(Still in Development β your support is appreciated!)
It's lightning fast, flexible and an easy to use modern content management system to provide a headless backend
This SveltyCMS headless CMS provides a powerful backend based on a modern SvelteKit 3 / Svelte 5 framework (on the SvelteKit 3 release-candidate β see svelte.dev/blog/sveltekit-3-release-candidate). Being designed to be database agnostic, we fully support MongoDB, PostgreSQL, SQLite, and MariaDB/MySQL (via Drizzle ORM).
You can define Content Collections in two ways: in code or via the GUI-based collection builder. Full TypeScript support and a rich widget library make it straightforward to build custom data structures.
All widget fields support localization, validation using Valibot, and access control.
System localization uses Inlang Paraglide JS, a lightweight, type-safe i18n library. English and German ship by default. Additional admin UI languages can be added in Setup (writes project.inlang/settings.json and runs machine translate) or by hand β see System Languages.
We use the latest tailwindcss v4, so the CMS can be quickly optimized to your personal needs.
Backend data is available via REST API or GraphQL Yoga for fast, flexible frontends.
| Feature | Status | Notes |
|---|---|---|
| Collection Builder | β | GUI and code-based definitions |
| Typed Widget System | β | Localization, validation, access control |
| Multi-language (Paraglide) | β | Compile-time i18n (type-safe) |
| REST API | β | CRUD and configuration endpoints |
| GraphQL API (Yoga) | β | GraphQL API; Yoga upgrade path tracked on roadmap |
| Database agnostic | β | MongoDB, PostgreSQL, SQLite, MariaDB/MySQL (Drizzle) |
| List / count product layer | β | findPage (hasMore/keyset), count modes, L1 count cache (all engines) |
| Database Resilience | β | Retries, self-healing reconnection, diagnostics |
| Email Templating | β | Svelte Email + SMTP |
| Roles & Permissions | β | Database-backed RBAC |
| Persistent DoS Protection | β | Hardware-aware rate limiting; state across restarts |
Get up and running fast:
- Clone and install
git clone https://github.com/SveltyCMS/SveltyCMS.git
cd SveltyCMS
bun install # or npm install --legacy-peer-deps / pnpm install- Start dev server (guided installer auto-launches)
bun run dev # or npm run dev / pnpm run dev- Open the app
- SvelyCMS: http://localhost:5173/
- GraphQL: http://localhost:5173/api/graphql
Prefer a full walkthrough? See: ./docs/getting-started.mdx
- CLI installer auto-launches for smooth first-run setup
- Typed widgets and schema-driven collection builder
- Fast feedback loop with hot reloads and strong typing
To clone our repository you need to be able to use Git.
git clone https://github.com/SveltyCMS/SveltyCMS.git
cd SveltyCMSTip
Dual-Runtime Flexibility:
- Node.js (>=24): Recommended for maximum sustained production throughput (1.8Γ to 2.4Γ higher RPS on full-stack workloads via V8 TurboFan optimization).
- Bun (>=1.3 / 1.4): Recommended for blazing-fast developer tooling, instant package installation (
bun install), test execution (bun test), and optional edge / serverless builds via nativeBun.serve.
Install LATEST STABLE Node.js (>=24) or Bun to get started. Then choose your preferred package manager:
bun
# Install bun if you haven't already
curl -fsSL https://bun.sh/install | bash
# Install all dependencies
bun install
# Development (guided setup launches automatically on first run)
bun run dev
# Production Build (Node.js runtime β highest sustained throughput)
bun run build:node
node build/index.js
# Production Build (Native Bun.serve β sub-10ms startup)
bun run build:bun
bun build/index.jsbun install fails with ParserError or corrupted packages (upstream Windows Bun issue), use npm install --legacy-peer-deps instead. bun run dev and other commands work normally after install.
npm
# Install all dependencies (use --legacy-peer-deps for SvelteKit 3 RC peer resolution)
npm install --legacy-peer-deps
# Development (CLI installer launches automatically if needed)
npm run dev
# Build for production
npm run build
# Preview production build
npm run previewpnpm
# Install pnpm if you haven't already
npm install -g pnpm
# Install all dependencies
pnpm install
# Development (CLI installer launches automatically if needed)
pnpm run dev
# Build for production
pnpm run build
# Preview production build
pnpm run previewWhen starting the dev server without configuration, the guided installer launches automatically:
- Smart detection via
vite.config.ts - Database configuration: MongoDB, PostgreSQL, SQLite, or MariaDB/MySQL
- Admin account setup, secrets/keys generation
- Optional SMTP and Google OAuth configuration
Start with:
bun run dev # or npm run dev / pnpm run devWe use the unified Vite+ (VoidZero) toolchain and support dual-target execution for both Node.js (>=24) and Bun (>=1.3):
- Development:
bun run dev(ornpm run dev/pnpm run devonlocalhost:5173) - Production Build:
bun run build(ornpm run build) - Production Server (Node.js):
npm run start:nodeornode index.cjs(standard production server powered by Node 24 V8 engine) - Production Server (Bun):
bun run start:bunorbun index.bun.ts(native high-throughputBun.serveruntime) - Preview:
bun run preview(runs onlocalhost:4173) - Linting:
bun run check(oxfmt + oxlint β project-wide checks in <50ms)
| Task / Lifecycle | Recommended Runtime | Why |
|---|---|---|
| Development & Tooling | Bun | 3β4Γ faster cold starts, instant package management, lightning-fast bun test and oxlint. |
| Production Server (Node.js) | Node.js 24 | Maximum V8 JSON parsing/serialization performance on high-volume JSON API workloads. |
| Production Server (Bun Native) | Bun 1.3+ | Native Bun.serve event loop, zero-copy socket I/O, and native bun:sqlite performance. |
See our package.json for all available commands.
SveltyCMS implements A++ enterprise-grade security with 4-layer defense-in-depth architecture.
Multi-Layer Protection:
- AI Bot Defense Shield β Proactive detection blocks 28 AI crawler patterns (GPTBot, Claude, Perplexity) and reconnaissance tools (Nmap, SQLMap, Burp Suite). A 45-route honeypot grid with progressive tarpit delays and response poisoning wastes attacker resources.
- 4-Layer Defense-in-Depth β Middleware β Dispatcher β Handler β Page Action; every layer re-validates permissions independently with fail-closed defaults.
- Enterprise SSO β Native SAML 2.0 and SCIM 2.0 support for automated user provisioning (Okta, Azure AD).
- Zero-Bias Cryptography β CSPRNG token generation with rejection sampling, Argon2id password hashing (64MB memory-hard), AES-256-GCM encryption, SHA-256 crypto-chained audit logs.
- Cross-Origin Isolation β COOP, COEP, and CORP headers on all API responses prevent Spectre/Meltdown side-channel attacks.
- Multi-Tenancy β Native
tenantIdisolation at the database adapter level with TBAC role scoping. - Granular RBAC β Role-based and field-level access control; OAuth HMAC state integrity; timing-safe cryptographic comparisons;
__Host-cookie prefix enforcement (RFC 6265bis).
You can log in with email/password, Google OAuth, or GitHub OAuth. Role- and field-based access control lets you define precisely who can view, edit, or delete content.
π Full Security Documentation
SveltyCMS features a native Svelte 5 component library (42+ primitives) built on Tailwind 4 CSS variables with zero third-party UI dependencies.
- Swappable Admin Themes β Centralized
app.cssusing Tailwind 4@themeblocks. Replace the default color palette to give your CMS a corporate brand identity β from startup purple to enterprise blue in minutes. - Dark Mode β Native support via
mediaandclassselectors. - Accessibility-First β All components verified for WCAG 2.2 AA compliance in the Kitchen Sink validation lab.
- Zero Runtime Overhead β Components use Svelte 5 Runes (
$state,$props) with Svelteuse:actionpatterns instead of heavy state machines.
π UI Style Guide
|
We use Paraglide JS with the inlang ecosystem for type-safe system translations. English and German ship compiled. Add a language
bun translate # machine-fill src/messages/{locale}.json
bun run paraglide # compile catalogsCommunity review: Fink (or a PR on |
SveltyCMS is designed with inclusivity at its core, strictly following WCAG 2.2 AA and ATAG 2.0 standards, and proactively moving towards WCAG 3.0 (Functional Performance).
- Screen Reader Ready: Semantic HTML landmarks, ARIA live regions for status updates, and descriptive labels.
- Keyboard Navigation: Full support for keyboard-only users, including complex widgets like tree views and drag-and-drop interfaces.
- Cognitive Accessibility: Clear input validation, consistent navigation, and focus management.
- For Developers: We provide a comprehensive Accessibility Guide to help you maintain these standards in your custom widgets.
Great Experience to designing user-friendly and intuitive interfaces for managing content. Full Typescript support to display all available widgets, options to create fully custom data structures.
Build and send emails using Svelty Email and TypeScript.
π¦ Optimized Bundle Size SveltyCMS is built with modern optimization techniques resulting in a compact bundle compared to traditional CMS platforms:
| CMS Platform | Total Asset Size | Bundle Size (Brotli) | Technology Stack |
|---|---|---|---|
| SveltyCMS | 3.01 MB | 842 KB β‘ | Svelte 5 + Vite+ |
| WordPress Admin | ~12.5 MB | ~950 KB | jQuery + PHP |
| Drupal Admin | ~15.0 MB | ~1.2 MB | jQuery + Drupal |
| Payload CMS | ~8.5 MB | ~1.1 MB | React + Next.js |
| Directus | ~6.5 MB | ~1.0 MB | Vue.js |
Note
Secure-by-Design Architecture: The 842 KB figure represents the total Brotli-compressed assets for the standard admin dashboard. By leveraging Svelte 5's zero-runtime reactivity and the Vite+ tree-shaking compiler, we achieve a highly optimized delivery where the client only receives exactly what it needs to render.
Self-measured suites under tests/benchmarks/ with per-DB MDX reports. Not a global βfastest CMSβ ranking β numbers depend on hardware, DB, and whether you measure adapter vs full HTTP stack.
| Area | Notes |
|---|---|
| 4 database adapters | SQLite (embedded), PostgreSQL / MariaDB / MongoDB (Docker local) |
| Optional Redis L2 | Cache variants in the matrix runner |
| List / count product layer | findPage vs legacy list+count; count estimate vs exact; L1 count cache hits (~0.024 ms for count only, not full list bodies) |
| Reports | docs/project/benchmarks/benchmark_<db>.mdx |
| Layer | Typical self-measured class |
|---|---|
| SQLite adapter FIND ONE | ~0.05β0.08 ms |
| Networked adapter FIND/INSERT (local Docker) | ~0.5β2+ ms (RTT-bound) |
findPage vs dual findMany+count |
~1.6β5.7Γ on that path (2026-08-04 matrix) |
| L1 count cache hit | ~0.024β0.029 ms (all four engines) |
Methodology and EU-safe competitive framing: benchmarks Β· performance architecture Β· achievements log.
# Console only (safe for normal dev)
bun test tests/benchmarks/database-performance.test.ts
# Record to report
BENCHMARK_RECORD=1 bun test tests/benchmarks/database-performance.test.ts
# Full matrix (long)
bun run scripts/benchmark-matrix/index.ts --sql- π Documentation β Guides, API reference, and architecture
- π― Getting Started β Quick start guide
- πΊοΈ Roadmap 2026 β In-progress vs planned work
- π§ͺ Test status β What to run; CI is source of truth for pass/fail
- π Security β Architecture (self-assessment, not a third-party audit)
- π Upgrading SveltyCMS β Safe update guide
- ποΈ Architecture: Database Resilience β ./docs/architecture/database-resilience.mdx
- π€ Contributing Guide β How to contribute
REST (fetch 5 posts):
curl -H "Authorization: Bearer <token>" \
"http://localhost:5173/api/collections/posts?limit=5"GraphQL (posts with author):
query {
posts(limit: 5) {
id
title
slug
author {
name
}
}
}SveltyCMS is licensed under the Business Source License 1.1 (BSL 1.1) β Fair Source software that balances openness with sustainability.
- β Free for individuals & small businesses β Use, modify, and deploy in production if your organization's total finances are under $1,000,000 USD
- πΌ Paid license for larger organizations β Commercial license required if total finances exceed $1M USD
- π Future open source β Automatically converts to MIT License on the "Change Date" specified in the license file
- π€ Open collaboration β Source code is publicly available; contributions welcome
If your organization's Total Finances (revenue, funding, assets) exceed $1,000,000 USD, you must purchase a commercial license to use SveltyCMS in production.
π§ Email: info@sveltycms.com
For more details, see the full LICENSE file.
Contact us if you're struggling with installation or other issues:
- π¬ GitHub Discussions
- π¬ Discord Server
- π§ Report Issues
- π Documentation
- π§ Email: support@sveltycms.com
For detailed information on our Git workflow, branching strategy, and commit conventions, see our Git Workflow & Automated Releases guide.
SveltyCMS uses tag-driven releases β the maintainer controls the version number.
next: feat: add media gallery ββ
fix: toolbar spacing ββ accumulate over days/weeks
feat: image derivatives ββ
β
merge next β main (when stable)
git tag v0.0.7
git push --tags
β
βΌ
Tag push triggers auto-release:
ββ npm publish β npmjs.com
ββ GitHub Release with auto-generated notes
ββ package.json version set from tag
nextbranch: Active development β all features and fixes land here. No releases.mainbranch: Production β merged fromnextwhen stable. Releases triggered by pushing a version tag.- Version source: Git tags are the source of truth β NOT
package.json.
Every commit must follow Conventional Commits:
feat:β new featurefix:β bug fixperf:β performance improvementdocs:,chore:,refactor:,test:,ci:,security:β maintenance
Commit prefixes inform the auto-generated release notes but do not drive version bumps β the maintainer chooses the version.
Before submitting Pull Requests, ensure your changes pass all checks by running:
bun run lint && bun run check && bun run test:unitThis runs the linter (oxlint), type checker (svelte-check), and the full unit test suite (vitest) exactly as the CI pipeline does.
Thank you for helping us maintain a consistent and predictable release process!
We welcome all kinds of contributions! Please see our CONTRIBUTING.md for details on how to get started.
If you find our project useful and would like to support its development, you can become a sponsor! Your sponsorship will help us cover the costs of maintaining the project and allow us to dedicate more time to its development.
There are several ways you can sponsor us:
Thank you for your support! π
To all our contributors β without you, SveltyCMS would never have been possible.
If you like what we're doing, give us a star and share our SveltyCMS project with others!



