Strapi

by Strapi, Inc. HTTP API in CMS & website publishing

Strapi, Inc. · strapi.io since 2015 · status page · who's behind it

Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.

Good for Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.

Is this your product? Claim this listing or verify it

Assessment. The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.

Facts

Transport
HTTP, Streamable HTTP
Auth
API key
Pricing
Freemium · $45 / mo
x402
No
Licence
MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms
Packages
npm @strapi/strapi
npm @strapi/client
llms.txt
published
Last release
GitHub stars
73k
npm / week
259k
Graded surface
The self-hosted Community Edition, version 5.57.0, through its REST Content API and the built-in MCP server. Strapi Cloud hosts the same software and APIs at https://<project>.strapiapp.com
REST Content API
Generated per content type under /api. GET, POST, PUT and DELETE on /api/:pluralApiId and /api/:pluralApiId/:documentId, with fields, populate, filters, sort, pagination, locale and status parameters. GraphQL is a plugin
MCP server
Built into core since 5.47.0 (28 May 2026 on npm), off by default, POST only at /mcp, stateless, MCP TypeScript SDK 2.0.0 with JSON Schema 2020-12 input and output schemas
MCP tools
Per collection type list, get, create, update, delete, publish, unpublish, discard_draft. Per single type get, write, delete, publish, unpublish, discard_draft. Media Library media_list_assets, media_get_asset, media_list_folders, media_update_asset, media_move_assets, media_delete_assets, media_create_folder, media_rename_folder, media_move_folder, media_delete_folder
Credentials
API tokens for /api (read-only, full access or custom per content type and action). Admin tokens for admin routes and /mcp (a subset of the owner's role, down to field and locale). Both expire after 7, 30 or 90 days or never, and can be regenerated. Sent as Authorization: Bearer
Draft and publish
Per content type. REST status=draft or status=published on reads and writes, with published as the default. MCP create writes a draft, with separate publish, unpublish and discard_draft tools
Localisation
locale query parameter on REST and an optional locale argument on MCP tools, limited to the locales the token may use
Assets
POST /api/upload (multipart), GET /api/upload/files/page, DELETE /api/upload/files/:id. Folders are managed in the admin panel or through MCP media tools. Strapi Cloud caps non-image files at 200 MB
Version history
Content History on Growth (14 days) and Enterprise (30 days), created only by admin panel edits
Audit
Audit Logs on the Enterprise plan, 90 days by default. MCP entry actions carry origin: mcp. Reads aren't recorded
Machine-readable docs
llms.txt, llms-full.txt and a .md copy of every docs page. strapi openapi generate writes an OpenAPI 3.1.0 file for a project's own Content API and is marked experimental
Rate limits
No rate limit on the Content API by default. Admin and Users & Permissions authentication routes allow 5 requests in 5 minutes. Strapi Cloud plans meter monthly API requests
Runtime
Node.js 20 to 26, with SQLite, MySQL, MariaDB or PostgreSQL
Client library
@strapi/client 1.6.2 for JavaScript and TypeScript (4 June 2026)
Strapi Cloud
Starter $35, Pro $90, Business $450 a project a month. Regions US (East), Europe (West) and Asia (Southeast). 99.9 per cent yearly uptime commitment on Business

Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry
  • The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields
  • Media delete tools preview by default through dryRun and name what would be removed before anything is deleted
  • Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version
  • MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page

Weaknesses

  • Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans
  • Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed
  • A REST POST or PUT publishes immediately unless the request passes status=draft
  • The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations
  • Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier

Before you call it notes for agents

  1. Pass status=draft on every REST POST and PUT. Without it the Content API publishes the entry at once
  2. Use an Admin token for /mcp and admin routes and an API token for /api. Each kind is rejected on the other's routes
  3. Upload files with multipart POST to /api/upload first, then reference the returned file id in the entry. MCP tools can't upload
  4. Call media_delete_assets and media_delete_folder without dryRun first to preview, and take asset ids only from media_list_assets
  5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version

Who's behind it provenance 68/100

  • Legal entity namedStrapi, Inc.20/20
  • Domain agestrapi.io, registered 2015-09-21 (11 years)15/15
  • Endpoint on the vendor's domain is not on strapi.io0/15
  • Terms of serviceread, states 7 of the 7 things a reader expects, and has 3 clauses that cost points4/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagestatus.strapi.io10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2026-10-07, states 7 of 7, 5 to know

TL;DR Dated 2026-10-07. States all 7 things a reader expects. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.

Restricts automated accesscosts points
introducing automated agents, scripts, or software to create multiple accounts, mine data, or bypass usage limits

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Restricts benchmarking or competitive usecosts points
Competitors of Strapi are strictly prohibited from accessing or using the Solution for any purpose.

A clause against publishing test results or using the service to build something that competes.

Says the terms or the service can change without noticecosts points
We may change its terms or discontinue it at any time without notice.

A customer may not hear about a change before it applies.

Says access can be ended without notice or for any reason
the right to immediately, without prior notice, suspend the Customer account and/or removing or disabling access by Users to the Solution (and Customer Content maintained thereon) or take such other remedial action Strapi deems reasonable, if Customer engages in any prohibited uses of the Solution.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
shall be submitted to and determined by arbitration in the county of San Francisco, California, U.S.A. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-10-07
Effective as of 7 October 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts Disputes go to the courts of San Francisco
The Agreement shall be governed by and construed in accordance with the California, USA and the courts of San Francisco, County in California shall have exclusive jurisdiction, excluding specifically any conflicts of laws provisions, the United Nations Convention on Contracts for the International Sale of Goods and th…

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at $100,
and (d) THE TOTAL LIABILITY OF STRAPI WITH RESPECT TO ANY TRIAL FOR ANY CAUSE OF ACTION RELATING TO THE TRIAL OR ARISING FROM THE TRIAL SHALL BE LIMITED TO $100, PROVIDED THAT STRAPI ASSUMES NO LIABILITY FOR ANY DAMAGE OR LOSS CAUSED BY LOSS OF DATA OR INFORMATION (EVEN PARTIAL).

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
This Agreement may be terminated by either Party: (i) if the other Party materially breaches this Agreement or the Order and fails to cure it within thirty (30) days of receipt of written notice of the breach;

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives thirty days of notice before a change
Strapi may make changes to its Support Policy with thirty (30) days’ notice to Customer (via the support portal or otherwise), provided such change is in connection with a standard change made to its then-current standard support and maintenance terms and there is no material degradation of the support offering.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
If you do not agree to be bound by the Terms, you must not use the service.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment Names 95% availability
Example: Assuming annual Subscription Fees of $120,000 for the Services, the Credits for an uptime of <95% would be calculated as follows: 30% * ($120,000 / 12) = $3,000

Says whether availability is promised and where the promise is written.

Strapi may use the customer's name and logo when it lists or mentions customers in its marketing and communications.
Customer agrees that Strapi may use Customer’s name and logo, for such purpose.

Noted by a second reader on 2026-10-08.

All project data is erased and cannot be recovered when a project is destroyed or the subscription is cancelled or terminated.
When a project is destroyed or upon cancellation or termination of your Subscription, all project data will be erased and will not be recoverable.

Noted by a second reader on 2026-10-08.

The subscription renews automatically for an equal term and the same subscription parameters unless the customer cancels before the term ends.
Unless Customer cancels the subscription prior to the end of the Subscription Term Customer’s subscription will automatically renew for an equal term to the prior Subscription Term for the exact same Subscription Parameters.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 16,252 words

Privacy policy dated 2023-03-01, states 6 of 8, 1 to know

TL;DR Dated 2023-03-01. States 6 of the 8 things a reader expects, and we didn't find whether data is sold or where data goes. To know before relying on it, no update in three years.

Has not been updated for three years or more
Last update: March 01, 2023

The date the document gives for itself is more than three years ago.

Gives the date it was last updated Last updated 2023-03-01
Last update: March 01, 2023

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
If you are our customer, please also check the contracts between us: they may contain further details on how we collect and process your data.

The basic statement a privacy policy exists to make.

Says how long data is kept
If you send us a spontaneous application, we will store your data until your withdrawal.

Says when data sent to the service is deleted.

Says who else receives the data
Legitimate interests: Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
You can exercise your rights by sending us an email at privacy@strapi.io.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@strapi.io
You can do this by emailing us at privacy@strapi.io.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

Strapi says it improves the service through data analysis and research that includes profiling and machine learning over the user's data, in some cases through third parties.
traffic optimization and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 2,930 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.

A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://<project>.strapiapp.com.

https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.

RDAP for strapi.io gives a registration date of 2015-09-21.

The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs.

Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 16:30 UTC

  • Vendor status page unknown, no machine-readable status found · 1 hour ago
  • github strapi/strapi v5.57.0, released 2026-10-07
  • npm @strapi/client 1.6.2
  • npm @strapi/strapi 5.57.0
  • GitHub stars 73k
  • npm downloads a week 259k
  • security.txt none · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/strapi.json

Notable

  • The built-in MCP server answers at /mcp over Streamable HTTP once mcp.enabled is set in config/server, takes an Admin token as a Bearer header, and is a free feature source
  • Each collection type generates up to 8 MCP tools (list, get, create, update, delete, publish, unpublish, discard_draft), each single type up to 6, and the Media Library adds 10 source
  • Content History versions are created only for edits made in the admin panel, not for REST, GraphQL, Document Service or import writes, and are kept 14 days on Growth and 30 days on Enterprise source
  • The REST API defaults to published for POST and PUT, while MCP create tools write a draft when Draft & Publish is on source
  • Advisories GHSA-rjg2-95x7-8qmx and GHSA-3xcq-8mjw-h6mx, both rated critical, were published on 13 May 2026 for versions up to 5.36.1 and 5.33.1 source
  • Strapi Cloud costs $35, $90 or $450 a project a month with 100,000, 1 million or 10 million API requests included and $1.50 per further 25,000 source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.4
Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in engines (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.0
No published OpenAPI file, because endpoints depend on each project's content types. strapi openapi generate writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as Content-manager list for api::article.article (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).
Agent ergonomics 13%16.2 10.6
A project with five collection types and Draft & Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST fields selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no readOnlyHint or destructiveHint in the MCP source. PUT by documentId is repeatable and media deletes have dryRun (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).
Security & auth 14%17.5 11.6
API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with origin: mcp but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).
Payments & pricing 10%12.5 6.2
Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (create-strapi, strapi admin:create-user) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.6
v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).
Transparency & trusteditorial 75, provenance 68 7%8.8 6.3
MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated "standard periods", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20).
Negative events≤15-6
Total65.7 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Strapi, or have the agent fetch /fixes/strapi.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Strapi

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/strapi, the October 2026 research run, assessed 7 October 2026. Grade B, 65.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Strapi: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 50 out of 100, up to 6.3 more on the total

Why it scored 50: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 66 out of 100, up to 6 more on the total

Why it scored 66: API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 65 out of 100, up to 5.7 more on the total

Why it scored 65: A project with five collection types and Draft & Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Reliability, 82 out of 100, up to 3.6 more on the total

Why it scored 82: Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 5. Schema & documentation, 80 out of 100, up to 3.3 more on the total

Why it scored 80: No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 72 out of 100, up to 2.5 more on the total

Made of editorial 75, provenance 68.

Why it scored 72: MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated "standard periods", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Endpoint on the vendor's domain:  is not on strapi.io (0 of 15)
- Terms of service: read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points (4 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 87 out of 100, up to 1.1 more on the total

Why it scored 87: v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text
- unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers
- unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)
- unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return
- The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan
- The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read
- We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0
- The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers

## Weaknesses

- Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans
- Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed
- A REST POST or PUT publishes immediately unless the request passes `status=draft`
- The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations
- Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once
- Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes
- Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload
- Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`
- Keep your own copy of an entry before updating it. API and MCP writes create no Content History version

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text
  • unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers
  • unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)
  • unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return
  • The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan
  • The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read
  • We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0
  • The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers

Sources 25

  1. MCP server docs docs.strapi.io · seen 2026-10-07
  2. Admin tokens docs.strapi.io · seen 2026-10-07
  3. API tokens docs.strapi.io · seen 2026-10-07
  4. REST API reference docs.strapi.io · seen 2026-10-07
  5. REST status parameter docs.strapi.io · seen 2026-10-07
  6. Upload API docs.strapi.io · seen 2026-10-07
  7. Content History docs.strapi.io · seen 2026-10-07
  8. Audit Logs docs.strapi.io · seen 2026-10-07
  9. OpenAPI generation docs.strapi.io · seen 2026-10-07
  10. error format docs.strapi.io · seen 2026-10-07
  11. telemetry docs.strapi.io · seen 2026-10-07
  12. docs index for agents docs.strapi.io · seen 2026-10-07
  13. repository, licence, SECURITY.md, tags and MCP source (clone) github.com · seen 2026-10-07
  14. security advisories github.com · seen 2026-10-07
  15. release notes github.com · seen 2026-10-07
  16. CI runs api.github.com · seen 2026-10-07
  17. npm package and version registry.npmjs.org · seen 2026-10-07
  18. Strapi Cloud pricing strapi.io · seen 2026-10-07
  19. self-hosted pricing strapi.io · seen 2026-10-07
  20. Cloud billing and overage rates docs.strapi.io · seen 2026-10-07
  21. Cloud terms, policies, service levels and DPA strapi.io · seen 2026-10-07
  22. privacy policy strapi.io · seen 2026-10-07
  23. security page strapi.io · seen 2026-10-07
  24. status page status.strapi.io · seen 2026-10-07
  25. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-07

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $45 / mo The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).

Prices

ItemPriceUnitNote
Community Edition, self-hostedfreeper month (plan)MIT, unlimited seats, you pay for your own hosting
Growth, self-hosted$45per month (plan)3 seats included, $15 per extra seat
Strapi Cloud Starter$35per month (plan)per project, 100,000 API requests
Strapi Cloud Pro$90per month (plan)per project, 1 million API requests
Strapi Cloud Business$450per month (plan)per project, 10 million API requests
Strapi Cloud API requests over the plan$0.06per 1,000 requests$1.50 per 25,000

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/strapi.xml, or this listing's score history at history.json.

Connect

Install

npx create-strapi@latest

First request

curl 'http://localhost:1337/api/restaurants?status=draft' \
  -H "Authorization: Bearer $STRAPI_API_TOKEN"

Claude Code

claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H "Authorization: Bearer YOUR_ADMIN_TOKEN"

MCP client configuration

{
  "mcpServers": {
    "strapi-mcp": {
      "headers": {
        "Authorization": "Bearer YOUR_ADMIN_TOKEN"
      },
      "type": "streamable-http",
      "url": "http://localhost:1337/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/strapi

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Sanity Sanity US Inc. and Sanity ASBB73.7cms.content cms.publish cms.assets cms.schema cms.localisationno
Storyblok Storyblok GmbHB67.7cms.content cms.publish cms.assets cms.localisation cms.schemano
Contentstack Contentstack Inc.B64cms.content cms.publish cms.assets cms.localisation cms.schemano

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Strapi on Anchor Terminal, B, 65.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/strapi"><img src="https://www.anchorterminal.com/badges/strapi.svg" alt="Strapi on Anchor Terminal" height="20"></a>
    [![Strapi on Anchor Terminal](https://www.anchorterminal.com/badges/strapi.svg)](https://www.anchorterminal.com/tools/strapi)

    It counts on a page on strapi.io or one of its subdomains, or the README of github.com/strapi/strapi.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "strapi", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.