{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/sanity.json",
        "name": "Sanity",
        "score": 73.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "sanity"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/webflow.json",
        "name": "Webflow",
        "score": 69.4,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "webflow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/storyblok.json",
        "name": "Storyblok",
        "score": 67.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "storyblok"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/strapi.json",
        "name": "Strapi",
        "score": 65.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.localisation",
          "cms.assets",
          "cms.schema"
        ],
        "slug": "strapi"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/wordpress.json",
        "name": "WordPress",
        "score": 64.8,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "wordpress"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ghost.json",
        "name": "Ghost",
        "score": 58.3,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "ghost"
      }
    ],
    "tool": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 264,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 71,
            "points": 14.2,
            "reason": "Read with the hosted lines and scored on the Content Management API. status.contentstack.com is a Statuspage site with components by cloud, region and service and a full incident history (20). Its feed lists nine incidents with customer impact between 9 July and 7 October 2026, each confined to one or two of the seven regions. The longest on the core APIs was a disruption of the management, delivery and automation APIs on Google Cloud North America on 11 July (74 minutes, marked minor). Webhook delivery on AWS Europe was disrupted for 59 minutes on 28 August (marked critical), and publishing and webhooks on Azure Europe were delayed for 51 minutes on 1 September (marked major). We read that as one major outage with several shorter ones (10). Rate limits have numbers, 10 reads and 10 writes a second per organisation and one bulk request a second (15). The docs say a 429 is returned and name `X-RateLimit-Limit` and `X-RateLimit-Remaining`. No Retry-After header, backoff guidance or idempotency key was found (6 of 15). The Services Description commits to 99.50 or 99.95 per cent monthly availability by plan, with service credits (10). The v3 API is generally available. The MCP server is at version 0.9.0 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 77,
            "points": 12.51,
            "reason": "An OpenAPI 3.0.0 file for the Content Management API is public, with 138 paths and 221 operations, and every MCP tool has a JSON Schema published at mcp.contentstack.com (25). www.contentstack.com/llms.txt indexes the docs. The full-text export it points to, llms-full.txt, returned 502 on 7 October (8 of 10). Operation descriptions in the spec are long (median 1,189 characters, in HTML) and MCP tool descriptions say what each tool does (median 142 characters in the `cma` group). Few say when not to use a tool (15 of 20). The spec has no enums and no component schemas, and request bodies are examples. The `cma` tool schemas have 369 properties with two enums and 13 untyped objects such as `entry_data`. Version 0.9.0 says it adds enums from the connected stack at run time, which we couldn't see without an account (7 of 15). The spec carries 494 examples but documents only a 200 response for each operation. The docs list status codes in a table (9 of 15). The API version is in the path, and a dated changelog with an RSS feed covers API, SDK and CLI changes. A behaviour change to `limit` shipped inside v3 (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "Responses can be sized with `only[BASE][]`, `except[BASE][]` and `limit`. The MCP server's default group is 78 tools and about 66 KB of schema, split from nine other groups by `--groups` (17 of 25). `limit` up to 100, `skip`, `include_count`, sort and a JSON `query` filter (20). Errors use standard status codes with a JSON body, with 412 and 422 explained in the docs. Error bodies aren't in the spec (12 of 20). No idempotency keys or conditional writes were found, and the MCP package contains no readOnlyHint or destructiveHint annotations. Entries keep version numbers, which helps check a write after a lost response (4 of 20). Management SDKs in JavaScript, Python, Java and .NET. Every call needs two headers and the right regional host (14 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 69,
            "points": 12.08,
            "reason": "OAuth 2.0 with scopes per module and action (cm.entry:read, cm.entry:write and cm.entry:publish are separate), 60-minute tokens, a refresh grant and revocation by users or organisation admins. Management tokens can be read-only, branch-limited and expiring, and are shown once. PKCE isn't mentioned in the OAuth docs (27 of 30). Read-only tokens and separate publish scopes allow least privilege, and stacks have workflows and publish rules. The MCP server has no read-only switch and no confirmation step, and its default group includes nine delete tools (13 of 20). Entries are written by a stack's own users and can still carry instructions. No prompt-injection guidance was found in the MCP docs (3 of 15). A stack audit log records creates, updates, deletes and publishes by user, with an API endpoint and MCP tools to read it. Its retention period isn't stated (13 of 15). SOC 2 Type II, ISO 27001:2022 and penetration tests twice a year. Reports go to security@contentstack.com with a stated 24-hour response, and SDK security fixes are listed in the changelog with CVE numbers. security.txt returns 404 and no bug bounty was found. We didn't search NVD (13 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login ($0, $29 and $299 a month, with included API calls stated). Build mentions pay-as-you-go overages and no unit rate is shown (10). The Free plan needs no card and doesn't expire. We didn't run the sign-up form to confirm it (20). A person signs up in a browser, verifies an email address and creates the token or approves OAuth (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "reason": "The JavaScript management SDK 1.31.2 was released on 22 September 2026, and the changelog's newest entry is 1 October 2026 (30). Dated entries in the last 90 days include the `limit` change on 11 September, recursive embedded items on 7 September, webhook HMAC signing on 30 July and more than ten SDK and CLI releases (20). Closed service with a public changelog and RSS feed, email support and a Discord community. We didn't test a support channel (10 of 15). Official management SDKs in four languages, all with releases since 27 July 2026. The MCP server isn't in the official MCP registry, which returned no result for Contentstack (15). The JavaScript SDK repository has unit-test, CodeQL and dependency-scan workflows, and its changelog shows regular dependency fixes. We didn't see the CI results (7 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "note": "editorial 59, provenance 87",
            "reason": "The service is closed under a Master Agreement last updated 17 July 2026 and Terms of Service from August 2022. The spec, SDKs, CLI and MCP package are MIT, though the MCP repository named on npm isn't public (15). The privacy policy of 30 June 2026 says customer content is deleted within 180 days of termination, data processing agreements for the US and for EMEA are published, and the AI addendum of 27 July 2026 says customer data isn't used to train general AI models. The older Terms of Service only say access to content ends on termination (24 of 30). No deprecation policy with a notice period was found. The Services Description lets Contentstack end a service during a term with a pro-rata refund, and the `limit` change was announced on the day it applied (5 of 20). The sub-processor list was updated on 25 May 2026 with purposes and locations. It gives the United States for Azure and Google Cloud although both have European regions in the API docs, and the page states no notice period for changes (15 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Responses can be sized with `only[BASE][]`, `except[BASE][]` and `limit`. The MCP server's default group is 78 tools and about 66 KB of schema, split from nine other groups by `--groups` (17 of 25). `limit` up to 100, `skip`, `include_count`, sort and a JSON `query` filter (20). Errors use standard status codes with a JSON body, with 412 and 422 explained in the docs. Error bodies aren't in the spec (12 of 20). No idempotency keys or conditional writes were found, and the MCP package contains no readOnlyHint or destructiveHint annotations. Entries keep version numbers, which helps check a write after a lost response (4 of 20). Management SDKs in JavaScript, Python, Java and .NET. Every call needs two headers and the right regional host (14 of 15).",
            "maintenance": "The JavaScript management SDK 1.31.2 was released on 22 September 2026, and the changelog's newest entry is 1 October 2026 (30). Dated entries in the last 90 days include the `limit` change on 11 September, recursive embedded items on 7 September, webhook HMAC signing on 30 July and more than ten SDK and CLI releases (20). Closed service with a public changelog and RSS feed, email support and a Discord community. We didn't test a support channel (10 of 15). Official management SDKs in four languages, all with releases since 27 July 2026. The MCP server isn't in the official MCP registry, which returned no result for Contentstack (15). The JavaScript SDK repository has unit-test, CodeQL and dependency-scan workflows, and its changelog shows regular dependency fixes. We didn't see the CI results (7 of 10).",
            "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login ($0, $29 and $299 a month, with included API calls stated). Build mentions pay-as-you-go overages and no unit rate is shown (10). The Free plan needs no card and doesn't expire. We didn't run the sign-up form to confirm it (20). A person signs up in a browser, verifies an email address and creates the token or approves OAuth (0).",
            "reliability": "Read with the hosted lines and scored on the Content Management API. status.contentstack.com is a Statuspage site with components by cloud, region and service and a full incident history (20). Its feed lists nine incidents with customer impact between 9 July and 7 October 2026, each confined to one or two of the seven regions. The longest on the core APIs was a disruption of the management, delivery and automation APIs on Google Cloud North America on 11 July (74 minutes, marked minor). Webhook delivery on AWS Europe was disrupted for 59 minutes on 28 August (marked critical), and publishing and webhooks on Azure Europe were delayed for 51 minutes on 1 September (marked major). We read that as one major outage with several shorter ones (10). Rate limits have numbers, 10 reads and 10 writes a second per organisation and one bulk request a second (15). The docs say a 429 is returned and name `X-RateLimit-Limit` and `X-RateLimit-Remaining`. No Retry-After header, backoff guidance or idempotency key was found (6 of 15). The Services Description commits to 99.50 or 99.95 per cent monthly availability by plan, with service credits (10). The v3 API is generally available. The MCP server is at version 0.9.0 (10).",
            "schema": "An OpenAPI 3.0.0 file for the Content Management API is public, with 138 paths and 221 operations, and every MCP tool has a JSON Schema published at mcp.contentstack.com (25). www.contentstack.com/llms.txt indexes the docs. The full-text export it points to, llms-full.txt, returned 502 on 7 October (8 of 10). Operation descriptions in the spec are long (median 1,189 characters, in HTML) and MCP tool descriptions say what each tool does (median 142 characters in the `cma` group). Few say when not to use a tool (15 of 20). The spec has no enums and no component schemas, and request bodies are examples. The `cma` tool schemas have 369 properties with two enums and 13 untyped objects such as `entry_data`. Version 0.9.0 says it adds enums from the connected stack at run time, which we couldn't see without an account (7 of 15). The spec carries 494 examples but documents only a 200 response for each operation. The docs list status codes in a table (9 of 15). The API version is in the path, and a dated changelog with an RSS feed covers API, SDK and CLI changes. A behaviour change to `limit` shipped inside v3 (13 of 15).",
            "security": "OAuth 2.0 with scopes per module and action (cm.entry:read, cm.entry:write and cm.entry:publish are separate), 60-minute tokens, a refresh grant and revocation by users or organisation admins. Management tokens can be read-only, branch-limited and expiring, and are shown once. PKCE isn't mentioned in the OAuth docs (27 of 30). Read-only tokens and separate publish scopes allow least privilege, and stacks have workflows and publish rules. The MCP server has no read-only switch and no confirmation step, and its default group includes nine delete tools (13 of 20). Entries are written by a stack's own users and can still carry instructions. No prompt-injection guidance was found in the MCP docs (3 of 15). A stack audit log records creates, updates, deletes and publishes by user, with an API endpoint and MCP tools to read it. Its retention period isn't stated (13 of 15). SOC 2 Type II, ISO 27001:2022 and penetration tests twice a year. Reports go to security@contentstack.com with a stated 24-hour response, and SDK security fixes are listed in the changelog with CVE numbers. security.txt returns 404 and no bug bounty was found. We didn't search NVD (13 of 20).",
            "transparency": "The service is closed under a Master Agreement last updated 17 July 2026 and Terms of Service from August 2022. The spec, SDKs, CLI and MCP package are MIT, though the MCP repository named on npm isn't public (15). The privacy policy of 30 June 2026 says customer content is deleted within 180 days of termination, data processing agreements for the US and for EMEA are published, and the AI addendum of 27 July 2026 says customer data isn't used to train general AI models. The older Terms of Service only say access to content ends on termination (24 of 30). No deprecation policy with a notice period was found. The Services Description lets Contentstack end a service during a term with a pro-rata refund, and the `limit` change was announced on the day it applied (5 of 20). The sub-processor list was updated on 25 May 2026 with purposes and locations. It gives the United States for Azure and Google Cloud although both have European regions in the API docs, and the page states no notice period for changes (15 of 20)."
          },
          "sources": [
            {
              "what": "Content Management API docs (auth, rate limits, errors, regions)",
              "url": "https://www.contentstack.com/docs/developers/apis/content-management-api",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI files repository",
              "url": "https://github.com/contentstack/contentstack-openapi",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server docs",
              "url": "https://www.contentstack.com/docs/agent-os/contentstack-mcp-server",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP package, README and versions",
              "url": "https://registry.npmjs.org/@contentstack/mcp",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP tool definitions, cma group",
              "url": "https://mcp.contentstack.com/cma/tools",
              "seen": "2026-10-07"
            },
            {
              "what": "status incident feed",
              "url": "https://status.contentstack.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.contentstack.com/pricing",
              "seen": "2026-10-07"
            },
            {
              "what": "changelog and RSS feed",
              "url": "https://www.contentstack.com/docs/changelog",
              "seen": "2026-10-07"
            },
            {
              "what": "management tokens",
              "url": "https://www.contentstack.com/docs/developers/create-tokens/create-a-management-token",
              "seen": "2026-10-07"
            },
            {
              "what": "OAuth",
              "url": "https://www.contentstack.com/docs/developers/developer-hub/contentstack-oauth",
              "seen": "2026-10-07"
            },
            {
              "what": "audit log",
              "url": "https://www.contentstack.com/docs/developers/set-up-stack/monitor-stack-activities-in-audit-log",
              "seen": "2026-10-07"
            },
            {
              "what": "trust page",
              "url": "https://www.contentstack.com/trust",
              "seen": "2026-10-07"
            },
            {
              "what": "Services Description (SLA, end of life)",
              "url": "https://www.contentstack.com/legal/services-description",
              "seen": "2026-10-07"
            },
            {
              "what": "Master Agreement",
              "url": "https://www.contentstack.com/legal/master-subscription-agreement",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://www.contentstack.com/legal/privacy",
              "seen": "2026-10-07"
            },
            {
              "what": "sub-processors",
              "url": "https://www.contentstack.com/legal/subprocessors",
              "seen": "2026-10-07"
            },
            {
              "what": "AI addendum",
              "url": "https://www.contentstack.com/legal/artificial-intelligence-addendum",
              "seen": "2026-10-07"
            },
            {
              "what": "JavaScript management SDK repository",
              "url": "https://github.com/contentstack/contentstack-management-javascript",
              "seen": "2026-10-07"
            },
            {
              "what": "llms.txt",
              "url": "https://www.contentstack.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "security.txt (404)",
              "url": "https://www.contentstack.com/.well-known/security.txt",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the endpoint-level API reference on the docs site, which renders in the browser. We read the introduction and the OpenAPI file",
            "unchecked: https://www.contentstack.com/llms-full.txt returned 502 on 7 October 2026",
            "unchecked: GitHub star counts, and whether CI passes on the SDK repositories",
            "unchecked: the sign-up form itself. The pricing page says no card is required",
            "unchecked: NVD and GitHub advisories for Contentstack packages",
            "unchecked: whether customers were told by email before the 11 September 2026 `limit` change. Only the public changelog was read",
            "The docs disagree on how many management tokens a stack may hold. The API page says 10 and the token guide says 30",
            "The run-time enrichment of MCP tool schemas in 0.9.0 needs a connected stack, so we graded the static definitions",
            "The Enterprise card on the pricing page says 99.5 per cent uptime while the Services Description names plans (Start, Grow, Scale, X1, X3, X5) that don't match the pricing page's plan names. Whether Free, Build and Growth carry any commitment wasn't established"
          ]
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "notable": [
        "The Content Management API answers on seven regional hosts across AWS, Azure and Google Cloud, with `api_key` plus a management token, OAuth token or user authtoken in headers (https://www.contentstack.com/docs/developers/apis/content-management-api)",
        "The MCP server is the npm package @contentstack/mcp, version 0.9.0 of 13 July 2026, run locally over stdio with `npx`. It has 206 tools in ten groups and loads the 78-tool `cma` group by default (https://www.npmjs.com/package/@contentstack/mcp)",
        "Contentstack publishes the MCP tool definitions, with input schemas, request mappings and OAuth scopes, at unauthenticated URLs such as https://mcp.contentstack.com/cma/tools",
        "Default rate limits are 10 reads and 10 writes a second per organisation and one bulk request a second, with `X-RateLimit-Limit` and `X-RateLimit-Remaining` headers (https://www.contentstack.com/docs/developers/apis/content-management-api)",
        "Self-serve sign-up and a free plan started on 16 September 2026. Free is $0 with no card, Build $29 a month and Growth $299 a month (https://www.contentstack.com/pricing)",
        "A changelog entry dated 11 September 2026 says `limit=0` on delivery and management requests now returns the default number of records where it used to return all of them (https://www.contentstack.com/docs/changelog)",
        "The Services Description of 28 July 2026 commits to 99.50 per cent monthly availability on Start, Grow, X1 and X3 plans and 99.95 per cent on Scale and X5, with service credits (https://www.contentstack.com/legal/services-description)",
        "SOC 2 Type II, ISO 27001:2022 and third-party penetration tests twice a year are listed on the trust page (https://www.contentstack.com/trust)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The Content Management API (REST, v3), which is generally available. The official MCP server (@contentstack/mcp 0.9.0, local stdio) wraps it and is noted where it differs"
        },
        {
          "label": "Regions",
          "value": "AWS North America (api.contentstack.io), AWS Europe, AWS Australia, Azure North America, Azure Europe, Google Cloud North America and Google Cloud Europe, each with its own contentstack.com host"
        },
        {
          "label": "Credentials",
          "value": "Management token (stack level, read-only or read-write, branch scope, optional expiry, own rate limits), OAuth 2.0 app or user token (authorisation code or client credentials, 60 minutes, refresh grant), or a user authtoken"
        },
        {
          "label": "OAuth scopes",
          "value": "Per module and action, for example cm.entry:read, cm.entry:write, cm.entry:publish, cm.asset:write and cm.content-types.management:write. 28 distinct scopes appear across the 78 tools of the `cma` group"
        },
        {
          "label": "Rate limits",
          "value": "10 GET requests and 10 write requests a second per organisation, one bulk request a second, one stack creation a minute. Limits vary by plan. Uncached delivery requests are capped at 100 a second per organisation"
        },
        {
          "label": "Pagination",
          "value": "`limit` (default and maximum 100), `skip`, `include_count`, `asc`, `desc`, a JSON `query` filter, and `only[BASE][]` and `except[BASE][]` for field selection"
        },
        {
          "label": "Errors",
          "value": "HTTP status codes with a JSON body. 412 for an invalid API key, 422 for validation errors and unknown fields, 429 for rate limits"
        },
        {
          "label": "Machine-readable contract",
          "value": "OpenAPI 3.0.0 files for the management and delivery APIs linked from github.com/contentstack/contentstack-openapi (MIT). The management file has 138 paths and 221 operations. A Postman collection is linked from the docs"
        },
        {
          "label": "MCP server",
          "value": "206 tools in ten groups (cma 78, cma-extended 22, cda 4, analytics 8, automations 9, brandkit 12, launch 27, developerhub 12, lytics 10, personalise 24), chosen with `--groups`. OAuth through `npx @contentstack/mcp --auth`, or a management token for the two cma groups. No tool annotations"
        },
        {
          "label": "Content operations",
          "value": "Entries, entry variants, assets and folders, content types, global fields, taxonomies, languages, environments, branches and aliases, releases, bulk publish, workflows, webhooks, roles and audit logs"
        },
        {
          "label": "SDKs",
          "value": "Management SDKs for JavaScript (@contentstack/management 1.31.2, 22 September 2026), Python (contentstack-management 1.11.2, 12 August 2026), Java (1.14.1) and .NET (1.1.1), all MIT, plus the csdx CLI (@contentstack/cli 2.0.2)"
        },
        {
          "label": "Plans",
          "value": "Free (1 stack, 3 users, 100,000 API calls a month, 10 content types, 1,000 entries), Build $29 a month, Growth $299 a month with 10 users and $25 for each extra user, Enterprise by quote"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II and ISO 27001:2022 per contentstack.com/trust. Penetration testing by a third party twice a year. Security reports go to security@contentstack.com"
        },
        {
          "label": "Status",
          "value": "status.contentstack.com on Statuspage, 334 components by cloud, region and service"
        },
        {
          "label": "Sub-processors",
          "value": "List updated 25 May 2026. AWS, Azure, Google Cloud, Fastly, MongoDB, Cloudflare, and OpenAI for Brand Kit only"
        }
      ],
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Contentstack Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "contentstack.com, registered 2011-10-29 (14 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.contentstack.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.contentstack.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.contentstack.com/legal/terms-of-service",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-08-01",
            "words": 12259,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective Date: August 2022",
                "says": "Last updated 2022-08-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement is governed by the laws of the state of California, U.S.A., without respect to its conflict of law provisions.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN NO EVENT WILL Contentstack, OR ITS SUPPLIERS OR LICENSORS, BE LIABLE WITH RESPECT TO ANY SUBJECT MATTER OF THIS AGREEMENT UNDER ANY CONTRACT, NEGLIGENCE, STRICT LIABILITY OR OTHER LEGAL OR EQUITABLE THEORY FOR: (I) ANY SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES;",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Further, you acknowledge that the Trial Subscription can be terminated at any time in the sole discretion of Contentstack as well as your access to Contentstack may be revoked or cancelled at any time at the discretion of Contentstack without notice, and that your Content may be deleted and your Account cancelled with…"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Contentstack reserves the right to change the payment terms and fees upon thirty (30) days prior written notice to you.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not agree to all the terms and conditions of this agreement, then you may not access the Sites or use any Contentstack products, including but not limited to Contentstack."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(j) access any part of the Contentstack Service in order to build a competitive product or service",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Contentstack may terminate your access to all or any part of the Contentstack Service at any time."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "The arbitration shall take place in San Francisco, California, in the English language and the arbitral decision may be enforced in any court."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Effective Date: August 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Contentstack may show the customer's company name and logo and links to its application for marketing, without notice or payment, and the customer can ask to be excluded.",
                "quote": "Contentstack reserves and you grant Contentstack the right to display links to your application or website and the name/logo of your company for marketing purposes and may do so without notice or compensation."
              },
              {
                "date": "2026-10-08",
                "text": "When the agreement ends the customer loses access to all content in the account, and saving that content beforehand is the customer's responsibility.",
                "quote": "Upon effective termination of the Agreement you forfeit and relinquish access to all content in your account."
              },
              {
                "date": "2026-10-08",
                "text": "Paid subscriptions renew automatically at the fee that applies at the time of renewal unless the customer cancels before the period ends.",
                "quote": "your purchased service subscription will automatically renew and you authorize us to collect the then-applicable annual or monthly subscription fee for such Purchased Services"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.contentstack.com/legal/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-30",
            "words": 14198,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: June 30, 2026",
                "says": "Last updated 2026-06-30"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "It is Contentstack's policy to respect your privacy regarding any information we may collect while operating our Sites and using our Services in accordance with applicable laws."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "After master accounts are terminated, we delete Customer Content data and End User data within 180 days after termination.",
                "says": "Names a period of 180 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Except as expressly set forth in this Privacy Policy, we will not sell or disclose or use End User personal data or content to any third parties without the authorization of the controller."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Except as expressly set forth in this Privacy Policy, we will not sell or disclose or use End User personal data or content to any third parties without the authorization of the controller.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If you have used these sites and have provided consent via their services, you can get more information from the G2 privacy policy, ZoomInfo privacy policy and privacy center and TechTarget privacy policy on your rights and choices."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Please address any questions or concerns regarding data privacy to us at [email protected] or at",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…Data based on the execution of a Data Processing Addendum or other written agreement incorporating EU Standard Contractual Clauses or other applicable terms.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We share personal information for targeted advertising purposes but do not otherwise engage in “sales” of personal information."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Customer content and end user data are deleted within 180 days after a master account is terminated.",
                "quote": "After master accounts are terminated, we delete Customer Content data and End User data within 180 days after termination."
              },
              {
                "date": "2026-10-08",
                "text": "Contentstack says it uses customer content, along with personal data and usage history, to detect fraud, abuse and breaches of its contract terms.",
                "quote": "Contentstack uses Personal Data, Content, Tracking Information, and your usage history to detect fraud, abuse, violation of our contract terms, violation of any laws, rules or regulations"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T17:36:33.652239638Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 535,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 541,
          "p95ms24h": 636,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:38:36.151379976Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "updatedAt": "2026-10-08T17:38:36.151379976Z"
      }
    },
    "verify": {
      "accepts": "a page on contentstack.com or one of its subdomains, or the README of github.com/contentstack/contentstack-openapi",
      "badgeUrl": "https://www.anchorterminal.com/badges/contentstack.svg",
      "body": {
        "slug": "contentstack",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/contentstack",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/contentstack\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/contentstack.svg\" alt=\"Contentstack on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Contentstack on Anchor Terminal](https://www.anchorterminal.com/badges/contentstack.svg)](https://www.anchorterminal.com/tools/contentstack)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/contentstack\"\u003eContentstack on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/contentstack",
    "json": "https://www.anchorterminal.com/tools/contentstack.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/contentstack.md",
    "slim": "https://www.anchorterminal.com/tools/contentstack.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 64/100 · rank #264 of 629 · #6 in CMS \u0026 website publishing · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Contentstack Inc. (https://www.contentstack.com) |\n| Kind | HTTP API |\n| Category | CMS \u0026 website publishing (https://www.anchorterminal.com/categories/cms) |\n| Transport | HTTP, stdio |\n| Endpoint | `https://api.contentstack.io` |\n| Auth | OAuth or key · Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools. |\n| Pricing | Freemium ($29 / mo) · Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT |\n| Tools exposed | 206 |\n| Packages | npm: `@contentstack/mcp`; npm: `@contentstack/management`; pypi: `contentstack-management` |\n| Source | https://github.com/contentstack/contentstack-openapi |\n| Docs | https://www.contentstack.com/docs/developers/apis/content-management-api |\n| llms.txt | https://www.contentstack.com/llms.txt |\n| Last release | 2026-09-22 |\n| npm downloads / week | 43,992 |\n| PyPI downloads / week | 1,504 |\n| Surface graded | The Content Management API (REST, v3), which is generally available. The official MCP server (@contentstack/mcp 0.9.0, local stdio) wraps it and is noted where it differs |\n| Regions | AWS North America (api.contentstack.io), AWS Europe, AWS Australia, Azure North America, Azure Europe, Google Cloud North America and Google Cloud Europe, each with its own contentstack.com host |\n| Credentials | Management token (stack level, read-only or read-write, branch scope, optional expiry, own rate limits), OAuth 2.0 app or user token (authorisation code or client credentials, 60 minutes, refresh grant), or a user authtoken |\n| OAuth scopes | Per module and action, for example cm.entry:read, cm.entry:write, cm.entry:publish, cm.asset:write and cm.content-types.management:write. 28 distinct scopes appear across the 78 tools of the `cma` group |\n| Rate limits | 10 GET requests and 10 write requests a second per organisation, one bulk request a second, one stack creation a minute. Limits vary by plan. Uncached delivery requests are capped at 100 a second per organisation |\n| Pagination | `limit` (default and maximum 100), `skip`, `include_count`, `asc`, `desc`, a JSON `query` filter, and `only[BASE][]` and `except[BASE][]` for field selection |\n| Errors | HTTP status codes with a JSON body. 412 for an invalid API key, 422 for validation errors and unknown fields, 429 for rate limits |\n| Machine-readable contract | OpenAPI 3.0.0 files for the management and delivery APIs linked from github.com/contentstack/contentstack-openapi (MIT). The management file has 138 paths and 221 operations. A Postman collection is linked from the docs |\n| MCP server | 206 tools in ten groups (cma 78, cma-extended 22, cda 4, analytics 8, automations 9, brandkit 12, launch 27, developerhub 12, lytics 10, personalise 24), chosen with `--groups`. OAuth through `npx @contentstack/mcp --auth`, or a management token for the two cma groups. No tool annotations |\n| Content operations | Entries, entry variants, assets and folders, content types, global fields, taxonomies, languages, environments, branches and aliases, releases, bulk publish, workflows, webhooks, roles and audit logs |\n| SDKs | Management SDKs for JavaScript (@contentstack/management 1.31.2, 22 September 2026), Python (contentstack-management 1.11.2, 12 August 2026), Java (1.14.1) and .NET (1.1.1), all MIT, plus the csdx CLI (@contentstack/cli 2.0.2) |\n| Plans | Free (1 stack, 3 users, 100,000 API calls a month, 10 content types, 1,000 entries), Build $29 a month, Growth $299 a month with 10 users and $25 for each extra user, Enterprise by quote |\n| Certifications | SOC 2 Type II and ISO 27001:2022 per contentstack.com/trust. Penetration testing by a third party twice a year. Security reports go to security@contentstack.com |\n| Status | status.contentstack.com on Statuspage, 334 components by cloud, region and service |\n| Sub-processors | List updated 25 May 2026. AWS, Azure, Google Cloud, Fastly, MongoDB, Cloudflare, and OpenAI for Brand Kit only |\n| Capabilities | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema |\n| Tags | hosted, official, mcp, openapi, llms-txt, oauth, free-tier, no-card, closed-source, webhooks, typescript, python, java, dotnet, status-page, soc2, sla |\n| JSON | https://www.anchorterminal.com/api/v1/tools/contentstack.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 71 | 14.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 77 | 12.5 |\n| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |\n| Security \u0026 auth | 14% | 17.5 | 69 | 12.1 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 82 | 7.2 |\n| Transparency \u0026 trust (editorial 59, provenance 87) | 7% | 8.8 | 73 | 6.4 |\n| Negative events | up to −15 | up to −15 | 11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog).  | -3 |\n| **Total** | | | | **64 → B** |\n\n### Why each score\n\n- Reliability 71: Read with the hosted lines and scored on the Content Management API. status.contentstack.com is a Statuspage site with components by cloud, region and service and a full incident history (20). Its feed lists nine incidents with customer impact between 9 July and 7 October 2026, each confined to one or two of the seven regions. The longest on the core APIs was a disruption of the management, delivery and automation APIs on Google Cloud North America on 11 July (74 minutes, marked minor). Webhook delivery on AWS Europe was disrupted for 59 minutes on 28 August (marked critical), and publishing and webhooks on Azure Europe were delayed for 51 minutes on 1 September (marked major). We read that as one major outage with several shorter ones (10). Rate limits have numbers, 10 reads and 10 writes a second per organisation and one bulk request a second (15). The docs say a 429 is returned and name `X-RateLimit-Limit` and `X-RateLimit-Remaining`. No Retry-After header, backoff guidance or idempotency key was found (6 of 15). The Services Description commits to 99.50 or 99.95 per cent monthly availability by plan, with service credits (10). The v3 API is generally available. The MCP server is at version 0.9.0 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 77: An OpenAPI 3.0.0 file for the Content Management API is public, with 138 paths and 221 operations, and every MCP tool has a JSON Schema published at mcp.contentstack.com (25). www.contentstack.com/llms.txt indexes the docs. The full-text export it points to, llms-full.txt, returned 502 on 7 October (8 of 10). Operation descriptions in the spec are long (median 1,189 characters, in HTML) and MCP tool descriptions say what each tool does (median 142 characters in the `cma` group). Few say when not to use a tool (15 of 20). The spec has no enums and no component schemas, and request bodies are examples. The `cma` tool schemas have 369 properties with two enums and 13 untyped objects such as `entry_data`. Version 0.9.0 says it adds enums from the connected stack at run time, which we couldn't see without an account (7 of 15). The spec carries 494 examples but documents only a 200 response for each operation. The docs list status codes in a table (9 of 15). The API version is in the path, and a dated changelog with an RSS feed covers API, SDK and CLI changes. A behaviour change to `limit` shipped inside v3 (13 of 15).\n- Agent ergonomics 67: Responses can be sized with `only[BASE][]`, `except[BASE][]` and `limit`. The MCP server's default group is 78 tools and about 66 KB of schema, split from nine other groups by `--groups` (17 of 25). `limit` up to 100, `skip`, `include_count`, sort and a JSON `query` filter (20). Errors use standard status codes with a JSON body, with 412 and 422 explained in the docs. Error bodies aren't in the spec (12 of 20). No idempotency keys or conditional writes were found, and the MCP package contains no readOnlyHint or destructiveHint annotations. Entries keep version numbers, which helps check a write after a lost response (4 of 20). Management SDKs in JavaScript, Python, Java and .NET. Every call needs two headers and the right regional host (14 of 15).\n- Security \u0026 auth 69: OAuth 2.0 with scopes per module and action (cm.entry:read, cm.entry:write and cm.entry:publish are separate), 60-minute tokens, a refresh grant and revocation by users or organisation admins. Management tokens can be read-only, branch-limited and expiring, and are shown once. PKCE isn't mentioned in the OAuth docs (27 of 30). Read-only tokens and separate publish scopes allow least privilege, and stacks have workflows and publish rules. The MCP server has no read-only switch and no confirmation step, and its default group includes nine delete tools (13 of 20). Entries are written by a stack's own users and can still carry instructions. No prompt-injection guidance was found in the MCP docs (3 of 15). A stack audit log records creates, updates, deletes and publishes by user, with an API endpoint and MCP tools to read it. Its retention period isn't stated (13 of 15). SOC 2 Type II, ISO 27001:2022 and penetration tests twice a year. Reports go to security@contentstack.com with a stated 24-hour response, and SDK security fixes are listed in the changelog with CVE numbers. security.txt returns 404 and no bug bounty was found. We didn't search NVD (13 of 20).\n- Payments \u0026 pricing 30: Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login ($0, $29 and $299 a month, with included API calls stated). Build mentions pay-as-you-go overages and no unit rate is shown (10). The Free plan needs no card and doesn't expire. We didn't run the sign-up form to confirm it (20). A person signs up in a browser, verifies an email address and creates the token or approves OAuth (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 82: The JavaScript management SDK 1.31.2 was released on 22 September 2026, and the changelog's newest entry is 1 October 2026 (30). Dated entries in the last 90 days include the `limit` change on 11 September, recursive embedded items on 7 September, webhook HMAC signing on 30 July and more than ten SDK and CLI releases (20). Closed service with a public changelog and RSS feed, email support and a Discord community. We didn't test a support channel (10 of 15). Official management SDKs in four languages, all with releases since 27 July 2026. The MCP server isn't in the official MCP registry, which returned no result for Contentstack (15). The JavaScript SDK repository has unit-test, CodeQL and dependency-scan workflows, and its changelog shows regular dependency fixes. We didn't see the CI results (7 of 10).\n- Transparency \u0026 trust 73: The service is closed under a Master Agreement last updated 17 July 2026 and Terms of Service from August 2022. The spec, SDKs, CLI and MCP package are MIT, though the MCP repository named on npm isn't public (15). The privacy policy of 30 June 2026 says customer content is deleted within 180 days of termination, data processing agreements for the US and for EMEA are published, and the AI addendum of 27 July 2026 says customer data isn't used to train general AI models. The older Terms of Service only say access to content ends on termination (24 of 30). No deprecation policy with a notice period was found. The Services Description lets Contentstack end a service during a term with a pro-rata refund, and the `limit` change was announced on the day it applied (5 of 20). The sub-processor list was updated on 25 May 2026 with purposes and locations. It gives the United States for Azure and Google Cloud although both have European regions in the API docs, and the page states no notice period for changes (15 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/contentstack.md (JSON https://www.anchorterminal.com/fixes/contentstack.json)\n\n### What we couldn't check\n\n- unchecked: the endpoint-level API reference on the docs site, which renders in the browser. We read the introduction and the OpenAPI file\n- unchecked: https://www.contentstack.com/llms-full.txt returned 502 on 7 October 2026\n- unchecked: GitHub star counts, and whether CI passes on the SDK repositories\n- unchecked: the sign-up form itself. The pricing page says no card is required\n- unchecked: NVD and GitHub advisories for Contentstack packages\n- unchecked: whether customers were told by email before the 11 September 2026 `limit` change. Only the public changelog was read\n- The docs disagree on how many management tokens a stack may hold. The API page says 10 and the token guide says 30\n- The run-time enrichment of MCP tool schemas in 0.9.0 needs a connected stack, so we graded the static definitions\n- The Enterprise card on the pricing page says 99.5 per cent uptime while the Services Description names plans (Start, Grow, Scale, X1, X3, X5) that don't match the pricing page's plan names. Whether Free, Build and Growth carry any commitment wasn't established\n\n### Sources\n\n- Content Management API docs (auth, rate limits, errors, regions): \u003chttps://www.contentstack.com/docs/developers/apis/content-management-api\u003e (seen 2026-10-07)\n- OpenAPI files repository: \u003chttps://github.com/contentstack/contentstack-openapi\u003e (seen 2026-10-07)\n- MCP server docs: \u003chttps://www.contentstack.com/docs/agent-os/contentstack-mcp-server\u003e (seen 2026-10-07)\n- MCP package, README and versions: \u003chttps://registry.npmjs.org/@contentstack/mcp\u003e (seen 2026-10-07)\n- MCP tool definitions, cma group: \u003chttps://mcp.contentstack.com/cma/tools\u003e (seen 2026-10-07)\n- status incident feed: \u003chttps://status.contentstack.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.contentstack.com/pricing\u003e (seen 2026-10-07)\n- changelog and RSS feed: \u003chttps://www.contentstack.com/docs/changelog\u003e (seen 2026-10-07)\n- management tokens: \u003chttps://www.contentstack.com/docs/developers/create-tokens/create-a-management-token\u003e (seen 2026-10-07)\n- OAuth: \u003chttps://www.contentstack.com/docs/developers/developer-hub/contentstack-oauth\u003e (seen 2026-10-07)\n- audit log: \u003chttps://www.contentstack.com/docs/developers/set-up-stack/monitor-stack-activities-in-audit-log\u003e (seen 2026-10-07)\n- trust page: \u003chttps://www.contentstack.com/trust\u003e (seen 2026-10-07)\n- Services Description (SLA, end of life): \u003chttps://www.contentstack.com/legal/services-description\u003e (seen 2026-10-07)\n- Master Agreement: \u003chttps://www.contentstack.com/legal/master-subscription-agreement\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://www.contentstack.com/legal/privacy\u003e (seen 2026-10-07)\n- sub-processors: \u003chttps://www.contentstack.com/legal/subprocessors\u003e (seen 2026-10-07)\n- AI addendum: \u003chttps://www.contentstack.com/legal/artificial-intelligence-addendum\u003e (seen 2026-10-07)\n- JavaScript management SDK repository: \u003chttps://github.com/contentstack/contentstack-management-javascript\u003e (seen 2026-10-07)\n- llms.txt: \u003chttps://www.contentstack.com/llms.txt\u003e (seen 2026-10-07)\n- security.txt (404): \u003chttps://www.contentstack.com/.well-known/security.txt\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 87/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Contentstack Inc. | 20/20 |\n| Domain age | contentstack.com, registered 2011-10-29 (14 years) | 15/15 |\n| Endpoint on the vendor's domain | api.contentstack.io | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.contentstack.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.\n\nThe Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.\n\nThe online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).\n\nwww.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.\n\nRDAP for contentstack.com gives a registration date of 2011-10-29.\n\nThe npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.contentstack.com/legal/terms-of-service), read 2026-10-08, dated 2022-08-01, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(j) access any part of the Contentstack Service in order to build a competitive product or service\"\n- To know. Says access can be ended without notice or for any reason. \"Contentstack may terminate your access to all or any part of the Contentstack Service at any time.\"\n- To know. Requires arbitration or waives class actions. \"The arbitration shall take place in San Francisco, California, in the English language and the arbitral decision may be enforced in any court.\"\n- To know. Has not been updated for three years or more. \"Effective Date: August 2022\"\n- Gives the date it was last updated. Last updated 2022-08-01.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Contentstack may show the customer's company name and logo and links to its application for marketing, without notice or payment, and the customer can ask to be excluded. \"Contentstack reserves and you grant Contentstack the right to display links to your application or website and the name/logo of your company for marketing purposes and may do so without notice or compensation.\"\n- Also in the text (2026-10-08). When the agreement ends the customer loses access to all content in the account, and saving that content beforehand is the customer's responsibility. \"Upon effective termination of the Agreement you forfeit and relinquish access to all content in your account.\"\n- Also in the text (2026-10-08). Paid subscriptions renew automatically at the fee that applies at the time of renewal unless the customer cancels before the period ends. \"your purchased service subscription will automatically renew and you authorize us to collect the then-applicable annual or monthly subscription fee for such Purchased Services\"\n\n**Privacy policy** (https://www.contentstack.com/legal/privacy), read 2026-10-08, dated 2026-06-30, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We share personal information for targeted advertising purposes but do not otherwise engage in “sales” of personal information.\"\n- Gives the date it was last updated. Last updated 2026-06-30.\n- Says how long data is kept. Names a period of 180 days.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Customer content and end user data are deleted within 180 days after a master account is terminated. \"After master accounts are terminated, we delete Customer Content data and End User data within 180 days after termination.\"\n- Also in the text (2026-10-08). Contentstack says it uses customer content, along with personal data and usage history, to detect fraud, abuse and breaches of its contract terms. \"Contentstack uses Personal Data, Content, Tracking Information, and your usage history to detect fraud, abuse, violation of our contract terms, violation of any laws, rules or regulations\"\n\n## Live (updated 2026-10-08 17:38 UTC)\n\n- Right now: up, HTTP 404, 535 ms, checked 2026-10-08 17:36 UTC (get on `https://api.contentstack.io`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 541 ms · p95 636 ms\n- Vendor status page: none, All Systems Operational\n- npm `@contentstack/management` 1.31.2\n- npm `@contentstack/mcp` 0.9.0\n- pypi `contentstack-management` 1.11.2, released 2026-08-12\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/contentstack.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Build | $29 | per month (plan) | 3 users, 250,000 API calls a month |\n| Growth | $299 | per month (plan) | 10 users, 1M API calls a month |\n| Growth, each extra user | $25 | per seat per month | beyond the 10 included |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant\n- Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits\n- Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026\n- Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com\n- Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API\n- Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description\n\n## Weaknesses\n\n- The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n- On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day\n- The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples\n- No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining\n- No security.txt and no bug bounty were found, and no deprecation policy with a notice period\n- Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions\n\n## Before you call it (notes for agents)\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n## Connect\n\nInstall:\n\n```bash\nnpx -y @contentstack/mcp\n```\n\nFirst request:\n\n```bash\ncurl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"contentstack\": {\n      \"args\": [\n        \"-y\",\n        \"@contentstack/mcp\"\n      ],\n      \"command\": \"npx\",\n      \"env\": {\n        \"CONTENTSTACK_API_KEY\": \"\\u003cYOUR_STACK_API_KEY\\u003e\",\n        \"GROUPS\": \"cma\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/contentstack. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Sanity | BB | 73.7 | 69 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/sanity.md |\n| Webflow | B | 69.4 | 150 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/webflow.md |\n| Storyblok | B | 67.7 | 188 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/storyblok.md |\n| Strapi | B | 65.7 | 231 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | no | https://www.anchorterminal.com/tools/strapi.md |\n| WordPress | B | 64.8 | 249 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/wordpress.md |\n| Ghost | C | 58.3 | 404 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/ghost.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The Content Management API answers on seven regional hosts across AWS, Azure and Google Cloud, with `api_key` plus a management token, OAuth token or user authtoken in headers (source: \u003chttps://www.contentstack.com/docs/developers/apis/content-management-api\u003e)\n- The MCP server is the npm package @contentstack/mcp, version 0.9.0 of 13 July 2026, run locally over stdio with `npx`. It has 206 tools in ten groups and loads the 78-tool `cma` group by default (source: \u003chttps://www.npmjs.com/package/@contentstack/mcp\u003e)\n- Contentstack publishes the MCP tool definitions, with input schemas, request mappings and OAuth scopes, at unauthenticated URLs such as https://mcp.contentstack.com/cma/tools\n- Default rate limits are 10 reads and 10 writes a second per organisation and one bulk request a second, with `X-RateLimit-Limit` and `X-RateLimit-Remaining` headers (source: \u003chttps://www.contentstack.com/docs/developers/apis/content-management-api\u003e)\n- Self-serve sign-up and a free plan started on 16 September 2026. Free is $0 with no card, Build $29 a month and Growth $299 a month (source: \u003chttps://www.contentstack.com/pricing\u003e)\n- A changelog entry dated 11 September 2026 says `limit=0` on delivery and management requests now returns the default number of records where it used to return all of them (source: \u003chttps://www.contentstack.com/docs/changelog\u003e)\n- The Services Description of 28 July 2026 commits to 99.50 per cent monthly availability on Start, Grow, X1 and X3 plans and 99.95 per cent on Scale and X5, with service credits (source: \u003chttps://www.contentstack.com/legal/services-description\u003e)\n- SOC 2 Type II, ISO 27001:2022 and third-party penetration tests twice a year are listed on the trust page (source: \u003chttps://www.contentstack.com/trust\u003e)\n\n## Compare\n\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md): B 64 vs C 58.3\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md): B 64 vs BB 73.7\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md): B 64 vs B 67.7\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md): B 64 vs B 65.7\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md): B 64 vs B 69.4\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md): B 64 vs B 64.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on contentstack.com or one of its subdomains, or the README of github.com/contentstack/contentstack-openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"contentstack\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/contentstack\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/contentstack.svg\" alt=\"Contentstack on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Contentstack on Anchor Terminal](https://www.anchorterminal.com/badges/contentstack.svg)](https://www.anchorterminal.com/tools/contentstack)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/contentstack\"\u003eContentstack on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Contentstack is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/contentstack-dark.png\n- Light: https://www.anchorterminal.com/assets/share/contentstack-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CMS \u0026 website publishing",
        "url": "https://www.anchorterminal.com/categories/cms"
      },
      {
        "name": "Contentstack",
        "url": ""
      }
    ],
    "description": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
    "facts": [
      "rank #264 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Contentstack",
    "image": "https://www.anchorterminal.com/assets/og/tools-contentstack.png",
    "path": "/tools/contentstack",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack review for AI agents, grade B (64/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/contentstack"
  },
  "tokens": {
    "markdown": 8550,
    "slim": 2080
  },
  "version": 1
}
