BookStack vs Fossil
A source-aware comparison of pricing, documented capabilities and workflow fit.
Short answer
- Price: both start at Free.
- How to start: both are free.
- Where they differ: only BookStack has public api and sso (saml); both offer open source / self-hostable.
These lines are generated from the pricing we track, not from a paid placement. How we score tools.
What BookStack is
BookStack is an MIT-licensed, self-hosted documentation application built around shelves, books, optional chapters and pages. It provides role and content-level permissions, multiple enterprise authentication options and a permission-aware REST API, but the operator remains responsible for the PHP and database stack, upgrades, filesystem permissions, security configuration and complete database-plus-file backups.
What Fossil is
Fossil is BSD-licensed distributed source-control software that packages repository history, wiki, tickets, forum, documentation and a web interface in one executable and repository file. It can work locally and synchronize with another Fossil repository, but teams self-hosting it must operate the server, TLS or proxy layer, access policy, repository files and backups.
Side by side
| BookStack | Fossil | |
|---|---|---|
| Category | Developer Tools | Developer Tools |
| How to start | Freeverified | Freeverified |
| Public API | Yes | No |
| Mobile app | No | No |
| Open source / self-hostable | Yes | Yes |
| SSO (SAML) | Yes | No |
| Visit | BookStack ↗ | Fossil ↗ |
What BookStack is built to do
- Book hierarchy
- Organizes page content within optional chapters, books and reusable bookshelves.
- Roles and permissions
- Combines system roles with content-level overrides and inherited controls.
- Federated authentication
- Documents OIDC, SAML 2.0 and LDAP configuration for self-hosted instances.
- REST API
- Provides token-authenticated JSON endpoints governed by the API user's permissions.
What Fossil is built to do
- Distributed version control
- Clones, commits and synchronizes repository history between Fossil instances.
- Built-in web UI
- Shows timelines, diffs, files, tickets, wiki, forum and historical downloads.
- Project knowledge
- Stores wiki, embedded documentation and ticket history with repository data.
- Self-hosted server
- Serves one or multiple repositories directly or through supported CGI setups.
Choose BookStack if
- Internal handbooks, runbooks and technical knowledge bases with a clear hierarchy
- Organizations needing self-hosting, role controls and supported identity integrations
- Teams that can automate upgrades, database and file backups, and restore drills
Skip BookStack if
- You need a vendor-operated SaaS with no infrastructure responsibility
- Your information model cannot fit shelves, books, chapters and pages
- You cannot preserve the database, uploads, configuration and original APP_KEY together
Choose Fossil if
- Projects that want source history, tickets, wiki and forum replicated together
- Teams comfortable administering a compact Fossil server and repository backups
- Workflows whose contributors and automation explicitly support Fossil
Skip Fossil if
- Required CI, IDE or deployment systems only accept Git repositories
- The organization needs a managed SaaS identity, compliance and support package
- Its review and issue process cannot fit or integrate with Fossil's built-in model
Evidence and freshness
Where a claim on this page comes from a vendor page, it is linked here.
BookStack
Official sources reviewed · reviewed 2026-08-24
Fossil
Official sources reviewed · reviewed 2026-08-24
BookStack: pros & cons
- Predictable structure: Shelves, books, chapters and pages give teams a constrained documentation hierarchy.
- Granular access: Roles can be combined and overridden at shelf, book, chapter or page level.
- Authentication choices: Official administration docs cover OpenID Connect, SAML 2.0 and LDAP.
- Automation surface: The REST API covers content and administrative resources while enforcing the API user's roles and permissions.
- Self-hosting burden: PHP, MySQL or MariaDB, web-server configuration, updates and monitoring are operator responsibilities.
- Manual recovery design: There is no built-in full backup and restore; both database records and instance files must be protected.
- Key dependency: Restores need the original APP_KEY for encrypted features such as multi-factor credentials.
- Hierarchy trade-off: The book metaphor is approachable but may constrain teams needing free-form graphs or complex publishing workflows.
Fossil: pros & cons
- Integrated project data: Version history, wiki, tickets, forum and documentation travel with a cloned repository.
- Single executable: Core project functions and the web interface are delivered through one Fossil program.
- Offline workflow: Local repositories can record code and project-content changes before later synchronization.
- Serving options: A repository can be served directly or through supported CGI and web-server arrangements.
- Self-hosting responsibility: Public service requires server configuration, TLS, permissions, updates, monitoring and backups.
- Fossil-specific ecosystem: Contributors and integrations must support Fossil rather than assume Git-compatible workflows.
- Single-file care: Repository content is convenient to copy, but file permissions, integrity checks and tested recovery remain operational duties.
- Built-in workflow fit: Teams needing a different review, issue or identity model must validate integrations or adapt their process.
Our verdict on BookStack
Choose BookStack when its constrained hierarchy matches the knowledge model and self-hosting is deliberate; validate identity mapping, permission inheritance, upgrades and a full database-plus-files restore before broad adoption.
Our verdict on Fossil
Choose Fossil when its integrated repository and project tools reduce more complexity than its smaller ecosystem adds; test the contributor toolchain and recovery process before adoption.