Roadmap · live from the CMS
What we're building, in the open.
Three things in progress at any time. Everything below them is sorted by what we'd pick up next. No dates, because dates on a roadmap are fiction.
- latest · 8 Oct
- 0.5.4
- shipped
- 38
- planned
- 14
Now
in progress- Area: api
Polymorphic content types
A content type can extend a parent: Products holds the shared fields, Digital and Physical add their own. List, filter and link across all of them.
Next
two, in order
- Area: admin
Document or form: an editor per content type
The document editor suits articles and pages. A product, a level, a config record or a redirect rule wants a form: every field inline, top to bottom. Each type gets the editor that fits, chosen automatically and overridable.
- Area: api
Environments and promotion
Write on dev, get it approved, promote to staging, then to production: content and schema move together as one change set, through whatever stages a team defines.
Later
when the above is done
- Area: sites
Forms
Define a form in the admin, collect submissions per site, notify by email or webhook.
- Area: api
Search
A full-text index over published content, per site and locale, on the delivery API.
- Area: admin
Admin SSO and SCIM
SAML and OIDC sign-in for teams.
- Area: ecosystem
Extension registry
Browse and install extensions from the admin.
- Area: commerce
Headless e-commerce
Catalogue as content, carts and orders as system tables, Stripe first, a storefront starter.
- Area: api
Field-changed events
An event when a published entry's field changes, with the old and new value, so the admin can offer a follow-up: add a redirect when a slug moves, notify a team, kick off a job.
- Area: api
Schema lenses
Old API clients keep working after a model changes. A client says which schema version it was built against and gets today's content in that shape.
- Area: api
Rules across fields
A content type can carry rules that involve more than one field: an end date after the start date, a price required once a product is for sale. The server checks them on every save and the form shows them before you save.
- Area: admin
Unused files in the media library
A filter that lists files no entry uses any more, and a bulk delete for them, with a person confirming as always.
- Area: admin
Linked from, on every entry
Every entry shows which entries link to it: this author appears on 14 posts and the homepage.
- Area: api
Typed fields from JSON
Start a field as JSON while its shape is still settling, then convert it to typed fields once you know what it holds: the same move as adding types to JavaScript.
Shipped
9 releases in 6 days. Pick one.
- Area: admin
Code field
Each field has a language the API reports (OpenAPI, GraphQL, generated types). JSON fields can require valid JSON.
- Area: api
Drafts mode for development servers
SHAPIO_DRAFTS=true in the starters reads drafts with a development token and marks every page with a Drafts badge.
- Area: api
Next.js: cached reads, revalidated on publish
The client tags every read; the starter calls revalidateTag for exactly the entries and models in each publish.
- Area: api
Next.js in-process delivery
About 2 ms saved per request against reading over HTTP; ahead of Payload's local API on throughput for two of three measured requests.
- Area: admin
Safer permissions
Hardening for mixed-version deployments.
- Area: admin
Fields anywhere in the document
Edits the model's display settings, so it pulls and applies like any other.
- Area: admin
A clearer entry editor
Shipped in 0.4.1.
- Area: api
Faster filtered reads
Ahead of Strapi on every measured request and ahead of Payload on throughput.
- Area: api
GraphQL playground in the Develop menu
The API explorer shows any REST request as the same GraphQL query, ready to copy or open in the playground, and the docs panel describes every field with its help text.
- Area: admin
SEO fields with site defaults
Each site sets a title template, a default description and a default image, and delivery can return the SEO fields with those defaults filled in.
- Area: sites
SEO tags in the starters
The Astro, Next.js and SvelteKit starters render titles, descriptions, social cards, robots tags and canonical URLs from the SEO fields.
- Area: admin
Six admin looks
Forest and Butter are new, and themes added by extensions are listed beside them.
- Area: api
Lighter, faster delivery
A page of 20 articles with an author drops from 78 KB to 52 KB. Sites made from an earlier starter add one option to keep receiving HTML.
- Area: admin
Named admin themes
Shapio, Classic, Murdered out and Snowed are built in, and each is checked for WCAG 2.1 AA contrast.
- Area: ecosystem
Themes from extensions
Shapio checks them at startup and warns when a theme's contrast falls below AA.
- Area: admin
A new brand
The logo becomes an acid-yellow tile with a plum S, in every theme, the favicon and the home-screen icon.
- Area: api
Steady under heavy load
Delivery reads under heavy load no longer stall the server, and a request that cannot get a database connection fails fast with a clear error.
- Area: sites
Content types per site, shared types
Two sites can each have a post with different fields, and a site never sees another site's types in its admin, APIs or schema files.
- Area: api
A GraphQL schema per site
The GraphQL endpoint answers with the requesting site's schema: its own content types plus the shared ones.
- Area: sites
Schema files per site
Pull, diff and apply schema files one site at a time; one folder can hold several sites without them touching each other.
- Area: admin
Choose where a type lives
Creating a content type asks whether it belongs to this site or to all sites, and shared types are marked in the sidebar.
- Area: ecosystem
Site-aware importers, agents and starters
The WordPress and Strapi importers, the MCP server and the starters create content types for one site or share them, as you choose.
- Area: sites
Many sites on one instance
One Shapio runs many sites, with shared admin users and roles and separate content, media, tokens, webhooks and deployments for each.
- Area: api
MySQL and SQLite
SQLite runs on Node's built-in driver for single-process installs; MySQL supports several instances on one database, like PostgreSQL.
- Area: ecosystem
An MCP server for agents
Shipping a change set stays with people unless you switch it on explicitly.
- Area: sites
Astro, Next.js and SvelteKit starters
The Next.js starter refreshes only the pages that changed when content is published.
- Area: admin
Visual editing
An entry opens beside a live preview of the site; clicking a field on the page jumps to it, and saving re-renders the page.
- Area: admin
Assist, with your own model
Off by default, nothing leaves your server while it is off, and an assist only proposes or writes drafts: it never publishes.
- Area: ecosystem
Vercel and Netlify deployments
Publishing can start builds on Vercel and Netlify, next to Cloudflare Pages, with the real build status shown in the admin.
- Area: ecosystem
Import from WordPress or Strapi
Plan content types from an export, apply them, then import media and entries into change sets for review.
- Area: admin
Live content modelling
Each change is validated, backfilled and switched on in one step, across 21 field types with interchangeable editors.
- Area: api
Schema as code
Pull the schema to JSON files, review the diff and apply it to a running instance; an apply refuses when the target moved since your pull.
- Area: admin
Change sets and snapshots
Every snapshot records why, who and the schema version, and restoring one opens a change set you can review.
- Area: admin
Documents, revisions and locales
Media goes to local or S3-compatible storage, with private files behind signed links and WebP variants.
- Area: api
REST and GraphQL delivery
Filters, sorting, populate, locales and pinned snapshots on REST and GraphQL, with OpenAPI and TypeScript types generated from the live schema.
- Area: admin
Roles, accounts and an audit log
Custom admin roles with field-level permissions, API tokens, end-user accounts with email, Google and GitHub sign-in, and an audit log.
- Area: ecosystem
Extensions and custom editors
Lifecycle hooks, custom routes, jobs and custom React field editors that load at runtime, with no rebuild of the admin.
- Area: ecosystem
Install with npm or Docker
Run Shapio as an npm package or a Docker image, with HTTPS from your own certificates and no hosted account.