Payload suits publishers with JavaScript developers who want a free, MIT-licensed CMS that lives in the same codebase as a Next.js front end. The trade-off is that roles, access rules, preview, sitemaps and redirects are things your developers write or wire up. There is no ready-made editorial setup for a newsroom.
What is Payload?
Payload is an open-source, code-first headless CMS. You define your setup in a Payload configuration file in code, and the documentation describes an admin panel plus REST, GraphQL and Local APIs. In version 3 it installs inside a Next.js application, so the admin panel, the APIs and, if you wish, the public site can share one codebase. The repository licence is MIT, copyright Payload CMS, LLC, 2018-2026, so the project has existed since at least 2018.
The latest GitHub release when we checked was v3.90.2, published 23 September 2026. For the headless approach in general, read our headless guide.
| Fact | Detail |
|---|---|
| Licence | MIT |
| Latest version | 3.90.2 (23 September 2026) |
| Written in | JavaScript on Node.js 20.18.1 or higher, installed into Next.js |
| Database | MongoDB, PostgreSQL or SQLite (via adapters) |
| Hosting | Self-hosted anywhere Next.js can run |
| Price | Free software; hosting and development are yours to fund |
| Made by | Payload CMS, LLC |
Who is Payload best for?
Payload suits a publisher with in-house JavaScript developers or an agency that wants a free, flexible CMS and is comfortable building the editorial layer. Keeping the CMS and the front end in one codebase can simplify deployment and preview. It fits custom projects such as a magazine with unusual content types.
It does not suit a newsroom without developers. There is no theme, and the access model starts empty. If you want roles, approval and SEO output ready on day one, a traditional CMS or a more packaged headless product is a better start.
Editorial workflow
Payload’s Versions feature stores a full copy of each document version, with the user and timestamp, and lets editors browse changes, view diffs and restore earlier versions. You can configure it as an audit log only, as versions plus drafts, or as versions plus drafts plus autosave. Drafts add a _status field that reads draft, published or changed.
Roles are your job. The access control documentation describes no built-in roles. You define a role field on the user collection and write functions that decide who can read, create, update or delete. That is powerful and precise, but a journalist, sub-editor and publisher hierarchy has to be designed and tested by your developers. The documentation says draft visibility can be limited by querying _status.
Scheduled publishing and unpublishing are supported, but the drafts documentation says they require a job queue. There is no staged review workflow described in the pages we read; build one with fields and access rules or look for a plugin you have verified.
What the front end must handle: preview. Live Preview shows your front end in an iframe in the admin panel. Your front end must listen for window.postMessage events from the admin panel and re-render with the incoming data, and must work when embedded in an iframe. If you serve drafts on a preview route, protect it with authentication so unpublished articles are not exposed or indexed.
SEO, structured data and feeds
Payload offers an official SEO plugin, @payloadcms/plugin-seo, which adds a meta group with title, description and image to the collections you enable. It supports auto-generation functions, a search snippet preview and character counters, and can be extended with custom fields such as Open Graph tags or JSON-LD. It stores values; your front end must output them in the page head.
The rest is front-end work:
- Sitemaps: the documents we read describe no built-in sitemap. Generate XML from published documents, excluding drafts.
- Structured data: build
ArticleorNewsArticleJSON-LD from your fields. The SEO plugin can hold custom JSON-LD fields, but rendering is yours. - Redirects: the redirects plugin adds a
redirectscollection withfromandtofields. The documentation says it does not perform the redirect, so your front end or server must read the collection and issue the correct HTTP status. - Canonicals and hreflang: model and render them yourself.
- Feeds: RSS or Atom generated from the API by your front end.
Media, multilingual and performance
Uploads are built into collections. Payload adds filename, MIME type and file size fields, and with imageSizes configured it uses the Sharp library to crop and resize each upload. Files go to local disk by default, or to cloud storage through plugins; the deployment documentation names S3, Google Cloud Storage, Azure Blob and Vercel Blob. It also restricts risky file types, which you can whitelist by MIME type.
Localisation is field-level: add localized: true to a field and each locale holds its own value, with fallbacks by default. REST and the Local API accept locale=all to return every translation at once. Per-locale publishing status is described as an experimental beta. Caching and CDN setup are part of your front end and hosting.
Hosting and requirements
Payload needs Node.js 20.18.1 or higher and works only with specific Next.js ranges; the installation page warns that not all Next.js 15 or 16 releases are compatible, so pin versions deliberately. You choose a database adapter for MongoDB, PostgreSQL or SQLite.
The deployment documentation says Payload can run anywhere Next.js can, including Vercel, Netlify, DigitalOcean and AWS. You also arrange file storage, an email provider and a CDN. On ephemeral filesystems such as Heroku or DigitalOcean Apps, uploaded files vanish on restart unless you use third-party storage. Docker examples are provided. Scheduled publishing needs a job queue on top.
Extending Payload
Everything is configuration in code, plus official plugins such as the SEO and redirects plugins named above. Payload exposes REST, GraphQL and a Local API; the versions documentation confirms all three for version operations. The release notes mention multi-tenant, cloud storage and MCP plugins. We have not verified the size of the wider ecosystem, so we give no count.
What Payload costs
The software is free under the MIT licence. Your costs are developer time, which is the large one, plus hosting, a database, file storage, email and a CDN. We did not verify a hosted Payload plan or its pricing from the pages we read, so we quote none. See the cost guide for how these categories compare, and the licence guide for what MIT permits.
Where Payload falls short
- No packaged editorial roles. Access control is custom code, and the first release needs design work.
- Developer-only setup. Collections, fields and plugins are configured in code.
- Next.js version constraints. Only specific Next.js ranges work.
- Scheduling needs a job queue. It is not a switch in the admin panel.
- SEO and redirects are half-built. The plugins store data, while your front end outputs and applies it.
- Ephemeral hosts need extra storage. Uploads can disappear on some platforms.
The verdict for publishers
Payload is a strong choice for a publisher that has developers and wants a free, code-first CMS sitting beside a Next.js site. The versions, drafts, localisation and upload systems are documented in depth, and the MIT licence leaves you free to host and modify as you like.
It is the wrong tool if you need a working editorial setup without engineering. Compare it with other headless systems and self-hosted options on the comparison hub. This profile is based on vendor documentation, not an install; see how we test.
Questions people ask
Is Payload really free?
The software is MIT-licensed according to its repository, so there is no licence fee. You pay for hosting, a database, file storage and developer time. We did not verify any paid vendor plan, so we quote no subscription prices.
Does Payload need Next.js?
Payload 3 installs inside a Next.js application, and the installation documentation lists the supported Next.js versions. Your front end can live in the same app, or you can use Payload's APIs from a separate site.
Does Payload have editor roles built in?
The access control documentation describes no built-in roles. Developers define a role field on the user collection and write access functions that check it. A newsroom needs that designed and built before editors log in.
Can Payload schedule articles?
Yes. Scheduled publishing and unpublishing are documented under drafts, but they require a job queue to be set up. That is a hosting and developer task, not a switch.
Who handles redirects and sitemaps in Payload?
Your front end. Payload's redirects plugin stores redirect pairs but does not apply them, and the documents we read describe no built-in sitemap feature. Developers must apply redirects and generate sitemaps.
Sources
- Payload's repository is licensed under the MIT Licence, copyright Payload CMS, LLC, 2018-2026. — source, checked 10 October 2026.
- The latest Payload release on GitHub is v3.90.2, published 23 September 2026. — source, checked 10 October 2026.
- Payload requires Node.js 20.18.1 or higher and any JavaScript package manager, works only with specific Next.js version ranges, and offers database adapters for MongoDB, PostgreSQL and SQLite. — source, checked 10 October 2026.
- Payload's Versions feature stores version history in a separate collection and can be configured as versions only, versions plus drafts, or versions plus drafts plus autosave; versions can be browsed, compared and restored. — source, checked 10 October 2026.
- Drafts add a _status field (draft, published, changed); scheduled publishing and unpublishing are supported but require a job queue to be set up, and draft visibility can be restricted with access control on _status. — source, checked 10 October 2026.
- Payload does not describe built-in roles; access control is written as functions in code, and roles are fields you define on your user collection. — source, checked 10 October 2026.
- Live Preview renders the front end in an iframe in the Admin Panel, and the front end must listen for window.postMessage events from the Admin Panel and re-render with the data it receives. — source, checked 10 October 2026.
- The @payloadcms/plugin-seo package adds a meta field group (title, description, image) with auto-generation functions, a search snippet preview and character counters, and can be extended with custom fields such as Open Graph tags or JSON-LD. — source, checked 10 October 2026.
- The redirects plugin adds a redirects collection with from and to fields but, according to the documentation, does not handle the redirect itself; the front end must apply the redirects. — source, checked 10 October 2026.
- Payload localisation is field-level (localized: true on a field), supports fallback locales, and an experimental beta feature allows publishing status to vary by locale. — source, checked 10 October 2026.
- Upload-enabled collections add filename, mimeType and filesize fields; with imageSizes configured, Payload uses Sharp to crop and resize uploads; files are stored locally by default unless a storage plugin such as S3 is used. — source, checked 10 October 2026.
- Payload can be deployed anywhere Next.js can run, and on ephemeral filesystem hosts such as Heroku or DigitalOcean Apps uploaded files are deleted on restart unless third-party storage is used. — source, checked 10 October 2026.