events | ≤15 | -6 | 0 | |\n| **Total** | | **67.1 · B** | **69.3 · B** | |\n\n## Facts side by side\n\n| Fact | Directus | Hygraph |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Monospace Inc. (Directus) | Hygraph GmbH |\n| Hosted endpoint | no (local only) | `https://mcp.hygraph.com/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT | Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT |\n| Tools exposed | 12 | 17 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-30 |\n| Terms last updated | no date given | no date given |\n| Privacy policy last updated | 2026-06-09 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 38k stars, 23k npm/wk | 52 stars, 8.6k npm/wk |\n\n## Verdicts\n\n**Directus.** The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n**Hygraph.** Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.\n\n## Before you call either\n\n### Directus\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n### Hygraph\n\n1. Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models\n2. Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation\n3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429\n4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed\n5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back\n\n## Questions\n\n### Which is better for AI agents, Directus or Hygraph?\n\nHygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Directus and Hygraph need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Directus and Hygraph without installing anything?\n\nNo hosted endpoint is listed for Directus. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/directus-vs-hygraph.json, and with the fewest tokens: https://www.anchorterminal.com/compare/directus-vs-hygraph.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"directus\", \"b\": \"hygraph\"}`. From a terminal: `anchor compare directus hygraph`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/directus.json and https://www.anchorterminal.com/api/v1/tools/hygraph.json\n\n## Other comparisons with Directus or Hygraph\n\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md)\n- [Contentstack vs Hygraph](https://www.anchorterminal.com/compare/contentstack-vs-hygraph.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Prismic](https://www.anchorterminal.com/compare/directus-vs-prismic.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Hygraph](https://www.anchorterminal.com/compare/ghost-vs-hygraph.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md)\n- [Hygraph vs Storyblok](https://www.anchorterminal.com/compare/hygraph-vs-storyblok.md)\n- [Hygraph vs Strapi](https://www.anchorterminal.com/compare/hygraph-vs-strapi.md)\n- [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md)\n- [Hygraph vs WordPress](https://www.anchorterminal.com/compare/hygraph-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Directus vs Hygraph",
        "url": ""
      }
    ],
    "description": "Hygraph scores 69.3 (B) on agent readiness against Directus's 67.1 (B), and leads in 1 of 7 scored categories. Directus leads on security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Directus B 67.1",
      "Hygraph B 69.3",
      "scores"
    ],
    "h1": "Directus vs Hygraph",
    "image": "https://www.anchorterminal.com/assets/og/compare-directus-vs-hygraph.png",
    "path": "/compare/directus-vs-hygraph",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Directus vs Hygraph for AI agents, B 67.1 vs B 69.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/directus-vs-hygraph"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
