# Hygraph (slim) > Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server. - Full: https://www.anchorterminal.com/tools/hygraph.md (~8,300 tokens) · this version ~2,430 tokens · JSON https://www.anchorterminal.com/tools/hygraph.json · canonical https://www.anchorterminal.com/tools/hygraph - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 69.3/100 · rank #182 of 842 · #4 in CMS & website publishing · not agent-ready · confidence medium** Assessment: Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found. ## Facts - Kind: HTTP API · vendor: Hygraph GmbH · category: CMS & website publishing · legal entity: Hygraph GmbH · provenance 75/100 - Endpoint: `https://mcp.hygraph.com/mcp` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: GraphQL Content API at `https://.hygraph.com/v2//` for reads and writes, a read endpoint on `.cdn.hygraph.com`, a GraphQL Management API for schema and settings, and a hosted MCP server - MCP server: Hosted, streamable HTTP. Content tools `list_entity_types`, `get_entity_schema`, `list_entities`, `get_entities_by_id`, `discover_entities`, `search_content`, `execute_graphql`, `create_entry`, `update_entry` and `publish_entry`. Schema tools `get_project_info`, `get_management_operation_schema` and `submit_batch_migration`. Also `get_ai_guidelines`, `list_agents`, `trigger_agents` and `check_progress`. The global endpoint adds `list_projects` and `list_environments`. Available on all projects - Credentials: Permanent Auth Tokens (JWTs) created in Project Settings, sent as a Bearer header. Hobby allows 3 tokens, Growth 5, Enterprise up to 30. The global MCP endpoint uses OAuth through auth.hygraph.com, whose metadata lists PKCE S256, a registration endpoint and a revocation endpoint - Permissions: Content permissions per token by model, stage, locale and environment for read, create, update, delete, publish and unpublish. Management API permissions apply to all environments. Public API access is off by default. Custom roles are Enterprise only - Rate limits: Uncached requests a second, 5 on Hobby, 25 on Growth, up to 500 on Enterprise. Concurrent operations per environment, 10 queries and 5 mutations on Hobby, 30 and 10 on Growth, 60 and 20 on Enterprise. Cached requests are not limited - Request size: Queries 10 KB and mutations 30 KB on Hobby, 15 KB and 70 KB on Growth, 20 KB and 80 KB on Enterprise. Larger requests return 413 - Free plan: Hobby, no card. Per the pricing page, 1,000 entries, 500,000 API calls and 100 GB of asset traffic a month, 3 seats, 2 locales, 20 models, 1 environment, 5 webhooks, 50 MB an asset. No version history. Usage past the limit returns 402 until the next period - Paid plans: Growth $199 a month with 10,000 entries, 1,000,000 API calls, 500 GB of asset traffic, 10 seats, 3 locales and 2 environments. Overage $0.20 per 10,000 API operations and per GB. Enterprise is priced through sales - Drafts and versions: Mutations write to DRAFT, and publish and unpublish are separate mutations per stage and locale, with batch forms. A version is written on each publish and read through `history` and `Version`. Retention is 14 days on Growth and up to 365 on Enterprise. Restore is documented in Studio only. Scheduled publishing is Enterprise only - Assets: `createAsset` returns a pre-signed upload URL, or takes a remote URL. Projects created before February 2024 may use a legacy asset system with a different upload API - Localisation: Per-field localisation with create, update, upsert and delete of a locale inside entry mutations, and publishing per locale. 2 locales on Hobby, 3 on Growth, up to 80 on Enterprise - Environments: 1 on Hobby, 2 on Growth, up to 10 on Enterprise. The Management SDK can diff one environment against another and apply the result, which replaces the target schema - Pagination: `first`, `last`, `skip`, `before` and `after`, with Relay connection types. Default 10 entries, maximum 100 - Errors: HTTP 400, 401, 402, 403, 404, 413, 429 and 500 with a GraphQL `errors` array of messages and `extensions.requestId`. No error code list - SDKs: `@hygraph/management-sdk` 1.6.1 (19 August 2026), JavaScript and TypeScript, MIT, Node.js 18 or later. No official Content API client. Any GraphQL client works - Audit: Audit logs on Enterprise with 90 days of retention, recording the member or token behind each change. Webhook logs and a usage metrics query on the Management API - SLA: The pricing page lists an uptime SLA of up to 99.95% on Enterprise. The SLA document was not found - Certifications: The site states SOC 2 Type 2 and hosting on ISO 27001 certified infrastructure. No bug bounty or disclosure policy found - Data location: 3 shared regions (EU, US, APAC) on Hobby and 9 on Growth per the pricing page. The status page lists 11 regions. Sub-processors are not named - Open source: No. The Management SDK is MIT - Prices: Growth $199 per month (plan); Additional API operations on Growth $0.02 per 1,000 requests; Additional asset traffic on Growth $0.20 per GB of traffic - Scores: Reliability 89, Performance pending, Schema & documentation 78, Agent ergonomics 72, Security & auth 63, Payments & pricing 35, Task success pending, Maintenance & community 74, Transparency & trust 60 · total over the 7 assessed categories - Why: Reliability, Graded on the GraphQL Content and Management APIs, with the hosted MCP server noted. · Schema & documentation, GraphQL introspection is on by default for each project's Content API, so the contract is machine-readable and specific to the project. · Agent ergonomics, GraphQL field selection sizes every response, `first` defaults to 10 and is capped at 100, and the MCP tool `list_entities` takes a limit an… · Security & auth, Permanent Auth Tokens are JWTs sent as a Bearer header, each limited by model, stage, locale, environment and action, with separate Manageme… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The changelog's newest entry is 30 September 2026 (30). · Transparency & trust, Closed service under published Terms of Service from Hygraph GmbH, with the Management SDK under MIT (15 of 30). - Sources: 28, open questions: 6, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/hygraph.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/hygraph.svg` or a link to https://www.anchorterminal.com/tools/hygraph from a page on hygraph.com or one of its subdomains, or the README of github.com/hygraph/management-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the Permanent Auth Token as `Authorization: Bearer ` to `https://.hygraph.com/v2//`. Read the schema by introspection first, because every type is generated from the project's models 2. Mutations write to DRAFT. Call `publish` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation 3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429 4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed 5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `Version` and write the old values back ## Connect ```bash npm install @hygraph/management-sdk ``` ```bash claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \ --transport http \ --header "Authorization: Bearer ${HYGRAPH_TOKEN}" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/hygraph ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | https://www.anchorterminal.com/tools/directus.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)