Webflow
by Webflow, Inc. HTTP API in CMS & website publishing
Hosted
Webflow, Inc. · webflow.com since 2003 · status page · who's behind it
Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.
Good for Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.
Is this your product? Claim this listing or verify it
Assessment. The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.webflow.com/v2- Auth
- OAuth or key
- Pricing
- Freemium · $15 / mo
- x402
- No
- Licence
- Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT
- Tools exposed
- 34
- Packages
npmwebflow-apipypiwebflownpmwebflow-mcp-server- MCP registry
com.webflow/mcp- llms.txt
- published
- Last release
- npm / week
- 85k
- PyPI / week
- 121k
- Surfaces
- Data API v2 (REST, JSON) at https://api.webflow.com/v2, a /beta namespace for new endpoints, and the official hosted MCP server over the same API. A read-only content delivery API serves cached CMS data
- MCP server
- Hosted at https://mcp.webflow.com/mcp (streamable HTTP), beta at https://mcp.webflow.com/beta/mcp. Version 2.1 since 21 September 2026. 27 data tools, 3 Designer session tools and 4 utility tools. OAuth only, one workspace per authorisation
- CMS actions
- Collections, static, option and reference fields, field groups, items created and updated as drafts, publish and unpublish (unpublish up to 100 a call), delete, and site publish
- Credentials
- OAuth apps and site tokens with read and write scope pairs (assets, cms, pages, sites, forms, components, comments, custom_code, ecommerce and others). At most 5 site tokens a site, expiring after 365 days unused. Custom code endpoints need an OAuth app
- Rate limits
- 60 requests a minute on Starter and Basic, 120 on higher site plans, custom on Enterprise, counted per token. Site publish once a minute. Asset compression 10 calls a minute per site
- Errors
- JSON body with
code,message,externalReferenceanddetails. 429 with Retry-After, and X-RateLimit-Limit and X-RateLimit-Remaining on every response - Pagination
limit(maximum 100) andoffset. Collection items filter withfilter[<fieldSlug>][<operator>](up to 10 terms) and sort on up to 3 custom fields- Drafts and versions
isDraftandlastPublishedgive the item state. A live item can hold staged changes. Scheduled publishing can't be set through the CMS API. No version history or rollback endpoint was found in the reviewed pages- Assets
- Two-step upload (create the asset with a file hash, then POST the bytes to a presigned URL). Folders can't be deleted through the API. Asset delete is a soft delete that the API can't restore
- Localisation
- Items and pages carry a locale id (
cmsLocaleId). The MCP server reads and updates content in secondary locales and can't create new localised CMS items. Localisation is a priced add-on - Free tier
- Starter site plan. 50 CMS items, 20 collections, 2 static pages, 1 GB bandwidth, CMS APIs at 60 requests a minute, MCP server included
- SDKs
- webflow-api 3.3.4 for JavaScript (16 March 2026) and webflow 2.0.0 for Python (12 March 2026), both MIT. The SDKs don't call beta endpoints
- Audit
- Agent changes are recorded in the site activity log. The pricing page lists the activity log and its API on Team and Enterprise, and an Audit Logs API on Enterprise
- Certifications
- SOC 1 Type 2, SOC 2 Type 2, ISO 27001, 27017, 27018 and 42001, PCI DSS per the trust centre. Bugcrowd disclosure programme named in security.txt
- Sub-processors
- List updated 9 July 2026 with countries, nearly all in the USA. AWS for hosting, Cloudflare for delivery, MongoDB for the database, Anthropic and OpenAI for AI services
- Open source
- No. The OpenAPI spec, both SDKs and an older local MCP server (webflow/mcp-server, last commit 10 April 2026) are MIT
- Capabilities
- cms.content cms.publish cms.assets cms.schema cms.localisation
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page
- OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens
- CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call
- 429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically
- Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page
Weaknesses
- The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions
- No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute
- The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales
- The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise
- On 7 October 2026 Get Site Plan changed its
idanddisplayNamevalues in place, marked as breaking in the changelog entry of the same day
Before you call it notes for agents
- Send the token as
Authorization: Bearerto https://api.webflow.com/v2. Ask forcms:readandcms:writeonly, plussites:writeif the task publishes - Create or update items first, then call Publish Items or Publish Site. An item with
isDrafttrue and alastPublisheddate is live with unpublished changes - Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429
- Page item lists with
limit(maximum 100) andoffset, and filter withfilter[<fieldSlug>][<operator>], up to 10 terms - Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's
cmsLocaleId
Who's behind it provenance 97/100
- Legal entity namedWebflow, Inc.20/20
- Domain agewebflow.com, registered 2003-03-31 (23 years)15/15
- Endpoint on the vendor's domainapi.webflow.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.webflow.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2023-11-15, states 6 of 7, 3 to know
TL;DR Dated 2023-11-15. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Says the terms or the service can change without noticecosts points
Therefore, we may, without prior notice, change the Platform, add features, stop providing the Platform or features of the Platform to you or to customers generally, or create usage limits for the Platform.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Webflow may terminate this license at any time for any reason or no reason.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
If you and Webflow are unable to resolve a Dispute through informal negotiations, all claims arising from use of the Platform (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration, unless otherwise prohibited by applicable law.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2023-11-15
Last modified date: November 15, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
The Agreement will be governed by and construed in accordance with the internal laws of the State of California, without regard to its conflicts of law provisions.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $100
IN NO EVENT SHALL WEBFLOW, ITS AFFILIATES, AGENTS, DIRECTORS, EMPLOYEES, SUPPLIERS, OR LICENSORS BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS RELATED TO THIS AGREEMENT IN AN AMOUNT EXCEEDING $100.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
and ( 2 ) the “Subscription Term” of the Agreement shall be as of the Effective Date until you terminate your Account and/or the expiration or termination of the last outstanding Order Form, as applicable.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
We may need to send you notices about important updates (like changes to these Terms or our Privacy Policy), or to inform you of legal inquiries we receive about your use of the Platform so you can make informed choices in response.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
IF YOU DO NOT AGREE TO THE TERMS AND CONDITIONS OF THE AGREEMENT, YOU MAY NOT USE THE PLATFORM OR ANY RELATED WEBFLOW OFFERINGS.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Webflow's liability for any claim related to the agreement is capped at 100 US dollars.
IN NO EVENT SHALL WEBFLOW, ITS AFFILIATES, AGENTS, DIRECTORS, EMPLOYEES, SUPPLIERS, OR LICENSORS BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS RELATED TO THIS AGREEMENT IN AN AMOUNT EXCEEDING $100.
Noted by a second reader on 2026-10-08.
The licence the customer grants over website content covers improving, testing and promoting the platform as well as running it, and is transferable and sub-licensable.
create derivative works (e.g., those resulting from you enabling localization translations and adaptations) of your Website Content for the purposes of providing, improving, testing, promoting, and securing the Platform.
Noted by a second reader on 2026-10-08.
Annual plans are billed up front, are non-refundable and renew automatically for a further year unless cancelled before the term ends.
Your annual plan will automatically renew for successive one (1) year subscription periods, and you will be charged the applicable Fees on each annual anniversary of your purchase, unless you cancel the plan(s) on your Account prior to the end of the then-current annual term.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 11,369 words
Privacy policy dated 2025-03-17, states 8 of 8, 1 to know
TL;DR Dated 2025-03-17. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
As described in this Privacy Policy, in certain situations we may share your Personal Information with certain third parties for our marketing or other purposes.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2025-03-17
Effective date: March 17, 2025
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Global Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect visitors’ and users’ information as part of the Platform.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
Webflow will retain Personal Information we process on your behalf for as long as necessary to provide the Platform to you, subject to our compliance with this Policy, or as required or permitted under applicable law.
Says when data sent to the service is deleted.
Says who else receives the data
In addition to collecting and using De-identified Data ourselves, we may share De-identified Data with third parties, including our customers, partners and service providers, for various purposes, including to help us better understand our customers’ needs and improve the Platform as well as for advertising and market…
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
If you would like us to no longer share your Personal Information in this way, you can opt-out by visiting the following web page: Do Not Sell My Info.
A plain statement either way.
Says what rights people have over their data
We will not discriminate against you for exercising your right to know, delete or opt-out of sales.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@webflow.com
If you ever receive such an email, please forward it to privacy@webflow.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
The countries data goes to and the safeguard used.
Webflow may store credentials for third-party applications the customer connects, in encrypted form, and use them to access those accounts on the customer's behalf.
To facilitate the exchange of data between third-party SaaS applications, we may need to store certain information (“App Credentials”) that helps us access these third-party SaaS application accounts on your behalf.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,648 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.
The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.
The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.
The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.
webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.
RDAP for webflow.com gives a registration date of 2003-03-31.
status.webflow.com runs on Statuspage with components for the Data API and the MCP server.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 19:09 UTC
Probed every five minutes at https://api.webflow.com/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 4 minutes ago
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| developers.webflow.com/home/changelog | changelog | 53 minutes ago · 200 | no change seen |
| webflow.com/pricing | pricing | 45 minutes ago · 200 | no change seen |
| webflow.com/legal/privacy | privacy | 45 minutes ago · 200 | no change seen |
| webflow.com/legal/terms | terms | 45 minutes ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/webflow.json
Notable
- The MCP server is hosted at https://mcp.webflow.com/mcp and since v2.0 most tools run through the Data API with no Designer session. Only snapshots, selection and canvas navigation need the Bridge App open source
- MCP v2.1 shipped on 21 September 2026 with tools for interactions, Webflow Cloud and Campaigns, and custom-field filters on
list_collection_itemssource - The official MCP registry lists com.webflow/mcp with the remote https://mcp.webflow.com/mcp, published 27 October 2025 source
- CMS items are created and updated as drafts, and
publish_collection_itemsor Publish Site makes them live source - The MCP server can't create new localised CMS items or change a site's access settings, and each authorisation covers one workspace source
- Rate limits are 60 requests a minute on Starter and Basic and 120 on higher site plans, per token, with Retry-After on 429 source
- The open-source server in webflow/mcp-server is at v1.2 with its last commit on 10 April 2026, behind the hosted v2.1 source
- Status history since 10 July 2026 shows four minor incidents on the Data API and MCP server, one of them a week of missing MCP tools from 9 to 16 July source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 15.8 | |
| Graded on the Data API v2 and the hosted MCP server. Public status page at status.webflow.com with components for the Data API and the MCP server and a full incident history (20). Since 10 July 2026 the graded surface had four incidents, all marked minor (MCP tools missing from 9 to 16 July, outgoing webhooks on 28 July, 503 errors on the MCP server for about two hours on 25 August, MCP authorisation for client workspaces on 17 September). Two major incidents and one critical one in the same period were on hosted site pages and form emails, outside the graded surface. We read that as 15 of 30, between minor only and one major, because the July incident ran for a week. Rate limits published, 60 requests a minute on Starter and Basic and 120 on higher site plans (15). 429 carries Retry-After and the SDKs back off, but no idempotency keys were found for Data API writes (11). An SLA page dated 1 September 2026 exists and the pricing page lists enhanced SLAs on Enterprise. The terms sit in a PDF we didn't read (8 of 10). The /v2 namespace is described as production and the MCP server has a separate beta URL (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.1 | |
Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. The hosted MCP server's v2.1 tool schemas aren't in the public repository, whose last commit is 10 April 2026 (23 of 25). A root llms.txt, section indexes and a Markdown copy of every page at the URL plus .md (10). The MCP data tools reference says for each tool whether it reads or writes, when to use it and what each action needs (16). The spec types parameters with enums and required fields. Item content in fieldData is an object checked against the collection's own schema (11). Request and response examples throughout, an error format with code, message and details, and an enumerated list of about 100 error codes (13). /v2 and /beta in the path and a dated changelog with a full index, though some changes land in place on the day (14). | |||
| Agent ergonomics | 13%16.2 | 11.7 | |
The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for get_more_tools, which loads specialised tools on request, and for tools labelled read or write (11 of 25). limit up to 100 and offset on lists, and custom-field filters and sorts on collection items with up to 10 filter terms (20). Errors carry a machine-readable code from a published list, and the MCP server returns ModeForbidden when a tool can't run in the current Designer mode (16). No idempotency keys on Data API writes. The open-source server sets readOnlyHint on its tools, and the hosted server has a dry run and an idempotency key for Webflow Cloud deploys only (10 of 20). Few required parameters, and official SDKs for JavaScript and Python (15). | |||
| Security & auth | 14%17.5 | 12.9 | |
OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days without use. The MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint. Tokens travel in the Authorization header. We took 2 off because the MCP metadata also accepts the plain challenge method and site-token rotation isn't described (28). Scopes split read from write, the person picks sites or a workspace at authorisation, and the MCP server follows the user's role. A granted tool grants all its actions and no confirmation step for deletes was found (14). Agent Instructions stored on a site are given to every connected agent automatically, and the docs give no guidance on treating site content as untrusted beyond limiting authorised sites and reviewing generated drafts (5). Agent changes are recorded in the site activity log, which the pricing page lists on Team and Enterprise, with an Audit Logs API on Enterprise (9). A valid security.txt pointing to a Bugcrowd disclosure programme, SOC 2 Type II, ISO 27001, 27017, 27018 and 42001, and an annual penetration test report in the trust centre (18). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices are public (Basic $15 and Premium $25 a month billed yearly, Team $2,500 a month on an annual contract), with Enterprise through sales and no per-call price (10). The Starter site plan is free and includes the CMS APIs at 60 requests a minute and the MCP server. The pricing page doesn't say whether signup needs a card (20, with that caveat). A person signs up in a browser and creates the token or approves the OAuth screen (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.0 | |
| The newest developer changelog entry is dated 7 October 2026 (30). Sixteen dated entries since 10 July 2026, among them MCP v2.0.1 on 21 July and MCP v2.1 on 21 September (20). Public changelog, a support site and a community forum. We couldn't read the GitHub issue trackers, and the open-source MCP repository has had no commits since 10 April 2026 while the hosted server moved to v2.1 (8 of 15). The server is in the official MCP registry as com.webflow/mcp, and the JavaScript SDK (3.3.4, 16 March 2026) and Python SDK (2.0.0, 12 March 2026) are current (15). The JavaScript SDK repository has CI and a dependency patch merged on 6 October 2026. The MCP repository pins webflow-api 3.2.1 (7). | |||
| Transparency & trusteditorial 65, provenance 97 | 7%8.8 | 7.1 | |
| Closed service with published Terms of Service and Developer Terms. The OpenAPI spec, both SDKs and the older open-source MCP server are MIT (17). Privacy policy effective 17 March 2025 and a DPA effective 15 November 2023 with deletion or return of personal data at termination. Retention is stated as for as long as necessary, with no periods (20). A dated v1 deprecation notice (31 March 2025) and a removal notice for the User Accounts APIs, but no written deprecation policy, and two breaking changes in the last 90 days landed on the day of their changelog entry (11). Sub-processor list updated 9 July 2026 with each company's country, nearly all in the USA. No choice of data region was found (17). | |||
| Negative events | ≤15 |
| -3 |
| Total | 69.4 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Webflow, or have the agent fetch /fixes/webflow.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Webflow From Anchor Terminal's listing at https://www.anchorterminal.com/tools/webflow, the October 2026 research run, assessed 8 October 2026. Grade B, 69.4 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Webflow: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices are public (Basic $15 and Premium $25 a month billed yearly, Team $2,500 a month on an annual contract), with Enterprise through sales and no per-call price (10). The Starter site plan is free and includes the CMS APIs at 60 requests a minute and the MCP server. The pricing page doesn't say whether signup needs a card (20, with that caveat). A person signs up in a browser and creates the token or approves the OAuth screen (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Agent ergonomics, 72 out of 100, up to 4.6 more on the total Why it scored 72: The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for `get_more_tools`, which loads specialised tools on request, and for tools labelled read or write (11 of 25). `limit` up to 100 and `offset` on lists, and custom-field filters and sorts on collection items with up to 10 filter terms (20). Errors carry a machine-readable code from a published list, and the MCP server returns `ModeForbidden` when a tool can't run in the current Designer mode (16). No idempotency keys on Data API writes. The open-source server sets `readOnlyHint` on its tools, and the hosted server has a dry run and an idempotency key for Webflow Cloud deploys only (10 of 20). Few required parameters, and official SDKs for JavaScript and Python (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 3. Security & auth, 74 out of 100, up to 4.6 more on the total Why it scored 74: OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days without use. The MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint. Tokens travel in the Authorization header. We took 2 off because the MCP metadata also accepts the `plain` challenge method and site-token rotation isn't described (28). Scopes split read from write, the person picks sites or a workspace at authorisation, and the MCP server follows the user's role. A granted tool grants all its actions and no confirmation step for deletes was found (14). Agent Instructions stored on a site are given to every connected agent automatically, and the docs give no guidance on treating site content as untrusted beyond limiting authorised sites and reviewing generated drafts (5). Agent changes are recorded in the site activity log, which the pricing page lists on Team and Enterprise, with an Audit Logs API on Enterprise (9). A valid security.txt pointing to a Bugcrowd disclosure programme, SOC 2 Type II, ISO 27001, 27017, 27018 and 42001, and an annual penetration test report in the trust centre (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Reliability, 79 out of 100, up to 4.2 more on the total Why it scored 79: Graded on the Data API v2 and the hosted MCP server. Public status page at status.webflow.com with components for the Data API and the MCP server and a full incident history (20). Since 10 July 2026 the graded surface had four incidents, all marked minor (MCP tools missing from 9 to 16 July, outgoing webhooks on 28 July, 503 errors on the MCP server for about two hours on 25 August, MCP authorisation for client workspaces on 17 September). Two major incidents and one critical one in the same period were on hosted site pages and form emails, outside the graded surface. We read that as 15 of 30, between minor only and one major, because the July incident ran for a week. Rate limits published, 60 requests a minute on Starter and Basic and 120 on higher site plans (15). 429 carries Retry-After and the SDKs back off, but no idempotency keys were found for Data API writes (11). An SLA page dated 1 September 2026 exists and the pricing page lists enhanced SLAs on Enterprise. The terms sit in a PDF we didn't read (8 of 10). The /v2 namespace is described as production and the MCP server has a separate beta URL (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 5. Schema & documentation, 87 out of 100, up to 2.1 more on the total Why it scored 87: Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. The hosted MCP server's v2.1 tool schemas aren't in the public repository, whose last commit is 10 April 2026 (23 of 25). A root llms.txt, section indexes and a Markdown copy of every page at the URL plus .md (10). The MCP data tools reference says for each tool whether it reads or writes, when to use it and what each action needs (16). The spec types parameters with enums and required fields. Item content in `fieldData` is an object checked against the collection's own schema (11). Request and response examples throughout, an error format with `code`, `message` and `details`, and an enumerated list of about 100 error codes (13). /v2 and /beta in the path and a dated changelog with a full index, though some changes land in place on the day (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Maintenance & community, 80 out of 100, up to 1.8 more on the total Why it scored 80: The newest developer changelog entry is dated 7 October 2026 (30). Sixteen dated entries since 10 July 2026, among them MCP v2.0.1 on 21 July and MCP v2.1 on 21 September (20). Public changelog, a support site and a community forum. We couldn't read the GitHub issue trackers, and the open-source MCP repository has had no commits since 10 April 2026 while the hosted server moved to v2.1 (8 of 15). The server is in the official MCP registry as com.webflow/mcp, and the JavaScript SDK (3.3.4, 16 March 2026) and Python SDK (2.0.0, 12 March 2026) are current (15). The JavaScript SDK repository has CI and a dependency patch merged on 6 October 2026. The MCP repository pins webflow-api 3.2.1 (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 81 out of 100, up to 1.7 more on the total Made of editorial 65, provenance 97. Why it scored 81: Closed service with published Terms of Service and Developer Terms. The OpenAPI spec, both SDKs and the older open-source MCP server are MIT (17). Privacy policy effective 17 March 2025 and a DPA effective 15 November 2023 with deletion or return of personal data at termination. Retention is stated as for as long as necessary, with no periods (20). A dated v1 deprecation notice (31 March 2025) and a removal notice for the User Accounts APIs, but no written deprecation policy, and two breaking changes in the last 90 days landed on the day of their changelog entry (11). Sub-processor list updated 9 July 2026 with each company's country, nearly all in the USA. No choice of data region was found (17). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10) ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: GitHub stars and open issues for webflow/mcp-server and webflow/js-webflow-api. The GitHub API refused us for its rate limit, so responsiveness on issues wasn't read - unchecked: the SLA terms and uptime figure, which sit in a PDF linked from webflow.com/legal/sla - unchecked: the hosted MCP server's v2.1 tool input schemas and annotations, which need a signed-in session. The public repository stops at v1.2 (10 April 2026) - unchecked: whether CI passes on the default branches of the SDK and MCP repositories - Not established whether signup for the free Starter plan needs a card. The pricing page lists it as free and doesn't say - Not established which price belongs to monthly billing. The pricing text shows yearly-billed prices, and the page's price attributes suggest $25 a month for Basic and $39 for Premium billed monthly - Not established whether the Starter plan can publish a single CMS item. The pricing table marks per-item publishing as absent on Starter and Basic - Not established when MCP v2.0 shipped or how much notice its tool renames had. The migration guide lists renames across v1.3, v2.0, v2.0.1 and v2.1 - The rate limits page still uses older plan names (CMS, eCommerce, Business), while the pricing page lists Starter, Basic and Premium - The lead's docs URL (data/docs/ai-tools) is an older page that still describes the Bridge App as required and remote authorisation as experimental. The current MCP docs are under developers.webflow.com/mcp ## Weaknesses - The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions - No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute - The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales - The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise - On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes - Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes - Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429 - Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[<fieldSlug>][<operator>]`, up to 10 terms - Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId` ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: GitHub stars and open issues for webflow/mcp-server and webflow/js-webflow-api. The GitHub API refused us for its rate limit, so responsiveness on issues wasn't read
- unchecked: the SLA terms and uptime figure, which sit in a PDF linked from webflow.com/legal/sla
- unchecked: the hosted MCP server's v2.1 tool input schemas and annotations, which need a signed-in session. The public repository stops at v1.2 (10 April 2026)
- unchecked: whether CI passes on the default branches of the SDK and MCP repositories
- Not established whether signup for the free Starter plan needs a card. The pricing page lists it as free and doesn't say
- Not established which price belongs to monthly billing. The pricing text shows yearly-billed prices, and the page's price attributes suggest $25 a month for Basic and $39 for Premium billed monthly
- Not established whether the Starter plan can publish a single CMS item. The pricing table marks per-item publishing as absent on Starter and Basic
- Not established when MCP v2.0 shipped or how much notice its tool renames had. The migration guide lists renames across v1.3, v2.0, v2.0.1 and v2.1
- The rate limits page still uses older plan names (CMS, eCommerce, Business), while the pricing page lists Starter, Basic and Premium
- The lead's docs URL (data/docs/ai-tools) is an older page that still describes the Bridge App as required and remote authorisation as experimental. The current MCP docs are under developers.webflow.com/mcp
Sources 35
- developer docs index (llms.txt) developers.webflow.com · seen 2026-10-08
- MCP server overview and limitations developers.webflow.com · seen 2026-10-08
- MCP server, how it works developers.webflow.com · seen 2026-10-08
- MCP data tools reference developers.webflow.com · seen 2026-10-08
- MCP utility tools reference developers.webflow.com · seen 2026-10-08
- MCP install for Claude Code developers.webflow.com · seen 2026-10-08
- MCP OAuth authorisation server metadata mcp.webflow.com · seen 2026-10-08
- rate limits developers.webflow.com · seen 2026-10-08
- error handling developers.webflow.com · seen 2026-10-08
- scopes developers.webflow.com · seen 2026-10-08
- site tokens developers.webflow.com · seen 2026-10-08
- OAuth and token revocation developers.webflow.com · seen 2026-10-08
- versioning developers.webflow.com · seen 2026-10-08
- publishing with the CMS API developers.webflow.com · seen 2026-10-08
- List Collection Items reference developers.webflow.com · seen 2026-10-08
- changelog index developers.webflow.com · seen 2026-10-08
- changelog entry, Get Site Plan breaking change developers.webflow.com · seen 2026-10-08
- changelog entry, translatable parameter change developers.webflow.com · seen 2026-10-08
- OpenAPI spec repository github.com · seen 2026-10-08
- open-source MCP server repository github.com · seen 2026-10-08
- JavaScript SDK repository github.com · seen 2026-10-08
- status page incident history status.webflow.com · seen 2026-10-08
- pricing webflow.com · seen 2026-10-08
- Terms of Service webflow.com · seen 2026-10-08
- Developer Terms of Service webflow.com · seen 2026-10-08
- privacy policy webflow.com · seen 2026-10-08
- data processing addendum webflow.com · seen 2026-10-08
- sub-processors webflow.com · seen 2026-10-08
- service level agreement page webflow.com · seen 2026-10-08
- security page webflow.com · seen 2026-10-08
- trust centre trust.webflow.com · seen 2026-10-08
- security.txt webflow.com · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- npm registry, webflow-api registry.npmjs.org · seen 2026-10-08
- PyPI, webflow pypi.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $15 / mo The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Basic site plan | $15 | per month (plan) | billed yearly, per site, no CMS |
| Premium site plan | $25 | per month (plan) | billed yearly, per site, 20,000 CMS items and 120 requests a minute |
| Team platform plan | $2500 | per month (plan) | annual contract, 5 full and 5 limited seats included |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/webflow.xml, or this listing's score history at history.json.
Connect
Install
npm install webflow-api
First request
curl --request GET \
--url https://api.webflow.com/v2/sites \
--header 'accept: application/json' \
--header 'authorization: Bearer YOUR_API_TOKEN'
Claude Code
claude mcp add --transport http webflow https://mcp.webflow.com/mcp
Through letme picks today, calling later
GET https://letme.dev/webflow
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Sanity BBStoryblok BStrapi BContentstack BWordPress BGhost C
Head to head Contentstack vs Webflow · Ghost vs Webflow · Sanity vs Webflow · Storyblok vs Webflow · Strapi vs Webflow · Webflow vs WordPress
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Sanity Sanity US Inc. and Sanity AS | BB | 73.7 | cms.content cms.publish cms.assets cms.schema cms.localisation | no |
| Storyblok Storyblok GmbH | B | 67.7 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| Strapi Strapi, Inc. | B | 65.7 | cms.content cms.publish cms.localisation cms.assets cms.schema | no |
| Contentstack Contentstack Inc. | B | 64 | cms.content cms.publish cms.assets cms.localisation cms.schema | no |
| WordPress WordPress.org (open-source project) | B | 64.8 | cms.content cms.publish cms.assets | no |
| Ghost Ghost Foundation | C | 58.3 | cms.content cms.publish cms.assets | no |
Machine-readable
- JSON
/api/v1/tools/webflow.json· historyhistory.json· badge/badges/webflow.svg· changes feed/feeds/tools/webflow.xml - Markdown
/tools/webflow.md· slim/tools/webflow.min.md(or sendAccept: text/markdown) - Fix list
/fixes/webflow.md·/fixes/webflow.json - From a terminal
anchor tool webflow --md(the CLI) · over MCPget_tool {"slug": "webflow"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/webflow"><img src="https://www.anchorterminal.com/badges/webflow.svg" alt="Webflow on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/webflow)<a href="https://www.anchorterminal.com/tools/webflow">Webflow on Anchor Terminal</a>It counts on a page on webflow.com or one of its subdomains, or the README of github.com/webflow/openapi-spec.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "webflow", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


