Head to head · Cms content · October 2026 research run

Payload vs Storyblok

Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.

Which one, for what

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Payments & pricing, 45 against 35

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Storyblok B

Good for Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.

Ahead on

  • Agent ergonomics, 78 against 64
  • Security & auth, 73 against 57
  • Transparency & trust, 80 against 62

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card

Watch for

The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)

Score by category

CategoryWeight this runPayloadStoryblokEdge
Reliability16%207879Storyblok +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27068Payload +2
Agent ergonomics13%16.26478Storyblok +14
Security & auth14%17.55773Storyblok +16
Payments & pricing10%12.54535Payload +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87880Storyblok +2
Transparency & trust7%8.86280Storyblok +18
Negative events≤15-10-3
Total55.2 · C67.7 · B

Facts side by side

FactPayloadStoryblok
KindHTTP APIHTTP API
VendorPayload CMS, Inc. (Figma)Storyblok GmbH
Hosted endpointno (local only)https://mapi.storyblok.com/v1
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingFreeFreemium
x402nono
LicenceMIT for the core and the official packages. Enterprise add-ons are sold separately through salesProprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT
Tools exposednone7
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-232026-10-02
Terms last updatedno document linkedcouldn't be read
Privacy policy last updated2024-03-282025-10-06
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity45k stars, 1.1M npm/wk68 stars, 433k npm/wk

Verdicts

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Storyblok

The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.

Before you call either

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Storyblok

  1. Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails
  2. Create stories without publish to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it
  3. Write translations as field__i18n__<code> keys inside the same content object, and set the component field to translatable first
  4. Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl
  5. Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422

Questions

Which is better for AI agents, Payload or Storyblok?

Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments & pricing.

Do Payload and Storyblok need an API key?

Payload needs an API key. Storyblok takes an API key or an OAuth sign-in.

Can an agent call Payload and Storyblok without installing anything?

No hosted endpoint is listed for Payload. Storyblok has a hosted endpoint at https://mapi.storyblok.com/v1.

Are Payload and Storyblok open source?

Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Storyblok.

Other comparisons with Payload or Storyblok

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.