# Storyblok (slim) > Storyblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools. - Full: https://www.anchorterminal.com/tools/storyblok.md (~7,550 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/storyblok.json · canonical https://www.anchorterminal.com/tools/storyblok - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 67.7/100 · rank #202 of 722 · #4 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request. ## Facts - Kind: HTTP API · vendor: Storyblok GmbH · category: CMS & website publishing · legal entity: Storyblok GmbH · provenance 87/100 - Endpoint: `https://mapi.storyblok.com/v1` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: Management API v1 (REST, JSON) for writes, official hosted MCP server over the same API, Content Delivery API v2 and GraphQL (Premium and Elite) for reads, Storyblok CLI for scripted work - MCP server: Hosted at https://mcp.storyblok.com/mcp, streamable HTTP, POST only. Seven tools in a search, describe, execute pattern. OAuth or a personal access token as a Bearer header - Regions: EU mapi.storyblok.com, US api-us.storyblok.com, Canada api-ca.storyblok.com, Australia api-ap.storyblok.com, China app.storyblokchina.cn, each under /v1 - Credentials: OAuth with PKCE and dynamic client registration, 29 scopes on a read, write and publish hierarchy, per-space selection, refresh tokens and revocation. Personal access tokens with 16 scope groups, a space list and an expiry date - Rate limits: Management API 3 requests a second on Starter, 6 on paid plans. Content Delivery API up to 1,000 a second cached, 50 a second for single entries uncached - Free tier: Starter is free with no card. 1 space, 1 seat, 100,000 API requests a month, 2 locales, 20,000 stories, 2,000 assets. New spaces get a 45-day trial of Growth Plus - Drafts and versions: Stories are drafts unless created with publish true. Publish, unpublish, version list, version compare and restore endpoints. Version retention 1 day on Starter, 30 days on Growth and Growth Plus, 180 days on Premium, unlimited on Elite - Assets: Three-step upload (signed response, POST to S3, finish upload). Maximum file size 500 MB on Starter, 1 GB on Growth and Growth Plus, 5 GB on Premium and Elite - Localisation: Field-level translations written as `field__i18n__` keys in the story content, and folder-level translation. 2 locales on Starter and Growth, 10 on Growth Plus - Pagination: `page` and `per_page` (default 25, maximum 1,000 on the Management API), with `total` and `per_page` response headers. The MCP execute tools take a `fields` filter - SDKs: @storyblok/management-api-client 0.9.1 (1 October 2026) and storyblok-js-client 7.7.7 for JavaScript, php-management-api-client, storyblok-swift and storyblok-kotlin. The CLI is the npm package storyblok, 4.23.4 - Audit: Activity log on every plan, readable through the Activities endpoints. Activity and webhook log retention follows version retention (1 day to unlimited) - SLA: 97 per cent annual average on Growth and Growth Plus, 99.9 per cent on Premium, 99.99 per cent on Elite, none on Starter. The service level page states it for the Content Delivery API - Certifications: ISO 27001 and TISAX per the trust centre. No SOC 2 report or bug bounty found in the reviewed pages - Sub-processors: DPA Annex 3 (effective 22 April 2026) lists AWS for hosting in the EU, US, Canada and Australia, Tiptap, and OpenAI, Google Cloud and Anthropic for AI tools - Open source: No. The SDKs, API clients and CLI in storyblok/monoblok are MIT - Prices: Growth $99 per month (plan); Growth Plus $349 per month (plan); Additional seat $15 per seat per month; Additional API requests on Growth $0.01 per 1,000 requests - Scores: Reliability 79, Performance pending, Schema & documentation 68, Agent ergonomics 78, Security & auth 73, Payments & pricing 35, Task success pending, Maintenance & community 80, Transparency & trust 80 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Graded on the Management API and the hosted MCP server. · Schema & documentation, The only public OpenAPI spec is for the Content Delivery API (3.1, 14 operations). · Agent ergonomics, Seven MCP tools cover the whole Management API through search, describe and execute, and a `fields` filter trims responses before they retur… · Security & auth, OAuth with PKCE S256, dynamic client registration, refresh tokens, revocation and 29 scopes on a read, write and publish hierarchy, or perso… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The changelog has entries on 5 October 2026 and the Management API client 0.9.1 was tagged on 1 October 2026 (30). · Transparency & trust, Closed service with published self-service and enterprise terms, and MIT client libraries (17). - Sources: 20, open questions: 7, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.localisation, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/storyblok.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/storyblok.svg` or a link to https://www.anchorterminal.com/tools/storyblok from a page on storyblok.com or one of its subdomains, or the README of github.com/storyblok/monoblok, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails 2. Create stories without `publish` to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it 3. Write translations as `field__i18n__` keys inside the same content object, and set the component field to translatable first 4. Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl 5. Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422 ## Connect ```bash npm install @storyblok/management-api-client ``` ```bash curl "https://mapi.storyblok.com/v1/spaces/$SPACE_ID/stories/" \ -H "Authorization: $STORYBLOK_PERSONAL_ACCESS_TOKEN" ``` ```bash claude mcp add --transport http Storyblok https://mcp.storyblok.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/storyblok ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Directus | B | 67.1 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | https://www.anchorterminal.com/tools/directus.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)