Head to head · Cms content · October 2026 research run

Payload vs Webflow

Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments & pricing. Both do cms content.

Which one, for what

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Payments & pricing, 45 against 30

Also in its favour

  • Open source

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

Webflow B

Good for Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.

Ahead on

  • Schema & documentation, 87 against 70
  • Agent ergonomics, 72 against 64
  • Security & auth, 74 against 57
  • Transparency & trust, 81 against 62

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions

Score by category

CategoryWeight this runPayloadWebflowEdge
Reliability16%207879Webflow +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27087Webflow +17
Agent ergonomics13%16.26472Webflow +8
Security & auth14%17.55774Webflow +17
Payments & pricing10%12.54530Payload +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87880Webflow +2
Transparency & trust7%8.86281Webflow +19
Negative events≤15-10-3
Total55.2 · C69.4 · B

Facts side by side

FactPayloadWebflow
KindHTTP APIHTTP API
VendorPayload CMS, Inc. (Figma)Webflow, Inc.
Hosted endpointno (local only)https://api.webflow.com/v2
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingFreeFreemium
x402nono
LicenceMIT for the core and the official packages. Enterprise add-ons are sold separately through salesProprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT
Tools exposednone34
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedcom.webflow/mcp
Last release2026-09-232026-10-07
Terms last updatedno document linked2023-11-15
Privacy policy last updated2024-03-282025-03-17
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity45k stars, 1.1M npm/wk85k npm/wk, 121k PyPI/wk

Verdicts

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

Webflow

The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.

Before you call either

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

Webflow

  1. Send the token as Authorization: Bearer to https://api.webflow.com/v2. Ask for cms:read and cms:write only, plus sites:write if the task publishes
  2. Create or update items first, then call Publish Items or Publish Site. An item with isDraft true and a lastPublished date is live with unpublished changes
  3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429
  4. Page item lists with limit (maximum 100) and offset, and filter with filter[<fieldSlug>][<operator>], up to 10 terms
  5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's cmsLocaleId

Questions

Which is better for AI agents, Payload or Webflow?

Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments & pricing.

Do Payload and Webflow need an API key?

Payload needs an API key. Webflow takes an API key or an OAuth sign-in.

Can an agent call Payload and Webflow without installing anything?

No hosted endpoint is listed for Payload. Webflow has a hosted endpoint at https://api.webflow.com/v2.

Are Payload and Webflow open source?

Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Webflow.

Other comparisons with Payload or Webflow

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.