# Sanity (slim) > Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io. - Full: https://www.anchorterminal.com/tools/sanity.md (~8,350 tokens) · this version ~2,180 tokens · JSON https://www.anchorterminal.com/tools/sanity.json · canonical https://www.anchorterminal.com/tools/sanity - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 73.7/100 · rank #69 of 629 · #1 in CMS & website publishing · agent-ready · confidence medium** Assessment: Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans. ## Facts - Kind: HTTP API · vendor: Sanity US Inc. and Sanity AS · category: CMS & website publishing · legal entity: Sanity US Inc. (with Sanity AS) · provenance 95/100 - Endpoint: `https://api.sanity.io` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces graded: The hosted HTTP API at https://.api.sanity.io/ and https://api.sanity.io, and the hosted MCP server at https://mcp.sanity.io. The open-source Studio is the editing app and is not a backend an agent can run alone - APIs: 26 OpenAPI specs, 225 operations. Query, Mutation, Actions, Assets, History, Listen, Live, Export, Webhooks, Media Library (16), Access (40), Projects (29), Roles (22), Applications (50) and others - MCP server: Hosted at https://mcp.sanity.io, streamable HTTP, 53 documented tools, v2.40.0 on 2 October 2026. OAuth by default or a Bearer token. `generate_image` and `transform_image` consume AI credits - Drafts and publishing: Documents exist as drafts, published documents and release versions. MCP `create_documents` and `patch_documents` write drafts or versions, and `publish_documents` publishes. Scheduling and publishing a release need the Actions API or the Studio - Schema validation: Not enforced by the Content Lake. Rules run in Sanity Studio, in some MCP tools and Agent Actions, and through `sanity documents validate` - Credentials: Robot tokens with a role, project or organisation wide, optional expiry, shown once. Personal tokens last one year. MCP OAuth with PKCE, dynamic client registration, a revocation endpoint and one scope, `global` - Roles: Administrator and Viewer on Free, plus Editor, Developer and Contributor on Growth. Custom roles through the Access API on Enterprise - Rate limits: 500 requests a second per IP, 25 mutations and 25 uploads a second per IP, 500 concurrent queries, 100 concurrent mutations and 5 concurrent exports per dataset. Cached API CDN responses are not limited. The MCP endpoint returned a `ratelimit` header of 10 in 1 second - Size limits: Document 32 MB, mutation request body 4 MB, query run time 1 minute, MCP query response 64 KiB, `patch_documents` 25 documents a call - Free tier: No card. 20 seats, 2 public datasets, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, 100 GB of assets and bandwidth, 1,000 AI credits. Hard caps answer 402 `plan_limit_reached` - History and audit: Draft change history 3 days on Free, 90 on Growth, 365 on Enterprise. Activity feed 90 days on Growth and 365 on Enterprise. Full audit trail and History API listed under Enterprise. Request log export covers 7 days on self-serve plans - Versioning: A date in the URL path, such as v2025-02-19. Deprecated versions send `X-Sanity-Deprecated: true` and removed ones answer 410 - Clients: `@sanity/client` 8.9.0 for JavaScript and TypeScript (Node 22.12 or later), sanity-php v1.5.2 from 27 January 2024, both MIT - SLA: 99.9 per cent on Enterprise E1 and 99.95 per cent on E2, with service credits. None on Free or Growth - Certifications: SOC 2 Type 2 covering the Security principle, and GDPR compliance, per sanity.io/security. Hosting on Google Cloud - Sub-processors: 11 listed on 19 January 2026 with locations. Google Cloud in Belgium (primary) and the United States, AWS for Functions, and OpenAI, Anthropic and Google for AI functions - Open source: Sanity Studio, the CLI and the clients are MIT (6,352 GitHub stars on sanity-io/sanity). The Content Lake and MCP server are closed - Prices: Growth $15 per seat per month; API requests over quota (Growth) $0.04 per 1,000 requests; API CDN requests over quota (Growth) $0.004 per 1,000 requests; Bandwidth over quota (Growth) $0.30 per GB of traffic; Increased quota add-on (Growth) $299 per month (plan); Extra dataset (Growth) $999 per month (plan) - Scores: Reliability 77, Performance pending, Schema & documentation 87, Agent ergonomics 74, Security & auth 67, Payments & pricing 40, Task success pending, Maintenance & community 89, Transparency & trust 87 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted HTTP API and the hosted MCP server. · Schema & documentation, 26 OpenAPI specs covering 225 operations are public at www.sanity.io/docs/api/openapi and through `sanity openapi get` (25). · Agent ergonomics, GROQ projections and slices let a caller choose the fields and the number of results, and MCP query responses are limited to 64 KiB. · Security & auth, The MCP server uses OAuth with PKCE, dynamic client registration and a revocation endpoint, but lists one scope, `global`. · Payments & pricing, No x402, MPP or L402 in the documentation or on the pricing page (0). · Maintenance & community, MCP server v2.40.0 on 2 October 2026 and Sanity Studio v6.18.0 on 6 October 2026 (30). · Transparency & trust, Sanity Studio, the CLI and `@sanity/client` are MIT. - Sources: 27, open questions: 8, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.schema, cms.localisation - JSON: https://www.anchorterminal.com/api/v1/tools/sanity.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sanity.svg` or a link to https://www.anchorterminal.com/tools/sanity from a page on sanity.io or one of its subdomains, or the README of github.com/sanity-io/sanity, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`. 2. Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules. 3. Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP. 4. Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`. 5. Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`. ## Connect ```bash npx sanity@latest mcp configure ``` ```bash curl -H "Authorization: Bearer " "https://.api.sanity.io/v2021-06-07/data/query/production?query=*" ``` ```bash claude mcp add Sanity -t http https://mcp.sanity.io --scope user ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sanity ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | | Contentstack | B | 64 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/contentstack.min.md | | WordPress | B | 64.8 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/wordpress.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)