{
  "data": {
    "a": {
      "slug": "datocms",
      "name": "DatoCMS",
      "vendor": "Dato Srl",
      "vendorUrl": "https://www.datocms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "DatoCMS is a hosted headless CMS from Dato Srl in Milan. Agents write records, assets, locales and schema through the REST Content Management API, the `datocms` CLI or a hosted MCP server, and read through a GraphQL Content Delivery API.",
      "url": "https://www.anchorterminal.com/tools/datocms",
      "markdownUrl": "https://www.anchorterminal.com/tools/datocms.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/datocms.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/datocms.json",
      "repo": "https://github.com/datocms/js-rest-api-clients",
      "license": "Proprietary service under Dato Srl's terms of service. The API clients in datocms/js-rest-api-clients and the CLI in datocms/cli are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://site-api.datocms.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@datocms/cma-client-node"
        },
        {
          "registry": "npm",
          "name": "@datocms/cma-client"
        },
        {
          "registry": "npm",
          "name": "datocms"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content Management API takes an API token as a Bearer header. A person creates the token in the project's settings and binds it to a role, which limits it by model, action and environment. Every project starts with a read-only token, and tokens can be rotated by API. The hosted MCP server uses browser OAuth through oauth.datocms.com with PKCE and dynamic client registration, where the person picks projects and one of three access levels. Accounts on single sign-on can't use the MCP server. No app review or sales approval is needed.",
      "pricing": "freemium",
      "pricingNotes": "The Free plan needs no card and includes 25,000 Content Management API calls a month, 300 records and three sandbox environments, with no overage. Professional is €199 a month, or €149 a month billed yearly, with 100,000 management API calls and €9 per extra 100,000. Enterprise is sold through sales. Prices are in euros only (https://www.datocms.com/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Content Management API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 152666,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.datocms.com/docs/content-management-api",
      "llmsTxt": "https://www.datocms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "cli",
        "graphql",
        "status-page",
        "iso27001"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 62,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 81,
          "payments": 35,
          "reliability": 80,
          "schema": 85,
          "security": 77,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route.",
        "bestFor": "Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment.",
        "strengths": [
          "Machine-readable JSON Hyper-Schema at `https://site-api.datocms.com/docs/site-api-hyperschema.json` covering 53 resources and 202 operations, with 656 examples",
          "Error bodies carry one of 100 documented codes, a `doc_url` and a `transient` flag, and 429 responses carry `x-ratelimit-reset`",
          "API tokens bind to custom roles by model, action and environment, and every project starts with a read-only token",
          "Hosted MCP server with OAuth (PKCE, dynamic client registration, revocation), per-project selection and a read-only level enforced at the network layer",
          "Free plan with no card, 25,000 Content Management API calls a month and three sandbox environments for testing changes away from the primary"
        ],
        "weaknesses": [
          "No idempotency keys in the reviewed documentation. Safe retries rest on optimistic locking and the JavaScript client's automatic retry",
          "The only official client library is JavaScript and TypeScript. No Python, Go, PHP or Ruby client appears in the documentation index",
          "Audit logs are an Enterprise feature with a default retention of two months",
          "A database upgrade on 19 September 2026 put every project in read-only mode for about four hours, over an hour past its announced window",
          "The terms let Dato Srl modify or discontinue API access with or without notice, and free projects are suspended for the rest of the month at a quota limit"
        ],
        "agentNotes": [
          "Send `X-Api-Version: 3` and `Accept: application/json` on every request, with `Content-Type: application/vnd.api+json` on writes",
          "Records are `items`, models are `item_types` and assets are `uploads` in every path and payload",
          "Save a record, then call the publish endpoint as a separate PUT. Send `meta.current_version` on updates and re-fetch on `STALE_ITEM_VERSION`",
          "Stay under 60 requests every 3 seconds. On 429 wait the seconds in `x-ratelimit-reset`, and retry any error whose body has `transient` set to true",
          "Fork a sandbox environment for schema changes and promote it when checked. Use `POST /items/validate` to test a payload without saving it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 81,
          "payments": 35,
          "reliability": 80,
          "schema": 85,
          "security": 77,
          "transparency": 65
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm install @datocms/cma-client-node",
        "http": "curl \\\n  -H 'Authorization: Bearer \u003cYOUR-API-TOKEN\u003e' \\\n  -H 'Accept: application/json' \\\n  -H 'X-Api-Version: 3' \\\n  https://site-api.datocms.com/site",
        "claudeCode": "claude mcp add --transport http DatoCMS https://mcp.datocms.com",
        "config": {
          "mcpServers": {
            "DatoCMS": {
              "type": "http",
              "url": "https://mcp.datocms.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/datocms"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Dato Srl",
        "domain": "datocms.com",
        "domainRegistered": "2016-03-18",
        "endpointOnVendorDomain": true,
        "terms": "https://www.datocms.com/legal/terms",
        "privacy": "https://www.datocms.com/legal/privacy-policy",
        "statusPage": "https://status.datocms.com",
        "changelog": "https://www.datocms.com/product-updates",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service and the privacy policy name DATO SRL, Via U. Visconti di Modrone 2, 20122 Milano, Italy. The terms cover every plan except Enterprise, which has a separate agreement we did not find published.",
          "The Content Management API answers at site-api.datocms.com, the MCP server at mcp.datocms.com and the OAuth server at oauth.datocms.com.",
          "www.datocms.com/.well-known/security.txt gives security@datocms.com, a PGP key and the security policy page, and has no Expires field.",
          "The privacy policy carries no revision date in the Markdown copy we read. The GDPR page was last updated on 3 June 2026 and the security page on 2 September 2025.",
          "RDAP for datocms.com gives a registration date of 2016-03-18.",
          "The status page is the vendor's own, with a static mirror at status2.datocms.com and RSS, Atom and JSON history feeds. No data processing agreement was found on the legal pages."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/datocms.json",
      "live": {
        "slug": "datocms",
        "probe": {
          "target": "https://site-api.datocms.com",
          "method": "get",
          "lastAt": "2026-10-09T01:12:44.33466529Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 60,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 60,
          "p95ms24h": 96,
          "samples24h": 63,
          "samples30d": 63,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 13,
              "ok": 13
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.datocms.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:25.080597068Z"
        },
        "updatedAt": "2026-10-09T01:12:44.33466529Z"
      }
    },
    "answer": "DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Dato Srl",
        "b": "Payload CMS, Inc. (Figma)",
        "name": "Vendor"
      },
      {
        "a": "https://site-api.datocms.com",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Dato Srl's terms of service. The API clients in datocms/js-rest-api-clients and the CLI in datocms/cli are MIT",
        "b": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "name": "Licence"
      },
      {
        "a": "9",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2024-03-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "153k npm/wk",
        "b": "45k stars, 1.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, DatoCMS or Payload?"
      },
      {
        "answer": "DatoCMS takes an API key or an OAuth sign-in. Payload needs an API key.",
        "question": "Do DatoCMS and Payload need an API key?"
      },
      {
        "answer": "DatoCMS has a hosted endpoint at https://site-api.datocms.com. No hosted endpoint is listed for Payload.",
        "question": "Can an agent call DatoCMS and Payload without installing anything?"
      },
      {
        "answer": "No open-source release is listed for DatoCMS. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).",
        "question": "Are DatoCMS and Payload open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 85 against 70",
          "Agent ergonomics, 78 against 64",
          "Security \u0026 auth, 77 against 57",
          "Transparency \u0026 trust, 80 against 62"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Payload loses 10 points for them"
        ],
        "goodFor": "Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment.",
        "slug": "datocms",
        "watchFor": "No idempotency keys in the reviewed documentation. Safe retries rest on optimistic locking and the JavaScript client's automatic retry"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 35"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-datocms.json",
        "title": "Contentstack vs DatoCMS",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-datocms"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-ghost.json",
        "title": "DatoCMS vs Ghost",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-sanity.json",
        "title": "DatoCMS vs Sanity",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-storyblok.json",
        "title": "DatoCMS vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-strapi.json",
        "title": "DatoCMS vs Strapi",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-webflow.json",
        "title": "DatoCMS vs Webflow",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-wordpress.json",
        "title": "DatoCMS vs WordPress",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 2,
        "datocms": 80,
        "edge": "datocms",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "datocms": 85,
        "edge": "datocms",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13
      },
      {
        "by": 14,
        "datocms": 78,
        "edge": "datocms",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13
      },
      {
        "by": 20,
        "datocms": 77,
        "edge": "datocms",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14
      },
      {
        "by": 10,
        "datocms": 35,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "datocms": 81,
        "edge": "datocms",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7
      },
      {
        "by": 18,
        "datocms": 80,
        "edge": "datocms",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7
      }
    ],
    "summary": "DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "datocms": "The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route.",
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/datocms-vs-payload",
    "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/datocms-vs-payload.md",
    "slim": "https://www.anchorterminal.com/compare/datocms-vs-payload.min.md"
  },
  "markdown": "DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.\n\n- DatoCMS: grade BB, 74.4/100, rank #62 of 722. Markdown https://www.anchorterminal.com/tools/datocms.md · JSON https://www.anchorterminal.com/api/v1/tools/datocms.json\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Which one, for what\n\n### DatoCMS (BB)\n\nGood for: Teams on DatoCMS who want an agent to create, translate and publish records, upload assets or change models, testing first in a sandbox environment.\n\nAhead on:\n- Schema \u0026 documentation, 85 against 70\n- Agent ergonomics, 78 against 64\n- Security \u0026 auth, 77 against 57\n- Transparency \u0026 trust, 80 against 62\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Payload loses 10 points for them\n\nWatch for: No idempotency keys in the reviewed documentation. Safe retries rest on optimistic locking and the JavaScript client's automatic retry\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 35\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n\n## Score by category\n\n| Category | Weight | DatoCMS | Payload | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 78 | DatoCMS +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 70 | DatoCMS +15 |\n| Agent ergonomics | 13% (16.2 this run) | 78 | 64 | DatoCMS +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 77 | 57 | DatoCMS +20 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 45 | Payload +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 78 | DatoCMS +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 62 | DatoCMS +18 |\n| Negative events | ≤15 | 0 | -10 | |\n| **Total** | | **74.4 · BB** | **55.2 · C** | |\n\n## Facts side by side\n\n| Fact | DatoCMS | Payload |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Dato Srl | Payload CMS, Inc. (Figma) |\n| Hosted endpoint | `https://site-api.datocms.com` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Dato Srl's terms of service. The API clients in datocms/js-rest-api-clients and the CLI in datocms/cli are MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |\n| Tools exposed | 9 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-01 | 2026-09-23 |\n| Terms last updated | couldn't be read | no document linked |\n| Privacy policy last updated | couldn't be read | 2024-03-28 |\n| Customer content may train models | couldn't be read |  |\n| Terms restrict automated access | couldn't be read |  |\n| Terms restrict benchmarking | couldn't be read |  |\n| Terms or service can change without notice | couldn't be read |  |\n| Arbitration or class-action waiver | couldn't be read |  |\n| Popularity | 153k npm/wk | 45k stars, 1.1M npm/wk |\n\n## Verdicts\n\n**DatoCMS.** The Content Management API publishes a JSON Hyper-Schema for 202 operations, 100 documented error codes and rate-limit headers, and the hosted MCP server adds OAuth with three access levels. There are no idempotency keys, the only official client library is JavaScript, audit logs are Enterprise only, and prices are in euros with no machine payment route.\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n## Before you call either\n\n### DatoCMS\n\n1. Send `X-Api-Version: 3` and `Accept: application/json` on every request, with `Content-Type: application/vnd.api+json` on writes\n2. Records are `items`, models are `item_types` and assets are `uploads` in every path and payload\n3. Save a record, then call the publish endpoint as a separate PUT. Send `meta.current_version` on updates and re-fetch on `STALE_ITEM_VERSION`\n4. Stay under 60 requests every 3 seconds. On 429 wait the seconds in `x-ratelimit-reset`, and retry any error whose body has `transient` set to true\n5. Fork a sandbox environment for schema changes and promote it when checked. Use `POST /items/validate` to test a payload without saving it\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n## Questions\n\n### Which is better for AI agents, DatoCMS or Payload?\n\nDatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do DatoCMS and Payload need an API key?\n\nDatoCMS takes an API key or an OAuth sign-in. Payload needs an API key.\n\n### Can an agent call DatoCMS and Payload without installing anything?\n\nDatoCMS has a hosted endpoint at https://site-api.datocms.com. No hosted endpoint is listed for Payload.\n\n### Are DatoCMS and Payload open source?\n\nNo open-source release is listed for DatoCMS. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/datocms-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/datocms-vs-payload.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"datocms\", \"b\": \"payload\"}`. From a terminal: `anchor compare datocms payload`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/datocms.json and https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Other comparisons with DatoCMS or Payload\n\n- [Contentstack vs DatoCMS](https://www.anchorterminal.com/compare/contentstack-vs-datocms.md)\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [DatoCMS vs Ghost](https://www.anchorterminal.com/compare/datocms-vs-ghost.md)\n- [DatoCMS vs Sanity](https://www.anchorterminal.com/compare/datocms-vs-sanity.md)\n- [DatoCMS vs Storyblok](https://www.anchorterminal.com/compare/datocms-vs-storyblok.md)\n- [DatoCMS vs Strapi](https://www.anchorterminal.com/compare/datocms-vs-strapi.md)\n- [DatoCMS vs Webflow](https://www.anchorterminal.com/compare/datocms-vs-webflow.md)\n- [DatoCMS vs WordPress](https://www.anchorterminal.com/compare/datocms-vs-wordpress.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "DatoCMS vs Payload",
        "url": ""
      }
    ],
    "description": "DatoCMS scores 74.4 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "DatoCMS BB 74.4",
      "Payload C 55.2",
      "scores"
    ],
    "h1": "DatoCMS vs Payload",
    "image": "https://www.anchorterminal.com/assets/og/compare-datocms-vs-payload.png",
    "path": "/compare/datocms-vs-payload",
    "published": "2026-10-01",
    "section": "tools",
    "title": "DatoCMS vs Payload for AI agents, BB 74.4 vs C 55.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
