{
  "data": {
    "a": {
      "slug": "contentstack",
      "name": "Contentstack",
      "vendor": "Contentstack Inc.",
      "vendorUrl": "https://www.contentstack.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Contentstack is a hosted headless CMS. Its Content Management API reads and writes entries, assets, content types, locales, releases and publishing across seven regional endpoints, and an official local MCP server wraps the same API for agents.",
      "url": "https://www.anchorterminal.com/tools/contentstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/contentstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/contentstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/contentstack.json",
      "repo": "https://github.com/contentstack/contentstack-openapi",
      "license": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.contentstack.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@contentstack/mcp"
        },
        {
          "registry": "npm",
          "name": "@contentstack/management"
        },
        {
          "registry": "pypi",
          "name": "contentstack-management"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Sign up, create a stack, then create a management token in the stack's settings (stack Owner or Admin only) and send it in the `authorization` header with the stack's `api_key`. Management tokens can be read-only or read-write, limited to branches, and given an expiry date. OAuth 2.0 apps are created in Developer Hub, with authorisation code and client credentials grants, scopes per module and action, 60-minute tokens and a refresh grant. A user authtoken from the login endpoint also works. The MCP server uses OAuth through `npx @contentstack/mcp --auth`, or a management token for content tools.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 a month with no card and no expiry (one stack, three users, 100,000 API calls a month, 1,000 entries), so an agent's owner can start without a contract. Build is $29 a month and Growth $299 a month with extra users at $25 each. Enterprise is priced by quote. Build mentions pay-as-you-go overages, and no overage rate is shown on the pricing page (https://www.contentstack.com/pricing, checked 2026-10-07).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP package or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 206,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 43992,
        "pypiWeekly": 1504,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.contentstack.com/docs/developers/apis/content-management-api",
      "llmsTxt": "https://www.contentstack.com/llms.txt",
      "openapi": "https://github.com/contentstack/contentstack-openapi",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "hosted",
        "official",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "free-tier",
        "no-card",
        "closed-source",
        "webhooks",
        "typescript",
        "python",
        "java",
        "dotnet",
        "status-page",
        "soc2",
        "sla"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64,
        "grade": "B",
        "agentReady": false,
        "rank": 288,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "11 September 2026. The `limit` query parameter on delivery and management requests changed behaviour inside v3. `limit=0` used to return every matching record and now returns the default 100, so an integration relying on it gets a truncated result with a 200 status. The changelog entry is dated the same day and gives a migration path, and no earlier notice was found in the changelog feed. Deducted 3, the low end, because it was documented (https://www.contentstack.com/docs/changelog)."
        ],
        "verdict": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
        "bestFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "strengths": [
          "OAuth 2.0 scopes separate read, write, publish and unpublish for entries and assets, with 60-minute tokens and a refresh grant",
          "Management tokens can be read-only, limited to named branches, given an expiry date and given their own per-second rate limits",
          "Free plan at $0 with no card and no expiry (one stack, three users, 100,000 API calls a month), launched 16 September 2026",
          "Public OpenAPI 3.0.0 file for the Content Management API (138 paths, 221 operations) and public JSON Schema for all 206 MCP tools at mcp.contentstack.com",
          "Stack audit log readable through /v3/audit-logs, and entry and asset version history through the API",
          "Uptime commitment of 99.50 or 99.95 per cent by plan, with service credits, published in the Services Description"
        ],
        "weaknesses": [
          "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch",
          "On 11 September 2026 `limit=0` stopped returning every record and now returns the default 100. The changelog entry is dated the same day",
          "The OpenAPI file documents only 200 responses and has no enums or component schemas. Request bodies are shown as examples",
          "No idempotency keys and no Retry-After header were found. The docs name only X-RateLimit-Limit and X-RateLimit-Remaining",
          "No security.txt and no bug bounty were found, and no deprecation policy with a notice period",
          "Nine incidents with customer impact on status.contentstack.com between 9 July and 7 October 2026, each in one or two regions"
        ],
        "agentNotes": [
          "Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts",
          "Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads",
          "Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything",
          "Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429",
          "Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 82,
          "payments": 30,
          "reliability": 71,
          "schema": 77,
          "security": 69,
          "transparency": 59
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npx -y @contentstack/mcp",
        "http": "curl \"https://api.contentstack.io/v3/content_types\" \\\n  -H \"api_key: $CONTENTSTACK_API_KEY\" -H \"authorization: $CONTENTSTACK_MANAGEMENT_TOKEN\"",
        "config": {
          "mcpServers": {
            "contentstack": {
              "args": [
                "-y",
                "@contentstack/mcp"
              ],
              "command": "npx",
              "env": {
                "CONTENTSTACK_API_KEY": "\u003cYOUR_STACK_API_KEY\u003e",
                "GROUPS": "cma"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/contentstack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Build",
          "unit": "month",
          "usd": 29,
          "note": "3 users, 250,000 API calls a month"
        },
        {
          "item": "Growth",
          "unit": "month",
          "usd": 299,
          "note": "10 users, 1M API calls a month"
        },
        {
          "item": "Growth, each extra user",
          "unit": "seat-month",
          "usd": 25,
          "note": "beyond the 10 included"
        }
      ],
      "provenance": {
        "legalEntity": "Contentstack Inc.",
        "domain": "contentstack.com",
        "domainRegistered": "2011-10-29",
        "domainNote": "The AWS North America API is on api.contentstack.io. The other six regions and the MCP tool definitions are on contentstack.com hosts.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.contentstack.com/legal/terms-of-service",
        "privacy": "https://www.contentstack.com/legal/privacy",
        "statusPage": "https://status.contentstack.com",
        "changelog": "https://www.contentstack.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Agreement (last updated 17 July 2026) names Contentstack Inc., a Delaware corporation at 1023 Springdale Rd., Bldg. 14A, Austin, TX 78721. The privacy policy is dated 30 June 2026.",
          "The online Terms of Service carry an effective date of August 2022. Paid subscriptions are governed by the Master Agreement and the Services Description (last updated 28 July 2026).",
          "www.contentstack.com/.well-known/security.txt and /security.txt both return 404. SECURITY.md in Contentstack's GitHub repositories sends reports to security@contentstack.com.",
          "RDAP for contentstack.com gives a registration date of 2011-10-29.",
          "The npm package @contentstack/mcp names github.com/contentstack/mcp as its repository. That repository asked for credentials when we tried to clone it, so it isn't public."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/contentstack.json",
      "live": {
        "slug": "contentstack",
        "probe": {
          "target": "https://api.contentstack.io",
          "method": "get",
          "lastAt": "2026-10-08T21:12:08.044941607Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 535,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 540,
          "p95ms24h": 611,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.contentstack.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:57.5636666Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@contentstack/management",
            "version": "1.31.2",
            "seenAt": "2026-10-08T16:06:51.377892172Z"
          },
          {
            "registry": "npm",
            "name": "@contentstack/mcp",
            "version": "0.9.0",
            "seenAt": "2026-10-08T16:06:47.529272792Z"
          },
          {
            "registry": "pypi",
            "name": "contentstack-management",
            "version": "1.11.2",
            "released": "2026-08-12",
            "seenAt": "2026-10-08T16:06:51.588548545Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 380,
        "pypiWeekly": 1518,
        "securityTxt": {
          "url": "https://contentstack.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:44.745635489Z"
        },
        "pages": [
          {
            "url": "https://www.contentstack.com/docs/changelog",
            "kind": "changelog",
            "status": 404,
            "checkedAt": "2026-10-08T18:27:09.968657878Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.contentstack.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:17.384677543Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5dd89e546041"
          },
          {
            "url": "https://www.contentstack.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:12.602685857Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "999e1b8c6308"
          },
          {
            "url": "https://www.contentstack.com/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:16.022719984Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9cc98c875af"
          }
        ],
        "updatedAt": "2026-10-08T21:12:08.044941607Z"
      }
    },
    "answer": "Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing.",
    "b": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentstack Inc.",
        "b": "Payload CMS, Inc. (Figma)",
        "name": "Vendor"
      },
      {
        "a": "https://api.contentstack.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT",
        "b": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "name": "Licence"
      },
      {
        "a": "206",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "2022-08-01",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-30",
        "b": "2024-03-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "44k npm/wk, 1.5k PyPI/wk",
        "b": "45k stars, 1.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Contentstack or Payload?"
      },
      {
        "answer": "Contentstack takes an API key or an OAuth sign-in. Payload needs an API key.",
        "question": "Do Contentstack and Payload need an API key?"
      },
      {
        "answer": "Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Payload.",
        "question": "Can an agent call Contentstack and Payload without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Contentstack. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).",
        "question": "Are Contentstack and Payload open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 77 against 70",
          "Security \u0026 auth, 69 against 57",
          "Transparency \u0026 trust, 73 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.",
        "slug": "contentstack",
        "watchFor": "The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch"
      },
      {
        "aheadOn": [
          "Reliability, 78 against 71",
          "Payments \u0026 pricing, 45 against 30"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-datocms.json",
        "title": "Contentstack vs DatoCMS",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-datocms"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
        "title": "Contentstack vs Directus",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-ghost.json",
        "title": "Contentstack vs Ghost",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress.json",
        "title": "Contentstack vs WordPress",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 7,
        "contentstack": 71,
        "edge": "payload",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "contentstack": 77,
        "edge": "contentstack",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13
      },
      {
        "by": 3,
        "contentstack": 67,
        "edge": "contentstack",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13
      },
      {
        "by": 12,
        "contentstack": 69,
        "edge": "contentstack",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14
      },
      {
        "by": 15,
        "contentstack": 30,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "contentstack": 82,
        "edge": "contentstack",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7
      },
      {
        "by": 11,
        "contentstack": 73,
        "edge": "contentstack",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7
      }
    ],
    "summary": "Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "contentstack": "The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.",
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/contentstack-vs-payload",
    "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/contentstack-vs-payload.md",
    "slim": "https://www.anchorterminal.com/compare/contentstack-vs-payload.min.md"
  },
  "markdown": "Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing. Both do cms content.\n\n- Contentstack: grade B, 64/100, rank #288 of 722. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Which one, for what\n\n### Contentstack (B)\n\nGood for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail.\n\nAhead on:\n- Schema \u0026 documentation, 77 against 70\n- Security \u0026 auth, 69 against 57\n- Transparency \u0026 trust, 73 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Reliability, 78 against 71\n- Payments \u0026 pricing, 45 against 30\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n\n## Score by category\n\n| Category | Weight | Contentstack | Payload | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 78 | Payload +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 70 | Contentstack +7 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 64 | Contentstack +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 57 | Contentstack +12 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 45 | Payload +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 78 | Contentstack +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 62 | Contentstack +11 |\n| Negative events | ≤15 | -3 | -10 | |\n| **Total** | | **64 · B** | **55.2 · C** | |\n\n## Facts side by side\n\n| Fact | Contentstack | Payload |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentstack Inc. | Payload CMS, Inc. (Figma) |\n| Hosted endpoint | `https://api.contentstack.io` | no (local only) |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |\n| Tools exposed | 206 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-09-23 |\n| Terms last updated | 2022-08-01 | no document linked |\n| Privacy policy last updated | 2026-06-30 | 2024-03-28 |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 44k npm/wk, 1.5k PyPI/wk | 45k stars, 1.1M npm/wk |\n\n## Verdicts\n\n**Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice.\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n## Before you call either\n\n### Contentstack\n\n1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts\n2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads\n3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything\n4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429\n5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n## Questions\n\n### Which is better for AI agents, Contentstack or Payload?\n\nContentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing.\n\n### Do Contentstack and Payload need an API key?\n\nContentstack takes an API key or an OAuth sign-in. Payload needs an API key.\n\n### Can an agent call Contentstack and Payload without installing anything?\n\nContentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Payload.\n\n### Are Contentstack and Payload open source?\n\nNo open-source release is listed for Contentstack. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-payload.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"contentstack\", \"b\": \"payload\"}`. From a terminal: `anchor compare contentstack payload`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Other comparisons with Contentstack or Payload\n\n- [Contentstack vs DatoCMS](https://www.anchorterminal.com/compare/contentstack-vs-datocms.md)\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md)\n- [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md)\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Contentstack vs Payload",
        "url": ""
      }
    ],
    "description": "Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Contentstack B 64",
      "Payload C 55.2",
      "scores"
    ],
    "h1": "Contentstack vs Payload",
    "image": "https://www.anchorterminal.com/assets/og/compare-contentstack-vs-payload.png",
    "path": "/compare/contentstack-vs-payload",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Contentstack vs Payload for AI agents, B 64 vs C 55.2",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 780
  },
  "version": 1
}
