{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "sanity",
      "name": "Sanity",
      "vendor": "Sanity US Inc. and Sanity AS",
      "vendorUrl": "https://www.sanity.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Sanity is a hosted headless CMS. Content is stored as JSON documents in the Content Lake, queried with GROQ and edited in the open-source Sanity Studio. Agents reach it through the HTTP API or the hosted MCP server at mcp.sanity.io.",
      "url": "https://www.anchorterminal.com/tools/sanity",
      "markdownUrl": "https://www.anchorterminal.com/tools/sanity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sanity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sanity.json",
      "repo": "https://github.com/sanity-io/sanity",
      "license": "Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.sanity.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@sanity/client"
        },
        {
          "registry": "npm",
          "name": "sanity"
        },
        {
          "registry": "packagist",
          "name": "sanity/sanity-php"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The HTTP API takes a Bearer token. Robot tokens are created in sanity.io/manage, with the CLI or through the Access API, carry a role (Viewer and Editor tokens on every plan), last until deleted unless given an expiry, and are shown once. Personal tokens last a year and act as the user. The MCP server at mcp.sanity.io uses OAuth with PKCE and dynamic client registration by default, with one scope named `global` and sessions of about 7 days, or accepts a token in the `Authorization` header. Custom roles that limit a token to a dataset or document type are Enterprise only. No app review or sales approval is needed.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with no card, 20 seats, 10,000 documents, 250,000 API requests and 1 million API CDN requests a month, and hard caps that answer 402 when reached. Growth is $15 a seat a month with overage billed per unit. Enterprise is priced by sales. New projects get a Growth trial with Free plan quotas. An agent can start on the Free plan once a person has created the account (checked 2026-10-07).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation (llms-full.txt) or on the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 53,
      "popularity": {
        "githubStars": 6352,
        "npmWeekly": 4069926,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.sanity.io/docs",
      "llmsTxt": "https://www.sanity.io/docs/llms.txt",
      "openapi": "https://www.sanity.io/docs/api/openapi",
      "registryName": "io.sanity.www/mcp",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.schema",
        "cms.localisation"
      ],
      "tags": [
        "hosted",
        "headless-cms",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "groq",
        "graphql",
        "javascript",
        "php",
        "free-tier",
        "status-page",
        "soc2",
        "open-source-studio"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.7,
        "grade": "BB",
        "agentReady": true,
        "rank": 73,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 89,
          "payments": 40,
          "reliability": 77,
          "schema": 87,
          "security": 67,
          "transparency": 87
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.",
        "bestFor": "Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.",
        "strengths": [
          "26 public OpenAPI specs covering 225 operations at www.sanity.io/docs/api/openapi, plus llms.txt and a Markdown copy of every documentation page",
          "MCP `patch_documents` saves to a draft or release version, never to published content, and `publish_documents` is a separate tool",
          "Mutations and actions accept `dryRun`, a caller-set `transactionId` and `ifRevisionID` for optimistic locking",
          "Free plan with 10,000 documents and 250,000 API requests a month, with Growth overage rates published per unit",
          "MCP server listed in the official MCP registry as io.sanity.www/mcp, with 30 versions published there between 15 July and 2 October 2026"
        ],
        "weaknesses": [
          "Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them",
          "Custom roles scoped to a dataset or document type are an Enterprise feature. Robot tokens on other plans take a built-in role across the project",
          "The MCP OAuth server lists one scope, `global`, and the server documents 53 tools with no toolset or read-only mode",
          "A status incident on 22 July 2026, marked major on api.sanity.io, stayed open for 6 hours 20 minutes with two recurrences",
          "The vulnerability disclosure page says the bug bounty pilot has closed and no rewards are paid"
        ],
        "agentNotes": [
          "Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`.",
          "Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules.",
          "Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.",
          "Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`.",
          "Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.7
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 89,
          "payments": 40,
          "reliability": 77,
          "schema": 87,
          "security": 67,
          "transparency": 79
        },
        "provenanceScore": 95
      },
      "connect": {
        "install": "npx sanity@latest mcp configure",
        "http": "curl -H \"Authorization: Bearer \u003ctoken\u003e\" \"https://\u003cproject\u003e.api.sanity.io/v2021-06-07/data/query/production?query=*\"",
        "claudeCode": "claude mcp add Sanity -t http https://mcp.sanity.io --scope user",
        "config": {
          "mcpServers": {
            "Sanity": {
              "type": "http",
              "url": "https://mcp.sanity.io"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/sanity"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "seat-month",
          "usd": 15,
          "note": "up to 50 seats"
        },
        {
          "item": "API requests over quota (Growth)",
          "unit": "1k-requests",
          "usd": 0.04,
          "note": "$1 per 25,000, after 250,000 a month included"
        },
        {
          "item": "API CDN requests over quota (Growth)",
          "unit": "1k-requests",
          "usd": 0.004,
          "note": "$1 per 250,000, after 1 million a month included"
        },
        {
          "item": "Bandwidth over quota (Growth)",
          "unit": "gb",
          "usd": 0.3,
          "note": "after 100 GB a month included"
        },
        {
          "item": "Increased quota add-on (Growth)",
          "unit": "month",
          "usd": 299,
          "note": "50,000 documents, 1 million API requests, 5 million API CDN requests"
        },
        {
          "item": "Extra dataset (Growth)",
          "unit": "month",
          "usd": 999,
          "note": "per dataset"
        }
      ],
      "provenance": {
        "legalEntity": "Sanity US Inc. (with Sanity AS)",
        "domain": "sanity.io",
        "domainRegistered": "2015-01-07",
        "endpointOnVendorDomain": true,
        "terms": "https://www.sanity.io/legal/tos",
        "privacy": "https://www.sanity.io/legal/privacy",
        "statusPage": "https://www.sanity-status.com",
        "changelog": "https://www.sanity.io/docs/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-07",
        "notes": [
          "The terms of service dated 12 August 2026 are entered into with Sanity US Inc. The privacy policy dated 4 May 2026 is that of Sanity AS and Sanity US Inc. Growth has its own terms at sanity.io/legal/tos-growth, dated 26 March 2026.",
          "The API answers at https://\u003cprojectId\u003e.api.sanity.io and https://api.sanity.io, and the MCP server at https://mcp.sanity.io.",
          "www.sanity.io/.well-known/security.txt names security@sanity.io and the disclosure policy at sanity.io/responsible-disclosure, and has no Expires field.",
          "status.sanity.io answers with the same Statuspage as www.sanity-status.com.",
          "RDAP for sanity.io gives a registration date of 2015-01-07."
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/sanity.json",
      "live": {
        "slug": "sanity",
        "probe": {
          "target": "https://api.sanity.io",
          "method": "get",
          "lastAt": "2026-10-08T21:12:20.810060738Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 47,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 36,
          "p95ms24h": 81,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.sanity-status.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:25.353474741Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "sanity-io/sanity",
            "version": "v6.18.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:28:11.279439468Z"
          },
          {
            "registry": "npm",
            "name": "@sanity/client",
            "version": "8.9.0",
            "seenAt": "2026-10-08T16:28:08.05519452Z"
          },
          {
            "registry": "npm",
            "name": "sanity",
            "version": "6.18.0",
            "seenAt": "2026-10-08T16:28:09.308419229Z"
          }
        ],
        "githubStars": 6352,
        "npmWeekly": 4069926,
        "securityTxt": {
          "url": "https://sanity.io/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:50.777207368Z"
        },
        "pages": [
          {
            "url": "https://www.sanity.io/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:11.065534137Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "906020038702"
          },
          {
            "url": "https://www.sanity.io/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:14.320679574Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0a780309f28"
          },
          {
            "url": "https://www.sanity.io/legal/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:15.452818667Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "68f22ec5d44d"
          }
        ],
        "updatedAt": "2026-10-08T21:12:20.810060738Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "Sanity US Inc. and Sanity AS",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.sanity.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "53",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.sanity.www/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "6.4k stars, 4.1M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Payload or Sanity?"
      },
      {
        "answer": "Payload needs an API key. Sanity takes an API key or an OAuth sign-in.",
        "question": "Do Payload and Sanity need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. Sanity has a hosted endpoint at https://api.sanity.io.",
        "question": "Can an agent call Payload and Sanity without installing anything?"
      },
      {
        "answer": "Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Sanity.",
        "question": "Are Payload and Sanity open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 40"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 70",
          "Agent ergonomics, 74 against 64",
          "Security \u0026 auth, 67 against 57",
          "Maintenance \u0026 community, 89 against 78",
          "Transparency \u0026 trust, 87 against 62"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Payload loses 10 points for them"
        ],
        "goodFor": "Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.",
        "slug": "sanity",
        "watchFor": "Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-sanity.json",
        "title": "Contentstack vs Sanity",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-sanity.json",
        "title": "DatoCMS vs Sanity",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-sanity.json",
        "title": "Directus vs Sanity",
        "url": "https://www.anchorterminal.com/compare/directus-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-sanity.json",
        "title": "Ghost vs Sanity",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-storyblok.json",
        "title": "Sanity vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-strapi.json",
        "title": "Sanity vs Strapi",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-webflow.json",
        "title": "Sanity vs Webflow",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-wordpress.json",
        "title": "Sanity vs WordPress",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "payload",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "sanity": 77,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "sanity",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "sanity": 87,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "sanity",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "sanity": 74,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "sanity",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "sanity": 67,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "sanity": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "sanity",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "sanity": 89,
        "weight": 7
      },
      {
        "by": 25,
        "edge": "sanity",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "sanity": 87,
        "weight": 7
      }
    ],
    "summary": "Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "sanity": "Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-sanity",
    "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-sanity.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-sanity.min.md"
  },
  "markdown": "Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Sanity: grade BB, 73.7/100, rank #73 of 722. Markdown https://www.anchorterminal.com/tools/sanity.md · JSON https://www.anchorterminal.com/api/v1/tools/sanity.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 40\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### Sanity (BB)\n\nGood for: Teams that model content as structured documents and want an agent to draft, patch and stage changes in releases for a person to publish.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 70\n- Agent ergonomics, 74 against 64\n- Security \u0026 auth, 67 against 57\n- Maintenance \u0026 community, 89 against 78\n- Transparency \u0026 trust, 87 against 62\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Payload loses 10 points for them\n\nWatch for: Schema validation rules run only in Sanity Studio. The HTTP mutation API accepts a document without checking them\n\n\n## Score by category\n\n| Category | Weight | Payload | Sanity | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 77 | Payload +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 87 | Sanity +17 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 74 | Sanity +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 67 | Sanity +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 40 | Payload +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 89 | Sanity +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 87 | Sanity +25 |\n| Negative events | ≤15 | -10 | 0 | |\n| **Total** | | **55.2 · C** | **73.7 · BB** | |\n\n## Facts side by side\n\n| Fact | Payload | Sanity |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | Sanity US Inc. and Sanity AS |\n| Hosted endpoint | no (local only) | `https://api.sanity.io` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | Proprietary hosted service under Sanity's terms of service. Sanity Studio, the CLI, `@sanity/client` and the agent toolkit on GitHub are MIT |\n| Tools exposed | none | 53 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `io.sanity.www/mcp` |\n| Last release | 2026-09-23 | 2026-10-02 |\n| Terms last updated | no document linked | no date given |\n| Privacy policy last updated | 2024-03-28 | no date given |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 45k stars, 1.1M npm/wk | 6.4k stars, 4.1M npm/wk |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**Sanity.** Sanity publishes 26 OpenAPI specs covering 225 operations, and its hosted MCP server saves edits to drafts or release versions, with publishing as a separate call. The Content Lake does not run schema validation on API writes, and custom roles that limit a token to one dataset or document type are sold only on Enterprise plans.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### Sanity\n\n1. Pin a static dated version in every URL, such as `v2025-02-19`. Omitting `apiVersion` in `@sanity/client` falls back to `v1`.\n2. Validate documents against the schema yourself before an HTTP write, or run `sanity documents validate` afterwards. The Content Lake does not enforce schema rules.\n3. Back off on 429 for mutations yourself. `@sanity/client` retries queries five times but never retries mutations. The limit is 25 mutations a second per IP.\n4. Over MCP, call `create_version` before `patch_documents` when editing inside a release, then patch the returned version ID with the same `releaseId`.\n5. Use GROQ projections and slices to size results. MCP query responses are limited to 64 KiB, and a blocked Free project answers 402 with `plan_limit_reached`.\n\n## Questions\n\n### Which is better for AI agents, Payload or Sanity?\n\nSanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do Payload and Sanity need an API key?\n\nPayload needs an API key. Sanity takes an API key or an OAuth sign-in.\n\n### Can an agent call Payload and Sanity without installing anything?\n\nNo hosted endpoint is listed for Payload. Sanity has a hosted endpoint at https://api.sanity.io.\n\n### Are Payload and Sanity open source?\n\nPayload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Sanity.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-sanity.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-sanity.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"sanity\"}`. From a terminal: `anchor compare payload sanity`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/sanity.json\n\n## Other comparisons with Payload or Sanity\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Sanity](https://www.anchorterminal.com/compare/contentstack-vs-sanity.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs Sanity](https://www.anchorterminal.com/compare/datocms-vs-sanity.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Sanity](https://www.anchorterminal.com/compare/directus-vs-sanity.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Sanity](https://www.anchorterminal.com/compare/ghost-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Sanity vs Storyblok](https://www.anchorterminal.com/compare/sanity-vs-storyblok.md)\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md)\n- [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md)\n- [Sanity vs WordPress](https://www.anchorterminal.com/compare/sanity-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs Sanity",
        "url": ""
      }
    ],
    "description": "Sanity scores 73.7 (BB) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "Sanity BB 73.7",
      "scores"
    ],
    "h1": "Payload vs Sanity",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-sanity.png",
    "path": "/compare/payload-vs-sanity",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs Sanity for AI agents, C 55.2 vs BB 73.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 780
  },
  "version": 1
}
