Payload CMS integration for AI agents.
Payload CMS integration for AI agents with secure authentication and server-side credential injection. Open Connector runs the OAuth, seals the token in an encrypted vault, and serves Payload CMS tools to your agent over MCP or a typed API — credentials injected server-side, every call audited, nothing leaving your infrastructure. Open source (AGPL-3.0) and self-hostable.
Real Payload CMS actions, managed and audited.
Your user connects Payload CMS once; your agent can then read and manage content in a Payload CMS deployment through its REST and GraphQL APIs — scoped to the OAuth permissions you grant and the tool allowlist you configure. Every action is least-privilege and written to a tamper-evident audit trail.
- 1
Your user grants Payload CMS access once (OAuth) — the token lands in the vault.
- 2
Your agent calls a tool over MCP or the typed API; Open Connector injects the credential server-side.
- 3
Every routed call appends a hash-chained audit record — nothing leaves your infra.
Supported Payload CMS tools.
10 tools are generated from the published Payload CMS catalog. Descriptions are plain text; each action remains subject to its configured authentication and tool allowlist.
Showing 10 tools. All published catalog entries are included in this page's server-rendered HTML.
- Run Payload CMS GraphQL query or mutation
- Executes an arbitrary GraphQL query or mutation against Payload CMS's API using the connected account. Use this escape hatch when reviewed tools do not cover the needed operation.
- graphqladvancedreadwrite
- Check Payload GraphQL endpoint
- Checks that the configured Payload GraphQL endpoint accepts a schema-independent query.
- graphqlhealthread
- Count Payload collection documents
- Counts documents visible in a Payload collection.
- collectionscountrestread
- Create a Payload collection document
- Creates one document in a Payload collection using fields accepted by the connected project schema.
- collectionscreaterestwrite
- Delete a Payload document by ID
- Deletes one Payload collection document by ID.
- collectionsdeleterestwrite
- Find Payload collection documents
- Lists documents from a Payload collection. The collection slug and available fields come from the connected project.
- collectionsrestread
- Find a Payload document by ID
- Retrieves one document from a Payload collection by ID.
- collectionsrestread
- Update a Payload document by ID
- Updates one Payload collection document by ID using fields accepted by the connected project schema.
- collectionsrestupdatewrite
- Get a Payload global
- Retrieves a Payload global by its project-defined slug.
- globalsrestread
- Update a Payload global
- Updates a Payload global using fields accepted by the connected project schema.
- globalsrestupdatewrite
Payload CMS integration, answered
- How do AI agents use Payload CMS through Open Connector?
- Your user connects Payload CMS once with one of its cataloged authentication methods. Open Connector stores the credential in an encrypted vault and exposes Payload CMS tools to your agent over MCP or a typed API, with credentials injected server-side on each call.
- Is this a Payload CMS MCP server?
- Yes. Open Connector can serve Payload CMS as a named MCP server with a scoped allowlist and a per-user connection URL, so any MCP client can call Payload CMS actions with credentials injected server-side.
- Where do Payload CMS credentials live?
- In your own infrastructure. Open Connector keeps credentials in its own vault and injects them at call time, so they never leave your environment.
Give your agents Payload CMS — keep the keys.
Open source, self-hostable, with Payload CMS credentials that never leave your infrastructure. Run it from source today.