Now booking enterprise content platform builds for 2026. Contact us

CMS comparison Keystone vs Payload

Keystone vs Payload

Keystone is an open-source headless CMS that you host yourself. Payload is an open-source headless CMS that you can host yourself or run on the vendor's cloud. The table below sets them side by side on 28 features. They get a different status on 15.

  • Keystone Headless · Open source · 6 of 28 built in
  • Payload Headless · Open source · 13 of 28 built in

Sources checked: Keystone on 29 Sept 2026, Payload on 29 Sept 2026. Plans and releases can change after those dates.

WAYF is an official Payload partner and top contributor. Every platform in the table is classified by the same published definitions, and each answer lists the vendor page it came from.


Feature comparison

Built inPaid tierPlugin or add-onLimitedNot available
Keystone vs Payload feature comparison. Columns are the two platforms. Rows are features, grouped by area.
Platform
Keystone Headless
Payload Headless
Overview
What it is Open-source Node.js headless CMS from Thinkmill that generates a GraphQL API and an admin UI from a TypeScript schema.Open-source TypeScript headless CMS and app framework that installs into a Next.js app and stores content in your own database.
Edition compared The product and release each column describes. Keystone 6, open source, from the @keystone-6/core package Version 8.1.0, released 31 Aug 2026 Payload 3, MIT-licensed open-source core Version 3.90.2, released 23 Sept 2026
Vendor Thinkmill keystonejs.com Figma (acquired Payload in June 2025) payloadcms.com
Licence Open source MIT Open source MIT
Hosting Self-hosting No vendor cloud No managed hosting. Thinkmill offers enterprise support. Self-hosting Vendor cloud Payload Cloud is paused for new projects. Payload offers hosting to enterprise customers.
Built with TypeScript, Node.js, GraphQL, Prisma, Next.js for the admin UITypeScript, Node.js, Next.js, React
Database PostgreSQL, MySQL, SQLitePostgreSQL, MongoDB, SQLite
Pricing Public list prices only. Hosting and implementation are extra everywhere. Free to start Free and open source. Enterprise support from Thinkmill on request. Free to start Free to self-host. Enterprise licence, support and hosting on request.
Content modelling
Content model in code You define content types in files in your repository, review them like any other code and apply them from there. Imperative migration scripts alone count as limited. Built in Lists and fields are TypeScript config. 4 Built in Collections, globals and fields are TypeScript config. 2
Content model in the UI Admins can create and change content types and fields in the admin interface without writing code. Not available Not available No schema builder in the admin.
Reusable blocks Editors compose pages from reusable, typed components or blocks, and can reorder them. Built in Component blocks inside the document field. 8 Built in Blocks field.
Localization Editors translate content per locale inside the CMS, by field or by entry, without a separate site for each language. Not available No locale support documented. Model translations yourself. 12 Built in Field-level localization.
Image transformations The CMS resizes, crops or converts images on request, through URL parameters or generated sizes, with no external service. Not available Image field stores originals. The Cloudinary field hands resizing to Cloudinary. 711 Built in Generates configured image sizes on upload, with crop and focal point. 11
APIs and delivery
REST API A documented REST or JSON HTTP API returns content. Not available GraphQL only. Custom REST routes through extendExpressApp. 4 Built in
GraphQL API The vendor or an official module provides a GraphQL API for content. Built in Built in
Webhooks The CMS can call an external URL when content is created, changed or published. Not available No webhook settings. Call URLs from hooks in code. 10 Not available No webhook settings. Call URLs from afterChange hooks in code. 17
Renders the website The CMS itself renders and serves the public pages through themes or templates. Headless-only products answer no. Not available Not available Runs inside your Next.js app. You build the pages.
Editorial workflow
Drafts Editors save changes as a draft and publish them later. The live version stays untouched until then. Not available Built in 10
Scheduled publishing An editor can set a future date and time for content to publish or unpublish. Not available Built in Scheduled publish and unpublish run through the jobs queue. 10
Version history The CMS keeps earlier versions of an entry, and editors can compare or restore them. Not available Built in Opt-in per collection or global. 10
Preview Editors can see unpublished content rendered as it will appear on the site before publishing. Not available Built in
Visual editing Editors can click on the rendered page and edit content in place or in a side panel next to it. Not available Not available Payload lists the Enterprise Visual Editor as coming soon. 37
Approval workflows Content moves through review stages you configure, such as draft, review and approved, with permissions per stage. Not available Paid tier Enterprise publishing workflows. 39
Content releases Editors group changes across several entries and publish them together as one release. Not available Not available
Real-time co-editing Two or more editors can work on the same entry at once and see each other's changes live. Not available Not available Document locking only. Payload lists enterprise multi-player editing as coming soon. 12320
Access and governance
Custom roles Admins define their own roles with granular permissions instead of picking from a fixed set. Limited Roles are access-control functions written in code. No role editor in the admin. 5 Limited Roles are access-control functions written in code. No role editor in the admin. 18
Field-level permissions Admins can restrict access to single fields, on top of content types and entries. Built in Field-level access control. 5 Built in Field-level access functions. 18
Single sign-on Editors can sign in through SAML or OpenID Connect against a company identity provider. Not available The auth package covers password login. SSO means custom session code. 6 Paid tier Enterprise licence, SAML and OAuth 2.0. 35
Audit log The CMS logs who changed what and when across the whole installation, and admins can review the log. Not available Paid tier Enterprise audit logs. 6
Platform and extensibility
Multiple sites One installation or account can manage several separate websites or brands with shared users. Not available Plugin or add-on Official multi-tenant plugin. 15
Extensible admin UI Developers can add their own components, views or fields to the editing interface. Built in Custom admin pages, navigation and field views. 9 Built in Custom React components, views and fields.
Plugin marketplace The vendor runs an official directory or marketplace of installable extensions. Not available Limited Docs list official plugins. Community plugin directories are third-party. 13
Form builder Editors can build and publish forms and collect submissions without code. Not available Plugin or add-on Official Form Builder plugin. 16
Site member accounts The platform handles sign-up and login for public site users or members, separate from editors. Built in createAuth works on any list, including site users. 6 Built in Any auth-enabled collection can hold site users.
AI writing assistant A first-party AI feature in the editing interface generates, rewrites or translates content. Not available Paid tier Enterprise AI writing assistant. Payload lists AI translation and image generation as coming soon. 8
Official MCP server The vendor publishes a Model Context Protocol server so AI agents can read or write content. Not available Plugin or add-on Official open-source MCP plugin. 14

Considering more platforms? Compare Keystone and Payload with the rest of your shortlist in the CMS comparison tool.


Where they differ

Keystone and Payload get a different status on 15 of the 28 features and the same status on 13. Keystone has 6 built in on its baseline edition, Payload has 13. Two matching statuses can still name different paid tiers or limits, so read the notes in the table before treating a row as equal.

Vendor cloud
Keystone has no vendor-run cloud. Payload has a vendor-run cloud.

Built in on Payload, a different answer on Keystone 7

  • Localization Keystone: Not available. Payload: Built in.
  • Image transformations Keystone: Not available. Payload: Built in.
  • REST API Keystone: Not available. Payload: Built in.
  • Drafts Keystone: Not available. Payload: Built in.
  • Scheduled publishing Keystone: Not available. Payload: Built in.
  • Version history Keystone: Not available. Payload: Built in.
  • Preview Keystone: Not available. Payload: Built in.

Built in on neither, with different answers 8

  • Approval workflows Keystone: Not available. Payload: Paid tier.
  • Single sign-on Keystone: Not available. Payload: Paid tier.
  • Audit log Keystone: Not available. Payload: Paid tier.
  • Multiple sites Keystone: Not available. Payload: Plugin or add-on.
  • Plugin marketplace Keystone: Not available. Payload: Limited.
  • Form builder Keystone: Not available. Payload: Plugin or add-on.
  • AI writing assistant Keystone: Not available. Payload: Paid tier.
  • Official MCP server Keystone: Not available. Payload: Plugin or add-on.

More comparisons

Open the CMS comparison tool to put up to six platforms in one table.


We're booking content platform
engagements for 2026.

Twenty-five minutes to walk through the work and decide if we're the right team for it. Scoping and a fixed price come after.