{
  "data": {
    "a": {
      "slug": "hygraph",
      "name": "Hygraph",
      "vendor": "Hygraph GmbH",
      "vendorUrl": "https://hygraph.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/hygraph",
      "markdownUrl": "https://www.anchorterminal.com/tools/hygraph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hygraph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hygraph.json",
      "repo": "https://github.com/hygraph/management-sdk",
      "license": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.hygraph.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@hygraph/management-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content API and Management API take a Permanent Auth Token as a Bearer header. A person creates the token in Project Settings and sets its content permissions (by model, stage, locale, environment and action) and its Management API permissions. A new token has none enabled. Deleting a token invalidates it, and no expiry or rotation was found. The project MCP endpoint takes the same token. The global MCP endpoint uses a browser login through auth.hygraph.com and follows the user's own permissions. OAuth for third-party apps needs a client ID from Hygraph support. No app review or sales approval is needed for tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Hobby plan is free with no card and includes 500,000 API calls a month, 1,000 entries, 2 locales and 3 API tokens. Usage past the limit is blocked until the next period. Growth is $199 a month with 1,000,000 API calls, and overage of $0.20 per 10,000 API operations and per GB of asset traffic. Enterprise is sold through sales, with a 30-day trial that needs no card (https://hygraph.com/pricing, checked 2026-10-08).",
      "priceSummary": "$199 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 17,
      "popularity": {
        "githubStars": 52,
        "npmWeekly": 8645,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://hygraph.com/docs/api-reference",
      "llmsTxt": "https://hygraph.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.3,
        "grade": "B",
        "agentReady": false,
        "rank": 182,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
        "bestFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "strengths": [
          "Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled",
          "The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction",
          "GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100",
          "The Hobby plan needs no card and includes 500,000 API calls a month, 1,000 entries and 3 API tokens",
          "`llms.txt` links a Markdown copy of every documentation section, and the changelog has dated entries for 30 July, 31 August and 30 September 2026"
        ],
        "weaknesses": [
          "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`",
          "No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field",
          "Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth",
          "No data processing agreement, named sub-processor list, security.txt or disclosure policy was found on hygraph.com. The privacy policy names categories of service provider only",
          "The only official SDK is `@hygraph/management-sdk` for JavaScript and TypeScript, and its public GitHub repository was last pushed on 13 September 2024"
        ],
        "agentNotes": [
          "Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models",
          "Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation",
          "Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429",
          "Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed",
          "Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.3
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 45
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @hygraph/management-sdk",
        "claudeCode": "claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \\\n  --transport http \\\n  --header \"Authorization: Bearer ${HYGRAPH_TOKEN}\"",
        "config": {
          "mcpServers": {
            "hygraph": {
              "args": [
                "mcp-remote",
                "https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/master/mcp",
                "--header",
                "Authorization: Bearer ${HYGRAPH_TOKEN}"
              ],
              "command": "npx",
              "env": {
                "HYGRAPH_TOKEN": "token_here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/hygraph"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 199,
          "note": "10 seats, 1,000,000 API calls and 500 GB of asset traffic included"
        },
        {
          "item": "Additional API operations on Growth",
          "unit": "1k-requests",
          "usd": 0.02,
          "note": "sold as $0.20 per 10,000 API operations"
        },
        {
          "item": "Additional asset traffic on Growth",
          "unit": "gb",
          "usd": 0.2,
          "note": "per GB past the plan's 500 GB"
        }
      ],
      "provenance": {
        "legalEntity": "Hygraph GmbH",
        "domain": "hygraph.com",
        "domainRegistered": "2022-03-04",
        "endpointOnVendorDomain": true,
        "terms": "https://hygraph.com/terms",
        "privacy": "https://hygraph.com/privacy",
        "statusPage": "https://status.hygraph.com",
        "changelog": "https://hygraph.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint and the privacy policy name Hygraph GmbH, Dircksenstraße 47, 10178 Berlin, registered at Amtsgericht Berlin Charlottenburg under HRB 250696 B.",
          "The Terms of Service define the Hygraph Services to include the cloud platform and the Hygraph API. The pricing page lists them as the online terms for Hobby and Growth, with custom terms on Enterprise.",
          "The privacy policy has a section on use of the Hygraph service and was last updated on 19 March 2025. It names categories of service provider and no companies. No data processing agreement was found on hygraph.com.",
          "The Content API answers at \u003cregion\u003e.hygraph.com, the Management API at management.hygraph.com, the MCP server at mcp.hygraph.com and the OAuth server at auth.hygraph.com.",
          "https://hygraph.com/.well-known/security.txt answered 404 on 8 October 2026.",
          "RDAP for hygraph.com gives a registration date of 2022-03-04. The product was named GraphCMS before that, and the older SDK is still on npm as `@graphcms/management`."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hygraph.json",
      "live": {
        "slug": "hygraph",
        "probe": {
          "target": "https://mcp.hygraph.com/mcp",
          "method": "get",
          "lastAt": "2026-10-09T09:26:53.018011399Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 163,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 94,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hygraph.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:14.386503586Z"
        },
        "updatedAt": "2026-10-09T09:26:53.018011399Z"
      }
    },
    "answer": "Hygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "strapi",
      "name": "Strapi",
      "vendor": "Strapi, Inc.",
      "vendorUrl": "https://strapi.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/strapi",
      "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
      "repo": "https://github.com/strapi/strapi",
      "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@strapi/strapi"
        },
        {
          "registry": "npm",
          "name": "@strapi/client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
      "priceSummary": "$45 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 73289,
        "npmWeekly": 258813,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.strapi.io",
      "llmsTxt": "https://docs.strapi.io/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "llms-txt",
        "webhooks",
        "graphql",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.7,
        "grade": "B",
        "agentReady": false,
        "rank": 285,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -6,
        "negativeNotes": [
          "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
        ],
        "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
        "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "strengths": [
          "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
          "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
          "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
          "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
          "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
          "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
          "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
          "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
          "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
        ],
        "agentNotes": [
          "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
          "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
          "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
          "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
          "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 75
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx create-strapi@latest",
        "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
        "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
        "config": {
          "mcpServers": {
            "strapi-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_ADMIN_TOKEN"
              },
              "type": "streamable-http",
              "url": "http://localhost:1337/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/strapi"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT, unlimited seats, you pay for your own hosting"
        },
        {
          "item": "Growth, self-hosted",
          "unit": "month",
          "usd": 45,
          "note": "3 seats included, $15 per extra seat"
        },
        {
          "item": "Strapi Cloud Starter",
          "unit": "month",
          "usd": 35,
          "note": "per project, 100,000 API requests"
        },
        {
          "item": "Strapi Cloud Pro",
          "unit": "month",
          "usd": 90,
          "note": "per project, 1 million API requests"
        },
        {
          "item": "Strapi Cloud Business",
          "unit": "month",
          "usd": 450,
          "note": "per project, 10 million API requests"
        },
        {
          "item": "Strapi Cloud API requests over the plan",
          "unit": "1k-requests",
          "usd": 0.06,
          "note": "$1.50 per 25,000"
        }
      ],
      "provenance": {
        "legalEntity": "Strapi, Inc.",
        "domain": "strapi.io",
        "domainRegistered": "2015-09-21",
        "endpointOnVendorDomain": false,
        "terms": "https://strapi.io/cloud-legal",
        "privacy": "https://strapi.io/privacy",
        "statusPage": "https://status.strapi.io",
        "changelog": "https://github.com/strapi/strapi/releases",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
          "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
          "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
          "RDAP for strapi.io gives a registration date of 2015-09-21.",
          "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
      "live": {
        "slug": "strapi",
        "vendorStatus": {
          "page": "https://status.strapi.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:33.871380671Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "strapi/strapi",
            "version": "v5.57.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:30:39.413193839Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/client",
            "version": "1.6.2",
            "seenAt": "2026-10-08T16:30:37.897146773Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/strapi",
            "version": "5.57.0",
            "seenAt": "2026-10-08T16:30:37.072939352Z"
          }
        ],
        "githubStars": 73292,
        "npmWeekly": 258813,
        "securityTxt": {
          "url": "https://strapi.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:07.890617672Z"
        },
        "pages": [
          {
            "url": "https://strapi.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:54.221268289Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9a83a678305b"
          },
          {
            "url": "https://strapi.io/cloud-legal",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:51.925906428Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e789fbc0c6c8"
          }
        ],
        "updatedAt": "2026-10-09T07:58:33.871380671Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Hygraph GmbH",
        "b": "Strapi, Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.hygraph.com/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
        "b": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
        "name": "Licence"
      },
      {
        "a": "17",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2026-10-07",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2023-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "52 stars, 8.6k npm/wk",
        "b": "73k stars, 259k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Hygraph or Strapi?"
      },
      {
        "answer": "Hygraph takes an API key or an OAuth sign-in. Strapi needs an API key.",
        "question": "Do Hygraph and Strapi need an API key?"
      },
      {
        "answer": "Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Strapi.",
        "question": "Can an agent call Hygraph and Strapi without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Hygraph. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).",
        "question": "Are Hygraph and Strapi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 82",
          "Agent ergonomics, 72 against 65"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Strapi loses 6 points for them"
        ],
        "goodFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "slug": "hygraph",
        "watchFor": "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 50 against 35",
          "Maintenance \u0026 community, 87 against 74",
          "Transparency \u0026 trust, 72 against 60"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "slug": "strapi",
        "watchFor": "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph.json",
        "title": "Contentstack vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-hygraph.json",
        "title": "DatoCMS vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-strapi.json",
        "title": "DatoCMS vs Strapi",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-hygraph.json",
        "title": "Directus vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/directus-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.json",
        "title": "Ghost vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-sanity.json",
        "title": "Hygraph vs Sanity",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok.json",
        "title": "Hygraph vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-webflow.json",
        "title": "Hygraph vs Webflow",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json",
        "title": "Hygraph vs WordPress",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-strapi.json",
        "title": "Prismic vs Strapi",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-strapi.json",
        "title": "Sanity vs Strapi",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-strapi.json",
        "title": "Storyblok vs Strapi",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 7,
        "edge": "hygraph",
        "hygraph": 89,
        "key": "reliability",
        "name": "Reliability",
        "strapi": 82,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "strapi",
        "hygraph": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "strapi": 80,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "hygraph",
        "hygraph": 72,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "strapi": 65,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "strapi",
        "hygraph": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "strapi": 66,
        "weight": 14
      },
      {
        "by": 15,
        "edge": "strapi",
        "hygraph": 35,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "strapi": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "strapi",
        "hygraph": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "strapi": 87,
        "weight": 7
      },
      {
        "by": 12,
        "edge": "strapi",
        "hygraph": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "strapi": 72,
        "weight": 7
      }
    ],
    "summary": "Hygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "hygraph": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
      "strapi": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hygraph-vs-strapi",
    "json": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.md",
    "slim": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.min.md"
  },
  "markdown": "Hygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.\n\n- Hygraph: grade B, 69.3/100, rank #182 of 842. Markdown https://www.anchorterminal.com/tools/hygraph.md · JSON https://www.anchorterminal.com/api/v1/tools/hygraph.json\n- Strapi: grade B, 65.7/100, rank #285 of 842. Markdown https://www.anchorterminal.com/tools/strapi.md · JSON https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Which one, for what\n\n### Hygraph (B)\n\nGood for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.\n\nAhead on:\n- Reliability, 89 against 82\n- Agent ergonomics, 72 against 65\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Strapi loses 6 points for them\n\nWatch for: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`\n\n### Strapi (B)\n\nGood for: Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.\n\nAhead on:\n- Payments \u0026 pricing, 50 against 35\n- Maintenance \u0026 community, 87 against 74\n- Transparency \u0026 trust, 72 against 60\n\nAlso in its favour:\n- Open source\n\nWatch for: Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n\n\n## Score by category\n\n| Category | Weight | Hygraph | Strapi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 82 | Hygraph +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 80 | Strapi +2 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 65 | Hygraph +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 66 | Strapi +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 50 | Strapi +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 87 | Strapi +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 72 | Strapi +12 |\n| Negative events | ≤15 | 0 | -6 | |\n| **Total** | | **69.3 · B** | **65.7 · B** | |\n\n## Facts side by side\n\n| Fact | Hygraph | Strapi |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Hygraph GmbH | Strapi, Inc. |\n| Hosted endpoint | `https://mcp.hygraph.com/mcp` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT | MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms |\n| Tools exposed | 17 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-10-07 |\n| Terms last updated | no date given | 2026-10-07 |\n| Privacy policy last updated | no date given | 2023-03-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 52 stars, 8.6k npm/wk | 73k stars, 259k npm/wk |\n\n## Verdicts\n\n**Hygraph.** Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.\n\n**Strapi.** The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n## Before you call either\n\n### Hygraph\n\n1. Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models\n2. Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation\n3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429\n4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed\n5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back\n\n### Strapi\n\n1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## Questions\n\n### Which is better for AI agents, Hygraph or Strapi?\n\nHygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Hygraph and Strapi need an API key?\n\nHygraph takes an API key or an OAuth sign-in. Strapi needs an API key.\n\n### Can an agent call Hygraph and Strapi without installing anything?\n\nHygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Strapi.\n\n### Are Hygraph and Strapi open source?\n\nNo open-source release is listed for Hygraph. Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hygraph-vs-strapi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hygraph-vs-strapi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hygraph\", \"b\": \"strapi\"}`. From a terminal: `anchor compare hygraph strapi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hygraph.json and https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Other comparisons with Hygraph or Strapi\n\n- [Contentstack vs Hygraph](https://www.anchorterminal.com/compare/contentstack-vs-hygraph.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md)\n- [DatoCMS vs Strapi](https://www.anchorterminal.com/compare/datocms-vs-strapi.md)\n- [Directus vs Hygraph](https://www.anchorterminal.com/compare/directus-vs-hygraph.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Ghost vs Hygraph](https://www.anchorterminal.com/compare/ghost-vs-hygraph.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md)\n- [Hygraph vs Storyblok](https://www.anchorterminal.com/compare/hygraph-vs-storyblok.md)\n- [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md)\n- [Hygraph vs WordPress](https://www.anchorterminal.com/compare/hygraph-vs-wordpress.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Prismic vs Strapi](https://www.anchorterminal.com/compare/prismic-vs-strapi.md)\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md)\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Hygraph vs Strapi",
        "url": ""
      }
    ],
    "description": "Hygraph scores 69.3 (B) on agent readiness against Strapi's 65.7 (B), and leads in 2 of 7 scored categories. Strapi leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Hygraph B 69.3",
      "Strapi B 65.7",
      "scores"
    ],
    "h1": "Hygraph vs Strapi",
    "image": "https://www.anchorterminal.com/assets/og/compare-hygraph-vs-strapi.png",
    "path": "/compare/hygraph-vs-strapi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Hygraph vs Strapi for AI agents, B 69.3 vs B 65.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/hygraph-vs-strapi"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
