# Webflow > Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools. - Canonical: https://www.anchorterminal.com/tools/webflow - Markdown: https://www.anchorterminal.com/tools/webflow.md (~8,700 tokens) - Slim: https://www.anchorterminal.com/tools/webflow.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/webflow.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 69.4/100 · rank #160 of 722 · #3 in CMS & website publishing · not agent-ready · confidence medium** ## Assessment The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan. ## Facts | Field | Value | | --- | --- | | Vendor | Webflow, Inc. (https://webflow.com) | | Kind | HTTP API | | Category | CMS & website publishing (https://www.anchorterminal.com/categories/cms) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://api.webflow.com/v2` | | Auth | OAuth or key · Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps & integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens. | | Pricing | Freemium ($15 / mo) · The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT | | Tools exposed | 34 | | Packages | npm: `webflow-api`; pypi: `webflow`; npm: `webflow-mcp-server` | | MCP registry name | `com.webflow/mcp` | | Source | https://github.com/webflow/openapi-spec | | Docs | https://developers.webflow.com/data/docs | | llms.txt | https://developers.webflow.com/llms.txt | | Last release | 2026-10-07 | | npm downloads / week | 85,160 | | PyPI downloads / week | 121,246 | | Surfaces | Data API v2 (REST, JSON) at https://api.webflow.com/v2, a /beta namespace for new endpoints, and the official hosted MCP server over the same API. A read-only content delivery API serves cached CMS data | | MCP server | Hosted at https://mcp.webflow.com/mcp (streamable HTTP), beta at https://mcp.webflow.com/beta/mcp. Version 2.1 since 21 September 2026. 27 data tools, 3 Designer session tools and 4 utility tools. OAuth only, one workspace per authorisation | | CMS actions | Collections, static, option and reference fields, field groups, items created and updated as drafts, publish and unpublish (unpublish up to 100 a call), delete, and site publish | | Credentials | OAuth apps and site tokens with read and write scope pairs (assets, cms, pages, sites, forms, components, comments, custom_code, ecommerce and others). At most 5 site tokens a site, expiring after 365 days unused. Custom code endpoints need an OAuth app | | Rate limits | 60 requests a minute on Starter and Basic, 120 on higher site plans, custom on Enterprise, counted per token. Site publish once a minute. Asset compression 10 calls a minute per site | | Errors | JSON body with `code`, `message`, `externalReference` and `details`. 429 with Retry-After, and X-RateLimit-Limit and X-RateLimit-Remaining on every response | | Pagination | `limit` (maximum 100) and `offset`. Collection items filter with `filter[][]` (up to 10 terms) and sort on up to 3 custom fields | | Drafts and versions | `isDraft` and `lastPublished` give the item state. A live item can hold staged changes. Scheduled publishing can't be set through the CMS API. No version history or rollback endpoint was found in the reviewed pages | | Assets | Two-step upload (create the asset with a file hash, then POST the bytes to a presigned URL). Folders can't be deleted through the API. Asset delete is a soft delete that the API can't restore | | Localisation | Items and pages carry a locale id (`cmsLocaleId`). The MCP server reads and updates content in secondary locales and can't create new localised CMS items. Localisation is a priced add-on | | Free tier | Starter site plan. 50 CMS items, 20 collections, 2 static pages, 1 GB bandwidth, CMS APIs at 60 requests a minute, MCP server included | | SDKs | webflow-api 3.3.4 for JavaScript (16 March 2026) and webflow 2.0.0 for Python (12 March 2026), both MIT. The SDKs don't call beta endpoints | | Audit | Agent changes are recorded in the site activity log. The pricing page lists the activity log and its API on Team and Enterprise, and an Audit Logs API on Enterprise | | Certifications | SOC 1 Type 2, SOC 2 Type 2, ISO 27001, 27017, 27018 and 42001, PCI DSS per the trust centre. Bugcrowd disclosure programme named in security.txt | | Sub-processors | List updated 9 July 2026 with countries, nearly all in the USA. AWS for hosting, Cloudflare for delivery, MongoDB for the database, Anthropic and OpenAI for AI services | | Open source | No. The OpenAPI spec, both SDKs and an older local MCP server (webflow/mcp-server, last commit 10 April 2026) are MIT | | Capabilities | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | | Tags | official, hosted, mcp, oauth, openapi, llms-txt, closed-source, free-tier, webhooks, typescript, python, status-page, soc2, iso27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/webflow.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 79 | 15.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 87 | 14.1 | | Agent ergonomics | 13% | 16.2 | 72 | 11.7 | | Security & auth | 14% | 17.5 | 74 | 12.9 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 80 | 7.0 | | Transparency & trust (editorial 65, provenance 97) | 7% | 8.8 | 81 | 7.1 | | Negative events | up to −15 | up to −15 | 7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7). | -3 | | **Total** | | | | **69.4 → B** | ### Why each score - Reliability 79: Graded on the Data API v2 and the hosted MCP server. Public status page at status.webflow.com with components for the Data API and the MCP server and a full incident history (20). Since 10 July 2026 the graded surface had four incidents, all marked minor (MCP tools missing from 9 to 16 July, outgoing webhooks on 28 July, 503 errors on the MCP server for about two hours on 25 August, MCP authorisation for client workspaces on 17 September). Two major incidents and one critical one in the same period were on hosted site pages and form emails, outside the graded surface. We read that as 15 of 30, between minor only and one major, because the July incident ran for a week. Rate limits published, 60 requests a minute on Starter and Basic and 120 on higher site plans (15). 429 carries Retry-After and the SDKs back off, but no idempotency keys were found for Data API writes (11). An SLA page dated 1 September 2026 exists and the pricing page lists enhanced SLAs on Enterprise. The terms sit in a PDF we didn't read (8 of 10). The /v2 namespace is described as production and the MCP server has a separate beta URL (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 87: Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. The hosted MCP server's v2.1 tool schemas aren't in the public repository, whose last commit is 10 April 2026 (23 of 25). A root llms.txt, section indexes and a Markdown copy of every page at the URL plus .md (10). The MCP data tools reference says for each tool whether it reads or writes, when to use it and what each action needs (16). The spec types parameters with enums and required fields. Item content in `fieldData` is an object checked against the collection's own schema (11). Request and response examples throughout, an error format with `code`, `message` and `details`, and an enumerated list of about 100 error codes (13). /v2 and /beta in the path and a dated changelog with a full index, though some changes land in place on the day (14). - Agent ergonomics 72: The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for `get_more_tools`, which loads specialised tools on request, and for tools labelled read or write (11 of 25). `limit` up to 100 and `offset` on lists, and custom-field filters and sorts on collection items with up to 10 filter terms (20). Errors carry a machine-readable code from a published list, and the MCP server returns `ModeForbidden` when a tool can't run in the current Designer mode (16). No idempotency keys on Data API writes. The open-source server sets `readOnlyHint` on its tools, and the hosted server has a dry run and an idempotency key for Webflow Cloud deploys only (10 of 20). Few required parameters, and official SDKs for JavaScript and Python (15). - Security & auth 74: OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days without use. The MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint. Tokens travel in the Authorization header. We took 2 off because the MCP metadata also accepts the `plain` challenge method and site-token rotation isn't described (28). Scopes split read from write, the person picks sites or a workspace at authorisation, and the MCP server follows the user's role. A granted tool grants all its actions and no confirmation step for deletes was found (14). Agent Instructions stored on a site are given to every connected agent automatically, and the docs give no guidance on treating site content as untrusted beyond limiting authorised sites and reviewing generated drafts (5). Agent changes are recorded in the site activity log, which the pricing page lists on Team and Enterprise, with an Audit Logs API on Enterprise (9). A valid security.txt pointing to a Bugcrowd disclosure programme, SOC 2 Type II, ISO 27001, 27017, 27018 and 42001, and an annual penetration test report in the trust centre (18). - Payments & pricing 30: No x402, MPP or L402 (0). Plan prices are public (Basic $15 and Premium $25 a month billed yearly, Team $2,500 a month on an annual contract), with Enterprise through sales and no per-call price (10). The Starter site plan is free and includes the CMS APIs at 60 requests a minute and the MCP server. The pricing page doesn't say whether signup needs a card (20, with that caveat). A person signs up in a browser and creates the token or approves the OAuth screen (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 80: The newest developer changelog entry is dated 7 October 2026 (30). Sixteen dated entries since 10 July 2026, among them MCP v2.0.1 on 21 July and MCP v2.1 on 21 September (20). Public changelog, a support site and a community forum. We couldn't read the GitHub issue trackers, and the open-source MCP repository has had no commits since 10 April 2026 while the hosted server moved to v2.1 (8 of 15). The server is in the official MCP registry as com.webflow/mcp, and the JavaScript SDK (3.3.4, 16 March 2026) and Python SDK (2.0.0, 12 March 2026) are current (15). The JavaScript SDK repository has CI and a dependency patch merged on 6 October 2026. The MCP repository pins webflow-api 3.2.1 (7). - Transparency & trust 81: Closed service with published Terms of Service and Developer Terms. The OpenAPI spec, both SDKs and the older open-source MCP server are MIT (17). Privacy policy effective 17 March 2025 and a DPA effective 15 November 2023 with deletion or return of personal data at termination. Retention is stated as for as long as necessary, with no periods (20). A dated v1 deprecation notice (31 March 2025) and a removal notice for the User Accounts APIs, but no written deprecation policy, and two breaking changes in the last 90 days landed on the day of their changelog entry (11). Sub-processor list updated 9 July 2026 with each company's country, nearly all in the USA. No choice of data region was found (17). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/webflow.md (JSON https://www.anchorterminal.com/fixes/webflow.json) ### What we couldn't check - unchecked: GitHub stars and open issues for webflow/mcp-server and webflow/js-webflow-api. The GitHub API refused us for its rate limit, so responsiveness on issues wasn't read - unchecked: the SLA terms and uptime figure, which sit in a PDF linked from webflow.com/legal/sla - unchecked: the hosted MCP server's v2.1 tool input schemas and annotations, which need a signed-in session. The public repository stops at v1.2 (10 April 2026) - unchecked: whether CI passes on the default branches of the SDK and MCP repositories - Not established whether signup for the free Starter plan needs a card. The pricing page lists it as free and doesn't say - Not established which price belongs to monthly billing. The pricing text shows yearly-billed prices, and the page's price attributes suggest $25 a month for Basic and $39 for Premium billed monthly - Not established whether the Starter plan can publish a single CMS item. The pricing table marks per-item publishing as absent on Starter and Basic - Not established when MCP v2.0 shipped or how much notice its tool renames had. The migration guide lists renames across v1.3, v2.0, v2.0.1 and v2.1 - The rate limits page still uses older plan names (CMS, eCommerce, Business), while the pricing page lists Starter, Basic and Premium - The lead's docs URL (data/docs/ai-tools) is an older page that still describes the Bridge App as required and remote authorisation as experimental. The current MCP docs are under developers.webflow.com/mcp ### Sources - developer docs index (llms.txt): (seen 2026-10-08) - MCP server overview and limitations: (seen 2026-10-08) - MCP server, how it works: (seen 2026-10-08) - MCP data tools reference: (seen 2026-10-08) - MCP utility tools reference: (seen 2026-10-08) - MCP install for Claude Code: (seen 2026-10-08) - MCP OAuth authorisation server metadata: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - error handling: (seen 2026-10-08) - scopes: (seen 2026-10-08) - site tokens: (seen 2026-10-08) - OAuth and token revocation: (seen 2026-10-08) - versioning: (seen 2026-10-08) - publishing with the CMS API: (seen 2026-10-08) - List Collection Items reference: (seen 2026-10-08) - changelog index: (seen 2026-10-08) - changelog entry, Get Site Plan breaking change: (seen 2026-10-08) - changelog entry, translatable parameter change: (seen 2026-10-08) - OpenAPI spec repository: (seen 2026-10-08) - open-source MCP server repository: (seen 2026-10-08) - JavaScript SDK repository: (seen 2026-10-08) - status page incident history: (seen 2026-10-08) - pricing: (seen 2026-10-08) - Terms of Service: (seen 2026-10-08) - Developer Terms of Service: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - data processing addendum: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - service level agreement page: (seen 2026-10-08) - security page: (seen 2026-10-08) - trust centre: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - npm registry, webflow-api: (seen 2026-10-08) - PyPI, webflow: (seen 2026-10-08) ## Who's behind it (provenance 97/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Webflow, Inc. | 20/20 | | Domain age | webflow.com, registered 2003-03-31 (23 years) | 15/15 | | Endpoint on the vendor's domain | api.webflow.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.webflow.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law. The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits. The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026. The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com. webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026. RDAP for webflow.com gives a registration date of 2003-03-31. status.webflow.com runs on Statuspage with components for the Data API and the MCP server. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://webflow.com/legal/terms), read 2026-10-08, dated 2023-11-15, states 6 of the 7 things a reader expects. - To know. Says the terms or the service can change without notice (costs points). "Therefore, we may, without prior notice, change the Platform, add features, stop providing the Platform or features of the Platform to you or to customers generally, or create usage limits for the Platform." - To know. Says access can be ended without notice or for any reason. "Webflow may terminate this license at any time for any reason or no reason." - To know. Requires arbitration or waives class actions. "If you and Webflow are unable to resolve a Dispute through informal negotiations, all claims arising from use of the Platform (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration, unless otherwise prohibited by applicable law." - Gives the date it was last updated. Last updated 2023-11-15. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at $100. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Webflow's liability for any claim related to the agreement is capped at 100 US dollars. "IN NO EVENT SHALL WEBFLOW, ITS AFFILIATES, AGENTS, DIRECTORS, EMPLOYEES, SUPPLIERS, OR LICENSORS BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS RELATED TO THIS AGREEMENT IN AN AMOUNT EXCEEDING $100." - Also in the text (2026-10-08). The licence the customer grants over website content covers improving, testing and promoting the platform as well as running it, and is transferable and sub-licensable. "create derivative works (e.g., those resulting from you enabling localization translations and adaptations) of your Website Content for the purposes of providing, improving, testing, promoting, and securing the Platform." - Also in the text (2026-10-08). Annual plans are billed up front, are non-refundable and renew automatically for a further year unless cancelled before the term ends. "Your annual plan will automatically renew for successive one (1) year subscription periods, and you will be charged the applicable Fees on each annual anniversary of your purchase, unless you cancel the plan(s) on your Account prior to the end of the then-current annual term." **Privacy policy** (https://webflow.com/legal/privacy), read 2026-10-08, dated 2025-03-17, states 8 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "As described in this Privacy Policy, in certain situations we may share your Personal Information with certain third parties for our marketing or other purposes." - Gives the date it was last updated. Last updated 2025-03-17. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@webflow.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). Webflow may store credentials for third-party applications the customer connects, in encrypted form, and use them to access those accounts on the customer's behalf. "To facilitate the exchange of data between third-party SaaS applications, we may need to store certain information (“App Credentials”) that helps us access these third-party SaaS application accounts on your behalf." ## Live (updated 2026-10-08 19:53 UTC) - Right now: up, HTTP 404, 256 ms, checked 2026-10-08 19:53 UTC (get on `https://api.webflow.com/v2`) - Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 268 ms · p95 436 ms - Vendor status page: none, All Systems Operational - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/webflow.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Basic site plan | $15 | per month (plan) | billed yearly, per site, no CMS | | Premium site plan | $25 | per month (plan) | billed yearly, per site, 20,000 CMS items and 120 requests a minute | | Team platform plan | $2500 | per month (plan) | annual contract, 5 full and 5 limited seats included | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page - OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens - CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call - 429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically - Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page ## Weaknesses - The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions - No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute - The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales - The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise - On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day ## Before you call it (notes for agents) 1. Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes 2. Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes 3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429 4. Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[][]`, up to 10 terms 5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId` ## Connect Install: ```bash npm install webflow-api ``` First request: ```bash curl --request GET \ --url https://api.webflow.com/v2/sites \ --header 'accept: application/json' \ --header 'authorization: Bearer YOUR_API_TOKEN' ``` Claude Code: ```bash claude mcp add --transport http webflow https://mcp.webflow.com/mcp ``` Through letme (picks today, calling later): https://letme.dev/webflow. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | 62 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/datocms.md | | Sanity | BB | 73.7 | 73 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | no | https://www.anchorterminal.com/tools/sanity.md | | Storyblok | B | 67.7 | 202 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/storyblok.md | | Directus | B | 67.1 | 217 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | no | https://www.anchorterminal.com/tools/directus.md | | Strapi | B | 65.7 | 252 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | no | https://www.anchorterminal.com/tools/strapi.md | | Contentstack | B | 64 | 288 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | no | https://www.anchorterminal.com/tools/contentstack.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The MCP server is hosted at https://mcp.webflow.com/mcp and since v2.0 most tools run through the Data API with no Designer session. Only snapshots, selection and canvas navigation need the Bridge App open (source: ) - MCP v2.1 shipped on 21 September 2026 with tools for interactions, Webflow Cloud and Campaigns, and custom-field filters on `list_collection_items` (source: ) - The official MCP registry lists com.webflow/mcp with the remote https://mcp.webflow.com/mcp, published 27 October 2025 (source: ) - CMS items are created and updated as drafts, and `publish_collection_items` or Publish Site makes them live (source: ) - The MCP server can't create new localised CMS items or change a site's access settings, and each authorisation covers one workspace (source: ) - Rate limits are 60 requests a minute on Starter and Basic and 120 on higher site plans, per token, with Retry-After on 429 (source: ) - The open-source server in webflow/mcp-server is at v1.2 with its last commit on 10 April 2026, behind the hosted v2.1 (source: ) - Status history since 10 July 2026 shows four minor incidents on the Data API and MCP server, one of them a week of missing MCP tools from 9 to 16 July (source: ) ## Compare - [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md): B 64 vs B 69.4 - [DatoCMS vs Webflow](https://www.anchorterminal.com/compare/datocms-vs-webflow.md): BB 74.4 vs B 69.4 - [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md): B 67.1 vs B 69.4 - [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md): C 58.3 vs B 69.4 - [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md): C 55.2 vs B 69.4 - [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md): BB 73.7 vs B 69.4 - [Storyblok vs Webflow](https://www.anchorterminal.com/compare/storyblok-vs-webflow.md): B 67.7 vs B 69.4 - [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md): B 65.7 vs B 69.4 - [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md): B 69.4 vs B 64.8 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on webflow.com or one of its subdomains, or the README of github.com/webflow/openapi-spec. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "webflow", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Webflow on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Webflow on Anchor Terminal](https://www.anchorterminal.com/badges/webflow.svg)](https://www.anchorterminal.com/tools/webflow) ``` Plain link: ```html Webflow on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Webflow is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/webflow-dark.png - Light: https://www.anchorterminal.com/assets/share/webflow-light.png