{
  "data": {
    "a": {
      "slug": "hygraph",
      "name": "Hygraph",
      "vendor": "Hygraph GmbH",
      "vendorUrl": "https://hygraph.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/hygraph",
      "markdownUrl": "https://www.anchorterminal.com/tools/hygraph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hygraph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hygraph.json",
      "repo": "https://github.com/hygraph/management-sdk",
      "license": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.hygraph.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@hygraph/management-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content API and Management API take a Permanent Auth Token as a Bearer header. A person creates the token in Project Settings and sets its content permissions (by model, stage, locale, environment and action) and its Management API permissions. A new token has none enabled. Deleting a token invalidates it, and no expiry or rotation was found. The project MCP endpoint takes the same token. The global MCP endpoint uses a browser login through auth.hygraph.com and follows the user's own permissions. OAuth for third-party apps needs a client ID from Hygraph support. No app review or sales approval is needed for tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Hobby plan is free with no card and includes 500,000 API calls a month, 1,000 entries, 2 locales and 3 API tokens. Usage past the limit is blocked until the next period. Growth is $199 a month with 1,000,000 API calls, and overage of $0.20 per 10,000 API operations and per GB of asset traffic. Enterprise is sold through sales, with a 30-day trial that needs no card (https://hygraph.com/pricing, checked 2026-10-08).",
      "priceSummary": "$199 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 17,
      "popularity": {
        "githubStars": 52,
        "npmWeekly": 8645,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://hygraph.com/docs/api-reference",
      "llmsTxt": "https://hygraph.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.3,
        "grade": "B",
        "agentReady": false,
        "rank": 182,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
        "bestFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "strengths": [
          "Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled",
          "The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction",
          "GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100",
          "The Hobby plan needs no card and includes 500,000 API calls a month, 1,000 entries and 3 API tokens",
          "`llms.txt` links a Markdown copy of every documentation section, and the changelog has dated entries for 30 July, 31 August and 30 September 2026"
        ],
        "weaknesses": [
          "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`",
          "No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field",
          "Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth",
          "No data processing agreement, named sub-processor list, security.txt or disclosure policy was found on hygraph.com. The privacy policy names categories of service provider only",
          "The only official SDK is `@hygraph/management-sdk` for JavaScript and TypeScript, and its public GitHub repository was last pushed on 13 September 2024"
        ],
        "agentNotes": [
          "Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models",
          "Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation",
          "Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429",
          "Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed",
          "Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.3
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 45
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @hygraph/management-sdk",
        "claudeCode": "claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \\\n  --transport http \\\n  --header \"Authorization: Bearer ${HYGRAPH_TOKEN}\"",
        "config": {
          "mcpServers": {
            "hygraph": {
              "args": [
                "mcp-remote",
                "https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/master/mcp",
                "--header",
                "Authorization: Bearer ${HYGRAPH_TOKEN}"
              ],
              "command": "npx",
              "env": {
                "HYGRAPH_TOKEN": "token_here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/hygraph"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 199,
          "note": "10 seats, 1,000,000 API calls and 500 GB of asset traffic included"
        },
        {
          "item": "Additional API operations on Growth",
          "unit": "1k-requests",
          "usd": 0.02,
          "note": "sold as $0.20 per 10,000 API operations"
        },
        {
          "item": "Additional asset traffic on Growth",
          "unit": "gb",
          "usd": 0.2,
          "note": "per GB past the plan's 500 GB"
        }
      ],
      "provenance": {
        "legalEntity": "Hygraph GmbH",
        "domain": "hygraph.com",
        "domainRegistered": "2022-03-04",
        "endpointOnVendorDomain": true,
        "terms": "https://hygraph.com/terms",
        "privacy": "https://hygraph.com/privacy",
        "statusPage": "https://status.hygraph.com",
        "changelog": "https://hygraph.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint and the privacy policy name Hygraph GmbH, Dircksenstraße 47, 10178 Berlin, registered at Amtsgericht Berlin Charlottenburg under HRB 250696 B.",
          "The Terms of Service define the Hygraph Services to include the cloud platform and the Hygraph API. The pricing page lists them as the online terms for Hobby and Growth, with custom terms on Enterprise.",
          "The privacy policy has a section on use of the Hygraph service and was last updated on 19 March 2025. It names categories of service provider and no companies. No data processing agreement was found on hygraph.com.",
          "The Content API answers at \u003cregion\u003e.hygraph.com, the Management API at management.hygraph.com, the MCP server at mcp.hygraph.com and the OAuth server at auth.hygraph.com.",
          "https://hygraph.com/.well-known/security.txt answered 404 on 8 October 2026.",
          "RDAP for hygraph.com gives a registration date of 2022-03-04. The product was named GraphCMS before that, and the older SDK is still on npm as `@graphcms/management`."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hygraph.json",
      "live": {
        "slug": "hygraph",
        "probe": {
          "target": "https://mcp.hygraph.com/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:14:17.145306856Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 161,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 161,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hygraph.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:11:00.581074358Z"
        },
        "updatedAt": "2026-10-09T10:14:17.145306856Z"
      }
    },
    "answer": "Hygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "wordpress",
      "name": "WordPress",
      "vendor": "WordPress.org (open-source project)",
      "vendorUrl": "https://wordpress.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
      "url": "https://www.anchorterminal.com/tools/wordpress",
      "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
      "repo": "https://github.com/WordPress/wordpress-develop",
      "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 21460,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.wordpress.org/rest-api/",
      "llmsTxt": "https://wordpress.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "rest",
        "mcp",
        "cli",
        "php",
        "llms-txt",
        "security-txt",
        "bug-bounty"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 310,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
        ],
        "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
        "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "strengths": [
          "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
          "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
          "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
          "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
          "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
        ],
        "weaknesses": [
          "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
          "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
          "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
          "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
          "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
        ],
        "agentNotes": [
          "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
          "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
          "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
          "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
          "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 72
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
        "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
        "config": {
          "mcpServers": {
            "wordpress": {
              "args": [
                "--path=/path/to/your/wordpress/site",
                "mcp-adapter",
                "serve",
                "--server=mcp-adapter-default-server",
                "--user=admin"
              ],
              "command": "wp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/wordpress"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WordPress, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
        "domain": "wordpress.org",
        "domainRegistered": "2003-03-28",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://wordpress.org/about/privacy/",
        "statusPage": "",
        "changelog": "https://wordpress.org/news/category/releases/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
          "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
          "The REST API answers on each owner's own domain.",
          "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
          "RDAP for wordpress.org gives a registration date of 2003-03-28.",
          "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
          "No status page applies to self-hosted software."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json",
      "live": {
        "slug": "wordpress",
        "pages": [
          {
            "url": "https://wordpress.org/news/category/releases/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.505193763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cbd71d93d029"
          },
          {
            "url": "https://wordpress.org/about/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.079319583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61575a1b129f"
          }
        ],
        "updatedAt": "2026-10-08T18:25:52.505193763Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Hygraph GmbH",
        "b": "WordPress.org (open-source project)",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.hygraph.com/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
        "b": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "name": "Licence"
      },
      {
        "a": "17",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "52 stars, 8.6k npm/wk",
        "b": "21k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Hygraph or WordPress?"
      },
      {
        "answer": "Hygraph takes an API key or an OAuth sign-in. WordPress needs an API key.",
        "question": "Do Hygraph and WordPress need an API key?"
      },
      {
        "answer": "Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. WordPress runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Hygraph and WordPress without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Hygraph. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).",
        "question": "Are Hygraph and WordPress open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 78",
          "Schema \u0026 documentation, 78 against 65"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where WordPress loses 5 points for them"
        ],
        "goodFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "slug": "hygraph",
        "watchFor": "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 60 against 35",
          "Maintenance \u0026 community, 83 against 74",
          "Transparency \u0026 trust, 68 against 60"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "slug": "wordpress",
        "watchFor": "Application Passwords have no scopes or expiry. Each one carries every capability of its user"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph.json",
        "title": "Contentstack vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-hygraph.json",
        "title": "DatoCMS vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-wordpress.json",
        "title": "DatoCMS vs WordPress",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-hygraph.json",
        "title": "Directus vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/directus-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.json",
        "title": "Ghost vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-sanity.json",
        "title": "Hygraph vs Sanity",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok.json",
        "title": "Hygraph vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.json",
        "title": "Hygraph vs Strapi",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-webflow.json",
        "title": "Hygraph vs Webflow",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-wordpress.json",
        "title": "Prismic vs WordPress",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 11,
        "edge": "hygraph",
        "hygraph": 89,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "wordpress": 78
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "hygraph",
        "hygraph": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "wordpress": 65
      },
      {
        "by": 2,
        "edge": "wordpress",
        "hygraph": 72,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "wordpress": 74
      },
      {
        "by": 1,
        "edge": "hygraph",
        "hygraph": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "wordpress": 62
      },
      {
        "by": 25,
        "edge": "wordpress",
        "hygraph": 35,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "wordpress": 60
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "wordpress",
        "hygraph": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "wordpress": 83
      },
      {
        "by": 8,
        "edge": "wordpress",
        "hygraph": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "wordpress": 68
      }
    ],
    "summary": "Hygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.",
    "verdicts": {
      "hygraph": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
      "wordpress": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress",
    "json": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.md",
    "slim": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.min.md"
  },
  "markdown": "Hygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content.\n\n- Hygraph: grade B, 69.3/100, rank #182 of 842. Markdown https://www.anchorterminal.com/tools/hygraph.md · JSON https://www.anchorterminal.com/api/v1/tools/hygraph.json\n- WordPress: grade B, 64.8/100, rank #310 of 842. Markdown https://www.anchorterminal.com/tools/wordpress.md · JSON https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Which one, for what\n\n### Hygraph (B)\n\nGood for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.\n\nAhead on:\n- Reliability, 89 against 78\n- Schema \u0026 documentation, 78 against 65\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where WordPress loses 5 points for them\n\nWatch for: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`\n\n### WordPress (B)\n\nGood for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.\n\nAhead on:\n- Payments \u0026 pricing, 60 against 35\n- Maintenance \u0026 community, 83 against 74\n- Transparency \u0026 trust, 68 against 60\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: Application Passwords have no scopes or expiry. Each one carries every capability of its user\n\n\n## Score by category\n\n| Category | Weight | Hygraph | WordPress | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 78 | Hygraph +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 65 | Hygraph +13 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 74 | WordPress +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 62 | Hygraph +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 60 | WordPress +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 83 | WordPress +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 68 | WordPress +8 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **69.3 · B** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Hygraph | WordPress |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Hygraph GmbH | WordPress.org (open-source project) |\n| Hosted endpoint | `https://mcp.hygraph.com/mcp` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, stdio |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |\n| Tools exposed | 17 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-10-06 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | no date given |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 52 stars, 8.6k npm/wk | 21k stars |\n\n## Verdicts\n\n**Hygraph.** Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.\n\n**WordPress.** The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n## Before you call either\n\n### Hygraph\n\n1. Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models\n2. Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation\n3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429\n4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed\n5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back\n\n### WordPress\n\n1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them\n2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment\n3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content\n4. To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route\n5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100\n\n## Questions\n\n### Which is better for AI agents, Hygraph or WordPress?\n\nHygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Hygraph and WordPress need an API key?\n\nHygraph takes an API key or an OAuth sign-in. WordPress needs an API key.\n\n### Can an agent call Hygraph and WordPress without installing anything?\n\nHygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. WordPress runs on your own machine, with no hosted endpoint listed.\n\n### Are Hygraph and WordPress open source?\n\nNo open-source release is listed for Hygraph. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hygraph-vs-wordpress.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hygraph\", \"b\": \"wordpress\"}`. From a terminal: `anchor compare hygraph wordpress`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hygraph.json and https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Other comparisons with Hygraph or WordPress\n\n- [Contentstack vs Hygraph](https://www.anchorterminal.com/compare/contentstack-vs-hygraph.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md)\n- [DatoCMS vs WordPress](https://www.anchorterminal.com/compare/datocms-vs-wordpress.md)\n- [Directus vs Hygraph](https://www.anchorterminal.com/compare/directus-vs-hygraph.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Hygraph](https://www.anchorterminal.com/compare/ghost-vs-hygraph.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md)\n- [Hygraph vs Storyblok](https://www.anchorterminal.com/compare/hygraph-vs-storyblok.md)\n- [Hygraph vs Strapi](https://www.anchorterminal.com/compare/hygraph-vs-strapi.md)\n- [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Prismic vs WordPress](https://www.anchorterminal.com/compare/prismic-vs-wordpress.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Hygraph vs WordPress",
        "url": ""
      }
    ],
    "description": "Hygraph scores 69.3 (B) on agent readiness against WordPress's 64.8 (B), and leads in 3 of 7 scored categories. WordPress leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do cms content. Category scores, facts, verdicts and agent notes side by…",
    "facts": [
      "Hygraph B 69.3",
      "WordPress B 64.8",
      "scores"
    ],
    "h1": "Hygraph vs WordPress",
    "image": "https://www.anchorterminal.com/assets/og/compare-hygraph-vs-wordpress.png",
    "path": "/compare/hygraph-vs-wordpress",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Hygraph vs WordPress for AI agents, B 69.3 vs B 64.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
