{
  "data": {
    "a": {
      "slug": "ghost",
      "name": "Ghost",
      "vendor": "Ghost Foundation",
      "vendorUrl": "https://ghost.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API.",
      "url": "https://www.anchorterminal.com/tools/ghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost.json",
      "repo": "https://github.com/TryGhost/Ghost",
      "license": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "ghost"
        },
        {
          "registry": "npm",
          "name": "@tryghost/admin-api"
        },
        {
          "registry": "npm",
          "name": "ghost-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve, with no app review or partner approval. An owner or administrator creates a custom integration in Ghost Admin and copies its Admin API key, an id and a hex secret joined by a colon. The client signs an HS256 JSON Web Token with the secret (`kid` the id, `aud` `/admin/`, expiry at most 5 minutes) and sends it as `Authorization: Ghost \u003ctoken\u003e`. Integrations hold one fixed permission set with no scopes. A staff access token from a user's profile works the same way and carries that user's role. Session login with email and password is meant for clients where the user is present. On Ghost(Pro) the Admin API and custom integrations need the Publisher plan or above.",
      "pricing": "freemium",
      "pricingNotes": "The software is free under MIT to self-host, so an agent's owner can start without a contract or a card. Ghost(Pro) lists Starter at $18, Publisher at $29 and Business at $199 a month billed yearly for up to 1,000 members, rising with audience size, and Custom through sales. The Admin API isn't included in Starter. Plans show a free trial, and we couldn't read whether it needs a card (checked 2026-10-08).",
      "priceSummary": "$18 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing page or the repository's file list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 55500,
        "npmWeekly": 23628,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ghost.org/admin-api",
      "llmsTxt": "https://docs.ghost.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "rest",
        "llms-txt",
        "webhooks",
        "newsletter",
        "memberships",
        "nodejs",
        "status-page"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 455,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "3 September to 1 October 2026. Ghost published 20 security advisories in five weeks, one critical, ten high, eight moderate and one low. They include GHSA-q734-xjgc-vpj9 (critical, suspended staff could reactivate accounts through password reset), GHSA-788w-68h3-cvxp (high, CVSS 8.8, remote code execution through bookmark card images in 6.56.0 to 6.65.0, fixed in 6.67.0) and GHSA-jj74-hc2q-xrvm (high, remote code execution through theme translation files). Several could be triggered by any staff user, Contributors included. All were published by the vendor with a fixed version, and we found no report of exploitation in the advisories we read, so we deduct 7 of a possible 15. https://github.com/TryGhost/Ghost/security/advisories ; https://github.com/TryGhost/Ghost/security/advisories/GHSA-788w-68h3-cvxp"
        ],
        "verdict": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
        "bestFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "strengths": [
          "Admin API keys sign JSON Web Tokens that last at most 5 minutes and travel in the Authorization header, so the key itself is never sent",
          "A staff access token carries its user's role, and a Contributor can add and edit drafts but can't change a post's status",
          "Every PUT must send the post's current `updated_at`, which Ghost uses for collision detection",
          "19 versions reached npm between 10 July and 8 October 2026, with 6.69.0 on 7 October",
          "MIT licence, with llms.txt, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository",
          "A custom integration has one fixed permission set covering posts, members, settings, themes and users, with no scopes and no read-only Admin key",
          "20 advisories were published from 3 September to 1 October 2026, one critical and ten high, including remote code execution through bookmark card images",
          "No content locales or custom content types, and the Admin API has no documented route for restoring a post revision",
          "On Ghost(Pro) the Admin API and custom integrations start at the Publisher plan, not Starter"
        ],
        "agentNotes": [
          "Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead",
          "Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`",
          "GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists",
          "Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card",
          "Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 51,
          "security": 56,
          "transparency": 76
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npm install @tryghost/admin-api",
        "http": "curl -H \"Authorization: Ghost $token\" -H \"Accept-Version: $version\" https://{admin_domain}/ghost/api/admin/{resource}/"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/ghost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Ghost",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and email delivery"
        },
        {
          "item": "Ghost(Pro) Starter",
          "unit": "month",
          "usd": 18,
          "note": "billed yearly, up to 1,000 members, no Admin API"
        },
        {
          "item": "Ghost(Pro) Publisher",
          "unit": "month",
          "usd": 29,
          "note": "billed yearly, up to 1,000 members, 3 staff users, Admin API included"
        },
        {
          "item": "Ghost(Pro) Business",
          "unit": "month",
          "usd": 199,
          "note": "billed yearly, up to 1,000 members, 15 staff users"
        }
      ],
      "provenance": {
        "legalEntity": "Ghost Foundation Ltd",
        "domain": "ghost.org",
        "domainRegistered": "2005-06-25",
        "endpointOnVendorDomain": false,
        "terms": "https://ghost.org/terms/",
        "privacy": "https://ghost.org/privacy/",
        "statusPage": "https://ghoststatus.org",
        "changelog": "https://github.com/TryGhost/Ghost/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms govern the Ghost.org website, the Ghost software and the hosted service, and name the Ghost Foundation as owner and operator under the law of England and Wales. The privacy policy names Ghost Foundation Ltd. Neither page showed a dated revision that we could read.",
          "The privacy policy covers Ghost Foundation's own website and services. Content on a self-hosted site stays on its owner's server and isn't covered by it.",
          "A self-hosted install answers on its owner's domain. Ghost(Pro) sites use a `*.ghost.io` admin domain.",
          "https://ghost.org/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md in the repository and https://docs.ghost.org/security give security@ghost.org and a disclosure policy.",
          "RDAP for ghost.org gives a registration date of 2005-06-25 and a transfer on 2013-09-12.",
          "status.ghost.org redirects to ghoststatus.org, an incident.io page for Ghost(Pro), not for self-hosted installs. It listed three minor incidents between 10 July and 8 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost.json",
      "live": {
        "slug": "ghost",
        "vendorStatus": {
          "page": "https://ghoststatus.org",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:50:43.208632006Z"
        },
        "pages": [
          {
            "url": "https://ghost.org/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:39.9398284Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de86a225cdd"
          },
          {
            "url": "https://ghost.org/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:42.180060747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "673039b71aa4"
          }
        ],
        "updatedAt": "2026-10-08T19:50:43.208632006Z"
      }
    },
    "answer": "Webflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "webflow",
      "name": "Webflow",
      "vendor": "Webflow, Inc.",
      "vendorUrl": "https://webflow.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.",
      "url": "https://www.anchorterminal.com/tools/webflow",
      "markdownUrl": "https://www.anchorterminal.com/tools/webflow.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/webflow.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/webflow.json",
      "repo": "https://github.com/webflow/openapi-spec",
      "license": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.webflow.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "webflow-api"
        },
        {
          "registry": "pypi",
          "name": "webflow"
        },
        {
          "registry": "npm",
          "name": "webflow-mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps \u0026 integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).",
      "priceSummary": "$15 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 85160,
        "pypiWeekly": 121246,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.webflow.com/data/docs",
      "llmsTxt": "https://developers.webflow.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/webflow/openapi-spec/main/openapi/v2.yml",
      "registryName": "com.webflow/mcp",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.schema",
        "cms.localisation"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "closed-source",
        "free-tier",
        "webhooks",
        "typescript",
        "python",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 160,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7)."
        ],
        "verdict": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
        "bestFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "strengths": [
          "Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page",
          "OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens",
          "CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call",
          "429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically",
          "Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page"
        ],
        "weaknesses": [
          "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions",
          "No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute",
          "The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales",
          "The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise",
          "On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes",
          "Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes",
          "Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429",
          "Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms",
          "Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 65
        },
        "provenanceScore": 97
      },
      "connect": {
        "install": "npm install webflow-api",
        "http": "curl --request GET \\\n  --url https://api.webflow.com/v2/sites \\\n  --header 'accept: application/json' \\\n  --header 'authorization: Bearer YOUR_API_TOKEN'",
        "claudeCode": "claude mcp add --transport http webflow https://mcp.webflow.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/webflow"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Basic site plan",
          "unit": "month",
          "usd": 15,
          "note": "billed yearly, per site, no CMS"
        },
        {
          "item": "Premium site plan",
          "unit": "month",
          "usd": 25,
          "note": "billed yearly, per site, 20,000 CMS items and 120 requests a minute"
        },
        {
          "item": "Team platform plan",
          "unit": "month",
          "usd": 2500,
          "note": "annual contract, 5 full and 5 limited seats included"
        }
      ],
      "provenance": {
        "legalEntity": "Webflow, Inc.",
        "domain": "webflow.com",
        "domainRegistered": "2003-03-31",
        "endpointOnVendorDomain": true,
        "terms": "https://webflow.com/legal/terms",
        "privacy": "https://webflow.com/legal/privacy",
        "statusPage": "https://status.webflow.com",
        "changelog": "https://developers.webflow.com/home/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.",
          "The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.",
          "The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.",
          "The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.",
          "webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.",
          "RDAP for webflow.com gives a registration date of 2003-03-31.",
          "status.webflow.com runs on Statuspage with components for the Data API and the MCP server."
        ],
        "score": 97
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/webflow.json",
      "live": {
        "slug": "webflow",
        "probe": {
          "target": "https://api.webflow.com/v2",
          "method": "get",
          "lastAt": "2026-10-08T19:53:06.461420599Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 256,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 268,
          "p95ms24h": 436,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.webflow.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:07.839303426Z"
        },
        "pages": [
          {
            "url": "https://developers.webflow.com/home/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:03.444775017Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "26398a0d385c"
          },
          {
            "url": "https://webflow.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:48.086194416Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1895a791460c"
          },
          {
            "url": "https://webflow.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:43.849393456Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1dc949e66fd3"
          },
          {
            "url": "https://webflow.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:46.083572378Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fab4ea21138a"
          }
        ],
        "updatedAt": "2026-10-08T19:53:06.461420599Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ghost Foundation",
        "b": "Webflow, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.webflow.com/v2",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms",
        "b": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "34",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.webflow/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2023-11-15",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2025-03-17",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "56k stars, 24k npm/wk",
        "b": "85k npm/wk, 121k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Webflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Ghost or Webflow?"
      },
      {
        "answer": "Ghost needs an API key. Webflow takes an API key or an OAuth sign-in.",
        "question": "Do Ghost and Webflow need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Ghost. Webflow has a hosted endpoint at https://api.webflow.com/v2.",
        "question": "Can an agent call Ghost and Webflow without installing anything?"
      },
      {
        "answer": "Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). No open-source release is listed for Webflow.",
        "question": "Are Ghost and Webflow open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 50 against 30",
          "Maintenance \u0026 community, 85 against 80"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.",
        "slug": "ghost",
        "watchFor": "No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 51",
          "Security \u0026 auth, 74 against 56",
          "Transparency \u0026 trust, 81 against 72"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "slug": "webflow",
        "watchFor": "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-ghost.json",
        "title": "DatoCMS vs Ghost",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-webflow.json",
        "title": "DatoCMS vs Webflow",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-webflow.json",
        "title": "Sanity vs Webflow",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-webflow.json",
        "title": "Storyblok vs Webflow",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "ghost",
        "ghost": 80,
        "key": "reliability",
        "name": "Reliability",
        "webflow": 79,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 36,
        "edge": "webflow",
        "ghost": 51,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "webflow": 87,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "webflow",
        "ghost": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "webflow": 72,
        "weight": 13
      },
      {
        "by": 18,
        "edge": "webflow",
        "ghost": 56,
        "key": "security",
        "name": "Security \u0026 auth",
        "webflow": 74,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "ghost",
        "ghost": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "webflow": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "ghost",
        "ghost": 85,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "webflow": 80,
        "weight": 7
      },
      {
        "by": 9,
        "edge": "webflow",
        "ghost": 72,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "webflow": 81,
        "weight": 7
      }
    ],
    "summary": "Webflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community. Both do cms content.",
    "verdicts": {
      "ghost": "A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.",
      "webflow": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ghost-vs-webflow",
    "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ghost-vs-webflow.md",
    "slim": "https://www.anchorterminal.com/compare/ghost-vs-webflow.min.md"
  },
  "markdown": "Webflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community. Both do cms content.\n\n- Ghost: grade C, 58.3/100, rank #455 of 722. Markdown https://www.anchorterminal.com/tools/ghost.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost.json\n- Webflow: grade B, 69.4/100, rank #160 of 722. Markdown https://www.anchorterminal.com/tools/webflow.md · JSON https://www.anchorterminal.com/api/v1/tools/webflow.json\n\n## Which one, for what\n\n### Ghost (C)\n\nGood for: A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.\n\nAhead on:\n- Payments \u0026 pricing, 50 against 30\n- Maintenance \u0026 community, 85 against 80\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository\n\n### Webflow (B)\n\nGood for: Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 51\n- Security \u0026 auth, 74 against 56\n- Transparency \u0026 trust, 81 against 72\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions\n\n\n## Score by category\n\n| Category | Weight | Ghost | Webflow | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 79 | Ghost +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 51 | 87 | Webflow +36 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 72 | Webflow +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 74 | Webflow +18 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 30 | Ghost +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 80 | Ghost +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 81 | Webflow +9 |\n| Negative events | ≤15 | -7 | -3 | |\n| **Total** | | **58.3 · C** | **69.4 · B** | |\n\n## Facts side by side\n\n| Fact | Ghost | Webflow |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ghost Foundation | Webflow, Inc. |\n| Hosted endpoint | no (local only) | `https://api.webflow.com/v2` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms | Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT |\n| Tools exposed | none | 34 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.webflow/mcp` |\n| Last release | 2026-10-07 | 2026-10-07 |\n| Terms last updated | no date given | 2023-11-15 |\n| Privacy policy last updated | no date given | 2025-03-17 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 56k stars, 24k npm/wk | 85k npm/wk, 121k PyPI/wk |\n\n## Verdicts\n\n**Ghost.** A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.\n\n**Webflow.** The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.\n\n## Before you call either\n\n### Ghost\n\n1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead\n2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published`\n3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists\n4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card\n5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error\n\n### Webflow\n\n1. Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes\n2. Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes\n3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429\n4. Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms\n5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`\n\n## Questions\n\n### Which is better for AI agents, Ghost or Webflow?\n\nWebflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Ghost and Webflow need an API key?\n\nGhost needs an API key. Webflow takes an API key or an OAuth sign-in.\n\n### Can an agent call Ghost and Webflow without installing anything?\n\nNo hosted endpoint is listed for Ghost. Webflow has a hosted endpoint at https://api.webflow.com/v2.\n\n### Are Ghost and Webflow open source?\n\nGhost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). No open-source release is listed for Webflow.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ghost-vs-webflow.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ghost-vs-webflow.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ghost\", \"b\": \"webflow\"}`. From a terminal: `anchor compare ghost webflow`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ghost.json and https://www.anchorterminal.com/api/v1/tools/webflow.json\n\n## Other comparisons with Ghost or Webflow\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [DatoCMS vs Ghost](https://www.anchorterminal.com/compare/datocms-vs-ghost.md)\n- [DatoCMS vs Webflow](https://www.anchorterminal.com/compare/datocms-vs-webflow.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md)\n- [Storyblok vs Webflow](https://www.anchorterminal.com/compare/storyblok-vs-webflow.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ghost vs Webflow",
        "url": ""
      }
    ],
    "description": "Webflow scores 69.4 (B) on agent readiness against Ghost's 58.3 (C), and leads in 4 of 7 scored categories. Ghost leads on payments \u0026 pricing and maintenance \u0026 community. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ghost C 58.3",
      "Webflow B 69.4",
      "scores"
    ],
    "h1": "Ghost vs Webflow",
    "image": "https://www.anchorterminal.com/assets/og/compare-ghost-vs-webflow.png",
    "path": "/compare/ghost-vs-webflow",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ghost vs Webflow for AI agents, C 58.3 vs B 69.4 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 680
  },
  "version": 1
}
