{
  "data": {
    "a": {
      "slug": "hygraph",
      "name": "Hygraph",
      "vendor": "Hygraph GmbH",
      "vendorUrl": "https://hygraph.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Hygraph is a hosted headless CMS from Hygraph GmbH in Berlin. Agents read and write entries, assets and localisations through a GraphQL Content API, change schema through a Management API and SDK, or connect through a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/hygraph",
      "markdownUrl": "https://www.anchorterminal.com/tools/hygraph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hygraph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hygraph.json",
      "repo": "https://github.com/hygraph/management-sdk",
      "license": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.hygraph.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@hygraph/management-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Content API and Management API take a Permanent Auth Token as a Bearer header. A person creates the token in Project Settings and sets its content permissions (by model, stage, locale, environment and action) and its Management API permissions. A new token has none enabled. Deleting a token invalidates it, and no expiry or rotation was found. The project MCP endpoint takes the same token. The global MCP endpoint uses a browser login through auth.hygraph.com and follows the user's own permissions. OAuth for third-party apps needs a client ID from Hygraph support. No app review or sales approval is needed for tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Hobby plan is free with no card and includes 500,000 API calls a month, 1,000 entries, 2 locales and 3 API tokens. Usage past the limit is blocked until the next period. Growth is $199 a month with 1,000,000 API calls, and overage of $0.20 per 10,000 API operations and per GB of asset traffic. Enterprise is sold through sales, with a 30-day trial that needs no card (https://hygraph.com/pricing, checked 2026-10-08).",
      "priceSummary": "$199 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 17,
      "popularity": {
        "githubStars": 52,
        "npmWeekly": 8645,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://hygraph.com/docs/api-reference",
      "llmsTxt": "https://hygraph.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.3,
        "grade": "B",
        "agentReady": false,
        "rank": 182,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
        "bestFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "strengths": [
          "Permanent Auth Tokens are limited by model, stage, locale, environment and action, and a new token starts with no permissions enabled",
          "The hosted MCP server rejects `delete*` and `unpublish*` operations, and `submit_batch_migration` takes `dry_run` and applies schema changes in one transaction",
          "GraphQL field selection, `first`, `skip` and cursor arguments and typed filters size every response. The default page is 10 entries and the maximum 100",
          "The Hobby plan needs no card and includes 500,000 API calls a month, 1,000 entries and 3 API tokens",
          "`llms.txt` links a Markdown copy of every documentation section, and the changelog has dated entries for 30 July, 31 August and 30 September 2026"
        ],
        "weaknesses": [
          "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`",
          "No idempotency keys in the reviewed documentation. Safe retries rest on `upsert` mutations keyed on a unique field",
          "Audit logs, backups with recovery and an uptime SLA are Enterprise only, and version history is absent on Hobby and 14 days on Growth",
          "No data processing agreement, named sub-processor list, security.txt or disclosure policy was found on hygraph.com. The privacy policy names categories of service provider only",
          "The only official SDK is `@hygraph/management-sdk` for JavaScript and TypeScript, and its public GitHub repository was last pushed on 13 September 2024"
        ],
        "agentNotes": [
          "Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models",
          "Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation",
          "Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429",
          "Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed",
          "Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.3
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 74,
          "payments": 35,
          "reliability": 89,
          "schema": 78,
          "security": 63,
          "transparency": 45
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @hygraph/management-sdk",
        "claudeCode": "claude mcp add hygraph https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/{ENVIRONMENT}/mcp \\\n  --transport http \\\n  --header \"Authorization: Bearer ${HYGRAPH_TOKEN}\"",
        "config": {
          "mcpServers": {
            "hygraph": {
              "args": [
                "mcp-remote",
                "https://mcp-{REGION}.hygraph.com/{PROJECT_ID}/master/mcp",
                "--header",
                "Authorization: Bearer ${HYGRAPH_TOKEN}"
              ],
              "command": "npx",
              "env": {
                "HYGRAPH_TOKEN": "token_here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/hygraph"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 199,
          "note": "10 seats, 1,000,000 API calls and 500 GB of asset traffic included"
        },
        {
          "item": "Additional API operations on Growth",
          "unit": "1k-requests",
          "usd": 0.02,
          "note": "sold as $0.20 per 10,000 API operations"
        },
        {
          "item": "Additional asset traffic on Growth",
          "unit": "gb",
          "usd": 0.2,
          "note": "per GB past the plan's 500 GB"
        }
      ],
      "provenance": {
        "legalEntity": "Hygraph GmbH",
        "domain": "hygraph.com",
        "domainRegistered": "2022-03-04",
        "endpointOnVendorDomain": true,
        "terms": "https://hygraph.com/terms",
        "privacy": "https://hygraph.com/privacy",
        "statusPage": "https://status.hygraph.com",
        "changelog": "https://hygraph.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint and the privacy policy name Hygraph GmbH, Dircksenstraße 47, 10178 Berlin, registered at Amtsgericht Berlin Charlottenburg under HRB 250696 B.",
          "The Terms of Service define the Hygraph Services to include the cloud platform and the Hygraph API. The pricing page lists them as the online terms for Hobby and Growth, with custom terms on Enterprise.",
          "The privacy policy has a section on use of the Hygraph service and was last updated on 19 March 2025. It names categories of service provider and no companies. No data processing agreement was found on hygraph.com.",
          "The Content API answers at \u003cregion\u003e.hygraph.com, the Management API at management.hygraph.com, the MCP server at mcp.hygraph.com and the OAuth server at auth.hygraph.com.",
          "https://hygraph.com/.well-known/security.txt answered 404 on 8 October 2026.",
          "RDAP for hygraph.com gives a registration date of 2022-03-04. The product was named GraphCMS before that, and the older SDK is still on npm as `@graphcms/management`."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hygraph.json",
      "live": {
        "slug": "hygraph",
        "probe": {
          "target": "https://mcp.hygraph.com/mcp",
          "method": "get",
          "lastAt": "2026-10-09T09:26:53.018011399Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 163,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 94,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hygraph.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:14.386503586Z"
        },
        "updatedAt": "2026-10-09T09:26:53.018011399Z"
      }
    },
    "answer": "Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Hygraph GmbH",
        "b": "Payload CMS, Inc. (Figma)",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.hygraph.com/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT",
        "b": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "name": "Licence"
      },
      {
        "a": "17",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2024-03-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "52 stars, 8.6k npm/wk",
        "b": "45k stars, 1.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Hygraph or Payload?"
      },
      {
        "answer": "Hygraph takes an API key or an OAuth sign-in. Payload needs an API key.",
        "question": "Do Hygraph and Payload need an API key?"
      },
      {
        "answer": "Hygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Payload.",
        "question": "Can an agent call Hygraph and Payload without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Hygraph. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).",
        "question": "Are Hygraph and Payload open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 78",
          "Schema \u0026 documentation, 78 against 70",
          "Agent ergonomics, 72 against 64",
          "Security \u0026 auth, 63 against 57"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Payload loses 10 points for them"
        ],
        "goodFor": "Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.",
        "slug": "hygraph",
        "watchFor": "GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 35"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph.json",
        "title": "Contentstack vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-hygraph.json",
        "title": "DatoCMS vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-hygraph.json",
        "title": "Directus vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/directus-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-hygraph.json",
        "title": "Ghost vs Hygraph",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-hygraph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-sanity.json",
        "title": "Hygraph vs Sanity",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok.json",
        "title": "Hygraph vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-strapi.json",
        "title": "Hygraph vs Strapi",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-webflow.json",
        "title": "Hygraph vs Webflow",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress.json",
        "title": "Hygraph vs WordPress",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-prismic.json",
        "title": "Payload vs Prismic",
        "url": "https://www.anchorterminal.com/compare/payload-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 11,
        "edge": "hygraph",
        "hygraph": 89,
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 8,
        "edge": "hygraph",
        "hygraph": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "hygraph",
        "hygraph": 72,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "hygraph",
        "hygraph": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "payload",
        "hygraph": 35,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "payload",
        "hygraph": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "payload",
        "hygraph": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7
      }
    ],
    "summary": "Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "hygraph": "Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.",
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hygraph-vs-payload",
    "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hygraph-vs-payload.md",
    "slim": "https://www.anchorterminal.com/compare/hygraph-vs-payload.min.md"
  },
  "markdown": "Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.\n\n- Hygraph: grade B, 69.3/100, rank #182 of 842. Markdown https://www.anchorterminal.com/tools/hygraph.md · JSON https://www.anchorterminal.com/api/v1/tools/hygraph.json\n- Payload: grade C, 55.2/100, rank #597 of 842. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Which one, for what\n\n### Hygraph (B)\n\nGood for: Teams on Hygraph who want an agent to create, localise and publish entries, upload assets or change schema, with delete and unpublish kept out of reach on MCP.\n\nAhead on:\n- Reliability, 89 against 78\n- Schema \u0026 documentation, 78 against 70\n- Agent ergonomics, 72 against 64\n- Security \u0026 auth, 63 against 57\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Payload loses 10 points for them\n\nWatch for: GraphQL error bodies carry a message and a `requestId` with no machine-readable code, and only asset transformation 429 responses are documented with `Retry-After`\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 35\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n\n## Score by category\n\n| Category | Weight | Hygraph | Payload | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 78 | Hygraph +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 70 | Hygraph +8 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 64 | Hygraph +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 57 | Hygraph +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 45 | Payload +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 78 | Payload +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 62 | Payload +2 |\n| Negative events | ≤15 | 0 | -10 | |\n| **Total** | | **69.3 · B** | **55.2 · C** | |\n\n## Facts side by side\n\n| Fact | Hygraph | Payload |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Hygraph GmbH | Payload CMS, Inc. (Figma) |\n| Hosted endpoint | `https://mcp.hygraph.com/mcp` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Hygraph GmbH's Terms of Service. The `@hygraph/management-sdk` package is MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |\n| Tools exposed | 17 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-09-23 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | 2024-03-28 |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 52 stars, 8.6k npm/wk | 45k stars, 1.1M npm/wk |\n\n## Verdicts\n\n**Hygraph.** Tokens are limited by model, stage, locale and action, the GraphQL schema is typed and introspectable, and a hosted MCP server rejects delete and unpublish operations. Error bodies carry a message without a machine code, there are no idempotency keys, audit logs are Enterprise only, and no data processing agreement, sub-processor list or security.txt was found.\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n## Before you call either\n\n### Hygraph\n\n1. Send the Permanent Auth Token as `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cregion\u003e.hygraph.com/v2/\u003cprojectId\u003e/\u003cenvironment\u003e`. Read the schema by introspection first, because every type is generated from the project's models\n2. Mutations write to DRAFT. Call `publish\u003cModel\u003e` with `to: [PUBLISHED]` as a separate mutation, and pass `locales` to write or publish a localisation\n3. Stay under the plan's limit for uncached requests (5 a second on Hobby, 25 on Growth) and its concurrent mutations (5 and 10). Back off exponentially on 429\n4. Upload an asset with `createAsset`, then POST the file to the returned pre-signed URL, or pass `uploadUrl` for a remote file. The asset stays `ASSET_CREATE_PENDING` until processed\n5. Schema changes go to the Management API through `@hygraph/management-sdk` or the MCP tool `submit_batch_migration`. Version restore has no documented mutation, so read `\u003cmodel\u003eVersion` and write the old values back\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n## Questions\n\n### Which is better for AI agents, Hygraph or Payload?\n\nHygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do Hygraph and Payload need an API key?\n\nHygraph takes an API key or an OAuth sign-in. Payload needs an API key.\n\n### Can an agent call Hygraph and Payload without installing anything?\n\nHygraph has a hosted endpoint at https://mcp.hygraph.com/mcp. No hosted endpoint is listed for Payload.\n\n### Are Hygraph and Payload open source?\n\nNo open-source release is listed for Hygraph. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hygraph-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hygraph-vs-payload.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hygraph\", \"b\": \"payload\"}`. From a terminal: `anchor compare hygraph payload`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hygraph.json and https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Other comparisons with Hygraph or Payload\n\n- [Contentstack vs Hygraph](https://www.anchorterminal.com/compare/contentstack-vs-hygraph.md)\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [DatoCMS vs Hygraph](https://www.anchorterminal.com/compare/datocms-vs-hygraph.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [Directus vs Hygraph](https://www.anchorterminal.com/compare/directus-vs-hygraph.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Ghost vs Hygraph](https://www.anchorterminal.com/compare/ghost-vs-hygraph.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Hygraph vs Sanity](https://www.anchorterminal.com/compare/hygraph-vs-sanity.md)\n- [Hygraph vs Storyblok](https://www.anchorterminal.com/compare/hygraph-vs-storyblok.md)\n- [Hygraph vs Strapi](https://www.anchorterminal.com/compare/hygraph-vs-strapi.md)\n- [Hygraph vs Webflow](https://www.anchorterminal.com/compare/hygraph-vs-webflow.md)\n- [Hygraph vs WordPress](https://www.anchorterminal.com/compare/hygraph-vs-wordpress.md)\n- [Payload vs Prismic](https://www.anchorterminal.com/compare/payload-vs-prismic.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Hygraph vs Payload",
        "url": ""
      }
    ],
    "description": "Hygraph scores 69.3 (B) on agent readiness against Payload's 55.2 (C), and leads in 4 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Hygraph B 69.3",
      "Payload C 55.2",
      "scores"
    ],
    "h1": "Hygraph vs Payload",
    "image": "https://www.anchorterminal.com/assets/og/compare-hygraph-vs-payload.png",
    "path": "/compare/hygraph-vs-payload",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Hygraph vs Payload for AI agents, B 69.3 vs C 55.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
