# Webflow (slim) > Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools. - Full: https://www.anchorterminal.com/tools/webflow.md (~8,700 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/webflow.json · canonical https://www.anchorterminal.com/tools/webflow - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 69.4/100 · rank #160 of 722 · #3 in CMS & website publishing · not agent-ready · confidence medium** Assessment: The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan. ## Facts - Kind: HTTP API · vendor: Webflow, Inc. · category: CMS & website publishing · legal entity: Webflow, Inc. · provenance 97/100 - Endpoint: `https://api.webflow.com/v2` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: Data API v2 (REST, JSON) at https://api.webflow.com/v2, a /beta namespace for new endpoints, and the official hosted MCP server over the same API. A read-only content delivery API serves cached CMS data - MCP server: Hosted at https://mcp.webflow.com/mcp (streamable HTTP), beta at https://mcp.webflow.com/beta/mcp. Version 2.1 since 21 September 2026. 27 data tools, 3 Designer session tools and 4 utility tools. OAuth only, one workspace per authorisation - CMS actions: Collections, static, option and reference fields, field groups, items created and updated as drafts, publish and unpublish (unpublish up to 100 a call), delete, and site publish - Credentials: OAuth apps and site tokens with read and write scope pairs (assets, cms, pages, sites, forms, components, comments, custom_code, ecommerce and others). At most 5 site tokens a site, expiring after 365 days unused. Custom code endpoints need an OAuth app - Rate limits: 60 requests a minute on Starter and Basic, 120 on higher site plans, custom on Enterprise, counted per token. Site publish once a minute. Asset compression 10 calls a minute per site - Errors: JSON body with `code`, `message`, `externalReference` and `details`. 429 with Retry-After, and X-RateLimit-Limit and X-RateLimit-Remaining on every response - Pagination: `limit` (maximum 100) and `offset`. Collection items filter with `filter[][]` (up to 10 terms) and sort on up to 3 custom fields - Drafts and versions: `isDraft` and `lastPublished` give the item state. A live item can hold staged changes. Scheduled publishing can't be set through the CMS API. No version history or rollback endpoint was found in the reviewed pages - Assets: Two-step upload (create the asset with a file hash, then POST the bytes to a presigned URL). Folders can't be deleted through the API. Asset delete is a soft delete that the API can't restore - Localisation: Items and pages carry a locale id (`cmsLocaleId`). The MCP server reads and updates content in secondary locales and can't create new localised CMS items. Localisation is a priced add-on - Free tier: Starter site plan. 50 CMS items, 20 collections, 2 static pages, 1 GB bandwidth, CMS APIs at 60 requests a minute, MCP server included - SDKs: webflow-api 3.3.4 for JavaScript (16 March 2026) and webflow 2.0.0 for Python (12 March 2026), both MIT. The SDKs don't call beta endpoints - Audit: Agent changes are recorded in the site activity log. The pricing page lists the activity log and its API on Team and Enterprise, and an Audit Logs API on Enterprise - Certifications: SOC 1 Type 2, SOC 2 Type 2, ISO 27001, 27017, 27018 and 42001, PCI DSS per the trust centre. Bugcrowd disclosure programme named in security.txt - Sub-processors: List updated 9 July 2026 with countries, nearly all in the USA. AWS for hosting, Cloudflare for delivery, MongoDB for the database, Anthropic and OpenAI for AI services - Open source: No. The OpenAPI spec, both SDKs and an older local MCP server (webflow/mcp-server, last commit 10 April 2026) are MIT - Prices: Basic site plan $15 per month (plan); Premium site plan $25 per month (plan); Team platform plan $2500 per month (plan) - Scores: Reliability 79, Performance pending, Schema & documentation 87, Agent ergonomics 72, Security & auth 74, Payments & pricing 30, Task success pending, Maintenance & community 80, Transparency & trust 81 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Graded on the Data API v2 and the hosted MCP server. · Schema & documentation, Public OpenAPI 3.1 spec in webflow/openapi-spec with 140 operations for v2 and 139 for v2 beta, MIT. · Agent ergonomics, The MCP server documents 34 tools, each bundling several actions, which is the checklist's 5. We added 6 for `get_more_tools`, which loads s… · Security & auth, OAuth with read and write scope pairs per resource, or site tokens with the same scopes, at most 5 per site, which expire after 365 days wit… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest developer changelog entry is dated 7 October 2026 (30). · Transparency & trust, Closed service with published Terms of Service and Developer Terms. - Sources: 35, open questions: 10, both in the full twin - Capabilities: cms.content, cms.publish, cms.assets, cms.schema, cms.localisation - JSON: https://www.anchorterminal.com/api/v1/tools/webflow.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/webflow.svg` or a link to https://www.anchorterminal.com/tools/webflow from a page on webflow.com or one of its subdomains, or the README of github.com/webflow/openapi-spec, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes 2. Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes 3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429 4. Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[][]`, up to 10 terms 5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId` ## Connect ```bash npm install webflow-api ``` ```bash curl --request GET \ --url https://api.webflow.com/v2/sites \ --header 'accept: application/json' \ --header 'authorization: Bearer YOUR_API_TOKEN' ``` ```bash claude mcp add --transport http webflow https://mcp.webflow.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/webflow ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | https://www.anchorterminal.com/tools/directus.min.md | | Strapi | B | 65.7 | cms.content, cms.publish, cms.localisation, cms.assets, cms.schema | https://www.anchorterminal.com/tools/strapi.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)