Cosmic is an AI-native headless CMS that pairs a simple, developer-friendly content API with one of the most complete agentic AI stacks in the category — hosted MCP server, four production agent types, and native text/image/video generation.
Contentful is the safer enterprise choice with SOC 2/ISO certifications, a large app marketplace, broad SDK coverage, and mature governance, while Cosmic counters with a far deeper native AI/agent stack, simpler configuration, and more transparent entry pricing. Teams choosing Cosmic trade enterprise trust artifacts and ecosystem breadth for AI-native velocity and lower complexity.
Full Comparison →Sanity leads on structured content depth (Portable Text AST, schema-as-code), real-time collaborative editing, and a much larger community, whereas Cosmic offers a flatter learning curve with no proprietary query language and a more complete out-of-the-box AI generation and agent suite. Sanity suits content-model-heavy products; Cosmic suits teams prioritizing AI automation and fast ramp.
Full Comparison →Storyblok's visual editor, marketer-friendly page composition, and stronger compliance posture make it the better fit for marketing-led teams, while Cosmic wins decisively on agentic AI, MCP tooling, and native media generation. Cosmic is the developer/AI-automation play; Storyblok is the editor-experience play.
Full Comparison →Strapi offers self-hosting, full source control, and a vastly larger open-source community — critical for data-sovereignty or customization-heavy needs — while Cosmic removes all infrastructure burden and ships native AI capabilities Strapi requires plugins and custom work to approximate. Choose Strapi for control and community; Cosmic for zero-ops and built-in AI.
Full Comparison →Cosmic ships a hosted first-party MCP server with 18 tools and bucket-scoped key permissions (10.4.1: 84), four production agent types including schedule/webhook-driven Content Agents and GitHub-PR-opening Code Agents (10.2.2: 80), and Agent Skills that install into 16+ AI coding assistants (10.4.3: 82). Native multi-model generation spans text, 4K images, Veo video, and TTS (10.1.2: 82), putting it at the agentic-first tier alongside much larger vendors.
As a fully managed SaaS on AWS/Fastly, Cosmic eliminates server-side dependency management (7.1.4: 80), handles security patching with no known CVEs (7.1.2: 80), and delivers CDN-backed performance requiring no query or cache tuning (7.2.3: 78). Hosting and ops team costs are among the lowest in the category (5.3.1: 80, 5.3.2: 80) — a solo developer can run a production site.
A compact concept model (Buckets, Object Types, Metafields — 6.1.1: 78), mainstream REST/TypeScript/Next.js tooling with no proprietary query language (6.1.3: 78), and three-value configuration (6.2.2: 72) mean a generalist React developer ships within hours (6.3.1: 74). SaaS-only architecture supports genuine solo-developer workflows (6.3.2: 78).
The Fastly-fronted API delivers documented sub-100ms cache-hit responses with cached requests excluded from plan limits (3.1.2: 70, 1.3.2: 76). MongoDB-style query operators, locale-aware queries, batch operations, and depth-controlled reference expansion make the delivery model flexible (1.3.1: 74), with a clean zero-dependency SDK 2.0 surface (3.1.1: 72).
Full tier pricing, per-unit overage rates, and add-on costs are all published (5.1.1: 78), and the free tier is genuinely usable with 1,000 objects and 300k AI tokens (5.1.5: 72). Single-file bucket.json export/import plus documented bidirectional migration guides keep exit costs low (5.3.3: 68), and the mainstream skill set carries minimal specialist premium (5.2.3: 72).
Cosmic publishes no SOC 2 Type II (9.2.1: 28), ISO 27001 (9.2.2: 30), or any additional certification (9.2.3: 32), and explicitly states it lacks bandwidth for custom security assessments. There is no BAA or HIPAA posture (9.1.2: 25), and GDPR support lacks a published DPA, SCCs, or sub-processor list (9.1.1: 45) — disqualifying for most regulated procurement.
There is no audience segmentation engine (2.1.1: 20), no content-variant personalization primitive (2.1.2: 30), no A/B or multivariate testing (2.1.3: 20), and no recommendation engine (2.1.4: 15). All targeting and experimentation must be assembled from external tools and frontend logic (8.1.5: 22, 8.1.6: 20).
Authoring is form-based with preview links only — there is no drag-and-drop page composer or click-to-edit overlay comparable to Storyblok or Sanity Presentation (1.2.1: 50, 2.7.1: 38). Marketers cannot create new landing-page layouts without developer work (8.1.1: 42), and preview integration requires custom frontend wiring (6.2.4: 48).
Only four predefined roles exist with no custom role builder, field-level permissions, or SCIM (2.9.4: 42), and authorization lacks content-instance ACLs (3.2.2: 52). SAML SSO is restricted to the sales-gated Enterprise tier (3.2.1: 62), and end-user audience-based content visibility is absent (8.3.1: 35) — limiting fit for large multi-team or regulated organizations.
Webhooks, localization, revision history, and automatic backups are each $99/mo add-ons (or a $199/mo bundle) rather than included in paid tiers (5.1.3: 38, 2.9.2: 58, 2.5.2: 52). Combined with the 6x Builder-to-Team pricing cliff, effective cost for a production marketing site can substantially exceed the sticker price.
External signals are weak: ~6 G2 reviews and ~358 LinkedIn followers (4.2.1: 42), scarce third-party tutorials and courses (4.2.4: 42), and few developers listing Cosmic experience (4.3.1: 38). The integration marketplace holds under 20 purpose-built apps with gaps in DAM, translation, and enterprise MarTech (3.1.4: 48), and community support depth trails tier-1 peers (7.3.2: 45).
Cosmic is an AI-native headless CMS that pairs a simple, developer-friendly content API with one of the most complete agentic AI stacks in the category — hosted MCP server, four production agent types, and native text/image/video generation. It excels at low-friction builds and low operational cost for small JavaScript/TypeScript teams, but carries material gaps in compliance certifications (no SOC 2/ISO 27001), enterprise governance, native personalization/experimentation, and visual editing. Its aggressive add-on pricing for table-stakes features (webhooks, localization, revision history at $99/mo each) and thin community/ecosystem keep it best suited to startups, agencies, and AI-forward product teams rather than regulated enterprises or marketing-led organizations.
Cosmic's Object Types provide ~15 metafield types (text, textarea, markdown, HTML, number, date, switch, color, dropdown/radio/checkbox, single/multiple file, object relationship, JSON, repeater, and parent/nested fields) plus 2025-2026 additions like conditional fields (show_when), unique constraints, and batch metafield operations. Schemas are primarily UI-configured with API-driven creation possible (and AI agents can auto-generate Object Types), but there is no native schema-as-code workflow (TypeScript-defined schema import/export) and union/polymorphic references are not first-class — capping it below Sanity/Hygraph.
Object relationships are handled via Object metafields referencing other Objects, with one-to-one and one-to-many supported and reverse lookups possible via query filters. Not graph-native like Hygraph — no bidirectional relationships defined at schema level, and polymorphic references require workarounds. Adequate for typical headless use cases but traversal depth and reverse-lookup ergonomics in a single query lag behind GraphQL-native peers.
Cosmic supports nested structured content via the Object metafield (references to other Objects), parent/nested fields, and repeater groups for repeating structured blocks, plus JSON metafields for arbitrary structured data. No first-class Portable Text or block-based composition primitive like Sanity or Storyblok — structured page composition is typically modeled via linked Objects rather than an embedded block editor with unlimited nesting.
Built-in validations include required, regex patterns, min/max, unique constraints, and conditional field visibility (show_when) with smart validation that skips hidden fields on save. File-type and size limits are platform-enforced on media uploads. Custom validation rules are limited — webhooks can react post-save but there is no native pre-save validation hook or app-extension framework comparable to Contentful UI Extensions or Sanity custom validators.
Every Object keeps a full revision history with rollback (click a revision, then Save Draft or Publish), and 2025-2026 added programmatic Revision APIs (GET revisions list and GET single revision by ID via REST/SDK; revisions are immutable). Merge Requests provide Git-like branching between Bucket environments with bulk edits, preview, and approval; scheduled publishing and draft/published states are native. The absence of an inline field-level snapshot diff UI keeps it below the 80+ best-in-class tier.
Cosmic is form-based with Preview Links for in-context review of draft and published states, but does not offer true in-page visual editing with drag-and-drop component rearrangement. Marketers cannot restructure page layouts without developer-defined Object Types and referenced components. This is characteristic of API-first headless platforms and scores near the rubric floor for visual editing.
The 2024-2025 New Content Editor provides standard WYSIWYG with sticky toolbar, code editing (multi-cursor), emoji, and AI text generation that can pull context from other metafields. Output is HTML (and raw markdown from the html-textarea/markdown metafield) rather than a portable AST like Portable Text, and there is no native custom node/mark extension framework for developers — limiting cross-channel portability and developer extensibility.
Built-in media library with folder organization, bulk operations, metadata, role-based access, signed URLs for sensitive content, and imgix-backed URL image transforms (resize, crop, format including WebP/AVIF, quality). The October 2025 infrastructure upgrade added automatic device-based image optimization with sub-100ms global delivery. Lacks a first-class focal-point editor and DAM-grade tagging taxonomies compared to Contentful or Sanity, capping it below 75.
Cosmic added Comments with mentions in April 2025 for async collaboration and has role-based workflow integration plus time-stamped audit logs. There is no real-time co-editing with live presence indicators — concurrent edits rely on last-write-wins / optimistic behavior. Merge Requests provide async reconciliation for parallel work in separate environments rather than simultaneous co-editing.
Four built-in roles (Admin, Developer, Editor, Contributor) with granular permissions; AI Workflows (2025-2026) add multi-step automations with human-in-the-loop approval gates; Merge Requests provide approval-style content promotion between environments with time-stamped audit logs. Customizable multi-stage editorial workflows beyond draft/published/approval are not as deeply configurable as Contentstack or Kontent.ai's stage-builders.
Cosmic offers both REST and GraphQL delivery APIs with separation between read/delivery and management endpoints, rich filtering (MongoDB-style query operators), sorting, pagination, locale parameters, batch operations, and depth-controlled reference expansion; SDK 2.0 ships zero-dep native fetch and Cosmic is deliberately REST-first for cacheability. Well-designed and flexible — does not hit 80+ because GraphQL is a secondary interface rather than the primary design and reference traversal depth is limited compared to graph-native peers.
The October 2025 infrastructure overhaul delivers sub-100ms global API responses via CDN caching with a documented large performance improvement; images are CDN-optimized through imgix with device-aware transforms and cache invalidation on publish is near-instant. No edge-compute personalization primitive (ESI/edge functions) of its own, which keeps it below the 80+ band reserved for platforms with edge-side composition or routing.
Webhooks support configurable events (object create/update/delete, publish), filtered payloads, and async delivery for build triggers and integrations. Public docs do not prominently feature HMAC-signed payloads, an in-dashboard delivery-log UI, or configurable retry policies — placing it in the adequate 60-70 band rather than best-in-class.
Purpose-built API-first headless — content is channel-agnostic with REST+GraphQL, and a hosted MCP endpoint (mcp.cosmicjs.com, ~18 tools) exposes content to AI agents/clients. Official SDK coverage centers on JavaScript/TypeScript (Node, React, Next.js starters); other language SDKs are largely community-maintained. Rich text output is HTML rather than a portable AST, which limits non-web channel portability. Strong for JS/agent ecosystems, narrower than Contentful/Contentstack for multi-language enterprise stacks.
No native audience segmentation engine. Cosmic has no built-in rules engine for defining audiences, no CDP integration, and no behavioral tracking. Audience definitions must live entirely in an external CDP or personalization layer and be applied by the consuming frontend.
No native content-variant-per-audience primitive. Personalization is achievable only by modeling variant Objects and selecting them in the frontend via external decision logic (Ninetailed, custom code). There is no in-editor preview per audience and no decision engine in the CMS.
No native A/B or multivariate testing. No traffic allocation, no statistical significance, no experiment management UI. Teams must plug in an external tool (LaunchDarkly, Optimizely, Vercel Edge Config) and manage test content via generic Objects.
No native algorithmic recommendation engine — no ML ranking, no collaborative filtering, no editorial recommendation weighting. Related content must be manually curated via Object references or computed externally via Algolia Recommend, AWS Personalize, or custom logic.
The REST/GraphQL query API supports filtering and basic full-text search via query parameters (title, metadata field matches, advanced query operators). No relevance tuning, no faceting, no typo tolerance, no autocomplete. Functional filter-based retrieval but not a production search experience out of the box.
Official Algolia integration documented as both a marketplace Extension and an integration guide, with webhook-driven index sync on Object publish/unpublish/delete events. Webhook infrastructure supports Elasticsearch/Typesense patterns through custom endpoints. No broad native search-app marketplace but the first-party Algolia pattern is well-documented.
No native commerce capabilities — no product catalog schema, no cart, no checkout, no pricing, no inventory, no order management. Cosmic is a pure headless content platform and explicitly positions commerce as an integration concern (typically Shopify, or a Stripe-enabled custom frontend).
Shopify integration is marketed and documented as a pattern — Cosmic manages rich product content while Shopify handles catalog/cart/checkout — but the connection is largely content-modeling + API fetch in the frontend rather than a packaged product picker app with live product data federation. No bidirectional sync, no first-party commercetools/BigCommerce/SFCC connectors documented.
Flexible Object Types and metafields (repeaters, references, rich text, image galleries) can model product descriptions, enriched copy, variant content and image assets, and Cosmic explicitly markets structured product content as a strong fit. No purpose-built PIM field types (SKU, pricing rules, stock, variant option matrix) — generic content types repurposed for product content.
Dashboard shows operational usage metrics (API requests, storage, bandwidth, object counts) per bucket, plus Insights data surfaced to AI agents. No native content performance analytics, no author productivity metrics, no content lifecycle dashboards. Analytics that exist are plan-limit monitoring rather than content effectiveness measurement.
Webhook system can push content lifecycle events to Segment, GA4 server-side, or custom analytics pipelines. No official marketplace connectors for GA4/Segment/Amplitude — integrations are pattern documentation + webhook wiring. Being headless, frontend analytics integrate at the application layer without CMS constraint.
Buckets serve as independent environments per project or site, and Projects/Clusters group buckets for shared usage/billing and umbrella admin. No native cross-bucket content sharing or shared component library — sites are silo-based with promotion between buckets via the 'Promote Content' / Merge Requests features.
Localization is treated as a first-class concept with locale identifiers on Objects and locale-based API queries, enabling parallel content development per locale. However, localization is a paid add-on (part of the $199/month Feature Bundle, or included on the Team plan) rather than a free core feature, and localization is document-level (locale-specific Object copies) rather than field-level.
No official marketplace integrations with major TMS platforms (Phrase, Smartling, Lokalise, Crowdin) documented. Translation is accomplished primarily via AI-driven localization workflows or via custom webhook-based pipelines, with bulk export/import possible through the Management API. No enterprise TMS connectors exist.
Projects/Clusters provide organization-level grouping of buckets with shared billing and centralized admin. Per-bucket roles enforce access but there are no cross-bucket shared component libraries, no cross-brand approval workflows, and no enforced global style/policy governance. Multi-brand support is organization-level billing + admin rather than true governance.
Media library supports folders, metadata, tagging, role-based access, and signed (time-limited) URLs for protected content. Revision/version history is a paid add-on and applies to content revisions; binary asset versioning is not documented. No rights/expiry management, no cross-content usage tracking, no enterprise asset workflows. Decent metadata-aware library but not a purpose-built DAM.
Native imgix integration auto-converts every uploaded image to an imgix URL with global CDN delivery. Full on-the-fly transforms via URL parameters: resize, crop, format conversion (WebP/AVIF/JPEG), quality, compression, intelligent cropping. An imgix Editor Extension enables in-dashboard visual editing with focal point controls. Strong result for a headless CMS — native CDN + modern formats + focal points clears the 70+ bar.
Video files can be uploaded and served via the media CDN, and YouTube can be connected for embedding, but there is no native transcoding, no adaptive bitrate streaming (HLS/DASH), no captions/subtitles management, no thumbnail generation. Production video use cases require external services (Mux, Cloudflare Stream, YouTube, Vimeo). Consistent with headless CMS peers.
Dashboard offers drag-and-drop media management and structured block composition via repeater metafields, with preview URLs per deployment and preview mode for draft content. However, there is no in-context visual editor overlaying the live frontend (no Sanity Presentation / Storyblok Visual Editor equivalent) and no drag-and-drop page canvas — authoring is form-based with a preview pane.
Merge Requests bring a git-like workflow: editors make bulk edits in a source bucket/environment, open a merge request to a target, and route through preview + admin approval before merge. Approval Gates add human-in-the-loop checkpoints for automated pipelines. Predefined roles route review responsibility, but there is no fully custom multi-state workflow engine, no SLA tracking, no parallel approval paths.
Scheduled publish and scheduled unpublish are supported on Objects, with each automatic publish event creating a new revision for auditability, giving functional embargo via scheduled unpublish. No dedicated calendar/timeline UI showing scheduled items; no named release bundle for atomic multi-object publishing.
Comments feature supports inline comments on Objects and specific metafields with @mentions and notifications. Revision History tracks changes with author attribution and supports rollback (add-on on some plans). No true simultaneous multi-author editing (no CRDT/OT), no presence indicators documented — collaboration is comments + revisions rather than real-time co-editing.
No native form builder. Forms are implemented by defining a Submission Object Type and using the REST/GraphQL API from the frontend to write submissions into Cosmic. No CAPTCHA, no conditional logic, no progressive profiling, no hosted form pages. Developer-only API workaround, not a marketer tool.
No native email sending or campaign management. HubSpot and other ESPs (Mailchimp, Brevo) are connectable via Zapier or custom webhooks but there is no in-CMS subscriber list sync, no triggered-send UI, and no email preview. All connections are basic API/webhook plumbing.
No native marketing automation — no behavioral triggers tied to visitor activity, no drip campaigns, no lead scoring, no lifecycle orchestration. AI Workflows automate content operations but this is content automation, not marketing automation. Marketing workflows live entirely in external tools (HubSpot, Marketo) connected via Zapier.
No certified CDP marketplace integrations (Segment, mParticle, Tealium, Salesforce CDP). Segment-style event forwarding is possible via webhooks but no bidirectional profile sync, no unified customer profiles in Cosmic, no in-CMS audience resolution. Custom integration patterns only.
Cosmic has an Extensions marketplace (imgix, Algolia Search, Unsplash, media/video tools) plus a growing AI Agent Marketplace and integration guides for Shopify, Algolia, HubSpot (via Zapier), and Vercel. Total first-party integration breadth is smaller than tier-1 headless CMS marketplaces (Contentful App Framework, Contentstack Exchange), but the extensions gallery plus agent ecosystem is a real, if modest, ecosystem.
Webhooks cover Object lifecycle events (create, update, delete, publish, unpublish), support event filtering by Object Type, offer authenticity verification (signed/verifiable payloads), and can trigger downstream workflows. Webhooks are a paid feature (part of the $199/month Feature Bundle, or included on higher plans). Retry policy details and log retention are less prominently documented than Hygraph/Contentful webhook infrastructure.
Preview URLs per deployment, draft/published states on Objects, and bucket-based staging environments provide solid preview infrastructure, with Merge Requests giving environment promotion workflows and GitHub PR preview deployments built in. Missing: shareable expiring preview links for unauthenticated stakeholders and multi-channel simultaneous preview.
Predefined roles (Admin, Developer, Editor, Contributor) cover basic access separation, and the Enterprise plan now adds SSO (single sign-on) plus a branded workspace — an improvement over prior documentation that showed no SSO. However there is still no custom role definition, no field-level permissions, no content-type-level ACL, no locale-specific permissions, and no documented SCIM, keeping the model coarse for enterprise buyers.
Cosmic offers both REST and GraphQL APIs with good documentation and an interactive reference, now positioned REST-first for cacheability and AI-agent consumption. The SDK 2.0 surface (native fetch, zero deps), batch operations, conditional fields, unique constraints, and multi-select metafields make it consistent and well-designed. Not best-in-class purpose-built quality (Sanity/Contentful), but solid.
All Cosmic endpoints (REST and GraphQL) are now served through the Fastly global CDN with documented sub-100ms cache-hit response times, and cache-served requests do not count toward plan request limits — a meaningful efficiency win. Request limits are documented (429 on overage, 6MB request/response ceiling, 30s timeout) and batch operations improve bulk writes. Still no sync/incremental delivery API equivalent to Contentful's, and published throughput (50M requests/month) trails tier-1 headless competitors.
Two official SDKs are now maintained under the cosmicjs org — the primary @cosmicjs/sdk (JavaScript/TypeScript, fully typed, zero runtime deps in v2.0) and cosmic-sdk-swift (a pure-Swift CRUD SDK for Swift/SwiftUI via Swift Package Manager). No official Python, Ruby, Java, PHP, or .NET SDKs; those languages access REST/GraphQL directly or via community packages. Still narrower than Contentful/Sanity/Contentstack, but the Swift addition moves it into the 2-SDK band.
Cosmic's marketplace lists roughly 7 first-party integrations (Vercel, Netlify, Cloudflare, Render, Kinsta, Algolia Search, Stripe/Stripe Products) plus a handful of extensions and templates (Mux — now archived, Unsplash, YouTube, Instagram, SEO/contact form blocks). Under 20 total purpose-built apps with clear gaps in DAM, translation/localization, dedicated analytics, and enterprise MarTech.
Cosmic now offers Functions (serverless functions in public beta) for custom server-side logic, alongside dashboard Extensions (below_publish_options/below_metafields), Blocks (custom React content UI), webhooks, an MCP Server, and event-triggered AI Agents that act autonomously on bucket events. The addition of server-side Functions closes much of the gap versus a full App Framework, though custom field-editor depth still trails Sanity Studio and Contentful's App Framework.
2FA is available free on all accounts — a positive. SAML 2.0 SSO (OneLogin, Okta, and any SAML 2.0 identity provider) remains restricted to the Enterprise plan, creating friction for mid-market buyers on the Team ($299) and Business ($499) tiers. Environment-specific API keys and read/write token separation are supported.
Team-based RBAC with role assignment and environment-scoped API keys are documented, but Cosmic does not prominently advertise field-level permissions or content-instance access control of the sort Contentful/Sanity offer. Suitable for small-to-mid teams, limited for regulated or large multi-team workflows.
Cosmic's own security page does not publish formal SOC 2 Type 2, ISO 27001, or HIPAA certifications — it directs compliance-specific inquiries to support. GDPR compliance is claimed (Cosmic as data controller) and EU data residency is supported via the eu-west-1 database region. Note: third-party sources conflate Cosmic (cosmicjs.com) with Cosmic DC (cosmicdc.com) — separate entities. Full compliance scored in cat9.
No known public breaches or significant CVEs. Disclosure is handled via [email protected] rather than a dedicated security.txt or bug bounty program. Clean but understated — lacks the formal vulnerability management communication that enterprise buyers expect.
Cosmic is SaaS-only on AWS (API, CDN via Fastly, MongoDB Atlas for storage). No self-hosted or private cloud option; regulated industries requiring on-prem or dedicated tenancy must choose differently. Simplicity win, flexibility loss.
A dedicated Service Level Agreement page documents a 99.95% uptime commitment, but the SLA is Enterprise-only — lower tiers have no explicit guarantee. A public status page (Statuspage) now exists for API monitoring and subscriptions, and automatic region-failover is described. Incident communication is still less mature than tier-1 headless competitors.
Fastly global CDN now fronts all AWS-hosted endpoints across four database regions (us-east-1, us-west-2, eu-west-1, ap-southeast-1) with cross-region failover, processing 50M+ requests/month for teams in 150+ countries. CDN-backed horizontal scaling is in place, but Cosmic lacks the Fortune-500 enterprise reference footprint of Contentful or Contentstack.
Automated cross-region failover is documented, and full content export via REST/GraphQL APIs and CLI is available. However, no public RTO/RPO numbers, backup retention schedule, or point-in-time restore options are published, leaving compliance buyers to negotiate in contract.
Cosmic ships a CLI with AI-powered content creation, app generation, and one-command deployment; local development is remote-first against a dev bucket/environment, and serverless starters exist for Functions. No full offline emulator like Sanity CLI's dev server or Payload's self-hosted dev mode.
Multiple environments (dev/staging/prod buckets) are supported with environment-specific API keys and webhook-triggered deployments to Vercel/Netlify/Cloudflare/Render/Kinsta. Schema migration tooling remains less mature than Contentful CLI's content migration scripts — changes are largely dashboard-driven with CLI import/export as the migration path.
A refreshed docs site covers 11+ frameworks (Next.js, Astro, Remix, Express, Nuxt, Svelte, Fastify, RedwoodJS, Vite, Hono, Bun) with REST/GraphQL API reference, CLI, Webhooks, Extensions, Blocks, Functions, and MCP Server sections. Good framework breadth and code examples; depth on advanced topics (migrations, enterprise patterns) is lighter than Contentful/Sanity.
@cosmicjs/sdk v2.0 is fully typed with typed responses out of the box for autocomplete and type safety, with no query-document compilation. However, automated type generation from the content model (Object Types/metafields) is not a first-class feature — developers hand-type or use community codegen, unlike Contentful's contentful-typescript-codegen or Sanity's sanity-codegen.
Cosmic sustained a near-weekly feature cadence into mid-2026: Gemini 3 Pro support, Cosmic Skills, Team Agents in Slack/WhatsApp/Telegram, Event-Triggered Agents, and Hosted MCP all shipped across early-to-mid 2026 (changelog entries through May 22 2026). Not higher because output remains concentrated in the AI-agents surface rather than spread evenly; not lower because the visible cadence rivals top headless peers.
Cosmic maintains a dedicated, paginated /changelog with clear dates and per-entry narrative posts. Entries are descriptive and discoverable but read more like blog posts than structured release notes; no clear semver tagging or dedicated migration guide per release. Not higher because breaking-change sections are absent; not lower because cadence and clarity are solid.
Cosmic now surfaces a public roadmap within the dashboard where users can add and vote on feature requests and submit bug reports, alongside a new in-dashboard feedback mechanism — a step up from purely retroactive blog/changelog signaling. Not higher because the roadmap sits behind the dashboard rather than as an open public backlog with visible timelines; not lower because a structured vote-and-request channel now exists and direction is clearly communicated.
As a managed SaaS with a stable REST/GraphQL API (and a versioned API v3), Cosmic absorbs most infrastructure churn for customers. SDK 2.0 (Apr 2026) shipped as a major version signaling the upgrade, but no public deprecation timeline or codemod is documented. Media-replace continues to demonstrate reference stability ('same URL and id'). Not higher because no formal API versioning/deprecation policy is published; not lower because end-users rarely report breakage.
Company LinkedIn shows ~358 followers; G2 has only 6 reviews; no prominent Discord, and the GitHub org has modest repos. Cosmic markets '75,000+ developers' but independent third-party signals remain thin compared to Strapi, Sanity, or Directus. Not lower because a Slack community, community-members page, and steady blog cadence exist; not higher because every external signal places Cosmic well below peers.
Cosmic operates a Slack community, publishes regular Community Deployments, added an in-dashboard Comments/feedback feature, and runs a 'Cosmic Rundown' news series alongside frequent tutorials. Team members participate visibly on blog and social. Not higher because there is no large public forum, no visible Stack Overflow activity, and no documented community SLA; not lower because the team is responsive and engagement density is healthy relative to base size.
Cosmic runs a formal Partner Program connecting a global network of agencies and technology providers, with a public directory of agency partners plus tech partners. No tier-1 global SIs (Accenture/Deloitte/Valtech), no certification exams, no referenceable named implementation practices. Not higher because depth is shallow; not lower because the program is real and includes both agency and technology partners.
Most tutorials, comparisons, and guides about Cosmic are first-party (cosmicjs.com/blog and /changelog). Limited YouTube coverage, no Pluralsight/Udemy courses surface in search, and conference talks are scarce, though independent review sites (Bejamas, StaticMania, Cuspera) profile it. Not higher because third-party amplification remains thin; not lower because listing/review sites still include Cosmic.
Cosmic is a niche platform with no mention in Stack Overflow developer surveys, no certification program, and few LinkedIn profiles listing it as a primary skill. Because Cosmic uses standard REST/GraphQL with a Next.js-friendly SDK, most React/Next.js developers ramp quickly, but specialized Cosmic experience is rare. Not higher because named Cosmic experts are hard to find; not lower because the generic skill overlap is broad.
Case studies profile customers like Prairie Robotics, marketing cites 75K+ developers, and Cosmic publishes content on YC companies adopting it, but no recent Fortune 500 logo announcements and the G2 review count remains static at 6. Heavy product velocity (Gemini 3 Pro, Team Agents, Hosted MCP) suggests continued signups. Not higher because enterprise traction signals are limited and there is no public ARR or customer-count update; not lower because the platform keeps publishing customer stories and shipping features that attract new builders.
Cosmic is a bootstrapped YC (W2019) company that reached ~$1.2M revenue by 2024 with no outside venture capital beyond YC's ~$150K, operating with a small ~8-person team as of Apr 2026. Self-funding means no burn/runway distress and no layoffs, but also a tiny team and no war chest to outspend well-funded rivals. Not higher because scale and financial cushion are limited; not lower because the company is revenue-generating, stable, and shipping heavily with no distress signals.
Cosmic has executed clearly on its 'AI-Powered Headless CMS' thesis — Hosted MCP, Event-Triggered Agents, Team Agents, and Gemini 3 Pro support all shipped in 2026, and it is actively repositioning the category ('Why Headless CMS Is the Wrong Category'). No Gartner MQ / Forrester Wave recognition in Headless CMS. Not higher because analyst validation is absent and the AI-CMS space is crowded; not lower because the AI-native narrative is differentiated and visibly delivered, not just promised.
G2 rating is 4.3/5 but based on only ~6 reviews, well below the 100-review threshold for mid-tier scoring. Reviews are generally positive (praising the headless approach, ease of use, workflow automation) with minor complaints about pricing for startups and limited versioning tooling. Not higher because sample size is too thin to establish strong sentiment; not lower because what exists is favorable and no widespread negative signal appears on Reddit or HN.
Cosmic publishes full pricing for Free, Builder ($49/mo), Team ($299/mo), and Business ($499/mo), plus per-user ($29) and per-bucket ($29) adders, itemized feature add-on prices, and a published metered overage rate. Only Enterprise is sales-gated, which is industry norm. Not higher because the add-on model ($99/mo per feature, $199/mo bundle) adds cognitive load to final-price estimation.
Flat monthly tiers with included limits are predictable, but the $49 Builder → $299 Team jump is a 6x cliff that forces teams into the expensive tier once they exceed 5,000 objects. Cosmic has since simplified CDN metering to a unified ~$10 per 1M events (cached API, media requests, API/media bandwidth), which is more legible than the old per-GB rates, but end-of-month bills still vary with traffic. Not lower because rates are published and the unified model is predictable; not higher because the Builder→Team cliff remains the dominant cost risk.
Webhooks, Localization, Revision History, and Automatic Backups are each sold as $99/mo add-ons (or $199/mo bundle) rather than being included in paid tiers — aggressive for a headless CMS where webhooks and revision history are table-stakes. SSO is now Enterprise-only (sales-gated), not on the Business plan as previously credited, so the earlier positive relative to peers no longer applies. Not lower because core content APIs are available at every tier; not higher because both basic operational features and SSO sit behind paywalls.
Monthly billing is supported on all tiers, yearly billing saves 10%, and the free tier requires no credit card. 14-day free trial on add-ons reduces commit risk. Not higher because no explicit startup, nonprofit, or education discount program is published; not lower because there's no onerous annual lock-in requirement and the free tier serves as a permanent low-commitment entry.
Free-forever plan includes 1,000 objects, 1 bucket, 2 team members, 100k cached API requests, and a recently expanded 300k AI tokens (a 30x increase), plus full REST API, TypeScript SDK, CLI, and MCP server — genuinely usable for prototyping and small production sites. The new $49 Builder tier also softens the free-to-paid step. Not higher because 1 bucket and limited bandwidth constrain any real traffic; not lower because the tier is meaningfully capable and permissive with no credit card required.
REST API with MongoDB-style query operators (no proprietary query language like GROQ), TypeScript SDK, CLI, MCP server, sub-100ms responses, and Next.js App Router support make a first content query achievable in well under an hour for a modern JS developer. AI Agents and code generation further compress scaffolding, and Cosmic documents a 30-minute Contentful migration. Not higher because multi-bucket structure and object-type modeling still require upfront content-modeling decisions.
Case studies cite 67% faster time-to-market vs. WordPress for a React team, consistent with simple marketing sites landing in 2–4 weeks. AI-native tooling (agents, code generation, MCP server) compresses the scaffolding phase. Not higher because no G2 Implementation award signal at the scale of Storyblok/Hygraph, and complex multi-locale or multi-bucket projects still require non-trivial setup; not lower because the stack is deliberately lightweight.
Cosmic relies on mainstream skills: REST, JSON, JavaScript/TypeScript, React/Next.js, MongoDB-style filters. No proprietary query language (unlike Sanity's GROQ) and no certification program — any competent JS/React developer can become productive quickly. Low specialist premium (~10–15% over generalist web dev). Not higher because the platform's AI Agent and Blocks conventions still require some Cosmic-specific familiarity for advanced work.
Fully managed SaaS — all storage, API, media CDN, and AI infrastructure included in tier price. Enterprise tier includes 99.95% SLA and isolated compute/storage. Buyers only pay for front-end hosting (Vercel/Netlify/etc.), which is standard for all headless CMS deployments. Not higher because media/CDN bandwidth overages metered at $10/1M events can add up for high-traffic sites and are effectively additional hosting spend.
Pure managed SaaS — no servers, databases, patching, or scaling for the CMS itself. A solo developer can run a production Cosmic site; no dedicated platform engineer required. Not higher because teams still own build/deploy pipelines and edge caching strategy on the consuming app, and add-on configuration (webhooks, localization) requires some operational oversight.
Cosmic advertises 'no vendor lock-in through proprietary formats' and supports full single-file export/import: the exact bucket.json you download is what you re-upload to restore or migrate, and content is standard JSON accessible via REST. Documented migration guides run both directions (Contentful/Sanity/Prismic/Storyblok into Cosmic, and the reverse via the same JSON). Not higher because AI Agents, Blocks conventions, and bucket-scoped object relationships create some adaptation work on exit; not lower because raw data is fully portable with documented tooling.
Cosmic's model is compact: Buckets (projects), Object Types, Objects, Metafields, and Environments — fewer moving parts than Contentful's Spaces/Environments/Content Types/Entries split. Responses are clean JSON with no envelope schema to unwrap, and Merge Requests borrow a Git mental model. Not higher because repeaters, groups, Blocks, and Extensions add a second layer once teams move beyond simple sites.
Docs cover 11+ frameworks (Next.js, Astro, Remix, Nuxt, SvelteKit, Vue, Express, etc.) with quickstarts, and 2026 additions — an official MCP Server (Cursor/Claude Code/GitHub Copilot) and an AI-powered CLI that scaffolds and deploys apps in one command — meaningfully lower the ramp for AI-assisted developers. Templates marketplace and guided app creator provide hands-on starts. Not higher because there is still no structured learning path or certification track comparable to Contentful Academy, and video/interactive tutorial coverage lags tier-1 peers.
Dual REST + GraphQL APIs, a fully-typed TypeScript SDK with a chainable query API, native fetch and zero dependencies, plus first-class Next.js App Router / server-component / ISR patterns. The 2026 MCP Server lets Cursor/Claude Code/Copilot read and write content from the IDE — squarely mainstream tooling with no proprietary abstractions. Not higher because schema is UI-managed rather than schema-as-code, which breaks the TypeScript-first workflow Sanity or Payload offer.
Official templates cover Next.js marketing site, blog, landing page, and portfolio patterns (the flagship cosmic-next-template ships Next.js 14 + shadcn/ui + Tailwind), and the AI-powered CLI generates apps with content model + example content + deploy config baked in. Extensions for Vercel/Netlify/Cloudflare/Render streamline hosting. Not higher because the catalog is smaller than Storyblok's or Sanity's, and non-Next.js starters don't reach the same polish as the flagship.
Zero-to-working integration needs three values: Bucket slug, Read key, and (for writes) Write key — all obtainable from the dashboard in under a minute. The SDK has sane defaults, no dependency tree, and environment switching is a single parameter — simpler than Contentful's Space ID + Delivery + Preview + Management token matrix. Not higher because scaling to multi-env workflows adds per-environment key management and webhook configuration overhead.
Schema changes are low-risk: metafields can be added, updated, or removed at any time without downtime or a migration script, there is no field-count ceiling, and 20+ field types plus conditional fields and unique constraints cover most modeling needs. However, there is no first-class migration-script runner comparable to contentful-migration for reproducible schema promotion across environments, so field renames still propagate as breaking changes to consuming queries and populated Object Types require careful manual sequencing.
Preview Links give editors in-context review in draft/published states, but wiring them up requires frontend work — a preview-mode route, draft-aware fetching via the status=any parameter, and a token-guarded preview URL. No plug-and-play visual preview or click-to-edit overlay of the kind Storyblok, Sanity Presentation, or Hygraph Click-to-Edit provide. Decent for a developer but not plug-and-play.
A generalist TypeScript/React developer can ship a Cosmic-backed site within hours — no certification, no proprietary query language (MongoDB-style is industry-standard), no custom templating, and the MCP Server lets AI coding tools do much of the wiring. Some familiarity with headless content modeling and Object Type relationships is needed, but the curve is flatter than GraphQL-native peers like Hygraph. Not higher because Extensions and Blocks require React component knowledge at the dashboard layer if teams extend the editor UI.
SaaS-only on AWS/Fastly eliminates DevOps, infrastructure, and backend roles. A solo developer can model content, build the frontend, and deploy to Vercel end-to-end, and the AI CLI + MCP Server compress that further; many Cosmic customer stories are 1–2 person teams. Scaling to multi-locale, multi-environment, Merge Request workflows may warrant 2–3 people but not the 5+ role DXP team. In line with peers Sanity/Storyblok.
Editors can create and update Objects in existing Object Types without developer involvement, and 2025–2026 additions — the New Content Editor with AI text generation, Comments, and autonomous AI Content Agents that research, draft, generate images, and publish on a schedule — reduce ongoing developer dependency for content operations. However, new page patterns, component types, or schema changes still require developer-defined Object Types, and without a visual page composer marketers cannot restructure layouts independently.
Cosmic is SaaS with continuous vendor-managed deployment, so the core platform requires no version upgrades. The v1→v3 transition did require connecting to new API keys and swapping the deprecated 'cosmicjs' npm package for '@cosmicjs/sdk', but Cosmic documents the new dashboard/API v3 as fully isolated from v1 with 'no possibility of breaking anything currently in production.' Not higher because that SDK/API migration still required customer action; not lower because the isolation design and upgrade guide keep it low-risk.
SaaS vendor-managed infrastructure — CVE patching is handled by Cosmic without customer action, and there are no publicly tracked Cosmic CMS CVEs (the CosmicSting CVE-2024-34102 is an unrelated Adobe Commerce vulnerability). Cosmic maintains a dedicated security page and scoped-permission/bucket-isolation design for AI agents. Not higher because Cosmic does not publish a formal SOC 2 advisory cadence or public security bulletin schedule like larger vendors (Contentful, Contentstack).
Cosmic has real forced-migration history: it progressed v1→v2→v3 in a relatively short window and deprecated the v1 dashboard, prior REST API versions, and the old 'cosmicjs' npm package. However, the new dashboard/API v3 is isolated from v1 (existing production keeps working) and Cosmic launched a migration assistance program with compatibility tooling. Not higher because API/SDK version churn is more frequent than large peers with 12+ month deprecation windows; not lower because the transitions were non-breaking to running production and assisted.
SaaS model — near-zero server-side dependencies for the customer, with no database, search, cache, or CDN to operate. The only client-side dependency is the JavaScript SDK ('@cosmicjs/sdk'). Not higher because customers must keep the SDK current and absorb the deprecation of the legacy 'cosmicjs' package when moving to the v3 SDK.
Cosmic provides a public status page (cosmicjs.statuspage.io) with uptime history and incident notifications, a 99.95% Enterprise uptime SLA, and usage dashboards in the project UI, so per-request monitoring is largely covered by the vendor. Customers still need application-layer monitoring for webhook delivery, API error rates, and quota consumption. Not higher because Cosmic lacks the native APM-grade webhook-delivery health dashboards seen in larger peers (Contentful, Contentstack).
Cosmic provides revisions, media management, and localization, and in 2026 added AI Content Agents that generate and manage content autonomously plus webhook-triggered workflows — emerging automation that reduces some content-ops burden. It still lacks classic content-hygiene tooling (orphan detection, broken-reference alerts, content-expiry workflows), and G2 reviews flag limited versioning/simultaneous-edit handling. Not higher because governance still relies largely on editorial discipline; not lower because AI agents and workflows now offload routine content operations.
SaaS with a global CDN and a high-speed caching layer that Cosmic reports improved API response times 10x+ (e.g., Vuetify moved from 300–400ms to ~50ms) — customers do no query optimization, index tuning, or cache configuration server-side. Not higher because API rate limits require attention and customers must still manage their own front-end ISR/SSG cache layer and quota-based throttling.
Free plan gets community support only; chat support is available on paid mid-tier plans; 24/7 dedicated phone/screenshare/onsite support is locked to the Enterprise tier. This mirrors typical SaaS headless tiering. Not higher because good synchronous/SLA-backed support requires Enterprise; not lower because the chat channel on mid-tier plans is advertised as responsive and the small team is engaged.
Cosmic has a smaller community than Tier 1 peers (Contentful, Sanity, Storyblok) — only ~6 G2 seller reviews, a modest Slack/Discord, thin Stack Overflow and GitHub discussion volume — though team members participate directly. Not higher because edge-case answers are harder to find with limited community content; not lower because the Cosmic team is reachable and responsive in public channels.
As a SaaS platform, fixes deploy immediately once shipped, and the Cosmic changelog shows a fast, transparent public cadence through 2025–2026 (multiple feature releases across April–May 2026 including AI agents, hosted MCP server, and dashboard improvements). Not higher because there is less public visibility into bug-tracker throughput and critical-bug SLAs than larger vendors publish; not lower because community reviews don't surface consistent complaints about stuck bugs.
Cosmic is explicitly structured-content/developer-first and does not ship a drag-and-drop visual page builder; it positions itself as an alternative to page-builder tools like Builder.io. Marketers can edit page field values and AI Content Agents can auto-generate landing-page copy/images, but creating new layouts still requires developer (or Code Agent) work on the frontend. That puts Cosmic in the 'marketers can edit content but not create new layouts' band, slightly lifted by AI scaffolding.
No native campaign calendar, multi-channel campaign orchestration, or campaign analytics. Cosmic provides scheduled publishing and AI-agent-scheduled content runs, which is closer to the 'scheduled publishing as the only campaign feature' band typical of headless CMS.
SEO is delivered via an SEO Fields extension/Block rather than built-in first-class SEO fields with validation. No native sitemap generation, redirect management, or canonical/Schema.org tooling — those are left to the frontend. Content model maps cleanly to schema.org (e.g., BlogPosting) but requires manual implementation. Fits the 'manual SEO field creation without built-in validation' band.
No native form builder, lead capture, UTM handling, or conversion tracking in the authoring layer. All performance-marketing instrumentation must be built on the frontend or delegated to external tools (HubSpot, Segment, GA4). (Cosmic Insights can now record conversion events, but there is no form/CTA/lead-capture builder.)
No native personalization, audience segmentation, or rule-based targeting engine. Any personalization requires pairing with an external CDP/personalization tool and frontend logic (Cosmic publishes only sample personalization apps, not a platform feature).
No native A/B testing, variant testing, or experimentation framework. Any content experiments must be orchestrated via external tools (Optimizely, VWO, LaunchDarkly) on the frontend.
This is a relative Cosmic strength: four agent types (Content, Code, Team, Computer Use) can draft landing pages, blog posts, and images autonomously, open PRs for new pages, and chain into multi-agent brief-to-publish workflows. Revision history, inline editing, bulk operations, and scheduled publishing are supported. Still relies on developer/Code-Agent implementation of new templates, keeping it below best-in-class visual-builder platforms.
Structured content via REST API (sub-100ms) enables web/mobile/email delivery from a single source. Team Agents extend reach into Slack/WhatsApp/Telegram and Computer Use Agents can cross-post media to other platforms via browser automation. No native renditions for push/SMS/social channels — each additional channel requires developer or agent integration. Fits the 'web-first with API-based delivery to other channels' band, lifted by agent-based distribution.
Materially improved: Cosmic Insights is now a native, cookieless web-analytics layer built into the dashboard. Every Object gets its own Insights page (pageviews, visitors, sessions, bounce rate, sources, devices, geography) with period-over-period comparison and a real-time online count, and AI agents can read this data to close the content loop. This is exactly the 'analytics dashboards within the CMS with content performance metrics' pattern. Held below the top band because it is Cosmic's own first-party tracker (requires a one-line JS instrument) rather than pre-built GA4/Adobe/Mixpanel connectors, and there is no content-decay flagging.
Component-based content modeling (repeaters, relationships, 20+ field types) allows structured brand reuse, but there are no native design-token enforcement, locked component palettes, or restricted-override guardrails at the platform level. Consistency is enforced by frontend implementation and editor discipline.
OG/Twitter card meta can be handled via the SEO Fields extension, and AI Content Agents generate social copy. The new Computer Use Agents can now cross-post media between platforms via browser automation, giving a genuine (if unconventional) push-to-social capability beyond just meta-tag management. Still no dedicated social scheduling calendar or UGC embed workflows, keeping it at the top of the OG-plus band rather than into best-in-class social tooling.
Cosmic has a media library with imgix-backed image transforms (resize/crop/format), tagging/folders, and AI-generated alt text in bulk. No usage tracking, rights management, or full DAM capabilities. Covers basic DAM needs but not enterprise marketing asset governance.
Localization is a paid add-on ($99/mo standalone, $199/mo bundle) supporting 400+ locales as first-class in the content model with locale-aware API queries. AI Workflows can propagate source-language updates to all localized versions automatically. No native transcreation workflow or locale-specific campaign variant tooling, but practical for most marketing localization.
Shopify integration is documented; Slack/WhatsApp/Telegram via Team Agents. Webhooks now fire on any content event (create/update/delete/publish) to Vercel, Netlify, Zapier, or any endpoint — available on all plans (as an add-on on self-service tiers). No pre-built CRM (Salesforce), MAP (Marketo, Pardot), or CDP connectors — integrations with those are custom via API/webhooks. Fits the 'some integrations plus generic webhook/API' band.
Flexible content modeling with repeaters, relationships, and nested objects enables custom product-content types (PDP, category, variants, attributes), and Cosmic now ships a production-grade e-commerce storefront template (full catalog, collection pages, dynamic routing, SSR, imgix optimization). Not purpose-built for commerce — no product attribute library, variant inheritance, or PIM-grade features. Generic modeling repurposed for product content fits the 40–60 band.
No native merchandising: no category management UI, no cross-sell/upsell tooling, no search merchandising, no product spotlight curation. These belong to the paired commerce platform (e.g., Shopify), not Cosmic.
Documented Shopify integration with pattern of mirroring product data into Cosmic for faster delivery (reports of 300ms→50ms). Integration is API-based and typically implemented per project rather than via a native product-picker UI in the editor or deep real-time federation. No first-class connectors for commercetools, SFCC, or BigCommerce.
Rich content modeling supports buying guides, lookbooks, and editorial pages. Product embeds are possible via relationship fields but shoppable-content authoring is not a first-class pattern — no inline product picker with purchase CTA component out of the box.
Cart/checkout in a Cosmic+Shopify setup lives in the commerce platform; Cosmic can host banners, trust badges, and shipping callouts as content but there is no native pattern for injecting CMS content into transactional flows.
No documented post-purchase content features (order-confirmation editorial, onboarding sequences, loyalty content tied to order events). Would require custom build on top of the commerce platform's order webhooks.
Basic role-based access control (Admin/Developer/Editor) and API key management, but no B2B-specific features: no account-based catalog gating, no customer-specific pricing display, no quote-request flows, no gated spec-sheet delivery.
Query-based API filtering is available but there is no native faceted search, synonym management, search-landing-page generation, or blended content+product search. Typical implementations add Algolia or similar on the frontend.
Scheduled publishing enables time-activated banners and promo blocks. No native countdown timers, channel-specific targeting, or tiered-pricing table automation. AI agents can schedule promotional content generation.
Multi-bucket architecture supports separate storefronts per brand/region. Merge-to-another-bucket allows content movement. No native pattern for shared product content across storefronts with storefront-specific editorial overlay — content duplication across buckets is the norm.
imgix-powered image transforms, AI image/video generation, basic galleries and video embeds. No native 360-degree view, AR/3D model, or hotspot/zoom tooling — those require frontend libraries or third-party media services.
Multi-author content and role-based permissions allow basic marketplace-style content, but no seller-profile management, review aggregation, or moderation-at-scale tooling. Not marketplace-specific.
Localization add-on enables locale-specific product content at the content layer. Not commerce-specific — no currency-aware content blocks, regional regulatory content (EU labels, Prop 65), or market promo calendars built in.
Materially improved: Cosmic Insights now tracks conversions and revenue with one line of JS — passing revenue_cents auto-rolls the event up against the content Object that drove it, giving genuine content-to-revenue attribution within the CMS. This directly matches the content-to-revenue-attribution criterion. Held below the top of the band because it is general first-party web analytics rather than deep commerce-funnel integration (no cart/checkout funnel analytics or per-SKU product-content performance tied to the commerce backend).
Three predefined roles (Admin, Developer, Editor) with RBAC on content management and separate read/write API keys. No audience-based content visibility for end users, no field-level sensitivity, no department-level audience targeting. SSO is Enterprise-tier only.
Revision history (add-on), content approval workflows, and flexible modeling support knowledge-article structures. No native content lifecycle (review dates, expiry, ownership assignment), and no knowledge-specific taxonomy tooling.
Pure headless CMS, not purpose-built or adapted for employee portals. Building a full EX portal (news feed, directory, notifications, personalized dashboards, mobile app) requires extensive custom frontend development.
No targeted internal-comms tooling: no read receipts, acknowledgment tracking, or mandatory-read workflows. Content could be modeled as internal announcements but distribution, targeting, and tracking are not built in.
No native people directory, org chart, or HRIS connector (Workday, BambooHR). A directory could be modeled as a content type but requires full custom build.
Revision history (add-on) provides version control; approval workflows available. No mandatory acknowledgment tracking, no automated review/expiry reminders, no audit-grade policy management.
No onboarding-specific features (role-based paths, 30/60/90-day progressive disclosure, HR-triggered new-hire portals). Would be a from-scratch frontend build.
Basic API-level query/filter support. No federated search across SharePoint/Confluence/Drive, no AI-relevance ranking, no faceted-filtering UI, no search analytics. Enterprise-search use cases require pairing with a dedicated search platform.
No native mobile app for editors or employees; sub-100ms REST API supports responsive frontend delivery. Team Agents in WhatsApp/Telegram/Slack give a distinct chat-based mobile access path but are agent interactions rather than a deskless-worker app.
No LMS integration (Cornerstone, Workday Learning), no native micro-learning, no completion/certification tracking. Training content can be authored as content types but tracking is out of scope.
Editor-side collaboration (comments, approvals) exists for content teams, but no end-user social layer: no public comments, reactions, forums, polls, or recognition tooling.
Team Agents run inside Slack, WhatsApp, and Telegram with persistent memory and custom personas, executing content tasks from chat. Not a full Teams/Google Workspace embedded-card experience, but the chat-native agent integration is stronger than most headless CMS peers — fits the middle 35–55 band at the top end.
Scheduled publishing and revision history (add-on) enable basic expiry and versioning. No automated review-date reminders, stale-content flagging, or ownership-assignment workflows for intranet trust.
Cosmic Insights now provides real page-view analytics (visitors, sessions, sources, geography) per content Object, lifting this above 'no analytics.' However, Insights is public-web-oriented — it lacks the intranet-specific measures this item targets: department-level views, failed-search-term tracking, engagement heatmaps, and adoption dashboards. Sits in the 'basic page view analytics' band.
Cosmic's Bucket-per-brand model gives clean silo-based isolation: independent content models, environments, and API keys per Bucket, with no cross-bucket data leakage. It is not a native multi-tenant data model (no shared schema with row-level tenancy), placing it in the 55–70 silo-based-isolation band.
Merge-to-another-bucket allows copying object types and content between buckets, but no native live-shared global content or design tokens across brands. Updates to a 'global' component must be propagated by merge/import. Frontend component libraries can be shared at the codebase level.
Workspace layer provides central user/team management across multiple buckets with granular roles, and API key management per bucket. No cross-brand enforced content standards, cross-brand approval chains, or global policy config — governance is per-bucket.
Included buckets scale by plan (1 free; Pro at $499/mo bundles 5 buckets, 50k objects, 3M AI tokens, 10 team members). Paid plans bundle objects/AI tokens with multiple buckets, giving modest economies of scale, but adding many brand buckets generally pushes into higher tiers. Not strong volume discounting, not strictly linear per-brand licensing.
Each bucket can define its own brand theme-token content types consumed by the frontend. No platform-level theming engine that applies per-brand styles to shared rendered components. Theming is effectively frontend configuration per brand.
Localization add-on enables per-locale content in each bucket. No brand-aware translation approval workflow or regional legal governance layered on top. Brand × locale governance is handled manually per bucket.
Cosmic Insights now provides content-performance analytics scoped to the current project or bucket (its real-time online count is explicitly bucket-scoped), so per-brand analytics exist where there were none before. But there is still no portfolio-level dashboard aggregating engagement across buckets — cross-brand comparison remains a manual aggregation exercise. Fits the 'basic per-brand analytics with manual aggregation' band.
Each bucket configures its own approval flow, scheduled publishing, and agent automations. Central audit across brand workflows is limited. Fits the 30–50 'some workflow variants per brand' band, lifted by per-bucket autonomy.
Merge-to-another-bucket enables copying content across environments/brands with the option to adapt downstream. Not a live corporate-to-brand push with override control — more of an import/copy model.
No per-brand compliance rules, GDPR-consent tooling, cookie-policy management, or publishing guardrails. Compliance is implemented outside the CMS. SOC 2 infrastructure-level compliance is baseline and applies to all buckets. (Cosmic Insights is cookieless, which incidentally eases consent burden but is not a compliance-control feature.)
No platform-level design-system registry with brand-extension and version propagation. Design systems are maintained in frontend codebases and consumed across brand sites.
Cosmic Workspace provides central admin across multiple buckets with team members and per-bucket roles. SSO is Enterprise-only. Solid central + per-brand role model, but not granular cross-bucket contributor roles or shared permission sets.
Object types can be merged/cloned between buckets to start from a shared base, but there is no inheritance model where a global schema is extended per brand without forking. Changes to a shared model must be re-propagated manually.
No executive portfolio reporting (freshness by brand, SLA adherence, cost allocation, capacity planning) inside Cosmic. Per-bucket views only; aggregation is a manual exercise.
Cosmic now publishes a discoverable privacy policy (previously 404) that names Cosmic JS as data controller, references the GDPR, and enumerates data-subject rights, and it offers EU data residency via AWS eu-west-1. However, no customer-facing DPA/data processing addendum, SCCs, or sub-processor list is published, so per the DPA anti-pattern the platform cannot reach the DPA-anchored band despite EU residency and a live privacy policy.
No BAA is advertised, no HIPAA-eligible infrastructure tier exists, and no healthcare guidance appears in documentation; Cosmic explicitly states it is a small team that does not fill out custom security assessments. Cosmic is not positioned for PHI workloads.
The privacy policy adds a California Civil Code (Shine the Light) disclosure alongside GDPR, but this falls short of full CCPA/CPRA compliance and no FedRAMP, IRAP, C5, PIPEDA, LGPD, PCI-DSS, or HITRUST references exist. Coverage is effectively GDPR plus a weak California reference, keeping it just above the GDPR-only band.
No public reference to SOC 2 Type 1 or Type 2 attestation exists on the security, enterprise, or features pages, and Cosmic explicitly states it is a small team without bandwidth to complete security assessments — a strong signal that no formal attestation program exists. For a SaaS CMS this is a material gap versus peers (Contentful, Kontent, Sanity).
No ISO 27001 platform-scope certification is published. Underlying AWS infrastructure carries ISO 27001/27017/27018, but per anti-patterns that inheritance does not transfer to the SaaS platform itself.
No CSA STAR, PCI DSS, Cyber Essentials, FedRAMP, IRAP, ENS, or C5 evidence found. Base score reflects the absence of any meaningful additional certifications.
Cosmic offers four AWS regions spanning US, EU, and APAC, which is a real strength for a small headless CMS, but there is no contractual residency guarantee and the documented automatic failover explicitly reroutes traffic to the closest available region — meaning data can cross the elected region boundary. Fastly CDN caching adds further egress, so residency is availability-driven rather than contractually controlled.
Full import/export via REST API and CLI provides genuine data portability, and the security FAQ now documents a retention approach (data kept indefinitely by default, securely disposed of or archived once no longer needed). Deletion, however, remains a manual support-ticket flow (deactivate account, then email support) rather than a self-service portal or API, and no fixed post-termination retention window is committed.
Cosmic lists audit logs plus role-based access control, API key management, and revision history as enterprise features, providing basic who-did-what visibility. However, no SIEM push, log export API, or configurable retention period is documented, keeping this near the basic-logs band.
No published WCAG 2.1 AA conformance statement or ATAG 2.0 reference for the Cosmic authoring dashboard was found. The only accessibility-adjacent content concerns delivered-content features (AI alt text, TTS), not the editor UI.
No VPAT, ACR, Section 508 conformance statement, or accessibility page is published for Cosmic. Procurement teams requiring an accessibility conformance report would have no artifact to attach.
Cosmic ships native AI text generation with real-time streaming (March 2025), an AI Content Studio (August 2025), and the Cosmic Content Assistant for SEO-friendly long-form content. Brand Guidelines (October 2025) enforce voice/style across generated content, and the API exposes multiple top-tier models (Claude Opus/Sonnet 4.5, Gemini 3.1 Pro, GPT-5 series) with chat/message support. Held below 85 because bulk editorial workflows and prompt template libraries are less formalized than Contentful AI Actions or Sanity Create.
Native image generation via Gemini 3.1 Flash Image and DALL-E 3 (up to 4K, reference-image consistency up to 14 images), native AI video via Veo 3.1 with 720p/1080p and extend endpoint, OpenAI TTS with 9 voices, plus AI-generated alt text including bulk. Generated media is auto-stored in the bucket with alt_text, folder, and metadata fields. One of the most complete media-AI stacks in the headless CMS market — score capped shy of 90 because there is no built-in Firefly-equivalent IP-safe generator or smart focal-point cropping specifically marketed.
Cosmic Intelligence provides native 'auto translate content with AI' directly in the dashboard, executed via the same multi-model AI layer (Claude/Gemini/GPT) so brand voice is preserved via Brand Guidelines. No dedicated TMS-grade features like per-segment quality scoring, translation memory, or glossary enforcement are surfaced. Score reflects a capable in-platform MT experience that stops short of a purpose-built localization engine.
Auto alt-text generation (including bulk), AI summaries, and SEO-optimized content generation are built into Cosmic Intelligence and exposed via the AI API. The Content Assistant explicitly targets SEO-friendly blog posts. No dedicated on-page SEO scoring dashboard, schema.org markup suggestions, or title/meta-description optimizer with competitive analysis surfaced in docs — so Cosmic covers generation but not measurement.
Content Agents run on schedules (hourly/daily/weekly/monthly) or webhook triggers to autonomously create, enrich, and publish content; multi-step workflows support sequential and parallel execution with real-time logging. Bulk alt text, bulk content generation, and scheduled publishing via agents are all GA. Score held below 80 because some traditional ops features (auto-tagging taxonomies, duplicate detection, content routing rules) are not explicitly marketed.
Launched December 2025, Cosmic ships four named production agent products: Team Agents (Slack/WhatsApp/Telegram with persistent memory), Content Agents (schedule/webhook-driven content creation and publishing), Code Agents (GitHub PRs), and Computer Use Agents (visual browser automation). Content Agents can research topics via web browsing, write full posts, generate images, and publish with metadata; plans meter agents (15 on Team, 25 on Business) and agents participate in multi-step workflows with approval gates. Positions Cosmic at the agentic-first tier alongside Contentstack Agent OS; shy of 85 because the ecosystem/agent marketplace is still nascent.
Cosmic Intelligence includes media asset chat (ask questions of PDFs/spreadsheets), AI summaries, and content-model generation from descriptions, which provide some content understanding. However, there is no built-in content gap analysis, topic clustering, stale-content detection, or editorial priority dashboard marketed today. Most intelligence is reactive (chat/ask) rather than proactive scoring.
Brand Guidelines (Oct 2025) provide AI-enforced brand voice compliance across generation, and Cosmic's platform-level content policy blocks disallowed outputs (celebrities, copyright, policy violations) with SynthID watermarking on generated video. No comprehensive audit scanner for accessibility, thin content, or compliance across existing published pages is advertised — auditing is focused on what AI produces, not what exists.
Cosmic's content API is RAG-ready (clean JSON, media-aware, usable by LLM context windows) and the MCP server exposes objects for retrieval, but there is no native vector embedding store, semantic search endpoint, or hybrid ranker shipped by Cosmic. Developers can feed Cosmic content into external vector DBs but must build that layer themselves. Score reflects RAG-friendly architecture without a native semantic search product.
Cosmic does not ship an ML-driven personalization engine: no audience scoring, predictive segment assignment, next-best-content recommendations, or CDP. As a pure headless CMS it expects personalization to happen in the presentation layer or via a dedicated CDP (Segment, Hightouch, etc.). Score sits at the typical 'no AI personalization' floor for headless CMS peers.
Cosmic ships an official first-party MCP server exposing 18 tools across four categories (content CRUD, media management, schema modification, and AI text/image/video generation), now offered as a zero-install hosted endpoint at mcp.cosmicjs.com plus a local stdio npm package (@cosmicjs/mcp). Access uses bucket-scoped read/write API keys so an agent holds only the permission it needs, and Cosmic markets an 'MCP control plane' governing agent access. Raised from 80 to 84 on this new evidence of granular permission scoping and governance; short of 90 pending organization-wide multi-tenant policy tooling.
Cosmic offers extensive model choice (Claude Opus/Sonnet/Haiku, Gemini 3.1 Pro, GPT-5 series, o-series reasoning, DALL-E 3, Veo 3.1, OpenAI TTS) and markets a 'model-agnostic' content API, but that neutrality refers to external agents pointing at Cosmic — its own native AI generation is brokered and metered through Cosmic's token system. There is no BYOK configuration, custom endpoint support, or data-residency control for the built-in AI. Users pick models but cannot supply their own keys or connect fine-tuned/private deployments.
Dedicated AI endpoints for text/image/video/audio, official JavaScript SDK with streaming iterators, hosted + local MCP server for agent tooling, webhook-driven agent triggers, and four programmatically addressable agent types. Cosmic now ships Agent Skills that install its context into 16+ AI coding assistants (Cursor, Claude Code, GitHub Copilot, Codex) and markets a model-neutral, framework-agnostic content API for any agent stack. Raised from 78 to 82 on the Agent Skills and hosted-MCP evidence; short of 88 because there is still no first-party LangChain/LlamaIndex integration guide or native vector-index tooling.
AI activity logs expose prompt-level history to admins, Brand Guidelines provide centrally-enforced brand/style governance, platform-level content policies block disallowed generations (celebrities/copyright), Veo videos carry SynthID watermarks, and agent output is draft-by-default with approval gates for human-in-the-loop review. Bucket-scoped read/write keys plus the marketed 'MCP control plane' add access governance over what agents can touch. Raised from 60 to 63; held below 70 because IP indemnification for AI outputs, formal hallucination/confidence scoring, and prompt-template governance libraries are not documented.
Dashboard Usage section tracks AI token consumption with input/output split, plan-based allowances (e.g., 300K free, 2M on Team, 6M on Business), token-pack overages at $9.50/M, and per-team usage monitoring. AI Agent limits are metered per plan. Score held below 75 because prompt-effectiveness analytics, model performance dashboards, and quality-trend monitoring specific to AI output are not surfaced today.
How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.
Cosmic shows modest but clearly positive momentum this review, with gains concentrated in Platform Velocity and Compliance & Trust while Cost Efficiency, Build Simplicity, and Operational Ease hold steady. The velocity gain reflects a sustained near-weekly release cadence through mid-2026 — including Gemini 3 Pro support, Cosmic Skills, and Team Agents in Slack — while Compliance & Trust edged up on newly documented data retention and deletion practices that improve data lifecycle transparency. Practitioners should note the standout API performance improvement from serving all REST and GraphQL endpoints through Fastly's global CDN with sub-100ms cache hits, but also the downgrade on data residency, where Cosmic's four AWS regions remain a strength yet fall short of firmer sovereignty guarantees — a consideration for regulated or EU-centric deployments.
Score Changes
Cosmic sustained a near-weekly feature cadence into mid-2026: Gemini 3 Pro support, Cosmic Skills, Team Agents in Slack/WhatsApp/Telegram, Event-Triggered Agents, and Hosted MCP all shipped across early-to-mid 2026 (changelog entries through May 22 2026). Not higher because output remains concentrated in the AI-agents surface rather than spread evenly; not lower because the visible cadence rivals top headless peers.
Cosmic offers four AWS regions spanning US, EU, and APAC, which is a real strength for a small headless CMS, but there is no contractual residency guarantee and the documented automatic failover explicitly reroutes traffic to the closest available region — meaning data can cross the elected region boundary. Fastly CDN caching adds further egress, so residency is availability-driven rather than contractually controlled.
Full import/export via REST API and CLI provides genuine data portability, and the security FAQ now documents a retention approach (data kept indefinitely by default, securely disposed of or archived once no longer needed). Deletion, however, remains a manual support-ticket flow (deactivate account, then email support) rather than a self-service portal or API, and no fixed post-termination retention window is committed.
Comments feature supports inline comments on Objects and specific metafields with @mentions and notifications. Revision History tracks changes with author attribution and supports rollback (add-on on some plans). No true simultaneous multi-author editing (no CRDT/OT), no presence indicators documented — collaboration is comments + revisions rather than real-time co-editing.
All Cosmic endpoints (REST and GraphQL) are now served through the Fastly global CDN with documented sub-100ms cache-hit response times, and cache-served requests do not count toward plan request limits — a meaningful efficiency win. Request limits are documented (429 on overage, 6MB request/response ceiling, 30s timeout) and batch operations improve bulk writes. Still no sync/incremental delivery API equivalent to Contentful's, and published throughput (50M requests/month) trails tier-1 headless competitors.
Cosmic now publishes a discoverable privacy policy (previously 404) that names Cosmic JS as data controller, references the GDPR, and enumerates data-subject rights, and it offers EU data residency via AWS eu-west-1. However, no customer-facing DPA/data processing addendum, SCCs, or sub-processor list is published, so per the DPA anti-pattern the platform cannot reach the DPA-anchored band despite EU residency and a live privacy policy.
Cosmic now offers Functions (serverless functions in public beta) for custom server-side logic, alongside dashboard Extensions (below_publish_options/below_metafields), Blocks (custom React content UI), webhooks, an MCP Server, and event-triggered AI Agents that act autonomously on bucket events. The addition of server-side Functions closes much of the gap versus a full App Framework, though custom field-editor depth still trails Sanity Studio and Contentful's App Framework.
Cosmic runs a formal Partner Program connecting a global network of agencies and technology providers, with a public directory of agency partners plus tech partners. No tier-1 global SIs (Accenture/Deloitte/Valtech), no certification exams, no referenceable named implementation practices. Not higher because depth is shallow; not lower because the program is real and includes both agency and technology partners.
Cosmic has executed clearly on its 'AI-Powered Headless CMS' thesis — Hosted MCP, Event-Triggered Agents, Team Agents, and Gemini 3 Pro support all shipped in 2026, and it is actively repositioning the category ('Why Headless CMS Is the Wrong Category'). No Gartner MQ / Forrester Wave recognition in Headless CMS. Not higher because analyst validation is absent and the AI-CMS space is crowded; not lower because the AI-native narrative is differentiated and visibly delivered, not just promised.
The privacy policy adds a California Civil Code (Shine the Light) disclosure alongside GDPR, but this falls short of full CCPA/CPRA compliance and no FedRAMP, IRAP, C5, PIPEDA, LGPD, PCI-DSS, or HITRUST references exist. Coverage is effectively GDPR plus a weak California reference, keeping it just above the GDPR-only band.
Cosmic holds a stable posture across all six composite dimensions since the last review, with no movement in Capability, Platform Velocity, Cost Efficiency, Build Simplicity, Operational Ease, or Compliance & Trust. The platform's relative profile remains intact: Cost Efficiency and Build Simplicity continue to anchor its appeal, while Compliance & Trust stays the clear weak point constraining enterprise reach. Absent item-level changes, the assessment carries forward unchanged.