{
  "data": {
    "a": {
      "slug": "webflow",
      "name": "Webflow",
      "vendor": "Webflow, Inc.",
      "vendorUrl": "https://webflow.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.",
      "url": "https://www.anchorterminal.com/tools/webflow",
      "markdownUrl": "https://www.anchorterminal.com/tools/webflow.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/webflow.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/webflow.json",
      "repo": "https://github.com/webflow/openapi-spec",
      "license": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.webflow.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "webflow-api"
        },
        {
          "registry": "pypi",
          "name": "webflow"
        },
        {
          "registry": "npm",
          "name": "webflow-mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps \u0026 integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).",
      "priceSummary": "$15 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 85160,
        "pypiWeekly": 121246,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.webflow.com/data/docs",
      "llmsTxt": "https://developers.webflow.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/webflow/openapi-spec/main/openapi/v2.yml",
      "registryName": "com.webflow/mcp",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.schema",
        "cms.localisation"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "closed-source",
        "free-tier",
        "webhooks",
        "typescript",
        "python",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 150,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7)."
        ],
        "verdict": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
        "bestFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "strengths": [
          "Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page",
          "OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens",
          "CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call",
          "429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically",
          "Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page"
        ],
        "weaknesses": [
          "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions",
          "No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute",
          "The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales",
          "The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise",
          "On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes",
          "Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes",
          "Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429",
          "Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms",
          "Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 65
        },
        "provenanceScore": 97
      },
      "connect": {
        "install": "npm install webflow-api",
        "http": "curl --request GET \\\n  --url https://api.webflow.com/v2/sites \\\n  --header 'accept: application/json' \\\n  --header 'authorization: Bearer YOUR_API_TOKEN'",
        "claudeCode": "claude mcp add --transport http webflow https://mcp.webflow.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/webflow"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Basic site plan",
          "unit": "month",
          "usd": 15,
          "note": "billed yearly, per site, no CMS"
        },
        {
          "item": "Premium site plan",
          "unit": "month",
          "usd": 25,
          "note": "billed yearly, per site, 20,000 CMS items and 120 requests a minute"
        },
        {
          "item": "Team platform plan",
          "unit": "month",
          "usd": 2500,
          "note": "annual contract, 5 full and 5 limited seats included"
        }
      ],
      "provenance": {
        "legalEntity": "Webflow, Inc.",
        "domain": "webflow.com",
        "domainRegistered": "2003-03-31",
        "endpointOnVendorDomain": true,
        "terms": "https://webflow.com/legal/terms",
        "privacy": "https://webflow.com/legal/privacy",
        "statusPage": "https://status.webflow.com",
        "changelog": "https://developers.webflow.com/home/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.",
          "The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.",
          "The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.",
          "The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.",
          "webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.",
          "RDAP for webflow.com gives a registration date of 2003-03-31.",
          "status.webflow.com runs on Statuspage with components for the Data API and the MCP server."
        ],
        "score": 97
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/webflow.json",
      "live": {
        "slug": "webflow",
        "probe": {
          "target": "https://api.webflow.com/v2",
          "method": "get",
          "lastAt": "2026-10-08T19:09:02.226742748Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 324,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 268,
          "p95ms24h": 617,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.webflow.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:07:04.499232802Z"
        },
        "pages": [
          {
            "url": "https://developers.webflow.com/home/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:03.444775017Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "26398a0d385c"
          },
          {
            "url": "https://webflow.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:48.086194416Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1895a791460c"
          },
          {
            "url": "https://webflow.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:43.849393456Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1dc949e66fd3"
          },
          {
            "url": "https://webflow.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:46.083572378Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fab4ea21138a"
          }
        ],
        "updatedAt": "2026-10-08T19:09:02.226742748Z"
      }
    },
    "answer": "Webflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing.",
    "b": {
      "slug": "wordpress",
      "name": "WordPress",
      "vendor": "WordPress.org (open-source project)",
      "vendorUrl": "https://wordpress.org",
      "kind": "http-api",
      "category": "cms",
      "summary": "WordPress is an open-source content management system that its owner hosts. Agents create, revise and publish posts, pages and media through the built-in REST API, WP-CLI or the official MCP Adapter plugin.",
      "url": "https://www.anchorterminal.com/tools/wordpress",
      "markdownUrl": "https://www.anchorterminal.com/tools/wordpress.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wordpress.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wordpress.json",
      "repo": "https://github.com/WordPress/wordpress-develop",
      "license": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [],
      "auth": "api-key",
      "authNotes": "Self-serve on your own site, with no app review or approval by WordPress.org. A user creates an Application Password on their profile, through `/wp/v2/users/\u003cid\u003e/application-passwords` or with `wp user application-password create`, and the agent sends it as Basic auth over HTTPS. A password has no scopes or expiry and carries every capability of its user, so access is set by the user's role. Each password can be revoked on its own. The MCP Adapter's HTTP transport takes the same credential, and its STDIO transport runs as the user named in `--user`.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy from WordPress.org, so an agent can start without a contract or a card. The owner pays for their own hosting. WordPress.com and other hosts sell hosted WordPress under their own prices, which aren't graded here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API handbook, wordpress.org/llms.txt or the core and MCP Adapter repositories (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 21460,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.wordpress.org/rest-api/",
      "llmsTxt": "https://wordpress.org/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "rest",
        "mcp",
        "cli",
        "php",
        "llms-txt",
        "security-txt",
        "bug-bounty"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 249,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "22 September 2026. WordPress 7.1.2 fixed a critical flaw, CVE-2026-87902 (GHSA-7hp8-65ch-5whp), in which an unauthenticated attacker could, where server and theme conditions were met, make template resolution include a local PHP file and reach remote code execution. 7.1.1 on 17 September and 7.1.3 on 6 October fixed 18 further security issues. All were published by the project with the fix and backported, and we found no report of exploitation in the release posts, so we deduct 5 of a possible 15. https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ ; https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/"
        ],
        "verdict": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.",
        "bestFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "strengths": [
          "Posts created without `status` are saved as drafts, and DELETE moves a post to the Trash unless `force=true` is passed",
          "Every REST or WP-CLI update to a post writes a revision that `/wp/v2/posts/\u003cid\u003e/revisions` lists with author and date",
          "`_fields` trims responses down to nested properties, with `per_page` up to 100 and X-WP-Total headers on every list",
          "Six stable releases between 6 August and 6 October 2026, and security fixes backported to 4.7",
          "GPL-2.0-or-later, free to self-host, with a valid security.txt and a HackerOne programme for core"
        ],
        "weaknesses": [
          "Application Passwords have no scopes or expiry. Each one carries every capability of its user",
          "The revisions route supports GET and DELETE only, so a rollback means writing the old content back as a new update",
          "Core has no rate limit, no idempotency keys and no log of API calls beyond revisions and a password's last use",
          "A critical flaw (CVE-2026-87902) fixed in 7.1.2 on 22 September 2026 allowed remote code execution under certain server and theme conditions",
          "No published OpenAPI file. Each site describes its own routes at `/wp-json`, and core has no content localisation"
        ],
        "agentNotes": [
          "Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them",
          "Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment",
          "Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content",
          "To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route",
          "Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 83,
          "payments": 60,
          "reliability": 78,
          "schema": 65,
          "security": 62,
          "transparency": 72
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "wp core download \u0026\u0026 wp core install --url=\u003curl\u003e --title=\u003ctitle\u003e --admin_user=\u003cuser\u003e --admin_email=\u003cemail\u003e",
        "http": "curl --user \"USERNAME:PASSWORD\" https://HOSTNAME/wp-json/wp/v2/users?context=edit",
        "config": {
          "mcpServers": {
            "wordpress": {
              "args": [
                "--path=/path/to/your/wordpress/site",
                "mcp-adapter",
                "serve",
                "--server=mcp-adapter-default-server",
                "--user=admin"
              ],
              "command": "wp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/wordpress"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WordPress, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "WordPress.org, an open-source project. The WordPress trademark belongs to the WordPress Foundation",
        "domain": "wordpress.org",
        "domainRegistered": "2003-03-28",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://wordpress.org/about/privacy/",
        "statusPage": "",
        "changelog": "https://wordpress.org/news/category/releases/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service govern the software. It is licensed under GPL version 2 or later, and no service agreement or API terms were found, so `terms` is left out.",
          "The privacy policy covers the WordPress.org websites and names api.wordpress.org, the service installations call to check for updates. It names no company, and gives dpo@wordpress.org as the contact. It doesn't cover content held on a self-hosted site.",
          "The REST API answers on each owner's own domain.",
          "https://wordpress.org/.well-known/security.txt returned 200 with Contact https://hackerone.com/wordpress and Expires 2027-06-30.",
          "RDAP for wordpress.org gives a registration date of 2003-03-28.",
          "The make.wordpress.org footer says the WordPress trademark is the intellectual property of the WordPress Foundation. `license.txt` gives copyright to the contributors.",
          "No status page applies to self-hosted software."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wordpress.json",
      "live": {
        "slug": "wordpress",
        "pages": [
          {
            "url": "https://wordpress.org/news/category/releases/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.505193763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cbd71d93d029"
          },
          {
            "url": "https://wordpress.org/about/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.079319583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61575a1b129f"
          }
        ],
        "updatedAt": "2026-10-08T18:25:52.505193763Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Webflow, Inc.",
        "b": "WordPress.org (open-source project)",
        "name": "Vendor"
      },
      {
        "a": "https://api.webflow.com/v2",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
        "b": "GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too",
        "name": "Licence"
      },
      {
        "a": "34",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "com.webflow/mcp",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2023-11-15",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2025-03-17",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "85k npm/wk, 121k PyPI/wk",
        "b": "21k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Webflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Webflow or WordPress?"
      },
      {
        "answer": "Webflow takes an API key or an OAuth sign-in. WordPress needs an API key.",
        "question": "Do Webflow and WordPress need an API key?"
      },
      {
        "answer": "Webflow has a hosted endpoint at https://api.webflow.com/v2. WordPress runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Webflow and WordPress without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Webflow. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).",
        "question": "Are Webflow and WordPress open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 65",
          "Security \u0026 auth, 74 against 62",
          "Transparency \u0026 trust, 81 against 68"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "slug": "webflow",
        "watchFor": "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 60 against 30"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.",
        "slug": "wordpress",
        "watchFor": "Application Passwords have no scopes or expiry. Each one carries every capability of its user"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-wordpress.json",
        "title": "Ghost vs WordPress",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-webflow.json",
        "title": "Sanity vs Webflow",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-webflow.json",
        "title": "Storyblok vs Webflow",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "webflow",
        "key": "reliability",
        "name": "Reliability",
        "webflow": 79,
        "weight": 16,
        "wordpress": 78
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 22,
        "edge": "webflow",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "webflow": 87,
        "weight": 13,
        "wordpress": 65
      },
      {
        "by": 2,
        "edge": "wordpress",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "webflow": 72,
        "weight": 13,
        "wordpress": 74
      },
      {
        "by": 12,
        "edge": "webflow",
        "key": "security",
        "name": "Security \u0026 auth",
        "webflow": 74,
        "weight": 14,
        "wordpress": 62
      },
      {
        "by": 30,
        "edge": "wordpress",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "webflow": 30,
        "weight": 10,
        "wordpress": 60
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "wordpress",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "webflow": 80,
        "weight": 7,
        "wordpress": 83
      },
      {
        "by": 13,
        "edge": "webflow",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "webflow": 81,
        "weight": 7,
        "wordpress": 68
      }
    ],
    "summary": "Webflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "webflow": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
      "wordpress": "The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/webflow-vs-wordpress",
    "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.md",
    "slim": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.min.md"
  },
  "markdown": "Webflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing. Both do cms content.\n\n- Webflow: grade B, 69.4/100, rank #150 of 629. Markdown https://www.anchorterminal.com/tools/webflow.md · JSON https://www.anchorterminal.com/api/v1/tools/webflow.json\n- WordPress: grade B, 64.8/100, rank #249 of 629. Markdown https://www.anchorterminal.com/tools/wordpress.md · JSON https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Which one, for what\n\n### Webflow (B)\n\nGood for: Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 65\n- Security \u0026 auth, 74 against 62\n- Transparency \u0026 trust, 81 against 68\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions\n\n### WordPress (B)\n\nGood for: Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.\n\nAhead on:\n- Payments \u0026 pricing, 60 against 30\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: Application Passwords have no scopes or expiry. Each one carries every capability of its user\n\n\n## Score by category\n\n| Category | Weight | Webflow | WordPress | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 79 | 78 | Webflow +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 65 | Webflow +22 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 74 | WordPress +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 74 | 62 | Webflow +12 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 60 | WordPress +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 83 | WordPress +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 81 | 68 | Webflow +13 |\n| Negative events | ≤15 | -3 | -5 | |\n| **Total** | | **69.4 · B** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Webflow | WordPress |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Webflow, Inc. | WordPress.org (open-source project) |\n| Hosted endpoint | `https://api.webflow.com/v2` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, stdio |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |\n| Tools exposed | 34 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `com.webflow/mcp` | not listed |\n| Last release | 2026-10-07 | 2026-10-06 |\n| Terms last updated | 2023-11-15 | no document linked |\n| Privacy policy last updated | 2025-03-17 | no date given |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 85k npm/wk, 121k PyPI/wk | 21k stars |\n\n## Verdicts\n\n**Webflow.** The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.\n\n**WordPress.** The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.\n\n## Before you call either\n\n### Webflow\n\n1. Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes\n2. Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes\n3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429\n4. Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms\n5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`\n\n### WordPress\n\n1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them\n2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment\n3. Upload a file with POST `/wp-json/wp/v2/media` first, then set `featured_media` or reference the returned URL in the post content\n4. To roll back, GET `/wp/v2/posts/\u003cid\u003e/revisions/\u003crev\u003e?context=edit` and POST its title and content to the post. There's no restore route\n5. Pass `_fields=id,status,link,modified` on lists and read X-WP-TotalPages. `per_page` stops at 100\n\n## Questions\n\n### Which is better for AI agents, Webflow or WordPress?\n\nWebflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing.\n\n### Do Webflow and WordPress need an API key?\n\nWebflow takes an API key or an OAuth sign-in. WordPress needs an API key.\n\n### Can an agent call Webflow and WordPress without installing anything?\n\nWebflow has a hosted endpoint at https://api.webflow.com/v2. WordPress runs on your own machine, with no hosted endpoint listed.\n\n### Are Webflow and WordPress open source?\n\nNo open-source release is listed for Webflow. WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/webflow-vs-wordpress.json, and with the fewest tokens: https://www.anchorterminal.com/compare/webflow-vs-wordpress.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"webflow\", \"b\": \"wordpress\"}`. From a terminal: `anchor compare webflow wordpress`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/webflow.json and https://www.anchorterminal.com/api/v1/tools/wordpress.json\n\n## Other comparisons with Webflow or WordPress\n\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Ghost vs WordPress](https://www.anchorterminal.com/compare/ghost-vs-wordpress.md)\n- [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n- [Storyblok vs Webflow](https://www.anchorterminal.com/compare/storyblok-vs-webflow.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Webflow vs WordPress",
        "url": ""
      }
    ],
    "description": "Webflow scores 69.4 (B) on agent readiness against WordPress's 64.8 (B), and leads in 4 of 7 scored categories. WordPress leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Webflow B 69.4",
      "WordPress B 64.8",
      "scores"
    ],
    "h1": "Webflow vs WordPress",
    "image": "https://www.anchorterminal.com/assets/og/compare-webflow-vs-wordpress.png",
    "path": "/compare/webflow-vs-wordpress",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Webflow vs WordPress for AI agents, B 69.4 vs B 64.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 730
  },
  "version": 1
}
