{
  "data": {
    "a": {
      "slug": "kontent-ai",
      "name": "Kontent.ai",
      "vendor": "Kontent CZ s.r.o.",
      "vendorUrl": "https://kontent.ai",
      "kind": "http-api",
      "category": "cms",
      "summary": "Kontent.ai is a hosted headless CMS from Kontent CZ s.r.o. in Brno. Its Management API v2 reads and writes content items, language variants, assets, content models and workflow steps, and an open-source MCP server wraps it.",
      "url": "https://www.anchorterminal.com/tools/kontent-ai",
      "markdownUrl": "https://www.anchorterminal.com/tools/kontent-ai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kontent-ai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kontent-ai.json",
      "repo": "https://github.com/kontent-ai/mcp-server",
      "license": "Proprietary service under the Kontent.ai Terms of Service. The management SDKs for JavaScript and .NET and the MCP server on GitHub are MIT",
      "transports": [
        "http",
        "stdio",
        "streamable-http"
      ],
      "remoteUrl": "https://manage.kontent.ai/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "@kontent-ai/management-sdk"
        },
        {
          "registry": "npm",
          "name": "@kontent-ai/mcp-server"
        }
      ],
      "auth": "api-key",
      "authNotes": "A Bearer API key in the `Authorization` header. A project manager creates a Management API key in the web app under Project settings, API keys, and picks its permissions (read content, edit content, read assets, edit assets, content model, environment settings), the environments it reaches and its expiry (1 minute to 2 years, 6 months by default). A Personal API key inherits its owner's role instead. Regenerating a key revokes the old one after a few minutes. No OAuth flow and no API for creating keys was found. The Management API has to be enabled per environment.",
      "pricing": "paid",
      "pricingNotes": "No public price. The pricing page shows sliders for user seats, content types and content items and a form that requests a calculation, and the terms put the price, limits and overage unit prices in an order form. A 30-day trial needs no card and includes API access. The terms mention a Developer Plan, which the pricing page does not show (checked 2026-10-09).",
      "priceSummary": "Paid",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Management API docs, the MCP server README or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 54,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 8381,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://kontent.ai/learn/docs/apis/management-api-v2",
      "llmsTxt": "https://kontent.ai/llms.txt",
      "registryName": "io.github.kontent-ai/mcp-server",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "closed-source",
        "api-key",
        "mcp",
        "free-trial",
        "no-card",
        "sales-led",
        "llms-txt",
        "typescript",
        "dotnet",
        "webhooks",
        "graphql",
        "status-page",
        "soc2",
        "iso27001",
        "audit-log"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 153,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 83,
          "payments": 20,
          "reliability": 82,
          "schema": 74,
          "security": 81,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Management API keys take per-area permissions, environment limits and an expiry from one minute to two years, and changes made with a key are named in the audit log. Rate limits and Retry-After are documented. No price is published, and no OpenAPI file was found. Access starts with a 30-day trial that a person opens in a browser.",
        "bestFor": "A company already on Kontent.ai, or evaluating it on a trial, that wants an agent to draft, localise, move through workflow and publish structured content with a permission-limited key and an audit trail.",
        "strengths": [
          "Management API keys carry selectable permissions (read content, edit content, assets, content model, environment settings), environment limits and an expiry from 1 minute to 2 years",
          "Rate limits are published (10 requests a second and 400 a minute per environment), and a 429 carries a Retry-After header",
          "The audit log keeps 90 days of changes and names the API key that made each one. Content item changes were added on 2 October 2026",
          "All 54 tools in the MCP server (MIT, version 0.39.0) set readOnlyHint and destructiveHint, and its README has a section on indirect prompt injection",
          "security.txt is valid to July 2027, with a disclosure policy that pays discretionary rewards, and the trust centre lists SOC 2 Type 2 and ISO 27001, 27017, 27018 and 42001",
          "The sub-processor page names each vendor, its location and the data sent, and projects can be stored in the US, the Netherlands, Australia or Canada"
        ],
        "weaknesses": [
          "No price is published. The pricing page shows sliders for seats, content types and items and a form that requests a quote",
          "No OpenAPI file was found. The docs link a Postman collection, which we did not read",
          "Access needs a person. The 30-day trial needs no card, but sign-up, the Management API toggle and key creation happen in the web app",
          "No idempotency keys. The docs advise against parallel requests, saying they may cause inconsistencies in content",
          "The availability annex covers the administration interface and the Delivery API, not the Management API, and the guaranteed level sits in each order form",
          "The Terms of Service forbid automated access to the Service unless the procedure is described in the documentation. This matters before any probe is run",
          "The MCP server loads 54 tools, 22 of them marked destructive, and runs only on the owner's machine. No hosted endpoint was found"
        ],
        "agentNotes": [
          "Send `Authorization: Bearer \u003ckey\u003e` to `https://manage.kontent.ai/v2/projects/{environment_id}/...`. The Management API must be switched on under Environment settings, General, Enabled APIs first",
          "Ask for a Management API key with only the permissions the task needs. Read content alone gives a read-only key, and keys expire after six months by default",
          "Stay under 10 requests a second and 400 a minute per environment, send requests one at a time, and wait the seconds in Retry-After on a 429",
          "Page lists by passing the `continuation_token` from the response back in the `x-continuation` header",
          "Create items with an `external_id` and write with the upsert PUT at `/items/external-id/{id}` so a retry after a lost response does not create a duplicate",
          "With the MCP server, call `get-patch-guide` before any patch tool, and use a client that prompts on destructiveHint"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.5
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 83,
          "payments": 20,
          "reliability": 82,
          "schema": 74,
          "security": 81,
          "transparency": 69
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm i @kontent-ai/management-sdk --save",
        "http": "curl --request GET \\\n  --url https://manage.kontent.ai/v2/projects/KONTENT_AI_ENVIRONMENT_ID/items \\\n  --header 'Authorization: Bearer KONTENT_AI_MANAGEMENT_API_KEY' \\\n  --header 'Content-type: application/json'",
        "config": {
          "kontent-ai-stdio": {
            "args": [
              "@kontent-ai/mcp-server@latest",
              "stdio"
            ],
            "command": "npx",
            "env": {
              "KONTENT_API_KEY": "\u003cyour-management-api-key\u003e",
              "KONTENT_ENVIRONMENT_ID": "\u003cyour-environment-id\u003e"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/kontent-ai"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kontent CZ s.r.o.",
        "domain": "kontent.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://kontent.ai/terms-of-service/",
        "privacy": "https://kontent.ai/privacy/",
        "statusPage": "https://status.kontent.ai",
        "changelog": "https://kontent.ai/learn/product-updates",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service effective 11 September 2026 name Kontent CZ s.r.o., Nové sady 996/25, 602 00 Brno, Czech Republic, company number 173 00 576, or an affiliate named in the order form. The Data Processing Addendum and the availability and AI annexes are part of the same page.",
          "The privacy policy effective 2 June 2025 is issued by Kontent s.r.o. at the same address with Kontent CZ s.r.o. and Kontent US, LLC as joint controllers, and has a section for users of the product.",
          "The Management API answers at manage.kontent.ai, a kontent.ai subdomain.",
          "kontent.ai/.well-known/security.txt gives security@kontent.ai, a PGP key, the disclosure policy and an Open Bug Bounty page, and expires on 21 July 2027.",
          "The domain's registration date was not looked up."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kontent-ai.json",
      "live": {
        "slug": "kontent-ai",
        "probe": {
          "target": "https://manage.kontent.ai/v2",
          "method": "get",
          "lastAt": "2026-10-10T02:54:59.59146656Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 364,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 373,
          "p95ms24h": 588,
          "samples24h": 115,
          "samples30d": 115,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.kontent.ai",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:50:26.134791542Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "kontent-ai/mcp-server",
            "version": "0.39.0",
            "released": "2026-08-31",
            "seenAt": "2026-10-09T17:00:51.588844437Z"
          },
          {
            "registry": "npm",
            "name": "@kontent-ai/management-sdk",
            "version": "8.5.7",
            "seenAt": "2026-10-09T17:00:49.298560089Z"
          },
          {
            "registry": "npm",
            "name": "@kontent-ai/mcp-server",
            "version": "0.39.0",
            "seenAt": "2026-10-09T17:00:50.153755771Z"
          }
        ],
        "githubStars": 9,
        "npmWeekly": 8381,
        "pages": [
          {
            "url": "https://kontent.ai/learn/product-updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:45.195164377Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3f0ce279378b"
          },
          {
            "url": "https://kontent.ai/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:47.371617041Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "47ae43c907ba"
          },
          {
            "url": "https://kontent.ai/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:49.654963617Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b1ef49b6e91c"
          }
        ],
        "updatedAt": "2026-10-10T02:54:59.59146656Z"
      }
    },
    "answer": "Kontent.ai scores 70.5 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 665,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 13,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json",
      "live": {
        "slug": "payload",
        "versions": [
          {
            "registry": "github",
            "name": "payloadcms/payload",
            "version": "v3.90.2",
            "released": "2026-09-23",
            "seenAt": "2026-10-09T17:12:11.388759776Z"
          },
          {
            "registry": "npm",
            "name": "@payloadcms/plugin-mcp",
            "version": "3.90.2",
            "seenAt": "2026-10-09T17:12:07.657473594Z"
          },
          {
            "registry": "npm",
            "name": "@payloadcms/sdk",
            "version": "3.90.2",
            "seenAt": "2026-10-09T17:12:09.433932063Z"
          },
          {
            "registry": "npm",
            "name": "payload",
            "version": "3.90.2",
            "seenAt": "2026-10-09T17:12:06.452715631Z"
          }
        ],
        "githubStars": 45169,
        "npmWeekly": 978799,
        "securityTxt": {
          "url": "https://payloadcms.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:09.37606023Z"
        },
        "llmsTxt": {
          "url": "https://payloadcms.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:34.390993883Z"
        },
        "pages": [
          {
            "url": "https://payloadcms.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:04.138715081Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0ac80167ab5"
          }
        ],
        "updatedAt": "2026-10-09T18:43:04.138715081Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Kontent CZ s.r.o.",
        "b": "Payload CMS, Inc. (Figma)",
        "name": "Vendor"
      },
      {
        "a": "https://manage.kontent.ai/v2",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Kontent.ai Terms of Service. The management SDKs for JavaScript and .NET and the MCP server on GitHub are MIT",
        "b": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "name": "Licence"
      },
      {
        "a": "54",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "io.github.kontent-ai/mcp-server",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-02",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "2026-09-11",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2025-06-02",
        "b": "2024-03-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "8.4k npm/wk",
        "b": "45k stars, 1.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kontent.ai scores 70.5 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Kontent.ai or Payload?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Kontent.ai and Payload need an API key?"
      },
      {
        "answer": "Kontent.ai has a hosted endpoint at https://manage.kontent.ai/v2. No hosted endpoint is listed for Payload.",
        "question": "Can an agent call Kontent.ai and Payload without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Kontent.ai. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).",
        "question": "Are Kontent.ai and Payload open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 71 against 64",
          "Security \u0026 auth, 81 against 57",
          "Maintenance \u0026 community, 83 against 78",
          "Transparency \u0026 trust, 75 against 62"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card",
          "No incidents deducted, where Payload loses 10 points for them"
        ],
        "goodFor": "A company already on Kontent.ai, or evaluating it on a trial, that wants an agent to draft, localise, move through workflow and publish structured content with a permission-limited key and an audit trail.",
        "slug": "kontent-ai",
        "watchFor": "No price is published. The pricing page shows sliders for seats, content types and items and a form that requests a quote"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 20"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Content management"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/buttercms-vs-kontent-ai.json",
        "title": "ButterCMS vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/buttercms-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/buttercms-vs-payload.json",
        "title": "ButterCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/buttercms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-kontent-ai.json",
        "title": "Contentstack vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-kontent-ai.json",
        "title": "DatoCMS vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-kontent-ai.json",
        "title": "Directus vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/directus-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-kontent-ai.json",
        "title": "Ghost vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-kontent-ai.json",
        "title": "Hygraph vs Kontent.ai",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-kontent-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-prismic.json",
        "title": "Kontent.ai vs Prismic",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-sanity.json",
        "title": "Kontent.ai vs Sanity",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-storyblok.json",
        "title": "Kontent.ai vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-strapi.json",
        "title": "Kontent.ai vs Strapi",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-webflow.json",
        "title": "Kontent.ai vs Webflow",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-wordpress.json",
        "title": "Kontent.ai vs WordPress",
        "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-prismic.json",
        "title": "Payload vs Prismic",
        "url": "https://www.anchorterminal.com/compare/payload-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 4,
        "edge": "kontent-ai",
        "key": "reliability",
        "kontent-ai": 82,
        "name": "Reliability",
        "payload": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "kontent-ai",
        "key": "schema",
        "kontent-ai": 74,
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "kontent-ai",
        "key": "ergonomics",
        "kontent-ai": 71,
        "name": "Agent ergonomics",
        "payload": 64,
        "weight": 13
      },
      {
        "by": 24,
        "edge": "kontent-ai",
        "key": "security",
        "kontent-ai": 81,
        "name": "Security \u0026 auth",
        "payload": 57,
        "weight": 14
      },
      {
        "by": 25,
        "edge": "payload",
        "key": "payments",
        "kontent-ai": 20,
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "kontent-ai",
        "key": "maintenance",
        "kontent-ai": 83,
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "weight": 7
      },
      {
        "by": 13,
        "edge": "kontent-ai",
        "key": "transparency",
        "kontent-ai": 75,
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "weight": 7
      }
    ],
    "summary": "Kontent.ai scores 70.5 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do content management.",
    "verdicts": {
      "kontent-ai": "Management API keys take per-area permissions, environment limits and an expiry from one minute to two years, and changes made with a key are named in the audit log. Rate limits and Retry-After are documented. No price is published, and no OpenAPI file was found. Access starts with a 30-day trial that a person opens in a browser.",
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kontent-ai-vs-payload",
    "json": "https://www.anchorterminal.com/compare/kontent-ai-vs-payload.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kontent-ai-vs-payload.md",
    "slim": "https://www.anchorterminal.com/compare/kontent-ai-vs-payload.min.md"
  },
  "markdown": "Kontent.ai scores 70.5 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do content management.\n\n- Kontent.ai: grade BB, 70.5/100, rank #153 of 950. Markdown https://www.anchorterminal.com/tools/kontent-ai.md · JSON https://www.anchorterminal.com/api/v1/tools/kontent-ai.json\n- Payload: grade C, 55.2/100, rank #665 of 950. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Best headless CMS and website publishing for AI agents: https://www.anchorterminal.com/best/cms/index.md\n- All 91 cms comparisons: https://www.anchorterminal.com/compare/cms/index.md\n\n## Which one, for what\n\n### Kontent.ai (BB)\n\nGood for: A company already on Kontent.ai, or evaluating it on a trial, that wants an agent to draft, localise, move through workflow and publish structured content with a permission-limited key and an audit trail.\n\nAhead on:\n- Agent ergonomics, 71 against 64\n- Security \u0026 auth, 81 against 57\n- Maintenance \u0026 community, 83 against 78\n- Transparency \u0026 trust, 75 against 62\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n- No incidents deducted, where Payload loses 10 points for them\n\nWatch for: No price is published. The pricing page shows sliders for seats, content types and items and a form that requests a quote\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 20\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n\n## Score by category\n\n| Category | Weight | Kontent.ai | Payload | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 78 | Kontent.ai +4 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 70 | Kontent.ai +4 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 64 | Kontent.ai +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 81 | 57 | Kontent.ai +24 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 45 | Payload +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 83 | 78 | Kontent.ai +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 62 | Kontent.ai +13 |\n| Negative events | ≤15 | 0 | -10 | |\n| **Total** | | **70.5 · BB** | **55.2 · C** | |\n\n## Facts side by side\n\n| Fact | Kontent.ai | Payload |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Kontent CZ s.r.o. | Payload CMS, Inc. (Figma) |\n| Hosted endpoint | `https://manage.kontent.ai/v2` | no (local only) |\n| Transports | HTTP, stdio, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | API key |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Proprietary service under the Kontent.ai Terms of Service. The management SDKs for JavaScript and .NET and the MCP server on GitHub are MIT | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales |\n| Tools exposed | 54 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| MCP registry | `io.github.kontent-ai/mcp-server` | not listed |\n| Last release | 2026-10-02 | 2026-09-23 |\n| Terms last updated | 2026-09-11 | no document linked |\n| Privacy policy last updated | 2025-06-02 | 2024-03-28 |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 8.4k npm/wk | 45k stars, 1.1M npm/wk |\n\n## Verdicts\n\n**Kontent.ai.** Management API keys take per-area permissions, environment limits and an expiry from one minute to two years, and changes made with a key are named in the audit log. Rate limits and Retry-After are documented. No price is published, and no OpenAPI file was found. Access starts with a 30-day trial that a person opens in a browser.\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n## Before you call either\n\n### Kontent.ai\n\n1. Send `Authorization: Bearer \u003ckey\u003e` to `https://manage.kontent.ai/v2/projects/{environment_id}/...`. The Management API must be switched on under Environment settings, General, Enabled APIs first\n2. Ask for a Management API key with only the permissions the task needs. Read content alone gives a read-only key, and keys expire after six months by default\n3. Stay under 10 requests a second and 400 a minute per environment, send requests one at a time, and wait the seconds in Retry-After on a 429\n4. Page lists by passing the `continuation_token` from the response back in the `x-continuation` header\n5. Create items with an `external_id` and write with the upsert PUT at `/items/external-id/{id}` so a retry after a lost response does not create a duplicate\n6. With the MCP server, call `get-patch-guide` before any patch tool, and use a client that prompts on destructiveHint\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n## Questions\n\n### Which is better for AI agents, Kontent.ai or Payload?\n\nKontent.ai scores 70.5 (BB) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do Kontent.ai and Payload need an API key?\n\nBoth need an API key.\n\n### Can an agent call Kontent.ai and Payload without installing anything?\n\nKontent.ai has a hosted endpoint at https://manage.kontent.ai/v2. No hosted endpoint is listed for Payload.\n\n### Are Kontent.ai and Payload open source?\n\nNo open-source release is listed for Kontent.ai. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kontent-ai-vs-payload.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kontent-ai-vs-payload.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kontent-ai\", \"b\": \"payload\"}`. From a terminal: `anchor compare kontent-ai payload`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kontent-ai.json and https://www.anchorterminal.com/api/v1/tools/payload.json\n\n## Other comparisons with Kontent.ai or Payload\n\n- [ButterCMS vs Kontent.ai](https://www.anchorterminal.com/compare/buttercms-vs-kontent-ai.md)\n- [ButterCMS vs Payload](https://www.anchorterminal.com/compare/buttercms-vs-payload.md)\n- [Contentstack vs Kontent.ai](https://www.anchorterminal.com/compare/contentstack-vs-kontent-ai.md)\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [DatoCMS vs Kontent.ai](https://www.anchorterminal.com/compare/datocms-vs-kontent-ai.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [Directus vs Kontent.ai](https://www.anchorterminal.com/compare/directus-vs-kontent-ai.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Ghost vs Kontent.ai](https://www.anchorterminal.com/compare/ghost-vs-kontent-ai.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Hygraph vs Kontent.ai](https://www.anchorterminal.com/compare/hygraph-vs-kontent-ai.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Kontent.ai vs Prismic](https://www.anchorterminal.com/compare/kontent-ai-vs-prismic.md)\n- [Kontent.ai vs Sanity](https://www.anchorterminal.com/compare/kontent-ai-vs-sanity.md)\n- [Kontent.ai vs Storyblok](https://www.anchorterminal.com/compare/kontent-ai-vs-storyblok.md)\n- [Kontent.ai vs Strapi](https://www.anchorterminal.com/compare/kontent-ai-vs-strapi.md)\n- [Kontent.ai vs Webflow](https://www.anchorterminal.com/compare/kontent-ai-vs-webflow.md)\n- [Kontent.ai vs WordPress](https://www.anchorterminal.com/compare/kontent-ai-vs-wordpress.md)\n- [Payload vs Prismic](https://www.anchorterminal.com/compare/payload-vs-prismic.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kontent.ai vs Payload",
        "url": ""
      }
    ],
    "description": "Kontent.ai scores 70.5 (BB) to Payload's 55.2 (C) for content management. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kontent.ai BB 70.5",
      "Payload C 55.2",
      "scores"
    ],
    "h1": "Kontent.ai vs Payload",
    "image": "https://www.anchorterminal.com/assets/og/compare-kontent-ai-vs-payload.png",
    "path": "/compare/kontent-ai-vs-payload",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kontent.ai vs Payload for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kontent-ai-vs-payload"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 780
  },
  "version": 1
}
