# Payload (slim) > Payload is an open-source, code-first headless CMS and application framework for Node.js and Next.js, now part of Figma. Agents manage content, drafts, versions and locales through generated REST and GraphQL APIs or an official MCP plugin. - Full: https://www.anchorterminal.com/tools/payload.md (~6,750 tokens) · this version ~1,680 tokens · JSON https://www.anchorterminal.com/tools/payload.json · canonical https://www.anchorterminal.com/tools/payload - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 55.2/100 · rank #516 of 722 · #10 in CMS & website publishing · not agent-ready · confidence medium** Assessment: Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published. ## Facts - Kind: HTTP API · vendor: Payload CMS, Inc. (Figma) · category: CMS & website publishing · legal entity: Payload CMS, Inc. · provenance 50/100 - Local only (HTTP, Streamable HTTP): npm `payload`, npm `@payloadcms/plugin-mcp`, npm `@payloadcms/sdk` - Auth: API key · pricing: Free · x402: no · licence: MIT for the core and the official packages. Enterprise add-ons are sold separately through sales - Probe metrics: not measured yet (probes haven't run) - Graded surface: Self-hosted Payload 3.90.2 (MIT) through its generated REST API and the official MCP plugin. Payload Cloud is closed to new projects, so it isn't graded - REST API: Generated per collection under `/api`. GET, POST, PATCH and DELETE on `/api/{collection-slug}` and `/api/{collection-slug}/{id}`, plus `/count`, `/versions` and `/api/globals/{global-slug}`, with `depth`, `locale`, `fallback-locale`, `select`, `populate`, `limit`, `page`, `sort`, `where` and `draft` parameters - MCP server: `@payloadcms/plugin-mcp` 3.90.2, built on `@modelcontextprotocol/sdk` 1.30.0, POST to `/api/mcp`. Tools are named `findPosts`, `createPosts`, `updatePosts` and `deletePosts` for a `posts` collection. Custom tools, prompts and resources can be added in config - GraphQL: `@payloadcms/graphql` generates queries and mutations from the same config, with `maxComplexity` to reject costly queries - Credentials: REST and GraphQL take a per-user API key (`auth.useAPIKey`) that doesn't expire and can be regenerated or revoked, or a JWT from login. MCP takes its own keys from the MCP API Keys collection - Drafts and versions: `versions.drafts` adds `_status` (draft or published). `GET /api/{collection-slug}/versions`, `GET /api/{collection-slug}/versions/:id` and `POST /api/{collection-slug}/versions/:id` to restore - Runtime: Node.js 20.9.0 or later, Next.js, and MongoDB, Postgres or SQLite - Telemetry: On by default and described as anonymous. `telemetry: false` in the Payload config turns it off - Paid options: Enterprise (SSO, publishing workflows, visual editor, dedicated support) through sales, no public price - Prices: Self-hosted Payload free per month (plan) - Scores: Reliability 78, Performance pending, Schema & documentation 70, Agent ergonomics 64, Security & auth 57, Payments & pricing 45, Task success pending, Maintenance & community 78, Transparency & trust 62 · negative events -10 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the graded surface is software its owner hosts. · Schema & documentation, No OpenAPI file is published or generated by the core packages, because endpoints depend on each project's config. · Agent ergonomics, Four MCP tools per enabled collection and two per global, so five collections give 20 tools, the 11 to 30 band (15). · Security & auth, REST keys are per user, revocable and regenerable, shown once, and limited by that user's access control down to field level. · Payments & pricing, Scored with the self-hosted rule. · Maintenance & community, 3.90.2 was published to npm on 23 September 2026, 15 days before this check (30). · Transparency & trust, MIT for the core and official packages, with LICENSE.md in the repository (30). - Sources: 24, open questions: 8, both in the full twin - Capabilities: cms.content, cms.publish, cms.localisation, cms.assets, cms.schema - JSON: https://www.anchorterminal.com/api/v1/tools/payload.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/payload.svg` or a link to https://www.anchorterminal.com/tools/payload from a page on payloadcms.com or one of its subdomains, or the README of github.com/payloadcms/payload, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing 2. Send REST keys as `Authorization: {collection-slug} API-Key {key}` and MCP keys as `Authorization: Bearer {key}`. The two key kinds are separate 3. To publish, set `_status: 'published'` in the data. The `draft` parameter only relaxes validation and chooses where an update is written 4. Upload files with multipart POST to the upload collection, with other fields as JSON in `_payload`. No MCP upload tool is documented 5. Roll back with `POST /api/{collection-slug}/versions/:id` after listing versions. Versions exist only where the collection config enables them ## Connect ```bash npx create-payload-app ``` ```bash curl 'http://localhost:3000/api/pages' \ -H "Authorization: users API-Key $PAYLOAD_API_KEY" ``` ```bash claude mcp add --transport http Payload http://127.0.0.1:3000/api/mcp \ --header "Authorization: Bearer MCP-USER-API-KEY" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/payload ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | DatoCMS | BB | 74.4 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/datocms.min.md | | Sanity | BB | 73.7 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/sanity.min.md | | Webflow | B | 69.4 | cms.content, cms.publish, cms.assets, cms.schema, cms.localisation | https://www.anchorterminal.com/tools/webflow.min.md | | Storyblok | B | 67.7 | cms.content, cms.publish, cms.assets, cms.localisation, cms.schema | https://www.anchorterminal.com/tools/storyblok.min.md | | Directus | B | 67.1 | cms.content, cms.schema, cms.assets, cms.publish, cms.localisation | https://www.anchorterminal.com/tools/directus.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)