Now booking enterprise content platform builds for 2026. Contact us

CMS comparison Keystone vs Sitecore

Keystone vs Sitecore

Keystone is an open-source headless CMS that you host yourself. Sitecore is a closed-source enterprise DXP that runs on the vendor's cloud. The table below sets them side by side on 28 features. They get a different status on 21.

  • Keystone Headless · Open source · 6 of 28 built in
  • Sitecore Enterprise DXP · Closed source · 22 of 28 built in

Sources checked: Keystone on 29 Sept 2026, Sitecore on 29 Sept 2026. Plans and releases can change after those dates.

WAYF is an official Payload partner and top contributor. Every platform in the table is classified by the same published definitions, and each answer lists the vendor page it came from.


Feature comparison

Built inPaid tierPlugin or add-onLimitedNot available
Keystone vs Sitecore feature comparison. Columns are the two platforms. Rows are features, grouped by area.
Platform
Keystone Headless
Sitecore Enterprise DXP
Overview
What it is Open-source Node.js headless CMS from Thinkmill that generates a GraphQL API and an admin UI from a TypeScript schema.Sitecore's SaaS digital experience platform, formerly XM Cloud. Sitecore hosts the CMS. Sites render in a separate front-end app.
Edition compared The product and release each column describes. Keystone 6, open source, from the @keystone-6/core package Version 8.1.0, released 31 Aug 2026 SitecoreAI, formerly XM Cloud, Sitecore's current flagship SaaS platform SaaS, continuously updated
Vendor Thinkmill keystonejs.com Sitecore sitecore.com
Licence Open source MIT Closed source Proprietary
Hosting Self-hosting No vendor cloud No managed hosting. Thinkmill offers enterprise support. No self-hosting Vendor cloud SitecoreAI is SaaS only. Self-hosting needs Sitecore XP 10.5, a separate product.
Built with TypeScript, Node.js, GraphQL, Prisma, Next.js for the admin UI.NET, Next.js Content SDK
Database PostgreSQL, MySQL, SQLiteManaged by Sitecore
Pricing Public list prices only. Hosting and implementation are extra everywhere. Free to start Free and open source. Enterprise support from Thinkmill on request. No free option Pricing on request.
Content modelling
Content model in code You define content types in files in your repository, review them like any other code and apply them from there. Imperative migration scripts alone count as limited. Built in Lists and fields are TypeScript config. 4 Built in Templates serialize to files in the repo with Sitecore Content Serialization. 2
Content model in the UI Admins can create and change content types and fields in the admin interface without writing code. Not available Built in Templates are items edited in the Content Editor.
Reusable blocks Editors compose pages from reusable, typed components or blocks, and can reorder them. Built in Component blocks inside the document field. 8 Built in Page builder with reusable components.
Localization Editors translate content per locale inside the CMS, by field or by entry, without a separate site for each language. Not available No locale support documented. Model translations yourself. 12 Built in Language versions per item.
Image transformations The CMS resizes, crops or converts images on request, through URL parameters or generated sizes, with no external service. Not available Image field stores originals. The Cloudinary field hands resizing to Cloudinary. 711 Built in Experience Edge media CDN resizes images with query string parameters. 3
APIs and delivery
REST API A documented REST or JSON HTTP API returns content. Not available GraphQL only. Custom REST routes through extendExpressApp. 4 Built in Content Items REST API since September 2026. Delivery through Experience Edge is GraphQL. 4
GraphQL API The vendor or an official module provides a GraphQL API for content. Built in Built in Experience Edge delivery API. 5
Webhooks The CMS can call an external URL when content is created, changed or published. Not available No webhook settings. Call URLs from hooks in code. 10 Built in Authoring webhooks and Experience Edge publish webhooks. 65
Renders the website The CMS itself renders and serves the public pages through themes or templates. Headless-only products answer no. Not available Not available Headless. Sites render in a separate app, with built-in Vercel and Netlify integrations. 7
Editorial workflow
Drafts Editors save changes as a draft and publish them later. The live version stays untouched until then. Not available Built in Saved changes stay unpublished until pushed to Experience Edge. 11
Scheduled publishing An editor can set a future date and time for content to publish or unpublish. Not available Limited Publishing restrictions set availability dates. A publish must still run on the date. 89
Version history The CMS keeps earlier versions of an entry, and editors can compare or restore them. Not available Built in Numbered item versions.
Preview Editors can see unpublished content rendered as it will appear on the site before publishing. Not available Built in
Visual editing Editors can click on the rendered page and edit content in place or in a side panel next to it. Not available Built in Page builder.
Approval workflows Content moves through review stages you configure, such as draft, review and approved, with permissions per stage. Not available Built in Item workflows with states and commands. 6
Content releases Editors group changes across several entries and publish them together as one release. Not available Not available No release bundles. Publishing jobs cover items, subitems and related items. 11
Real-time co-editing Two or more editors can work on the same entry at once and see each other's changes live. Not available Limited Page builder saves concurrent edits per field. Others get a reload prompt. No live updates. 10
Access and governance
Custom roles Admins define their own roles with granular permissions instead of picking from a fixed set. Limited Roles are access-control functions written in code. No role editor in the admin. 5 Built in Roles with item access rights. 12
Field-level permissions Admins can restrict access to single fields, on top of content types and entries. Built in Field-level access control. 5 Built in Field read and field write access rights. 12
Single sign-on Editors can sign in through SAML or OpenID Connect against a company identity provider. Not available The auth package covers password login. SSO means custom session code. 6 Built in SAML or OIDC through the Sitecore Cloud Portal. 13
Audit log The CMS logs who changed what and when across the whole installation, and admins can review the log. Not available Limited Common Audit Log covers only the Cloud Portal and leaves out SitecoreAI content. Item actions show in CM logs. 1415
Platform and extensibility
Multiple sites One installation or account can manage several separate websites or brands with shared users. Not available Built in Site collections with shared content.
Extensible admin UI Developers can add their own components, views or fields to the editing interface. Built in Custom admin pages, navigation and field views. 9 Built in Marketplace apps add custom fields, panels and dashboard widgets. 17
Plugin marketplace The vendor runs an official directory or marketplace of installable extensions. Not available Built in Sitecore Marketplace. 16
Form builder Editors can build and publish forms and collect submissions without code. Not available Built in Built-in Forms with webhook submission handling. 18
Site member accounts The platform handles sign-up and login for public site users or members, separate from editors. Built in createAuth works on any list, including site users. 6 Not available Developers have to build visitor login in the front-end app.
AI writing assistant A first-party AI feature in the editing interface generates, rewrites or translates content. Not available Built in Content, variant and translation assistants. Brand kits need Stream Premium. 19
Official MCP server The vendor publishes a Model Context Protocol server so AI agents can read or write content. Not available Built in Sitecore Marketer MCP server. 20

Considering more platforms? Compare Keystone and Sitecore with the rest of your shortlist in the CMS comparison tool.


Where they differ

Keystone and Sitecore get a different status on 21 of the 28 features and the same status on 7. Keystone has 6 built in on its baseline edition, Sitecore has 22. Two matching statuses can still name different paid tiers or limits, so read the notes in the table before treating a row as equal.

Licence
Keystone is open source (MIT). Sitecore is closed source (Proprietary).
Self-hosting
Keystone can be self-hosted. Sitecore cannot be self-hosted.
Vendor cloud
Keystone has no vendor-run cloud. Sitecore has a vendor-run cloud.
Free option
Keystone has a free option. Sitecore has no free option.

Built in on Keystone, a different answer on Sitecore 1

  • Site member accounts Keystone: Built in. Sitecore: Not available.

Built in on Sitecore, a different answer on Keystone 17

  • Content model in the UI Keystone: Not available. Sitecore: Built in.
  • Localization Keystone: Not available. Sitecore: Built in.
  • Image transformations Keystone: Not available. Sitecore: Built in.
  • REST API Keystone: Not available. Sitecore: Built in.
  • Webhooks Keystone: Not available. Sitecore: Built in.
  • Drafts Keystone: Not available. Sitecore: Built in.
  • Version history Keystone: Not available. Sitecore: Built in.
  • Preview Keystone: Not available. Sitecore: Built in.
  • Visual editing Keystone: Not available. Sitecore: Built in.
  • Approval workflows Keystone: Not available. Sitecore: Built in.
  • Custom roles Keystone: Limited. Sitecore: Built in.
  • Single sign-on Keystone: Not available. Sitecore: Built in.
  • Multiple sites Keystone: Not available. Sitecore: Built in.
  • Plugin marketplace Keystone: Not available. Sitecore: Built in.
  • Form builder Keystone: Not available. Sitecore: Built in.
  • AI writing assistant Keystone: Not available. Sitecore: Built in.
  • Official MCP server Keystone: Not available. Sitecore: Built in.

Built in on neither, with different answers 3

  • Scheduled publishing Keystone: Not available. Sitecore: Limited.
  • Real-time co-editing Keystone: Not available. Sitecore: Limited.
  • Audit log Keystone: Not available. Sitecore: Limited.

More comparisons

Full write-ups with worked examples and costs: Sitecore vs Payload.

Open the CMS comparison tool to put up to six platforms in one table.


We're booking content platform
engagements for 2026.

Twenty-five minutes to walk through the work and decide if we're the right team for it. Scoping and a fixed price come after.