BookStack vs Netlify CMS
A source-aware comparison of pricing, documented capabilities and workflow fit.
Short answer
- Price: both start at Free.
- How to start: both are free.
- Where they differ: only BookStack has sso (saml); both offer public api and open source / self-hostable.
These lines are generated from the pricing we track, not from a paid placement. How we score tools.
What BookStack is
BookStack is an MIT-licensed, self-hosted documentation application built around shelves, books, optional chapters and pages. It provides role and content-level permissions, multiple enterprise authentication options and a permission-aware REST API, but the operator remains responsible for the PHP and database stack, upgrades, filesystem permissions, security configuration and complete database-plus-file backups.
What Netlify CMS is
Netlify CMS was renamed Decap CMS in February 2023. The maintained project is an MIT-licensed React single-page application placed in a site's admin path; it presents an editing UI over content stored in Git and communicates with supported Git hosts through their APIs. Authentication, repository permissions, content schema, media handling, previews and build/deploy behavior still have to be configured and secured as one delivery chain.
Side by side
| BookStack | Netlify CMS | |
|---|---|---|
| Category | Developer Tools | Developer Tools |
| How to start | Freeverified | Freeverified |
| Public API | Yes | Yes |
| Mobile app | No | No |
| Open source / self-hostable | Yes | Yes |
| SSO (SAML) | Yes | No |
| Visit | BookStack ↗ | Netlify CMS ↗ |
What BookStack is built to do
- Book hierarchy
- Organizes page content within optional chapters, books and reusable bookshelves.
- Roles and permissions
- Combines system roles with content-level overrides and inherited controls.
- Federated authentication
- Documents OIDC, SAML 2.0 and LDAP configuration for self-hosted instances.
- REST API
- Provides token-authenticated JSON endpoints governed by the API user's permissions.
What Netlify CMS is built to do
- Git-backed editor
- Reads and writes configured content files through a supported repository backend.
- Content collections
- Defines file or folder content models and editor fields in YAML configuration.
- Editorial workflow
- Represents drafts and approvals using branches plus pull or merge requests.
- Custom UI extensions
- Supports custom previews, widgets and editor plugins for project-specific authoring.
Choose BookStack if
- Internal handbooks, runbooks and technical knowledge bases with a clear hierarchy
- Organizations needing self-hosting, role controls and supported identity integrations
- Teams that can automate upgrades, database and file backups, and restore drills
Skip BookStack if
- You need a vendor-operated SaaS with no infrastructure responsibility
- Your information model cannot fit shelves, books, chapters and pages
- You cannot preserve the database, uploads, configuration and original APP_KEY together
Choose Netlify CMS if
- Markdown or structured-file sites already built and deployed from Git
- Small editorial teams whose review process maps cleanly to branches and pull requests
- Projects able to operate OAuth or Git Gateway and protect repository permissions
Skip Netlify CMS if
- You need a database-first CMS or complex relational content operations
- Editors must be independent of Git-host and build-pipeline availability
- You cannot securely operate the selected authentication and repository-access path
Evidence and freshness
Where a claim on this page comes from a vendor page, it is linked here.
BookStack
Official sources reviewed · reviewed 2026-08-24
Netlify CMS
Official sources reviewed · reviewed 2026-08-24
BookStack: pros & cons
- Predictable structure: Shelves, books, chapters and pages give teams a constrained documentation hierarchy.
- Granular access: Roles can be combined and overridden at shelf, book, chapter or page level.
- Authentication choices: Official administration docs cover OpenID Connect, SAML 2.0 and LDAP.
- Automation surface: The REST API covers content and administrative resources while enforcing the API user's roles and permissions.
- Self-hosting burden: PHP, MySQL or MariaDB, web-server configuration, updates and monitoring are operator responsibilities.
- Manual recovery design: There is no built-in full backup and restore; both database records and instance files must be protected.
- Key dependency: Restores need the original APP_KEY for encrypted features such as multi-factor credentials.
- Hierarchy trade-off: The book metaphor is approachable but may constrain teams needing free-form graphs or complex publishing workflows.
Netlify CMS: pros & cons
- Git-native content: Editorial changes are stored alongside site content with repository history and review options.
- Static-generator flexibility: The project is designed to work across static-site generators rather than require Netlify hosting.
- Editorial workflow: Drafts can map to branches and pull or merge requests before publication.
- Extensible editor: Teams can define collections and fields and add custom previews, widgets and editor plugins.
- Renamed product: Current documentation, packages and support use Decap CMS, so the Netlify CMS name is legacy.
- Authentication setup: Direct Git backends can require an OAuth proxy, while Git Gateway introduces an additional identity and gateway dependency.
- Repository coupling: Content editing depends on Git-host APIs, permissions, branches and rate or service availability.
- No full delivery platform: Site builds, hosting, backups, asset strategy and deployment controls come from separate services and configuration.
Our verdict on BookStack
Choose BookStack when its constrained hierarchy matches the knowledge model and self-hosting is deliberate; validate identity mapping, permission inheritance, upgrades and a full database-plus-files restore before broad adoption.
Our verdict on Netlify CMS
Evaluate this product under its current Decap CMS identity. Choose it when Git-backed content is intentional, then test authentication, least-privilege repository access, editorial branches, media, previews and deployment failure recovery end to end.