{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "Strapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category.",
    "b": {
      "slug": "strapi",
      "name": "Strapi",
      "vendor": "Strapi, Inc.",
      "vendorUrl": "https://strapi.io",
      "kind": "http-api",
      "category": "cms",
      "summary": "Strapi is an open-source headless CMS for Node.js that its owner hosts, with a paid cloud. Agents create, localise and publish entries through generated REST and GraphQL APIs or a built-in MCP server.",
      "url": "https://www.anchorterminal.com/tools/strapi",
      "markdownUrl": "https://www.anchorterminal.com/tools/strapi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/strapi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/strapi.json",
      "repo": "https://github.com/strapi/strapi",
      "license": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@strapi/strapi"
        },
        {
          "registry": "npm",
          "name": "@strapi/client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve tokens created in the admin panel of your own instance, with no app review or partner approval. API tokens authenticate the Content API under /api and are read-only, full access or custom per content type and action. Admin tokens authenticate admin routes and the MCP server at /mcp and hold a chosen subset of their owner's permissions, down to field and locale. Each kind is rejected on the other's routes. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel as `Authorization: Bearer`. An Admin token is shown once.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free to self-host with unlimited seats, so an agent can start without a contract or a card. Growth is $45 a month for 3 seats ($15 per extra seat) with a 30-day trial and no card, and Enterprise is priced by sales. Strapi Cloud is $35, $90 or $450 a project a month, needs a card at project creation, and charges $1.50 per 25,000 API requests over the plan (checked 2026-10-07).",
      "priceSummary": "$45 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the pricing pages or the repository's MCP code (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 73289,
        "npmWeekly": 258813,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.strapi.io",
      "llmsTxt": "https://docs.strapi.io/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "hosted",
        "mcp",
        "llms-txt",
        "webhooks",
        "graphql",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.7,
        "grade": "B",
        "agentReady": false,
        "rank": 252,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -6,
        "negativeNotes": [
          "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
        ],
        "verdict": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.",
        "bestFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "strengths": [
          "Admin tokens carry a chosen subset of the owner's permissions, down to content type, action, field and locale, with 7, 30 or 90 day expiry",
          "The MCP server lists only the tools a token may use and narrows each input and output schema to permitted fields",
          "Media delete tools preview by default through `dryRun` and name what would be removed before anything is deleted",
          "Weekly releases, 13 tagged versions between 15 July and 7 October 2026, with release notes per version",
          "MIT Community Edition, free to self-host with unlimited seats, plus llms.txt, llms-full.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
          "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
          "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
          "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
          "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
        ],
        "agentNotes": [
          "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
          "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
          "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
          "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
          "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 50,
          "reliability": 82,
          "schema": 80,
          "security": 66,
          "transparency": 75
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx create-strapi@latest",
        "http": "curl 'http://localhost:1337/api/restaurants?status=draft' \\\n  -H \"Authorization: Bearer $STRAPI_API_TOKEN\"",
        "claudeCode": "claude mcp add strapi-mcp --transport http http://localhost:1337/mcp -H \"Authorization: Bearer YOUR_ADMIN_TOKEN\"",
        "config": {
          "mcpServers": {
            "strapi-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_ADMIN_TOKEN"
              },
              "type": "streamable-http",
              "url": "http://localhost:1337/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/strapi"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition, self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT, unlimited seats, you pay for your own hosting"
        },
        {
          "item": "Growth, self-hosted",
          "unit": "month",
          "usd": 45,
          "note": "3 seats included, $15 per extra seat"
        },
        {
          "item": "Strapi Cloud Starter",
          "unit": "month",
          "usd": 35,
          "note": "per project, 100,000 API requests"
        },
        {
          "item": "Strapi Cloud Pro",
          "unit": "month",
          "usd": 90,
          "note": "per project, 1 million API requests"
        },
        {
          "item": "Strapi Cloud Business",
          "unit": "month",
          "usd": 450,
          "note": "per project, 10 million API requests"
        },
        {
          "item": "Strapi Cloud API requests over the plan",
          "unit": "1k-requests",
          "usd": 0.06,
          "note": "$1.50 per 25,000"
        }
      ],
      "provenance": {
        "legalEntity": "Strapi, Inc.",
        "domain": "strapi.io",
        "domainRegistered": "2015-09-21",
        "endpointOnVendorDomain": false,
        "terms": "https://strapi.io/cloud-legal",
        "privacy": "https://strapi.io/privacy",
        "statusPage": "https://status.strapi.io",
        "changelog": "https://github.com/strapi/strapi/releases",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Strapi Cloud terms (effective 7 October 2026) name Strapi, Inc., 548 Market St, PMB 60577, San Francisco, California 94104. The repository's copyright line names Strapi Solutions SAS, and the privacy policy gives Strapi Solutions, 128 rue de la Boétie, 75008 Paris.",
          "A self-hosted install answers on its owner's domain. Strapi Cloud projects answer at https://\u003cproject\u003e.strapiapp.com.",
          "https://strapi.io/.well-known/security.txt returned 404 to our reader on 7 October 2026. The repository holds a .well-known/security.txt with an Expires of 20 May 2027 and a Canonical line pointing at that URL.",
          "RDAP for strapi.io gives a registration date of 2015-09-21.",
          "The status page runs on Better Stack and covers Strapi Cloud, the website and the docs, not self-hosted installs."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/strapi.json",
      "live": {
        "slug": "strapi",
        "vendorStatus": {
          "page": "https://status.strapi.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:14.197616628Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "strapi/strapi",
            "version": "v5.57.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:30:39.413193839Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/client",
            "version": "1.6.2",
            "seenAt": "2026-10-08T16:30:37.897146773Z"
          },
          {
            "registry": "npm",
            "name": "@strapi/strapi",
            "version": "5.57.0",
            "seenAt": "2026-10-08T16:30:37.072939352Z"
          }
        ],
        "githubStars": 73292,
        "npmWeekly": 258813,
        "securityTxt": {
          "url": "https://strapi.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:07.890617672Z"
        },
        "pages": [
          {
            "url": "https://strapi.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:54.221268289Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9a83a678305b"
          },
          {
            "url": "https://strapi.io/cloud-legal",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:51.925906428Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e789fbc0c6c8"
          }
        ],
        "updatedAt": "2026-10-08T19:39:14.197616628Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "Strapi, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-10-07",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "2023-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "73k stars, 259k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Strapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category.",
        "question": "Which is better for AI agents, Payload or Strapi?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Payload and Strapi need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. No hosted endpoint is listed for Strapi.",
        "question": "Can an agent call Payload and Strapi without installing anything?"
      },
      {
        "answer": "Yes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).",
        "question": "Are Payload and Strapi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 80 against 70",
          "Security \u0026 auth, 66 against 57",
          "Payments \u0026 pricing, 50 against 45",
          "Maintenance \u0026 community, 87 against 78",
          "Transparency \u0026 trust, 72 against 62"
        ],
        "also": null,
        "goodFor": "Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.",
        "slug": "strapi",
        "watchFor": "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-strapi.json",
        "title": "Contentstack vs Strapi",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-strapi.json",
        "title": "DatoCMS vs Strapi",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-strapi.json",
        "title": "Directus vs Strapi",
        "url": "https://www.anchorterminal.com/compare/directus-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-strapi.json",
        "title": "Ghost vs Strapi",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
        "title": "Payload vs Webflow",
        "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-strapi.json",
        "title": "Sanity vs Strapi",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-strapi.json",
        "title": "Storyblok vs Strapi",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-wordpress.json",
        "title": "Strapi vs WordPress",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 4,
        "edge": "strapi",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "strapi": 82,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "strapi",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "strapi": 80,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "strapi",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "strapi": 65,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "strapi",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "strapi": 66,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "strapi",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "strapi": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "strapi",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "strapi": 87,
        "weight": 7
      },
      {
        "by": 10,
        "edge": "strapi",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "strapi": 72,
        "weight": 7
      }
    ],
    "summary": "Strapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "strapi": "The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-strapi",
    "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-strapi.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-strapi.min.md"
  },
  "markdown": "Strapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Strapi: grade B, 65.7/100, rank #252 of 722. Markdown https://www.anchorterminal.com/tools/strapi.md · JSON https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### Strapi (B)\n\nGood for: Teams that want to own their CMS and let an agent draft, localise and publish entries under a narrow token.\n\nAhead on:\n- Schema \u0026 documentation, 80 against 70\n- Security \u0026 auth, 66 against 57\n- Payments \u0026 pricing, 50 against 45\n- Maintenance \u0026 community, 87 against 78\n- Transparency \u0026 trust, 72 against 62\n\nWatch for: Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n\n\n## Score by category\n\n| Category | Weight | Payload | Strapi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 82 | Strapi +4 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 80 | Strapi +10 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 65 | Strapi +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 66 | Strapi +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 50 | Strapi +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 87 | Strapi +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 72 | Strapi +10 |\n| Negative events | ≤15 | -10 | -6 | |\n| **Total** | | **55.2 · C** | **65.7 · B** | |\n\n## Facts side by side\n\n| Fact | Payload | Strapi |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | Strapi, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | API key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-23 | 2026-10-07 |\n| Terms last updated | no document linked | 2026-10-07 |\n| Privacy policy last updated | 2024-03-28 | 2023-03-01 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | yes |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 45k stars, 1.1M npm/wk | 73k stars, 259k npm/wk |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**Strapi.** The built-in MCP server shows an agent only the tools, fields and locales its Admin token permits, and content tools create drafts by default. Rollback is the limit. Content History is a paid feature and records admin panel edits only, so API and MCP writes leave no version to restore, and the MCP server can't upload files.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### Strapi\n\n1. Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n2. Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n3. Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n4. Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n5. Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## Questions\n\n### Which is better for AI agents, Payload or Strapi?\n\nStrapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category.\n\n### Do Payload and Strapi need an API key?\n\nBoth need an API key.\n\n### Can an agent call Payload and Strapi without installing anything?\n\nNo hosted endpoint is listed for Payload. No hosted endpoint is listed for Strapi.\n\n### Are Payload and Strapi open source?\n\nYes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). Strapi is open source (MIT for the Community Edition. Code under ee/ directories is under Strapi's Enterprise Edition licence, and Strapi Cloud is a paid service under its own terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-strapi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-strapi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"strapi\"}`. From a terminal: `anchor compare payload strapi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/strapi.json\n\n## Other comparisons with Payload or Strapi\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Strapi](https://www.anchorterminal.com/compare/contentstack-vs-strapi.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs Strapi](https://www.anchorterminal.com/compare/datocms-vs-strapi.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Strapi](https://www.anchorterminal.com/compare/directus-vs-strapi.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Strapi](https://www.anchorterminal.com/compare/ghost-vs-strapi.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Webflow](https://www.anchorterminal.com/compare/payload-vs-webflow.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Sanity vs Strapi](https://www.anchorterminal.com/compare/sanity-vs-strapi.md)\n- [Storyblok vs Strapi](https://www.anchorterminal.com/compare/storyblok-vs-strapi.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Strapi vs WordPress](https://www.anchorterminal.com/compare/strapi-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs Strapi",
        "url": ""
      }
    ],
    "description": "Strapi scores 65.7 (B) on agent readiness against Payload's 55.2 (C), and leads in every scored category. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "Strapi B 65.7",
      "scores"
    ],
    "h1": "Payload vs Strapi",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-strapi.png",
    "path": "/compare/payload-vs-strapi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs Strapi for AI agents, C 55.2 vs B 65.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 630
  },
  "version": 1
}
