{
  "data": {
    "a": {
      "slug": "ghost",
      "name": "Ghost",
      "vendor": "Ghost Foundation",
      "vendorUrl": "https://ghost.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
      "url": "https://www.anchorterminal.com/tools/ghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
      "repo": "https://github.com/TryGhost/Ghost",
      "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "ghost"
        },
        {
          "registry": "npm",
          "name": "@tryghost/admin-api"
        },
        {
          "registry": "npm",
          "name": "ghost-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
      "pricing": "freemium",
      "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
      "priceSummary": "$18 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 55500,
        "npmWeekly": 23628,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ghost.org/admin-api",
      "llmsTxt": "https://docs.ghost.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "rest",
        "llms-txt",
        "webhooks",
        "newsletter",
        "memberships",
        "nodejs",
        "status-page"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 526,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
        ],
        "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
        "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "strengths": [
          "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
          "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
          "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
          "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
          "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
          "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
          "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
          "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
          "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
        ],
        "agentNotes": [
          "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
          "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
          "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
          "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
          "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 76
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npm install @tryghost/admin-api",
        "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/ghost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Ghost",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and email delivery"
        },
        {
          "item": "Ghost(Pro) Starter",
          "unit": "month",
          "usd": 18,
          "note": "billed yearly, up to 1,000 members, no Admin API"
        },
        {
          "item": "Ghost(Pro) Publisher",
          "unit": "month",
          "usd": 29,
          "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
        },
        {
          "item": "Ghost(Pro) Business",
          "unit": "month",
          "usd": 199,
          "note": "billed yearly, up to 1,000 members, 15 staff users"
        }
      ],
      "provenance": {
        "legalEntity": "Ghost Foundation Ltd",
        "domain": "ghost.org",
        "domainRegistered": "2005-06-25",
        "endpointOnVendorDomain": false,
        "terms": "https://ghost.org/terms/",
        "privacy": "https://ghost.org/privacy/",
        "statusPage": "https://ghoststatus.org",
        "changelog": "https://github.com/TryGhost/Ghost/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
          "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
          "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
          "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
          "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
          "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
      "live": {
        "slug": "ghost",
        "vendorStatus": {
          "page": "https://ghoststatus.org",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:11.990281502Z"
        },
        "pages": [
          {
            "url": "https://ghost.org/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:39.9398284Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de86a225cdd"
          },
          {
            "url": "https://ghost.org/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:42.180060747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "673039b71aa4"
          }
        ],
        "updatedAt": "2026-10-09T09:25:11.990281502Z"
      }
    },
    "answer": "Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "hygraph",
      "name": "Hygraph",
      "vendor": "Hygraph GmbH",
      "vendorUrl": "https://hygraph.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/hygraph",
      "markdownUrl": "https://www.anchorterminal.com/tools/hygraph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hygraph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hygraph.json",
      "repo": "https://github.com/hygraph/management-sdk",
      "license": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.hygraph.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@hygraph/management-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content API and Management API take a Permanent Auth Token as a Bearer header. A person creates the token in Project Settings and sets its content permissions (by model, stage, locale, environment and action) and its Management API permissions. A new token has none enabled. Deleting a token invalidates it, and no expiry or rotation was found. The project MCP endpoint takes the same token. The global MCP endpoint uses a browser login through auth.hygraph.com and follows the user's own permissions. OAuth for third-party apps needs a client ID from Hygraph support. No app review or sales approval is needed for tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Hobby plan is free with no card and includes 500,000 API calls a month, 1,000 entries, 2 locales and 3 API tokens. Usage past the limit is blocked until the next period. Growth is $199 a month with 1,000,000 API calls, and overage of $0.20 per 10,000 API operations and per GB of asset traffic. Enterprise is sold through sales, with a 30-day trial that needs no card (https://hygraph.com/pricing, checked 2026-10-08).",
      "priceSummary": "$199 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 17,
      "popularity": {
        "githubStars": 52,
        "npmWeekly": 8645,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://hygraph.com/docs/api-reference",
      "llmsTxt": "https://hygraph.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.3,
        "grade": "B",
        "agentReady": false,
        "rank": 182,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
        "bestFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "strengths": [
          "Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled",
          "The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction",
          "GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100",
          "The Hobby plan needs no card and includes 500,000 API calls a month, 1,000 entries and 3 API tokens",
          "`llms.txt` links a Markdown copy of every documentation section, and the changelog has dated entries for 30 July, 31 August and 30 September 2026"
        ],
        "weaknesses": [
          "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`",
          "No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field",
          "Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth",
          "No data processing agreement, named sub-processor list, security.txt or disclosure policy was found on hygraph.com. The privacy policy names categories of service provider only",
          "The only official SDK is `@hygraph/management-sdk` for JavaScript and TypeScript, and its public GitHub repository was last pushed on 13 September 2024"
        ],
        "agentNotes": [
          "Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models",
          "Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation",
          "Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429",
          "Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed",
          "Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.3
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 45
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @hygraph/management-sdk",
        "claudeCode": "claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \\\n  --transport http \\\n  --header \"Authorization: Bearer ${HYGRAPH_TOKEN}\"",
        "config": {
          "mcpServers": {
            "hygraph": {
              "args": [
                "mcp-remote",
                "https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/master/mcp",
                "--header",
                "Authorization: Bearer ${HYGRAPH_TOKEN}"
              ],
              "command": "npx",
              "env": {
                "HYGRAPH_TOKEN": "token_here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/hygraph"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 199,
          "note": "10 seats, 1,000,000 API calls and 500 GB of asset traffic included"
        },
        {
          "item": "Additional API operations on Growth",
          "unit": "1k-requests",
          "usd": 0.02,
          "note": "sold as $0.20 per 10,000 API operations"
        },
        {
          "item": "Additional asset traffic on Growth",
          "unit": "gb",
          "usd": 0.2,
          "note": "per GB past the plan's 500 GB"
        }
      ],
      "provenance": {
        "legalEntity": "Hygraph GmbH",
        "domain": "hygraph.com",
        "domainRegistered": "2022-03-04",
        "endpointOnVendorDomain": true,
        "terms": "https://hygraph.com/terms",
        "privacy": "https://hygraph.com/privacy",
        "statusPage": "https://status.hygraph.com",
        "changelog": "https://hygraph.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint and the privacy policy name Hygraph GmbH, Dircksenstraße 47, 10178 Berlin, registered at Amtsgericht Berlin Charlottenburg under HRB 250696 B.",
          "The Terms of Service define the Hygraph Services to include the cloud platform and the Hygraph API. The pricing page lists them as the online terms for Hobby and Growth, with custom terms on Enterprise.",
          "The privacy policy has a section on use of the Hygraph service and was last updated on 19 March 2025. It names categories of service provider and no companies. No data processing agreement was found on hygraph.com.",
          "The Content API answers at \u003cregion\u003e.hygraph.com, the Management API at management.hygraph.com, the MCP server at mcp.hygraph.com and the OAuth server at auth.hygraph.com.",
          "https://hygraph.com/.well-known/security.txt answered 404 on 8 October 2026.",
          "RDAP for hygraph.com gives a registration date of 2022-03-04. The product was named GraphCMS before that, and the older SDK is still on npm as `@graphcms/management`."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hygraph.json",
      "live": {
        "slug": "hygraph",
        "probe": {
          "target": "https://mcp.hygraph.com/mcp",
          "method": "get",
          "lastAt": "2026-10-09T09:26:53.018011399Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 163,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 94,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hygraph.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:14.386503586Z"
        },
        "updatedAt": "2026-10-09T09:26:53.018011399Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ghost Foundation",
        "b": "Hygraph GmbH",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.hygraph.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "b": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "17",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "56k stars, 24k npm/wk",
        "b": "52 stars, 8.6k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Ghost or Hygraph?"
      },
      {
        "answer": "Ghost needs an API key. Hygraph takes an API key or an OAuth sign-in.",
        "question": "Do Ghost and Hygraph need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Ghost. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.",
        "question": "Can an agent call Ghost and Hygraph without installing anything?"
      },
      {
        "answer": "Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). No open-source release is listed for Hygraph.",
        "question": "Are Ghost and Hygraph open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 50 against 35",
          "Maintenance \u0026 community, 85 against 74",
          "Transparency \u0026 trust, 72 against 60"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "slug": "ghost",
        "watchFor": "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 80",
          "Schema \u0026 documentation, 78 against 51",
          "Security \u0026 auth, 63 against 56"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Ghost loses 7 points for them"
        ],
        "goodFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "slug": "hygraph",
        "watchFor": "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph.json",
        "title": "Contentstack vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-ghost.json",
        "title": "DatoCMS vs Ghost",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-hygraph.json",
        "title": "DatoCMS vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-hygraph.json",
        "title": "Directus vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/directus-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-prismic.json",
        "title": "Ghost vs Prismic",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-sanity.json",
        "title": "Hygraph vs Sanity",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok.json",
        "title": "Hygraph vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.json",
        "title": "Hygraph vs Strapi",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-webflow.json",
        "title": "Hygraph vs Webflow",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json",
        "title": "Hygraph vs WordPress",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 9,
        "edge": "hygraph",
        "ghost": 80,
        "hygraph": 89,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 27,
        "edge": "hygraph",
        "ghost": 51,
        "hygraph": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 3,
        "edge": "hygraph",
        "ghost": 69,
        "hygraph": 72,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 7,
        "edge": "hygraph",
        "ghost": 56,
        "hygraph": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 15,
        "edge": "ghost",
        "ghost": 50,
        "hygraph": 35,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "ghost",
        "ghost": 85,
        "hygraph": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 12,
        "edge": "ghost",
        "ghost": 72,
        "hygraph": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "ghost": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
      "hygraph": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ghost-vs-hygraph",
    "json": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.md",
    "slim": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.min.md"
  },
  "markdown": "Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.\n\n- Ghost: grade C, 58.3/100, rank #526 of 842. Markdown https://www.anchorterminal.com/tools/ghost.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost.json\n- Hygraph: grade B, 69.3/100, rank #182 of 842. Markdown https://www.anchorterminal.com/tools/hygraph.md · JSON https://www.anchorterminal.com/api/v1/tools/hygraph.json\n\n## Which one, for what\n\n### Ghost (C)\n\nGood for: A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.\n\nAhead on:\n- Payments \u0026 pricing, 50 against 35\n- Maintenance \u0026 community, 85 against 74\n- Transparency \u0026 trust, 72 against 60\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository\n\n### Hygraph (B)\n\nGood for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.\n\nAhead on:\n- Reliability, 89 against 80\n- Schema \u0026 documentation, 78 against 51\n- Security \u0026 auth, 63 against 56\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Ghost loses 7 points for them\n\nWatch for: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`\n\n\n## Score by category\n\n| Category | Weight | Ghost | Hygraph | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 89 | Hygraph +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 51 | 78 | Hygraph +27 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 72 | Hygraph +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 63 | Hygraph +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 35 | Ghost +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 74 | Ghost +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 60 | Ghost +12 |\n| Negative events | ≤15 | -7 | 0 | |\n| **Total** | | **58.3 · C** | **69.3 · B** | |\n\n## Facts side by side\n\n| Fact | Ghost | Hygraph |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ghost Foundation | Hygraph GmbH |\n| Hosted endpoint | no (local only) | `https://mcp.hygraph.com/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms | Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT |\n| Tools exposed | none | 17 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-30 |\n| Terms last updated | no date given | no date given |\n| Privacy policy last updated | no date given | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 56k stars, 24k npm/wk | 52 stars, 8.6k npm/wk |\n\n## Verdicts\n\n**Ghost.** A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n**Hygraph.** Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.\n\n## Before you call either\n\n### Ghost\n\n1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead\n2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`\n3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists\n4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card\n5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error\n\n### Hygraph\n\n1. Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models\n2. Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation\n3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429\n4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed\n5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back\n\n## Questions\n\n### Which is better for AI agents, Ghost or Hygraph?\n\nHygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Ghost and Hygraph need an API key?\n\nGhost needs an API key. Hygraph takes an API key or an OAuth sign-in.\n\n### Can an agent call Ghost and Hygraph without installing anything?\n\nNo hosted endpoint is listed for Ghost. Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp.\n\n### Are Ghost and Hygraph open source?\n\nGhost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). No open-source release is listed for Hygraph.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ghost-vs-hygraph.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ghost-vs-hygraph.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ghost\", \"b\": \"hygraph\"}`. From a terminal: `anchor compare ghost hygraph`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ghost.json and https://www.anchorterminal.com/api/v1/tools/hygraph.json\n\n## Other comparisons with Ghost or Hygraph\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Hygraph](https://www.anchorterminal.com/compare/contentstack-vs-hygraph.md)\n- [DatoCMS vs Ghost](https://www.anchorterminal.com/compare/datocms-vs-ghost.md)\n- [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Hygraph](https://www.anchorterminal.com/compare/directus-vs-hygraph.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Prismic](https://www.anchorterminal.com/compare/ghost-vs-prismic.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md)\n- [Hygraph vs Storyblok](https://www.anchorterminal.com/compare/hygraph-vs-storyblok.md)\n- [Hygraph vs Strapi](https://www.anchorterminal.com/compare/hygraph-vs-strapi.md)\n- [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md)\n- [Hygraph vs WordPress](https://www.anchorterminal.com/compare/hygraph-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ghost vs Hygraph",
        "url": ""
      }
    ],
    "description": "Hygraph scores 69.3 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ghost C 58.3",
      "Hygraph B 69.3",
      "scores"
    ],
    "h1": "Ghost vs Hygraph",
    "image": "https://www.anchorterminal.com/assets/og/compare-ghost-vs-hygraph.png",
    "path": "/compare/ghost-vs-hygraph",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ghost vs Hygraph for AI agents, C 58.3 vs B 69.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/ghost-vs-hygraph"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
