{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 597,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "Prismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing.",
    "b": {
      "slug": "prismic",
      "name": "Prismic",
      "vendor": "Prismic.io Inc.",
      "vendorUrl": "https://prismic.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Prismic is a hosted headless CMS and page builder. Agents write to it through the official hosted MCP server (16 tools that stage changes in releases) or the Migration, Asset and Types APIs with a write token.",
      "url": "https://www.anchorterminal.com/tools/prismic",
      "markdownUrl": "https://www.anchorterminal.com/tools/prismic.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/prismic.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prismic.json",
      "repo": "https://github.com/prismicio/prismic-client",
      "license": "Proprietary service under Prismic's Master Services Agreement. The JavaScript clients, the CLI and the agent skill on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.prismic.io/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@prismicio/client"
        },
        {
          "registry": "npm",
          "name": "@prismicio/migrate"
        },
        {
          "registry": "npm",
          "name": "prismic"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The MCP server signs a person in through browser OAuth (authorisation code with PKCE and dynamic client registration) and works with that person's repository role. A repository Administrator or Owner must activate Prismic MCP first. Sign-ins expire after 90 days. The Migration, Asset and Types APIs take a repository write token as a Bearer header with a `repository` header. A person creates the token in Settings, API \u0026 Security, Write APIs, or with `npx prismic token create --write`. No scopes or expiry for write tokens were found in the reviewed documentation. No app review or sales approval is needed.",
      "pricing": "freemium",
      "pricingNotes": "Free is $0 per repository and includes the Migration API, 1 user, 2 locales and 4 million API calls a month, with no card on file needed. Starter is $10, Small $25, Medium $150 and Platinum $675 a month per repository, billed annually. Enterprise is sold through sales. The launch note says Prismic MCP is currently free on every plan (https://prismic.io/pricing, checked 2026-10-09).",
      "priceSummary": "$10 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP docs, the write API references or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 16,
      "popularity": {
        "githubStars": 177,
        "npmWeekly": 236949,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://prismic.io/docs/mcp",
      "llmsTxt": "https://prismic.io/docs/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "cli",
        "graphql",
        "status-page"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.9,
        "grade": "C",
        "agentReady": false,
        "rank": 410,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 79,
          "payments": 35,
          "reliability": 78,
          "schema": 60,
          "security": 50,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "The hosted MCP server stages every write as a draft in a release, cannot delete, and publishes only when a user with the Publisher role asks. Write tokens for the Migration, Asset and Types APIs have no scopes, no OpenAPI file was found, writes are limited to one request a second, and the acceptable use policy forbids access by scripts.",
        "bestFor": "Teams already on Prismic who want an agent to bulk-edit, localise or migrate pages into releases for human review.",
        "strengths": [
          "Official hosted MCP server at `https://mcp.prismic.io/mcp` with 16 tools, free on every plan per the 8 June 2026 launch note",
          "MCP writes land as drafts in a release, the server has no delete tool, and `publish_release` needs the Publisher role",
          "OAuth on the MCP server with PKCE S256, dynamic client registration, refresh tokens and a revocation endpoint",
          "Free plan at $0 with the Migration API, 4 million API calls a month and unlimited documents, types and assets",
          "Root and docs `llms.txt`, and every docs page served as Markdown at the same URL plus `.md`"
        ],
        "weaknesses": [
          "No OpenAPI file for the Migration, Asset or Types APIs in the reviewed documentation. The Types API links a Postman collection",
          "Write tokens cover the whole repository with no scopes or expiry in the reviewed documentation, and the docs say they carry many privileges",
          "The Migration and Asset APIs each take one item a request at one request a second, with no idempotency keys",
          "The acceptable use policy forbids accessing the Solution by bots, programs or scripts, and the terms bar benchmarking without written consent",
          "Writer and Publisher roles start on the Medium plan ($150 a month). On Starter and Small every user is an Administrator"
        ],
        "agentNotes": [
          "Ask a repository Administrator to activate Prismic MCP in Settings first. Activation can take several minutes, and each environment has its own setting",
          "Call `list_repositories`, then `get_custom_type` or `get_shared_slice` for the empty content template before `create_document`",
          "Create a release with `create_release` and write into it. Call `publish_release` only on an explicit request, because a publish cannot be undone through MCP",
          "For the Migration API send `Authorization: Bearer \u003cwrite token\u003e` and a `repository` header, one page a request, one request a second, and keep each returned `id` for later PUT calls",
          "Upload media first (`upload_asset` or POST to `https://asset-api.prismic.io/assets`) and reference the asset `id` in image and media link fields"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.9
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 79,
          "payments": 35,
          "reliability": 78,
          "schema": 60,
          "security": 50,
          "transparency": 59
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install @prismicio/client @prismicio/migrate",
        "http": "curl --location --request GET 'https://customtypes.prismic.io/customtypes' \\\n  --header 'repository: your-repo-name' \\\n  --header 'Authorization: Bearer \u003ctoken\u003e'",
        "config": {
          "mcpServers": {
            "Prismic": {
              "url": "https://mcp.prismic.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/prismic"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Starter",
          "unit": "month",
          "usd": 10,
          "note": "per repository, billed annually, 3 users and 3 locales"
        },
        {
          "item": "Small",
          "unit": "month",
          "usd": 25,
          "note": "per repository, billed annually, 7 users and 4 locales"
        },
        {
          "item": "Medium",
          "unit": "month",
          "usd": 150,
          "note": "per repository, billed annually, 25 users, 5 million API calls, user roles"
        },
        {
          "item": "Platinum",
          "unit": "month",
          "usd": 675,
          "note": "per repository, billed annually, unlimited users, 10 million API calls"
        },
        {
          "item": "CDN bandwidth overage",
          "unit": "gb",
          "usd": 0.3,
          "note": "Starter, Small and Medium. $0.25 on Platinum"
        }
      ],
      "provenance": {
        "legalEntity": "Prismic.io Inc.",
        "domain": "prismic.io",
        "domainRegistered": "2013-06-05",
        "endpointOnVendorDomain": true,
        "terms": "https://prismic.io/legal/terms-of-service",
        "privacy": "https://prismic.io/legal/privacy",
        "statusPage": "https://status.prismic.io",
        "changelog": "https://prismic.io/updates",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms page is a Master Services Agreement, last updated 1 December 2025, between the customer and Prismic.io Inc., with notices to 185 Alewife Brook Parkway, Suite 210, Cambridge, Massachusetts 02138, USA. The legal page gives 9 rue de la Pierre Levée, 75011 Paris, France.",
          "The privacy policy, last updated 8 April 2026, covers the website and the Prismic Services, has a section on Prismic MCP, and links a self-service DPA and a sub-processor list, both PDFs we did not read.",
          "The AI Terms of Service (4 February 2026) name Prismic, Inc. and apply to AI functions.",
          "The MCP server answers at mcp.prismic.io and the write APIs at migration.prismic.io, asset-api.prismic.io and customtypes.prismic.io. The MCP docs name prismic-auth.eu.auth0.com as the sign-in server.",
          "prismic.io/.well-known/security.txt and prismic.io/security.txt return 404. The security page gives security@prismic.io.",
          "RDAP for prismic.io gives a registration date of 2013-06-05.",
          "robots.txt on prismic.io carries Content-Signal ai-train=no, search=yes, ai-input=yes."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/prismic.json",
      "live": {
        "slug": "prismic",
        "probe": {
          "target": "https://mcp.prismic.io/mcp",
          "method": "get",
          "lastAt": "2026-10-09T10:42:53.540899126Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 382,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 337,
          "p95ms24h": 390,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.prismic.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:42:00.249405282Z"
        },
        "updatedAt": "2026-10-09T10:42:53.540899126Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "Prismic.io Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.prismic.io/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "Proprietary service under Prismic's Master Services Agreement. The JavaScript clients, the CLI and the agent skill on GitHub are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "16",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2025-12-01",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "2026-04-08",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "177 stars, 237k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Prismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Payload or Prismic?"
      },
      {
        "answer": "Payload needs an API key. Prismic takes an API key or an OAuth sign-in.",
        "question": "Do Payload and Prismic need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. Prismic has a hosted endpoint at https://mcp.prismic.io/mcp.",
        "question": "Can an agent call Payload and Prismic without installing anything?"
      },
      {
        "answer": "Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Prismic.",
        "question": "Are Payload and Prismic open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 70 against 60",
          "Security \u0026 auth, 57 against 50",
          "Payments \u0026 pricing, 45 against 35"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Transparency \u0026 trust, 72 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where Payload loses 10 points for them"
        ],
        "goodFor": "Teams already on Prismic who want an agent to bulk-edit, localise or migrate pages into releases for human review.",
        "slug": "prismic",
        "watchFor": "No OpenAPI file for the Migration, Asset or Types APIs in the reviewed documentation. The Types API links a Postman collection"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-prismic.json",
        "title": "Contentstack vs Prismic",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-prismic.json",
        "title": "DatoCMS vs Prismic",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-prismic.json",
        "title": "Directus vs Prismic",
        "url": "https://www.anchorterminal.com/compare/directus-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-prismic.json",
        "title": "Ghost vs Prismic",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-payload.json",
        "title": "Hygraph vs Payload",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hygraph-vs-prismic.json",
        "title": "Hygraph vs Prismic",
        "url": "https://www.anchorterminal.com/compare/hygraph-vs-prismic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-sanity.json",
        "title": "Prismic vs Sanity",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-storyblok.json",
        "title": "Prismic vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-strapi.json",
        "title": "Prismic vs Strapi",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-webflow.json",
        "title": "Prismic vs Webflow",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismic-vs-wordpress.json",
        "title": "Prismic vs WordPress",
        "url": "https://www.anchorterminal.com/compare/prismic-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 0,
        "edge": "",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "prismic": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "payload",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "prismic": 60,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "payload",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "prismic": 63,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "payload",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "prismic": 50,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "prismic": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "prismic",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "prismic": 79,
        "weight": 7
      },
      {
        "by": 10,
        "edge": "prismic",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "prismic": 72,
        "weight": 7
      }
    ],
    "summary": "Prismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "prismic": "The hosted MCP server stages every write as a draft in a release, cannot delete, and publishes only when a user with the Publisher role asks. Write tokens for the Migration, Asset and Types APIs have no scopes, no OpenAPI file was found, writes are limited to one request a second, and the acceptable use policy forbids access by scripts."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-prismic",
    "json": "https://www.anchorterminal.com/compare/payload-vs-prismic.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-prismic.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-prismic.min.md"
  },
  "markdown": "Prismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #597 of 842. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Prismic: grade C, 61.9/100, rank #410 of 842. Markdown https://www.anchorterminal.com/tools/prismic.md · JSON https://www.anchorterminal.com/api/v1/tools/prismic.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Schema \u0026 documentation, 70 against 60\n- Security \u0026 auth, 57 against 50\n- Payments \u0026 pricing, 45 against 35\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### Prismic (C)\n\nGood for: Teams already on Prismic who want an agent to bulk-edit, localise or migrate pages into releases for human review.\n\nAhead on:\n- Transparency \u0026 trust, 72 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where Payload loses 10 points for them\n\nWatch for: No OpenAPI file for the Migration, Asset or Types APIs in the reviewed documentation. The Types API links a Postman collection\n\n\n## Score by category\n\n| Category | Weight | Payload | Prismic | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 78 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 60 | Payload +10 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 63 | Payload +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 50 | Payload +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 35 | Payload +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 79 | Prismic +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 72 | Prismic +10 |\n| Negative events | ≤15 | -10 | 0 | |\n| **Total** | | **55.2 · C** | **61.9 · C** | |\n\n## Facts side by side\n\n| Fact | Payload | Prismic |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | Prismic.io Inc. |\n| Hosted endpoint | no (local only) | `https://mcp.prismic.io/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | Proprietary service under Prismic's Master Services Agreement. The JavaScript clients, the CLI and the agent skill on GitHub are Apache-2.0 |\n| Tools exposed | none | 16 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-23 | 2026-10-08 |\n| Terms last updated | no document linked | 2025-12-01 |\n| Privacy policy last updated | 2024-03-28 | 2026-04-08 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 45k stars, 1.1M npm/wk | 177 stars, 237k npm/wk |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**Prismic.** The hosted MCP server stages every write as a draft in a release, cannot delete, and publishes only when a user with the Publisher role asks. Write tokens for the Migration, Asset and Types APIs have no scopes, no OpenAPI file was found, writes are limited to one request a second, and the acceptable use policy forbids access by scripts.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### Prismic\n\n1. Ask a repository Administrator to activate Prismic MCP in Settings first. Activation can take several minutes, and each environment has its own setting\n2. Call `list_repositories`, then `get_custom_type` or `get_shared_slice` for the empty content template before `create_document`\n3. Create a release with `create_release` and write into it. Call `publish_release` only on an explicit request, because a publish cannot be undone through MCP\n4. For the Migration API send `Authorization: Bearer \u003cwrite token\u003e` and a `repository` header, one page a request, one request a second, and keep each returned `id` for later PUT calls\n5. Upload media first (`upload_asset` or POST to `https://asset-api.prismic.io/assets`) and reference the asset `id` in image and media link fields\n\n## Questions\n\n### Which is better for AI agents, Payload or Prismic?\n\nPrismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing.\n\n### Do Payload and Prismic need an API key?\n\nPayload needs an API key. Prismic takes an API key or an OAuth sign-in.\n\n### Can an agent call Payload and Prismic without installing anything?\n\nNo hosted endpoint is listed for Payload. Prismic has a hosted endpoint at https://mcp.prismic.io/mcp.\n\n### Are Payload and Prismic open source?\n\nPayload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Prismic.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-prismic.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-prismic.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"prismic\"}`. From a terminal: `anchor compare payload prismic`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/prismic.json\n\n## Other comparisons with Payload or Prismic\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Prismic](https://www.anchorterminal.com/compare/contentstack-vs-prismic.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs Prismic](https://www.anchorterminal.com/compare/datocms-vs-prismic.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Prismic](https://www.anchorterminal.com/compare/directus-vs-prismic.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Prismic](https://www.anchorterminal.com/compare/ghost-vs-prismic.md)\n- [Hygraph vs Payload](https://www.anchorterminal.com/compare/hygraph-vs-payload.md)\n- [Hygraph vs Prismic](https://www.anchorterminal.com/compare/hygraph-vs-prismic.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Prismic vs Sanity](https://www.anchorterminal.com/compare/prismic-vs-sanity.md)\n- [Prismic vs Storyblok](https://www.anchorterminal.com/compare/prismic-vs-storyblok.md)\n- [Prismic vs Strapi](https://www.anchorterminal.com/compare/prismic-vs-strapi.md)\n- [Prismic vs Webflow](https://www.anchorterminal.com/compare/prismic-vs-webflow.md)\n- [Prismic vs WordPress](https://www.anchorterminal.com/compare/prismic-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs Prismic",
        "url": ""
      }
    ],
    "description": "Prismic scores 61.9 (C) on agent readiness against Payload's 55.2 (C), and leads in 2 of 7 scored categories. Payload leads on schema \u0026 documentation, security \u0026 auth and payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "Prismic C 61.9",
      "scores"
    ],
    "h1": "Payload vs Prismic",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-prismic.png",
    "path": "/compare/payload-vs-prismic",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs Prismic for AI agents, C 55.2 vs C 61.9 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/payload-vs-prismic"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
