Strapi
by Strapi, Inc. HTTP API in CMS & website publishing
Strapi, Inc. · strapi.io since 2015 · status page · who's behind it
Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.
Good for Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.
Is this your product? Claim this listing or verify it
Assessment. The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.
Facts
- Transport
- HTTP, Streamable HTTP
- Auth
- API key
- Pricing
- Freemium · $45 / mo
- x402
- No
- Licence
- MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms
- Packages
npm@strapi/strapinpm@strapi/client- Source
- github.com/strapi/strapi
- Docs
- docs.strapi.io
- llms.txt
- published
- Last release
- GitHub stars
- 73k
- npm / week
- 259k
- Graded surface
- The self-hosted Community Edition, version 5.57.0, through its REST Content API and the built-in MCP server. Strapi Cloud hosts the same software and APIs at https://<project>.strapiapp.com
- REST Content API
- Generated per content type under /api. GET, POST, PUT and DELETE on
/api/:pluralApiIdand/api/:pluralApiId/:documentId, withfields,populate,filters,sort,pagination,localeandstatusparameters. GraphQL is a plugin - MCP server
- Built into core since 5.47.0 (28 May 2026 on npm), off by default, POST only at /mcp, stateless, MCP TypeScript SDK 2.0.0 with JSON Schema 2020-12 input and output schemas
- MCP tools
- Per collection type list, get, create, update, delete, publish, unpublish, discard_draft. Per single type get, write, delete, publish, unpublish, discard_draft. Media Library media_list_assets, media_get_asset, media_list_folders, media_update_asset, media_move_assets, media_delete_assets, media_create_folder, media_rename_folder, media_move_folder, media_delete_folder
- Credentials
- API tokens for /api (read-only, full access or custom per content type and action). Admin tokens for admin routes and /mcp (a subset of the owner's role, down to field and locale). Both expire after 7, 30 or 90 days or never, and can be regenerated. Sent as
Authorization: Bearer - Draft and publish
- Per content type. REST
status=draftorstatus=publishedon reads and writes, with published as the default. MCP create writes a draft, with separate publish, unpublish and discard_draft tools - Localisation
localequery parameter on REST and an optionallocaleargument on MCP tools, limited to the locales the token may use- Assets
POST /api/upload(multipart),GET /api/upload/files/page,DELETE /api/upload/files/:id. Folders are managed in the admin panel or through MCP media tools. Strapi Cloud caps non-image files at 200 MB- Version history
- Content History on Growth (14 days) and Enterprise (30 days), created only by admin panel edits
- Audit
- Audit Logs on the Enterprise plan, 90 days by default. MCP entry actions carry
origin: mcp. Reads aren't recorded - Machine-readable docs
- llms.txt, llms-full.txt and a .md copy of every docs page.
strapi openapi generatewrites an OpenAPI 3.1.0 file for a project's own Content API and is marked experimental - Rate limits
- No rate limit on the Content API by default. Admin and Users & Permissions authentication routes allow 5 requests in 5 minutes. Strapi Cloud plans meter monthly API requests
- Runtime
- Node.js 20 to 26, with SQLite, MySQL, MariaDB or PostgreSQL
- Client library
- @strapi/client 1.6.2 for JavaScript and TypeScript (4 June 2026)
- Strapi Cloud
- Starter $35, Pro $90, Business $450 a project a month. Regions US (East), Europe (West) and Asia (Southeast). 99.9 per cent yearly uptime commitment on Business
- Capabilities
- cms.content cms.publish cms.localisation cms.assets cms.schema
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry
- The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields
- Media delete tools preview by default through
dryRunand name what would be removed before anything is deleted - Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version
- MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page
Weaknesses
- Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans
- Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed
- A REST POST or PUT publishes immediately unless the request passes
status=draft - The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations
- Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier
Before you call it notes for agents
- Pass
status=drafton every REST POST and PUT. Without it the Content API publishes the entry at once - Use an Admin token for
/mcpand admin routes and an API token for/api. Each kind is rejected on the other's routes - Upload files with multipart POST to
/api/uploadfirst, then reference the returned file id in the entry. MCP tools can't upload - Call
media_delete_assetsandmedia_delete_folderwithoutdryRunfirst to preview, and take asset ids only frommedia_list_assets - Keep your own copy of an entry before updating it. API and MCP writes create no Content History version
Who's behind it provenance 68/100
- Legal entity namedStrapi, Inc.20/20
- Domain agestrapi.io, registered 2015-09-21 (11 years)15/15
- Endpoint on the vendor's domain is not on strapi.io0/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 3 clauses that cost points4/10
- Privacy policyread, states 6 of the 8 things a reader expects8.5/10
- Status pagestatus.strapi.io10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-10-07, states 7 of 7, 5 to know
TL;DR Dated 2026-10-07. States all 7 things a reader expects. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
introducing automated agents, scripts, or software to create multiple accounts, mine data, or bypass usage limits
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
Competitors of Strapi are strictly prohibited from accessing or using the Solution for any purpose.
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
We may change its terms or discontinue it at any time without notice.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
the right to immediately, without prior notice, suspend the Customer account and/or removing or disabling access by Users to the Solution (and Customer Content maintained thereon) or take such other remedial action Strapi deems reasonable, if Customer engages in any prohibited uses of the Solution.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
shall be submitted to and determined by arbitration in the county of San Francisco, California, U.S.A. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-10-07
Effective as of 7 October 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts Disputes go to the courts of San Francisco
The Agreement shall be governed by and construed in accordance with the California, USA and the courts of San Francisco, County in California shall have exclusive jurisdiction, excluding specifically any conflicts of laws provisions, the United Nations Convention on Contracts for the International Sale of Goods and th…
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $100,
and (d) THE TOTAL LIABILITY OF STRAPI WITH RESPECT TO ANY TRIAL FOR ANY CAUSE OF ACTION RELATING TO THE TRIAL OR ARISING FROM THE TRIAL SHALL BE LIMITED TO $100, PROVIDED THAT STRAPI ASSUMES NO LIABILITY FOR ANY DAMAGE OR LOSS CAUSED BY LOSS OF DATA OR INFORMATION (EVEN PARTIAL).
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
This Agreement may be terminated by either Party: (i) if the other Party materially breaches this Agreement or the Order and fails to cure it within thirty (30) days of receipt of written notice of the breach;
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives thirty days of notice before a change
Strapi may make changes to its Support Policy with thirty (30) days’ notice to Customer (via the support portal or otherwise), provided such change is in connection with a standard change made to its then-current standard support and maintenance terms and there is no material degradation of the support offering.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you do not agree to be bound by the Terms, you must not use the service.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment Names 95% availability
Example: Assuming annual Subscription Fees of $120,000 for the Services, the Credits for an uptime of <95% would be calculated as follows: 30% * ($120,000 / 12) = $3,000
Says whether availability is promised and where the promise is written.
Strapi may use the customer's name and logo when it lists or mentions customers in its marketing and communications.
Customer agrees that Strapi may use Customer’s name and logo, for such purpose.
Noted by a second reader on 2026-10-08.
All project data is erased and cannot be recovered when a project is destroyed or the subscription is cancelled or terminated.
When a project is destroyed or upon cancellation or termination of your Subscription, all project data will be erased and will not be recoverable.
Noted by a second reader on 2026-10-08.
The subscription renews automatically for an equal term and the same subscription parameters unless the customer cancels before the term ends.
Unless Customer cancels the subscription prior to the end of the Subscription Term Customer’s subscription will automatically renew for an equal term to the prior Subscription Term for the exact same Subscription Parameters.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 16,252 words
Privacy policy dated 2023-03-01, states 6 of 8, 1 to know
TL;DR Dated 2023-03-01. States 6 of the 8 things a reader expects, and we didn't find whether data is sold or where data goes. To know before relying on it, no update in three years.
Has not been updated for three years or more
Last update: March 01, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-03-01
Last update: March 01, 2023
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
If you are our customer, please also check the contracts between us: they may contain further details on how we collect and process your data.
The basic statement a privacy policy exists to make.
Says how long data is kept
If you send us a spontaneous application, we will store your data until your withdrawal.
Says when data sent to the service is deleted.
Says who else receives the data
Legitimate interests: Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
You can exercise your rights by sending us an email at privacy@strapi.io.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@strapi.io
You can do this by emailing us at privacy@strapi.io.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Strapi says it improves the service through data analysis and research that includes profiling and machine learning over the user's data, in some cases through third parties.
traffic optimization and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 2,930 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.
A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://<project>.strapiapp.com.
https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.
RDAP for strapi.io gives a registration date of 2015-09-21.
The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs.
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:30 UTC
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- github
strapi/strapiv5.57.0, released 2026-10-07 - npm
@strapi/client1.6.2 - npm
@strapi/strapi5.57.0 - GitHub stars 73k
- npm downloads a week 259k
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/strapi.json
Notable
- The built-in MCP server answers at /mcp over Streamable HTTP once
mcp.enabledis set in config/server, takes an Admin token as a Bearer header, and is a free feature source - Each collection type generates up to 8 MCP tools (list, get, create, update, delete, publish, unpublish, discard_draft), each single type up to 6, and the Media Library adds 10 source
- Content History versions are created only for edits made in the admin panel, not for REST, GraphQL, Document Service or import writes, and are kept 14 days on Growth and 30 days on Enterprise source
- The REST API defaults to published for POST and PUT, while MCP create tools write a draft when Draft & Publish is on source
- Advisories GHSA-rjg2-95x7-8qmx and GHSA-3xcq-8mjw-h6mx, both rated critical, were published on 13 May 2026 for versions up to 5.36.1 and 5.33.1 source
- Strapi Cloud costs $35, $90 or $450 a project a month with 100,000, 1 million or 10 million API requests included and $1.50 per further 25,000 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 16.4 | |
Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in engines (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.0 | |
No published OpenAPI file, because endpoints depend on each project's content types. strapi openapi generate writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as Content-manager list for api::article.article (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15). | |||
| Agent ergonomics | 13%16.2 | 10.6 | |
A project with five collection types and Draft & Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST fields selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no readOnlyHint or destructiveHint in the MCP source. PUT by documentId is repeatable and media deletes have dryRun (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15). | |||
| Security & auth | 14%17.5 | 11.6 | |
API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with origin: mcp but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20). | |||
| Payments & pricing | 10%12.5 | 6.2 | |
Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (create-strapi, strapi admin:create-user) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.6 | |
| v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10). | |||
| Transparency & trusteditorial 75, provenance 68 | 7%8.8 | 6.3 | |
| MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated "standard periods", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20). | |||
| Negative events | ≤15 |
| -6 |
| Total | 65.7 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Strapi, or have the agent fetch /fixes/strapi.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Strapi From Anchor Terminal's listing at https://www.anchorterminal.com/tools/strapi, the October 2026 research run, assessed 7 October 2026. Grade B, 65.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Strapi: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 50 out of 100, up to 6.3 more on the total Why it scored 50: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 66 out of 100, up to 6 more on the total Why it scored 66: API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Agent ergonomics, 65 out of 100, up to 5.7 more on the total Why it scored 65: A project with five collection types and Draft & Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Reliability, 82 out of 100, up to 3.6 more on the total Why it scored 82: Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 5. Schema & documentation, 80 out of 100, up to 3.3 more on the total Why it scored 80: No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Transparency & trust, 72 out of 100, up to 2.5 more on the total Made of editorial 75, provenance 68. Why it scored 72: MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated "standard periods", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Endpoint on the vendor's domain: is not on strapi.io (0 of 15) - Terms of service: read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points (4 of 10) - Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 87 out of 100, up to 1.1 more on the total Why it scored 87: v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text - unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers - unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date) - unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return - The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan - The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read - We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0 - The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers ## Weaknesses - Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans - Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed - A REST POST or PUT publishes immediately unless the request passes `status=draft` - The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations - Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once - Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes - Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload - Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets` - Keep your own copy of an entry before updating it. API and MCP writes create no Content History version ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text
- unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers
- unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)
- unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return
- The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan
- The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read
- We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0
- The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers
Sources 25
- MCP server docs docs.strapi.io · seen 2026-10-07
- Admin tokens docs.strapi.io · seen 2026-10-07
- API tokens docs.strapi.io · seen 2026-10-07
- REST API reference docs.strapi.io · seen 2026-10-07
- REST status parameter docs.strapi.io · seen 2026-10-07
- Upload API docs.strapi.io · seen 2026-10-07
- Content History docs.strapi.io · seen 2026-10-07
- Audit Logs docs.strapi.io · seen 2026-10-07
- OpenAPI generation docs.strapi.io · seen 2026-10-07
- error format docs.strapi.io · seen 2026-10-07
- telemetry docs.strapi.io · seen 2026-10-07
- docs index for agents docs.strapi.io · seen 2026-10-07
- repository, licence, SECURITY.md, tags and MCP source (clone) github.com · seen 2026-10-07
- security advisories github.com · seen 2026-10-07
- release notes github.com · seen 2026-10-07
- CI runs api.github.com · seen 2026-10-07
- npm package and version registry.npmjs.org · seen 2026-10-07
- Strapi Cloud pricing strapi.io · seen 2026-10-07
- self-hosted pricing strapi.io · seen 2026-10-07
- Cloud billing and overage rates docs.strapi.io · seen 2026-10-07
- Cloud terms, policies, service levels and DPA strapi.io · seen 2026-10-07
- privacy policy strapi.io · seen 2026-10-07
- security page strapi.io · seen 2026-10-07
- status page status.strapi.io · seen 2026-10-07
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $45 / mo The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Community Edition, self-hosted | free | per month (plan) | MIT, unlimited seats, you pay for your own hosting |
| Growth, self-hosted | $45 | per month (plan) | 3 seats included, $15 per extra seat |
| Strapi Cloud Starter | $35 | per month (plan) | per project, 100,000 API requests |
| Strapi Cloud Pro | $90 | per month (plan) | per project, 1 million API requests |
| Strapi Cloud Business | $450 | per month (plan) | per project, 10 million API requests |
| Strapi Cloud API requests over the plan | $0.06 | per 1,000 requests | $1.50 per 25,000 |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/strapi.xml, or this listing's score history at history.json.
Connect
Install
npx create-strapi@latest
First request
curl 'http://localhost:1337/api/restaurants?status=draft' \
-H "Authorization: Bearer $STRAPI_API_TOKEN"
Claude Code
claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H "Authorization: Bearer YOUR_ADMIN_TOKEN"
MCP client configuration
{
"mcpServers": {
"strapi-mcp": {
"headers": {
"Authorization": "Bearer YOUR_ADMIN_TOKEN"
},
"type": "streamable-http",
"url": "http://localhost:1337/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/strapi
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Sanity BBStoryblok BContentstack B
Head to head Contentstack vs Strapi · Sanity vs Strapi · Storyblok vs Strapi
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Sanity Sanity US Inc. and Sanity AS | BB | 73.7 | cms.content cms.publish cms.assets cms.schema cms.localisation | no |
| Storyblok Storyblok GmbH | B | 67.7 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| Contentstack Contentstack Inc. | B | 64 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
Machine-readable
- JSON
/api/v1/tools/strapi.json· historyhistory.json· badge/badges/strapi.svg· changes feed/feeds/tools/strapi.xml - Markdown
/tools/strapi.md· slim/tools/strapi.min.md(or sendAccept: text/markdown) - Fix list
/fixes/strapi.md·/fixes/strapi.json - From a terminal
anchor tool strapi --md(the CLI) · over MCPget_tool {"slug": "strapi"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/strapi"><img src="https://www.anchorterminal.com/badges/strapi.svg" alt="Strapi on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/strapi)<a href="https://www.anchorterminal.com/tools/strapi">Strapi on Anchor Terminal</a>It counts on a page on strapi.io or one of its subdomains, or the README of github.com/strapi/strapi.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "strapi", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
