{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/datocms.json",
        "name": "DatoCMS",
        "score": 74.4,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "datocms"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/sanity.json",
        "name": "Sanity",
        "score": 73.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "sanity"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/webflow.json",
        "name": "Webflow",
        "score": 69.4,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "webflow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/storyblok.json",
        "name": "Storyblok",
        "score": 67.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "storyblok"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/strapi.json",
        "name": "Strapi",
        "score": 65.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.localisation",
          "cms.assets",
          "cms.schema"
        ],
        "slug": "strapi"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/contentstack.json",
        "name": "Contentstack",
        "score": 64,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "contentstack"
      }
    ],
    "tool": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 217,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 82,
            "points": 16.4,
            "reason": "Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 73,
            "points": 11.86,
            "reason": "Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 68,
            "points": 11.9,
            "reason": "MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 55,
            "points": 6.88,
            "reason": "Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 86,
            "points": 7.53,
            "reason": "v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 61,
            "points": 5.34,
            "note": "editorial 55, provenance 66",
            "reason": "The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15).",
            "maintenance": "v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).",
            "payments": "Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).",
            "reliability": "Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).",
            "schema": "An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).",
            "security": "MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).",
            "transparency": "The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20)."
          },
          "sources": [
            {
              "what": "MCP overview",
              "url": "https://directus.com/docs/guides/ai/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP installation, tool modes and settings",
              "url": "https://directus.com/docs/guides/ai/mcp/installation",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tools",
              "url": "https://directus.com/docs/guides/ai/mcp/tools",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth",
              "url": "https://directus.com/docs/guides/ai/mcp/oauth",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP security guide",
              "url": "https://directus.com/docs/guides/ai/mcp/security",
              "seen": "2026-10-08"
            },
            {
              "what": "access tokens",
              "url": "https://directus.com/docs/guides/auth/tokens-cookies",
              "seen": "2026-10-08"
            },
            {
              "what": "activity log",
              "url": "https://directus.com/docs/guides/auth/accountability",
              "seen": "2026-10-08"
            },
            {
              "what": "errors",
              "url": "https://directus.com/docs/guides/connect/errors",
              "seen": "2026-10-08"
            },
            {
              "what": "query parameters",
              "url": "https://directus.com/docs/guides/connect/query-parameters",
              "seen": "2026-10-08"
            },
            {
              "what": "content versioning",
              "url": "https://directus.com/docs/guides/content/content-versioning",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limiting configuration",
              "url": "https://directus.com/docs/configuration/security-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "licensing overview",
              "url": "https://directus.com/docs/licensing/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "telemetry",
              "url": "https://directus.com/docs/licensing/telemetry",
              "seen": "2026-10-08"
            },
            {
              "what": "release policy",
              "url": "https://directus.com/docs/releases",
              "seen": "2026-10-08"
            },
            {
              "what": "breaking changes in version 12",
              "url": "https://directus.com/docs/releases/breaking-changes/version-12",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://directus.com/docs/releases/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "security reporting",
              "url": "https://directus.com/docs/community/reporting-and-support/security-reporting",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://directus.com/docs/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://directus.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "licence text",
              "url": "https://directus.com/license",
              "seen": "2026-10-08"
            },
            {
              "what": "terms",
              "url": "https://directus.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://directus.com/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "Cloud policies",
              "url": "https://directus.com/cloud-policies",
              "seen": "2026-10-08"
            },
            {
              "what": "trust centre",
              "url": "https://trust.directus.com",
              "seen": "2026-10-08"
            },
            {
              "what": "Directus Cloud status incidents",
              "url": "https://status.directus.cloud/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "repository, licence file, tags, MCP tool source and OpenAPI spec (clone at v12.5.0)",
              "url": "https://github.com/directus/directus",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories",
              "url": "https://github.com/directus/directus/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "critical advisory",
              "url": "https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c",
              "seen": "2026-10-08"
            },
            {
              "what": "CI runs on main",
              "url": "https://github.com/directus/directus/actions/workflows/check.yml?query=branch%3Amain",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/directus/directus/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package and version",
              "url": "https://registry.npmjs.org/directus/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK package and version",
              "url": "https://registry.npmjs.org/@directus/sdk/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/directus.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the official MCP registry search for Directus timed out twice from our network",
            "unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages",
            "unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown",
            "unchecked: whether the 14-day Directus Cloud trial asks for a card",
            "We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through `PATCH /settings` is inferred from the `mcp_enabled` settings field, not from the docs",
            "The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12",
            "directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so `provenance.terms` points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies",
            "The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes",
            "The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise",
            "The repository's `security.md` gives security@directus.io while the docs give security@directus.com"
          ]
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "notable": [
        "The MCP server is built into Directus from v11.12, off by default, and answers at `/mcp` with 12 tools, or at `/mcp?tool_mode=registry` with `search`, `execute` and `schema` (https://directus.com/docs/guides/ai/mcp/tools)",
        "MCP OAuth issues a token with the `mcp:access` scope and the MCP endpoint as audience, and administrators can review and revoke registered clients (https://directus.com/docs/guides/ai/mcp/oauth)",
        "Version 12.0.0 (10 June 2026) introduced licence enforcement. An instance over its tier limits after the grace period blocks `/items` and disables GraphQL, WebSockets and MCP (https://directus.com/docs/licensing/overview)",
        "The free Core tier allows 3 Studio seats, 25 collections and 5 flows, with activity logs and revisions kept 30 days. API-only users don't count as seats (https://directus.com/pricing)",
        "The docs say releases don't follow semantic versioning, so any release may include breaking changes (https://directus.com/docs/releases)",
        "Advisory GHSA-97xr-jchp-xm3c, rated critical, was published on 5 August 2026 for versions before 12.1.0 (https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c)",
        "Telemetry reports the instance's public URL and usage counts every 6 hours, and the `TELEMETRY=false` opt-out applies only where the licence allows it (https://directus.com/docs/licensing/telemetry)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Graded surface",
          "value": "Self-hosted Directus 12.5.0 on the free Core tier, through the built-in MCP server and the REST API. Directus Cloud hosts the same software as a paid add-on"
        },
        {
          "label": "MCP server",
          "value": "Built in from v11.12 at `/mcp`, off by default and enabled under Settings, AI, Model Context Protocol. Default mode lists every tool. Registry mode (`/mcp?tool_mode=registry`) lists `search`, `execute` and `schema`"
        },
        {
          "label": "MCP tools",
          "value": "system-prompt, items, files, folders, assets, flows, trigger-flow, operations, schema, collections, fields, relations. Each takes an `action` (create, read, update, delete, and import for files). Stored prompts can be served from a chosen collection"
        },
        {
          "label": "REST and GraphQL",
          "value": "Generated from the database schema. `/items/{collection}`, `/files`, `/collections`, `/fields`, `/relations`, `/versions`, `/revisions`, `/activity` and others, 70 paths in the OpenAPI file. Each instance serves its own spec at `/server/specs/oas`"
        },
        {
          "label": "Credentials",
          "value": "MCP OAuth with PKCE (scope `mcp:access`, MCP endpoint only), static tokens (one per user, no expiry), log-in access and refresh tokens, session cookies, and third-party JWTs. Sent as `Authorization: Bearer`, a cookie or `?access_token=`"
        },
        {
          "label": "Permissions",
          "value": "Access policies per role or user, by collection, action, field and item rule. MCP calls run as the connected user. Allow Deletes is a separate MCP setting, off by default"
        },
        {
          "label": "Draft and publish",
          "value": "Content versioning per collection, with reserved `draft` and `published` keys, `?version=` on reads, and `POST /versions/{id}/save`, `/compare` and `/promote`. Published items in versioned collections are locked from direct edits since v12"
        },
        {
          "label": "Localisation",
          "value": "Translations are a related collection per content collection, written as nested `translations` data. AI translation in the Studio is an Enterprise feature"
        },
        {
          "label": "Assets",
          "value": "`POST /files` (multipart) and import from a URL, which the MCP `files` tool also does. The `assets` tool returns file content as base64. Storage adapters for local disk, S3, GCS, Azure, Cloudinary and Supabase"
        },
        {
          "label": "Audit",
          "value": "Activity log with user, action, time, IP address, user agent, collection and item, plus revisions per change. Kept 30 days on Core, 90 on Team and configurable on Enterprise"
        },
        {
          "label": "Rate limits",
          "value": "Off by default. `RATE_LIMITER_ENABLED` allows 50 requests a second per IP and a global pool of 1,000, with `Retry-After` on 429. MCP OAuth authorisation is limited to 60 requests and client registration to 30 per window. A pressure limiter answers 503 under load"
        },
        {
          "label": "Errors",
          "value": "`{errors: [{message, extensions: {code}}]}` with codes such as `FORBIDDEN`, `FAILED_VALIDATION`, `INVALID_PAYLOAD` and `COLLECTION_INACTIVE`. Missing items answer `FORBIDDEN`, not 404"
        },
        {
          "label": "Licensing",
          "value": "Core runs with no key. Paid tiers and the grant use `LICENSE_KEY`, bound to `PUBLIC_URL` and revalidated with licensing.directus.com at least every 12 hours. Offline tokens are Enterprise only"
        },
        {
          "label": "Telemetry",
          "value": "A report every 6 hours to telemetry.directus.io with the public URL, version, database vendor, counts and feature flags. `TELEMETRY=false` opts out where the licence allows. Project owner registration has its own switch, `PROJECT_OWNER_ENABLED`"
        },
        {
          "label": "Runtime",
          "value": "Docker image `directus/directus`, Node.js 22 or later, with PostgreSQL, MySQL, MariaDB, SQLite, MS SQL Server, CockroachDB or OracleDB. Redis for caching and horizontal scaling"
        },
        {
          "label": "SDK",
          "value": "`@directus/sdk` 27.0.0 for JavaScript and TypeScript, MIT. An older stdio MCP server, `@directus/content-mcp` 0.1.0, remains for instances before v11.12"
        },
        {
          "label": "Directus Cloud",
          "value": "$99 a month hosting add-on for Core, Team and the grant, with Enterprise priced by sales. Statuspage at status.directus.cloud. The Cloud policies give no uptime commitment to self-service projects"
        }
      ],
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Monospace Inc. (doing business as Directus)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "directus.com, registered 1997-02-06 (29 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on directus.com",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 1 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 2.9,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 5 of the 8 things a reader expects",
            "points": 7.8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.directus.cloud",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://directus.com/license",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 1032,
            "points": 2.9,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": false
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": false
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You must not move, change, disable or circumvent the license key functionality of the Software or modify any portion of the Software protected by the license key to:"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "A Permitted Purpose is any purpose other than a Competing Use.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The document is a licence for the Directus software and excludes all liability of the licensor arising from the software.",
                "quote": "IN NO EVENT WILL WE HAVE ANY LIABILITY TO YOU ARISING OUT OF OR RELATED TO THE SOFTWARE, INCLUDING INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES, EVEN IF WE HAVE BEEN INFORMED OF THEIR POSSIBILITY IN ADVANCE."
              },
              {
                "date": "2026-10-08",
                "text": "Each version of the software also becomes usable under GPL-3.0 four years after it is made available.",
                "quote": "We hereby irrevocably grant you an additional license to use the Software under the GNU General Public License version 3 (GPL-3.0), effective on the fourth anniversary of the date we make the Software available."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://directus.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-09",
            "words": 3459,
            "points": 7.8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: June 9, 2026",
                "says": "Last updated 2026-06-09"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Please review our Privacy Policy which helps you understand the information we collect and receive, how we use it and the choices you have."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may utilize the services of third parties and provide some of our services through contractual arrangements with affiliates, service providers, partners, and other third parties, and to facilitate such arrangements we reserve the right to share with such third parties Personally Identifiable Information."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Nevada residents may email questions regarding our practices relating to personal information to info@directus.io"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If you are a California resident, you have the right, subject to certain exceptions defined in the California Consumer Privacy Act (“CCPA”) and other applicable laws and regulations, to request that Directus disclose certain information to you about our collection and use of your personal information over the past twe…"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": false
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy covers the Directus website, and personal information processed for customers of the product is handled under customer agreements instead.",
                "quote": "When we process personal information in the course of providing the Directus Solution to our Customers, we do so pursuant to our agreements with our Customers, not this Privacy Policy."
              },
              {
                "date": "2026-10-08",
                "text": "For US residents, data partners may use cookies to link site visits to an email or home address, which Directus may then use for marketing, with an opt-out link.",
                "quote": "When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email or home address."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:50.444721767Z"
        },
        "updatedAt": "2026-10-08T21:57:50.444721767Z"
      }
    },
    "verify": {
      "accepts": "a page on directus.com or one of its subdomains, or the README of github.com/directus/directus",
      "badgeUrl": "https://www.anchorterminal.com/badges/directus.svg",
      "body": {
        "slug": "directus",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/directus",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/directus\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/directus.svg\" alt=\"Directus on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Directus on Anchor Terminal](https://www.anchorterminal.com/badges/directus.svg)](https://www.anchorterminal.com/tools/directus)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/directus\"\u003eDirectus on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/directus",
    "json": "https://www.anchorterminal.com/tools/directus.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/directus.md",
    "slim": "https://www.anchorterminal.com/tools/directus.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 67.1/100 · rank #217 of 722 · #5 in CMS \u0026 website publishing · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Monospace Inc. (Directus) (https://directus.com) |\n| Kind | HTTP API |\n| Category | CMS \u0026 website publishing (https://www.anchorterminal.com/categories/cms) |\n| Transport | HTTP, Streamable HTTP |\n| Auth | OAuth or key · Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule. |\n| Pricing | Freemium ($499 / mo) · The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08). |\n| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT |\n| Tools exposed | 12 |\n| Packages | npm: `directus`; npm: `@directus/sdk`; npm: `@directus/specs` |\n| Source | https://github.com/directus/directus |\n| Docs | https://directus.com/docs |\n| llms.txt | https://directus.com/docs/llms.txt |\n| Last release | 2026-10-07 |\n| GitHub stars | 38,295 (as of 2026-10-08) |\n| npm downloads / week | 22,588 |\n| Graded surface | Self-hosted Directus 12.5.0 on the free Core tier, through the built-in MCP server and the REST API. Directus Cloud hosts the same software as a paid add-on |\n| MCP server | Built in from v11.12 at `/mcp`, off by default and enabled under Settings, AI, Model Context Protocol. Default mode lists every tool. Registry mode (`/mcp?tool_mode=registry`) lists `search`, `execute` and `schema` |\n| MCP tools | system-prompt, items, files, folders, assets, flows, trigger-flow, operations, schema, collections, fields, relations. Each takes an `action` (create, read, update, delete, and import for files). Stored prompts can be served from a chosen collection |\n| REST and GraphQL | Generated from the database schema. `/items/{collection}`, `/files`, `/collections`, `/fields`, `/relations`, `/versions`, `/revisions`, `/activity` and others, 70 paths in the OpenAPI file. Each instance serves its own spec at `/server/specs/oas` |\n| Credentials | MCP OAuth with PKCE (scope `mcp:access`, MCP endpoint only), static tokens (one per user, no expiry), log-in access and refresh tokens, session cookies, and third-party JWTs. Sent as `Authorization: Bearer`, a cookie or `?access_token=` |\n| Permissions | Access policies per role or user, by collection, action, field and item rule. MCP calls run as the connected user. Allow Deletes is a separate MCP setting, off by default |\n| Draft and publish | Content versioning per collection, with reserved `draft` and `published` keys, `?version=` on reads, and `POST /versions/{id}/save`, `/compare` and `/promote`. Published items in versioned collections are locked from direct edits since v12 |\n| Localisation | Translations are a related collection per content collection, written as nested `translations` data. AI translation in the Studio is an Enterprise feature |\n| Assets | `POST /files` (multipart) and import from a URL, which the MCP `files` tool also does. The `assets` tool returns file content as base64. Storage adapters for local disk, S3, GCS, Azure, Cloudinary and Supabase |\n| Audit | Activity log with user, action, time, IP address, user agent, collection and item, plus revisions per change. Kept 30 days on Core, 90 on Team and configurable on Enterprise |\n| Rate limits | Off by default. `RATE_LIMITER_ENABLED` allows 50 requests a second per IP and a global pool of 1,000, with `Retry-After` on 429. MCP OAuth authorisation is limited to 60 requests and client registration to 30 per window. A pressure limiter answers 503 under load |\n| Errors | `{errors: [{message, extensions: {code}}]}` with codes such as `FORBIDDEN`, `FAILED_VALIDATION`, `INVALID_PAYLOAD` and `COLLECTION_INACTIVE`. Missing items answer `FORBIDDEN`, not 404 |\n| Licensing | Core runs with no key. Paid tiers and the grant use `LICENSE_KEY`, bound to `PUBLIC_URL` and revalidated with licensing.directus.com at least every 12 hours. Offline tokens are Enterprise only |\n| Telemetry | A report every 6 hours to telemetry.directus.io with the public URL, version, database vendor, counts and feature flags. `TELEMETRY=false` opts out where the licence allows. Project owner registration has its own switch, `PROJECT_OWNER_ENABLED` |\n| Runtime | Docker image `directus/directus`, Node.js 22 or later, with PostgreSQL, MySQL, MariaDB, SQLite, MS SQL Server, CockroachDB or OracleDB. Redis for caching and horizontal scaling |\n| SDK | `@directus/sdk` 27.0.0 for JavaScript and TypeScript, MIT. An older stdio MCP server, `@directus/content-mcp` 0.1.0, remains for instances before v11.12 |\n| Directus Cloud | $99 a month hosting add-on for Core, Team and the grant, with Enterprise priced by sales. Statuspage at status.directus.cloud. The Cloud policies give no uptime commitment to self-service projects |\n| Capabilities | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation |\n| Tags | source-available, self-hosted, hosted, mcp, oauth, openapi, llms-txt, graphql, typescript, sql, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/directus.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 82 | 16.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 81 | 13.2 |\n| Agent ergonomics | 13% | 16.2 | 73 | 11.9 |\n| Security \u0026 auth | 14% | 17.5 | 68 | 11.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 55 | 6.9 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 86 | 7.5 |\n| Transparency \u0026 trust (editorial 55, provenance 66) | 7% | 8.8 | 61 | 5.3 |\n| Negative events | up to −15 | up to −15 | 5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories  | -6 |\n| **Total** | | | | **67.1 → B** |\n\n### Why each score\n\n- Reliability 82: Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. Directus Cloud's status page isn't scored here. Official Docker image `directus/directus` and npm package `directus` 12.5.0, with Node.js 22 or later in `engines` and the supported databases listed (20). The Check workflow passed on the 10 most recent runs on main, the release of 12.5.0 among them, and separate end-to-end and CodeQL workflows exist (25). 339 open issues. The 15 newest carry labels and one to eight comments, but we couldn't read closed counts, and at least 20 advisories were fixed between June and September 2026 (15 of 25). The docs say releases don't follow semantic versioning and any release may break. Breaking changes are listed per version, and 12.1 to 12.5 each had some (7 of 15). Version 12, and the MCP server isn't marked beta (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 81: An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a typed input schema. The spec's `info.version` still reads 10 (22 of 25). llms.txt, llms-full.txt and a raw Markdown copy of every docs page (10). Each tool has a one-sentence description and a `prompt.md` of instructions with worked examples, up to 13 KB for flows, and a `system-prompt` tool sets conventions (16 of 20). Actions are enums and validation uses strict unions per action, but item data, filters, `deep`, and field `schema` and `meta` are open records (8 of 15). The errors page lists HTTP statuses and error codes with the response shape, and guides show REST, GraphQL and SDK examples side by side (14 of 15). A monthly changelog, release notes and breaking-change pages per major version. REST paths carry no version and releases aren't semantic (11 of 15).\n- Agent ergonomics 73: Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so we scored 10 and added 8 for registry mode, which lists three tools and loads details on demand (18 of 25). `limit` (default 100), `offset`, `page`, `fields`, `filter`, `search`, `sort` and `aggregate`, with `QUERY_LIMIT_MAX` as a server cap (20). One error shape with a machine-readable `extensions.code`. Missing items answer `FORBIDDEN`, not 404, by design (17 of 20). Tools set `readOnlyHint` and `destructiveHint`, though one `items` tool covers reads and writes and is marked destructive. No idempotency keys were found in the reviewed documentation (10 of 20). Few required parameters. One official SDK, `@directus/sdk` for JavaScript and TypeScript (8 of 15).\n- Security \u0026 auth 68: MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and the MCP endpoint as audience, and lets administrators revoke clients. Static tokens are one per user, don't expire and are stored in plain text. We scored 26 and took 10 because `?access_token=` in the URL is a documented option that the MCP guide uses for three clients (16 of 30). Access policies limit a user by collection, action, field and item rule, the MCP server is off by default, and deletes are refused unless Allow Deletes is on. No server-side approval step for other writes (16 of 20). A security guide for MCP covers prompt injection, mixing servers and auto-approval, with advice only (11 of 15). The activity log records user, action, time, IP address, user agent, collection and item, kept 30 days on Core (11 of 15). A disclosure policy with private GitHub reports and a security address, advisories published in public, and SOC 2 Type 2 with a penetration test report on the trust centre. No bug bounty found, and security.txt returns 404 (14 of 20).\n- Payments \u0026 pricing 55: Scored with the self-hosted rule, taking prices from the paid options beside the free tier. No x402, MPP or L402 (0). Core is $0, Team is $499 a month on an annual term or $599 monthly, extra seats are $50 each a month, and Directus Cloud hosting is a $99 a month add-on, all public. Enterprise is priced by sales (20). The Core tier is free to self-host with no card and no account, and Cloud has a 14-day trial (20). `ADMIN_EMAIL`, `ADMIN_PASSWORD` and `ADMIN_TOKEN` create the first administrator and a static token at start-up, so the REST route needs no browser. The docs enable the MCP server only through the Studio settings page, so we took 5 off (15 of 20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 86: v12.5.0 was tagged on 7 October 2026, the day before this check (30). Six tagged releases since 29 July 2026 (12.2.0, 12.3.0, 12.3.1, 12.4.0, 12.4.1 and 12.5.0) (20). 339 open issues, the newest labelled and answered, with 170 commits on main since 10 July. Closed-issue counts weren't readable (17 of 25). `@directus/sdk` 27.0.0 is current and is the only official SDK. We couldn't reach the official MCP registry, which matters less for a server built into the product (10 of 15). Dependency updates for CVEs land in each release, CI passes on main and CodeQL runs (9 of 10).\n- Transparency \u0026 trust 61: The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 after four years. It isn't an OSI licence. The SDK is MIT. The docs index still calls the licence BSL (19 of 30). A self-hosted install keeps content on its owner's servers. The privacy policy of 9 June 2026 says customer data is handled under customer agreements and not the policy, the terms dated 28 April 2025 let the company keep or delete account materials at its discretion, and no public DPA or retention period was found. The trust centre names five subprocessors without locations (16 of 30). Breaking changes are documented per version, upgrades to version 12 got a 30-day grace period and old monthly plans six months. No stated notice period for API changes (10 of 20). Telemetry is documented field by field with an opt-out variable, but it sends the instance's public URL and the opt-out is honoured only where the licence allows, which the pricing table lists for Enterprise alone (10 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/directus.md (JSON https://www.anchorterminal.com/fixes/directus.json)\n\n### What we couldn't check\n\n- unchecked: the official MCP registry search for Directus timed out twice from our network\n- unchecked: the GitHub API refused us for its rate limit, so closed-issue counts and advisory pages 3 to 8 weren't read. Advisory counts come from the first two pages\n- unchecked: the trust centre's SOC 2 report, penetration test report and Master Services Agreement sit behind an access request, and subprocessor locations aren't shown\n- unchecked: whether the 14-day Directus Cloud trial asks for a card\n- We didn't run an instance. Tool counts, annotations and instruction sizes come from the source at v12.5.0, and enabling MCP through `PATCH /settings` is inferred from the `mcp_enabled` settings field, not from the docs\n- The lead called Directus open source. It has been source-available since April 2023 (BSL 1.1) and moved to MSCL-1.0-GPL with licence-key enforcement in version 12\n- directus.com/terms opens by saying it applies to self-hosted, cloud and enterprise products but reads as website terms of use, so `provenance.terms` points at the software licence that governs a self-hosted install. Directus Cloud is also bound by the Cloud policies\n- The privacy policy says customer data processed for the product falls under customer agreements, which aren't public. It is listed as the only privacy document the vendor publishes\n- The dossier grades the self-hosted Core tier. A reader on Directus Cloud should weigh the status history noted for reviewers and the lack of an uptime commitment below Enterprise\n- The repository's `security.md` gives security@directus.io while the docs give security@directus.com\n\n### Sources\n\n- MCP overview: \u003chttps://directus.com/docs/guides/ai/mcp\u003e (seen 2026-10-08)\n- MCP installation, tool modes and settings: \u003chttps://directus.com/docs/guides/ai/mcp/installation\u003e (seen 2026-10-08)\n- MCP tools: \u003chttps://directus.com/docs/guides/ai/mcp/tools\u003e (seen 2026-10-08)\n- MCP OAuth: \u003chttps://directus.com/docs/guides/ai/mcp/oauth\u003e (seen 2026-10-08)\n- MCP security guide: \u003chttps://directus.com/docs/guides/ai/mcp/security\u003e (seen 2026-10-08)\n- access tokens: \u003chttps://directus.com/docs/guides/auth/tokens-cookies\u003e (seen 2026-10-08)\n- activity log: \u003chttps://directus.com/docs/guides/auth/accountability\u003e (seen 2026-10-08)\n- errors: \u003chttps://directus.com/docs/guides/connect/errors\u003e (seen 2026-10-08)\n- query parameters: \u003chttps://directus.com/docs/guides/connect/query-parameters\u003e (seen 2026-10-08)\n- content versioning: \u003chttps://directus.com/docs/guides/content/content-versioning\u003e (seen 2026-10-08)\n- rate limiting configuration: \u003chttps://directus.com/docs/configuration/security-limits\u003e (seen 2026-10-08)\n- licensing overview: \u003chttps://directus.com/docs/licensing/overview\u003e (seen 2026-10-08)\n- telemetry: \u003chttps://directus.com/docs/licensing/telemetry\u003e (seen 2026-10-08)\n- release policy: \u003chttps://directus.com/docs/releases\u003e (seen 2026-10-08)\n- breaking changes in version 12: \u003chttps://directus.com/docs/releases/breaking-changes/version-12\u003e (seen 2026-10-08)\n- changelog: \u003chttps://directus.com/docs/releases/changelog\u003e (seen 2026-10-08)\n- security reporting: \u003chttps://directus.com/docs/community/reporting-and-support/security-reporting\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://directus.com/docs/llms.txt\u003e (seen 2026-10-08)\n- pricing: \u003chttps://directus.com/pricing\u003e (seen 2026-10-08)\n- licence text: \u003chttps://directus.com/license\u003e (seen 2026-10-08)\n- terms: \u003chttps://directus.com/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://directus.com/privacy\u003e (seen 2026-10-08)\n- Cloud policies: \u003chttps://directus.com/cloud-policies\u003e (seen 2026-10-08)\n- trust centre: \u003chttps://trust.directus.com\u003e (seen 2026-10-08)\n- Directus Cloud status incidents: \u003chttps://status.directus.cloud/api/v2/incidents.json\u003e (seen 2026-10-08)\n- repository, licence file, tags, MCP tool source and OpenAPI spec (clone at v12.5.0): \u003chttps://github.com/directus/directus\u003e (seen 2026-10-08)\n- security advisories: \u003chttps://github.com/directus/directus/security/advisories\u003e (seen 2026-10-08)\n- critical advisory: \u003chttps://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c\u003e (seen 2026-10-08)\n- CI runs on main: \u003chttps://github.com/directus/directus/actions/workflows/check.yml?query=branch%3Amain\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/directus/directus/issues\u003e (seen 2026-10-08)\n- npm package and version: \u003chttps://registry.npmjs.org/directus/latest\u003e (seen 2026-10-08)\n- SDK package and version: \u003chttps://registry.npmjs.org/@directus/sdk/latest\u003e (seen 2026-10-08)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/directus.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 66/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Monospace Inc. (doing business as Directus) | 20/20 |\n| Domain age | directus.com, registered 1997-02-06 (29 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on directus.com | 0/15 |\n| Terms of service | read, states 1 of the 7 things a reader expects, and has 1 clause that costs points | 2.9/10 |\n| Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 |\n| Status page | status.directus.cloud | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.\n\n`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.\n\nThe privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.\n\nA self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.\n\nhttps://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.\n\nRDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.\n\nThe status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://directus.com/license), read 2026-10-08, gives no date, states 1 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"A Permitted Purpose is any purpose other than a Competing Use.\"\n- Not found in the text. Gives the date it was last updated.\n- Not found in the text. Names the governing law or courts.\n- Not found in the text. States a limit on its liability.\n- Not found in the text. Says how the agreement or account can be ended.\n- Not found in the text. Says how changes to the terms are announced.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). The document is a licence for the Directus software and excludes all liability of the licensor arising from the software. \"IN NO EVENT WILL WE HAVE ANY LIABILITY TO YOU ARISING OUT OF OR RELATED TO THE SOFTWARE, INCLUDING INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES, EVEN IF WE HAVE BEEN INFORMED OF THEIR POSSIBILITY IN ADVANCE.\"\n- Also in the text (2026-10-08). Each version of the software also becomes usable under GPL-3.0 four years after it is made available. \"We hereby irrevocably grant you an additional license to use the Software under the GNU General Public License version 3 (GPL-3.0), effective on the fourth anniversary of the date we make the Software available.\"\n\n**Privacy policy** (https://directus.com/privacy), read 2026-10-08, dated 2026-06-09, states 5 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-06-09.\n- Not found in the text. Says how long data is kept.\n- Not found in the text. Gives a privacy contact.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). The policy covers the Directus website, and personal information processed for customers of the product is handled under customer agreements instead. \"When we process personal information in the course of providing the Directus Solution to our Customers, we do so pursuant to our agreements with our Customers, not this Privacy Policy.\"\n- Also in the text (2026-10-08). For US residents, data partners may use cookies to link site visits to an email or home address, which Directus may then use for marketing, with an opt-out link. \"When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email or home address.\"\n\n## Live (updated 2026-10-08 21:57 UTC)\n\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/directus.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Core, self-hosted | free | per month (plan) | 3 Studio seats, 25 collections, 5 flows |\n| Team | $499 | per month (plan) | annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows |\n| Team extra seat | $50 | per seat per month | Studio users only |\n| Directus Cloud hosting add-on | $99 | per month (plan) | for Core, Team and Open Innovation Grant projects |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients\n- Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default\n- Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`\n- Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change\n- Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs\n\n## Weaknesses\n\n- Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n- The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key\n- Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`\n- Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes\n- At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high\n\n## Before you call it (notes for agents)\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @directus/sdk\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http directus https://your-directus-url.com/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"directus\": {\n      \"headers\": {\n        \"Authorization\": \"Bearer your-generated-token\"\n      },\n      \"url\": \"https://your-directus-url.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/directus. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| DatoCMS | BB | 74.4 | 62 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/datocms.md |\n| Sanity | BB | 73.7 | 73 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/sanity.md |\n| Webflow | B | 69.4 | 160 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/webflow.md |\n| Storyblok | B | 67.7 | 202 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/storyblok.md |\n| Strapi | B | 65.7 | 252 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | no | https://www.anchorterminal.com/tools/strapi.md |\n| Contentstack | B | 64 | 288 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/contentstack.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server is built into Directus from v11.12, off by default, and answers at `/mcp` with 12 tools, or at `/mcp?tool_mode=registry` with `search`, `execute` and `schema` (source: \u003chttps://directus.com/docs/guides/ai/mcp/tools\u003e)\n- MCP OAuth issues a token with the `mcp:access` scope and the MCP endpoint as audience, and administrators can review and revoke registered clients (source: \u003chttps://directus.com/docs/guides/ai/mcp/oauth\u003e)\n- Version 12.0.0 (10 June 2026) introduced licence enforcement. An instance over its tier limits after the grace period blocks `/items` and disables GraphQL, WebSockets and MCP (source: \u003chttps://directus.com/docs/licensing/overview\u003e)\n- The free Core tier allows 3 Studio seats, 25 collections and 5 flows, with activity logs and revisions kept 30 days. API-only users don't count as seats (source: \u003chttps://directus.com/pricing\u003e)\n- The docs say releases don't follow semantic versioning, so any release may include breaking changes (source: \u003chttps://directus.com/docs/releases\u003e)\n- Advisory GHSA-97xr-jchp-xm3c, rated critical, was published on 5 August 2026 for versions before 12.1.0 (source: \u003chttps://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c\u003e)\n- Telemetry reports the instance's public URL and usage counts every 6 hours, and the `TELEMETRY=false` opt-out applies only where the licence allows it (source: \u003chttps://directus.com/docs/licensing/telemetry\u003e)\n\n## Compare\n\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md): B 64 vs B 67.1\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md): BB 74.4 vs B 67.1\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md): B 67.1 vs C 58.3\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md): B 67.1 vs C 55.2\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md): B 67.1 vs BB 73.7\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md): B 67.1 vs B 67.7\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md): B 67.1 vs B 65.7\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md): B 67.1 vs B 69.4\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md): B 67.1 vs B 64.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on directus.com or one of its subdomains, or the README of github.com/directus/directus. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"directus\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/directus\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/directus.svg\" alt=\"Directus on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Directus on Anchor Terminal](https://www.anchorterminal.com/badges/directus.svg)](https://www.anchorterminal.com/tools/directus)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/directus\"\u003eDirectus on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Directus is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/directus-dark.png\n- Light: https://www.anchorterminal.com/assets/share/directus-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CMS \u0026 website publishing",
        "url": "https://www.anchorterminal.com/categories/cms"
      },
      {
        "name": "Directus",
        "url": ""
      }
    ],
    "description": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
    "facts": [
      "rank #217 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Directus",
    "image": "https://www.anchorterminal.com/assets/og/tools-directus.png",
    "path": "/tools/directus",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Directus review for AI agents, grade B (67.1/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/directus"
  },
  "tokens": {
    "markdown": 8600,
    "slim": 2280
  },
  "version": 1
}
