# Contentstack (slim) > Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents. - Full: https://www.anchorterminal.com/tools/contentstack.md (~8,550 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/contentstack.json · canonical https://www.anchorterminal.com/tools/contentstack - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 64/100 · rank #264 of 629 · #6 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice. ## Facts - Kind: HTTP API · vendor: Contentstack Inc. · category: CMS & website publishing · legal entity: Contentstack Inc. · provenance 87/100 - Endpoint: `https://api.contentstack.io` (HTTP, stdio) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT - Probe metrics: not measured yet (probes haven't run) - Surface graded: The Content Management API (REST, v3), which is generally available. The official MCP server (@contentstack/mcp 0.9.0, local stdio) wraps it and is noted where it differs - Regions: AWS North America (api.contentstack.io), AWS Europe, AWS Australia, Azure North America, Azure Europe, Google Cloud North America and Google Cloud Europe, each with its own contentstack.com host - Credentials: Management token (stack level, read-only or read-write, branch scope, optional expiry, own rate limits), OAuth 2.0 app or user token (authorisation code or client credentials, 60 minutes, refresh grant), or a user authtoken - OAuth scopes: Per module and action, for example cm.entry:read, cm.entry:write, cm.entry:publish, cm.asset:write and cm.content-types.management:write. 28 distinct scopes appear across the 78 tools of the `cma` group - Rate limits: 10 GET requests and 10 write requests a second per organisation, one bulk request a second, one stack creation a minute. Limits vary by plan. Uncached delivery requests are capped at 100 a second per organisation - Pagination: `limit` (default and maximum 100), `skip`, `include_count`, `asc`, `desc`, a JSON `query` filter, and `only[BASE][]` and `except[BASE][]` for field selection - Errors: HTTP status codes with a JSON body. 412 for an invalid API key, 422 for validation errors and unknown fields, 429 for rate limits - Machine-readable contract: OpenAPI 3.0.0 files for the management and delivery APIs linked from github.com/contentstack/contentstack-openapi (MIT). The management file has 138 paths and 221 operations. A Postman collection is linked from the docs - MCP server: 206 tools in ten groups (cma 78, cma-extended 22, cda 4, analytics 8, automations 9, brandkit 12, launch 27, developerhub 12, lytics 10, personalise 24), chosen with `--groups`. OAuth through `npx @contentstack/mcp --auth`, or a management token for the two cma groups. No tool annotations - Content operations: Entries, entry variants, assets and folders, content types, global fields, taxonomies, languages, environments, branches and aliases, releases, bulk publish, workflows, webhooks, roles and audit logs - SDKs: Management SDKs for JavaScript (@contentstack/management 1.31.2, 22 September 2026), Python (contentstack-management 1.11.2, 12 August 2026), Java (1.14.1) and .NET (1.1.1), all MIT, plus the csdx CLI (@contentstack/cli 2.0.2) - Plans: Free (1 stack, 3 users, 100,000 API calls a month, 10 content types, 1,000 entries), Build $29 a month, Growth $299 a month with 10 users and $25 for each extra user, Enterprise by quote - Certifications: SOC 2 Type II and ISO 27001:2022 per contentstack.com/trust. Penetration testing by a third party twice a year. Security reports go to security@contentstack.com - Status: status.contentstack.com on Statuspage, 334 components by cloud, region and service - Sub-processors: List updated 25 May 2026. AWS, Azure, Google Cloud, Fastly, MongoDB, Cloudflare, and OpenAI for Brand Kit only - Prices: Build $29 per month (plan); Growth $299 per month (plan); Growth, each extra user $25 per seat per month - Scores: Reliability 71, Performance pending, Schema & documentation 77, Agent ergonomics 67, Security & auth 69, Payments & pricing 30, Task success pending, Maintenance & community 82, Transparency & trust 73 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the Content Management API. · Schema & documentation, An OpenAPI 3.0.0 file for the Content Management API is public, with 138 paths and 221 operations, and every MCP tool has a JSON Schema publ… · Agent ergonomics, Responses can be sized with `only[BASE][]`, `except[BASE][]` and `limit`. · Security & auth, OAuth 2.0 with scopes per module and action (cm.entry:read, cm.entry:write and cm.entry:publish are separate), 60-minute tokens, a refresh g… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The JavaScript management SDK 1.31.2 was released on 22 September 2026, and the changelog's newest entry is 1 October 2026 (30). · Transparency & trust, The service is closed under a Master Agreement last updated 17 July 2026 and Terms of Service from August 2022. The spec, SDKs, CLI and MCP… - Sources: 20, open questions: 9, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/contentstack.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/contentstack.svg` or a link to https://www.anchorterminal.com/tools/contentstack from a page on contentstack.com or one of its subdomains, or the README of github.com/contentstack/contentstack-openapi, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts 2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads 3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything 4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429 5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation ## Connect ```bash npx -y @contentstack/mcp ``` ```bash curl "https://api.contentstack.io/v3/content_types" \ -H "api_key: $CONTENTSTACK_API_KEY" -H "authorization: $CONTENTSTACK_MANAGEMENT_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/contentstack ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | | WordPress | B | 64.8 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/wordpress.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)