dotCMS website screenshot

dotCMS

dotCMS is a Java-based visual headless content management system aimed at compliance-led enterprises, deployable as SaaS (dotCMS Cloud), on premise, or as a managed service. It covers content modelling, authoring, workflow, multi-site management, personalization, experiments and content analytics, and pairs headless delivery with a Universal Visual Editor so authors can edit content in place inside a React, Angular or Next.js front end. Every dotCMS instance serves its own first-party OpenAPI 3.0.1 at /api/openapi.json — 592 paths and 754 operations across 71 tags, covering content, content types, workflow, publishing, sites, roles, permissions and dotAI — alongside a GraphQL endpoint at /api/v1/graphql. dotCMS also ships an early agent surface: a first-party MCP server, two published Agent Skills, an RFC 9727 API catalog and markdown content negotiation. It is certified to ISO/IEC 27001, ISO/IEC 42001 (AI management), SOC 2 Type II and TX-RAMP Level II.

dotCMS publishes 1 API on the APIs.io network: REST API. Tagged areas include CMS, Content, Content Management, Headless CMS, and Digital Experience.

The dotCMS catalog on APIs.io includes 1 event-driven AsyncAPI specification.

dotCMS’s developer surface includes authentication, engineering blog, CLI, changelog, sandbox, documentation, API reference, and 33 more developer resources.

70.4/100 exemplar ▬ flat Agent 42/100 agent ready Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemiumSelf serve⚡ Free to try
2 APIs 1 MCP Servers
CMSContentContent ManagementHeadless CMSDigital ExperienceContent DeliveryWorkflowsGraphQLMCPJava

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/dotcms: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

dotCMS REST API

The dotCMS REST API exposes the platform's content management capabilities through HTTP endpoints, allowing developers to create, read, update, and delete content, manage workfl...

dotCMS GraphQL API

The dotCMS GraphQL API provides a single endpoint for querying content across all content types using a self-documenting schema. It supports Lucene-style query strings, paginati...

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

dotCMS MCP Server

dotCMS ships a first-party MCP server. It is distributed as an npm package run over stdio — there is no hosted endpoint an agent can POST to — and its source lives inside the op...

MCP SERVER

GraphQL 1

GraphQL schemas published by this provider.

dotCMS GraphQL API

The dotCMS GraphQL API provides a single endpoint for querying content across all content types using a self-documenting schema. It supports Lucene-style query strings, paginati...

GRAPHQL

Pricing Plans 1

Published pricing tiers and plan structures.

Dotcms Plans Pricing

4 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Dotcms Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Dotcms Authentication

http/apiKey-as-bearer/session · 5 schemes

SECURITY

Dotcms Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Dotcms Vulnerability Disclosure

security.txt · contact published

SECURITY

Dotcms Trust Center

ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Type II, TX-RAMP Level II, CSA CAIQ

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Dotcms Agentic Access

754 operations · 417 acting · 13 human-in-the-loop

754 operations · 417 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 6

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 4

Pagination, idempotency, versioning, errors, and events

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 7

Authentication, authorization, and security posture

Scroll for all 7

Operate 5

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: dotcms
url: https://raw.githubusercontent.com/api-evangelist/dotcms/refs/heads/main/apis.yml
common:
- type: Website
  url: https://www.dotcms.com/
- type: VulnerabilityDisclosure
  url: security/dotcms-vulnerability-disclosure.yml
- type: AgenticAccess
  url: agentic-access/dotcms-agentic-access.yml
- type: DomainSecurity
  url: security/dotcms-domain-security.yml
- type: Authentication
  url: authentication/dotcms-authentication.yml
- type: GitHubOrganization
  url: https://github.com/dotCMS
- type: LinkedIn
  url: https://www.linkedin.com/company/dotcms
- type: LlmsText
  url: https://dev.dotcms.com/llms.txt
- type: Blog
  url: https://www.dotcms.com/blog
- type: Packages
  url: packages/dotcms-packages.yml
- type: SDKs
  url: packages/dotcms-packages.yml
- type: CLI
  url: cli/dotcms-cli.yml
- type: Components
  url: components/dotcms-components.yml
- type: WellKnown
  url: well-known/dotcms-well-known.yml
- type: APICatalog
  url: https://www.dotcms.com/.well-known/api-catalog
- type: SecurityTxt
  url: well-known/dotcms-security.txt
- type: MCPServer
  url: mcp/dotcms-mcp.yml
- type: ToolCrosswalk
  url: mcp/dotcms-tool-crosswalk.yml
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/dotcms-llms.txt
- type: Conformance
  url: conformance/dotcms-conformance.yml
- type: Compliance
  url: https://www.dotcms.com/product/security-compliance
- type: TrustCenter
  url: security/dotcms-trust-center.yml
- type: Security
  url: https://dev.dotcms.com/docs/manage/access-and-security/security-and-privacy/responsible-disclosure-policy
- type: Lifecycle
  url: lifecycle/dotcms-lifecycle.yml
- type: Deprecation
  url: https://dev.dotcms.com/docs/reference/releases/product-versions/release-support-lifecycle
- type: ChangeLog
  url: changelog/dotcms-changelog.yml
- type: Sandbox
  url: sandbox/dotcms-sandbox.yml
- type: Webhooks
  url: asyncapi/dotcms-event-surface.yml
- type: Plans
  url: plans/dotcms-plans-pricing.yml
- type: RateLimits
  url: rate-limits/dotcms-rate-limits.yml
- type: DeveloperPortal
  url: https://dev.dotcms.com/
- type: Documentation
  url: https://dev.dotcms.com/docs
- type: APIReference
  url: https://dev.dotcms.com/docs/build/apis/rest-apis/api-playground
- type: GettingStarted
  url: https://dev.dotcms.com/getting-started
- type: Support
  url: https://community.dotcms.com/
- type: Roadmap
  url: https://www.dotcms.com/roadmap
- type: Pricing
  url: https://www.dotcms.com/pricing
- type: TermsOfService
  url: https://www.dotcms.com/bsl
- type: PrivacyPolicy
  url: https://dev.dotcms.com/docs/manage/access-and-security/security-and-privacy/privacy-policy
apis:
- aid: dotcms:rest
  name: dotCMS REST API
  tags:
  - CMS
  - Content
  - Content Management
  humanURL: https://dev.dotcms.com/docs/build/apis/api-basics/rest-apis
  baseURL: https://demo.dotcms.com/api
  properties:
  - url: https://dev.dotcms.com/docs/build/apis/api-basics/rest-apis
    type: Documentation
  - url: https://dev.dotcms.com/
    type: DeveloperPortal
  - url: openapi/dotcms-rest-api-openapi.json
    type: OpenAPI
  - url: https://dev.dotcms.com/docs/build/apis/rest-apis/api-playground
    type: APIReference
  - url: overlays/dotcms-rest-api-overlay.yaml
    type: Overlay
  - url: errors/dotcms-problem-types.yml
    type: ErrorCatalog
  - url: data-model/dotcms-data-model.yml
    type: DataModel
  - url: conventions/dotcms-conventions.yml
    type: Conventions
  description: The dotCMS REST API exposes the platform's content management capabilities through HTTP endpoints, allowing
    developers to create, read, update, and delete content, manage workflows, navigate site hierarchy, perform search queries,
    and administer users, roles, and permissions. The API is organized into resource groups including Content, Workflow, Search,
    Navigation, Sites, and User management, and supports authentication via JWT tokens, basic auth, and API keys.
- aid: dotcms:graphql
  name: dotCMS GraphQL API
  tags:
  - CMS
  - Content
  - Content Management
  - GraphQL
  humanURL: https://dev.dotcms.com/docs/graphql
  baseURL: https://demo.dotcms.com/api/v1/graphql
  properties:
  - url: https://dev.dotcms.com/docs/graphql
    type: Documentation
  - url: graphql/dotcms-graphql.md
    type: GraphQL
  description: The dotCMS GraphQL API provides a single endpoint for querying content across all content types using a self-documenting
    schema. It supports Lucene-style query strings, pagination, sorting, and content-type collections, and exposes base types
    for File, Form, Key/Value, Page, Persona, Vanity URL, and Widget content. The API accepts the same authentication methods
    as the dotCMS REST API and includes a built-in GraphQL Playground for exploring the schema.
name: dotCMS
tags:
- CMS
- Content
- Content Management
- Headless CMS
- Digital Experience
- Content Delivery
- Workflows
- GraphQL
- MCP
- Java
type: Index
deliveryModel:
  model: unknown
  open_source: false
  commercial: false
  callable_host: true
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: medium
  source:
  - plans
  - authentication
  - security
  generated: '2026-09-03'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/dotcms.png
access: 3rd-Party
created: '2025-01-08'
modified: '2026-09-06'
position: Consuming
description: 'dotCMS is a Java-based visual headless content management system aimed at compliance-led enterprises, deployable
  as SaaS (dotCMS Cloud), on premise, or as a managed service. It covers content modelling, authoring, workflow, multi-site
  management, personalization, experiments and content analytics, and pairs headless delivery with a Universal Visual Editor
  so authors can edit content in place inside a React, Angular or Next.js front end. Every dotCMS instance serves its own
  first-party OpenAPI 3.0.1 at /api/openapi.json — 592 paths and 754 operations across 71 tags, covering content, content
  types, workflow, publishing, sites, roles, permissions and dotAI — alongside a GraphQL endpoint at /api/v1/graphql. dotCMS
  also ships an early agent surface: a first-party MCP server, two published Agent Skills, an RFC 9727 API catalog and markdown
  content negotiation. It is certified to ISO/IEC 27001, ISO/IEC 42001 (AI management), SOC 2 Type II and TX-RAMP Level II.'
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
specificationVersion: '0.23'
x-enrichment:
  date: '2026-09-06'
  status: enriched
  artifacts_added: 24
  pass: local-v3
  note: STEP 0b contract discovery found the real first-party OpenAPI at https://demo.dotcms.com/api/openapi.json (592 paths
    / 754 operations), superseding seven documentation-derived scaffold specs of 19 paths total. Also found a first-party
    MCP server, two provider-authored Agent Skills, an RFC 9727 API catalog and an RFC 9116 security.txt. No agent card is
    served on any host (probed, 404 on all five) — nothing was written for a2a.

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/dotcms"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/dotcms/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/dotcms/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.