{
 "categories": [
  "documents",
  "developer-tools"
 ],
 "deployment": "hybrid",
 "evidence": [
  {
   "date": "2026-10-04",
   "fact": "homepage",
   "note": "Directus presents a database backend with REST and GraphQL APIs, a no-code studio, and a native MCP server. The footer copyright is Monospace Inc.",
   "source": "https://directus.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "deployment",
   "note": "The homepage says to self-host on your own infrastructure or deploy to Directus Cloud.",
   "source": "https://directus.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "platforms",
   "note": "The product is used through the Data Studio and generated APIs. The homepage does not name desktop operating systems.",
   "source": "https://directus.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "license",
   "note": "Directus is licensed under the Monospace Sustainable Core License. Instances without a license run on the free core tier. Additional capabilities require a license. The homepage says self-host free with no credit card required.",
   "source": "https://directus.com/docs/licensing/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.exists",
   "note": "Directus documents REST endpoints generated for each collection, including GET and POST /items/posts.",
   "source": "https://directus.com/docs/getting-started/use-the-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.kinds[0]",
   "note": "The getting-started guide uses HTTP GET and POST against /items endpoints.",
   "source": "https://directus.com/docs/getting-started/use-the-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.kinds[1]",
   "note": "The homepage says connecting a database generates a REST and GraphQL API. The getting-started guide points the API reference at GraphQL examples as well.",
   "source": "https://directus.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.auth[0]",
   "note": "Requests can send Authorization Bearer with a static token or a short-lived access token. Each user can have one static token.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.auth[1]",
   "note": "Session authentication uses the directus_session_token cookie, which the browser sends automatically.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.auth[2]",
   "note": "Requests can append access_token as a query parameter. The page says that can leak the token and to prefer another method.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.api.coverage",
   "note": "Item endpoints follow the collections and the token's permissions. The licensing overview says a locked instance disables /items and GraphQL.",
   "source": "https://directus.com/docs/getting-started/use-the-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.sdk.exists",
   "note": "The authentication guide shows createDirectus from @directus/sdk with authentication and REST helpers.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.sdk.languages[0]",
   "note": "The documented SDK examples are JavaScript imports from @directus/sdk.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.sdk.official",
   "note": "The package is shown in Directus's own authentication documentation.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "modalities.mcp.first_party",
   "note": "Directus v11.12 or later includes a remote MCP server at /mcp. It is disabled by default. Auth is OAuth or a static token. Allow Deletes is off by default.",
   "source": "https://directus.com/docs/guides/ai/mcp/installation",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "verdict.scores.api",
   "note": "Generated collection CRUD with bearer tokens is a practical production path. Role permissions and the license lock on over-limit instances are the material limits.",
   "source": "https://directus.com/docs/getting-started/use-the-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "verdict.scores.mcp",
   "note": "The built-in server is official and permission-scoped. It must be enabled, requires v11.12 or later, and does not delete unless Allow Deletes is turned on.",
   "source": "https://directus.com/docs/guides/ai/mcp/installation",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "freshness.watch[0].url",
   "note": "Opened the current remote MCP installation guide, including version, auth, and tool modes.",
   "source": "https://directus.com/docs/guides/ai/mcp/installation",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "freshness.watch[1].url",
   "note": "Opened the current REST getting-started guide for collection items.",
   "source": "https://directus.com/docs/getting-started/use-the-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "freshness.watch[2].url",
   "note": "Opened the current authentication guide for bearer, cookie, and query-token access.",
   "source": "https://directus.com/docs/guides/connect/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-04",
   "fact": "freshness.watch[3].url",
   "note": "Opened the current licensing overview, including the core tier and locked-down API behavior.",
   "source": "https://directus.com/docs/licensing/overview",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-04",
  "volatility": "high",
  "watch": [
   {
    "type": "docs",
    "url": "https://directus.com/docs/guides/ai/mcp/installation"
   },
   {
    "type": "docs",
    "url": "https://directus.com/docs/getting-started/use-the-api"
   },
   {
    "type": "docs",
    "url": "https://directus.com/docs/guides/connect/authentication"
   },
   {
    "type": "docs",
    "url": "https://directus.com/docs/licensing/overview"
   }
  ]
 },
 "homepage": "https://directus.com/",
 "id": "directus",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "bearer-token",
    "session-cookie",
    "query-token"
   ],
   "coverage": "partial",
   "docs": "https://directus.com/docs/getting-started/use-the-api",
   "exists": true,
   "kinds": [
    "rest",
    "graphql"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The generated REST API and the built-in MCP server cover collection access without browser control.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "javascript"
   ],
   "official": true
  }
 },
 "name": "Directus",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "contentful",
   "storyblok",
   "sanity",
   "strapi"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Monospace Inc.",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Directus is automatable today through the APIs it generates from a connected database. REST item endpoints such as GET and POST /items/posts accept Authorization Bearer with a static access token. The authentication guide also documents a session cookie named directus_session_token and an access_token query parameter, and it says to prefer a method other than the query parameter. The homepage says Directus generates REST and GraphQL APIs. The docs show a JavaScript client, @directus/sdk. Directus v11.12 or later includes a remote MCP server at /mcp. It is disabled until an administrator enables it under Settings, AI, Model Context Protocol. Auth is OAuth or a static user token. Registry mode at /mcp?tool_mode=registry exposes search, execute, and schema. Deletes stay off unless Allow Deletes is enabled. Permissions follow the connected user. Directus is licensed under the Monospace Sustainable Core License. A self-hosted instance without a license runs on the core tier. Higher limits need a paid license. If an instance is over its entitlement and the grace period has elapsed, item, GraphQL, and MCP APIs are disabled. The homepage says the same product can be self-hosted or run on Directus Cloud, and self-hosting can start free. Zapier, Make, Power Automate, and n8n were not assessed. A command-line inventory was not established. Computer-use viability is unassessed. API scores 8. MCP scores 7. API is the best path because a static bearer token calls generated item endpoints directly, without enabling MCP.\n"
 }
}