Admin that respects your eyes
Dark, fast, htmx-driven. Built for long editing sessions, not dashboard cosplay.
Forma
Dark admin. Pages, blog, podcasts. Real SEO. Connect Grok or another compatible AI with one URL — no shell, no copied token. One SQLite file you can move anywhere.
Portability, not theater
The old pitch was “no database.” The honest one is better: Forma keeps everything in a single SQLite file. Fast enough to feel local. Small enough to copy. Serious enough to run a real site.
formax-site-*.zip
No connection pool, no Redis ritual. PHP + SQLite on cheap hosting still feels snappy.
Drop the folder on Apache or Nginx. Log in. Change the damn password. Build.
Move hosts with a zip: database, uploads, and a versioned manifest future Forma can migrate.
One admin. CSRF. Rate-limited login. File validation. Fewer moving parts, fewer ways to get wrecked.
Why Forma kicks ass
Same spirit as the original Forma site — SQLite core, htmx admin, agent-ready.
Dark, fast, htmx-driven. Built for long editing sessions, not dashboard cosplay.
Markdown, HTML, or Twig. Own the markup. Ship the layout you actually want.
Markdown-first posts, clean RSS/JSON feeds, publish dates that mean something.
Episodes, show notes, iTunes-compatible feed. Optional $39 unlock — you host the audio; Forma handles the XML.
Reusable blocks with shortcodes. Write once, drop everywhere — copy-paste is for suckers.
Upload, preview, link. Images and audio without a plugin bazaar.
robots.txt, sitemap (with images), Open Graph, JSON-LD (FAQ and custom schema included), redirects, per-page health checks right in the editor — automatic when you let it.
Paste one MCP URL into Grok or a compatible chatbot, sign in, and approve. Cursor and scripts can use scoped API keys. No SSH theater.
Chatbots get short-lived OAuth access without delete, accounts, imports, backups, or core updates. Forma protects one last-known-good site before the first AI edit.
See it in the product
No theme store. No page-builder prison. Forma assumes you’re willing to hack a little — and rewards you for it.
Download on GitHub Source on GitHub Buy Podcast — $39 CMS is free. Podcast is optional.
Sections load fast. Editors use real code tools. Settings for SEO, hosting, cache, access, and versioned backups live where you’d look for them.
Distraction-light editing, meta fields that matter, SERP / OG previews so you see what Google and social will see before you publish.
Remote MCP clients discover Forma’s OAuth flow automatically. You sign in, review the exact Site editor permissions, and approve or cancel. API keys remain available for Cursor and scripts.
Get started in minutes
No MySQL wizard. No Composer rabbit hole. PHP 8.1+, SQLite, and a web root.
Clone from GitHub, or unzip the latest Release (not main). Keep database/ and uploads/ writable. Later versions: Settings → Update. DreamHost notes are in the docs.
git clone https://github.com/Alta-forma/forma-cms.git chmod -R 775 database uploads feeds
Apache with mod_rewrite, or Nginx try_files. Local hack:
php -S localhost:8787 router.php
Open /admin. Default credentials ship for first boot — change them immediately in Settings → Access. A red bar stays on every admin screen until you do. Later CMS versions: Settings → Update (GitHub Releases only — never main).
Edit the home page, wire SEO, upload a favicon, hit Backup for a site package before you get brave.
From the blog
CMS craft, agents, SEO, and portability — written like we build. Subscribe via RSS or JSON Feed.

Paste one URL, sign in, and approve. Forma now connects to Grok and compatible AI tools through OAuth instead of hand-copied API keys.

Practical prompts for auditing pages, improving SEO, drafting posts, updating media, and safely undoing AI edits in Forma.

A high-level look at Forma’s security strategy: OAuth, narrow scopes, short-lived credentials, owner consent, revocation, and rollback.
Self-hosted PHP + SQLite. Dark admin. Built-in SEO. OAuth-powered AI editing with rollback. One file you can move anywhere — this is the live product. Podcast is a $39 unlock.