{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "storyblok",
      "name": "Storyblok",
      "vendor": "Storyblok GmbH",
      "vendorUrl": "https://www.storyblok.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Storyblok is a hosted headless CMS with a visual editor. Agents write to it through the Management API (stories, components, assets, releases, workflows) or the official hosted MCP server, which wraps that API in seven tools.",
      "url": "https://www.anchorterminal.com/tools/storyblok",
      "markdownUrl": "https://www.anchorterminal.com/tools/storyblok.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/storyblok.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/storyblok.json",
      "repo": "https://github.com/storyblok/monoblok",
      "license": "Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mapi.storyblok.com/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@storyblok/management-api-client"
        },
        {
          "registry": "npm",
          "name": "storyblok-js-client"
        },
        {
          "registry": "npm",
          "name": "storyblok"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Management API takes a personal access token or an OAuth token in the request header. A person creates the token in account settings and picks scopes (16 groups such as stories, assets and components, on a read, write and publish hierarchy), the spaces it covers and an expiry date. The MCP server uses browser OAuth with PKCE and dynamic client registration, where the person picks permissions and spaces on a consent screen, or the same token as a Bearer header. No app review or sales approval is needed. The changelog describes OAuth scoped grants for custom integrations as a Premium and Enterprise feature. Content Delivery API tokens are read-only and travel in the `token` query parameter.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with no card and includes the Management API, 100,000 API requests a month, 1 seat and 2 locales. Growth is $99 a month and Growth Plus $349 a month billed monthly. Premium and Elite are sold through sales. New spaces start with a 45-day Growth Plus trial. On Growth, extra API requests cost $10 per million and extra seats $15 each (https://www.storyblok.com/pricing, checked 2026-10-07).",
      "priceSummary": "$99 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Management API docs, the MCP server docs or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 7,
      "popularity": {
        "githubStars": 68,
        "npmWeekly": 432535,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://www.storyblok.com/docs/api/management",
      "llmsTxt": "https://www.storyblok.com/llms.txt",
      "openapi": "https://www.storyblok.com/docs/openapi-spec/cdn-v2.openapi.yaml",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.localisation",
        "cms.schema"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "closed-source",
        "no-card",
        "free-tier",
        "llms-txt",
        "webhooks",
        "typescript",
        "php",
        "status-page",
        "iso27001"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.7,
        "grade": "B",
        "agentReady": false,
        "rank": 202,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 80,
          "payments": 35,
          "reliability": 79,
          "schema": 68,
          "security": 73,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "8 April 2026. Storyblok fixed a flaw where the Webhook and Webhook Logs endpoints of the Management API didn't enforce the Admin and Owner restriction the UI applies, so Editor and Restricted roles could manage webhooks by API. It was fixed and disclosed in the changelog, so the deduction is small (https://www.storyblok.com/cl/2026-april-security-fix-webhook-api-now-aligned-with-ui-access-controls)."
        ],
        "verdict": "The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.",
        "bestFor": "Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.",
        "strengths": [
          "Official hosted MCP server at mcp.storyblok.com/mcp with seven tools (search, describe, three execute tools, two for asset upload) and a `fields` filter that trims responses",
          "OAuth with PKCE, dynamic client registration and 29 scopes on a read, write and publish hierarchy, chosen per space on a consent screen",
          "Personal access tokens take scopes, a space list and an expiry date since 27 May 2026, and unscoped tokens are revoked on 30 November 2026",
          "Free Starter plan with no card, 100,000 API requests a month and Management API access on every plan",
          "Every docs page is served as Markdown by adding .md, with request examples in nine languages"
        ],
        "weaknesses": [
          "The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)",
          "Management API limit is 3 requests a second on Starter and 6 on paid plans, with no idempotency keys in the reviewed documentation",
          "The status page monitors four delivery services and has no Management API or MCP monitor",
          "On 8 April 2026 Storyblok fixed webhook endpoints that had let Editor and Restricted roles manage webhooks through the API",
          "Version history is kept for 1 day on Starter and 30 days on Growth, so a rollback depends on the plan"
        ],
        "agentNotes": [
          "Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails",
          "Create stories without `publish` to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it",
          "Write translations as `field__i18n__\u003ccode\u003e` keys inside the same content object, and set the component field to translatable first",
          "Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl",
          "Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.7
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 80,
          "payments": 35,
          "reliability": 79,
          "schema": 68,
          "security": 73,
          "transparency": 73
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npm install @storyblok/management-api-client",
        "http": "curl \"https://mapi.storyblok.com/v1/spaces/$SPACE_ID/stories/\" \\\n  -H \"Authorization: $STORYBLOK_PERSONAL_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http Storyblok https://mcp.storyblok.com/mcp",
        "config": {
          "mcpServers": {
            "Storyblok": {
              "type": "http",
              "url": "https://mcp.storyblok.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/storyblok"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Growth",
          "unit": "month",
          "usd": 99,
          "note": "billed monthly, $90.75 billed yearly, 5 seats and 1M API requests included"
        },
        {
          "item": "Growth Plus",
          "unit": "month",
          "usd": 349,
          "note": "billed monthly, $319.91 billed yearly, 15 seats and 4M API requests included"
        },
        {
          "item": "Additional seat",
          "unit": "seat-month",
          "usd": 15,
          "note": "Starter (up to 2 seats) and Growth (up to 10)"
        },
        {
          "item": "Additional API requests on Growth",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "sold as $10 per 1M, up to 5M a month"
        }
      ],
      "provenance": {
        "legalEntity": "Storyblok GmbH",
        "domain": "storyblok.com",
        "domainRegistered": "2015-08-15",
        "endpointOnVendorDomain": true,
        "terms": "https://www.storyblok.com/legal/terms",
        "privacy": "https://www.storyblok.com/legal/privacy-policy",
        "statusPage": "https://uptime.storyblok.com",
        "changelog": "https://www.storyblok.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The legal notice names Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria, company register number FN 479743 f, Regional Court Linz.",
          "The Management API answers on storyblok.com subdomains and the MCP server at mcp.storyblok.com. Spaces in China use app.storyblokchina.cn.",
          "security.txt returns 404 on www.storyblok.com, storyblok.com and mapi.storyblok.com. The privacy policy gives security@storyblok.com for security matters.",
          "The terms page was last updated on 2 October 2026 and links separate self-service and enterprise terms. The self-service terms are governed by Austrian law.",
          "RDAP for storyblok.com gives a registration date of 2015-08-15.",
          "The status page runs on UptimeRobot with four monitors (Content Delivery API v1 and v2, GraphQL API, Image Service)."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/storyblok.json",
      "live": {
        "slug": "storyblok",
        "probe": {
          "target": "https://mapi.storyblok.com/v1",
          "method": "get",
          "lastAt": "2026-10-08T21:12:22.51797594Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 50,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 56,
          "p95ms24h": 99,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://uptime.storyblok.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:14.077416069Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "storyblok/monoblok",
            "version": "storyblok@4.23.4",
            "released": "2026-10-02",
            "seenAt": "2026-10-08T16:30:30.68015309Z"
          },
          {
            "registry": "npm",
            "name": "@storyblok/management-api-client",
            "version": "0.9.1",
            "seenAt": "2026-10-08T16:30:26.446005464Z"
          },
          {
            "registry": "npm",
            "name": "storyblok",
            "version": "4.23.4",
            "seenAt": "2026-10-08T16:30:28.73366054Z"
          },
          {
            "registry": "npm",
            "name": "storyblok-js-client",
            "version": "7.7.7",
            "seenAt": "2026-10-08T16:30:27.249684993Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 94500,
        "securityTxt": {
          "url": "https://storyblok.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:51.218593751Z"
        },
        "pages": [
          {
            "url": "https://www.storyblok.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:42.335720318Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5ca6efffc344"
          },
          {
            "url": "https://www.storyblok.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:48.641769602Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f2ecb91f1df2"
          },
          {
            "url": "https://www.storyblok.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:44.809888853Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "24506da32465"
          },
          {
            "url": "https://www.storyblok.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:46.89854338Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b848b65d0369"
          }
        ],
        "updatedAt": "2026-10-08T21:12:22.51797594Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "Storyblok GmbH",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mapi.storyblok.com/v1",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "7",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "2025-10-06",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "68 stars, 433k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Payload or Storyblok?"
      },
      {
        "answer": "Payload needs an API key. Storyblok takes an API key or an OAuth sign-in.",
        "question": "Do Payload and Storyblok need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. Storyblok has a hosted endpoint at https://mapi.storyblok.com/v1.",
        "question": "Can an agent call Payload and Storyblok without installing anything?"
      },
      {
        "answer": "Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Storyblok.",
        "question": "Are Payload and Storyblok open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 35"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 78 against 64",
          "Security \u0026 auth, 73 against 57",
          "Transparency \u0026 trust, 80 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.",
        "slug": "storyblok",
        "watchFor": "The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok.json",
        "title": "Contentstack vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-storyblok.json",
        "title": "DatoCMS vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-storyblok.json",
        "title": "Directus vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/directus-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-storyblok.json",
        "title": "Ghost vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-storyblok.json",
        "title": "Sanity vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-strapi.json",
        "title": "Storyblok vs Strapi",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-webflow.json",
        "title": "Storyblok vs Webflow",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress.json",
        "title": "Storyblok vs WordPress",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "storyblok",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "storyblok": 79,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "payload",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "storyblok": 68,
        "weight": 13
      },
      {
        "by": 14,
        "edge": "storyblok",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "storyblok": 78,
        "weight": 13
      },
      {
        "by": 16,
        "edge": "storyblok",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "storyblok": 73,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "storyblok": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "storyblok",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "storyblok": 80,
        "weight": 7
      },
      {
        "by": 18,
        "edge": "storyblok",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "storyblok": 80,
        "weight": 7
      }
    ],
    "summary": "Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "storyblok": "The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-storyblok",
    "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-storyblok.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-storyblok.min.md"
  },
  "markdown": "Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Storyblok: grade B, 67.7/100, rank #202 of 722. Markdown https://www.anchorterminal.com/tools/storyblok.md · JSON https://www.anchorterminal.com/api/v1/tools/storyblok.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 35\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### Storyblok (B)\n\nGood for: Teams already on Storyblok who want an agent to draft, translate and publish stories or change component schemas under scoped, per-space permissions.\n\nAhead on:\n- Agent ergonomics, 78 against 64\n- Security \u0026 auth, 73 against 57\n- Transparency \u0026 trust, 80 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: The Management API's OpenAPI spec sits in a private repository. Only the Content Delivery API has a public spec (OpenAPI 3.1, 14 operations)\n\n\n## Score by category\n\n| Category | Weight | Payload | Storyblok | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 79 | Storyblok +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 68 | Payload +2 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 78 | Storyblok +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 73 | Storyblok +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 35 | Payload +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 80 | Storyblok +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 80 | Storyblok +18 |\n| Negative events | ≤15 | -10 | -3 | |\n| **Total** | | **55.2 · C** | **67.7 · B** | |\n\n## Facts side by side\n\n| Fact | Payload | Storyblok |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | Storyblok GmbH |\n| Hosted endpoint | no (local only) | `https://mapi.storyblok.com/v1` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | Proprietary service under Storyblok's terms. The SDKs, API clients and CLI in storyblok/monoblok are MIT |\n| Tools exposed | none | 7 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-23 | 2026-10-02 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | 2024-03-28 | 2025-10-06 |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 45k stars, 1.1M npm/wk | 68 stars, 433k npm/wk |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**Storyblok.** The hosted MCP server covers the whole Management API with seven tools, OAuth scopes split into read, write and publish per space, and a confirmation step on deletes. The Management API has no public OpenAPI spec, no idempotency keys and no monitor on the public status page, and publishing is a GET request.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### Storyblok\n\n1. Pick the base URL by the space's region (mapi.storyblok.com for the EU, api-us, api-ca or api-ap otherwise). A token sent to the wrong region fails\n2. Create stories without `publish` to keep them as drafts, then call the publish endpoint. It is a GET, so never prefetch or blindly retry it\n3. Write translations as `field__i18n__\u003ccode\u003e` keys inside the same content object, and set the component field to translatable first\n4. Upload an asset in three steps (signed response, POST to S3, finish upload). Through MCP the S3 step needs shell access for curl\n5. Stay under 3 calls a second on Starter and 6 on paid plans, and back off exponentially on 429. Saves that break a field's max_length return 422\n\n## Questions\n\n### Which is better for AI agents, Payload or Storyblok?\n\nStoryblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do Payload and Storyblok need an API key?\n\nPayload needs an API key. Storyblok takes an API key or an OAuth sign-in.\n\n### Can an agent call Payload and Storyblok without installing anything?\n\nNo hosted endpoint is listed for Payload. Storyblok has a hosted endpoint at https://mapi.storyblok.com/v1.\n\n### Are Payload and Storyblok open source?\n\nPayload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Storyblok.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-storyblok.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-storyblok.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"storyblok\"}`. From a terminal: `anchor compare payload storyblok`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/storyblok.json\n\n## Other comparisons with Payload or Storyblok\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Storyblok](https://www.anchorterminal.com/compare/contentstack-vs-storyblok.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs Storyblok](https://www.anchorterminal.com/compare/datocms-vs-storyblok.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Storyblok](https://www.anchorterminal.com/compare/directus-vs-storyblok.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Storyblok](https://www.anchorterminal.com/compare/ghost-vs-storyblok.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Sanity vs Storyblok](https://www.anchorterminal.com/compare/sanity-vs-storyblok.md)\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md)\n- [Storyblok vs Webflow](https://www.anchorterminal.com/compare/storyblok-vs-webflow.md)\n- [Storyblok vs WordPress](https://www.anchorterminal.com/compare/storyblok-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs Storyblok",
        "url": ""
      }
    ],
    "description": "Storyblok scores 67.7 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "Storyblok B 67.7",
      "scores"
    ],
    "h1": "Payload vs Storyblok",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-storyblok.png",
    "path": "/compare/payload-vs-storyblok",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs Storyblok for AI agents, C 55.2 vs B 67.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
