Head to head · Cms content · October 2026 research run

DatoCMS vs Payload

DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.

Which one, for what

DatoCMS BB

Good for Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment.

Ahead on

  • Schema & documentation, 85 against 70
  • Agent ergonomics, 78 against 64
  • Security & auth, 77 against 57
  • Transparency & trust, 80 against 62

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where Payload loses 10 points for them

Watch for

No idempotency keys in the reviewed documentation. Safe retries rest on optimistic locking and the JavaScript client's automatic retry

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Payments & pricing, 45 against 35

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Score by category

CategoryWeight this runDatoCMSPayloadEdge
Reliability16%208078DatoCMS +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28570DatoCMS +15
Agent ergonomics13%16.27864DatoCMS +14
Security & auth14%17.57757DatoCMS +20
Payments & pricing10%12.53545Payload +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88178DatoCMS +3
Transparency & trust7%8.88062DatoCMS +18
Negative events≤150-10
Total74.4 · BB55.2 · C

Facts side by side

FactDatoCMSPayload
KindHTTP APIHTTP API
VendorDato SrlPayload CMS, Inc. (Figma)
Hosted endpointhttps://site-api.datocms.comno (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary service under Dato Srl's terms of service. The API clients in datocms/js-rest-api-clients and the CLI in datocms/cli are MITMIT for the core and the official packages. Enterprise add-ons are sold separately through sales
Tools exposed9none
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-012026-09-23
Terms last updatedcouldn't be readno document linked
Privacy policy last updatedcouldn't be read2024-03-28
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity153k npm/wk45k stars, 1.1M npm/wk

Verdicts

DatoCMS

The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route.

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Before you call either

DatoCMS

  1. Send X-Api-Version: 3 and Accept: application/json on every request, with Content-Type: application/vnd.api+json on writes
  2. Records are items, models are item_types and assets are uploads in every path and payload
  3. Save a record, then call the publish endpoint as a separate PUT. Send meta.current_version on updates and re-fetch on STALE_ITEM_VERSION
  4. Stay under 60 requests every 3 seconds. On 429 wait the seconds in x-ratelimit-reset, and retry any error whose body has transient set to true
  5. Fork a sandbox environment for schema changes and promote it when checked. Use POST /items/validate to test a payload without saving it

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Questions

Which is better for AI agents, DatoCMS or Payload?

DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments & pricing.

Do DatoCMS and Payload need an API key?

DatoCMS takes an API key or an OAuth sign-in. Payload needs an API key.

Can an agent call DatoCMS and Payload without installing anything?

DatoCMS has a hosted endpoint at https://site-api.datocms.com. No hosted endpoint is listed for Payload.

Are DatoCMS and Payload open source?

No open-source release is listed for DatoCMS. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).

Other comparisons with DatoCMS or Payload

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.