Head to head · Cms content · October 2026 research run
Hygraph vs Payload
Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.
Which one, for what
Hygraph B
Good for Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.
Ahead on
- Reliability, 89 against 78
- Schema & documentation, 78 against 70
- Agent ergonomics, 72 against 64
- Security & auth, 63 against 57
Also in its favour
- A hosted endpoint, with nothing to install
- Free to start without a card
- No incidents deducted, where Payload loses 10 points for them
Watch for
GraphQL error bodies carry a message and a requestId with no machine-readable code, and only asset transformation 429 responses are documented with Retry-After
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Ahead on
- Payments & pricing, 45 against 35
Also in its favour
- Open source
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Score by category
| Category | Weight this run | Hygraph | Payload | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 89 | 78 | Hygraph +11 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 78 | 70 | Hygraph +8 |
| Agent ergonomics | 13%16.2 | 72 | 64 | Hygraph +8 |
| Security & auth | 14%17.5 | 63 | 57 | Hygraph +6 |
| Payments & pricing | 10%12.5 | 35 | 45 | Payload +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 74 | 78 | Payload +4 |
| Transparency & trust | 7%8.8 | 60 | 62 | Payload +2 |
| Negative events | ≤15 | 0 | -10 | |
| Total | 69.3 · B | 55.2 · C |
Facts side by side
| Fact | Hygraph | Payload |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Hygraph GmbH | Payload CMS, Inc. (Figma) |
| Hosted endpoint | https://mcp.hygraph.com/mcp | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | Proprietary service under Hygraph GmbH's Terms of Service. The @hygraph/management-sdk package is MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |
| Tools exposed | 17 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-09-30 | 2026-09-23 |
| Terms last updated | no date given | no document linked |
| Privacy policy last updated | no date given | 2024-03-28 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | yes | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 52 stars, 8.6k npm/wk | 45k stars, 1.1M npm/wk |
Verdicts
Hygraph
Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
Before you call either
Hygraph
- Send the Permanent Auth Token as
Authorization: Bearer <token>tohttps://<region>.hygraph.com/v2/<projectId>/<environment>. Read the schema by introspection first, because every type is generated from the project's models - Mutations write to DRAFT. Call
publish<Model>withto: [PUBLISHED]as a separate mutation, and passlocalesto write or publish a localisation - Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429
- Upload an asset with
createAsset, then POST the file to the returned pre-signed URL, or passuploadUrlfor a remote file. The asset staysASSET_CREATE_PENDINGuntil processed - Schema changes go to the Management API through
@hygraph/management-sdkor the MCP toolsubmit_batch_migration. Version restore has no documented mutation, so read<model>Versionand write the old values back
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
Questions
Which is better for AI agents, Hygraph or Payload?
Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments & pricing.
Do Hygraph and Payload need an API key?
Hygraph takes an API key or an OAuth sign-in. Payload needs an API key.
Can an agent call Hygraph and Payload without installing anything?
Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Payload.
Are Hygraph and Payload open source?
No open-source release is listed for Hygraph. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).
Other comparisons with Hygraph or Payload
- Contentstack vs Hygraph
- Contentstack vs Payload
- DatoCMS vs Hygraph
- DatoCMS vs Payload
- Directus vs Hygraph
- Directus vs Payload
- Ghost vs Hygraph
- Ghost vs Payload
- Hygraph vs Prismic
- Hygraph vs Sanity
- Hygraph vs Storyblok
- Hygraph vs Strapi
- Hygraph vs Webflow
- Hygraph vs WordPress
- Payload vs Prismic
- Payload vs Sanity
- Payload vs Storyblok
- Payload vs Strapi
- Payload vs Webflow
- Payload vs WordPress
Machine-readable
- This page as Markdown
/compare/hygraph-vs-payload.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/hygraph.json·/api/v1/tools/payload.json - From a terminal
anchor compare hygraph payload(the CLI) - Over MCP
compare_tools {"a": "hygraph", "b": "payload"}at/mcp, no key