Agent skill

Payload

by payloadcms in payloadcms/payload

A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

MITAuto-check passedBackend & APIs

Install Payload

skills CLI
$ npx skills add payloadcms/payload --skill payload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install payloadcms/payload payload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/payload/skills/payload .claude/skills/payload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
payload
GitHub stars
45k
Used in
5 other repos
Token cost
~6.2k tokens
SKILL.md length
1,391 words
Files
12
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

  • Works in 3 steps: Local API Access Control (CRITICAL) → Transaction Failures in Hooks → Infinite Hook Loops
  • Working with Payload projects (payload.config.ts
  • SKILL.md covers Quick Reference, Quick Start, Essential Patterns and Security Pitfalls, plus 6 more sections
  • Calls npx and pnpm; needs PAYLOAD_SECRET

What it does

Payload is an agent skill from payloadcms/payload. Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files (for example `reference/ACCESS-CONTROL-ADVANCED.md`, `reference/ACCESS-CONTROL.md` and `reference/ADAPTERS.md`).

It sits in Backend & APIs, covering Authorization and RBAC. It works with Payload CMS, Next.js and TypeScript. The repository describes itself as: Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a… The licence is MIT.

When your agent uses it

  • Working with Payload projects (payload.config.ts
  • Debugging validation errors
  • Security issues
  • Relationship queries

Example prompts

  • “/payload”

Requirements

  • Node.js
  • A credential in PAYLOAD_SECRET

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Local API Access Control (CRITICAL)
  2. Transaction Failures in Hooks
  3. Infinite Hook Loops

What it can do on your machine

Read from SKILL.md and the folder at commit ed6a954. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • payloadcms.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PAYLOAD_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Payload loads about 6.2k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 1,391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from payloadcms/payload at commit ed6a954, republished under its MIT licence (© payloadcms). 1,391 words, ~6,213 tokens.

Download SKILL.mdSave it as .claude/skills/payload/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
payload
description
Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.

Payload Application Development

Payload is a Next.js native CMS with TypeScript-first architecture, providing admin panel, database management, REST/GraphQL APIs, authentication, and file storage.

Quick Reference

TaskSolutionDetails
Auto-generate slugs{ type: 'slug', useAsSlug: 'title' }FIELDS.md#slug-field
Restrict content by userAccess control with queryACCESS-CONTROL.md#row-level-security-with-complex-queries
Local API user opsuser + overrideAccess: falseQUERIES.md#access-control-in-local-api
Draft/publish workflowversions: { drafts: true }COLLECTIONS.md#versioning--drafts
Computed fieldsvirtual: true with field-level hooks.afterRead returning the valueFIELDS.md#virtual-fields
Document titlesStored top-level field in admin.useAsTitleCOLLECTIONS.md#useastitle
Conditional fieldsadmin.conditionFIELDS.md#conditional-fields
Custom field validationvalidate functionFIELDS.md#validation
Filter relationship listfilterOptions on fieldFIELDS.md#relationship
Select specific fieldsselect parameterQUERIES.md#field-selection
Auto-set author/datesbeforeChange hookHOOKS.md#collection-hooks
Prevent hook loopsreq.context checkHOOKS.md#context
Cascading deletesbeforeDelete hookHOOKS.md#collection-hooks
Geospatial queriespoint field with near/withinFIELDS.md#point-geolocation
Reverse relationshipsjoin field typeFIELDS.md#join-fields
Next.js revalidationContext control in afterChangeHOOKS.md#nextjs-revalidation-with-context-control
Query by relationshipNested property syntaxQUERIES.md#nested-properties
Complex queriesAND/OR logicQUERIES.md#andor-logic
TransactionsPass req to operationsADAPTERS.md#threading-req-through-operations
Background jobsJobs queue with tasksADVANCED.md#jobs-queue
Custom API routesCollection custom endpointsADVANCED.md#custom-endpoints
Cloud storageStorage adapter pluginsADAPTERS.md#storage-adapters
Multi-languagelocalization config + localized: trueADVANCED.md#localization
Create plugin(options) => (config) => ConfigPLUGIN-DEVELOPMENT.md#plugin-architecture
Plugin package setupPackage structure with SWCPLUGIN-DEVELOPMENT.md#plugin-package-structure
Add fields to collectionMap collections, spread fieldsPLUGIN-DEVELOPMENT.md#adding-fields-to-collections
Plugin hooksPreserve existing hooks in arrayPLUGIN-DEVELOPMENT.md#adding-hooks
Check field typeType guard functionsFIELD-TYPE-GUARDS.md

Quick Start

bash
npx create-payload-app@latest my-app
cd my-app
pnpm dev
Minimal Config
ts
import { buildConfig } from 'payload'
import { mongooseAdapter } from '@payloadcms/db-mongodb'
import { lexicalEditor } from '@payloadcms/richtext-lexical'
import path from 'path'
import { fileURLToPath } from 'url'

const filename = fileURLToPath(import.meta.url)
const dirname = path.dirname(filename)

export default buildConfig({
  admin: {
    user: 'users',
    importMap: {
      baseDir: path.resolve(dirname),
    },
  },
  collections: [Users, Media],
  editor: lexicalEditor(),
  secret: process.env.PAYLOAD_SECRET,
  typescript: {
    outputFile: path.resolve(dirname, 'payload-types.ts'),
  },
  db: mongooseAdapter({
    url: process.env.DATABASE_URL,
  }),
})

Essential Patterns

Defaults & Conventions

Apply these defaults when modeling content unless there's a clear reason not to:

  • Enable drafts/versions by default: versions: { drafts: true }. This is the recommended starting point for any content collection. It auto-injects a _status field (draft / published / changed) — don't add your own status field, it's redundant. Only skip versions for collections that have no publish/draft lifecycle (e.g. internal join tables, settings).
  • Use the native slug field type for all slugs instead of hand-rolling { name: 'slug', type: 'text', unique: true }. It auto-generates the slug from a source field, adds a regenerate toggle, and defaults to required, unique, index, and position: 'sidebar'. useAsSlug is required — name the source field to generate from: { name: 'slug', type: 'slug', useAsSlug: 'title' }.
  • position: 'sidebar' is for short, at-a-glance fields — status, category, author, publish date. Avoid it for long fields that need horizontal space to be usable (description, rich text content, long text). Those belong in the main document area.
  • Use a stored top-level field for admin.useAsTitle. Never set admin.useAsTitle to a computed field configured with virtual: true; these fields are not queryable and Payload rejects the configuration. A relationship-path virtual such as virtual: 'author.name' is supported, but use it only when the title must come from a related document.
Basic Collection
ts
import type { CollectionConfig } from 'payload'

export const Posts: CollectionConfig = {
  slug: 'posts',
  admin: {
    useAsTitle: 'title',
    // _status (from versions.drafts) shows the draft/published state — no custom status field needed
    defaultColumns: ['title', 'author', '_status', 'createdAt'],
  },
  versions: {
    drafts: true,
  },
  fields: [
    { name: 'title', type: 'text', required: true },
    { name: 'slug', type: 'slug', useAsSlug: 'title' }, // auto-generates from `title`, unique + indexed, sidebar position
    { name: 'content', type: 'richText' }, // long field — stays in the main area, not the sidebar
    // short, at-a-glance field — good sidebar candidate
    { name: 'author', type: 'relationship', relationTo: 'users', admin: { position: 'sidebar' } },
  ],
  timestamps: true,
}

For more collection patterns (auth, upload, drafts, live preview), see COLLECTIONS.md.

Common Fields
ts
// Text field
{ name: 'title', type: 'text', required: true }

// Relationship
{ name: 'author', type: 'relationship', relationTo: 'users', required: true }

// Rich text
{ name: 'content', type: 'richText', required: true }

// Slug — use the native field type instead of a hand-rolled text field
{ name: 'slug', type: 'slug', useAsSlug: 'title' }

// Select (for genuine taxonomy — NOT publish state; use versions.drafts + _status for that)
{ name: 'category', type: 'select', options: ['news', 'tutorial', 'opinion'] }

// Upload
{ name: 'image', type: 'upload', relationTo: 'media' }

For all field types (array, blocks, point, join, virtual, conditional, etc.), see FIELDS.md.

Hook Example

Hooks live at one of two levels and they are not interchangeable. Collection hooks receive { doc, data, req, operation, ... } and act on the whole document. Field hooks live inside an individual field's hooks object, receive { value, siblingData, ... }, and return the new value for that field. Computed/virtual fields, per-field formatters, and per-field access masking are field hooks; cross-field business logic is a collection hook.

ts
// Collection-level: business logic across the document
export const Posts: CollectionConfig = {
  slug: 'posts',
  hooks: {
    beforeChange: [
      async ({ data, operation }) => {
        if (operation === 'create') {
          data.slug = slugify(data.title)
        }
        return data
      },
    ],
  },
  fields: [{ name: 'title', type: 'text' }],
}

// Field-level: compute / format a single field's value (virtual fields use this)
export const Users: CollectionConfig = {
  slug: 'users',
  fields: [
    { name: 'firstName', type: 'text' },
    { name: 'lastName', type: 'text' },
    {
      name: 'fullName',
      type: 'text',
      virtual: true,
      hooks: {
        afterRead: [({ siblingData }) => `${siblingData.firstName} ${siblingData.lastName}`],
      },
    },
  ],
}

When asked to "compute a field" or "populate a field's value in a hook", use a field-level hook on that field — never a collection-level afterRead that mutates doc.

For all hook patterns, see HOOKS.md. For access control, see ACCESS-CONTROL.md.

Access Control with Type Safety
ts
import type { Access } from 'payload'
import type { User } from '@/payload-types'

// Type-safe access control
export const adminOnly: Access = ({ req }) => {
  const user = req.user as User
  return user?.roles?.includes('admin') || false
}

// Row-level access control
export const ownPostsOnly: Access = ({ req }) => {
  const user = req.user as User
  if (!user) return false
  if (user.roles?.includes('admin')) return true

  return {
    author: { equals: user.id },
  }
}
Query Example
ts
// Local API
const posts = await payload.find({
  collection: 'posts',
  overrideAccess: true,
  where: {
    status: { equals: 'published' },
    'author.name': { contains: 'john' },
  },
  depth: 2,
  limit: 10,
  sort: '-createdAt',
})

// Query with populated relationships
const post = await payload.findByID({
  collection: 'posts',
  overrideAccess: true,
  id: '123',
  depth: 2, // Populates relationships (default is 2)
})
// Returns: { author: { id: "user123", name: "John" } }

// Without depth, relationships return IDs only
const post = await payload.findByID({
  collection: 'posts',
  overrideAccess: true,
  id: '123',
  depth: 0,
})
// Returns: { author: "user123" }

For all query operators and REST/GraphQL examples, see QUERIES.md.

Getting Payload Instance
ts
// In API routes (Next.js)
import { getPayload } from 'payload'
import config from '@payload-config'

export async function GET(request: Request) {
  const payload = await getPayload({ config })
  const { user } = await payload.auth({ headers: request.headers })

  const posts = await payload.find({
    collection: 'posts',
    overrideAccess: false, // this route answers for whoever called it
    user,
  })

  return Response.json(posts)
}

// In Server Components
import { headers } from 'next/headers'
import { getPayload } from 'payload'
import config from '@payload-config'

export default async function Page() {
  const payload = await getPayload({ config })
  const { user } = await payload.auth({ headers: await headers() })
  const { docs } = await payload.find({
    collection: 'posts',
    overrideAccess: false,
    user,
  })

  return <div>{docs.map(post => <h1 key={post.id}>{post.title}</h1>)}</div>
}

Security Pitfalls

1. Local API Access Control (CRITICAL)

overrideAccess: true bypasses ALL access control, even when a user is passed.

ts
// ❌ SECURITY BUG: Passes user but bypasses their permissions anyway
await payload.find({
  collection: 'posts',
  user: someUser,
  overrideAccess: true, // Access control is BYPASSED!
})

// ✅ SECURE: Respects the user's permissions — this is the default, overrideAccess can be omitted
await payload.find({
  collection: 'posts',
  user: someUser,
})

On Local API operations where overrideAccess is optional, it defaults to false — Access Control is respected unless explicitly bypassed.

  • Omit it, or set overrideAccess: false - operating on behalf of a user (API routes, user-facing server functions, and webhooks acting as a user). Pass user alongside it.
  • overrideAccess: true - trusted system work (cron jobs, seeds, migrations, system tasks, and independently authenticated webhooks intentionally granted full permissions)

Never set overrideAccess: true out of habit or by copying a nearby call — pick the value this call means.

See QUERIES.md#access-control-in-local-api.

2. Transaction Failures in Hooks

Nested operations in hooks without req break transaction atomicity.

ts
// ❌ DATA CORRUPTION RISK: Separate transaction
hooks: {
  afterChange: [
    async ({ doc, req }) => {
      await req.payload.create({
        collection: 'audit-log',
        overrideAccess: true,
        data: { docId: doc.id },
        // Missing req - runs in separate transaction!
      })
    },
  ]
}

// ✅ ATOMIC: Same transaction
hooks: {
  afterChange: [
    async ({ doc, req }) => {
      await req.payload.create({
        collection: 'audit-log',
        overrideAccess: true,
        data: { docId: doc.id },
        req, // Maintains atomicity
      })
    },
  ]
}

See ADAPTERS.md#threading-req-through-operations.

3. Infinite Hook Loops

Hooks triggering operations that trigger the same hooks create infinite loops.

ts
// ❌ INFINITE LOOP
hooks: {
  afterChange: [
    async ({ doc, req }) => {
      await req.payload.update({
        collection: 'posts',
        overrideAccess: true,
        id: doc.id,
        data: { views: doc.views + 1 },
        req,
      }) // Triggers afterChange again!
    },
  ]
}

// ✅ SAFE: Use context flag
hooks: {
  afterChange: [
    async ({ doc, req, context }) => {
      if (context.skipHooks) return

      await req.payload.update({
        collection: 'posts',
        overrideAccess: true,
        id: doc.id,
        data: { views: doc.views + 1 },
        context: { skipHooks: true },
        req,
      })
    },
  ]
}

See HOOKS.md#context.

Project Structure

txt
src/
├── app/
│   ├── (frontend)/
│   │   └── page.tsx
│   └── (payload)/
│       └── admin/[[...segments]]/page.tsx
├── collections/
│   ├── Posts.ts
│   ├── Media.ts
│   └── Users.ts
├── globals/
│   └── Header.ts
├── components/
│   └── CustomField.tsx
├── hooks/
│   └── slugify.ts
└── payload.config.ts

Building & Type Generation

Payload generates payload-types.ts for you — you rarely need to run generate:types by hand.

  • During development: typescript.autoGenerate defaults to true, so the dev server regenerates types automatically whenever your config changes. Don't run generate:types manually while the dev server is running — it's redundant.
  • During builds: payload build generates the import map and types before running next build. Prefer it over calling next build directly so neither is ever stale. Pass --no-types to skip type generation.
  • Manual generation (payload generate:types) is an escape hatch — only when neither the dev server nor a build is in the loop (e.g. a one-off script, or CI before a step that doesn't run payload build).
ts
// payload.config.ts
export default buildConfig({
  typescript: {
    outputFile: path.resolve(dirname, 'payload-types.ts'),
    // autoGenerate defaults to true — types regenerate in dev automatically
  },
})

// Usage
import type { Post, User } from '@/payload-types'
Show full SKILL.md (558 more words)Show less

Common Gotchas

  1. Local API operations with optional overrideAccess respect access control by default — set it to true only for trusted server-side work
  2. Missing req in nested operations breaks transaction atomicity
  3. Hook loops — operations in hooks can re-trigger the same hooks; use req.context flags
  4. Field-level access returns boolean only, no query constraints
  5. Relationship depth defaults to 2; set depth: 0 for IDs only
  6. Draft status — _status field is auto-injected when drafts are enabled
  7. Types regenerate automatically in dev (autoGenerate) and during payload build — avoid running generate:types manually
  8. MongoDB transactions require replica set configuration
  9. SQLite transactions are disabled by default; enable with transactionOptions: {}
  10. Point fields are not supported in SQLite
  11. Computed virtual titles — fields configured with virtual: true cannot be used in admin.useAsTitle; use a stored top-level field

Best Practices

Content Modeling
  • Enable versions: { drafts: true } by default on content collections; rely on the auto-injected _status field rather than adding a custom status field
  • Use the native slug field type for slugs instead of hand-rolling a unique text field
  • Use a stored top-level field for admin.useAsTitle; never use a computed virtual: true field as the title
  • Reserve position: 'sidebar' for short, at-a-glance fields (status, category, author, date); keep long fields (description, rich text) in the main area
Security
  • Default to restrictive access, gradually add permissions
  • Use overrideAccess: false whenever the call acts for a user, and pass that user
  • Field-level access only returns boolean (no query constraints)
  • Never trust client-provided data
  • Use saveToJWT: true for roles to avoid database lookups
Performance
  • Index frequently queried fields
  • Use select to limit returned fields
  • Set maxDepth on relationships to prevent over-fetching
  • Prefer query constraints over async operations in access control
  • Cache expensive operations in req.context
Data Integrity
  • Always pass req to nested operations in hooks
  • Use context flags to prevent infinite hook loops
  • Enable transactions for MongoDB (requires replica set) and Postgres
  • Use beforeValidate for data formatting
  • Use beforeChange for business logic
Type Safety
  • Let dev (autoGenerate) and payload build generate types; run generate:types manually only when neither is running
  • Import types from generated payload-types.ts
  • Type your user object: import type { User } from '@/payload-types'
  • Use field type guards for runtime type checking
  • When extracting any Payload value into a named constant — a collection, field, hook, access function, plugin, etc. — annotate it with the matching Payload type (CollectionConfig, Field, CollectionBeforeChangeHook, Access, Plugin, …) or use satisfies <Type>. Without an annotation, string properties like type: 'text' widen to string and discriminated unions (Field, CollectionConfig) fail to resolve. Inline literals get this for free via contextual typing; extracted constants do not.
Organization
  • Keep collections in separate files
  • Extract access control to access/ directory
  • Extract hooks to hooks/ directory
  • Use reusable field factories for common patterns
  • Document complex access control with comments

Reference Documentation

  • FIELDS.md - All field types, validation, admin options
  • FIELD-TYPE-GUARDS.md - Type guards for runtime field type checking and narrowing
  • COLLECTIONS.md - Collection configs, auth, upload, drafts, live preview
  • HOOKS.md - Collection hooks, field hooks, context patterns
  • ACCESS-CONTROL.md - Collection, field, global access control, RBAC, multi-tenant
  • ACCESS-CONTROL-ADVANCED.md - Context-aware, time-based, subscription-based access, factory functions, templates
  • QUERIES.md - Query operators, Local/REST/GraphQL APIs
  • ENDPOINTS.md - Custom API endpoints: authentication, helpers, request/response patterns
  • ADAPTERS.md - Database, storage, email adapters, transactions
  • ADVANCED.md - Authentication, jobs, endpoints, components, plugins, localization
  • PLUGIN-DEVELOPMENT.md - Plugin architecture, monorepo structure, patterns, best practices

Resources

© payloadcms, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files in packages/payload/skills/payload of payloadcms/payload.

  • SKILL.md
  • reference/ACCESS-CONTROL-ADVANCED.md
  • reference/ACCESS-CONTROL.md
  • reference/ADAPTERS.md
  • reference/ADVANCED.md
  • reference/COLLECTIONS.md
  • reference/ENDPOINTS.md
  • reference/FIELD-TYPE-GUARDS.md
  • reference/FIELDS.md
  • reference/HOOKS.md
  • reference/PLUGIN-DEVELOPMENT.md
  • reference/QUERIES.md

Open the folder on GitHubat commit ed6a954

Used in 6 other repositories

We found 27 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in payloadcms/payload, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Payload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Payload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Payload this skillpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Better Autheinverne/dotfiles121—~4kAutomated safety check: NotesMIT
Better Authsecondsky/claude-skills227—~7.5kAutomated safety check: PassMIT
Shipany SaaS Boilerplate Referencelittleben/awesomeAgentskills188—~645Automated safety check: PassMIT
Qstash JSupstash/qstash-js2691 repos~746Automated safety check: PassMIT
Stack Previewvicoa-ai/vicoa490—~1.8kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Better Auth

    einverne/dotfiles

    Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.

    121 GitHub stars~4k tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes
  • Better Auth

    secondsky/claude-skills

    Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks.

    227 GitHub stars~7.5k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Shipany SaaS Boilerplate Reference

    littleben/awesomeAgentskills

    Shipany AI-powered SaaS boilerplate documentation. Use when working with Shipany framework, Next.js 15, TypeScript, Drizzle ORM, NextAuth, payment…

    188 GitHub stars~645 tokensUpdated 8 mo ago
    Backend & APIsAuto-check passed
  • Qstash JS

    upstash/qstash-js

    Official

    Work with the QStash JavaScript/TypeScript SDK for serverless messaging, scheduling.

    269 GitHub starsUsed in 1 repo~746 tokens
    Backend & APIsAuto-check passed
  • Stack Preview

    vicoa-ai/vicoa

    Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or…

    490 GitHub stars~1.8k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Implementation patterns for Upstash Workflow and QStash handlers in the LobeHub codebase: dry runs, fan-out chunking and single-item execution.

    83k GitHub stars~1.7k tokensUpdated today
    Backend & APIsAuto-check passed

More from payloadcms/payload

All 9 skills in this repo
  • Record PR Demo

    payloadcms/payload

    A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.

    45k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Audit Dependencies

    payloadcms/payload

    A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

    45k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Generate Translations

    payloadcms/payload

    A skill your agent uses when new translation keys are added to packages to generate new translations strings

    45k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Triage CI Flake

    payloadcms/payload

    A skill your agent uses when CI tests fail on main branch after PR merge, when investigating flaky test failures, or when user provides a PR URL/number to aggregate all failing tests

    45k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Ui4 Convert Tests

    payloadcms/payload

    A skill your agent uses when UI changes are complete and e2e tests need updating.

    45k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Payload Accessibility

    payloadcms/payload

    A skill your agent uses when changing or reviewing rendered Payload UI, interaction or focus behavior, semantic markup, accessibility tests, or WCAG/VPAT evidence.

    45k GitHub stars~808 tokensUpdated today
    Auto-check passed

Questions about Payload

What does Payload do?

A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Payload is an agent skill from payloadcms/payload.ts, collections, fields, hooks, access control, Payload API).

When should I use Payload?

Payload fits situations like: working with Payload projects (payload.config.ts; debugging validation errors; security issues; relationship queries.

How do I install Payload in Claude Code?

Run `npx skills add payloadcms/payload --skill payload -a claude-code`. Or copy the skill folder (packages/payload/skills/payload in payloadcms/payload) into .claude/skills/payload in your project. Claude Code loads it when a task matches its description.

How do I install Payload in Codex?

Run `npx skills add payloadcms/payload --skill payload -a codex`. Or copy the skill folder (packages/payload/skills/payload in payloadcms/payload) into .agents/skills/payload in your project. Codex loads it when a task matches its description.

Can I use Payload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add payloadcms/payload --skill payload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payload, .gemini/skills/payload, .github/skills/payload and .opencode/skills/payload in your project.

What does Payload need to run?

Going by SKILL.md and its folder, Payload needs the command-line tools its instructions call (npx and pnpm) and credentials named PAYLOAD_SECRET. Our summary lists: Node.js; A credential in PAYLOAD_SECRET.

Does Payload access the network?

SKILL.md names 1 domain. As links in the text: payloadcms.com. This is read from the text; nothing was executed.

Is Payload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Payload use?

Payload is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Payload use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Payload?

Skills that share tags, products or a category with Payload: Better Auth (einverne/dotfiles, 121 stars), Better Auth (secondsky/claude-skills, 227 stars), Shipany SaaS Boilerplate Reference (littleben/awesomeAgentskills, 188 stars) and Qstash JS (upstash/qstash-js, 269 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Payload?

payloadcms (a GitHub organization) maintains it in payloadcms/payload, which has 45,120 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: payloadcms/payload on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.