{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/sanity.json",
        "name": "Sanity",
        "score": 73.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "sanity"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/webflow.json",
        "name": "Webflow",
        "score": 69.4,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.schema",
          "cms.localisation"
        ],
        "slug": "webflow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/storyblok.json",
        "name": "Storyblok",
        "score": 67.7,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "storyblok"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/contentstack.json",
        "name": "Contentstack",
        "score": 64,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets",
          "cms.localisation",
          "cms.schema"
        ],
        "slug": "contentstack"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/wordpress.json",
        "name": "WordPress",
        "score": 64.8,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "wordpress"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ghost.json",
        "name": "Ghost",
        "score": 58.3,
        "shared": [
          "cms.content",
          "cms.publish",
          "cms.assets"
        ],
        "slug": "ghost"
      }
    ],
    "tool": {
      "slug": "strapi",
      "name": "Strapi",
      "vendor": "Strapi, Inc.",
      "vendorUrl": "https://strapi.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/strapi",
      "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
      "repo": "https://github.com/strapi/strapi",
      "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@strapi/strapi"
        },
        {
          "registry": "npm",
          "name": "@strapi/client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
      "priceSummary": "$45 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 73289,
        "npmWeekly": 258813,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.strapi.io",
      "llmsTxt": "https://docs.strapi.io/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "llms-txt",
        "webhooks",
        "graphql",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.7,
        "grade": "B",
        "agentReady": false,
        "rank": 231,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 82,
            "points": 16.4,
            "reason": "Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 80,
            "points": 13,
            "reason": "No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 65,
            "points": 10.56,
            "reason": "A project with five collection types and Draft \u0026 Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 66,
            "points": 11.55,
            "reason": "API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 50,
            "points": 6.25,
            "reason": "Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 87,
            "points": 7.61,
            "reason": "v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 75, provenance 68",
            "reason": "MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated \"standard periods\", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "A project with five collection types and Draft \u0026 Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).",
            "maintenance": "v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).",
            "payments": "Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).",
            "reliability": "Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).",
            "schema": "No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).",
            "security": "API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).",
            "transparency": "MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated \"standard periods\", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20)."
          },
          "sources": [
            {
              "what": "MCP server docs",
              "url": "https://docs.strapi.io/cms/features/strapi-mcp-server",
              "seen": "2026-10-07"
            },
            {
              "what": "Admin tokens",
              "url": "https://docs.strapi.io/cms/features/admin-tokens",
              "seen": "2026-10-07"
            },
            {
              "what": "API tokens",
              "url": "https://docs.strapi.io/cms/features/api-tokens",
              "seen": "2026-10-07"
            },
            {
              "what": "REST API reference",
              "url": "https://docs.strapi.io/cms/api/rest",
              "seen": "2026-10-07"
            },
            {
              "what": "REST status parameter",
              "url": "https://docs.strapi.io/cms/api/rest/status",
              "seen": "2026-10-07"
            },
            {
              "what": "Upload API",
              "url": "https://docs.strapi.io/cms/api/rest/upload",
              "seen": "2026-10-07"
            },
            {
              "what": "Content History",
              "url": "https://docs.strapi.io/cms/features/content-history",
              "seen": "2026-10-07"
            },
            {
              "what": "Audit Logs",
              "url": "https://docs.strapi.io/cms/features/audit-logs",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI generation",
              "url": "https://docs.strapi.io/cms/api/openapi",
              "seen": "2026-10-07"
            },
            {
              "what": "error format",
              "url": "https://docs.strapi.io/cms/error-handling",
              "seen": "2026-10-07"
            },
            {
              "what": "telemetry",
              "url": "https://docs.strapi.io/cms/usage-information",
              "seen": "2026-10-07"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.strapi.io/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "repository, licence, SECURITY.md, tags and MCP source (clone)",
              "url": "https://github.com/strapi/strapi",
              "seen": "2026-10-07"
            },
            {
              "what": "security advisories",
              "url": "https://github.com/strapi/strapi/security/advisories",
              "seen": "2026-10-07"
            },
            {
              "what": "release notes",
              "url": "https://github.com/strapi/strapi/releases",
              "seen": "2026-10-07"
            },
            {
              "what": "CI runs",
              "url": "https://api.github.com/repos/strapi/strapi/actions/runs?branch=main",
              "seen": "2026-10-07"
            },
            {
              "what": "npm package and version",
              "url": "https://registry.npmjs.org/@strapi/strapi/latest",
              "seen": "2026-10-07"
            },
            {
              "what": "Strapi Cloud pricing",
              "url": "https://strapi.io/pricing-cloud",
              "seen": "2026-10-07"
            },
            {
              "what": "self-hosted pricing",
              "url": "https://strapi.io/pricing-self-hosted",
              "seen": "2026-10-07"
            },
            {
              "what": "Cloud billing and overage rates",
              "url": "https://docs.strapi.io/cloud/getting-started/usage-billing",
              "seen": "2026-10-07"
            },
            {
              "what": "Cloud terms, policies, service levels and DPA",
              "url": "https://strapi.io/cloud-legal",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://strapi.io/privacy",
              "seen": "2026-10-07"
            },
            {
              "what": "security page",
              "url": "https://strapi.io/security",
              "seen": "2026-10-07"
            },
            {
              "what": "status page",
              "url": "https://status.strapi.io/",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=strapi",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text",
            "unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers",
            "unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)",
            "unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return",
            "The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan",
            "The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read",
            "We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0",
            "The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers"
          ]
        },
        "negative": -6,
        "negativeNotes": [
          "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
        ],
        "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
        "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "strengths": [
          "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
          "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
          "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
          "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
          "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
          "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
          "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
          "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
          "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
        ],
        "agentNotes": [
          "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
          "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
          "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
          "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
          "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 75
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx create-strapi@latest",
        "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
        "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
        "config": {
          "mcpServers": {
            "strapi-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_ADMIN_TOKEN"
              },
              "type": "streamable-http",
              "url": "http://localhost:1337/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/strapi"
      },
      "notable": [
        "The built-in MCP server answers at /mcp over Streamable HTTP once `mcp.enabled` is set in config/server, takes an Admin token as a Bearer header, and is a free feature (https://docs.strapi.io/cms/features/strapi-mcp-server)",
        "Each collection type generates up to 8 MCP tools (list, get, create, update, delete, publish, unpublish, discard_draft), each single type up to 6, and the Media Library adds 10 (https://docs.strapi.io/cms/features/strapi-mcp-server)",
        "Content History versions are created only for edits made in the admin panel, not for REST, GraphQL, Document Service or import writes, and are kept 14 days on Growth and 30 days on Enterprise (https://docs.strapi.io/cms/features/content-history)",
        "The REST API defaults to published for POST and PUT, while MCP create tools write a draft when Draft \u0026 Publish is on (https://docs.strapi.io/cms/api/rest/status)",
        "Advisories GHSA-rjg2-95x7-8qmx and GHSA-3xcq-8mjw-h6mx, both rated critical, were published on 13 May 2026 for versions up to 5.36.1 and 5.33.1 (https://github.com/strapi/strapi/security/advisories)",
        "Strapi Cloud costs $35, $90 or $450 a project a month with 100,000, 1 million or 10 million API requests included and $1.50 per further 25,000 (https://strapi.io/pricing-cloud)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Graded surface",
          "value": "The self-hosted Community Edition, version 5.57.0, through its REST Content API and the built-in MCP server. Strapi Cloud hosts the same software and APIs at https://\u003cproject\u003e.strapiapp.com"
        },
        {
          "label": "REST Content API",
          "value": "Generated per content type under /api. GET, POST, PUT and DELETE on `/api/:pluralApiId` and `/api/:pluralApiId/:documentId`, with `fields`, `populate`, `filters`, `sort`, `pagination`, `locale` and `status` parameters. GraphQL is a plugin"
        },
        {
          "label": "MCP server",
          "value": "Built into core since 5.47.0 (28 May 2026 on npm), off by default, POST only at /mcp, stateless, MCP TypeScript SDK 2.0.0 with JSON Schema 2020-12 input and output schemas"
        },
        {
          "label": "MCP tools",
          "value": "Per collection type list, get, create, update, delete, publish, unpublish, discard_draft. Per single type get, write, delete, publish, unpublish, discard_draft. Media Library media_list_assets, media_get_asset, media_list_folders, media_update_asset, media_move_assets, media_delete_assets, media_create_folder, media_rename_folder, media_move_folder, media_delete_folder"
        },
        {
          "label": "Credentials",
          "value": "API tokens for /api (read-only, full access or custom per content type and action). Admin tokens for admin routes and /mcp (a subset of the owner's role, down to field and locale). Both expire after 7, 30 or 90 days or never, and can be regenerated. Sent as `Authorization: Bearer`"
        },
        {
          "label": "Draft and publish",
          "value": "Per content type. REST `status=draft` or `status=published` on reads and writes, with published as the default. MCP create writes a draft, with separate publish, unpublish and discard_draft tools"
        },
        {
          "label": "Localisation",
          "value": "`locale` query parameter on REST and an optional `locale` argument on MCP tools, limited to the locales the token may use"
        },
        {
          "label": "Assets",
          "value": "`POST /api/upload` (multipart), `GET /api/upload/files/page`, `DELETE /api/upload/files/:id`. Folders are managed in the admin panel or through MCP media tools. Strapi Cloud caps non-image files at 200 MB"
        },
        {
          "label": "Version history",
          "value": "Content History on Growth (14 days) and Enterprise (30 days), created only by admin panel edits"
        },
        {
          "label": "Audit",
          "value": "Audit Logs on the Enterprise plan, 90 days by default. MCP entry actions carry `origin: mcp`. Reads aren't recorded"
        },
        {
          "label": "Machine-readable docs",
          "value": "llms.txt, llms-full.txt and a .md copy of every docs page. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project's own Content API and is marked experimental"
        },
        {
          "label": "Rate limits",
          "value": "No rate limit on the Content API by default. Admin and Users \u0026 Permissions authentication routes allow 5 requests in 5 minutes. Strapi Cloud plans meter monthly API requests"
        },
        {
          "label": "Runtime",
          "value": "Node.js 20 to 26, with SQLite, MySQL, MariaDB or PostgreSQL"
        },
        {
          "label": "Client library",
          "value": "@strapi/client 1.6.2 for JavaScript and TypeScript (4 June 2026)"
        },
        {
          "label": "Strapi Cloud",
          "value": "Starter $35, Pro $90, Business $450 a project a month. Regions US (East), Europe (West) and Asia (Southeast). 99.9 per cent yearly uptime commitment on Business"
        }
      ],
      "unitPrices": [
        {
          "item": "Community Edition, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT, unlimited seats, you pay for your own hosting"
        },
        {
          "item": "Growth, self-hosted",
          "unit": "month",
          "usd": 45,
          "note": "3 seats included, $15 per extra seat"
        },
        {
          "item": "Strapi Cloud Starter",
          "unit": "month",
          "usd": 35,
          "note": "per project, 100,000 API requests"
        },
        {
          "item": "Strapi Cloud Pro",
          "unit": "month",
          "usd": 90,
          "note": "per project, 1 million API requests"
        },
        {
          "item": "Strapi Cloud Business",
          "unit": "month",
          "usd": 450,
          "note": "per project, 10 million API requests"
        },
        {
          "item": "Strapi Cloud API requests over the plan",
          "unit": "1k-requests",
          "usd": 0.06,
          "note": "$1.50 per 25,000"
        }
      ],
      "provenance": {
        "legalEntity": "Strapi, Inc.",
        "domain": "strapi.io",
        "domainRegistered": "2015-09-21",
        "endpointOnVendorDomain": false,
        "terms": "https://strapi.io/cloud-legal",
        "privacy": "https://strapi.io/privacy",
        "statusPage": "https://status.strapi.io",
        "changelog": "https://github.com/strapi/strapi/releases",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
          "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
          "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
          "RDAP for strapi.io gives a registration date of 2015-09-21.",
          "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
        ],
        "score": 68,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Strapi, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "strapi.io, registered 2015-09-21 (11 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on strapi.io",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 4,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.strapi.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://strapi.io/cloud-legal",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-07",
            "words": 16252,
            "points": 4,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of 7 October 2026",
                "says": "Last updated 2026-10-07"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Agreement shall be governed by and construed in accordance with the California, USA and the courts of San Francisco, County in California shall have exclusive jurisdiction, excluding specifically any conflicts of laws provisions, the United Nations Convention on Contracts for the International Sale of Goods and th…",
                "says": "Disputes go to the courts of San Francisco"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "and (d) THE TOTAL LIABILITY OF STRAPI WITH RESPECT TO ANY TRIAL FOR ANY CAUSE OF ACTION RELATING TO THE TRIAL OR ARISING FROM THE TRIAL SHALL BE LIMITED TO $100, PROVIDED THAT STRAPI ASSUMES NO LIABILITY FOR ANY DAMAGE OR LOSS CAUSED BY LOSS OF DATA OR INFORMATION (EVEN PARTIAL).",
                "says": "Capped at $100,"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "This Agreement may be terminated by either Party: (i) if the other Party materially breaches this Agreement or the Order and fails to cure it within thirty (30) days of receipt of written notice of the breach;"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Strapi may make changes to its Support Policy with thirty (30) days’ notice to Customer (via the support portal or otherwise), provided such change is in connection with a standard change made to its then-current standard support and maintenance terms and there is no material degradation of the support offering.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not agree to be bound by the Terms, you must not use the service."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Example: Assuming annual Subscription Fees of $120,000 for the Services, the Credits for an uptime of \u003c95% would be calculated as follows: 30% * ($120,000 / 12) = $3,000",
                "says": "Names 95% availability"
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "introducing automated agents, scripts, or software to create multiple accounts, mine data, or bypass usage limits",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Competitors of Strapi are strictly prohibited from accessing or using the Solution for any purpose.",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We may change its terms or discontinue it at any time without notice.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "the right to immediately, without prior notice, suspend the Customer account and/or removing or disabling access by Users to the Solution (and Customer Content maintained thereon) or take such other remedial action Strapi deems reasonable, if Customer engages in any prohibited uses of the Solution."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "shall be submitted to and determined by arbitration in the county of San Francisco, California, U.S.A. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Strapi may use the customer's name and logo when it lists or mentions customers in its marketing and communications.",
                "quote": "Customer agrees that Strapi may use Customer’s name and logo, for such purpose."
              },
              {
                "date": "2026-10-08",
                "text": "All project data is erased and cannot be recovered when a project is destroyed or the subscription is cancelled or terminated.",
                "quote": "When a project is destroyed or upon cancellation or termination of your Subscription, all project data will be erased and will not be recoverable."
              },
              {
                "date": "2026-10-08",
                "text": "The subscription renews automatically for an equal term and the same subscription parameters unless the customer cancels before the term ends.",
                "quote": "Unless Customer cancels the subscription prior to the end of the Subscription Term Customer’s subscription will automatically renew for an equal term to the prior Subscription Term for the exact same Subscription Parameters."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://strapi.io/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2023-03-01",
            "words": 2930,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last update: March 01, 2023",
                "says": "Last updated 2023-03-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "If you are our customer, please also check the contracts between us: they may contain further details on how we collect and process your data."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "If you send us a spontaneous application, we will store your data until your withdrawal."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Legitimate interests: Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You can exercise your rights by sending us an email at privacy@strapi.io."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You can do this by emailing us at privacy@strapi.io.",
                "says": "privacy@strapi.io"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last update: March 01, 2023"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Strapi says it improves the service through data analysis and research that includes profiling and machine learning over the user's data, in some cases through third parties.",
                "quote": "traffic optimization and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
      "live": {
        "slug": "strapi",
        "vendorStatus": {
          "page": "https://status.strapi.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:37:17.41184558Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "strapi/strapi",
            "version": "v5.57.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:30:39.413193839Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/client",
            "version": "1.6.2",
            "seenAt": "2026-10-08T16:30:37.897146773Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/strapi",
            "version": "5.57.0",
            "seenAt": "2026-10-08T16:30:37.072939352Z"
          }
        ],
        "githubStars": 73292,
        "npmWeekly": 258813,
        "securityTxt": {
          "url": "https://strapi.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:07.890617672Z"
        },
        "updatedAt": "2026-10-08T16:30:39.413193839Z"
      }
    },
    "verify": {
      "accepts": "a page on strapi.io or one of its subdomains, or the README of github.com/strapi/strapi",
      "badgeUrl": "https://www.anchorterminal.com/badges/strapi.svg",
      "body": {
        "slug": "strapi",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/strapi",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/strapi\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/strapi.svg\" alt=\"Strapi on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Strapi on Anchor Terminal](https://www.anchorterminal.com/badges/strapi.svg)](https://www.anchorterminal.com/tools/strapi)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/strapi\"\u003eStrapi on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/strapi",
    "json": "https://www.anchorterminal.com/tools/strapi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/strapi.md",
    "slim": "https://www.anchorterminal.com/tools/strapi.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 65.7/100 · rank #231 of 629 · #4 in CMS \u0026 website publishing · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Strapi, Inc. (https://strapi.io) |\n| Kind | HTTP API |\n| Category | CMS \u0026 website publishing (https://www.anchorterminal.com/categories/cms) |\n| Transport | HTTP, Streamable HTTP |\n| Auth | API key · Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once. |\n| Pricing | Freemium ($45 / mo) · The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07). |\n| Licence | MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms |\n| Packages | npm: `@strapi/strapi`; npm: `@strapi/client` |\n| Source | https://github.com/strapi/strapi |\n| Docs | https://docs.strapi.io |\n| llms.txt | https://docs.strapi.io/llms.txt |\n| Last release | 2026-10-07 |\n| GitHub stars | 73,289 (as of 2026-10-07) |\n| npm downloads / week | 258,813 |\n| Graded surface | The self-hosted Community Edition, version 5.57.0, through its REST Content API and the built-in MCP server. Strapi Cloud hosts the same software and APIs at https://\u003cproject\u003e.strapiapp.com |\n| REST Content API | Generated per content type under /api. GET, POST, PUT and DELETE on `/api/:pluralApiId` and `/api/:pluralApiId/:documentId`, with `fields`, `populate`, `filters`, `sort`, `pagination`, `locale` and `status` parameters. GraphQL is a plugin |\n| MCP server | Built into core since 5.47.0 (28 May 2026 on npm), off by default, POST only at /mcp, stateless, MCP TypeScript SDK 2.0.0 with JSON Schema 2020-12 input and output schemas |\n| MCP tools | Per collection type list, get, create, update, delete, publish, unpublish, discard_draft. Per single type get, write, delete, publish, unpublish, discard_draft. Media Library media_list_assets, media_get_asset, media_list_folders, media_update_asset, media_move_assets, media_delete_assets, media_create_folder, media_rename_folder, media_move_folder, media_delete_folder |\n| Credentials | API tokens for /api (read-only, full access or custom per content type and action). Admin tokens for admin routes and /mcp (a subset of the owner's role, down to field and locale). Both expire after 7, 30 or 90 days or never, and can be regenerated. Sent as `Authorization: Bearer` |\n| Draft and publish | Per content type. REST `status=draft` or `status=published` on reads and writes, with published as the default. MCP create writes a draft, with separate publish, unpublish and discard_draft tools |\n| Localisation | `locale` query parameter on REST and an optional `locale` argument on MCP tools, limited to the locales the token may use |\n| Assets | `POST /api/upload` (multipart), `GET /api/upload/files/page`, `DELETE /api/upload/files/:id`. Folders are managed in the admin panel or through MCP media tools. Strapi Cloud caps non-image files at 200 MB |\n| Version history | Content History on Growth (14 days) and Enterprise (30 days), created only by admin panel edits |\n| Audit | Audit Logs on the Enterprise plan, 90 days by default. MCP entry actions carry `origin: mcp`. Reads aren't recorded |\n| Machine-readable docs | llms.txt, llms-full.txt and a .md copy of every docs page. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project's own Content API and is marked experimental |\n| Rate limits | No rate limit on the Content API by default. Admin and Users \u0026 Permissions authentication routes allow 5 requests in 5 minutes. Strapi Cloud plans meter monthly API requests |\n| Runtime | Node.js 20 to 26, with SQLite, MySQL, MariaDB or PostgreSQL |\n| Client library | @strapi/client 1.6.2 for JavaScript and TypeScript (4 June 2026) |\n| Strapi Cloud | Starter $35, Pro $90, Business $450 a project a month. Regions US (East), Europe (West) and Asia (Southeast). 99.9 per cent yearly uptime commitment on Business |\n| Capabilities | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema |\n| Tags | open-source, self-hosted, hosted, mcp, llms-txt, webhooks, graphql, typescript, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/strapi.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 82 | 16.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 80 | 13.0 |\n| Agent ergonomics | 13% | 16.2 | 65 | 10.6 |\n| Security \u0026 auth | 14% | 17.5 | 66 | 11.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 50 | 6.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 87 | 7.6 |\n| Transparency \u0026 trust (editorial 75, provenance 68) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | 13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx  | -6 |\n| **Total** | | | | **65.7 → B** |\n\n### Why each score\n\n- Reliability 82: Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 80: No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).\n- Agent ergonomics 65: A project with five collection types and Draft \u0026 Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).\n- Security \u0026 auth 66: API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).\n- Payments \u0026 pricing 50: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 87: v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).\n- Transparency \u0026 trust 72: MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated \"standard periods\", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/strapi.md (JSON https://www.anchorterminal.com/fixes/strapi.json)\n\n### What we couldn't check\n\n- unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text\n- unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers\n- unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)\n- unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return\n- The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan\n- The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read\n- We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0\n- The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers\n\n### Sources\n\n- MCP server docs: \u003chttps://docs.strapi.io/cms/features/strapi-mcp-server\u003e (seen 2026-10-07)\n- Admin tokens: \u003chttps://docs.strapi.io/cms/features/admin-tokens\u003e (seen 2026-10-07)\n- API tokens: \u003chttps://docs.strapi.io/cms/features/api-tokens\u003e (seen 2026-10-07)\n- REST API reference: \u003chttps://docs.strapi.io/cms/api/rest\u003e (seen 2026-10-07)\n- REST status parameter: \u003chttps://docs.strapi.io/cms/api/rest/status\u003e (seen 2026-10-07)\n- Upload API: \u003chttps://docs.strapi.io/cms/api/rest/upload\u003e (seen 2026-10-07)\n- Content History: \u003chttps://docs.strapi.io/cms/features/content-history\u003e (seen 2026-10-07)\n- Audit Logs: \u003chttps://docs.strapi.io/cms/features/audit-logs\u003e (seen 2026-10-07)\n- OpenAPI generation: \u003chttps://docs.strapi.io/cms/api/openapi\u003e (seen 2026-10-07)\n- error format: \u003chttps://docs.strapi.io/cms/error-handling\u003e (seen 2026-10-07)\n- telemetry: \u003chttps://docs.strapi.io/cms/usage-information\u003e (seen 2026-10-07)\n- docs index for agents: \u003chttps://docs.strapi.io/llms.txt\u003e (seen 2026-10-07)\n- repository, licence, SECURITY.md, tags and MCP source (clone): \u003chttps://github.com/strapi/strapi\u003e (seen 2026-10-07)\n- security advisories: \u003chttps://github.com/strapi/strapi/security/advisories\u003e (seen 2026-10-07)\n- release notes: \u003chttps://github.com/strapi/strapi/releases\u003e (seen 2026-10-07)\n- CI runs: \u003chttps://api.github.com/repos/strapi/strapi/actions/runs?branch=main\u003e (seen 2026-10-07)\n- npm package and version: \u003chttps://registry.npmjs.org/@strapi/strapi/latest\u003e (seen 2026-10-07)\n- Strapi Cloud pricing: \u003chttps://strapi.io/pricing-cloud\u003e (seen 2026-10-07)\n- self-hosted pricing: \u003chttps://strapi.io/pricing-self-hosted\u003e (seen 2026-10-07)\n- Cloud billing and overage rates: \u003chttps://docs.strapi.io/cloud/getting-started/usage-billing\u003e (seen 2026-10-07)\n- Cloud terms, policies, service levels and DPA: \u003chttps://strapi.io/cloud-legal\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://strapi.io/privacy\u003e (seen 2026-10-07)\n- security page: \u003chttps://strapi.io/security\u003e (seen 2026-10-07)\n- status page: \u003chttps://status.strapi.io/\u003e (seen 2026-10-07)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=strapi\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 68/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Strapi, Inc. | 20/20 |\n| Domain age | strapi.io, registered 2015-09-21 (11 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on strapi.io | 0/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points | 4/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.strapi.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.\n\nA self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.\n\nhttps://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.\n\nRDAP for strapi.io gives a registration date of 2015-09-21.\n\nThe status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://strapi.io/cloud-legal), read 2026-10-08, dated 2026-10-07, states 7 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"introducing automated agents, scripts, or software to create multiple accounts, mine data, or bypass usage limits\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Competitors of Strapi are strictly prohibited from accessing or using the Solution for any purpose.\"\n- To know. Says the terms or the service can change without notice (costs points). \"We may change its terms or discontinue it at any time without notice.\"\n- To know. Says access can be ended without notice or for any reason. \"the right to immediately, without prior notice, suspend the Customer account and/or removing or disabling access by Users to the Solution (and Customer Content maintained thereon) or take such other remedial action Strapi deems reasonable, if Customer engages in any prohibited uses of the Solution.\"\n- To know. Requires arbitration or waives class actions. \"shall be submitted to and determined by arbitration in the county of San Francisco, California, U.S.A. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures.\"\n- Gives the date it was last updated. Last updated 2026-10-07.\n- Names the governing law or courts. Disputes go to the courts of San Francisco.\n- States a limit on its liability. Capped at $100,.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Refers to a service level or uptime commitment. Names 95% availability.\n- Also in the text (2026-10-08). Strapi may use the customer's name and logo when it lists or mentions customers in its marketing and communications. \"Customer agrees that Strapi may use Customer’s name and logo, for such purpose.\"\n- Also in the text (2026-10-08). All project data is erased and cannot be recovered when a project is destroyed or the subscription is cancelled or terminated. \"When a project is destroyed or upon cancellation or termination of your Subscription, all project data will be erased and will not be recoverable.\"\n- Also in the text (2026-10-08). The subscription renews automatically for an equal term and the same subscription parameters unless the customer cancels before the term ends. \"Unless Customer cancels the subscription prior to the end of the Subscription Term Customer’s subscription will automatically renew for an equal term to the prior Subscription Term for the exact same Subscription Parameters.\"\n\n**Privacy policy** (https://strapi.io/privacy), read 2026-10-08, dated 2023-03-01, states 6 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Last update: March 01, 2023\"\n- Gives the date it was last updated. Last updated 2023-03-01.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. privacy@strapi.io.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Strapi says it improves the service through data analysis and research that includes profiling and machine learning over the user's data, in some cases through third parties. \"traffic optimization and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this.\"\n\n## Live (updated 2026-10-08 16:30 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- github `strapi/strapi` v5.57.0, released 2026-10-07\n- npm `@strapi/client` 1.6.2\n- npm `@strapi/strapi` 5.57.0\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/strapi.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Community Edition, self-hosted | free | per month (plan) | MIT, unlimited seats, you pay for your own hosting |\n| Growth, self-hosted | $45 | per month (plan) | 3 seats included, $15 per extra seat |\n| Strapi Cloud Starter | $35 | per month (plan) | per project, 100,000 API requests |\n| Strapi Cloud Pro | $90 | per month (plan) | per project, 1 million API requests |\n| Strapi Cloud Business | $450 | per month (plan) | per project, 10 million API requests |\n| Strapi Cloud API requests over the plan | $0.06 | per 1,000 requests | $1.50 per 25,000 |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry\n- The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields\n- Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted\n- Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version\n- MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page\n\n## Weaknesses\n\n- Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n- Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed\n- A REST POST or PUT publishes immediately unless the request passes `status=draft`\n- The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations\n- Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier\n\n## Before you call it (notes for agents)\n\n1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## Connect\n\nInstall:\n\n```bash\nnpx create-strapi@latest\n```\n\nFirst request:\n\n```bash\ncurl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"strapi-mcp\": {\n      \"headers\": {\n        \"Authorization\": \"Bearer YOUR_ADMIN_TOKEN\"\n      },\n      \"type\": \"streamable-http\",\n      \"url\": \"http://localhost:1337/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/strapi. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Sanity | BB | 73.7 | 69 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/sanity.md |\n| Webflow | B | 69.4 | 150 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/webflow.md |\n| Storyblok | B | 67.7 | 188 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/storyblok.md |\n| Contentstack | B | 64 | 264 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/contentstack.md |\n| WordPress | B | 64.8 | 249 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/wordpress.md |\n| Ghost | C | 58.3 | 404 | cms.content, cms.publish, cms.assets | no | https://www.anchorterminal.com/tools/ghost.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The built-in MCP server answers at /mcp over Streamable HTTP once `mcp.enabled` is set in config/server, takes an Admin token as a Bearer header, and is a free feature (source: \u003chttps://docs.strapi.io/cms/features/strapi-mcp-server\u003e)\n- Each collection type generates up to 8 MCP tools (list, get, create, update, delete, publish, unpublish, discard_draft), each single type up to 6, and the Media Library adds 10 (source: \u003chttps://docs.strapi.io/cms/features/strapi-mcp-server\u003e)\n- Content History versions are created only for edits made in the admin panel, not for REST, GraphQL, Document Service or import writes, and are kept 14 days on Growth and 30 days on Enterprise (source: \u003chttps://docs.strapi.io/cms/features/content-history\u003e)\n- The REST API defaults to published for POST and PUT, while MCP create tools write a draft when Draft \u0026 Publish is on (source: \u003chttps://docs.strapi.io/cms/api/rest/status\u003e)\n- Advisories GHSA-rjg2-95x7-8qmx and GHSA-3xcq-8mjw-h6mx, both rated critical, were published on 13 May 2026 for versions up to 5.36.1 and 5.33.1 (source: \u003chttps://github.com/strapi/strapi/security/advisories\u003e)\n- Strapi Cloud costs $35, $90 or $450 a project a month with 100,000, 1 million or 10 million API requests included and $1.50 per further 25,000 (source: \u003chttps://strapi.io/pricing-cloud\u003e)\n\n## Compare\n\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md): B 64 vs B 65.7\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md): C 58.3 vs B 65.7\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md): BB 73.7 vs B 65.7\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md): B 67.7 vs B 65.7\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md): B 65.7 vs B 69.4\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md): B 65.7 vs B 64.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on strapi.io or one of its subdomains, or the README of github.com/strapi/strapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"strapi\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/strapi\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/strapi.svg\" alt=\"Strapi on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Strapi on Anchor Terminal](https://www.anchorterminal.com/badges/strapi.svg)](https://www.anchorterminal.com/tools/strapi)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/strapi\"\u003eStrapi on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Strapi is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/strapi-dark.png\n- Light: https://www.anchorterminal.com/assets/share/strapi-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CMS \u0026 website publishing",
        "url": "https://www.anchorterminal.com/categories/cms"
      },
      {
        "name": "Strapi",
        "url": ""
      }
    ],
    "description": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
    "facts": [
      "rank #231 of 629",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Strapi",
    "image": "https://www.anchorterminal.com/assets/og/tools-strapi.png",
    "path": "/tools/strapi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Strapi review for AI agents, grade B (65.7/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/strapi"
  },
  "tokens": {
    "markdown": 8000,
    "slim": 2080
  },
  "version": 1
}
