Projects, datasets, schemas, GROQ queries, documents, drafts and versions, releases, generated or transformed images, and Studio or schema deployments.
Sanity
Included because its hosted MCP gives agents schema-aware access to structured content, GROQ queries, releases, datasets, schema deployment, and media operations under Sanity roles and revision history.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
Inspect project and schema context, execute GROQ, query documents, list datasets and releases, and search Sanity documentation with the authenticated actor's scope.
Create, patch, publish, unpublish, and delete documents; create projects and manage datasets; create, schedule, and publish releases; deploy schemas; and generate or transform images.
The hosted server uses OAuth by default or a bearer API token. Calls inherit the OAuth user's permissions or the token's role and scopes; a personal token also attributes changes in revision history.
Use a named user or narrowly scoped token so revisions remain attributable; limit project and dataset access through Sanity roles, and disable credit-consuming image or version-generation tools in the client when they are not needed.
OAuth sessions typically expire after seven days, available tools can change as the hosted service updates, and image generation, image transformation, and instructed version creation can consume AI credits.
First-party access
Documented surfaces
Agent access
MCP support
Support: Official MCP server
Read scope: Operational server reads schemas/project context, runs GROQ, creates and patches documents, generates images, manages datasets and releases, deploys schemas and Studio; Sanity Context supplies schema-aware read-only dataset access
Write scope: The operational Sanity MCP can deploy schemas and Studio, create/patch/publish/unpublish content, discard drafts/versions, create projects and datasets, update dataset access, and manage releases subject to OAuth or token role permissions. Sanity Context remains a distinct read-only surface.
Authentication: Hosted OAuth is the default. A client can instead send an Authorization bearer token, in which case OAuth is not used.
Approval boundary: Require a preview and explicit confirmation before publish, unpublish, permanent document deletion, release publication, dataset-access changes, or schema and Studio deployment.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Sanity ships them.
Single-platform patterns
- Structured content production and governance studio
- Campaign asset assembly room
- Brief-to-experience studio
- Content approval queue
Multi-platform compositions
- Sanity + CRM or campaign platform: campaign asset assembly room
- Sanity + work-management system + analytics or distribution platform: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
6 recorded sources
Official Sanity documentation confirms hosted OAuth or token authentication, active GA releases and MCP App widgets. Distinguish the broad operational server from Sanity Context, which is intentionally read-only and…
- Publisher updated
- Jun 24, 2026
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- Apr 15, 2026
- BYO-UI reviewed
- Jul 12, 2026
Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.
First-party developer documentation or platform overview.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Reverified the named access facet exactly as bounded by the reviewed first-party record.
- Publisher published
- Apr 15, 2026
- BYO-UI reviewed
- Jul 12, 2026
Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party webhook, event, SDK, embedded-app, or extension documentation.
- Publisher updated
- Apr 29, 2026
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.