Head to head · Cms content · October 2026 research run

Hygraph vs Payload

Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.

Which one, for what

Hygraph B

Good for Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.

Ahead on

  • Reliability, 89 against 78
  • Schema & documentation, 78 against 70
  • Agent ergonomics, 72 against 64
  • Security & auth, 63 against 57

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where Payload loses 10 points for them

Watch for

GraphQL error bodies carry a message and a requestId with no machine-readable code, and only asset transformation 429 responses are documented with Retry-After

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Payments & pricing, 45 against 35

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Score by category

CategoryWeight this runHygraphPayloadEdge
Reliability16%208978Hygraph +11
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27870Hygraph +8
Agent ergonomics13%16.27264Hygraph +8
Security & auth14%17.56357Hygraph +6
Payments & pricing10%12.53545Payload +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87478Payload +4
Transparency & trust7%8.86062Payload +2
Negative events≤150-10
Total69.3 · B55.2 · C

Facts side by side

FactHygraphPayload
KindHTTP APIHTTP API
VendorHygraph GmbHPayload CMS, Inc. (Figma)
Hosted endpointhttps://mcp.hygraph.com/mcpno (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary service under Hygraph GmbH's Terms of Service. The @hygraph/management-sdk package is MITMIT for the core and the official packages. Enterprise add-ons are sold separately through sales
Tools exposed17none
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-302026-09-23
Terms last updatedno date givenno document linked
Privacy policy last updatedno date given2024-03-28
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity52 stars, 8.6k npm/wk45k stars, 1.1M npm/wk

Verdicts

Hygraph

Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Before you call either

Hygraph

  1. Send the Permanent Auth Token as Authorization: Bearer <token> to https://<region>.hygraph.com/v2/<projectId>/<environment>. Read the schema by introspection first, because every type is generated from the project's models
  2. Mutations write to DRAFT. Call publish<Model> with to: [PUBLISHED] as a separate mutation, and pass locales to write or publish a localisation
  3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429
  4. Upload an asset with createAsset, then POST the file to the returned pre-signed URL, or pass uploadUrl for a remote file. The asset stays ASSET_CREATE_PENDING until processed
  5. Schema changes go to the Management API through @hygraph/management-sdk or the MCP tool submit_batch_migration. Version restore has no documented mutation, so read <model>Version and write the old values back

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Questions

Which is better for AI agents, Hygraph or Payload?

Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments & pricing.

Do Hygraph and Payload need an API key?

Hygraph takes an API key or an OAuth sign-in. Payload needs an API key.

Can an agent call Hygraph and Payload without installing anything?

Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Payload.

Are Hygraph and Payload open source?

No open-source release is listed for Hygraph. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).

Other comparisons with Hygraph or Payload

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.