{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/webflow.json",
        "name": "Webflow",
        "score": 69.4,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "webflow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/storyblok.json",
        "name": "Storyblok",
        "score": 67.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "storyblok"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/strapi.json",
        "name": "Strapi",
        "score": 65.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.localisation",
          "cms.assets",
          "cms.schema"
        ],
        "slug": "strapi"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/contentstack.json",
        "name": "Contentstack",
        "score": 64,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "contentstack"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/wordpress.json",
        "name": "WordPress",
        "score": 64.8,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "wordpress"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ghost.json",
        "name": "Ghost",
        "score": 58.3,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "ghost"
      }
    ],
    "tool": {
      "slug": "sanity",
      "name": "Sanity",
      "vendor": "Sanity US Inc. and Sanity AS",
      "vendorUrl": "https://www.sanity.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io.",
      "url": "https://www.anchorterminal.com/tools/sanity",
      "markdownUrl": "https://www.anchorterminal.com/tools/sanity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sanity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sanity.json",
      "repo": "https://github.com/sanity-io/sanity",
      "license": "Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.sanity.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@sanity/client"
        },
        {
          "registry": "npm",
          "name": "sanity"
        },
        {
          "registry": "packagist",
          "name": "sanity/sanity-php"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The HTTP API takes a Bearer token. Robot tokens are created in sanity.io/manage, with the CLI or through the Access API, carry a role (Viewer and Editor tokens on every plan), last until deleted unless given an expiry, and are shown once. Personal tokens last a year and act as the user. The MCP server at mcp.sanity.io uses OAuth with PKCE and dynamic client registration by default, with one scope named `global` and sessions of about 7 days, or accepts a token in the `Authorization` header. Custom roles that limit a token to a dataset or document type are Enterprise only. No app review or sales approval is needed.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with no card, 20 seats, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, and hard caps that answer 402 when reached. Growth is $15 a seat a month with overage billed per unit. Enterprise is priced by sales. New projects get a Growth trial with Free plan quotas. An agent can start on the Free plan once a person has created the account (checked 2026-10-07).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation (llms-full.txt) or on the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 53,
      "popularity": {
        "githubStars": 6352,
        "npmWeekly": 4069926,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.sanity.io/docs",
      "llmsTxt": "https://www.sanity.io/docs/llms.txt",
      "openapi": "https://www.sanity.io/docs/api/openapi",
      "registryName": "io.sanity.www/mcp",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.schema",
        "cms.localisation"
      ],
      "tags": [
        "hosted",
        "headless-cms",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "groq",
        "graphql",
        "javascript",
        "php",
        "free-tier",
        "status-page",
        "soc2",
        "open-source-studio"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.7,
        "grade": "BB",
        "agentReady": true,
        "rank": 69,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 89,
          "payments": 40,
          "reliability": 77,
          "schema": 87,
          "security": 67,
          "transparency": 87
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 77,
            "points": 15.4,
            "reason": "Graded on the hosted HTTP API and the hosted MCP server. Statuspage at www.sanity-status.com with 25 components, including api.sanity.io, apicdn.sanity.io and MCP Server, and a full incident history (20). Between 9 July and 7 October 2026 it lists three incidents marked major. Studio connectivity on api.sanity.io on 22 July stayed open for 6 hours 20 minutes with two recurrences, API and API CDN errors on 14 August were resolved in 46 minutes, and Content Agent errors on 23 September lasted 59 minutes. Minor incidents include mutation errors for some projects on 15 September. We read that as one major outage of the core API (10). Rate limits are published with numbers, 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries and 100 concurrent mutations per dataset (15). 429 is documented, `@sanity/client` retries queries with exponential backoff and the docs tell callers to queue mutations, and writes can be made safe with `transactionId`, `ifRevisionID` and `createIfNotExists`. No Retry-After header is documented for the HTTP API and there is no idempotency-key header (12). The SLA at sanity.io/legal/sla commits to 99.9 per cent on Enterprise E1 and 99.95 per cent on E2 (10). The HTTP API is generally available and the MCP server has been since v2.6.0 on 11 December 2025 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 87,
            "points": 14.14,
            "reason": "26 OpenAPI specs covering 225 operations are public at www.sanity.io/docs/api/openapi and through `sanity openapi get` (25). llms.txt, llms-full.txt and a Markdown copy of every documentation page (10). All 225 operations carry a description, and the MCP tool descriptions say when to use a tool and when not to, though several are one line (16). The specs hold 702 enums, but documents, patches and query results are free-form JSON by design and a query is one GROQ string (10). 1,272 example keys across the specs. 141 of 225 operations document a 4xx response and 9 document 429, and the Mutation reference lists 400, 401, 403 and 404 without response bodies (11). Dated API versions in the URL and a public changelog with an entry per release (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 74,
            "points": 12.03,
            "reason": "GROQ projections and slices let a caller choose the fields and the number of results, and MCP query responses are limited to 64 KiB. The MCP server documents 53 tools, which scores 5 on the MCP line with no toolsets or read-only subset documented, so we settled on 15 of 25 across both surfaces. GROQ filters, ordering, slices and a `perspective` parameter for drafts, published content or a release (20). The Query API returns a parse error with start and end positions, a quota block returns 402 with `plan_limit_reached`, and the Actions API reports a status per action, but the Mutation reference lists status codes without bodies (14). `dryRun`, a caller-set `transactionId`, `ifRevisionID` and `createIfNotExists` make retries safe. The v2.14.0 changelog says read-only and destructive annotations were added to MCP tools, which we couldn't read without a token (15). Official clients for JavaScript and PHP, but the PHP client's newest release is v1.5.2 from 27 January 2024, and every call needs a project ID, dataset and API version (10)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 67,
            "points": 11.73,
            "reason": "The MCP server uses OAuth with PKCE, dynamic client registration and a revocation endpoint, but lists one scope, `global`. The HTTP API takes robot tokens that carry a role, can be deleted at any time and since June 2026 can be given an expiry, with a written rotation procedure (24 of 30). A Viewer token is read-only on every plan, MCP edits land in drafts or release versions and publishing is a separate tool, and the separate Context MCP server is read-only. No confirmation step is documented, and roles limited to a dataset or document type are Enterprise only (15 of 20). No prompt-injection guidance found in the MCP documentation. Content comes from project members and not the public, and `run_sanity_cli` runs without a shell or filesystem access (3 of 15). Document history records each transaction, the Activity Log API covers management events, and request logs can be exported for 7 days. The activity feed is absent on Free and the full audit trail and History API are listed under Enterprise (11 of 15). SOC 2 Type 2, a vulnerability disclosure programme and a security.txt without an Expires field. The bug bounty pilot has closed and no ISO 27001 certificate of Sanity's own was found (14 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 in the documentation or on the pricing page (0). Plans and unit prices are public. Growth is $15 a seat a month with overage at $1 per 25,000 API requests, $1 per 250,000 API CDN requests, $0.30 a GB of bandwidth and $0.50 a GB of assets (20). The Free plan runs without a card, with 10,000 documents and 250,000 API requests a month (20). A person has to create the account in a browser. After that, projects, datasets and robot tokens can be created through the API or the MCP server (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 89,
            "points": 7.79,
            "reason": "MCP server v2.40.0 on 2 October 2026 and Sanity Studio v6.18.0 on 6 October 2026 (30). The MCP registry lists 30 versions of the server published between 15 July and 2 October 2026, each with a changelog entry or a patch note (20). The open-source Studio repository has 6,352 stars and 284 open issues and pull requests. Two of the three newest open issues had comments when we looked, a small sample, and there is a Discord channel for the MCP server (17 of 25). io.sanity.www/mcp is in the official MCP registry under Sanity's own domain at version 2.40.0, and `@sanity/client` is at 8.9.0 (15). Packages are current and require Node 22.12 or later. We didn't read their CI (7 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 87,
            "points": 7.61,
            "note": "editorial 79, provenance 95",
            "reason": "Sanity Studio, the CLI and `@sanity/client` are MIT. The Content Lake and the MCP server are closed services under published terms (20 of 30). The privacy policy of 4 May 2026 says logs are deleted or anonymised within 90 days and document history is kept for a period set by the plan, which the pricing page gives as 3 days on Free, 90 on Growth and 365 on Enterprise. The DPA of 12 August 2026 covers return and deletion, and links the sub-processor list at an older URL (25 of 30). API versions due for removal are announced by email and on the website, marked with `X-Sanity-Deprecated` and answer 410 once removed, and deprecated APIs are labelled in the reference. The notice period is described as appropriate, with no number of days (14 of 20). The sub-processor list of 19 January 2026 names 11 companies with processing locations, with Google Cloud in Belgium as the primary host (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "GROQ projections and slices let a caller choose the fields and the number of results, and MCP query responses are limited to 64 KiB. The MCP server documents 53 tools, which scores 5 on the MCP line with no toolsets or read-only subset documented, so we settled on 15 of 25 across both surfaces. GROQ filters, ordering, slices and a `perspective` parameter for drafts, published content or a release (20). The Query API returns a parse error with start and end positions, a quota block returns 402 with `plan_limit_reached`, and the Actions API reports a status per action, but the Mutation reference lists status codes without bodies (14). `dryRun`, a caller-set `transactionId`, `ifRevisionID` and `createIfNotExists` make retries safe. The v2.14.0 changelog says read-only and destructive annotations were added to MCP tools, which we couldn't read without a token (15). Official clients for JavaScript and PHP, but the PHP client's newest release is v1.5.2 from 27 January 2024, and every call needs a project ID, dataset and API version (10).",
            "maintenance": "MCP server v2.40.0 on 2 October 2026 and Sanity Studio v6.18.0 on 6 October 2026 (30). The MCP registry lists 30 versions of the server published between 15 July and 2 October 2026, each with a changelog entry or a patch note (20). The open-source Studio repository has 6,352 stars and 284 open issues and pull requests. Two of the three newest open issues had comments when we looked, a small sample, and there is a Discord channel for the MCP server (17 of 25). io.sanity.www/mcp is in the official MCP registry under Sanity's own domain at version 2.40.0, and `@sanity/client` is at 8.9.0 (15). Packages are current and require Node 22.12 or later. We didn't read their CI (7 of 10).",
            "payments": "No x402, MPP or L402 in the documentation or on the pricing page (0). Plans and unit prices are public. Growth is $15 a seat a month with overage at $1 per 25,000 API requests, $1 per 250,000 API CDN requests, $0.30 a GB of bandwidth and $0.50 a GB of assets (20). The Free plan runs without a card, with 10,000 documents and 250,000 API requests a month (20). A person has to create the account in a browser. After that, projects, datasets and robot tokens can be created through the API or the MCP server (0).",
            "reliability": "Graded on the hosted HTTP API and the hosted MCP server. Statuspage at www.sanity-status.com with 25 components, including api.sanity.io, apicdn.sanity.io and MCP Server, and a full incident history (20). Between 9 July and 7 October 2026 it lists three incidents marked major. Studio connectivity on api.sanity.io on 22 July stayed open for 6 hours 20 minutes with two recurrences, API and API CDN errors on 14 August were resolved in 46 minutes, and Content Agent errors on 23 September lasted 59 minutes. Minor incidents include mutation errors for some projects on 15 September. We read that as one major outage of the core API (10). Rate limits are published with numbers, 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries and 100 concurrent mutations per dataset (15). 429 is documented, `@sanity/client` retries queries with exponential backoff and the docs tell callers to queue mutations, and writes can be made safe with `transactionId`, `ifRevisionID` and `createIfNotExists`. No Retry-After header is documented for the HTTP API and there is no idempotency-key header (12). The SLA at sanity.io/legal/sla commits to 99.9 per cent on Enterprise E1 and 99.95 per cent on E2 (10). The HTTP API is generally available and the MCP server has been since v2.6.0 on 11 December 2025 (10).",
            "schema": "26 OpenAPI specs covering 225 operations are public at www.sanity.io/docs/api/openapi and through `sanity openapi get` (25). llms.txt, llms-full.txt and a Markdown copy of every documentation page (10). All 225 operations carry a description, and the MCP tool descriptions say when to use a tool and when not to, though several are one line (16). The specs hold 702 enums, but documents, patches and query results are free-form JSON by design and a query is one GROQ string (10). 1,272 example keys across the specs. 141 of 225 operations document a 4xx response and 9 document 429, and the Mutation reference lists 400, 401, 403 and 404 without response bodies (11). Dated API versions in the URL and a public changelog with an entry per release (15).",
            "security": "The MCP server uses OAuth with PKCE, dynamic client registration and a revocation endpoint, but lists one scope, `global`. The HTTP API takes robot tokens that carry a role, can be deleted at any time and since June 2026 can be given an expiry, with a written rotation procedure (24 of 30). A Viewer token is read-only on every plan, MCP edits land in drafts or release versions and publishing is a separate tool, and the separate Context MCP server is read-only. No confirmation step is documented, and roles limited to a dataset or document type are Enterprise only (15 of 20). No prompt-injection guidance found in the MCP documentation. Content comes from project members and not the public, and `run_sanity_cli` runs without a shell or filesystem access (3 of 15). Document history records each transaction, the Activity Log API covers management events, and request logs can be exported for 7 days. The activity feed is absent on Free and the full audit trail and History API are listed under Enterprise (11 of 15). SOC 2 Type 2, a vulnerability disclosure programme and a security.txt without an Expires field. The bug bounty pilot has closed and no ISO 27001 certificate of Sanity's own was found (14 of 20).",
            "transparency": "Sanity Studio, the CLI and `@sanity/client` are MIT. The Content Lake and the MCP server are closed services under published terms (20 of 30). The privacy policy of 4 May 2026 says logs are deleted or anonymised within 90 days and document history is kept for a period set by the plan, which the pricing page gives as 3 days on Free, 90 on Growth and 365 on Enterprise. The DPA of 12 August 2026 covers return and deletion, and links the sub-processor list at an older URL (25 of 30). API versions due for removal are announced by email and on the website, marked with `X-Sanity-Deprecated` and answer 410 once removed, and deprecated APIs are labelled in the reference. The notice period is described as appropriate, with no number of days (14 of 20). The sub-processor list of 19 January 2026 names 11 companies with processing locations, with Google Cloud in Belgium as the primary host (20)."
          },
          "sources": [
            {
              "what": "MCP server documentation and tool list",
              "url": "https://www.sanity.io/docs/ai/mcp-server",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI spec index",
              "url": "https://www.sanity.io/docs/api/openapi",
              "seen": "2026-10-07"
            },
            {
              "what": "HTTP API reference",
              "url": "https://www.sanity.io/docs/http-reference",
              "seen": "2026-10-07"
            },
            {
              "what": "Mutation API reference",
              "url": "https://www.sanity.io/docs/http-reference/mutation",
              "seen": "2026-10-07"
            },
            {
              "what": "technical limits and rate limits",
              "url": "https://www.sanity.io/docs/content-lake/technical-limits",
              "seen": "2026-10-07"
            },
            {
              "what": "API CDN, 429 and retry guidance",
              "url": "https://www.sanity.io/docs/content-lake/api-cdn",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication and tokens",
              "url": "https://www.sanity.io/docs/content-lake/http-auth",
              "seen": "2026-10-07"
            },
            {
              "what": "API versioning and deprecation",
              "url": "https://www.sanity.io/docs/content-lake/api-versioning",
              "seen": "2026-10-07"
            },
            {
              "what": "schema validation",
              "url": "https://www.sanity.io/docs/content-lake/schema-validation-and-the-content-lake",
              "seen": "2026-10-07"
            },
            {
              "what": "roles",
              "url": "https://www.sanity.io/docs/content-lake/roles-concepts",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.sanity.io/pricing",
              "seen": "2026-10-07"
            },
            {
              "what": "plans, quotas and 402 responses",
              "url": "https://www.sanity.io/docs/platform-management/plans-and-payments",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents",
              "url": "https://www.sanity-status.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "changelog",
              "url": "https://www.sanity.io/docs/changelog",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP registry entry",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=sanity",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.sanity.io/.well-known/oauth-authorization-server",
              "seen": "2026-10-07"
            },
            {
              "what": "security page",
              "url": "https://www.sanity.io/security",
              "seen": "2026-10-07"
            },
            {
              "what": "vulnerability disclosure programme",
              "url": "https://www.sanity.io/responsible-disclosure",
              "seen": "2026-10-07"
            },
            {
              "what": "security.txt",
              "url": "https://www.sanity.io/.well-known/security.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "SLA",
              "url": "https://www.sanity.io/legal/sla",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://www.sanity.io/legal/privacy",
              "seen": "2026-10-07"
            },
            {
              "what": "DPA",
              "url": "https://www.sanity.io/legal/dpa",
              "seen": "2026-10-07"
            },
            {
              "what": "sub-processors",
              "url": "https://www.sanity.io/legal/third-party-sub-processors",
              "seen": "2026-10-07"
            },
            {
              "what": "terms of service",
              "url": "https://www.sanity.io/legal/tos",
              "seen": "2026-10-07"
            },
            {
              "what": "npm registry, @sanity/client",
              "url": "https://registry.npmjs.org/@sanity/client/latest",
              "seen": "2026-10-07"
            },
            {
              "what": "Studio repository",
              "url": "https://github.com/sanity-io/sanity",
              "seen": "2026-10-07"
            },
            {
              "what": "llms.txt",
              "url": "https://www.sanity.io/docs/llms.txt",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: MCP tool input schemas and the read-only and destructive annotations, which need an authenticated session. The count of 53 tools comes from the documentation page",
            "unchecked: whether the HTTP API sends a Retry-After header on 429. The documentation mentions it only in MCP tool descriptions",
            "unchecked: CI status of the sanity-io/sanity and sanity-io/client repositories",
            "The pricing page gives the Growth plan 25,000 documents and the technical limits page gives 50,000. We used the pricing page",
            "The 22 July 2026 incident is titled as a Studio connectivity problem but is filed against api.sanity.io. We counted it as a major outage of the core API, and the status page doesn't say how many API calls failed",
            "PyPI download figures were not read, pypistats.org answered 429. Sanity has no official Python client in the documentation we read",
            "No ISO 27001 certificate of Sanity's own was found on the security page, which lists ISO certifications for Google Cloud",
            "lastRelease is the MCP server's v2.40.0 on 2 October 2026. Sanity Studio v6.18.0 followed on 6 October"
          ]
        },
        "negative": 0,
        "verdict": "Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.",
        "bestFor": "Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.",
        "strengths": [
          "26 public OpenAPI specs covering 225 operations at www.sanity.io/docs/api/openapi, plus llms.txt and a Markdown copy of every documentation page",
          "MCP `patch_documents` saves to a draft or release version, never to published content, and `publish_documents` is a separate tool",
          "Mutations and actions accept `dryRun`, a caller-set `transactionId` and `ifRevisionID` for optimistic locking",
          "Free plan with 10,000 documents and 250,000 API requests a month, with Growth overage rates published per unit",
          "MCP server listed in the official MCP registry as io.sanity.www/mcp, with 30 versions published there between 15 July and 2 October 2026"
        ],
        "weaknesses": [
          "Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them",
          "Custom roles scoped to a dataset or document type are an Enterprise feature. Robot tokens on other plans take a built-in role across the project",
          "The MCP OAuth server lists one scope, `global`, and the server documents 53 tools with no toolset or read-only mode",
          "A status incident on 22 July 2026, marked major on api.sanity.io, stayed open for 6 hours 20 minutes with two recurrences",
          "The vulnerability disclosure page says the bug bounty pilot has closed and no rewards are paid"
        ],
        "agentNotes": [
          "Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`.",
          "Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules.",
          "Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.",
          "Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`.",
          "Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.7
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 89,
          "payments": 40,
          "reliability": 77,
          "schema": 87,
          "security": 67,
          "transparency": 79
        },
        "provenanceScore": 95
      },
      "connect": {
        "install": "npx sanity@latest mcp configure",
        "http": "curl -H \"Authorization: Bearer \u003ctoken\u003e\" \"https://\u003cproject\u003e.api.sanity.io/v2021-06-07/data/query/production?query=*\"",
        "claudeCode": "claude mcp add Sanity -t http https://mcp.sanity.io --scope user",
        "config": {
          "mcpServers": {
            "Sanity": {
              "type": "http",
              "url": "https://mcp.sanity.io"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/sanity"
      },
      "notable": [
        "26 OpenAPI specs covering 225 operations are served at https://www.sanity.io/docs/api/openapi and https://www.sanity.io/docs/api/openapi/\u003cslug\u003e, and through the `sanity openapi` CLI command (https://www.sanity.io/docs/cli-reference/openapi)",
        "The hosted MCP server at https://mcp.sanity.io documents 53 tools for documents, releases, schemas, datasets, assets, the Media Library, CORS origins and documentation search (https://www.sanity.io/docs/ai/mcp-server)",
        "Schema validation rules run in Sanity Studio and not on the server, so writes through the HTTP API or a client library are accepted without them (https://www.sanity.io/docs/content-lake/schema-validation-and-the-content-lake)",
        "Rate limits are 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, and 500 concurrent queries and 100 concurrent mutations per dataset (https://www.sanity.io/docs/content-lake/technical-limits)",
        "Robot tokens can carry an expiry since June 2026, set in the management console or with `expiresAt` on the Access API (https://www.sanity.io/docs/content-lake/http-auth)",
        "The status page lists three incidents marked major between 9 July and 7 October 2026, the longest open for 6 hours 20 minutes on 22 July (https://www.sanity-status.com/history)",
        "The pricing page gives Growth 25,000 documents while the technical limits page gives 50,000 (https://www.sanity.io/pricing, https://www.sanity.io/docs/content-lake/technical-limits)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surfaces graded",
          "value": "The hosted HTTP API at https://\u003cprojectId\u003e.api.sanity.io/\u003cversion\u003e and https://api.sanity.io, and the hosted MCP server at https://mcp.sanity.io. The open-source Studio is the editing app and is not a backend an agent can run alone"
        },
        {
          "label": "APIs",
          "value": "26 OpenAPI specs, 225 operations. Query, Mutation, Actions, Assets, History, Listen, Live, Export, Webhooks, Media Library (16), Access (40), Projects (29), Roles (22), Applications (50) and others"
        },
        {
          "label": "MCP server",
          "value": "Hosted at https://mcp.sanity.io, streamable HTTP, 53 documented tools, v2.40.0 on 2 October 2026. OAuth by default or a Bearer token. `generate_image` and `transform_image` consume AI credits"
        },
        {
          "label": "Drafts and publishing",
          "value": "Documents exist as drafts, published documents and release versions. MCP `create_documents` and `patch_documents` write drafts or versions, and `publish_documents` publishes. Scheduling and publishing a release need the Actions API or the Studio"
        },
        {
          "label": "Schema validation",
          "value": "Not enforced by the Content Lake. Rules run in Sanity Studio, in some MCP tools and Agent Actions, and through `sanity documents validate`"
        },
        {
          "label": "Credentials",
          "value": "Robot tokens with a role, project or organisation wide, optional expiry, shown once. Personal tokens last one year. MCP OAuth with PKCE, dynamic client registration, a revocation endpoint and one scope, `global`"
        },
        {
          "label": "Roles",
          "value": "Administrator and Viewer on Free, plus Editor, Developer and Contributor on Growth. Custom roles through the Access API on Enterprise"
        },
        {
          "label": "Rate limits",
          "value": "500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries, 100 concurrent mutations and 5 concurrent exports per dataset. Cached API CDN responses are not limited. The MCP endpoint returned a `ratelimit` header of 10 in 1 second"
        },
        {
          "label": "Size limits",
          "value": "Document 32 MB, mutation request body 4 MB, query run time 1 minute, MCP query response 64 KiB, `patch_documents` 25 documents a call"
        },
        {
          "label": "Free tier",
          "value": "No card. 20 seats, 2 public datasets, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, 100 GB of assets and bandwidth, 1,000 AI credits. Hard caps answer 402 `plan_limit_reached`"
        },
        {
          "label": "History and audit",
          "value": "Draft change history 3 days on Free, 90 on Growth, 365 on Enterprise. Activity feed 90 days on Growth and 365 on Enterprise. Full audit trail and History API listed under Enterprise. Request log export covers 7 days on self-serve plans"
        },
        {
          "label": "Versioning",
          "value": "A date in the URL path, such as v2025-02-19. Deprecated versions send `X-Sanity-Deprecated: true` and removed ones answer 410"
        },
        {
          "label": "Clients",
          "value": "`@sanity/client` 8.9.0 for JavaScript and TypeScript (Node 22.12 or later), sanity-php v1.5.2 from 27 January 2024, both MIT"
        },
        {
          "label": "SLA",
          "value": "99.9 per cent on Enterprise E1 and 99.95 per cent on E2, with service credits. None on Free or Growth"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 covering the Security principle, and GDPR compliance, per sanity.io/security. Hosting on Google Cloud"
        },
        {
          "label": "Sub-processors",
          "value": "11 listed on 19 January 2026 with locations. Google Cloud in Belgium (primary) and the United States, AWS for Functions, and OpenAI, Anthropic and Google for AI functions"
        },
        {
          "label": "Open source",
          "value": "Sanity Studio, the CLI and the clients are MIT (6,352 GitHub stars on sanity-io/sanity). The Content Lake and MCP server are closed"
        }
      ],
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "seat-month",
          "usd": 15,
          "note": "up to 50 seats"
        },
        {
          "item": "API requests over quota (Growth)",
          "unit": "1k-requests",
          "usd": 0.04,
          "note": "$1 per 25,000, after 250,000 a month included"
        },
        {
          "item": "API CDN requests over quota (Growth)",
          "unit": "1k-requests",
          "usd": 0.004,
          "note": "$1 per 250,000, after 1 million a month included"
        },
        {
          "item": "Bandwidth over quota (Growth)",
          "unit": "gb",
          "usd": 0.3,
          "note": "after 100 GB a month included"
        },
        {
          "item": "Increased quota add-on (Growth)",
          "unit": "month",
          "usd": 299,
          "note": "50,000 documents, 1 million API requests, 5 million API CDN requests"
        },
        {
          "item": "Extra dataset (Growth)",
          "unit": "month",
          "usd": 999,
          "note": "per dataset"
        }
      ],
      "provenance": {
        "legalEntity": "Sanity US Inc. (with Sanity AS)",
        "domain": "sanity.io",
        "domainRegistered": "2015-01-07",
        "endpointOnVendorDomain": true,
        "terms": "https://www.sanity.io/legal/tos",
        "privacy": "https://www.sanity.io/legal/privacy",
        "statusPage": "https://www.sanity-status.com",
        "changelog": "https://www.sanity.io/docs/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-07",
        "notes": [
          "The terms of service dated 12 August 2026 are entered into with Sanity US Inc. The privacy policy dated 4 May 2026 is that of Sanity AS and Sanity US Inc. Growth has its own terms at sanity.io/legal/tos-growth, dated 26 March 2026.",
          "The API answers at https://\u003cprojectId\u003e.api.sanity.io and https://api.sanity.io, and the MCP server at https://mcp.sanity.io.",
          "www.sanity.io/.well-known/security.txt names security@sanity.io and the disclosure policy at sanity.io/responsible-disclosure, and has no Expires field.",
          "status.sanity.io answers with the same Statuspage as www.sanity-status.com.",
          "RDAP for sanity.io gives a registration date of 2015-01-07."
        ],
        "score": 95,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Sanity US Inc. (with Sanity AS)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "sanity.io, registered 2015-01-07 (11 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.sanity.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 4 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 5.4,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "www.sanity-status.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.sanity.io/legal/tos",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 5075,
            "points": 5.4,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Excluding conflict of laws rules, the Agreement shall be governed by and construed under the laws of State of California.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…TO SECTION 8.3, EACH PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE AMOUNT OF FEES PAID BY SUBSCRIBER TO SANITY FOR THE SERVICE UNDER THE AGREEMENT DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE ACT THAT GAVE RISE TO THE LIABILITY, EVEN IF THE PARTY HAS BEEN ADVISE…",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Without limiting any of its other rights in law or equity, subject to Section 4.3 herein, in the event any fees are past due, Sanity may suspend its obligations under this Terms and Subscriber’s access to the Service."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "The United Nations Convention on Contracts for the International Sale of Goods and the Uniform Computer Information Transactions Act, as currently enacted by any jurisdiction or as may be codified or amended from time to time by any jurisdiction, do not apply to the Agreement."
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": false
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(g) use the Service for benchmarking or to developing a product which is competitive with any Sanity products or services;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The agreement renews automatically for successive one year periods unless either party gives written notice at least 60 days before the current term ends.",
                "quote": "Thereafter, the Initial Term will automatically be renewed for successive one (1) year periods (each a “Renewal Term”), unless either Party provides the other Party advance written notice of its desire to not renew no later than sixty (60) days prior to the end of the then-current term."
              },
              {
                "date": "2026-10-08",
                "text": "Sanity is not obliged to keep Subscriber Data for more than 30 days after the subscription term expires or is terminated.",
                "quote": "Sanity is not obligated to maintain Subscriber Data for more than thirty (30) days following termination or expiration of the Subscription Term"
              },
              {
                "date": "2026-10-08",
                "text": "Sanity may change at any time how many AI Credits an agent action consumes, and the change applies immediately to actions started after it is published.",
                "quote": "Sanity reserves the right to modify the Consumption Rates listed in the Pricing Documentation at any time. Any changes to Consumption Rates will apply immediately to all agent actions initiated after the update is published."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.sanity.io/legal/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 5528,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "When visiting our Site we collect aggregate statistics about your actions on our Site and store these with a third-party processor for analytics and statistics to improve the Site and Sanity Services."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We delete or anonymize logs within 90 days of collection.",
                "says": "Names a period of 90 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "You may register using third-party identity providers, such as Google and Github."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Selling Personal Data – While we do not sell Personal Data in exchange for monetary consideration, we do disclose Personal Data for other benefits that could be deemed a “sale” under various data protection laws because it is sometimes broadly defined to include activities such as the delivery of interest-based advert…",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Meta also offers an Ad Preferences center to customize your settings, as well as a Privacy Policy with additional information on how you can exercise your rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "…and (b) a description of the categories of personal information disclosed, by contacting us at privacy@sanity.io.",
                "says": "privacy@sanity.io"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…of these regions when it has ensured appropriate safeguards for such Personal Data through use of the standard contractual clauses or other lawful and approved methods.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "…the date on which this Privacy Policy was last updated and the categories of third parties to whom we Sell or Share Personal Information (as those terms are defined in the CCPA)."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Document IDs chosen by users are kept indefinitely, until the whole dataset is deleted.",
                "quote": "Note that user-specified document IDs will be retained in our systems indefinitely (until the entire dataset is deleted), for technical reasons - we strongly recommend that document IDs never contain personal or sensitive data."
              },
              {
                "date": "2026-10-08",
                "text": "Sanity analyses personal data of existing customers to find potential customers with similar characteristics.",
                "quote": "We also analyze Personal Data of our existing customers to find new potential customers who share similar characteristics in order to improve our lead generation efforts and reach individuals and companies who are likely to be interested in our Services."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/sanity.json",
      "live": {
        "slug": "sanity",
        "probe": {
          "target": "https://api.sanity.io",
          "method": "get",
          "lastAt": "2026-10-08T19:08:57.852403582Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 60,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 36,
          "p95ms24h": 81,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.sanity-status.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T19:06:58.382927191Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "sanity-io/sanity",
            "version": "v6.18.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:28:11.279439468Z"
          },
          {
            "registry": "npm",
            "name": "@sanity/client",
            "version": "8.9.0",
            "seenAt": "2026-10-08T16:28:08.05519452Z"
          },
          {
            "registry": "npm",
            "name": "sanity",
            "version": "6.18.0",
            "seenAt": "2026-10-08T16:28:09.308419229Z"
          }
        ],
        "githubStars": 6352,
        "npmWeekly": 4069926,
        "securityTxt": {
          "url": "https://sanity.io/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:50.777207368Z"
        },
        "pages": [
          {
            "url": "https://www.sanity.io/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:11.065534137Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "906020038702"
          },
          {
            "url": "https://www.sanity.io/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:14.320679574Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0a780309f28"
          },
          {
            "url": "https://www.sanity.io/legal/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:15.452818667Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "68f22ec5d44d"
          }
        ],
        "updatedAt": "2026-10-08T19:08:57.852403582Z"
      }
    },
    "verify": {
      "accepts": "a page on sanity.io or one of its subdomains, or the README of github.com/sanity-io/sanity",
      "badgeUrl": "https://www.anchorterminal.com/badges/sanity.svg",
      "body": {
        "slug": "sanity",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/sanity",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/sanity\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/sanity.svg\" alt=\"Sanity on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Sanity on Anchor Terminal](https://www.anchorterminal.com/badges/sanity.svg)](https://www.anchorterminal.com/tools/sanity)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/sanity\"\u003eSanity on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/sanity",
    "json": "https://www.anchorterminal.com/tools/sanity.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/sanity.md",
    "slim": "https://www.anchorterminal.com/tools/sanity.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 73.7/100 · rank #69 of 629 · #1 in CMS \u0026 website publishing · agent-ready · confidence medium**\n\n\n## Assessment\n\nSanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Sanity US Inc. and Sanity AS (https://www.sanity.io) |\n| Kind | HTTP API |\n| Category | CMS \u0026 website publishing (https://www.anchorterminal.com/categories/cms) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://api.sanity.io` |\n| Auth | OAuth or key · Self-serve. The HTTP API takes a Bearer token. Robot tokens are created in sanity.io/manage, with the CLI or through the Access API, carry a role (Viewer and Editor tokens on every plan), last until deleted unless given an expiry, and are shown once. Personal tokens last a year and act as the user. The MCP server at mcp.sanity.io uses OAuth with PKCE and dynamic client registration by default, with one scope named `global` and sessions of about 7 days, or accepts a token in the `Authorization` header. Custom roles that limit a token to a dataset or document type are Enterprise only. No app review or sales approval is needed. |\n| Pricing | Freemium ($15 / seat-mo) · Free plan at $0 with no card, 20 seats, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, and hard caps that answer 402 when reached. Growth is $15 a seat a month with overage billed per unit. Enterprise is priced by sales. New projects get a Growth trial with Free plan quotas. An agent can start on the Free plan once a person has created the account (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the documentation (llms-full.txt) or on the pricing page (checked 2026-10-07). |\n| Licence | Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT |\n| Tools exposed | 53 |\n| Packages | npm: `@sanity/client`; npm: `sanity`; packagist: `sanity/sanity-php` |\n| MCP registry name | `io.sanity.www/mcp` |\n| Source | https://github.com/sanity-io/sanity |\n| Docs | https://www.sanity.io/docs |\n| llms.txt | https://www.sanity.io/docs/llms.txt |\n| Last release | 2026-10-02 |\n| GitHub stars | 6,352 (as of 2026-10-07) |\n| npm downloads / week | 4,069,926 |\n| Surfaces graded | The hosted HTTP API at https://\u003cprojectId\u003e.api.sanity.io/\u003cversion\u003e and https://api.sanity.io, and the hosted MCP server at https://mcp.sanity.io. The open-source Studio is the editing app and is not a backend an agent can run alone |\n| APIs | 26 OpenAPI specs, 225 operations. Query, Mutation, Actions, Assets, History, Listen, Live, Export, Webhooks, Media Library (16), Access (40), Projects (29), Roles (22), Applications (50) and others |\n| MCP server | Hosted at https://mcp.sanity.io, streamable HTTP, 53 documented tools, v2.40.0 on 2 October 2026. OAuth by default or a Bearer token. `generate_image` and `transform_image` consume AI credits |\n| Drafts and publishing | Documents exist as drafts, published documents and release versions. MCP `create_documents` and `patch_documents` write drafts or versions, and `publish_documents` publishes. Scheduling and publishing a release need the Actions API or the Studio |\n| Schema validation | Not enforced by the Content Lake. Rules run in Sanity Studio, in some MCP tools and Agent Actions, and through `sanity documents validate` |\n| Credentials | Robot tokens with a role, project or organisation wide, optional expiry, shown once. Personal tokens last one year. MCP OAuth with PKCE, dynamic client registration, a revocation endpoint and one scope, `global` |\n| Roles | Administrator and Viewer on Free, plus Editor, Developer and Contributor on Growth. Custom roles through the Access API on Enterprise |\n| Rate limits | 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries, 100 concurrent mutations and 5 concurrent exports per dataset. Cached API CDN responses are not limited. The MCP endpoint returned a `ratelimit` header of 10 in 1 second |\n| Size limits | Document 32 MB, mutation request body 4 MB, query run time 1 minute, MCP query response 64 KiB, `patch_documents` 25 documents a call |\n| Free tier | No card. 20 seats, 2 public datasets, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, 100 GB of assets and bandwidth, 1,000 AI credits. Hard caps answer 402 `plan_limit_reached` |\n| History and audit | Draft change history 3 days on Free, 90 on Growth, 365 on Enterprise. Activity feed 90 days on Growth and 365 on Enterprise. Full audit trail and History API listed under Enterprise. Request log export covers 7 days on self-serve plans |\n| Versioning | A date in the URL path, such as v2025-02-19. Deprecated versions send `X-Sanity-Deprecated: true` and removed ones answer 410 |\n| Clients | `@sanity/client` 8.9.0 for JavaScript and TypeScript (Node 22.12 or later), sanity-php v1.5.2 from 27 January 2024, both MIT |\n| SLA | 99.9 per cent on Enterprise E1 and 99.95 per cent on E2, with service credits. None on Free or Growth |\n| Certifications | SOC 2 Type 2 covering the Security principle, and GDPR compliance, per sanity.io/security. Hosting on Google Cloud |\n| Sub-processors | 11 listed on 19 January 2026 with locations. Google Cloud in Belgium (primary) and the United States, AWS for Functions, and OpenAI, Anthropic and Google for AI functions |\n| Open source | Sanity Studio, the CLI and the clients are MIT (6,352 GitHub stars on sanity-io/sanity). The Content Lake and MCP server are closed |\n| Capabilities | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation |\n| Tags | hosted, headless-cms, mcp, oauth, openapi, llms-txt, groq, graphql, javascript, php, free-tier, status-page, soc2, open-source-studio |\n| JSON | https://www.anchorterminal.com/api/v1/tools/sanity.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 77 | 15.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 87 | 14.1 |\n| Agent ergonomics | 13% | 16.2 | 74 | 12.0 |\n| Security \u0026 auth | 14% | 17.5 | 67 | 11.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 89 | 7.8 |\n| Transparency \u0026 trust (editorial 79, provenance 95) | 7% | 8.8 | 87 | 7.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **73.7 → BB** |\n\n### Why each score\n\n- Reliability 77: Graded on the hosted HTTP API and the hosted MCP server. Statuspage at www.sanity-status.com with 25 components, including api.sanity.io, apicdn.sanity.io and MCP Server, and a full incident history (20). Between 9 July and 7 October 2026 it lists three incidents marked major. Studio connectivity on api.sanity.io on 22 July stayed open for 6 hours 20 minutes with two recurrences, API and API CDN errors on 14 August were resolved in 46 minutes, and Content Agent errors on 23 September lasted 59 minutes. Minor incidents include mutation errors for some projects on 15 September. We read that as one major outage of the core API (10). Rate limits are published with numbers, 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries and 100 concurrent mutations per dataset (15). 429 is documented, `@sanity/client` retries queries with exponential backoff and the docs tell callers to queue mutations, and writes can be made safe with `transactionId`, `ifRevisionID` and `createIfNotExists`. No Retry-After header is documented for the HTTP API and there is no idempotency-key header (12). The SLA at sanity.io/legal/sla commits to 99.9 per cent on Enterprise E1 and 99.95 per cent on E2 (10). The HTTP API is generally available and the MCP server has been since v2.6.0 on 11 December 2025 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 87: 26 OpenAPI specs covering 225 operations are public at www.sanity.io/docs/api/openapi and through `sanity openapi get` (25). llms.txt, llms-full.txt and a Markdown copy of every documentation page (10). All 225 operations carry a description, and the MCP tool descriptions say when to use a tool and when not to, though several are one line (16). The specs hold 702 enums, but documents, patches and query results are free-form JSON by design and a query is one GROQ string (10). 1,272 example keys across the specs. 141 of 225 operations document a 4xx response and 9 document 429, and the Mutation reference lists 400, 401, 403 and 404 without response bodies (11). Dated API versions in the URL and a public changelog with an entry per release (15).\n- Agent ergonomics 74: GROQ projections and slices let a caller choose the fields and the number of results, and MCP query responses are limited to 64 KiB. The MCP server documents 53 tools, which scores 5 on the MCP line with no toolsets or read-only subset documented, so we settled on 15 of 25 across both surfaces. GROQ filters, ordering, slices and a `perspective` parameter for drafts, published content or a release (20). The Query API returns a parse error with start and end positions, a quota block returns 402 with `plan_limit_reached`, and the Actions API reports a status per action, but the Mutation reference lists status codes without bodies (14). `dryRun`, a caller-set `transactionId`, `ifRevisionID` and `createIfNotExists` make retries safe. The v2.14.0 changelog says read-only and destructive annotations were added to MCP tools, which we couldn't read without a token (15). Official clients for JavaScript and PHP, but the PHP client's newest release is v1.5.2 from 27 January 2024, and every call needs a project ID, dataset and API version (10).\n- Security \u0026 auth 67: The MCP server uses OAuth with PKCE, dynamic client registration and a revocation endpoint, but lists one scope, `global`. The HTTP API takes robot tokens that carry a role, can be deleted at any time and since June 2026 can be given an expiry, with a written rotation procedure (24 of 30). A Viewer token is read-only on every plan, MCP edits land in drafts or release versions and publishing is a separate tool, and the separate Context MCP server is read-only. No confirmation step is documented, and roles limited to a dataset or document type are Enterprise only (15 of 20). No prompt-injection guidance found in the MCP documentation. Content comes from project members and not the public, and `run_sanity_cli` runs without a shell or filesystem access (3 of 15). Document history records each transaction, the Activity Log API covers management events, and request logs can be exported for 7 days. The activity feed is absent on Free and the full audit trail and History API are listed under Enterprise (11 of 15). SOC 2 Type 2, a vulnerability disclosure programme and a security.txt without an Expires field. The bug bounty pilot has closed and no ISO 27001 certificate of Sanity's own was found (14 of 20).\n- Payments \u0026 pricing 40: No x402, MPP or L402 in the documentation or on the pricing page (0). Plans and unit prices are public. Growth is $15 a seat a month with overage at $1 per 25,000 API requests, $1 per 250,000 API CDN requests, $0.30 a GB of bandwidth and $0.50 a GB of assets (20). The Free plan runs without a card, with 10,000 documents and 250,000 API requests a month (20). A person has to create the account in a browser. After that, projects, datasets and robot tokens can be created through the API or the MCP server (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 89: MCP server v2.40.0 on 2 October 2026 and Sanity Studio v6.18.0 on 6 October 2026 (30). The MCP registry lists 30 versions of the server published between 15 July and 2 October 2026, each with a changelog entry or a patch note (20). The open-source Studio repository has 6,352 stars and 284 open issues and pull requests. Two of the three newest open issues had comments when we looked, a small sample, and there is a Discord channel for the MCP server (17 of 25). io.sanity.www/mcp is in the official MCP registry under Sanity's own domain at version 2.40.0, and `@sanity/client` is at 8.9.0 (15). Packages are current and require Node 22.12 or later. We didn't read their CI (7 of 10).\n- Transparency \u0026 trust 87: Sanity Studio, the CLI and `@sanity/client` are MIT. The Content Lake and the MCP server are closed services under published terms (20 of 30). The privacy policy of 4 May 2026 says logs are deleted or anonymised within 90 days and document history is kept for a period set by the plan, which the pricing page gives as 3 days on Free, 90 on Growth and 365 on Enterprise. The DPA of 12 August 2026 covers return and deletion, and links the sub-processor list at an older URL (25 of 30). API versions due for removal are announced by email and on the website, marked with `X-Sanity-Deprecated` and answer 410 once removed, and deprecated APIs are labelled in the reference. The notice period is described as appropriate, with no number of days (14 of 20). The sub-processor list of 19 January 2026 names 11 companies with processing locations, with Google Cloud in Belgium as the primary host (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/sanity.md (JSON https://www.anchorterminal.com/fixes/sanity.json)\n\n### What we couldn't check\n\n- unchecked: MCP tool input schemas and the read-only and destructive annotations, which need an authenticated session. The count of 53 tools comes from the documentation page\n- unchecked: whether the HTTP API sends a Retry-After header on 429. The documentation mentions it only in MCP tool descriptions\n- unchecked: CI status of the sanity-io/sanity and sanity-io/client repositories\n- The pricing page gives the Growth plan 25,000 documents and the technical limits page gives 50,000. We used the pricing page\n- The 22 July 2026 incident is titled as a Studio connectivity problem but is filed against api.sanity.io. We counted it as a major outage of the core API, and the status page doesn't say how many API calls failed\n- PyPI download figures were not read, pypistats.org answered 429. Sanity has no official Python client in the documentation we read\n- No ISO 27001 certificate of Sanity's own was found on the security page, which lists ISO certifications for Google Cloud\n- lastRelease is the MCP server's v2.40.0 on 2 October 2026. Sanity Studio v6.18.0 followed on 6 October\n\n### Sources\n\n- MCP server documentation and tool list: \u003chttps://www.sanity.io/docs/ai/mcp-server\u003e (seen 2026-10-07)\n- OpenAPI spec index: \u003chttps://www.sanity.io/docs/api/openapi\u003e (seen 2026-10-07)\n- HTTP API reference: \u003chttps://www.sanity.io/docs/http-reference\u003e (seen 2026-10-07)\n- Mutation API reference: \u003chttps://www.sanity.io/docs/http-reference/mutation\u003e (seen 2026-10-07)\n- technical limits and rate limits: \u003chttps://www.sanity.io/docs/content-lake/technical-limits\u003e (seen 2026-10-07)\n- API CDN, 429 and retry guidance: \u003chttps://www.sanity.io/docs/content-lake/api-cdn\u003e (seen 2026-10-07)\n- authentication and tokens: \u003chttps://www.sanity.io/docs/content-lake/http-auth\u003e (seen 2026-10-07)\n- API versioning and deprecation: \u003chttps://www.sanity.io/docs/content-lake/api-versioning\u003e (seen 2026-10-07)\n- schema validation: \u003chttps://www.sanity.io/docs/content-lake/schema-validation-and-the-content-lake\u003e (seen 2026-10-07)\n- roles: \u003chttps://www.sanity.io/docs/content-lake/roles-concepts\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.sanity.io/pricing\u003e (seen 2026-10-07)\n- plans, quotas and 402 responses: \u003chttps://www.sanity.io/docs/platform-management/plans-and-payments\u003e (seen 2026-10-07)\n- status incidents: \u003chttps://www.sanity-status.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- changelog: \u003chttps://www.sanity.io/docs/changelog\u003e (seen 2026-10-07)\n- MCP registry entry: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=sanity\u003e (seen 2026-10-07)\n- MCP OAuth metadata: \u003chttps://mcp.sanity.io/.well-known/oauth-authorization-server\u003e (seen 2026-10-07)\n- security page: \u003chttps://www.sanity.io/security\u003e (seen 2026-10-07)\n- vulnerability disclosure programme: \u003chttps://www.sanity.io/responsible-disclosure\u003e (seen 2026-10-07)\n- security.txt: \u003chttps://www.sanity.io/.well-known/security.txt\u003e (seen 2026-10-07)\n- SLA: \u003chttps://www.sanity.io/legal/sla\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://www.sanity.io/legal/privacy\u003e (seen 2026-10-07)\n- DPA: \u003chttps://www.sanity.io/legal/dpa\u003e (seen 2026-10-07)\n- sub-processors: \u003chttps://www.sanity.io/legal/third-party-sub-processors\u003e (seen 2026-10-07)\n- terms of service: \u003chttps://www.sanity.io/legal/tos\u003e (seen 2026-10-07)\n- npm registry, @sanity/client: \u003chttps://registry.npmjs.org/@sanity/client/latest\u003e (seen 2026-10-07)\n- Studio repository: \u003chttps://github.com/sanity-io/sanity\u003e (seen 2026-10-07)\n- llms.txt: \u003chttps://www.sanity.io/docs/llms.txt\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 95/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Sanity US Inc. (with Sanity AS) | 20/20 |\n| Domain age | sanity.io, registered 2015-01-07 (11 years) | 15/15 |\n| Endpoint on the vendor's domain | api.sanity.io | 15/15 |\n| Terms of service | read, states 4 of the 7 things a reader expects, and has 1 clause that costs points | 5.4/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | www.sanity-status.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe terms of service dated 12 August 2026 are entered into with Sanity US Inc. The privacy policy dated 4 May 2026 is that of Sanity AS and Sanity US Inc. Growth has its own terms at sanity.io/legal/tos-growth, dated 26 March 2026.\n\nThe API answers at https://\u003cprojectId\u003e.api.sanity.io and https://api.sanity.io, and the MCP server at https://mcp.sanity.io.\n\nwww.sanity.io/.well-known/security.txt names security@sanity.io and the disclosure policy at sanity.io/responsible-disclosure, and has no Expires field.\n\nstatus.sanity.io answers with the same Statuspage as www.sanity-status.com.\n\nRDAP for sanity.io gives a registration date of 2015-01-07.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.sanity.io/legal/tos), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(g) use the Service for benchmarking or to developing a product which is competitive with any Sanity products or services;\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Not found in the text. Lists what users may not do.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). The agreement renews automatically for successive one year periods unless either party gives written notice at least 60 days before the current term ends. \"Thereafter, the Initial Term will automatically be renewed for successive one (1) year periods (each a “Renewal Term”), unless either Party provides the other Party advance written notice of its desire to not renew no later than sixty (60) days prior to the end of the then-current term.\"\n- Also in the text (2026-10-08). Sanity is not obliged to keep Subscriber Data for more than 30 days after the subscription term expires or is terminated. \"Sanity is not obligated to maintain Subscriber Data for more than thirty (30) days following termination or expiration of the Subscription Term\"\n- Also in the text (2026-10-08). Sanity may change at any time how many AI Credits an agent action consumes, and the change applies immediately to actions started after it is published. \"Sanity reserves the right to modify the Consumption Rates listed in the Pricing Documentation at any time. Any changes to Consumption Rates will apply immediately to all agent actions initiated after the update is published.\"\n\n**Privacy policy** (https://www.sanity.io/legal/privacy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"…the date on which this Privacy Policy was last updated and the categories of third parties to whom we Sell or Share Personal Information (as those terms are defined in the CCPA).\"\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. Names a period of 90 days.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@sanity.io.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Document IDs chosen by users are kept indefinitely, until the whole dataset is deleted. \"Note that user-specified document IDs will be retained in our systems indefinitely (until the entire dataset is deleted), for technical reasons - we strongly recommend that document IDs never contain personal or sensitive data.\"\n- Also in the text (2026-10-08). Sanity analyses personal data of existing customers to find potential customers with similar characteristics. \"We also analyze Personal Data of our existing customers to find new potential customers who share similar characteristics in order to improve our lead generation efforts and reach individuals and companies who are likely to be interested in our Services.\"\n\n## Live (updated 2026-10-08 19:08 UTC)\n\n- Right now: up, HTTP 200, 60 ms, checked 2026-10-08 19:08 UTC (get on `https://api.sanity.io`)\n- Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 36 ms · p95 81 ms\n- Vendor status page: minor, Partially Degraded Service\n- github `sanity-io/sanity` v6.18.0, released 2026-10-06\n- npm `@sanity/client` 8.9.0\n- npm `sanity` 6.18.0\n- security.txt: valid\n- Watching changelog \u003chttps://www.sanity.io/docs/changelog\u003e\n- Watching privacy \u003chttps://www.sanity.io/legal/privacy\u003e\n- Watching terms \u003chttps://www.sanity.io/legal/tos\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/sanity.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Growth | $15 | per seat per month | up to 50 seats |\n| API requests over quota (Growth) | $0.04 | per 1,000 requests | $1 per 25,000, after 250,000 a month included |\n| API CDN requests over quota (Growth) | $0.004 | per 1,000 requests | $1 per 250,000, after 1 million a month included |\n| Bandwidth over quota (Growth) | $0.30 | per GB of traffic | after 100 GB a month included |\n| Increased quota add-on (Growth) | $299 | per month (plan) | 50,000 documents, 1 million API requests, 5 million API CDN requests |\n| Extra dataset (Growth) | $999 | per month (plan) | per dataset |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- 26 public OpenAPI specs covering 225 operations at www.sanity.io/docs/api/openapi, plus llms.txt and a Markdown copy of every documentation page\n- MCP `patch_documents` saves to a draft or release version, never to published content, and `publish_documents` is a separate tool\n- Mutations and actions accept `dryRun`, a caller-set `transactionId` and `ifRevisionID` for optimistic locking\n- Free plan with 10,000 documents and 250,000 API requests a month, with Growth overage rates published per unit\n- MCP server listed in the official MCP registry as io.sanity.www/mcp, with 30 versions published there between 15 July and 2 October 2026\n\n## Weaknesses\n\n- Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them\n- Custom roles scoped to a dataset or document type are an Enterprise feature. Robot tokens on other plans take a built-in role across the project\n- The MCP OAuth server lists one scope, `global`, and the server documents 53 tools with no toolset or read-only mode\n- A status incident on 22 July 2026, marked major on api.sanity.io, stayed open for 6 hours 20 minutes with two recurrences\n- The vulnerability disclosure page says the bug bounty pilot has closed and no rewards are paid\n\n## Before you call it (notes for agents)\n\n1. Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`.\n2. Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules.\n3. Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.\n4. Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`.\n5. Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`.\n\n## Connect\n\nInstall:\n\n```bash\nnpx sanity@latest mcp configure\n```\n\nFirst request:\n\n```bash\ncurl -H \"Authorization: Bearer \u003ctoken\u003e\" \"https://\u003cproject\u003e.api.sanity.io/v2021-06-07/data/query/production?query=*\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add Sanity -t http https://mcp.sanity.io --scope user\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"Sanity\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.sanity.io\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/sanity (letme picks it for cms.assets, the top-graded tool for the job, letme picks it for cms.content, the top-graded tool for the job, letme picks it for cms.localisation, the top-graded tool for the job, letme picks it for cms.publish, the top-graded tool for the job, letme picks it for cms.schema, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Webflow | B | 69.4 | 150 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/webflow.md |\n| Storyblok | B | 67.7 | 188 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/storyblok.md |\n| Strapi | B | 65.7 | 231 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | no | https://www.anchorterminal.com/tools/strapi.md |\n| Contentstack | B | 64 | 264 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/contentstack.md |\n| WordPress | B | 64.8 | 249 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/wordpress.md |\n| Ghost | C | 58.3 | 404 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/ghost.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- 26 OpenAPI specs covering 225 operations are served at https://www.sanity.io/docs/api/openapi and https://www.sanity.io/docs/api/openapi/\u003cslug\u003e, and through the `sanity openapi` CLI command (source: \u003chttps://www.sanity.io/docs/cli-reference/openapi\u003e)\n- The hosted MCP server at https://mcp.sanity.io documents 53 tools for documents, releases, schemas, datasets, assets, the Media Library, CORS origins and documentation search (source: \u003chttps://www.sanity.io/docs/ai/mcp-server\u003e)\n- Schema validation rules run in Sanity Studio and not on the server, so writes through the HTTP API or a client library are accepted without them (source: \u003chttps://www.sanity.io/docs/content-lake/schema-validation-and-the-content-lake\u003e)\n- Rate limits are 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, and 500 concurrent queries and 100 concurrent mutations per dataset (source: \u003chttps://www.sanity.io/docs/content-lake/technical-limits\u003e)\n- Robot tokens can carry an expiry since June 2026, set in the management console or with `expiresAt` on the Access API (source: \u003chttps://www.sanity.io/docs/content-lake/http-auth\u003e)\n- The status page lists three incidents marked major between 9 July and 7 October 2026, the longest open for 6 hours 20 minutes on 22 July (source: \u003chttps://www.sanity-status.com/history\u003e)\n- The pricing page gives Growth 25,000 documents while the technical limits page gives 50,000 (source: \u003chttps://www.sanity.io/pricing, https://www.sanity.io/docs/content-lake/technical-limits\u003e)\n\n## Compare\n\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md): B 64 vs BB 73.7\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md): C 58.3 vs BB 73.7\n- [Sanity vs Storyblok](https://www.anchorterminal.com/compare/sanity-vs-storyblok.md): BB 73.7 vs B 67.7\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md): BB 73.7 vs B 65.7\n- [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md): BB 73.7 vs B 69.4\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md): BB 73.7 vs B 64.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on sanity.io or one of its subdomains, or the README of github.com/sanity-io/sanity. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"sanity\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/sanity\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/sanity.svg\" alt=\"Sanity on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Sanity on Anchor Terminal](https://www.anchorterminal.com/badges/sanity.svg)](https://www.anchorterminal.com/tools/sanity)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/sanity\"\u003eSanity on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Sanity is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/sanity-dark.png\n- Light: https://www.anchorterminal.com/assets/share/sanity-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CMS \u0026 website publishing",
        "url": "https://www.anchorterminal.com/categories/cms"
      },
      {
        "name": "Sanity",
        "url": ""
      }
    ],
    "description": "Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io.",
    "facts": [
      "rank #69 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Sanity",
    "image": "https://www.anchorterminal.com/assets/og/tools-sanity.png",
    "path": "/tools/sanity",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Sanity review for AI agents, grade BB (73.7/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/sanity"
  },
  "tokens": {
    "markdown": 8400,
    "slim": 2180
  },
  "version": 1
}
