Head to head · Cms content · October 2026 research run

Ghost vs Payload

Ghost scores 58.3 (C) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation. Both do cms content.

Which one, for what

Ghost C

Good for A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.

Ahead on

  • Agent ergonomics, 69 against 64
  • Payments & pricing, 50 against 45
  • Maintenance & community, 85 against 78
  • Transparency & trust, 72 against 62

Watch for

No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Schema & documentation, 70 against 51

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Score by category

CategoryWeight this runGhostPayloadEdge
Reliability16%208078Ghost +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25170Payload +19
Agent ergonomics13%16.26964Ghost +5
Security & auth14%17.55657Payload +1
Payments & pricing10%12.55045Ghost +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88578Ghost +7
Transparency & trust7%8.87262Ghost +10
Negative events≤15-7-10
Total58.3 · C55.2 · C

Facts side by side

FactGhostPayload
KindHTTP APIHTTP API
VendorGhost FoundationPayload CMS, Inc. (Figma)
Hosted endpointno (local only)no (local only)
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyAPI key
PricingFreemiumFree
x402nono
LicenceMIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's termsMIT for the core and the official packages. Enterprise add-ons are sold separately through sales
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-09-23
Terms last updatedno date givenno document linked
Privacy policy last updatedno date given2024-03-28
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity56k stars, 24k npm/wk45k stars, 1.1M npm/wk

Verdicts

Ghost

A create needs only a title, updates are checked against updated_at so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Before you call either

Ghost

  1. Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set kid to the key id, aud to /admin/ and exp at most 5 minutes ahead
  2. Set status to draft on every create unless told to publish, and publish later with a PUT that sets status to published
  3. GET the post before each PUT and send its updated_at back. Tags and authors in a PUT replace the existing lists
  4. Send content as a Lexical JSON string, or add ?source=html and send html. The HTML conversion is lossy unless wrapped in an HTML card
  5. Page through lists with limit up to 100 and page. Since Ghost 6.0 limit=all returns 100 items without an error

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Questions

Which is better for AI agents, Ghost or Payload?

Ghost scores 58.3 (C) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation.

Do Ghost and Payload need an API key?

Both need an API key.

Can an agent call Ghost and Payload without installing anything?

No hosted endpoint is listed for Ghost. No hosted endpoint is listed for Payload.

Are Ghost and Payload open source?

Yes. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).

Other comparisons with Ghost or Payload

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.