{
  "data": {
    "a": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 217,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:59.495414141Z"
        },
        "updatedAt": "2026-10-08T21:05:59.495414141Z"
      }
    },
    "answer": "Directus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust.",
    "b": {
      "slug": "strapi",
      "name": "Strapi",
      "vendor": "Strapi, Inc.",
      "vendorUrl": "https://strapi.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/strapi",
      "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
      "repo": "https://github.com/strapi/strapi",
      "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@strapi/strapi"
        },
        {
          "registry": "npm",
          "name": "@strapi/client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
      "priceSummary": "$45 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 73289,
        "npmWeekly": 258813,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.strapi.io",
      "llmsTxt": "https://docs.strapi.io/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "llms-txt",
        "webhooks",
        "graphql",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.7,
        "grade": "B",
        "agentReady": false,
        "rank": 252,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -6,
        "negativeNotes": [
          "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
        ],
        "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
        "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "strengths": [
          "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
          "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
          "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
          "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
          "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
          "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
          "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
          "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
          "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
        ],
        "agentNotes": [
          "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
          "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
          "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
          "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
          "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 75
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx create-strapi@latest",
        "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
        "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
        "config": {
          "mcpServers": {
            "strapi-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_ADMIN_TOKEN"
              },
              "type": "streamable-http",
              "url": "http://localhost:1337/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/strapi"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT, unlimited seats, you pay for your own hosting"
        },
        {
          "item": "Growth, self-hosted",
          "unit": "month",
          "usd": 45,
          "note": "3 seats included, $15 per extra seat"
        },
        {
          "item": "Strapi Cloud Starter",
          "unit": "month",
          "usd": 35,
          "note": "per project, 100,000 API requests"
        },
        {
          "item": "Strapi Cloud Pro",
          "unit": "month",
          "usd": 90,
          "note": "per project, 1 million API requests"
        },
        {
          "item": "Strapi Cloud Business",
          "unit": "month",
          "usd": 450,
          "note": "per project, 10 million API requests"
        },
        {
          "item": "Strapi Cloud API requests over the plan",
          "unit": "1k-requests",
          "usd": 0.06,
          "note": "$1.50 per 25,000"
        }
      ],
      "provenance": {
        "legalEntity": "Strapi, Inc.",
        "domain": "strapi.io",
        "domainRegistered": "2015-09-21",
        "endpointOnVendorDomain": false,
        "terms": "https://strapi.io/cloud-legal",
        "privacy": "https://strapi.io/privacy",
        "statusPage": "https://status.strapi.io",
        "changelog": "https://github.com/strapi/strapi/releases",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
          "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
          "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
          "RDAP for strapi.io gives a registration date of 2015-09-21.",
          "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
      "live": {
        "slug": "strapi",
        "vendorStatus": {
          "page": "https://status.strapi.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:14.197616628Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "strapi/strapi",
            "version": "v5.57.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:30:39.413193839Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/client",
            "version": "1.6.2",
            "seenAt": "2026-10-08T16:30:37.897146773Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/strapi",
            "version": "5.57.0",
            "seenAt": "2026-10-08T16:30:37.072939352Z"
          }
        ],
        "githubStars": 73292,
        "npmWeekly": 258813,
        "securityTxt": {
          "url": "https://strapi.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:07.890617672Z"
        },
        "pages": [
          {
            "url": "https://strapi.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:54.221268289Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9a83a678305b"
          },
          {
            "url": "https://strapi.io/cloud-legal",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:51.925906428Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e789fbc0c6c8"
          }
        ],
        "updatedAt": "2026-10-08T19:39:14.197616628Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Monospace Inc. (Directus)",
        "b": "Strapi, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
        "b": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
        "name": "Licence"
      },
      {
        "a": "12",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2026-10-07",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-09",
        "b": "2023-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "38k stars, 23k npm/wk",
        "b": "73k stars, 259k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Directus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Directus or Strapi?"
      },
      {
        "answer": "Directus takes an API key or an OAuth sign-in. Strapi needs an API key.",
        "question": "Do Directus and Strapi need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Directus. No hosted endpoint is listed for Strapi.",
        "question": "Can an agent call Directus and Strapi without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Directus. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).",
        "question": "Are Directus and Strapi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 73 against 65",
          "Payments \u0026 pricing, 55 against 50"
        ],
        "also": null,
        "goodFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "slug": "directus",
        "watchFor": "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period"
      },
      {
        "aheadOn": [
          "Transparency \u0026 trust, 72 against 61"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "slug": "strapi",
        "watchFor": "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
        "title": "Contentstack vs Directus",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-strapi.json",
        "title": "DatoCMS vs Strapi",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-strapi.json",
        "title": "Sanity vs Strapi",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-strapi.json",
        "title": "Storyblok vs Strapi",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 0,
        "directus": 82,
        "edge": "",
        "key": "reliability",
        "name": "Reliability",
        "strapi": 82,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "directus": 81,
        "edge": "directus",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "strapi": 80,
        "weight": 13
      },
      {
        "by": 8,
        "directus": 73,
        "edge": "directus",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "strapi": 65,
        "weight": 13
      },
      {
        "by": 2,
        "directus": 68,
        "edge": "directus",
        "key": "security",
        "name": "Security \u0026 auth",
        "strapi": 66,
        "weight": 14
      },
      {
        "by": 5,
        "directus": 55,
        "edge": "directus",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "strapi": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "directus": 86,
        "edge": "strapi",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "strapi": 87,
        "weight": 7
      },
      {
        "by": 11,
        "directus": 61,
        "edge": "strapi",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "strapi": 72,
        "weight": 7
      }
    ],
    "summary": "Directus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "directus": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
      "strapi": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/directus-vs-strapi",
    "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/directus-vs-strapi.md",
    "slim": "https://www.anchorterminal.com/compare/directus-vs-strapi.min.md"
  },
  "markdown": "Directus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust. Both do cms content.\n\n- Directus: grade B, 67.1/100, rank #217 of 722. Markdown https://www.anchorterminal.com/tools/directus.md · JSON https://www.anchorterminal.com/api/v1/tools/directus.json\n- Strapi: grade B, 65.7/100, rank #252 of 722. Markdown https://www.anchorterminal.com/tools/strapi.md · JSON https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Which one, for what\n\n### Directus (B)\n\nGood for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.\n\nAhead on:\n- Agent ergonomics, 73 against 65\n- Payments \u0026 pricing, 55 against 50\n\nWatch for: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n\n### Strapi (B)\n\nGood for: Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.\n\nAhead on:\n- Transparency \u0026 trust, 72 against 61\n\nAlso in its favour:\n- Open source\n\nWatch for: Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n\n\n## Score by category\n\n| Category | Weight | Directus | Strapi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 82 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 80 | Directus +1 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 65 | Directus +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 66 | Directus +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 55 | 50 | Directus +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 87 | Strapi +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 72 | Strapi +11 |\n| Negative events | ≤15 | -6 | -6 | |\n| **Total** | | **67.1 · B** | **65.7 · B** | |\n\n## Facts side by side\n\n| Fact | Directus | Strapi |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Monospace Inc. (Directus) | Strapi, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT | MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms |\n| Tools exposed | 12 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-10-07 |\n| Terms last updated | no date given | 2026-10-07 |\n| Privacy policy last updated | 2026-06-09 | 2023-03-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 38k stars, 23k npm/wk | 73k stars, 259k npm/wk |\n\n## Verdicts\n\n**Directus.** The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n**Strapi.** The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n## Before you call either\n\n### Directus\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n### Strapi\n\n1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## Questions\n\n### Which is better for AI agents, Directus or Strapi?\n\nDirectus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust.\n\n### Do Directus and Strapi need an API key?\n\nDirectus takes an API key or an OAuth sign-in. Strapi needs an API key.\n\n### Can an agent call Directus and Strapi without installing anything?\n\nNo hosted endpoint is listed for Directus. No hosted endpoint is listed for Strapi.\n\n### Are Directus and Strapi open source?\n\nNo open-source release is listed for Directus. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/directus-vs-strapi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/directus-vs-strapi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"directus\", \"b\": \"strapi\"}`. From a terminal: `anchor compare directus strapi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/directus.json and https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Other comparisons with Directus or Strapi\n\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [DatoCMS vs Strapi](https://www.anchorterminal.com/compare/datocms-vs-strapi.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md)\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Directus vs Strapi",
        "url": ""
      }
    ],
    "description": "Directus scores 67.1 (B) on agent readiness against Strapi's 65.7 (B), and leads in 4 of 7 scored categories. Strapi leads on transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Directus B 67.1",
      "Strapi B 65.7",
      "scores"
    ],
    "h1": "Directus vs Strapi",
    "image": "https://www.anchorterminal.com/assets/og/compare-directus-vs-strapi.png",
    "path": "/compare/directus-vs-strapi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Directus vs Strapi for AI agents, B 67.1 vs B 65.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 630
  },
  "version": 1
}
