# DatoCMS (slim) > DatoCMS is a hosted headless CMS from Dato Srl in Milan. Agents write records, assets, locales and schema through the REST Content Management API, the datocms CLI or a hosted MCP server, and read through a GraphQL Content Delivery API. - Full: https://www.anchorterminal.com/tools/datocms.md (~7,800 tokens) · this version ~2,180 tokens · JSON https://www.anchorterminal.com/tools/datocms.json · canonical https://www.anchorterminal.com/tools/datocms - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 74.4/100 · rank #62 of 722 · #1 in CMS & website publishing · agent-ready · confidence medium** Assessment: The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route. ## Facts - Kind: HTTP API · vendor: Dato Srl · category: CMS & website publishing · legal entity: Dato Srl · provenance 94/100 - Endpoint: `https://site-api.datocms.com` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Dato Srl's terms of service. The API clients in datocms/js-rest-api-clients and the CLI in datocms/cli are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: Content Management API v3 (REST, JSON:API) at https://site-api.datocms.com for writes, hosted MCP server at https://mcp.datocms.com, `datocms` CLI with `cma:call`, `cma:script`, `cma:docs` and `schema:inspect`, GraphQL Content Delivery API at https://graphql.datocms.com for reads - MCP server: Hosted, streamable HTTP, OAuth only. Tools named in the docs are `search_projects`, `list_api_resources`, `get_api_methods`, `get_schema`, `upsert_and_execute_safe_script`, `view_script`, `upsert_and_execute_unsafe_script`, `whoami` and `report_api_issue`. Single sign-on accounts are not supported - Credentials: API tokens created in project settings, each bound to a role, sent as a Bearer header. Tokens can be rotated in the interface or by API. MCP uses OAuth through oauth.datocms.com with PKCE S256, dynamic client registration, revocation and introspection - Roles: Admin and Editor by default, custom roles by model, action (create, update, delete, publish) and environment. Locale-specific permissions are Enterprise only - Rate limits: 60 requests every 3 seconds on the Content Management API. Shared infrastructure can return 429 under high load even inside the limit - Free plan: No card. Per the pricing page, 300 records, 5 locales, 100 models, 3 sandbox environments, 25,000 Content Management API calls and 100,000 Content Delivery API calls a month, 200 MB of files. No overage. A project at its limit is suspended until the next month - Paid plans: Professional €199 a month, or €149 a month billed yearly, with 100,000 records and 100,000 Content Management API calls a month. Overage €9 per extra 100,000 Content Management API calls, €9 per extra 1M Content Delivery API calls, €19 per extra locale. Enterprise is priced through sales - Drafts and versions: Draft and published states per model, publish and unpublish as PUT requests, bulk publish, scheduled publication, version list and restore. History kept 3 days on Free and 60 days on Professional - Assets: Upload permission request, file upload to storage, then upload creation, wrapped by `createFromLocalFile` and `createFromUrl` in the JavaScript client. Maximum 1 GB an asset - Localisation: Per-field localisation with all locales written in one record payload. 5 locales included on Free and Professional - Environments: Primary and sandbox environments with fork, promote, rename and delete endpoints, and a maintenance mode that makes the primary read-only - Pagination: Offset based, `page[limit]` and `page[offset]`, with `meta.total_count`. Records default to 30 a page, and the documented maximum varies by endpoint. Filters by ids, model, text query and field values - Errors: JSON body with `code`, `doc_url`, `details` and an optional `transient` flag. 100 codes documented, among them `STALE_ITEM_VERSION`, `RATE_LIMIT_EXCEEDED` and `PLATFORM_SCHEDULED_MAINTENANCE` - SDKs: @datocms/cma-client 6.8.0 (1 October 2026) with Node and browser builds, @datocms/cda-client 0.3.2, CLI `datocms` 4.2.0 (31 August 2026). JavaScript and TypeScript only, MIT - Audit: Audit logs on Enterprise, queryable by API, default retention two months. Record versions show who saved and published - SLA: The pricing page lists guaranteed uptime SLAs on Enterprise. No figure is published - Certifications: ISO 27001, certificate on request. No SOC 2 report of its own or bug bounty found in the reviewed pages - Data location: AWS eu-west-1 (Ireland), backups in eu-west-3 (France), assets in Cloudflare R2 under EU jurisdiction. The GDPR page lists 22 third-party services with the data each receives - Open source: No. The API clients and CLI are MIT - Scores: Reliability 80, Performance pending, Schema & documentation 85, Agent ergonomics 78, Security & auth 77, Payments & pricing 35, Task success pending, Maintenance & community 81, Transparency & trust 80 · total over the 7 assessed categories - Why: Reliability, Graded on the Content Management API, with the hosted MCP server noted. · Schema & documentation, A public JSON Hyper-Schema describes 53 resources and 202 operations. · Agent ergonomics, List responses are sized with `page[limit]` and a `nested` switch for block content. · Security & auth, API tokens bound to custom roles, revocable and rotatable by API, sent only as a Bearer header. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, @datocms/cma-client 6.8.0 was tagged on 1 October 2026 and the product changelog has an entry the same day (30). · Transparency & trust, Closed service with published terms for the Free and Professional plans, and MIT clients and CLI. - Sources: 36, open questions: 8, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/datocms.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/datocms.svg` or a link to https://www.anchorterminal.com/tools/datocms from a page on datocms.com or one of its subdomains, or the README of github.com/datocms/js-rest-api-clients, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `X-Api-Version: 3` and `Accept: application/json` on every request, with `Content-Type: application/vnd.api+json` on writes 2. Records are `items`, models are `item_types` and assets are `uploads` in every path and payload 3. Save a record, then call the publish endpoint as a separate PUT. Send `meta.current_version` on updates and re-fetch on `STALE_ITEM_VERSION` 4. Stay under 60 requests every 3 seconds. On 429 wait the seconds in `x-ratelimit-reset`, and retry any error whose body has `transient` set to true 5. Fork a sandbox environment for schema changes and promote it when checked. Use `POST /items/validate` to test a payload without saving it ## Connect ```bash npm install @datocms/cma-client-node ``` ```bash curl \ -H 'Authorization: Bearer ' \ -H 'Accept: application/json' \ -H 'X-Api-Version: 3' \ https://site-api.datocms.com/site ``` ```bash claude mcp add --transport http DatoCMS https://mcp.datocms.com ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/datocms ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | https://www.anchorterminal.com/tools/directus.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)