JustFlows

Everything you need to build

A complete website and content platform — visual for authors, flexible for developers, and ready to run on your own infrastructure.

Content management

Create structured content without giving up visual control. Pages, posts, and custom content types share one publishing workflow and one flexible block document.

  • Visual builder for pages, posts, and other content types
  • Reusable blocks, responsive grids, patterns, and undo/redo
  • Multilingual routes, a visual menu designer with mega menus, Post List, Link List, and WordPress import
  • Configurable permalink structures with automatic 301s, plus a redirect manager with 404 reports
  • Public threaded comments with moderation, notifications, and CAPTCHA
  • Working revisions on every type — draft, compare, and restore the last five
  • Recoverable Trash for content, media, comments, and menus
Explore documentation

Built-in SEO

Ship technically sound pages without assembling an SEO plugin stack. Core produces the essential metadata and discovery files for every public site.

  • Titles, descriptions, canonical URLs, and social sharing cards
  • Safe JSON-LD structured data on published content
  • Automatic sitemap.xml and configurable robots.txt
Explore documentation

Full-site visual design

Design the whole public site from the admin. Start with a theme, then make its structure and visual system your own without maintaining a fork.

  • Build the home page, blog index, header library, and shared footer
  • Light and dark color palettes with an automatic device mode
  • Design tokens for typography, spacing, width, corners, and shadows
  • Per-block color, opacity, and theme-variable controls — no CSS
  • Themes ship their own Customizer controls and default site chrome
  • WordPress-style template hierarchy with a visual editor for every slot
  • Install community themes from the Marketplace
Explore documentation

Auth, roles, and security

Give every person the access they need, from public registration to full administration — with a second factor, session rotation, and a reconstructable audit trail.

  • TOTP two-factor authentication with encrypted recovery codes
  • Password change and reset that revoke every existing session
  • Administrative audit log, signed sessions, CSRF, and rate-limited login
  • Site-local custom roles, per-user capability grants and denies, and content, locale, and ownership scopes
  • Device-session list with per-session revoke, plus self-service password reset by email
Explore documentation

Media library

Keep files organized in one library and reuse them throughout the site. MIME verification, upload limits, library quotas, and safe local delivery are built into the live admin path.

  • Verified image, document, video, and audio uploads with configurable limits
  • Media picker inside Image and other URL-aware blocks
  • Site icon from Settings, plus Gallery layouts: Grid, Masonry, Carousel, Slideshow, and List
Explore documentation

Developer API

Use Justflows as a complete website or as the content backend for any frontend. The public contract is discoverable, documented, and friendly to typed clients.

  • Public REST endpoints for content, types, media, and menus
  • OpenAPI document for client generation and API exploration
  • Locale-aware published content for headless applications
  • Outgoing signed webhooks for content, media, user, and system events
Explore documentation

Extensible core

Extend the platform at stable boundaries instead of patching core. Plugins can add behavior and editor experiences while lifecycle and permissions remain explicit.

  • Typed actions, gates, filters, jobs, blocks, and admin extensions
  • Install, activate, deactivate, and remove plugins at runtime
  • Plugin-owned admin apps in a sandboxed same-origin frame — Forms is now a fully standalone plugin
  • A content-hashed front-end asset bundle every active plugin folds into
  • Signed packages, declared permissions, and active-only execution
Explore documentation

Static and edge export

Publish your site in the admin, then write the whole thing out as a folder of files you can serve from object storage or a CDN — no Node origin required for the published pages.

  • Every published page, asset, locale variant, sitemap.xml, robots.txt, favicon, themed 404, and the built /theme.css
  • A manifest with per-file sha256 and Cache-Control advice, plus a _headers file for Cloudflare Pages and Netlify and ready-to-use .htaccess / nginx config
  • Optional auto-rebuild: an incremental re-export after publish, menu, theme, or settings changes
  • Forms, comments, analytics, and cookie consent keep working off-origin via CORS and a generic window.__JF_ORIGIN__ stamp
  • staticExport.routes, assets, formAction, completed, and deploy SDK hooks
Explore documentation

Operations and updates

Run the platform with the tools an operator expects: guided core updates, deep diagnostics, versioned system emails, and a recoverable delete for everything.

  • One-click core updates with checksum verification, plus an opt-in daily auto-update that never crosses a major version
  • Admin diagnostics: runtime, database, migration, cache, plugin and hook state, correlation IDs, and confirmed support bundles
  • Site-scoped Trash for content, media, comments, and menus — restore with revisions intact or purge on a schedule
  • Move the admin URL off /admin with a reachability check and automatic rollback
  • Versioned system emails with branding, typed variables, locale variants, and sanitized test sends
Explore documentation

Privacy and consent

Meet consent and data-subject obligations with first-party tools — no third-party scripts, no IP lookups, nothing to bolt on.

  • First-party Cookie Consent: categorised banner, preference center, and per-category script and embed gating
  • A site cookie registry every extension declares into, re-classifiable per cookie
  • Versioned consent records, exportable as CSV and erasable per record
  • Subject-access export and erasure APIs that anonymise rather than delete authored content
  • Administrative audit log with configurable retention
Explore documentation

AI-ready development

The repository explains itself to modern coding agents. Machine-readable guidance helps them find the right extension points and preserve the platform’s contracts.

  • Repository-native instructions and focused development skills
  • Architecture, security boundaries, and verification paths in context
  • Guided workflows for plugins, themes, APIs, and platform changes
Explore documentation