{
  "data": {
    "a": {
      "slug": "directus",
      "name": "Directus",
      "vendor": "Monospace Inc. (Directus)",
      "vendorUrl": "https://directus.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Directus is a source-available headless CMS and data platform that runs on an SQL database, self-hosted or on a paid cloud. Agents manage items, files and the data model through REST, GraphQL and a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/directus",
      "markdownUrl": "https://www.anchorterminal.com/tools/directus.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/directus.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/directus.json",
      "repo": "https://github.com/directus/directus",
      "license": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "directus"
        },
        {
          "registry": "npm",
          "name": "@directus/sdk"
        },
        {
          "registry": "npm",
          "name": "@directus/specs"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve on your own instance, with no app review or partner approval. The MCP server at `/mcp` accepts OAuth (PKCE, with dynamic client registration or client ID metadata documents, both off by default) and issues a token with the `mcp:access` scope that works only on the MCP endpoint. REST, GraphQL and MCP also accept a static token, one per user, which doesn't expire and is sent as `Authorization: Bearer` or as `?access_token=` in the URL. Log-in tokens are short-lived with a refresh token. Every credential acts with its user's access policies, down to collection, action, field and item rule.",
      "pricing": "freemium",
      "pricingNotes": "The Core tier is free to self-host with 3 Studio seats, 25 collections and 5 flows, with no card, account or contract, so an agent can start at once. Team is $499 a month on an annual term or $599 monthly, Enterprise is priced by sales, and Directus Cloud hosting is a $99 a month add-on with a 14-day trial. The Open Innovation Grant lifts the limits for organisations under $5M revenue and 50 employees (checked 2026-10-08).",
      "priceSummary": "$499 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page or the repository's MCP source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 12,
      "popularity": {
        "githubStars": 38295,
        "npmWeekly": 22588,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://directus.com/docs",
      "llmsTxt": "https://directus.com/docs/llms.txt",
      "openapi": "https://github.com/directus/directus/blob/main/packages/specs/src/openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.schema",
        "cms.assets",
        "cms.publish",
        "cms.localisation"
      ],
      "tags": [
        "source-available",
        "self-hosted",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "graphql",
        "typescript",
        "sql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.1,
        "grade": "B",
        "agentReady": false,
        "rank": 217,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "5 August 2026. Directus published GHSA-97xr-jchp-xm3c (critical, CVSS 9.2, no CVE). On versions before 12.1.0, a public WebSocket client could read, create, update or delete items in user collections after a failed authentication message. At least 20 advisories were published between 24 June and 2 September 2026, at least 11 rated high, among them SQL injection through geometry fields (GHSA-chfm-g7r3-vv42) and a TUS upload authorisation bypass (GHSA-xjxq-pj7h-g676). The critical fix shipped in 12.1.0 on 1 July, before publication, the vendor published every advisory itself, and none mentions exploitation, so we deduct 6 of a possible 15. https://github.com/directus/directus/security/advisories/GHSA-97xr-jchp-xm3c ; https://github.com/directus/directus/security/advisories"
        ],
        "verdict": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
        "bestFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "strengths": [
          "MCP OAuth with PKCE issues tokens with the `mcp:access` scope and the MCP endpoint as audience, and administrators can revoke registered clients",
          "Deletes through MCP are refused unless the Allow Deletes setting is on, and the MCP server itself is off by default",
          "Registry mode at `/mcp?tool_mode=registry` cuts the tool list to `search`, `execute` and `schema`",
          "Content versioning has REST endpoints to save, compare and promote a version, and revisions record each change",
          "Six tagged releases between 29 July and 7 October 2026, with breaking changes listed per version in the docs"
        ],
        "weaknesses": [
          "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period",
          "The licence is MSCL-1.0-GPL, source-available and not OSI approved, with a ban on competing use and on bypassing the licence key",
          "Static tokens never expire, are stored in plain text in `directus_users`, and the MCP guide shows them in the URL as `?access_token=`",
          "Releases don't follow semantic versioning, and 12.1 to 12.5 each carried breaking changes",
          "At least 20 security advisories were published between June and September 2026, one rated critical and at least 11 rated high"
        ],
        "agentNotes": [
          "Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged",
          "Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total",
          "Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model",
          "Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`",
          "Count translation and junction tables against the 25-collection Core limit before creating collections"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 55,
          "reliability": 82,
          "schema": 81,
          "security": 68,
          "transparency": 55
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install @directus/sdk",
        "claudeCode": "claude mcp add --transport http directus https://your-directus-url.com/mcp",
        "config": {
          "mcpServers": {
            "directus": {
              "headers": {
                "Authorization": "Bearer your-generated-token"
              },
              "url": "https://your-directus-url.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/directus"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Core, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "3 Studio seats, 25 collections, 5 flows"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 499,
          "note": "annual term, or $599 billed monthly. 10 seats, 50 collections, 20 flows"
        },
        {
          "item": "Team extra seat",
          "unit": "seat-month",
          "usd": 50,
          "note": "Studio users only"
        },
        {
          "item": "Directus Cloud hosting add-on",
          "unit": "month",
          "usd": 99,
          "note": "for Core, Team and Open Innovation Grant projects"
        }
      ],
      "provenance": {
        "legalEntity": "Monospace Inc. (doing business as Directus)",
        "domain": "directus.com",
        "domainRegistered": "1997-02-06",
        "endpointOnVendorDomain": false,
        "terms": "https://directus.com/license",
        "privacy": "https://directus.com/privacy",
        "statusPage": "https://status.directus.cloud",
        "changelog": "https://github.com/directus/directus/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 9 June 2026) names Monospace Inc., doing business as Directus, a Delaware corporation, at 223 Bedford Ave STE A #855, Brooklyn, New York. The terms page, dated 28 April 2025, gives the same entity.",
          "`terms` points at the MSCL-1.0-GPL licence text, which governs a self-hosted install. directus.com/terms reads as website terms of use, and Directus Cloud has separate Cloud policies at directus.com/cloud-policies.",
          "The privacy policy says personal information processed for customers of the product is handled under customer agreements, not the policy. No public DPA was found.",
          "A self-hosted install answers on its owner's domain. It contacts licensing.directus.com when a licence key is set and telemetry.directus.io for usage reports.",
          "https://directus.com/.well-known/security.txt returned 404 on 8 October 2026. directus.io redirects to directus.com.",
          "RDAP for directus.com gives a registration date of 1997-02-06, which predates the company's use of the domain.",
          "The status page runs on Statuspage and covers Directus Cloud regions and the dashboard, not self-hosted installs."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/directus.json",
      "live": {
        "slug": "directus",
        "vendorStatus": {
          "page": "https://status.directus.cloud",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T01:07:26.729225578Z"
        },
        "updatedAt": "2026-10-09T01:07:26.729225578Z"
      }
    },
    "answer": "Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Monospace Inc. (Directus)",
        "b": "Payload CMS, Inc. (Figma)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT",
        "b": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "name": "Licence"
      },
      {
        "a": "12",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-09",
        "b": "2024-03-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "38k stars, 23k npm/wk",
        "b": "45k stars, 1.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Directus or Payload?"
      },
      {
        "answer": "Directus takes an API key or an OAuth sign-in. Payload needs an API key.",
        "question": "Do Directus and Payload need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Directus. No hosted endpoint is listed for Payload.",
        "question": "Can an agent call Directus and Payload without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Directus. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).",
        "question": "Are Directus and Payload open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 81 against 70",
          "Agent ergonomics, 73 against 64",
          "Security \u0026 auth, 68 against 57",
          "Payments \u0026 pricing, 55 against 45",
          "Maintenance \u0026 community, 86 against 78"
        ],
        "also": null,
        "goodFor": "Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.",
        "slug": "directus",
        "watchFor": "Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period"
      },
      {
        "aheadOn": null,
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-directus.json",
        "title": "Contentstack vs Directus",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-directus.json",
        "title": "DatoCMS vs Directus",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-directus"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-ghost.json",
        "title": "Directus vs Ghost",
        "url": "https://www.anchorterminal.com/compare/directus-vs-ghost"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-wordpress.json",
        "title": "Directus vs WordPress",
        "url": "https://www.anchorterminal.com/compare/directus-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 4,
        "directus": 82,
        "edge": "directus",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "directus": 81,
        "edge": "directus",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13
      },
      {
        "by": 9,
        "directus": 73,
        "edge": "directus",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13
      },
      {
        "by": 11,
        "directus": 68,
        "edge": "directus",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14
      },
      {
        "by": 10,
        "directus": 55,
        "edge": "directus",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 8,
        "directus": 86,
        "edge": "directus",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7
      },
      {
        "by": 1,
        "directus": 61,
        "edge": "payload",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7
      }
    ],
    "summary": "Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Both do cms content.",
    "verdicts": {
      "directus": "The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.",
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/directus-vs-payload",
    "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/directus-vs-payload.md",
    "slim": "https://www.anchorterminal.com/compare/directus-vs-payload.min.md"
  },
  "markdown": "Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Both do cms content.\n\n- Directus: grade B, 67.1/100, rank #217 of 722. Markdown https://www.anchorterminal.com/tools/directus.md · JSON https://www.anchorterminal.com/api/v1/tools/directus.json\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Which one, for what\n\n### Directus (B)\n\nGood for: Teams that already keep content in an SQL database and want an agent to edit items, files and the data model under a named user's permissions.\n\nAhead on:\n- Schema \u0026 documentation, 81 against 70\n- Agent ergonomics, 73 against 64\n- Security \u0026 auth, 68 against 57\n- Payments \u0026 pricing, 55 against 45\n- Maintenance \u0026 community, 86 against 78\n\nWatch for: Version 12 (10 June 2026) added licence enforcement. The free Core tier allows 3 Studio seats, 25 collections and 5 flows, and an instance over its limits is locked after a grace period\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n\n## Score by category\n\n| Category | Weight | Directus | Payload | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 78 | Directus +4 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 70 | Directus +11 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 64 | Directus +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 57 | Directus +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 55 | 45 | Directus +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 78 | Directus +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 62 | Payload +1 |\n| Negative events | ≤15 | -6 | -10 | |\n| **Total** | | **67.1 · B** | **55.2 · C** | |\n\n## Facts side by side\n\n| Fact | Directus | Payload |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Monospace Inc. (Directus) | Payload CMS, Inc. (Figma) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | MSCL-1.0-GPL (Monospace Sustainable Core Licence 1.0), source-available with a licence key for paid tiers, each version converting to GPL-3.0 after four years. `@directus/sdk` is MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |\n| Tools exposed | 12 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-23 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | 2026-06-09 | 2024-03-28 |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 38k stars, 23k npm/wk | 45k stars, 1.1M npm/wk |\n\n## Verdicts\n\n**Directus.** The built-in MCP server works under the connecting user's permissions, supports OAuth limited to the MCP endpoint and blocks deletes unless an administrator allows them. Since version 12 a licence check caps the free Core tier at 3 Studio seats, 25 collections and 5 flows, and the default tool list carries about 79 KB of instructions.\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n## Before you call either\n\n### Directus\n\n1. Connect with OAuth or an `Authorization: Bearer` header. Don't put the token in the URL as `?access_token=`, where it can be logged\n2. Use `/mcp?tool_mode=registry` when the client loads every tool definition. Default mode sends each tool's full instructions, about 79 KB in total\n3. Read the `schema` tool before writing. Item payloads are untyped objects, so field names and types come only from the data model\n4. Publish a version with `POST /versions/{id}/promote` over REST. The MCP `items` tool refuses system collections such as `directus_versions`\n5. Count translation and junction tables against the 25-collection Core limit before creating collections\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n## Questions\n\n### Which is better for AI agents, Directus or Payload?\n\nDirectus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories.\n\n### Do Directus and Payload need an API key?\n\nDirectus takes an API key or an OAuth sign-in. Payload needs an API key.\n\n### Can an agent call Directus and Payload without installing anything?\n\nNo hosted endpoint is listed for Directus. No hosted endpoint is listed for Payload.\n\n### Are Directus and Payload open source?\n\nNo open-source release is listed for Directus. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/directus-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/directus-vs-payload.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"directus\", \"b\": \"payload\"}`. From a terminal: `anchor compare directus payload`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/directus.json and https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Other comparisons with Directus or Payload\n\n- [Contentstack vs Directus](https://www.anchorterminal.com/compare/contentstack-vs-directus.md)\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [DatoCMS vs Directus](https://www.anchorterminal.com/compare/datocms-vs-directus.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [Directus vs Ghost](https://www.anchorterminal.com/compare/directus-vs-ghost.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Directus vs WordPress](https://www.anchorterminal.com/compare/directus-vs-wordpress.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Directus vs Payload",
        "url": ""
      }
    ],
    "description": "Directus scores 67.1 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Directus B 67.1",
      "Payload C 55.2",
      "scores"
    ],
    "h1": "Directus vs Payload",
    "image": "https://www.anchorterminal.com/assets/og/compare-directus-vs-payload.png",
    "path": "/compare/directus-vs-payload",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Directus vs Payload for AI agents, B 67.1 vs C 55.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
