{
  "fixes": {
    "slug": "directus",
    "name": "Directus",
    "listing": "https://www.anchorterminal.com/tools/directus",
    "markdown": "# Fix list: Directus\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/directus, the October 2026 research run, assessed 8 October 2026. Grade B, 67.1 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Directus: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Security \u0026 auth, 68 out of 100, up to 5.6 more on the total\n\nWhy it scored 68: MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 2. Payments \u0026 pricing, 55 out of 100, up to 5.6 more on the total\n\nWhy it scored 55: Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Agent ergonomics, 73 out of 100, up to 4.4 more on the total\n\nWhy it scored 73: Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 4. Reliability, 82 out of 100, up to 3.6 more on the total\n\nWhy it scored 82: Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 5. Transparency \u0026 trust, 61 out of 100, up to 3.4 more on the total\n\nMade of editorial 55, provenance 66.\n\nWhy it scored 61: The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Endpoint on the vendor's domain:  is not on directus.com (0 of 15)\n- Terms of service: read, states 1 of the 7 things a reader expects, and has 1 clause that costs points (2.9 of 10)\n- Privacy policy: read, states 5 of the 8 things a reader expects (7.8 of 10)\n- security.txt: not found (0 of 10)\n\n## 6. Schema \u0026 documentation, 81 out of 100, up to 3.1 more on the total\n\nWhy it scored 81: An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 7. Maintenance \u0026 community, 86 out of 100, up to 1.2 more on the total\n\nWhy it scored 86: v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the official MCP registry search for Directus timed out twice from our network\n- unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages\n- unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown\n- unchecked: whether the 14-day Directus Cloud trial asks for a card\n- We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through `PATCH /settings` is inferred from the `mcp_enabled` settings field, not from the docs\n- The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12\n- directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so `provenance.terms` points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies\n- The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes\n- The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise\n- The repository's `security.md` gives security@directus.io while the docs give security@directus.com\n\n## Weaknesses\n\n- Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n- The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key\n- Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`\n- Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes\n- At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n- Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n- Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n- Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n- Count translation and junction tables against the 25-collection Core limit before creating collections\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "B",
    "score": 67.1,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 68,
        "maxGain": 5.6,
        "reason": "MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 55,
        "maxGain": 5.6,
        "reason": "Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 73,
        "maxGain": 4.4,
        "reason": "Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 82,
        "maxGain": 3.6,
        "reason": "Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 61,
        "maxGain": 3.4,
        "reason": "The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20).",
        "blend": "editorial 55, provenance 66",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 81,
        "maxGain": 3.1,
        "reason": "An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 86,
        "maxGain": 1.2,
        "reason": "v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Endpoint on the vendor's domain",
        "value": " is not on directus.com",
        "points": 0,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "read, states 1 of the 7 things a reader expects, and has 1 clause that costs points",
        "points": 2.9,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 5 of the 8 things a reader expects",
        "points": 7.8,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
    ],
    "unchecked": [
      "unchecked: the official MCP registry search for Directus timed out twice from our network",
      "unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages",
      "unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown",
      "unchecked: whether the 14-day Directus Cloud trial asks for a card",
      "We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through `PATCH /settings` is inferred from the `mcp_enabled` settings field, not from the docs",
      "The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12",
      "directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so `provenance.terms` points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies",
      "The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes",
      "The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise",
      "The repository's `security.md` gives security@directus.io while the docs give security@directus.com"
    ],
    "weaknesses": [
      "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
      "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
      "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
      "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
      "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
    ],
    "agentNotes": [
      "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
      "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
      "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
      "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
      "Count translation and junction tables against the 25-collection Core limit before creating collections"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
