Head to head · Cms content · October 2026 research run
Payload vs Sanity
Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.
Which one, for what
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Ahead on
- Payments & pricing, 45 against 40
Also in its favour
- Open source
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Sanity BB
Good for Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.
Ahead on
- Schema & documentation, 87 against 70
- Agent ergonomics, 74 against 64
- Security & auth, 67 against 57
- Maintenance & community, 89 against 78
- Transparency & trust, 87 against 62
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- No incidents deducted, where Payload loses 10 points for them
Watch for
Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them
Score by category
| Category | Weight this run | Payload | Sanity | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 78 | 77 | Payload +1 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 70 | 87 | Sanity +17 |
| Agent ergonomics | 13%16.2 | 64 | 74 | Sanity +10 |
| Security & auth | 14%17.5 | 57 | 67 | Sanity +10 |
| Payments & pricing | 10%12.5 | 45 | 40 | Payload +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 78 | 89 | Sanity +11 |
| Transparency & trust | 7%8.8 | 62 | 87 | Sanity +25 |
| Negative events | ≤15 | -10 | 0 | |
| Total | 55.2 · C | 73.7 · BB |
Facts side by side
| Fact | Payload | Sanity |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Payload CMS, Inc. (Figma) | Sanity US Inc. and Sanity AS |
| Hosted endpoint | no (local only) | https://api.sanity.io |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | API key | OAuth or key |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, @sanity/client and the agent toolkit on GitHub are MIT |
| Tools exposed | none | 53 |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| MCP registry | not listed | io.sanity.www/mcp |
| Last release | 2026-09-23 | 2026-10-02 |
| Terms last updated | no document linked | no date given |
| Privacy policy last updated | 2024-03-28 | no date given |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 45k stars, 1.1M npm/wk | 6.4k stars, 4.1M npm/wk |
Verdicts
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
Sanity
Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.
Before you call either
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
Sanity
- Pin a static dated version in every URL, such as
v2025-02-19. OmittingapiVersionin@sanity/clientfalls back tov1. - Validate documents against the schema yourself before an HTTP write, or run
sanity documents validateafterwards. The Content Lake does not enforce schema rules. - Back off on 429 for mutations yourself.
@sanity/clientretries queries five times but never retries mutations. The limit is 25 mutations a second per IP. - Over MCP, call
create_versionbeforepatch_documentswhen editing inside a release, then patch the returned version ID with the samereleaseId. - Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with
plan_limit_reached.
Questions
Which is better for AI agents, Payload or Sanity?
Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing.
Do Payload and Sanity need an API key?
Payload needs an API key. Sanity takes an API key or an OAuth sign-in.
Can an agent call Payload and Sanity without installing anything?
No hosted endpoint is listed for Payload. Sanity has a hosted endpoint at https://api.sanity.io.
Are Payload and Sanity open source?
Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Sanity.
Other comparisons with Payload or Sanity
Machine-readable
- This page as Markdown
/compare/payload-vs-sanity.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/payload.json·/api/v1/tools/sanity.json - From a terminal
anchor compare payload sanity(the CLI) - Over MCP
compare_tools {"a": "payload", "b": "sanity"}at/mcp, no key