Payload CMSBLOCK
Payload CMS MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A specialized MCP server for Payload CMS 3.0 Validate code, generate templates, and scaffold projects following best practices
📋 Overview
The Payload CMS 3.0 MCP Server is a specialized Model Context Protocol server designed to enhance your Payload CMS development experience. It helps developers build better Payload CMS applications by providing code validation, template generation, and project scaffolding capabilities that follow best practices.
✨ Features
📚 Code Validation Validate Payload CMS code for collections, fields, globals, and config files with detailed feedback on syntax errors and best practices.
🔍 Code Generation Generate code templates for collections, fields, globals, access control, hooks, endpoints, plugins, blocks, and migrations.
🚀 Project Scaffolding Scaffold entire Payload CMS projects with validated options for consistency and adhere
b7d481b22bacOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add payload-cms-mcp --env CRON_SECRET=${CRON_SECRET} --env PAYLOAD_SECRET=${PAYLOAD_SECRET} -- npx -y [email protected]{
"mcpServers": {
"payload-cms-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CRON_SECRET": "${CRON_SECRET}",
"PAYLOAD_SECRET": "${PAYLOAD_SECRET}"
}
}
}
}Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Timestamps | read | Collections should have timestamps enabled |
echo | read | |
generate_collection | read | |
generate_field | read | |
generate_template | read | |
mcp_query | read | |
query | read | |
scaffold_project | read | |
validate | read |
Trust audit
BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (14)
const collection = eval(`(${code})`);const field = eval(`(${code})`);const global = eval(`(${code})`);const config = eval(`(${code})`);tls: redisUrl.startsWith('rediss://') ? { rejectUnauthorized: false } : undefined,tls: redisUrl.startsWith('rediss://') ? { rejectUnauthorized: false } : undefined,tls: redisUrl.startsWith('rediss://') ? { rejectUnauthorized: false } : undefined,: 'DATABASE_URI=postgres://postgres:postgres@localhost:5432/payload-cms-3-project'}
.DS_Store
.DS_Store
<img src="https://www.payloadcmsmcp.info/logopayload.png" alt="Payload CMS Logo" width="120" height="120" style="border-radius: 10px; padding: 5px; background-color: white; box-shadow: 0 3px 10px rgba
.DS_Store
.DS_Store
@modelcontextprotocol/sdk, content-type, express, http-proxy-middleware, raw-body, redis, zod, @types/node
Gates applied: no_behavioural_pass.
b7d481b22bacfull audit observations/trust-audit/mcp-server/matmax-worldwide__payload-cms.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b7d481b22bac | BLOCK | F | 48 | first audit |
Questions
What is the Payload CMS MCP server?
Payload CMS MCP Server
What tools does Payload CMS expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Payload CMS safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (48/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Payload CMS need?
It reads CRON_SECRET and PAYLOAD_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Payload CMS run?
It speaks sse, so it runs as a service you connect to over the network. It is published on npm as payload-cms-mcp at 1.0.2.
How current is this page?
The grade is for one exact copy of the source (b7d481b22bac), read on 2026-10-07. The repository is watched and re-audited when it changes.