Head to head · Cms content · October 2026 research run

Payload vs Sanity

Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.

Which one, for what

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Payments & pricing, 45 against 40

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Sanity BB

Good for Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.

Ahead on

  • Schema & documentation, 87 against 70
  • Agent ergonomics, 74 against 64
  • Security & auth, 67 against 57
  • Maintenance & community, 89 against 78
  • Transparency & trust, 87 against 62

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Payload loses 10 points for them

Watch for

Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them

Score by category

CategoryWeight this runPayloadSanityEdge
Reliability16%207877Payload +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27087Sanity +17
Agent ergonomics13%16.26474Sanity +10
Security & auth14%17.55767Sanity +10
Payments & pricing10%12.54540Payload +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87889Sanity +11
Transparency & trust7%8.86287Sanity +25
Negative events≤15-100
Total55.2 · C73.7 · BB

Facts side by side

FactPayloadSanity
KindHTTP APIHTTP API
VendorPayload CMS, Inc. (Figma)Sanity US Inc. and Sanity AS
Hosted endpointno (local only)https://api.sanity.io
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingFreeFreemium
x402nono
LicenceMIT for the core and the official packages. Enterprise add-ons are sold separately through salesProprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, @sanity/client and the agent toolkit on GitHub are MIT
Tools exposednone53
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedio.sanity.www/mcp
Last release2026-09-232026-10-02
Terms last updatedno document linkedno date given
Privacy policy last updated2024-03-28no date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity45k stars, 1.1M npm/wk6.4k stars, 4.1M npm/wk

Verdicts

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Sanity

Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.

Before you call either

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Sanity

  1. Pin a static dated version in every URL, such as v2025-02-19. Omitting apiVersion in @sanity/client falls back to v1.
  2. Validate documents against the schema yourself before an HTTP write, or run sanity documents validate afterwards. The Content Lake does not enforce schema rules.
  3. Back off on 429 for mutations yourself. @sanity/client retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.
  4. Over MCP, call create_version before patch_documents when editing inside a release, then patch the returned version ID with the same releaseId.
  5. Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with plan_limit_reached.

Questions

Which is better for AI agents, Payload or Sanity?

Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing.

Do Payload and Sanity need an API key?

Payload needs an API key. Sanity takes an API key or an OAuth sign-in.

Can an agent call Payload and Sanity without installing anything?

No hosted endpoint is listed for Payload. Sanity has a hosted endpoint at https://api.sanity.io.

Are Payload and Sanity open source?

Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Sanity.

Other comparisons with Payload or Sanity

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.