{
  "data": {
    "a": {
      "slug": "payload",
      "name": "Payload",
      "vendor": "Payload CMS, Inc. (Figma)",
      "vendorUrl": "https://payloadcms.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin.",
      "url": "https://www.anchorterminal.com/tools/payload",
      "markdownUrl": "https://www.anchorterminal.com/tools/payload.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payload.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payload.json",
      "repo": "https://github.com/payloadcms/payload",
      "license": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "payload"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/plugin-mcp"
        },
        {
          "registry": "npm",
          "name": "@payloadcms/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve keys on your own instance, with no app review or partner approval. REST and GraphQL take a per-user API key sent as `Authorization: {collection-slug} API-Key {key}` once `auth.useAPIKey` is set on an auth collection. The key signs requests in as that user under the collection's access control, doesn't expire, is shown once, and can be regenerated or revoked by an admin. The MCP plugin has its own keys, created in the admin panel under MCP API Keys with find, create, update and delete switches per collection, sent as `Authorization: Bearer {key}`. Changing `PAYLOAD_SECRET` invalidates every key.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the MIT licence, with no account at Payload and no card, so an agent can start without a contract. Enterprise (SSO, publishing workflows, visual editor, dedicated support) is sold through sales with no public price. Payload Cloud has paused deployment of new projects since Payload joined Figma (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the 3.x documentation, the get-started page or the MCP plugin source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 45151,
        "npmWeekly": 1108564,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://payloadcms.com/docs",
      "llmsTxt": "https://payloadcms.com/llms.txt",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.localisation",
        "cms.assets",
        "cms.schema"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "graphql",
        "rest",
        "typescript",
        "nextjs"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.2,
        "grade": "C",
        "agentReady": false,
        "rank": 516,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "18 September to 8 October 2026. Payload published 38 security advisories in three weeks, 49 in the 12 months to 8 October 2026 (8 critical, 23 high, 18 medium). They include remote code execution through the first-register operation (GHSA-97rh-rhh2-7vjv), SQL injection on Postgres and SQLite (GHSA-v49j-62m6-pgrr), unauthorised document updates on orderable collections (GHSA-f7hx-52q9-hcrf) and four in `@payloadcms/plugin-mcp`, one an account takeover through the experimental password recovery tool (GHSA-h5rh-4jwf-738p). All are fixed in 3.90.0 or earlier, each was published by the vendor with affected versions and a workaround, and we found no report of exploitation, so we deduct 10 of a possible 15. https://github.com/payloadcms/payload/security/advisories"
        ],
        "verdict": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
        "bestFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "strengths": [
          "MIT core with drafts, version history and restore through `POST /api/{collection-slug}/versions/:id`, none of it behind a paid plan",
          "MCP API keys carry find, create, update and delete switches per collection, and the key's user still passes through the collection's access control",
          "New documents default to `_status: 'draft'`, so nothing is published unless the request sets `_status: 'published'`",
          "MCP find tools default to 10 documents and depth 0, cap at 100, and take `select` to return named fields only",
          "llms.txt per major version, llms-full.txt and a Markdown copy of every docs page"
        ],
        "weaknesses": [
          "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026",
          "No OpenAPI file is published or generated by the core packages, and REST error responses have no reference page",
          "REST and MCP API keys don't expire, and rate limiting is left to the owner's own hooks or proxy",
          "No idempotency keys, and the MCP tools set no `readOnlyHint` or `destructiveHint` annotations",
          "Payload Cloud is closed to new projects, Enterprise is priced by sales, and no status page or security.txt was found"
        ],
        "agentNotes": [
          "Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing",
          "Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate",
          "To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written",
          "Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented",
          "Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 78,
          "payments": 45,
          "reliability": 78,
          "schema": 70,
          "security": 57,
          "transparency": 74
        },
        "provenanceScore": 50
      },
      "connect": {
        "install": "npx create-payload-app",
        "http": "curl 'http://localhost:3000/api/pages' \\\n  -H \"Authorization: users API-Key $PAYLOAD_API_KEY\"",
        "claudeCode": "claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \\\n  --header \"Authorization: Bearer MCP-USER-API-KEY\"",
        "config": {
          "mcpServers": {
            "Payload": {
              "headers": {
                "Authorization": "Bearer MCP-USER-API-KEY"
              },
              "type": "http",
              "url": "http://localhost:3000/api/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/payload"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Self-hosted Payload",
          "unit": "month",
          "usd": 0,
          "note": "MIT, you pay for your own hosting and database"
        }
      ],
      "provenance": {
        "legalEntity": "Payload CMS, Inc.",
        "domain": "payloadcms.com",
        "domainRegistered": "2018-04-02",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "https://payloadcms.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/payloadcms/payload/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No `terms` is recorded. The only terms on payloadcms.com are the Payload Cloud terms at https://payloadcms.com/cloud-terms, which govern a hosted service closed to new projects. The software an agent uses is under the MIT licence in LICENSE.md.",
          "The privacy policy (effective 28 March 2024) names Payload CMS, Inc. as controller. The Cloud terms call it a Delaware corporation with an address at 624 Stocking Ave. NW, Grand Rapids, Michigan 49504. LICENSE.md names Payload CMS, LLC.",
          "The site says Payload has joined Figma. The privacy policy and the Cloud terms don't mention Figma.",
          "A self-hosted install answers on its owner's domain.",
          "https://payloadcms.com/.well-known/security.txt and https://payloadcms.com/security.txt returned 404 on 8 October 2026. SECURITY.md gives security@payloadcms.com.",
          "No status page is linked from the site footer, the security page or the get-started page, and status.payloadcms.com didn't resolve.",
          "RDAP for payloadcms.com gives a registration date of 2018-04-02."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payload.json"
    },
    "answer": "Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
    "b": {
      "slug": "webflow",
      "name": "Webflow",
      "vendor": "Webflow, Inc.",
      "vendorUrl": "https://webflow.com",
      "kind": "http-api",
      "category": "cms",
      "summary": "Webflow is a hosted website builder with a built-in CMS. Agents reach it through the Data API v2 (collections, items, assets, pages, locales, publishing) or the official hosted MCP server, which wraps that API in 34 tools.",
      "url": "https://www.anchorterminal.com/tools/webflow",
      "markdownUrl": "https://www.anchorterminal.com/tools/webflow.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/webflow.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/webflow.json",
      "repo": "https://github.com/webflow/openapi-spec",
      "license": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.webflow.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "webflow-api"
        },
        {
          "registry": "pypi",
          "name": "webflow"
        },
        {
          "registry": "npm",
          "name": "webflow-mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Data API takes a Bearer token, either a site token or an OAuth access token. A site administrator creates a site token under Apps \u0026 integrations and picks read and write scopes. Each site allows 5 tokens and a token expires after 365 days without use. An OAuth app is registered in a workspace with its scopes, and only apps listed on the Marketplace go through review. The MCP server uses browser OAuth with PKCE and dynamic client registration, where a site owner or admin picks the sites or the workspace. Custom code endpoints and workspace activity logs aren't open to site tokens.",
      "pricing": "freemium",
      "pricingNotes": "The Starter site plan is free and includes the CMS APIs at 60 requests a minute, 50 CMS items and the MCP server, so an agent can start without a contract. Basic is $15 a month billed yearly and has no CMS. Premium is $25 a month billed yearly with 20,000 CMS items and 120 requests a minute. Team is $2,500 a month on an annual contract and Enterprise is sold through sales. Prices are per site (https://webflow.com/pricing, checked 2026-10-08).",
      "priceSummary": "$15 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Data API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 34,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 85160,
        "pypiWeekly": 121246,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.webflow.com/data/docs",
      "llmsTxt": "https://developers.webflow.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/webflow/openapi-spec/main/openapi/v2.yml",
      "registryName": "com.webflow/mcp",
      "capabilities": [
        "cms.content",
        "cms.publish",
        "cms.assets",
        "cms.schema",
        "cms.localisation"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "closed-source",
        "free-tier",
        "webhooks",
        "typescript",
        "python",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 160,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "7 October 2026. The Get Site Plan endpoint changed the `id` and `displayName` it returns for Starter sites and renamed some plans, in place. The changelog entry of the same date calls it a breaking change and no earlier notice was found. It is documented, so the deduction is small (https://developers.webflow.com/home/changelog/2026/10/7)."
        ],
        "verdict": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.",
        "bestFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "strengths": [
          "Public OpenAPI 3.1 spec for Data API v2 with 140 operations, MIT, last synced on 2 September 2026, plus llms.txt and a Markdown copy of every docs page",
          "OAuth and site tokens take read and write scope pairs per resource (cms, assets, pages, sites and others), and each site allows at most 5 tokens",
          "CMS items are created and updated as drafts. Publishing an item or the whole site is a separate call",
          "429 responses carry Retry-After, every response carries X-RateLimit-Remaining, and the JavaScript and Python SDKs back off automatically",
          "Hosted MCP server at mcp.webflow.com/mcp is listed in the official MCP registry as com.webflow/mcp and has its own component on the status page"
        ],
        "weaknesses": [
          "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions",
          "No idempotency keys on Data API writes in the reviewed documentation. Site publish is limited to one successful call a minute",
          "The MCP server can't create new localised CMS items. It reads and updates existing items in secondary locales",
          "The Starter plan allows 50 CMS items and 60 requests a minute. The site activity log that records agent changes is listed on Team ($2,500 a month) and Enterprise",
          "On 7 October 2026 Get Site Plan changed its `id` and `displayName` values in place, marked as breaking in the changelog entry of the same day"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes",
          "Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes",
          "Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429",
          "Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms",
          "Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 30,
          "reliability": 79,
          "schema": 87,
          "security": 74,
          "transparency": 65
        },
        "provenanceScore": 97
      },
      "connect": {
        "install": "npm install webflow-api",
        "http": "curl --request GET \\\n  --url https://api.webflow.com/v2/sites \\\n  --header 'accept: application/json' \\\n  --header 'authorization: Bearer YOUR_API_TOKEN'",
        "claudeCode": "claude mcp add --transport http webflow https://mcp.webflow.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/cms.content",
        "tool": "https://letme.dev/webflow"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Basic site plan",
          "unit": "month",
          "usd": 15,
          "note": "billed yearly, per site, no CMS"
        },
        {
          "item": "Premium site plan",
          "unit": "month",
          "usd": 25,
          "note": "billed yearly, per site, 20,000 CMS items and 120 requests a minute"
        },
        {
          "item": "Team platform plan",
          "unit": "month",
          "usd": 2500,
          "note": "annual contract, 5 full and 5 limited seats included"
        }
      ],
      "provenance": {
        "legalEntity": "Webflow, Inc.",
        "domain": "webflow.com",
        "domainRegistered": "2003-03-31",
        "endpointOnVendorDomain": true,
        "terms": "https://webflow.com/legal/terms",
        "privacy": "https://webflow.com/legal/privacy",
        "statusPage": "https://status.webflow.com",
        "changelog": "https://developers.webflow.com/home/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service name Webflow, Inc., a Delaware corporation at 398 11th Street, Floor 2, San Francisco, CA 94103, and are governed by California law.",
          "The Terms of Service (effective 15 November 2023) govern the platform and incorporate the Developer Terms of Service at https://webflow.com/legal/developer-terms-of-service, which cover API use and rate limits.",
          "The privacy policy is effective 17 March 2025. The DPA is effective 15 November 2023 and the sub-processor list was updated on 9 July 2026.",
          "The Data API answers at api.webflow.com and the MCP server at mcp.webflow.com.",
          "webflow.com/.well-known/security.txt points to a Bugcrowd disclosure programme and expires on 31 December 2026.",
          "RDAP for webflow.com gives a registration date of 2003-03-31.",
          "status.webflow.com runs on Statuspage with components for the Data API and the MCP server."
        ],
        "score": 97
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/webflow.json",
      "live": {
        "slug": "webflow",
        "probe": {
          "target": "https://api.webflow.com/v2",
          "method": "get",
          "lastAt": "2026-10-09T01:13:01.356676253Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 252,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 266,
          "p95ms24h": 348,
          "samples24h": 83,
          "samples30d": 83,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 70,
              "ok": 70
            },
            {
              "date": "2026-10-09",
              "probes": 13,
              "ok": 13
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.webflow.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T01:07:56.42335962Z"
        },
        "pages": [
          {
            "url": "https://developers.webflow.com/home/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:03.444775017Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "26398a0d385c"
          },
          {
            "url": "https://webflow.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:48.086194416Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1895a791460c"
          },
          {
            "url": "https://webflow.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:43.849393456Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1dc949e66fd3"
          },
          {
            "url": "https://webflow.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:46.083572378Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fab4ea21138a"
          }
        ],
        "updatedAt": "2026-10-09T01:13:01.356676253Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payload CMS, Inc. (Figma)",
        "b": "Webflow, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.webflow.com/v2",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the core and the official packages. Enterprise add-ons are sold separately through sales",
        "b": "Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "34",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.webflow/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2023-11-15",
        "name": "Terms last updated"
      },
      {
        "a": "2024-03-28",
        "b": "2025-03-17",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "45k stars, 1.1M npm/wk",
        "b": "85k npm/wk, 121k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Payload or Webflow?"
      },
      {
        "answer": "Payload needs an API key. Webflow takes an API key or an OAuth sign-in.",
        "question": "Do Payload and Webflow need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Payload. Webflow has a hosted endpoint at https://api.webflow.com/v2.",
        "question": "Can an agent call Payload and Webflow without installing anything?"
      },
      {
        "answer": "Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Webflow.",
        "question": "Are Payload and Webflow open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 30"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.",
        "slug": "payload",
        "watchFor": "49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 70",
          "Agent ergonomics, 72 against 64",
          "Security \u0026 auth, 74 against 57",
          "Transparency \u0026 trust, 81 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.",
        "slug": "webflow",
        "watchFor": "The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions"
      }
    ],
    "job": {
      "capability": "cms.content",
      "name": "Cms content"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-payload.json",
        "title": "Contentstack vs Payload",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/contentstack-vs-webflow.json",
        "title": "Contentstack vs Webflow",
        "url": "https://www.anchorterminal.com/compare/contentstack-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-payload.json",
        "title": "DatoCMS vs Payload",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/datocms-vs-webflow.json",
        "title": "DatoCMS vs Webflow",
        "url": "https://www.anchorterminal.com/compare/datocms-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-payload.json",
        "title": "Directus vs Payload",
        "url": "https://www.anchorterminal.com/compare/directus-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/directus-vs-webflow.json",
        "title": "Directus vs Webflow",
        "url": "https://www.anchorterminal.com/compare/directus-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-payload.json",
        "title": "Ghost vs Payload",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-payload"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-vs-webflow.json",
        "title": "Ghost vs Webflow",
        "url": "https://www.anchorterminal.com/compare/ghost-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-sanity.json",
        "title": "Payload vs Sanity",
        "url": "https://www.anchorterminal.com/compare/payload-vs-sanity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-storyblok.json",
        "title": "Payload vs Storyblok",
        "url": "https://www.anchorterminal.com/compare/payload-vs-storyblok"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-strapi.json",
        "title": "Payload vs Strapi",
        "url": "https://www.anchorterminal.com/compare/payload-vs-strapi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payload-vs-wordpress.json",
        "title": "Payload vs WordPress",
        "url": "https://www.anchorterminal.com/compare/payload-vs-wordpress"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sanity-vs-webflow.json",
        "title": "Sanity vs Webflow",
        "url": "https://www.anchorterminal.com/compare/sanity-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/storyblok-vs-webflow.json",
        "title": "Storyblok vs Webflow",
        "url": "https://www.anchorterminal.com/compare/storyblok-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/strapi-vs-webflow.json",
        "title": "Strapi vs Webflow",
        "url": "https://www.anchorterminal.com/compare/strapi-vs-webflow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/webflow-vs-wordpress.json",
        "title": "Webflow vs WordPress",
        "url": "https://www.anchorterminal.com/compare/webflow-vs-wordpress"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "webflow",
        "key": "reliability",
        "name": "Reliability",
        "payload": 78,
        "webflow": 79,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "webflow",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payload": 70,
        "webflow": 87,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "webflow",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payload": 64,
        "webflow": 72,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "webflow",
        "key": "security",
        "name": "Security \u0026 auth",
        "payload": 57,
        "webflow": 74,
        "weight": 14
      },
      {
        "by": 15,
        "edge": "payload",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payload": 45,
        "webflow": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "webflow",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payload": 78,
        "webflow": 80,
        "weight": 7
      },
      {
        "by": 19,
        "edge": "webflow",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payload": 62,
        "webflow": 81,
        "weight": 7
      }
    ],
    "summary": "Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.",
    "verdicts": {
      "payload": "Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.",
      "webflow": "The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payload-vs-webflow",
    "json": "https://www.anchorterminal.com/compare/payload-vs-webflow.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payload-vs-webflow.md",
    "slim": "https://www.anchorterminal.com/compare/payload-vs-webflow.min.md"
  },
  "markdown": "Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content.\n\n- Payload: grade C, 55.2/100, rank #516 of 722. Markdown https://www.anchorterminal.com/tools/payload.md · JSON https://www.anchorterminal.com/api/v1/tools/payload.json\n- Webflow: grade B, 69.4/100, rank #160 of 722. Markdown https://www.anchorterminal.com/tools/webflow.md · JSON https://www.anchorterminal.com/api/v1/tools/webflow.json\n\n## Which one, for what\n\n### Payload (C)\n\nGood for: Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 30\n\nAlso in its favour:\n- Open source\n\nWatch for: 49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026\n\n### Webflow (B)\n\nGood for: Teams whose website already runs on Webflow and who want an agent to draft, update and publish CMS items, fix metadata or manage assets.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 70\n- Agent ergonomics, 72 against 64\n- Security \u0026 auth, 74 against 57\n- Transparency \u0026 trust, 81 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The MCP server documents 34 tools (27 data, 3 Designer session, 4 utility), each with several actions, and a granted tool grants all its actions\n\n\n## Score by category\n\n| Category | Weight | Payload | Webflow | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 78 | 79 | Webflow +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 87 | Webflow +17 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 72 | Webflow +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 74 | Webflow +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 30 | Payload +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 78 | 80 | Webflow +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 81 | Webflow +19 |\n| Negative events | ≤15 | -10 | -3 | |\n| **Total** | | **55.2 · C** | **69.4 · B** | |\n\n## Facts side by side\n\n| Fact | Payload | Webflow |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payload CMS, Inc. (Figma) | Webflow, Inc. |\n| Hosted endpoint | no (local only) | `https://api.webflow.com/v2` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | Proprietary service under Webflow's Terms of Service. The OpenAPI spec, the JavaScript and Python SDKs and the open-source MCP server on GitHub are MIT |\n| Tools exposed | none | 34 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.webflow/mcp` |\n| Last release | 2026-09-23 | 2026-10-07 |\n| Terms last updated | no document linked | 2023-11-15 |\n| Privacy policy last updated | 2024-03-28 | 2025-03-17 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | yes |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 45k stars, 1.1M npm/wk | 85k npm/wk, 121k PyPI/wk |\n\n## Verdicts\n\n**Payload.** Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.\n\n**Webflow.** The Data API has a public OpenAPI 3.1 spec with 140 operations, scoped OAuth and site tokens, and CMS items that stay drafts until a separate publish call. The MCP server loads 34 multi-action tools and can't create new localised CMS items. The free plan holds 50 CMS items, and the activity log needs the $2,500 Team plan.\n\n## Before you call either\n\n### Payload\n\n1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing\n2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate\n3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written\n4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented\n5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them\n\n### Webflow\n\n1. Send the token as `Authorization: Bearer` to https://api.webflow.com/v2. Ask for `cms:read` and `cms:write` only, plus `sites:write` if the task publishes\n2. Create or update items first, then call Publish Items or Publish Site. An item with `isDraft` true and a `lastPublished` date is live with unpublished changes\n3. Stay under 60 requests a minute on Starter and Basic and 120 on Premium, read X-RateLimit-Remaining, and wait for Retry-After on 429\n4. Page item lists with `limit` (maximum 100) and `offset`, and filter with `filter[\u003cfieldSlug\u003e][\u003coperator\u003e]`, up to 10 terms\n5. Upload an asset in two steps (create the asset with a file hash, then POST the bytes to the presigned URL). Write localised content with the item's `cmsLocaleId`\n\n## Questions\n\n### Which is better for AI agents, Payload or Webflow?\n\nWebflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing.\n\n### Do Payload and Webflow need an API key?\n\nPayload needs an API key. Webflow takes an API key or an OAuth sign-in.\n\n### Can an agent call Payload and Webflow without installing anything?\n\nNo hosted endpoint is listed for Payload. Webflow has a hosted endpoint at https://api.webflow.com/v2.\n\n### Are Payload and Webflow open source?\n\nPayload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). No open-source release is listed for Webflow.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payload-vs-webflow.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payload-vs-webflow.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payload\", \"b\": \"webflow\"}`. From a terminal: `anchor compare payload webflow`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payload.json and https://www.anchorterminal.com/api/v1/tools/webflow.json\n\n## Other comparisons with Payload or Webflow\n\n- [Contentstack vs Payload](https://www.anchorterminal.com/compare/contentstack-vs-payload.md)\n- [Contentstack vs Webflow](https://www.anchorterminal.com/compare/contentstack-vs-webflow.md)\n- [DatoCMS vs Payload](https://www.anchorterminal.com/compare/datocms-vs-payload.md)\n- [DatoCMS vs Webflow](https://www.anchorterminal.com/compare/datocms-vs-webflow.md)\n- [Directus vs Payload](https://www.anchorterminal.com/compare/directus-vs-payload.md)\n- [Directus vs Webflow](https://www.anchorterminal.com/compare/directus-vs-webflow.md)\n- [Ghost vs Payload](https://www.anchorterminal.com/compare/ghost-vs-payload.md)\n- [Ghost vs Webflow](https://www.anchorterminal.com/compare/ghost-vs-webflow.md)\n- [Payload vs Sanity](https://www.anchorterminal.com/compare/payload-vs-sanity.md)\n- [Payload vs Storyblok](https://www.anchorterminal.com/compare/payload-vs-storyblok.md)\n- [Payload vs Strapi](https://www.anchorterminal.com/compare/payload-vs-strapi.md)\n- [Payload vs WordPress](https://www.anchorterminal.com/compare/payload-vs-wordpress.md)\n- [Sanity vs Webflow](https://www.anchorterminal.com/compare/sanity-vs-webflow.md)\n- [Storyblok vs Webflow](https://www.anchorterminal.com/compare/storyblok-vs-webflow.md)\n- [Strapi vs Webflow](https://www.anchorterminal.com/compare/strapi-vs-webflow.md)\n- [Webflow vs WordPress](https://www.anchorterminal.com/compare/webflow-vs-wordpress.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payload vs Webflow",
        "url": ""
      }
    ],
    "description": "Webflow scores 69.4 (B) on agent readiness against Payload's 55.2 (C), and leads in 6 of 7 scored categories. Payload leads on payments \u0026 pricing. Both do cms content. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payload C 55.2",
      "Webflow B 69.4",
      "scores"
    ],
    "h1": "Payload vs Webflow",
    "image": "https://www.anchorterminal.com/assets/og/compare-payload-vs-webflow.png",
    "path": "/compare/payload-vs-webflow",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payload vs Webflow for AI agents, C 55.2 vs B 69.4 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/payload-vs-webflow"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
