Prismic
by Prismic.io Inc. HTTP API in CMS & website publishing
Hosted
Prismic.io Inc. · prismic.io since 2013 · status page · who's behind it
Prismic is a hosted headless CMS and page builder. Agents write to it through the official hosted MCP server (16 tools that stage changes in releases) or the Migration, Asset and Types APIs with a write token.
Good for Teams already on Prismic who want an agent to bulk-edit, localise or migrate pages into releases for human review.
Is this your product? Claim this listing or verify it
Assessment. The hosted MCP server stages every write as a draft in a release, cannot delete, and publishes only when a user with the Publisher role asks. Write tokens for the Migration, Asset and Types APIs have no scopes, no OpenAPI file was found, writes are limited to one request a second, and the acceptable use policy forbids access by scripts.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://mcp.prismic.io/mcp- Auth
- OAuth or key
- Pricing
- Freemium · $10 / mo
- x402
- No
- Licence
- Proprietary service under Prismic's Master Services Agreement. The JavaScript clients, the CLI and the agent skill on GitHub are Apache-2.0
- Tools exposed
- 16
- Packages
npm@prismicio/clientnpm@prismicio/migratenpmprismic- llms.txt
- published
- Last release
- GitHub stars
- 177
- npm / week
- 237k
- Surfaces
- Hosted MCP server for content, Migration API for pages, Asset API for media, Types API for content models, Content API and GraphQL for reads, Prismic CLI for repository settings and models
- MCP server
https://mcp.prismic.io/mcpover HTTP with OAuth. On by default for new repositories, and an Administrator or Owner activates or deactivates it per repository and per environment- MCP tools
- 16. Discovery
list_repositories,list_custom_types,list_shared_slices,list_locales,list_releases,list_document_versions. Readsearch_documents,search_assets,get_document,get_custom_type,get_shared_slice. Writecreate_release,create_document,update_document,upload_asset,publish_release - Write APIs
https://migration.prismic.io/documents(POST, PUT),https://asset-api.prismic.io/assets(GET, POST, PATCH, DELETE),https://customtypes.prismic.io(/customtypes,/slices, insert, update, DELETE)- Credentials
- MCP uses OAuth authorisation code with PKCE S256, dynamic client registration, refresh tokens and revocation, with no scopes in the server metadata. Sign-ins expire after 90 days. The write APIs take a repository write token as a Bearer header plus a
repositoryheader - Rate limits
- Migration API one request a second per repository, Asset API one request a second, Content API 200 requests a second uncached. No MCP limit found
- Drafts and versions
- Migration API and MCP writes are drafts in a release.
list_document_versionslists draft, published, archived and release versions. Full revision history on every plan per the pricing page. No unpublish or rollback tool in MCP - Assets
upload_assetfetches from a URL. The Asset API takes multipart uploads, one asset a request, withlimit,cursorandkeywordon the list call. The acceptable use policy caps files at 20 MB- Localisation
langandalternate_language_idon Migration API pages, andlist_localesin MCP. 2 locales on Free, 3 on Starter, 4 on Small, 5 on Medium, 8 on Platinum- Roles
- Writer, Publisher, Administrator and Owner on Medium and above. On Starter and Small every user is an Administrator. Custom roles per locale on Enterprise
- SDKs
@prismicio/client7.22.3 (8 October 2026) and@prismicio/migrate0.0.2 for JavaScript, Apache-2.0. The CLI is the npm packageprismic, 1.22.1 (5 October 2026). An agent skill in prismicio/skills- Free tier
- Free plan per repository with 1 user, 4 million API calls and 100 GB of CDN bandwidth a month, 2 locales, no overages. The repository is locked when usage exceeds the limits
- Status
- status.prismic.io on incident.io with nine components, the Migration API among them and no MCP component. One incident in the feed, on 14 September 2026
- Hosting
- AWS us-east-1 (Northern Virginia) across three availability zones per the security page. Sub-processor list published as a PDF, revision 16 of July 2026
- Open source
- No. The JavaScript clients, the CLI and the agent skill are Apache-2.0
- Capabilities
- cms.content cms.publish cms.assets cms.localisation cms.schema
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Official hosted MCP server at
https://mcp.prismic.io/mcpwith 16 tools, free on every plan per the 8 June 2026 launch note - MCP writes land as drafts in a release, the server has no delete tool, and
publish_releaseneeds the Publisher role - OAuth on the MCP server with PKCE S256, dynamic client registration, refresh tokens and a revocation endpoint
- Free plan at $0 with the Migration API, 4 million API calls a month and unlimited documents, types and assets
- Root and docs
llms.txt, and every docs page served as Markdown at the same URL plus.md
Weaknesses
- No OpenAPI file for the Migration, Asset or Types APIs in the reviewed documentation. The Types API links a Postman collection
- Write tokens cover the whole repository with no scopes or expiry in the reviewed documentation, and the docs say they carry many privileges
- The Migration and Asset APIs each take one item a request at one request a second, with no idempotency keys
- The acceptable use policy forbids accessing the Solution by bots, programs or scripts, and the terms bar benchmarking without written consent
- Writer and Publisher roles start on the Medium plan ($150 a month). On Starter and Small every user is an Administrator
Before you call it notes for agents
- Ask a repository Administrator to activate Prismic MCP in Settings first. Activation can take several minutes, and each environment has its own setting
- Call
list_repositories, thenget_custom_typeorget_shared_slicefor the empty content template beforecreate_document - Create a release with
create_releaseand write into it. Callpublish_releaseonly on an explicit request, because a publish cannot be undone through MCP - For the Migration API send
Authorization: Bearer <write token>and arepositoryheader, one page a request, one request a second, and keep each returnedidfor later PUT calls - Upload media first (
upload_assetor POST tohttps://asset-api.prismic.io/assets) and reference the assetidin image and media link fields
Who's behind it provenance 85/100
- Legal entity namedPrismic.io Inc.20/20
- Domain ageprismic.io, registered 2013-06-05 (13 years)15/15
- Endpoint on the vendor's domainmcp.prismic.io15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.prismic.io10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2025-12-01, states 6 of 7, 2 to know
TL;DR Dated 2025-12-01. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access and limits on benchmarking.
Restricts automated accesscosts points
You are prohibited from (1) attempting to use or gain unauthorized access to our or to any third-party's networks or equipment and from accessing the Solution using automated means such as “bots” or other computer programs or scripts;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(v) benchmark the performance of the Software or Solution without our prior written consent;
A clause against publishing test results or using the service to build something that competes.
Gives the date it was last updated Last updated 2025-12-01
Last updated Dec 1, 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Delaware
…this Agreement), Prismic's advertising, or any related service (a "Dispute" ) shall be governed by the laws of the State of Delaware, without regard to conflicts of law.
Says where a dispute would be heard and under whose law.
States a limit on its liability
…THIS AGREEMENT (INCLUDING WITH RESPECT TO ANY SOLUTIONS PROVIDED HEREUNDER) IN ANY 12-MONTH PERIOD WILL NOT EXCEED THE TOTAL AMOUNT RECEIVED BY PRISMIC.IO DURING THE PRIOR TWELVE (12) MONTHS OF THIS AGREEMENT FOR THE SPECIFIC SOLUTION GIVING RISE TO SUCH CLAIM(S).
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Either party may terminate this Agreement if the other party commits a material breach and the breach is not cured within sixty (60) days of receipt of written notice describing the nature of the breach.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 7 days of notice before a change
Although we cannot guarantee that you will receive advance notice of repairs or maintenance, we will endeavor to provide at least 7 days notice of scheduled updates and patches.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You may not assign this Agreement or any rights or obligations under this Agreement to a third-party without our prior written consent.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Unless auto-renewal is declined in writing at least 30 days before the term ends, Prismic may renew the agreement for a further term at its then-current list price.
Unless you decline auto-renewal in writing at least thirty (30) days prior to the expiration of the Term, we may automatically renew this Agreement and the related Solution(s) for a successive Term at our then-current list price.
Noted by a second reader on 2026-10-08.
Use of any artificial intelligence function in the service is subject to separate AI Terms of Service.
By using AI Feature(s), you agree to be bound by those additional terms.
Noted by a second reader on 2026-10-08.
Prismic may delete stored data 60 days after it terminates the agreement, or if an order is not renewed within 60 days of expiry.
We may delete your data stored through the Solution (a) sixty (60) days following any termination by us pursuant to Section 4 of this Agreement, or (b) if you fail to renew an applicable Order within sixty (60) days of expiration.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,003 words
Privacy policy dated 2026-04-08, states 8 of 8
TL;DR Dated 2026-04-08. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-04-08
Last updated Apr 8, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
…that you accept the practices and policies outlined in this Privacy Policy, and consent to the fact that we may collect, use, and share your information in any ways outlined in this Policy.
The basic statement a privacy policy exists to make.
Says how long data is kept
Information regarding our subprocessors, the categories of personal data processed, the purposes of processing, applicable retention periods, international data transfers, and your privacy rights is available in our Privacy Policy and the applicable DPA.
Says when data sent to the service is deleted.
Says who else receives the data
In certain cases, we may also share some Personal Data with third parties, but only as described below.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
We neither rent nor sell your Personal Data in personally identifiable form to anyone.
A plain statement either way.
Says what rights people have over their data
Protection of Prismic and Others: We reserve the right to access, read, preserve, and disclose any information that we reasonably believe is necessary to comply with law or court order;
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact dataprivacy@prismic.io
If you are a California resident and would like a copy of this notice, please contact us at dataprivacy@prismic.io.
An address or officer to send a request to.
Says where data is transferred or stored
Right to be informed of the appropriate safeguards where Personal Data is transferred to a third country or to an international organization
The countries data goes to and the safeguard used.
The Prismic MCP does not access or reconstruct the conversation with the AI beyond the information explicitly given to the MCP in a request.
It does not access or reconstruct your conversation with the AI beyond the information explicitly provided to the MCP as part of your request.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 2,906 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms page is a Master Services Agreement, last updated 1 December 2025, between the customer and Prismic.io Inc., with notices to 185 Alewife Brook Parkway, Suite 210, Cambridge, Massachusetts 02138, USA. The legal page gives 9 rue de la Pierre Levée, 75011 Paris, France.
The privacy policy, last updated 8 April 2026, covers the website and the Prismic Services, has a section on Prismic MCP, and links a self-service DPA and a sub-processor list, both PDFs we did not read.
The AI Terms of Service (4 February 2026) name Prismic, Inc. and apply to AI functions.
The MCP server answers at mcp.prismic.io and the write APIs at migration.prismic.io, asset-api.prismic.io and customtypes.prismic.io. The MCP docs name prismic-auth.eu.auth0.com as the sign-in server.
prismic.io/.well-known/security.txt and prismic.io/security.txt return 404. The security page gives security@prismic.io.
RDAP for prismic.io gives a registration date of 2013-06-05.
robots.txt on prismic.io carries Content-Signal ai-train=no, search=yes, ai-input=yes.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 09:03 UTC
Probed every five minutes at https://mcp.prismic.io/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 1 minute ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/prismic.json
Notable
- Prismic MCP shipped on 8 June 2026 as the official MCP server and is listed in the Claude and ChatGPT directories. The launch note says it is free on every plan source
- Since 11 August 2026 the MCP server and the Migration API can publish a release. The note says Prismic is working on a clearer way to confirm a publish from inside the MCP source
- The docs call the Migration API with
@prismicio/clientthe previous way to migrate and recommend an agent with the CLI and the MCP server for new migrations source - Migration API limits are one page a request and one request a second per repository, and a release holds up to 1,000 pages source
- The acceptable use policy forbids accessing the Solution using automated means such as bots or other computer programs or scripts, and uploading files over 20 MB source
- The Master Services Agreement bars benchmarking the Software or Solution without prior written consent source
- The root llms.txt carries guidance addressed to AI models on which Prismic pages to prefer when answering. Recorded as a fact source
- The official MCP registry returns no server for a search on prismic source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 15.6 | |
Graded on the hosted MCP server and the Migration, Asset and Types APIs. Public status page at status.prismic.io with nine components and uptime since July 2026, the Migration API among them and no MCP component (18 of 20). The feed lists one incident, an elevated error rate on the Content API and Editor resolved on 14 September 2026, with both at 99.993 per cent and the Migration API at 100 per cent (25 of 30). Limits published for the Migration API and Asset API (one request a second) and the Content API (200 a second uncached). No MCP limit found (13). The docs say @prismicio/client retries rate-limited queries, and its source reads retry-after on 429. The write API references give no 429 guidance and no idempotency keys (7). The pricing page lists support and uptime SLAs on Enterprise with no figures (5). The Migration API went generally available on 4 August 2025 and the MCP docs carry no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 9.8 | |
No OpenAPI file was found for the Migration, Asset or Types APIs. The Types API links a Postman collection, the client ships TypeScript types, and the MCP tool schemas need a signed-in session we did not have (10 of 25). A root llms.txt, a docs llms.txt and a Markdown copy of every docs page at the same URL plus .md (10). The MCP page gives each tool's purpose and says which to call first, and the docs say when to prefer the packages or an agent over raw HTTP (14). The Migration API reference types every field with formats and allowed values, while data follows the repository's own types and Types API models are free-form JSON (9). One full request body, two error examples and Types API status codes. The Asset API page promises error handling and documents none (9). No version in the write API paths. A dated updates page with four entries in 2026, plus changelogs for the client and CLI (8). | |||
| Agent ergonomics | 13%16.2 | 10.2 | |
16 MCP tools (15), plus 4 because search_documents returns metadata only and get_custom_type returns an empty template to fill in (19 of 25). limit, cursor and keyword on the Asset API, and type, locale, status and tag filters on search_documents (16). Migration API errors return a list naming the property, the value and the fault. Status codes are not listed (12). No idempotency keys. Updates are PUT by id, MCP writes stay as drafts in a release, and we could not read the tool annotations (8). create_document fills missing fields with model defaults. The official SDK is JavaScript only (8). | |||
| Security & auth | 14%17.5 | 8.8 | |
The MCP server uses OAuth with PKCE S256, dynamic client registration, refresh tokens and revocation, with no scopes, and works with the signed-in person's role. Write tokens are revocable, repository-wide and unscoped (20 of 30). MCP has no delete tool, stages writes as drafts and publishes only for a Publisher on request, and an Administrator can switch it off per repository. Writer and Publisher roles need the Medium plan, and write tokens have no read-only form (13). The docs recommend human review before publishing. No guidance on treating stored content as untrusted was found, and upload_asset fetches a URL the agent supplies (5). Revision history on every plan and a version list in MCP. No audit log for API or MCP calls found (6). A security page with yearly penetration tests, external audits and a contact address. No security.txt, bug bounty, SOC 2 or ISO 27001 report for Prismic found (6). | |||
| Payments & pricing | 10%12.5 | 4.4 | |
| No x402, MPP or L402 (0). Plan prices are public from $0 to $675 a month per repository with a unit price for bandwidth overage ($0.30 a GB). Enterprise is priced through sales (15). The Free plan needs no card and includes the Migration API and MCP (20). A person signs up in a browser, then creates the write token or approves the OAuth sign-in (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.9 | |
@prismicio/client 7.22.3 was tagged on 8 October 2026 and the MCP docs were updated on 7 October 2026 (30). Four client tags and eight CLI tags since 17 August 2026 (20). A public updates page, a community forum and a help centre. The client repository shows 2 open issues. We did not sample reply times (11 of 15). Current official JavaScript SDKs and CLI, and listings in the Claude and ChatGPT directories. No entry in the official MCP registry (11). The client and CLI repositories have validate and publish workflows. We did not check that CI passes (7). | |||
| Transparency & trusteditorial 59, provenance 85 | 7%8.8 | 6.3 | |
| Closed service with a published Master Services Agreement, and Apache-2.0 clients (17). Privacy policy of 8 April 2026 with an MCP section, a self-service DPA and deletion of customer data 60 days after termination. The security page of 11 June 2026 still says a DPA is not yet online, the privacy policy still cites Privacy Shield, and the AI terms allow use of AI feature data for training (18 of 30). No written deprecation policy. Notices are dated but brief, such as the old MCP server and Slice Machine, and the terms promise an effort at 7 days' notice of updates (8). A sub-processor list published as a PDF and hosting stated as AWS us-east-1 (16). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 61.9 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Prismic, or have the agent fetch /fixes/prismic.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Prismic From Anchor Terminal's listing at https://www.anchorterminal.com/tools/prismic, the October 2026 research run, assessed 9 October 2026. Grade C, 61.9 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Prismic: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 50 out of 100, up to 8.8 more on the total Why it scored 50: The MCP server uses OAuth with PKCE S256, dynamic client registration, refresh tokens and revocation, with no scopes, and works with the signed-in person's role. Write tokens are revocable, repository-wide and unscoped (20 of 30). MCP has no delete tool, stages writes as drafts and publishes only for a Publisher on request, and an Administrator can switch it off per repository. Writer and Publisher roles need the Medium plan, and write tokens have no read-only form (13). The docs recommend human review before publishing. No guidance on treating stored content as untrusted was found, and `upload_asset` fetches a URL the agent supplies (5). Revision history on every plan and a version list in MCP. No audit log for API or MCP calls found (6). A security page with yearly penetration tests, external audits and a contact address. No security.txt, bug bounty, SOC 2 or ISO 27001 report for Prismic found (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 35 out of 100, up to 8.1 more on the total Why it scored 35: No x402, MPP or L402 (0). Plan prices are public from $0 to $675 a month per repository with a unit price for bandwidth overage ($0.30 a GB). Enterprise is priced through sales (15). The Free plan needs no card and includes the Migration API and MCP (20). A person signs up in a browser, then creates the write token or approves the OAuth sign-in (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Schema & documentation, 60 out of 100, up to 6.5 more on the total Why it scored 60: No OpenAPI file was found for the Migration, Asset or Types APIs. The Types API links a Postman collection, the client ships TypeScript types, and the MCP tool schemas need a signed-in session we did not have (10 of 25). A root llms.txt, a docs llms.txt and a Markdown copy of every docs page at the same URL plus `.md` (10). The MCP page gives each tool's purpose and says which to call first, and the docs say when to prefer the packages or an agent over raw HTTP (14). The Migration API reference types every field with formats and allowed values, while `data` follows the repository's own types and Types API models are free-form JSON (9). One full request body, two error examples and Types API status codes. The Asset API page promises error handling and documents none (9). No version in the write API paths. A dated updates page with four entries in 2026, plus changelogs for the client and CLI (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Agent ergonomics, 63 out of 100, up to 6 more on the total Why it scored 63: 16 MCP tools (15), plus 4 because `search_documents` returns metadata only and `get_custom_type` returns an empty template to fill in (19 of 25). `limit`, `cursor` and `keyword` on the Asset API, and type, locale, status and tag filters on `search_documents` (16). Migration API errors return a list naming the property, the value and the fault. Status codes are not listed (12). No idempotency keys. Updates are PUT by `id`, MCP writes stay as drafts in a release, and we could not read the tool annotations (8). `create_document` fills missing fields with model defaults. The official SDK is JavaScript only (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Reliability, 78 out of 100, up to 4.4 more on the total Why it scored 78: Graded on the hosted MCP server and the Migration, Asset and Types APIs. Public status page at status.prismic.io with nine components and uptime since July 2026, the Migration API among them and no MCP component (18 of 20). The feed lists one incident, an elevated error rate on the Content API and Editor resolved on 14 September 2026, with both at 99.993 per cent and the Migration API at 100 per cent (25 of 30). Limits published for the Migration API and Asset API (one request a second) and the Content API (200 a second uncached). No MCP limit found (13). The docs say `@prismicio/client` retries rate-limited queries, and its source reads `retry-after` on 429. The write API references give no 429 guidance and no idempotency keys (7). The pricing page lists support and uptime SLAs on Enterprise with no figures (5). The Migration API went generally available on 4 August 2025 and the MCP docs carry no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 6. Transparency & trust, 72 out of 100, up to 2.5 more on the total Made of editorial 59, provenance 85. Why it scored 72: Closed service with a published Master Services Agreement, and Apache-2.0 clients (17). Privacy policy of 8 April 2026 with an MCP section, a self-service DPA and deletion of customer data 60 days after termination. The security page of 11 June 2026 still says a DPA is not yet online, the privacy policy still cites Privacy Shield, and the AI terms allow use of AI feature data for training (18 of 30). No written deprecation policy. Notices are dated but brief, such as the old MCP server and Slice Machine, and the terms promise an effort at 7 days' notice of updates (8). A sub-processor list published as a PDF and hosting stated as AWS us-east-1 (16). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 79 out of 100, up to 1.8 more on the total Why it scored 79: `@prismicio/client` 7.22.3 was tagged on 8 October 2026 and the MCP docs were updated on 7 October 2026 (30). Four client tags and eight CLI tags since 17 August 2026 (20). A public updates page, a community forum and a help centre. The client repository shows 2 open issues. We did not sample reply times (11 of 15). Current official JavaScript SDKs and CLI, and listings in the Claude and ChatGPT directories. No entry in the official MCP registry (11). The client and CLI repositories have validate and publish workflows. We did not check that CI passes (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: MCP tool input schemas and annotations, which need a signed-in session - unchecked: the self-service DPA and the sub-processor list, both PDFs linked from the privacy policy - unchecked: monthly billing prices, which sit behind a toggle on the pricing page. The prices recorded are the annual-billing ones - unchecked: whether CI passes on the default branches of prismicio/prismic-client and prismicio/cli - unchecked: whether the CLI's usage tracking is disclosed in its README. The source sends tracking unless a `.prismicrc` file disables it, and the CLI docs page does not mention it - Not established whether write tokens can be scoped or given an expiry. The docs say only that they carry many privileges - Not established how the acceptable use policy's ban on access by bots, programs or scripts applies to the MCP server and the write APIs Prismic documents - Not established what the Enterprise uptime SLA promises. No figure is published - Not established whether the MCP server has its own rate limit or status component - The lead named the Migration API and JavaScript client as the interface. Prismic's docs now call that the previous way and point agents to the hosted MCP server, launched 8 June 2026 ## Weaknesses - No OpenAPI file for the Migration, Asset or Types APIs in the reviewed documentation. The Types API links a Postman collection - Write tokens cover the whole repository with no scopes or expiry in the reviewed documentation, and the docs say they carry many privileges - The Migration and Asset APIs each take one item a request at one request a second, with no idempotency keys - The acceptable use policy forbids accessing the Solution by bots, programs or scripts, and the terms bar benchmarking without written consent - Writer and Publisher roles start on the Medium plan ($150 a month). On Starter and Small every user is an Administrator ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Ask a repository Administrator to activate Prismic MCP in Settings first. Activation can take several minutes, and each environment has its own setting - Call `list_repositories`, then `get_custom_type` or `get_shared_slice` for the empty content template before `create_document` - Create a release with `create_release` and write into it. Call `publish_release` only on an explicit request, because a publish cannot be undone through MCP - For the Migration API send `Authorization: Bearer <write token>` and a `repository` header, one page a request, one request a second, and keep each returned `id` for later PUT calls - Upload media first (`upload_asset` or POST to `https://asset-api.prismic.io/assets`) and reference the asset `id` in image and media link fields ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: MCP tool input schemas and annotations, which need a signed-in session
- unchecked: the self-service DPA and the sub-processor list, both PDFs linked from the privacy policy
- unchecked: monthly billing prices, which sit behind a toggle on the pricing page. The prices recorded are the annual-billing ones
- unchecked: whether CI passes on the default branches of prismicio/prismic-client and prismicio/cli
- unchecked: whether the CLI's usage tracking is disclosed in its README. The source sends tracking unless a
.prismicrcfile disables it, and the CLI docs page does not mention it - Not established whether write tokens can be scoped or given an expiry. The docs say only that they carry many privileges
- Not established how the acceptable use policy's ban on access by bots, programs or scripts applies to the MCP server and the write APIs Prismic documents
- Not established what the Enterprise uptime SLA promises. No figure is published
- Not established whether the MCP server has its own rate limit or status component
- The lead named the Migration API and JavaScript client as the interface. Prismic's docs now call that the previous way and point agents to the hosted MCP server, launched 8 June 2026
Sources 31
- MCP server docs prismic.io · seen 2026-10-09
- MCP OAuth authorisation server metadata mcp.prismic.io · seen 2026-10-09
- Migration API technical reference prismic.io · seen 2026-10-09
- Asset API technical reference prismic.io · seen 2026-10-09
- Types API prismic.io · seen 2026-10-09
- API authentication prismic.io · seen 2026-10-09
- API references index prismic.io · seen 2026-10-09
- migration guide prismic.io · seen 2026-10-09
- programmatic migration guide prismic.io · seen 2026-10-09
- Prismic with AI prismic.io · seen 2026-10-09
- Prismic CLI docs prismic.io · seen 2026-10-09
- Content API limits prismic.io · seen 2026-10-09
- users and roles prismic.io · seen 2026-10-09
- billing prismic.io · seen 2026-10-09
- pricing prismic.io · seen 2026-10-09
- updates page prismic.io · seen 2026-10-09
- Prismic MCP update notes prismic.io · seen 2026-10-09
- Migration API general availability prismic.io · seen 2026-10-09
- status page status.prismic.io · seen 2026-10-09
- status incident feed status.prismic.io · seen 2026-10-09
- Master Services Agreement prismic.io · seen 2026-10-09
- acceptable use policy prismic.io · seen 2026-10-09
- AI terms of service prismic.io · seen 2026-10-09
- privacy policy prismic.io · seen 2026-10-09
- security page prismic.io · seen 2026-10-09
- root llms.txt prismic.io · seen 2026-10-09
- robots.txt prismic.io · seen 2026-10-09
- client repository (changelog, tags, retry code) github.com · seen 2026-10-09
- CLI repository (tags, tracking code) github.com · seen 2026-10-09
- npm registry, @prismicio/client registry.npmjs.org · seen 2026-10-09
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $10 / mo Free is $0 per repository and includes the Migration API, 1 user, 2 locales and 4 million API calls a month, with no card on file needed. Starter is $10, Small $25, Medium $150 and Platinum $675 a month per repository, billed annually. Enterprise is sold through sales. The launch note says Prismic MCP is currently free on every plan (https://prismic.io/pricing, checked 2026-10-09).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Starter | $10 | per month (plan) | per repository, billed annually, 3 users and 3 locales |
| Small | $25 | per month (plan) | per repository, billed annually, 7 users and 4 locales |
| Medium | $150 | per month (plan) | per repository, billed annually, 25 users, 5 million API calls, user roles |
| Platinum | $675 | per month (plan) | per repository, billed annually, unlimited users, 10 million API calls |
| CDN bandwidth overage | $0.30 | per GB of traffic | Starter, Small and Medium. $0.25 on Platinum |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/prismic.xml, or this listing's score history at history.json.
Connect
Install
npm install @prismicio/client @prismicio/migrate
First request
curl --location --request GET 'https://customtypes.prismic.io/customtypes' \
--header 'repository: your-repo-name' \
--header 'Authorization: Bearer <token>'
MCP client configuration
{
"mcpServers": {
"Prismic": {
"url": "https://mcp.prismic.io/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/prismic
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
DatoCMS BBSanity BBWebflow BHygraph BStoryblok BDirectus B
Head to head Contentstack vs Prismic · DatoCMS vs Prismic · Directus vs Prismic · Ghost vs Prismic · Hygraph vs Prismic · Payload vs Prismic · Prismic vs Sanity · Prismic vs Storyblok · Prismic vs Strapi · Prismic vs Webflow · Prismic vs WordPress
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| DatoCMS Dato Srl | BB | 74.4 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| Sanity Sanity US Inc. and Sanity AS | BB | 73.7 | cms.content cms.publish cms.assets cms.schema cms.localisation | no |
| Webflow Webflow, Inc. | B | 69.4 | cms.content cms.publish cms.assets cms.schema cms.localisation | no |
| Hygraph Hygraph GmbH | B | 69.3 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| Storyblok Storyblok GmbH | B | 67.7 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| Directus Monospace Inc. (Directus) | B | 67.1 | cms.content cms.schema cms.assets cms.publish cms.localisation | no |
Machine-readable
- JSON
/api/v1/tools/prismic.json· historyhistory.json· badge/badges/prismic.svg· changes feed/feeds/tools/prismic.xml - Markdown
/tools/prismic.md· slim/tools/prismic.min.md(or sendAccept: text/markdown) - Fix list
/fixes/prismic.md·/fixes/prismic.json - From a terminal
anchor tool prismic --md(the CLI) · over MCPget_tool {"slug": "prismic"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/prismic"><img src="https://www.anchorterminal.com/badges/prismic.svg" alt="Prismic on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/prismic)<a href="https://www.anchorterminal.com/tools/prismic">Prismic on Anchor Terminal</a>It counts on a page on prismic.io or one of its subdomains, or the README of github.com/prismicio/prismic-client.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "prismic", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


