Head to head · Cms content · October 2026 research run
Directus vs Payload
Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Both do cms content.
Which one, for what
Directus B
Good for Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.
Ahead on
- Schema & documentation, 81 against 70
- Agent ergonomics, 73 against 64
- Security & auth, 68 against 57
- Payments & pricing, 55 against 45
- Maintenance & community, 86 against 78
Watch for
Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Also in its favour
- Open source
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Score by category
| Category | Weight this run | Directus | Payload | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 82 | 78 | Directus +4 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 81 | 70 | Directus +11 |
| Agent ergonomics | 13%16.2 | 73 | 64 | Directus +9 |
| Security & auth | 14%17.5 | 68 | 57 | Directus +11 |
| Payments & pricing | 10%12.5 | 55 | 45 | Directus +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 78 | Directus +8 |
| Transparency & trust | 7%8.8 | 61 | 62 | Payload +1 |
| Negative events | ≤15 | -6 | -10 | |
| Total | 67.1 · B | 55.2 · C |
Facts side by side
| Fact | Directus | Payload |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Monospace Inc. (Directus) | Payload CMS, Inc. (Figma) |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. @directus/sdk is MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |
| Tools exposed | 12 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-10-07 | 2026-09-23 |
| Terms last updated | no date given | no document linked |
| Privacy policy last updated | 2026-06-09 | 2024-03-28 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 38k stars, 23k npm/wk | 45k stars, 1.1M npm/wk |
Verdicts
Directus
The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
Before you call either
Directus
- Connect with OAuth or an
Authorization: Bearerheader. Don't put the token in the URL as?access_token=, where it can be logged - Use
/mcp?tool_mode=registrywhen the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total - Read the
schematool before writing. Item payloads are untyped objects, so field names and types come only from the data model - Publish a version with
POST /versions/{id}/promoteover REST. The MCPitemstool refuses system collections such asdirectus_versions - Count translation and junction tables against the 25-collection Core limit before creating collections
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
Questions
Which is better for AI agents, Directus or Payload?
Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories.
Do Directus and Payload need an API key?
Directus takes an API key or an OAuth sign-in. Payload needs an API key.
Can an agent call Directus and Payload without installing anything?
No hosted endpoint is listed for Directus. No hosted endpoint is listed for Payload.
Are Directus and Payload open source?
No open-source release is listed for Directus. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).
Other comparisons with Directus or Payload
- Contentstack vs Directus
- Contentstack vs Payload
- DatoCMS vs Directus
- DatoCMS vs Payload
- Directus vs Ghost
- Directus vs Sanity
- Directus vs Storyblok
- Directus vs Strapi
- Directus vs Webflow
- Directus vs WordPress
- Ghost vs Payload
- Payload vs Sanity
- Payload vs Storyblok
- Payload vs Strapi
- Payload vs Webflow
- Payload vs WordPress
Machine-readable
- This page as Markdown
/compare/directus-vs-payload.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/directus.json·/api/v1/tools/payload.json - From a terminal
anchor compare directus payload(the CLI) - Over MCP
compare_tools {"a": "directus", "b": "payload"}at/mcp, no key