Appsmith

appsmith.comcontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

A builder for internal tools: drag widgets onto a canvas, bind them to queries against your databases and APIs, and share the result with colleagues.

Promptfree, for everyone, and the only version there is
Build me the internal tool I actually need instead of a hosted Appsmith: a few screens over my own database, with the permissions and the audit log a builder charges for.

Read this first: the product you are replacing is open source, and self-hosting it is a real answer. What the paid tier sells is single sign-on, granular permissions and audit logs. If you need a general canvas that colleagues drag widgets onto, self-host. If you need four screens over your own data, build them — a builder is a very expensive way to render a table.

STACK
- Node 20+ with Fastify, server-rendered HTML with a little vanilla JS
- Your existing database through its own driver, plus SQLite for this tool's own state
- No client-side framework
- Caddy in front

THE DATA MODEL, MEANING THIS TOOL'S OWN
- users: id, email, name, is_active, created_at, last_seen_at
- roles: id, name, description
- permissions: id, role_id, resource, action, scope_json — resource is a screen or a query, action is read, write or run
- sessions: id, user_id, token_hash, ip_hash, user_agent_bucket, created_at, expires_at, revoked_at
- audit_log: id, actor_id, action, resource, target_id, before_json, after_json, ip_hash, at — append-only, enforced by a trigger
- queries: id, name, sql, params_json, is_mutation, requires_role, description — every query named, versioned and reviewed, never assembled from user input
- exports: id, actor_id, query_id, row_count, at — an internal tool is how data walks out of a company; every export is a row

AUTHENTICATION
- Single sign-on through OIDC against whatever identity provider is in use, which is the only sane answer for staff accounts
- A local fallback with magic links for the case where there is no provider
- Sessions with a short life and a refresh, revocable centrally, and a list of a user's sessions they can end
- No shared logins, ever, because an audit log with a shared account in it answers nothing

PERMISSIONS
- Role-based, checked on the server for every screen and every query, never in the browser
- Row-level scope where it matters: a support agent sees the customers in their region, expressed as a scope predicate joined into the query
- The default is deny. A new screen is invisible until a role is granted it
- A page that shows exactly what each role can do, generated from the permissions table rather than written by hand and left stale

THE SCREENS
- A list screen: filters, sorting, pagination, and a column set defined in code
- A detail screen: fields, related records, and the actions allowed on this record
- An action is a named mutation with its own permission, its own confirmation, and its own audit entry. Never a free-form SQL box in production — that is the thing internal tools are breached through
- Bulk actions with an explicit count in the confirmation: 'this will refund 214 orders'
- Every destructive action is reversible or requires typing something to confirm

QUERIES
- SQL written in files, parameterised, reviewed like any other code
- Read queries run against a replica or a read-only connection where one exists
- A statement timeout on everything and a row limit on every list, because one unbounded query on a big table takes the database down and the internal tool takes the company with it
- Slow queries logged with their parameters redacted

THE AUDIT LOG, WHICH IS WHAT IS BEING BOUGHT
- Every read of sensitive data, every mutation, every export, every permission change
- Before and after values for mutations, with sensitive fields hashed rather than stored
- Searchable by actor, by target, by time
- Nothing in it is ever updated or deleted; retention is long and stated

THE INTERFACE
- Dense and plain: tables that align, a header with who you are and what you can do, keyboard navigation for the list screens
- Fast on a laptop over a poor connection — no bundle, no spinner
- Dark and light

OPERATIONS
- .env: DATABASE_PATH, TARGET_DATABASE_URL, BASE_URL, OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, SESSION_SECRET, HASH_SALT
- Migrations on boot, each once
- The tool reachable only behind whatever the company already uses — a VPN, an identity-aware proxy — with public exposure a deliberate decision
- Nightly backup of this tool's database, restore script
- Health endpoint

WHAT MATTERS MOST
Permissions and the audit log. Build deny-by-default, the server-side check on every query, and the append-only log before a single screen looks good. An internal tool is a permanent standing route into the company's data, and the difference between one that is safe and one that is not is entirely in those two things.

Give me the repository, migrations, .env.example, three example screens over a seed schema, and a README with deploy steps behind Caddy and the network placement spelled out.

What you lose

  • Connectors for dozens of databases and APIs, each with its own authentication, already written and maintained
  • Audit logs, single sign-on and granular permissions, which is what the paid tier is actually for
  • A canvas a colleague can rearrange without opening an editor

If you would rather not build

  • Retool, if you would rather buy the polished version

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$15/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Appsmith

$0

The product itself, self-hostable with Docker.

appsmithorg/appsmithfree · open source

Budibase

$0

Self-hosted internal apps with a built-in database or external connections.

Budibase/budibasefree · open source

Why this verdict

our own opinion · changed only by a person

73/100

Verdict yes at 73. Two or three internal tools are quicker to write than to configure; past that, self-host the real thing.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 1/day
views0130 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Appsmith

answered from the record above

Is Appsmith free?

No — the plan we track is $15 a month. Business at around $15 per user per month billed monthly on the cloud; the community edition is free to self-host.

Can you replace Appsmith by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 73 out of 100, build time one session. Read what you lose before you decide.

How much does Appsmith cost?

$15 a month on Business — $180 a year. Recorded 9 Aug 2026.

What do you lose by replacing Appsmith?

Connectors for dozens of databases and APIs, each with its own authentication, already written and maintained; Audit logs, single sign-on and granular permissions, which is what the paid tier is actually for; A canvas a colleague can rearrange without opening an editor. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Appsmith?

Yes: Appsmith, Budibase. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 16 in No-code apps & databases

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc