# Contentstack vs Payload > Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/contentstack-vs-payload - Markdown: https://www.anchorterminal.com/compare/contentstack-vs-payload.md (~2,350 tokens) - Slim: https://www.anchorterminal.com/compare/contentstack-vs-payload.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/contentstack-vs-payload.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing. Both do cms content. - Contentstack: grade B, 64/100, rank #288 of 722. Markdown https://www.anchorterminal.com/tools/contentstack.md · JSON https://www.anchorterminal.com/api/v1/tools/contentstack.json - Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json ## Which one, for what ### Contentstack (B) Good for: Teams already on Contentstack, or starting on its free plan, who want an agent to draft, localise, release and publish structured content with scoped credentials and an audit trail. Ahead on: - Schema & documentation, 77 against 70 - Security & auth, 69 against 57 - Transparency & trust, 73 against 62 Also in its favour: - A hosted endpoint, with nothing to install - Runs on your own machine - Free to start without a card Watch for: The MCP server's default group loads 78 tools, including nine deletes, with no readOnlyHint or destructiveHint annotations and no read-only switch ### Payload (C) Good for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core. Ahead on: - Reliability, 78 against 71 - Payments & pricing, 45 against 30 Also in its favour: - Open source Watch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026 ## Score by category | Category | Weight | Contentstack | Payload | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 71 | 78 | Payload +7 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 77 | 70 | Contentstack +7 | | Agent ergonomics | 13% (16.2 this run) | 67 | 64 | Contentstack +3 | | Security & auth | 14% (17.5 this run) | 69 | 57 | Contentstack +12 | | Payments & pricing | 10% (12.5 this run) | 30 | 45 | Payload +15 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 82 | 78 | Contentstack +4 | | Transparency & trust | 7% (8.8 this run) | 73 | 62 | Contentstack +11 | | Negative events | ≤15 | -3 | -10 | | | **Total** | | **64 · B** | **55.2 · C** | | ## Facts side by side | Fact | Contentstack | Payload | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Contentstack Inc. | Payload CMS, Inc. (Figma) | | Hosted endpoint | `https://api.contentstack.io` | no (local only) | | Transports | HTTP, stdio | HTTP, Streamable HTTP | | Auth | OAuth or key | API key | | Pricing | Freemium | Free | | x402 | no | no | | Licence | Proprietary service under Contentstack's Master Agreement and Terms of Service. The OpenAPI files, the management SDKs, the CLI and the @contentstack/mcp package are MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | | Tools exposed | 206 | none | | Read-only variant documented | yes | no | | llms.txt | yes | yes | | Last release | 2026-09-22 | 2026-09-23 | | Terms last updated | 2022-08-01 | no document linked | | Privacy policy last updated | 2026-06-30 | 2024-03-28 | | Customer content may train models | not found in the text | | | Terms restrict automated access | not found in the text | | | Terms restrict benchmarking | yes | | | Terms or service can change without notice | not found in the text | | | Arbitration or class-action waiver | yes | | | Popularity | 44k npm/wk, 1.5k PyPI/wk | 45k stars, 1.1M npm/wk | ## Verdicts **Contentstack.** The Content Management API has a public OpenAPI file, OAuth scopes that separate read, write and publish, read-only management tokens and a stack audit log. A free plan needs no card. The MCP server loads 78 tools by default with no annotations or read-only switch, and the `limit=0` behaviour changed on 11 September 2026 without advance notice. **Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published. ## Before you call either ### Contentstack 1. Pick the base URL for the stack's region first. North America on AWS is https://api.contentstack.io, and the other six regions use contentstack.com hosts 2. Send `api_key` and `authorization` headers on every Content Management API call. Ask for a read-only management token when the task only reads 3. Page with `limit` (100 at most), `skip` and `include_count=true`. `limit=0` no longer returns everything 4. Stay under 10 reads and 10 writes a second per organisation, and one bulk request a second. Watch `X-RateLimit-Remaining` and back off on 429 5. Start the MCP server with `--groups cma` only, and add `cma-extended` when the task needs audit logs or version history. Publishing and deleting need no confirmation ### Payload 1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing 2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate 3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written 4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented 5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them ## Questions ### Which is better for AI agents, Contentstack or Payload? Contentstack scores 64 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on reliability and payments & pricing. ### Do Contentstack and Payload need an API key? Contentstack takes an API key or an OAuth sign-in. Payload needs an API key. ### Can an agent call Contentstack and Payload without installing anything? Contentstack has a hosted endpoint at https://api.contentstack.io. No hosted endpoint is listed for Payload. ### Are Contentstack and Payload open source? No open-source release is listed for Contentstack. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/contentstack-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/contentstack-vs-payload.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "contentstack", "b": "payload"}`. From a terminal: `anchor compare contentstack payload` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/contentstack.json and https://www.anchorterminal.com/api/v1/tools/payload.json ## Other comparisons with Contentstack or Payload - [Contentstack vs DatoCMS](https://www.anchorterminal.com/compare/contentstack-vs-datocms.md) - [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md) - [Contentstack vs Ghost](https://www.anchorterminal.com/compare/contentstack-vs-ghost.md) - [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md) - [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md) - [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md) - [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md) - [Contentstack vs WordPress](https://www.anchorterminal.com/compare/contentstack-vs-wordpress.md) - [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md) - [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md) - [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md) - [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md) - [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md) - [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md) - [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md) - [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)