Head to head · Cms content · October 2026 research run
Contentstack vs Payload
Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing. Both do cms content.
Which one, for what
Good for Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.
Ahead on
- Schema & documentation, 77 against 70
- Security & auth, 69 against 57
- Transparency & trust, 73 against 62
Also in its favour
- A hosted endpoint, with nothing to install
- Runs on your own machine
- Free to start without a card
Watch for
The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Ahead on
- Reliability, 78 against 71
- Payments & pricing, 45 against 30
Also in its favour
- Open source
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Score by category
| Category | Weight this run | Contentstack | Payload | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 71 | 78 | Payload +7 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 77 | 70 | Contentstack +7 |
| Agent ergonomics | 13%16.2 | 67 | 64 | Contentstack +3 |
| Security & auth | 14%17.5 | 69 | 57 | Contentstack +12 |
| Payments & pricing | 10%12.5 | 30 | 45 | Payload +15 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 82 | 78 | Contentstack +4 |
| Transparency & trust | 7%8.8 | 73 | 62 | Contentstack +11 |
| Negative events | ≤15 | -3 | -10 | |
| Total | 64 · B | 55.2 · C |
Facts side by side
| Fact | Contentstack | Payload |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Contentstack Inc. | Payload CMS, Inc. (Figma) |
| Hosted endpoint | https://api.contentstack.io | no (local only) |
| Transports | HTTP, stdio | HTTP, Streamable HTTP |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |
| Tools exposed | 206 | none |
| Read-only variant documented | yes | no |
| llms.txt | yes | yes |
| Last release | 2026-09-22 | 2026-09-23 |
| Terms last updated | 2022-08-01 | no document linked |
| Privacy policy last updated | 2026-06-30 | 2024-03-28 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | yes | |
| Popularity | 44k npm/wk, 1.5k PyPI/wk | 45k stars, 1.1M npm/wk |
Verdicts
Contentstack
The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the limit=0 behaviour changed on 11 September 2026 without advance notice.
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
Before you call either
Contentstack
- Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts
- Send
api_keyandauthorizationheaders on every Content Management API call. Ask for a read-only management token when the task only reads - Page with
limit(100 at most),skipandinclude_count=true.limit=0no longer returns everything - Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch
X-RateLimit-Remainingand back off on 429 - Start the MCP server with
--groups cmaonly, and addcma-extendedwhen the task needs audit logs or version history. Publishing and deleting need no confirmation
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
Questions
Which is better for AI agents, Contentstack or Payload?
Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing.
Do Contentstack and Payload need an API key?
Contentstack takes an API key or an OAuth sign-in. Payload needs an API key.
Can an agent call Contentstack and Payload without installing anything?
Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Payload.
Are Contentstack and Payload open source?
No open-source release is listed for Contentstack. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).
Other comparisons with Contentstack or Payload
- Contentstack vs DatoCMS
- Contentstack vs Directus
- Contentstack vs Ghost
- Contentstack vs Sanity
- Contentstack vs Storyblok
- Contentstack vs Strapi
- Contentstack vs Webflow
- Contentstack vs WordPress
- DatoCMS vs Payload
- Directus vs Payload
- Ghost vs Payload
- Payload vs Sanity
- Payload vs Storyblok
- Payload vs Strapi
- Payload vs Webflow
- Payload vs WordPress
Machine-readable
- This page as Markdown
/compare/contentstack-vs-payload.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/contentstack.json·/api/v1/tools/payload.json - From a terminal
anchor compare contentstack payload(the CLI) - Over MCP
compare_tools {"a": "contentstack", "b": "payload"}at/mcp, no key