# Ghost (slim) > Ghost is an open-source publishing platform for websites, newsletters and paid memberships, self-hosted or run by the Ghost Foundation as Ghost(Pro). Agents create, edit and publish posts and pages and upload images through its Admin API. - Full: https://www.anchorterminal.com/tools/ghost.md (~7,700 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/ghost.json · canonical https://www.anchorterminal.com/tools/ghost - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 58.3/100 · rank #455 of 722 · #9 in CMS & website publishing · not agent-ready · confidence medium** Assessment: A create needs only a title, updates are checked against `updated_at` so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026. ## Facts - Kind: HTTP API · vendor: Ghost Foundation · category: CMS & website publishing · legal entity: Ghost Foundation Ltd · provenance 68/100 - Local only (HTTP): npm `ghost`, npm `@tryghost/admin-api`, npm `ghost-cli` - Auth: API key · pricing: Freemium · x402: no · licence: MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms - Probe metrics: not measured yet (probes haven't run) - Graded surface: Self-hosted Ghost 6.69.0 through the Admin API, authenticated as a custom integration. Ghost(Pro) runs the same software and API at a `*.ghost.io` admin domain. No official MCP server was found - Admin API: REST and JSON at https://{admin_domain}/ghost/api/admin/. Requests and responses wrap resources in an array under the resource name. Documented stable resources are post, page, tag, tier, newsletter, offer, member, label, user (read only), image, theme, site and webhook. More routes exist for user sessions and aren't documented - Credentials: Admin API key per custom integration (id and hex secret), regenerable, used to sign HS256 tokens valid for at most 5 minutes. Staff access tokens per user with that user's role. Email and password sessions with device verification or two-factor codes - Permissions: One fixed permission set for every integration, with no scopes. Staff roles are Contributor, Author, Editor, Administrator and Owner. Staff tokens can't transfer ownership or delete all content - Draft and publish: `status` on the post. Publish with a PUT that sets `status` to `published`. Contributors can add and edit drafts but can't change status (post model in the repository) - Content format: Lexical JSON as a string, or HTML with `?source=html`, converted to Lexical with possible loss. `formats=html,lexical` returns both - Assets: `POST /images/upload/` as multipart form data with `file`, `purpose` (image, profile_image or icon) and an optional `ref`. WEBP, JPEG, GIF, PNG and SVG. The routes file also holds media and file upload routes that the reference doesn't document - Version history: `save_revision=true` on an update stores a revision. The post model keeps up to 25 revisions per post. No documented Admin API route restores one - Localisation and content types: None. Posts and pages have fixed fields and no locales - Pagination and filtering: `page`, `limit` (default 15, maximum 100), `order`, `filter`, `fields`, `include` and `formats` - Versioning: `Accept-Version: v{major}.{minor}` states the minimum version a client works with, and Ghost answers with `Content-Version`. Endpoints are marked stable, experimental or deprecated - Rate limits: No Admin API rate limit was found in the docs. Staff logins and password resets are limited to 5 an hour per IP address. Ghost(Pro) applies a fair use policy with 50 GB to 500 GB a month of bandwidth for headless use - Audit: An actions log readable at `GET /actions` with user authentication or an integration's `action` permission. No per-call log was found - Machine-readable docs: llms.txt (177 links), llms-full.txt and a .md copy of every page. No OpenAPI file - Runtime: Node.js ^22.23.1 or ^24.20.0. The supported stack is Ubuntu 22.04, 24.04 or 26.04, MySQL 8.0 or 8.4, NGINX and systemd, installed with Ghost-CLI. A Docker Compose install is in preview - Client library: @tryghost/admin-api 1.14.13 for JavaScript (21 September 2026) - Ghost(Pro): Starter $18, Publisher $29, Business $199 a month billed yearly at up to 1,000 members, and Custom with a 99.9 per cent uptime SLA. File size limits of 5 MB, 100 MB, 250 MB and 1 GB - Prices: Self-hosted Ghost free per month (plan); Ghost(Pro) Starter $18 per month (plan); Ghost(Pro) Publisher $29 per month (plan); Ghost(Pro) Business $199 per month (plan) - Scores: Reliability 80, Performance pending, Schema & documentation 51, Agent ergonomics 69, Security & auth 56, Payments & pricing 50, Task success pending, Maintenance & community 85, Transparency & trust 72 · negative events -7 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the graded surface is the open-source release its owner hosts. · Schema & documentation, No OpenAPI or similar file was found in the docs index or the repository (0 of 25). · Agent ergonomics, `fields`, `include` and `formats` size a response, and lists return 15 records by default (20 of 25). · Security & auth, An Admin API key belongs to one custom integration, can be regenerated, and signs tokens that last at most 5 minutes and travel in the Autho… · Payments & pricing, Scored with the self-hosted rule, taking prices from Ghost(Pro) beside the free software. · Maintenance & community, 6.69.0 was tagged and published to npm on 7 October 2026, the day before this check (30). · Transparency & trust, MIT, copyright Ghost Foundation, with the source public (30). - Sources: 28, open questions: 10, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets - JSON: https://www.anchorterminal.com/api/v1/tools/ghost.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/ghost.svg` or a link to https://www.anchorterminal.com/tools/ghost from a page on ghost.org or one of its subdomains, or the README of github.com/TryGhost/Ghost, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set `kid` to the key id, `aud` to `/admin/` and `exp` at most 5 minutes ahead 2. Set `status` to `draft` on every create unless told to publish, and publish later with a PUT that sets `status` to `published` 3. GET the post before each PUT and send its `updated_at` back. Tags and authors in a PUT replace the existing lists 4. Send content as a Lexical JSON string, or add `?source=html` and send `html`. The HTML conversion is lossy unless wrapped in an HTML card 5. Page through lists with `limit` up to 100 and `page`. Since Ghost 6.0 `limit=all` returns 100 items without an error ## Connect ```bash npm install @tryghost/admin-api ``` ```bash curl -H "Authorization: Ghost $token" -H "Accept-Version: $version" https://{admin_domain}/ghost/api/admin/{resource}/ ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/ghost ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.assets, cms.publish | https://www.anchorterminal.com/tools/directus.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)