Head to head · Cms content · October 2026 research run
Ghost vs Payload
Ghost scores 58.3 (C) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation. Both do cms content.
Which one, for what
Ghost C
Good for A publication, blog or newsletter where an agent drafts posts and a person or a higher role publishes.
Ahead on
- Agent ergonomics, 69 against 64
- Payments & pricing, 50 against 45
- Maintenance & community, 85 against 78
- Transparency & trust, 72 against 62
Watch for
No OpenAPI or other machine-readable description of the Admin API was found in the docs or the repository
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Ahead on
- Schema & documentation, 70 against 51
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Score by category
| Category | Weight this run | Ghost | Payload | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 80 | 78 | Ghost +2 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 51 | 70 | Payload +19 |
| Agent ergonomics | 13%16.2 | 69 | 64 | Ghost +5 |
| Security & auth | 14%17.5 | 56 | 57 | Payload +1 |
| Payments & pricing | 10%12.5 | 50 | 45 | Ghost +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 85 | 78 | Ghost +7 |
| Transparency & trust | 7%8.8 | 72 | 62 | Ghost +10 |
| Negative events | ≤15 | -7 | -10 | |
| Total | 58.3 · C | 55.2 · C |
Facts side by side
| Fact | Ghost | Payload |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Ghost Foundation | Payload CMS, Inc. (Figma) |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | API key | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-10-07 | 2026-09-23 |
| Terms last updated | no date given | no document linked |
| Privacy policy last updated | no date given | 2024-03-28 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 56k stars, 24k npm/wk | 45k stars, 1.1M npm/wk |
Verdicts
Ghost
A create needs only a title, updates are checked against updated_at so a stale write is refused, and a Contributor's staff token can draft without being able to publish. The Admin API has no OpenAPI file and one fixed permission set per integration, and 20 security advisories were published between 3 September and 1 October 2026.
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
Before you call either
Ghost
- Sign a fresh HS256 token for each batch of calls. Decode the hex secret to bytes, set
kidto the key id,audto/admin/andexpat most 5 minutes ahead - Set
statustodrafton every create unless told to publish, and publish later with a PUT that setsstatustopublished - GET the post before each PUT and send its
updated_atback. Tags and authors in a PUT replace the existing lists - Send content as a Lexical JSON string, or add
?source=htmland sendhtml. The HTML conversion is lossy unless wrapped in an HTML card - Page through lists with
limitup to 100 andpage. Since Ghost 6.0limit=allreturns 100 items without an error
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
Questions
Which is better for AI agents, Ghost or Payload?
Ghost scores 58.3 (C) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation.
Do Ghost and Payload need an API key?
Both need an API key.
Can an agent call Ghost and Payload without installing anything?
No hosted endpoint is listed for Ghost. No hosted endpoint is listed for Payload.
Are Ghost and Payload open source?
Yes. Ghost is open source (MIT, copyright Ghost Foundation. Ghost(Pro) is a paid hosting service under the Ghost Foundation's terms). Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).
Other comparisons with Ghost or Payload
Machine-readable
- This page as Markdown
/compare/ghost-vs-payload.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/ghost.json·/api/v1/tools/payload.json - From a terminal
anchor compare ghost payload(the CLI) - Over MCP
compare_tools {"a": "ghost", "b": "payload"}at/mcp, no key