Payload CMS in 2026: What It Is and When It Fits
Choosing a CMS decides more than where your content lives. It decides how quickly your marketing team can publish, who owns your data, what it costs each time you add an editor, and how much work every new page type takes. Payload has become one of the most talked-about options for businesses building on Next.js. Its GitHub repository has around 45,000 stars, and it was downloaded about three million times in the month to late September 2026.
This guide is for the people who have to make the call: what Payload is, what changed when Figma bought it, where it shines and where it asks more of you.
What Payload is
Payload describes itself as "the Next.js fullstack framework". In practice, a developer describes your content in code: the kinds of content you have, such as pages, articles or products, the fields each one needs, and who is allowed to see or change what. From that description Payload builds the admin panel your team edits in, the database behind it, the APIs your website and apps read from, and the logins and permissions that protect it all.
Since version 3.0, released in November 2024, Payload installs directly inside a Next.js application. The website and the CMS become one project that deploys together, and the site reads content straight from Payload without a trip across the network. For a business, that means one codebase to maintain, one deployment and no separate CMS server to keep in step with the site.
The software is open source under the MIT licence, so it is free to use, including commercially. Payload was founded by James Mikrut, Dan Ribbens and Elliot DeNolf in Grand Rapids, Michigan, and went through Y Combinator in 2022.
What changed when Figma bought it
In June 2025, Figma announced that Payload was joining the company. Both sides said Payload would stay open source, its founders still run the project, and as of September 2026 the licence is unchanged. The practical difference for new projects is hosting. Payload's own managed hosting, Payload Cloud, has paused new deployments, so a new Payload site means choosing and running your own infrastructure on a platform such as Vercel, AWS or Cloudflare.
Our read is that the acquisition makes Payload a safer long-term bet and could bring design-to-content tooling later. It does not change what kind of CMS it is.
What your team gets
Editors get an admin panel shaped around your own content rather than a generic template. The rich text editor can hold embedded blocks, so a marketer can drop a call to action or a product card into an article. There are drafts, version history, autosave and scheduled publishing, and live preview shows the real page while you edit. Content can be translated field by field, and the admin interface itself is available in more than 30 languages.
Developers work in TypeScript throughout, so the content model and the code stay in step. Access control reaches individual documents and fields, hooks run your own logic whenever content changes, and you choose the database, whether MongoDB, Postgres or SQLite. Official plugins cover SEO, forms, redirects, search, multi-tenant sites and e-commerce, and a paid Enterprise tier adds single sign-on, publishing workflows, audit logs and AI features for teams that need them.
Where it asks more of you
Payload is a developer's tool first. The content model lives in code, so adding a new content type is a development task, and the quality of the editing experience depends on how well it was built. There is no drag-and-drop schema builder.
You also run it. Hosting, backups, monitoring and upgrades are your responsibility, and upgrades are not optional. In September 2026 Payload published a large batch of security fixes, several of them rated critical, and asked every site to move to version 3.90.0 or later. The fixes arrived quickly, but they only protect the sites that apply them, so a maintenance plan belongs in the budget from day one.
Two smaller points are worth knowing. The plugin ecosystem numbers in the hundreds rather than the tens of thousands WordPress offers, so more gets built than installed. And a document locks while someone edits it, so there is no real-time co-editing of the kind Sanity offers. Payload 4.0, now in preview, adds a redesigned admin panel and support for frameworks beyond Next.js, along with some breaking changes to plan for.
When Payload is the right choice
Payload fits best when your site is built on Next.js and you have developers, in-house or through a partner, to look after it. It suits businesses that want to own their content and data on infrastructure they choose, and teams where many people need editing access, because there is no fee per editor. It is especially strong when content goes beyond pages into products, members or anything app-like, where a full backend earns its keep.
It is the wrong choice if nobody can maintain code, if you want a fully managed service with no hosting decisions, or if real-time co-editing is central to how your team works. In those cases a hosted CMS such as Sanity or Hygraph will serve you better.
How we build with it
We start by modelling the content with the people who will edit it, so the admin panel matches how they actually work. Roles and permissions are decided up front, drafts and live preview are wired in from the start, and hosting, backups and monitoring are set up alongside the site rather than after launch. Before handover we agree an update policy, so security patches are applied on a schedule you know about, and your team gets training and documentation of the content model.
If you are weighing Payload against the alternatives, talk to us. We will look at your content, your team and your stack, and tell you honestly whether it is the right fit.
Payload, the Payload design, and related marks, designs, and logos are trademarks or registered trademarks of Payload CMS, Inc. in the U.S. and other countries.




