# Directus (slim) > Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server. - Full: https://www.anchorterminal.com/tools/directus.md (~8,600 tokens) · this version ~2,280 tokens · JSON https://www.anchorterminal.com/tools/directus.json · canonical https://www.anchorterminal.com/tools/directus - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 67.1/100 · rank #217 of 722 · #5 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions. ## Facts - Kind: HTTP API · vendor: Monospace Inc. (Directus) · category: CMS & website publishing · legal entity: Monospace Inc. (doing business as Directus) · provenance 66/100 - Local only (HTTP, Streamable HTTP): npm `directus`, npm `@directus/sdk`, npm `@directus/specs` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT - Probe metrics: not measured yet (probes haven't run) - Graded surface: Self-hosted Directus 12.5.0 on the free Core tier, through the built-in MCP server and the REST API. Directus Cloud hosts the same software as a paid add-on - MCP server: Built in from v11.12 at `/mcp`, off by default and enabled under Settings, AI, Model Context Protocol. Default mode lists every tool. Registry mode (`/mcp?tool_mode=registry`) lists `search`, `execute` and `schema` - MCP tools: system-prompt, items, files, folders, assets, flows, trigger-flow, operations, schema, collections, fields, relations. Each takes an `action` (create, read, update, delete, and import for files). Stored prompts can be served from a chosen collection - REST and GraphQL: Generated from the database schema. `/items/{collection}`, `/files`, `/collections`, `/fields`, `/relations`, `/versions`, `/revisions`, `/activity` and others, 70 paths in the OpenAPI file. Each instance serves its own spec at `/server/specs/oas` - Credentials: MCP OAuth with PKCE (scope `mcp:access`, MCP endpoint only), static tokens (one per user, no expiry), log-in access and refresh tokens, session cookies, and third-party JWTs. Sent as `Authorization: Bearer`, a cookie or `?access_token=` - Permissions: Access policies per role or user, by collection, action, field and item rule. MCP calls run as the connected user. Allow Deletes is a separate MCP setting, off by default - Draft and publish: Content versioning per collection, with reserved `draft` and `published` keys, `?version=` on reads, and `POST /versions/{id}/save`, `/compare` and `/promote`. Published items in versioned collections are locked from direct edits since v12 - Localisation: Translations are a related collection per content collection, written as nested `translations` data. AI translation in the Studio is an Enterprise feature - Assets: `POST /files` (multipart) and import from a URL, which the MCP `files` tool also does. The `assets` tool returns file content as base64. Storage adapters for local disk, S3, GCS, Azure, Cloudinary and Supabase - Audit: Activity log with user, action, time, IP address, user agent, collection and item, plus revisions per change. Kept 30 days on Core, 90 on Team and configurable on Enterprise - Rate limits: Off by default. `RATE_LIMITER_ENABLED` allows 50 requests a second per IP and a global pool of 1,000, with `Retry-After` on 429. MCP OAuth authorisation is limited to 60 requests and client registration to 30 per window. A pressure limiter answers 503 under load - Errors: `{errors: [{message, extensions: {code}}]}` with codes such as `FORBIDDEN`, `FAILED_VALIDATION`, `INVALID_PAYLOAD` and `COLLECTION_INACTIVE`. Missing items answer `FORBIDDEN`, not 404 - Licensing: Core runs with no key. Paid tiers and the grant use `LICENSE_KEY`, bound to `PUBLIC_URL` and revalidated with licensing.directus.com at least every 12 hours. Offline tokens are Enterprise only - Telemetry: A report every 6 hours to telemetry.directus.io with the public URL, version, database vendor, counts and feature flags. `TELEMETRY=false` opts out where the licence allows. Project owner registration has its own switch, `PROJECT_OWNER_ENABLED` - Runtime: Docker image `directus/directus`, Node.js 22 or later, with PostgreSQL, MySQL, MariaDB, SQLite, MS SQL Server, CockroachDB or OracleDB. Redis for caching and horizontal scaling - SDK: `@directus/sdk` 27.0.0 for JavaScript and TypeScript, MIT. An older stdio MCP server, `@directus/content-mcp` 0.1.0, remains for instances before v11.12 - Directus Cloud: $99 a month hosting add-on for Core, Team and the grant, with Enterprise priced by sales. Statuspage at status.directus.cloud. The Cloud policies give no uptime commitment to self-service projects - Prices: Core, self-hosted free per month (plan); Team $499 per month (plan); Team extra seat $50 per seat per month; Directus Cloud hosting add-on $99 per month (plan) - Scores: Reliability 82, Performance pending, Schema & documentation 81, Agent ergonomics 73, Security & auth 68, Payments & pricing 55, Task success pending, Maintenance & community 86, Transparency & trust 61 · negative events -6 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the graded surface is the self-hosted software on the free Core tier. · Schema & documentation, An OpenAPI file ships in `@directus/specs` with 70 paths, each instance serves its own at `/server/specs/oas`, and every MCP tool has a type… · Agent ergonomics, Default mode lists 12 tools, the 11 to 30 band, but each definition carries its whole instruction file, 78,855 bytes in total at v12.5.0, so… · Security & auth, MCP OAuth uses PKCE with dynamic client registration or client ID metadata documents, issues a token with the single `mcp:access` scope and… · Payments & pricing, Scored with the self-hosted rule, taking prices from the paid options beside the free tier. · Maintenance & community, v12.5.0 was tagged on 7 October 2026, the day before this check (30). · Transparency & trust, The full source is public under MSCL-1.0-GPL, which bars competing use and bypassing the licence key and converts each version to GPL-3.0 af… - Sources: 33, open questions: 10, both in the full twin - Capabilities: cms.content, cms.schema, cms.assets, cms.publish, cms.localisation - JSON: https://www.anchorterminal.com/api/v1/tools/directus.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/directus.svg` or a link to https://www.anchorterminal.com/tools/directus from a page on directus.com or one of its subdomains, or the README of github.com/directus/directus, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged 2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total 3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model 4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions` 5. Count translation and junction tables against the 25-collection Core limit before creating collections ## Connect ```bash npm install @directus/sdk ``` ```bash claude mcp add --transport http directus https://your-directus-url.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/directus ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)