Head to head · Cms content · October 2026 research run

Ghost vs Hygraph

Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments & pricing, maintenance & community and transparency & trust. Both do cms content.

Which one, for what

Ghost C

Good for A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.

Ahead on

  • Payments & pricing, 50 against 35
  • Maintenance & community, 85 against 74
  • Transparency & trust, 72 against 60

Also in its favour

  • Open source

Watch for

No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository

Hygraph B

Good for Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.

Ahead on

  • Reliability, 89 against 80
  • Schema & documentation, 78 against 51
  • Security & auth, 63 against 56

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where Ghost loses 7 points for them

Watch for

GraphQL error bodies carry a message and a requestId with no machine-readable code, and only asset transformation 429 responses are documented with Retry-After

Score by category

CategoryWeight this runGhostHygraphEdge
Reliability16%208089Hygraph +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25178Hygraph +27
Agent ergonomics13%16.26972Hygraph +3
Security & auth14%17.55663Hygraph +7
Payments & pricing10%12.55035Ghost +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88574Ghost +11
Transparency & trust7%8.87260Ghost +12
Negative events≤15-70
Total58.3 · C69.3 · B

Facts side by side

FactGhostHygraph
KindHTTP APIHTTP API
VendorGhost FoundationHygraph GmbH
Hosted endpointno (local only)https://mcp.hygraph.com/mcp
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's termsProprietary service under Hygraph GmbH's Terms of Service. The @hygraph/management-sdk package is MIT
Tools exposednone17
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-09-30
Terms last updatedno date givenno date given
Privacy policy last updatedno date givenno date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textnot found in the text
Popularity56k stars, 24k npm/wk52 stars, 8.6k npm/wk

Verdicts

Ghost

A create needs only a title, updates are checked against updated_at so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.

Hygraph

Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.

Before you call either

Ghost

  1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set kid to the key id, aud to /admin/ and exp at most 5 minutes ahead
  2. Set status to draft on every create unless told to publish, and publish later with a PUT that sets status to published
  3. GET the post before each PUT and send its updated_at back. Tags and authors in a PUT replace the existing lists
  4. Send content as a Lexical JSON string, or add ?source=html and send html. The HTML conversion is lossy unless wrapped in an HTML card
  5. Page through lists with limit up to 100 and page. Since Ghost 6.0 limit=all returns 100 items without an error

Hygraph

  1. Send the Permanent Auth Token as Authorization: Bearer <token> to https://<region>.hygraph.com/v2/<projectId>/<environment>. Read the schema by introspection first, because every type is generated from the project's models
  2. Mutations write to DRAFT. Call publish<Model> with to: [PUBLISHED] as a separate mutation, and pass locales to write or publish a localisation
  3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429
  4. Upload an asset with createAsset, then POST the file to the returned pre-signed URL, or pass uploadUrl for a remote file. The asset stays ASSET_CREATE_PENDING until processed
  5. Schema changes go to the Management API through @hygraph/management-sdk or the MCP tool submit_batch_migration. Version restore has no documented mutation, so read <model>Version and write the old values back

Questions

Which is better for AI agents, Ghost or Hygraph?

Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments & pricing, maintenance & community and transparency & trust.

Do Ghost and Hygraph need an API key?

Ghost needs an API key. Hygraph takes an API key or an OAuth sign-in.

Can an agent call Ghost and Hygraph without installing anything?

No hosted endpoint is listed for Ghost. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.

Are Ghost and Hygraph open source?

Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). No open-source release is listed for Hygraph.

Other comparisons with Ghost or Hygraph

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.