Directus

by Monospace Inc. (Directus) HTTP API in CMS & website publishing

Monospace Inc. · directus.com since 1997 · status page · who's behind it

Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.

Good for Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.

Is this your product? Claim this listing or verify it

Assessment. The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.

Facts

Transport
HTTP, Streamable HTTP
Auth
OAuth or key
Pricing
Freemium · $499 / mo
x402
No
Licence
MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT
Tools exposed
12
Packages
npm directus
npm @directus/sdk
npm @directus/specs
llms.txt
published
Last release
GitHub stars
38k
npm / week
23k
Graded surface
Self-hosted Directus 12.5.0 on the free Core tier, through the built-in MCP server and the REST API. Directus Cloud hosts the same software as a paid add-on
MCP server
Built in from v11.12 at /mcp, off by default and enabled under Settings, AI, Model Context Protocol. Default mode lists every tool. Registry mode (/mcp?tool_mode=registry) lists search, execute and schema
MCP tools
system-prompt, items, files, folders, assets, flows, trigger-flow, operations, schema, collections, fields, relations. Each takes an action (create, read, update, delete, and import for files). Stored prompts can be served from a chosen collection
REST and GraphQL
Generated from the database schema. /items/{collection}, /files, /collections, /fields, /relations, /versions, /revisions, /activity and others, 70 paths in the OpenAPI file. Each instance serves its own spec at /server/specs/oas
Credentials
MCP OAuth with PKCE (scope mcp:access, MCP endpoint only), static tokens (one per user, no expiry), log-in access and refresh tokens, session cookies, and third-party JWTs. Sent as Authorization: Bearer, a cookie or ?access_token=
Permissions
Access policies per role or user, by collection, action, field and item rule. MCP calls run as the connected user. Allow Deletes is a separate MCP setting, off by default
Draft and publish
Content versioning per collection, with reserved draft and published keys, ?version= on reads, and POST /versions/{id}/save, /compare and /promote. Published items in versioned collections are locked from direct edits since v12
Localisation
Translations are a related collection per content collection, written as nested translations data. AI translation in the Studio is an Enterprise feature
Assets
POST /files (multipart) and import from a URL, which the MCP files tool also does. The assets tool returns file content as base64. Storage adapters for local disk, S3, GCS, Azure, Cloudinary and Supabase
Audit
Activity log with user, action, time, IP address, user agent, collection and item, plus revisions per change. Kept 30 days on Core, 90 on Team and configurable on Enterprise
Rate limits
Off by default. RATE_LIMITER_ENABLED allows 50 requests a second per IP and a global pool of 1,000, with Retry-After on 429. MCP OAuth authorisation is limited to 60 requests and client registration to 30 per window. A pressure limiter answers 503 under load
Errors
{errors: [{message, extensions: {code}}]} with codes such as FORBIDDEN, FAILED_VALIDATION, INVALID_PAYLOAD and COLLECTION_INACTIVE. Missing items answer FORBIDDEN, not 404
Licensing
Core runs with no key. Paid tiers and the grant use LICENSE_KEY, bound to PUBLIC_URL and revalidated with licensing.directus.com at least every 12 hours. Offline tokens are Enterprise only
Telemetry
A report every 6 hours to telemetry.directus.io with the public URL, version, database vendor, counts and feature flags. TELEMETRY=false opts out where the licence allows. Project owner registration has its own switch, PROJECT_OWNER_ENABLED
Runtime
Docker image directus/directus, Node.js 22 or later, with PostgreSQL, MySQL, MariaDB, SQLite, MS SQL Server, CockroachDB or OracleDB. Redis for caching and horizontal scaling
SDK
@directus/sdk 27.0.0 for JavaScript and TypeScript, MIT. An older stdio MCP server, @directus/content-mcp 0.1.0, remains for instances before v11.12
Directus Cloud
$99 a month hosting add-on for Core, Team and the grant, with Enterprise priced by sales. Statuspage at status.directus.cloud. The Cloud policies give no uptime commitment to self-service projects

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • MCP OAuth with PKCE issues tokens with the mcp:access scope and the MCP endpoint as audience, and administrators can revoke registered clients
  • Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default
  • Registry mode at /mcp?tool_mode=registry cuts the tool list to search, execute and schema
  • Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change
  • Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs

Weaknesses

  • Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period
  • The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key
  • Static tokens never expire, are stored in plain text in directus_users, and the MCP guide shows them in the URL as ?access_token=
  • Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes
  • At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high

Before you call it notes for agents

  1. Connect with OAuth or an Authorization: Bearer header. Don't put the token in the URL as ?access_token=, where it can be logged
  2. Use /mcp?tool_mode=registry when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total
  3. Read the schema tool before writing. Item payloads are untyped objects, so field names and types come only from the data model
  4. Publish a version with POST /versions/{id}/promote over REST. The MCP items tool refuses system collections such as directus_versions
  5. Count translation and junction tables against the 25-collection Core limit before creating collections

Who's behind it provenance 66/100

  • Legal entity namedMonospace Inc. (doing business as Directus)20/20
  • Domain agedirectus.com, registered 1997-02-06 (29 years)15/15
  • Endpoint on the vendor's domain is not on directus.com0/15
  • Terms of serviceread, states 1 of the 7 things a reader expects, and has 1 clause that costs points2.9/10
  • Privacy policyread, states 5 of the 8 things a reader expects7.8/10
  • Status pagestatus.directus.cloud10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 1 of 7, 1 to know

TL;DR Gives no date. States 1 of the 7 things a reader expects, and we didn't find the governing law, a liability limit, how it ends, how changes are announced or a service level. To know before relying on it, limits on benchmarking.

Restricts benchmarking or competitive usecosts points
A Permitted Purpose is any purpose other than a Competing Use.

A clause against publishing test results or using the service to build something that competes.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts

Not found in the text.

Says where a dispute would be heard and under whose law.

States a limit on its liability

Not found in the text.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended

Not found in the text.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
You must not move, change, disable or circumvent the license key functionality of the Software or modify any portion of the Software protected by the license key to:

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

The document is a licence for the Directus software and excludes all liability of the licensor arising from the software.
IN NO EVENT WILL WE HAVE ANY LIABILITY TO YOU ARISING OUT OF OR RELATED TO THE SOFTWARE, INCLUDING INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES, EVEN IF WE HAVE BEEN INFORMED OF THEIR POSSIBILITY IN ADVANCE.

Noted by a second reader on 2026-10-08.

Each version of the software also becomes usable under GPL-3.0 four years after it is made available.
We hereby irrevocably grant you an additional license to use the Software under the GNU General Public License version 3 (GPL-3.0), effective on the fourth anniversary of the date we make the Software available.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 1,032 words

Privacy policy dated 2026-06-09, states 5 of 8

TL;DR Dated 2026-06-09. States 5 of the 8 things a reader expects, and we didn't find how long data is kept, a privacy contact or where data goes. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-06-09
Last Updated: June 9, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
Please review our Privacy Policy which helps you understand the information we collect and receive, how we use it and the choices you have.

The basic statement a privacy policy exists to make.

Says how long data is kept

Not found in the text.

Says when data sent to the service is deleted.

Says who else receives the data
We may utilize the services of third parties and provide some of our services through contractual arrangements with affiliates, service providers, partners, and other third parties, and to facilitate such arrangements we reserve the right to share with such third parties Personally Identifiable Information.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
Nevada residents may email questions regarding our practices relating to personal information to info@directus.io

A plain statement either way.

Says what rights people have over their data
If you are a California resident, you have the right, subject to certain exceptions defined in the California Consumer Privacy Act (“CCPA”) and other applicable laws and regulations, to request that Directus disclose certain information to you about our collection and use of your personal information over the past twe…

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact

Not found in the text.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

The policy covers the Directus website, and personal information processed for customers of the product is handled under customer agreements instead.
When we process personal information in the course of providing the Directus Solution to our Customers, we do so pursuant to our agreements with our Customers, not this Privacy Policy.

Noted by a second reader on 2026-10-08.

For US residents, data partners may use cookies to link site visits to an email or home address, which Directus may then use for marketing, with an opt-out link.
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email or home address.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 3,459 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.

terms points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.

The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.

A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.

https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.

RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.

The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:05 UTC

  • Vendor status page all systems normal, All Systems Operational · 6 minutes ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/directus.json

Notable

  • The MCP server is built into Directus from v11.12, off by default, and answers at /mcp with 12 tools, or at /mcp?tool_mode=registry with search, execute and schema source
  • MCP OAuth issues a token with the mcp:access scope and the MCP endpoint as audience, and administrators can review and revoke registered clients source
  • Version 12.0.0 (10 June 2026) introduced licence enforcement. An instance over its tier limits after the grace period blocks /items and disables GraphQL, WebSockets and MCP source
  • The free Core tier allows 3 Studio seats, 25 collections and 5 flows, with activity logs and revisions kept 30 days. API-only users don't count as seats source
  • The docs say releases don't follow semantic versioning, so any release may include breaking changes source
  • Advisory GHSA-97xr-jchp-xm3c, rated critical, was published on 5 August 2026 for versions before 12.1.0 source
  • Telemetry reports the instance's public URL and usage counts every 6 hours, and the TELEMETRY=false opt-out applies only where the licence allows it source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.4
Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image directus/directus and npm package directus 12.5.0, with Node.js 22 or later in engines and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.2
An OpenAPI file ships in @directus/specs with 70 paths, each instance serves its own at /server/specs/oas, and every MCP tool has a typed input schema. The spec's info.version still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a prompt.md of instructions with worked examples, up to 13 KB for flows, and a system-prompt tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, deep, and field schema and meta are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).
Agent ergonomics 13%16.2 11.9
Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). limit (default 100), offset, page, fields, filter, search, sort and aggregate, with QUERY_LIMIT_MAX as a server cap (20). One error shape with a machine-readable extensions.code. Missing items answer FORBIDDEN, not 404, by design (17 of 20). Tools set readOnlyHint and destructiveHint, though one items tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, @directus/sdk for JavaScript and TypeScript (8 of 15).
Security & auth 14%17.5 11.9
MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single mcp:access scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because ?access_token= in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).
Payments & pricing 10%12.5 6.9
Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). ADMIN_EMAIL, ADMIN_PASSWORD and ADMIN_TOKEN create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.5
v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). @directus/sdk 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).
Transparency & trusteditorial 55, provenance 66 7%8.8 5.3
The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20).
Negative events≤15
  • 5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories
-6
Total67.1 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 22 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Directus, or have the agent fetch /fixes/directus.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Directus

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/directus, the October 2026 research run, assessed 8 October 2026. Grade B, 67.1 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Directus: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Security & auth, 68 out of 100, up to 5.6 more on the total

Why it scored 68: MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 2. Payments & pricing, 55 out of 100, up to 5.6 more on the total

Why it scored 55: Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Agent ergonomics, 73 out of 100, up to 4.4 more on the total

Why it scored 73: Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Reliability, 82 out of 100, up to 3.6 more on the total

Why it scored 82: Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 5. Transparency & trust, 61 out of 100, up to 3.4 more on the total

Made of editorial 55, provenance 66.

Why it scored 61: The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Endpoint on the vendor's domain:  is not on directus.com (0 of 15)
- Terms of service: read, states 1 of the 7 things a reader expects, and has 1 clause that costs points (2.9 of 10)
- Privacy policy: read, states 5 of the 8 things a reader expects (7.8 of 10)
- security.txt: not found (0 of 10)

## 6. Schema & documentation, 81 out of 100, up to 3.1 more on the total

Why it scored 81: An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 7. Maintenance & community, 86 out of 100, up to 1.2 more on the total

Why it scored 86: v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the official MCP registry search for Directus timed out twice from our network
- unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages
- unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown
- unchecked: whether the 14-day Directus Cloud trial asks for a card
- We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through `PATCH /settings` is inferred from the `mcp_enabled` settings field, not from the docs
- The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12
- directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so `provenance.terms` points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies
- The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes
- The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise
- The repository's `security.md` gives security@directus.io while the docs give security@directus.com

## Weaknesses

- Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period
- The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key
- Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`
- Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes
- At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged
- Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total
- Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model
- Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`
- Count translation and junction tables against the 25-collection Core limit before creating collections

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the official MCP registry search for Directus timed out twice from our network
  • unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages
  • unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown
  • unchecked: whether the 14-day Directus Cloud trial asks for a card
  • We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through PATCH /settings is inferred from the mcp_enabled settings field, not from the docs
  • The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12
  • directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so provenance.terms points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies
  • The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes
  • The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise
  • The repository's security.md gives security@directus.io while the docs give security@directus.com

Sources 33

  1. MCP overview directus.com · seen 2026-10-08
  2. MCP installation, tool modes and settings directus.com · seen 2026-10-08
  3. MCP tools directus.com · seen 2026-10-08
  4. MCP OAuth directus.com · seen 2026-10-08
  5. MCP security guide directus.com · seen 2026-10-08
  6. access tokens directus.com · seen 2026-10-08
  7. activity log directus.com · seen 2026-10-08
  8. errors directus.com · seen 2026-10-08
  9. query parameters directus.com · seen 2026-10-08
  10. content versioning directus.com · seen 2026-10-08
  11. rate limiting configuration directus.com · seen 2026-10-08
  12. licensing overview directus.com · seen 2026-10-08
  13. telemetry directus.com · seen 2026-10-08
  14. release policy directus.com · seen 2026-10-08
  15. breaking changes in version 12 directus.com · seen 2026-10-08
  16. changelog directus.com · seen 2026-10-08
  17. security reporting directus.com · seen 2026-10-08
  18. docs index for agents directus.com · seen 2026-10-08
  19. pricing directus.com · seen 2026-10-08
  20. licence text directus.com · seen 2026-10-08
  21. terms directus.com · seen 2026-10-08
  22. privacy policy directus.com · seen 2026-10-08
  23. Cloud policies directus.com · seen 2026-10-08
  24. trust centre trust.directus.com · seen 2026-10-08
  25. Directus Cloud status incidents status.directus.cloud · seen 2026-10-08
  26. repository, licence file, tags, MCP tool source and OpenAPI spec (clone at v12.5.0) github.com · seen 2026-10-08
  27. security advisories github.com · seen 2026-10-08
  28. critical advisory github.com · seen 2026-10-08
  29. CI runs on main github.com · seen 2026-10-08
  30. open issues github.com · seen 2026-10-08
  31. npm package and version registry.npmjs.org · seen 2026-10-08
  32. SDK package and version registry.npmjs.org · seen 2026-10-08
  33. domain registration (RDAP) rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $499 / mo The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).

Prices

ItemPriceUnitNote
Core, self-hostedfreeper month (plan)3 Studio seats, 25 collections, 5 flows
Team$499per month (plan)annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows
Team extra seat$50per seat per monthStudio users only
Directus Cloud hosting add-on$99per month (plan)for Core, Team and Open Innovation Grant projects

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/directus.xml, or this listing's score history at history.json.

Connect

Install

npm install @directus/sdk

Claude Code

claude mcp add --transport http directus https://your-directus-url.com/mcp

MCP client configuration

{
  "mcpServers": {
    "directus": {
      "headers": {
        "Authorization": "Bearer your-generated-token"
      },
      "url": "https://your-directus-url.com/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/directus

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
DatoCMS Dato SrlBB74.4cms.content cms.publish cms.assets cms.localisation cms.schemano
Sanity Sanity US Inc. and Sanity ASBB73.7cms.content cms.publish cms.assets cms.schema cms.localisationno
Webflow Webflow, Inc.B69.4cms.content cms.publish cms.assets cms.schema cms.localisationno
Storyblok Storyblok GmbHB67.7cms.content cms.publish cms.assets cms.localisation cms.schemano
Strapi Strapi, Inc.B65.7cms.content cms.publish cms.localisation cms.assets cms.schemano
Contentstack Contentstack Inc.B64cms.content cms.publish cms.assets cms.localisation cms.schemano

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Directus on Anchor Terminal, B, 67.1/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/directus"><img src="https://www.anchorterminal.com/badges/directus.svg" alt="Directus on Anchor Terminal" height="20"></a>
    [![Directus on Anchor Terminal](https://www.anchorterminal.com/badges/directus.svg)](https://www.anchorterminal.com/tools/directus)

    It counts on a page on directus.com or one of its subdomains, or the README of github.com/directus/directus.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "directus", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.