# Strapi (slim) > Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server. - Full: https://www.anchorterminal.com/tools/strapi.md (~8,000 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/strapi.json · canonical https://www.anchorterminal.com/tools/strapi - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 65.7/100 · rank #231 of 629 · #4 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files. ## Facts - Kind: HTTP API · vendor: Strapi, Inc. · category: CMS & website publishing · legal entity: Strapi, Inc. · provenance 68/100 - Local only (HTTP, Streamable HTTP): npm `@strapi/strapi`, npm `@strapi/client` - Auth: API key · pricing: Freemium · x402: no · licence: MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms - Probe metrics: not measured yet (probes haven't run) - Graded surface: The self-hosted Community Edition, version 5.57.0, through its REST Content API and the built-in MCP server. Strapi Cloud hosts the same software and APIs at https://.strapiapp.com - REST Content API: Generated per content type under /api. GET, POST, PUT and DELETE on `/api/:pluralApiId` and `/api/:pluralApiId/:documentId`, with `fields`, `populate`, `filters`, `sort`, `pagination`, `locale` and `status` parameters. GraphQL is a plugin - MCP server: Built into core since 5.47.0 (28 May 2026 on npm), off by default, POST only at /mcp, stateless, MCP TypeScript SDK 2.0.0 with JSON Schema 2020-12 input and output schemas - MCP tools: Per collection type list, get, create, update, delete, publish, unpublish, discard_draft. Per single type get, write, delete, publish, unpublish, discard_draft. Media Library media_list_assets, media_get_asset, media_list_folders, media_update_asset, media_move_assets, media_delete_assets, media_create_folder, media_rename_folder, media_move_folder, media_delete_folder - Credentials: API tokens for /api (read-only, full access or custom per content type and action). Admin tokens for admin routes and /mcp (a subset of the owner's role, down to field and locale). Both expire after 7, 30 or 90 days or never, and can be regenerated. Sent as `Authorization: Bearer` - Draft and publish: Per content type. REST `status=draft` or `status=published` on reads and writes, with published as the default. MCP create writes a draft, with separate publish, unpublish and discard_draft tools - Localisation: `locale` query parameter on REST and an optional `locale` argument on MCP tools, limited to the locales the token may use - Assets: `POST /api/upload` (multipart), `GET /api/upload/files/page`, `DELETE /api/upload/files/:id`. Folders are managed in the admin panel or through MCP media tools. Strapi Cloud caps non-image files at 200 MB - Version history: Content History on Growth (14 days) and Enterprise (30 days), created only by admin panel edits - Audit: Audit Logs on the Enterprise plan, 90 days by default. MCP entry actions carry `origin: mcp`. Reads aren't recorded - Machine-readable docs: llms.txt, llms-full.txt and a .md copy of every docs page. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project's own Content API and is marked experimental - Rate limits: No rate limit on the Content API by default. Admin and Users & Permissions authentication routes allow 5 requests in 5 minutes. Strapi Cloud plans meter monthly API requests - Runtime: Node.js 20 to 26, with SQLite, MySQL, MariaDB or PostgreSQL - Client library: @strapi/client 1.6.2 for JavaScript and TypeScript (4 June 2026) - Strapi Cloud: Starter $35, Pro $90, Business $450 a project a month. Regions US (East), Europe (West) and Asia (Southeast). 99.9 per cent yearly uptime commitment on Business - Prices: Community Edition, self-hosted free per month (plan); Growth, self-hosted $45 per month (plan); Strapi Cloud Starter $35 per month (plan); Strapi Cloud Pro $90 per month (plan); Strapi Cloud Business $450 per month (plan); Strapi Cloud API requests over the plan $0.06 per 1,000 requests - Scores: Reliability 82, Performance pending, Schema & documentation 80, Agent ergonomics 65, Security & auth 66, Payments & pricing 50, Task success pending, Maintenance & community 87, Transparency & trust 72 · negative events -6 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. · Schema & documentation, No published OpenAPI file, because endpoints depend on each project's content types. · Agent ergonomics, A project with five collection types and Draft & Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-… · Security & auth, API tokens are read-only, full access or custom per content type and action. · Payments & pricing, Scored with the self-hosted rule, taking prices from the paid options beside the free edition. · Maintenance & community, v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). · Transparency & trust, MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). - Sources: 25, open questions: 8, both in the full twin - Capabilities: cms.content, cms.publish, cms.localisation, cms.assets, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/strapi.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/strapi.svg` or a link to https://www.anchorterminal.com/tools/strapi from a page on strapi.io or one of its subdomains, or the README of github.com/strapi/strapi, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once 2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes 3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload 4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets` 5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version ## Connect ```bash npx create-strapi@latest ``` ```bash curl 'http://localhost:1337/api/restaurants?status=draft' \ -H "Authorization: Bearer $STRAPI_API_TOKEN" ``` ```bash claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H "Authorization: Bearer YOUR_ADMIN_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/strapi ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Contentstack | B | 64 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/contentstack.min.md | | WordPress | B | 64.8 | cms.content, cms.publish, cms.assets | https://www.anchorterminal.com/tools/wordpress.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)