Head to head · Cms content · October 2026 research run

Contentstack vs Payload

Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing. Both do cms content.

Which one, for what

Contentstack B

Good for Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.

Ahead on

  • Schema & documentation, 77 against 70
  • Security & auth, 69 against 57
  • Transparency & trust, 73 against 62

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card

Watch for

The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Reliability, 78 against 71
  • Payments & pricing, 45 against 30

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Score by category

CategoryWeight this runContentstackPayloadEdge
Reliability16%207178Payload +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27770Contentstack +7
Agent ergonomics13%16.26764Contentstack +3
Security & auth14%17.56957Contentstack +12
Payments & pricing10%12.53045Payload +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88278Contentstack +4
Transparency & trust7%8.87362Contentstack +11
Negative events≤15-3-10
Total64 · B55.2 · C

Facts side by side

FactContentstackPayload
KindHTTP APIHTTP API
VendorContentstack Inc.Payload CMS, Inc. (Figma)
Hosted endpointhttps://api.contentstack.iono (local only)
TransportsHTTP, stdioHTTP, Streamable HTTP
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MITMIT for the core and the official packages. Enterprise add-ons are sold separately through sales
Tools exposed206none
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-222026-09-23
Terms last updated2022-08-01no document linked
Privacy policy last updated2026-06-302024-03-28
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity44k npm/wk, 1.5k PyPI/wk45k stars, 1.1M npm/wk

Verdicts

Contentstack

The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the limit=0 behaviour changed on 11 September 2026 without advance notice.

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Before you call either

Contentstack

  1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts
  2. Send api_key and authorization headers on every Content Management API call. Ask for a read-only management token when the task only reads
  3. Page with limit (100 at most), skip and include_count=true. limit=0 no longer returns everything
  4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch X-RateLimit-Remaining and back off on 429
  5. Start the MCP server with --groups cma only, and add cma-extended when the task needs audit logs or version history. Publishing and deleting need no confirmation

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Questions

Which is better for AI agents, Contentstack or Payload?

Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing.

Do Contentstack and Payload need an API key?

Contentstack takes an API key or an OAuth sign-in. Payload needs an API key.

Can an agent call Contentstack and Payload without installing anything?

Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Payload.

Are Contentstack and Payload open source?

No open-source release is listed for Contentstack. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).

Other comparisons with Contentstack or Payload

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.