# Directus: an MSCL licence, a debugging only compose file, and a sqlite3 default

> Directus wraps an existing SQL database in generated REST and GraphQL APIs, a visual Studio, and a native MCP server, and it now carries an AI Assistant that acts on live data under the same role permissions as a human. The licence is source-available rather than open source, the repository's compose file is marked debugging only, and the production image boots on sqlite3 unless you tell it otherwise.

**directus/directus** — The flexible backend for all your projects 🐰 Turn your DB into a headless CMS, admin panels, or apps with a custom UI, instant APIs, auth & more.

- Repository: https://github.com/directus/directus
- Website: https://directus.com
- Stars: 37,993 · Forks: 4,957
- Language: TypeScript
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/directus-directus

## The licence is source-available, and the free offer has two thresholds

Directus is licensed under the Monospace Sustainable Core License 1.0, described in the README as a source-available license derived from the Fair Core License. The repository's license field is reported as NOASSERTION, and there is a license file at the root.

Three states are described. A free core tier is available to everyone to explore and build on Directus without a commercial license. Organizations under $5M in annual revenue and 50 employees can use it free under the Open Innovation Grant, and the note at the top of the README says to apply for that license and get a key in minutes. Organizations above those thresholds, when using advanced or enterprise features, require a commercial license, with pricing on the site.

The consequence is that the headline figure, 45M+ downloads and 500K+ projects deployed, does not tell you which tier any of those projects sit on, and the two conditions are joined by and rather than or, so crossing either one changes the answer. The grant is also a key you have to apply for, not a setting you flip. Any team whose revenue or headcount is near those numbers should read the licence itself before assuming the free tier covers them.

## There is no install command in the README at all

The acquisition paths are three, and none of them is a command you can paste. Directus Cloud provisions a fully managed project in under 90 seconds with a self-service dashboard, database, storage, auto-scaling, and a global CDN, after you select a region. The one-click deployment section covers Railway, one click with PostgreSQL, Redis, and S3-compatible storage already provisioned over Railway's private network. Everything else is a link to the documentation.

There is no npm line, no npx line, and no docker run line. The repository does carry a Dockerfile, a Dockerfile.dhi, a docker-entrypoint.cjs, and a docker-compose.yml, but the README never mentions them.

The consequence is that the two easiest paths both run someone else's infrastructure, and a self-hoster's first action is to leave the repository and read the docs. The two supported deployment options are also the two with a commercial relationship behind them, which is worth noticing before you evaluate a project whose headline features are free for small teams.

## The committed compose file declares itself debugging only

The header of docker-compose.yml is unambiguous:

```
# ONLY FOR DEBUGGING. THIS IS NOT INTENDED FOR PRODUCTION USE.
#
# For production use see the docker compose file example in the docs:
#    https://directus.com/docs/self-hosting/deploying#docker-compose-examples
```

The file spins up a copy of every supported database vendor plus Redis, RustFS for S3, Azure Blob storage, Keycloak, CockroachDB, and a fake SMTP server called MailDev. The ports are all in the 5100 range, from Postgres on 5100 through CockroachDB on 5113, with MailDev's SMTP on 1025 and its web interface on 1080. The credentials are written into the file, including postgres with the password secret, sa with Test@123 for MS SQL, secretsysuser with secretpassword for Oracle, rustfsadmin twice for RustFS, and admin with secret for Keycloak.

The consequence is that a single docker compose up from a clone gives you a working multi-database sandbox with the passwords printed in the repository, which is exactly what it is for. Two things follow if you are tempted to keep it: the credentials travel with the file, and it pins a dozen ports, so it will not collide with a database you already run locally but it will occupy them all. MailDev also needs EMAIL_FROM, EMAIL_TRANSPORT, EMAIL_SMTP_HOST, and EMAIL_SMTP_PORT set before it can receive anything.

## The production image defaults to sqlite3 and ships without npm

The Dockerfile is two stages on node 22, with the version taken from a NODE_VERSION build argument. The builder installs python3, build-base, enables corepack, and runs as the node user. It sets NODE_OPTIONS to an 8GB old space cap, then installs offline from the lockfile with --recursive --offline --frozen-lockfile, builds with a workspace concurrency of 2, and deploys only the directus package into dist. That dist package.json is then rewritten by a node one-liner that keeps only name, version, type, exports, bin, and packageManager, and three directories are created: database, extensions, and uploads.

The runtime stage upgrades the OS packages, which the comment says covers openssl, zlib, and busybox patches, and then deletes npm, npx, corepack, and the npm cache. Its environment block begins with DB_CLIENT set to sqlite3.

The consequence is a deployment that fails open rather than closed. A container started without a database configured does not crash, it comes up on a SQLite file under the database directory, so a misconfigured production environment looks healthy until someone reads the data. And because npm is stripped from the runtime image, any operational habit that assumes npm is present, installing a package or running a script at runtime, will not work inside the container.

## Node 22, pnpm 10, and dev dependencies declared as catalog references

The root package is directus-monorepo, marked private, so it is a workspace root and not something you install. The engine requirements are exact: node 22 and pnpm >=10 <11, with packageManager pinned to pnpm@10.27.0. The scripts are workspace-wide: build runs pnpm --recursive run build, test and test:coverage do the same for tests, lint is eslint --cache ., format is prettier --cache --check ., and lint:style runs stylelint across css, scss, and vue files while ignoring anything in .gitignore.

The detail worth pausing on is that every devDependency is written as catalog: rather than as a version, including eslint, prettier, typescript, rimraf, stylelint, and @changesets/cli.

The consequence is that a clone cannot be installed with npm at all, and the dependency versions are not in package.json either, they live in the workspace catalog file pnpm-workspace.yaml at the root. A contributor who updates the catalog and not the lockfile, or the other way round, is building against a set of versions that the repository never intended, and the frozen lockfile used in the image build is what catches it there rather than on a laptop.

## Twelve pnpm overrides pin the transitive tree

The overrides block in the root package.json is longer than the dependency list of most small applications. It pins @yarnpkg/shell's copy of cross-spawn to 7.0.6, tar to 7.5.22, the editorconfig and glob packages under js-beautify to 3.0.2 and 11.1.0, adm-zip to 0.6.0, js-yaml in both its 4.x and 3.x lines to 4.3.2 and 3.15.2, unplugin-yaml's yaml to 2.9.0, uuid to 11.1.1, @ai-sdk/provider-utils to 4.0.51, and @opentelemetry/core to 2.11.0.

The consequence is that the tree you run is not the tree any individual package declares, which is the normal way a monorepo responds to a vulnerable or broken transitive dependency without waiting for every upstream release. It also means anything inside the monorepo that depends on those packages inherits the pins, whether or not the maintainers intended that. None of the overrides carries a comment saying which advisory or which breakage it answers, so a reader has to infer the reason from the version numbers and from the fact that several of them are old major versions held in place.

## AI agents get your roles, and there is no separate grant for them

Directus now ships two agent surfaces. The AI Assistant is embedded in the Studio and creates content, runs translations, and triggers workflows directly. The native MCP server lets any MCP-compatible tool, named examples being Claude, Cursor, and ChatGPT, connect straight to the data. The governance claim is specific: the same access policies that apply to your team apply to AI, and agents operate under the same role based permissions as human users, with no special cases and no workarounds. The permission model underneath is policy based access control, granular down to the field level, and it is stated to cover humans and agents alike.

The repository carries the matching policy files at the root, ai_policy.md, cla.md, AGENTS.md, and a .claude directory.

The consequence is that the shared policy is both the feature and the limit. An agent cannot be granted something a human role cannot have, so a workflow that needs an agent to reach data no role can see has to be solved by widening a role, which widens it for the people in that role too. And because the assistant acts rather than suggests, creating content and triggering workflows, that role is the only boundary between a prompt and a write. There is no narrower, machine specific permission tier to fall back on.

## Conclusion

Directus fits a team that already owns its database and wants an admin interface, a generated API, and an agent surface without replacing the schema, especially one that can live entirely on its own infrastructure. It does not fit a team that needs an OSI open source licence, because the project is source-available under MSCL 1.0, and it does not fit a company above the stated revenue or headcount thresholds that expects advanced features to be free. Before you commit, read the licence text rather than the free tier summary, set every DB_CLIENT and connection variable explicitly so the image cannot fall back to its sqlite3 default, and take the production compose example from the documentation instead of the one in the repository.

## FAQ

### What is Directus used for?

It wraps any SQL database with a REST and GraphQL API layer and a visual Studio, with the APIs generated from your schema and no configuration required. Non-technical teammates work in the Studio, engineers keep control of schema and access, and Postgres, MySQL, MariaDB, MS SQL, SQLite, OracleDB, and CockroachDB are all supported.

### Is Directus CMS free?

It depends on the tier and on your size. A free core tier is open to everyone to explore and build on, organizations under $5M in annual revenue and 50 employees can use it free under the Open Innovation Grant, and organizations above those thresholds using advanced or enterprise features need a commercial license. The licence itself is MSCL 1.0, a source-available license, not an OSI open source one.

### how to install directus

The README contains no install command. Its three paths are Directus Cloud, which provisions a managed project in under 90 seconds after you pick a region, a Railway one click with PostgreSQL, Redis, and S3-compatible storage, and the documentation. The repository does contain a Dockerfile and a docker-compose.yml, but the compose file states it is only for debugging.

### what is directus built on

It is a TypeScript pnpm monorepo. The root package is directus-monorepo and is private, engines require node 22 and pnpm between 10 and 11, and the tree contains api, app, packages, and sdk directories alongside directus, with docker-entrypoint.cjs and ecosystem.config.cjs at the root.

### how to use directus api

The REST and GraphQL APIs are generated from your database schema with no configuration required, and access is controlled by policy based permissions down to the field level. An SDK lives in the sdk directory of the repository, and a native MCP server exposes the same data to MCP-compatible tools under the same role based permissions as human users.

## Sources

- [directus/directus on GitHub](https://github.com/directus/directus)
- [Issues](https://github.com/directus/directus/issues)
- [Project website](https://directus.com)
- [README](https://github.com/directus/directus/blob/main/README.md)
- [Releases](https://github.com/directus/directus/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/directus-directus
