Friction

Directus

directus.io · Headless CMS

Open-source data platform and headless CMS for SQL databases.

50 items · 53 source threads · 2 source types · updated 2026-09

Compare

Pain points 36

ItemAreaSeveritySupportLast seen
Nested update permission filters stopped working in 10.3.0

A permission rule allowing edits to A only when related B is published blocks all edits after upgrading to 10.3.0, though earlier versions worked.

Affects: admins with relational permission rules

Permissions & securityCauses churn2 sources2023-08

“the update permissions for nested filters don't work since 10.3.0”

“It's new bug which was introduced in 10.3.0, previous versions works fine”

Fresh install on MSSQL fails during migrations

Bootstrapping against a cloud MSSQL database fails when a migration tries to drop a column that other objects depend on.

Affects: teams using SQL Server

Setup & onboardingCauses churn2 sources2023-07

“When the container is starting up, it immediately fails”

“When trying to set up a fresh Directus (docker) project, by connecting to a cloud MSSQL database, the installation process errors”

Version bump breaks startup with a Zod error in extension setup

After upgrading Directus, the instance crashes at startup with a Zod discriminated union error while an extension has its own zod dependency.

Affects: developers running custom extensions in Docker

Self-hosting & upgradesBlocks work2 sources2025-08

“Now I just bumped from 11.10.0 to 10.11.0 with D itself and I get this error when running:”

“New requirement with new version of argon ?”

Filtering M2M with two categories in an AND returns nothing

Querying items tagged with two categories through an _and filter returns no results although each category alone works, in both the UI and GraphQL.

Affects: users with many-to-many categories

API & developer experienceBlocks work2 sources2023-12

“but adding a second category in the AND close doesn't return anything”

“the API is returning a 500 internal server error when I try to filter items based on a self-referencing m2m-relationship”

SDK keeps refreshing expired token before public calls

After a refresh token expires, public SDK calls still attempt a token refresh and fail, leaving the site unusable until the cookie is cleared.

Affects: developers mixing logged-in and anonymous access

API & developer experienceBlocks work2 sources2022-01

“my website becomes dysfunctional and I have to manually remove the cookie in the browser preferences”

“Setting the option to use authRefresh does nothing”

SSO login ends in a 404 on Firefox

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityBlocks work2 sources2021-09
No pricing transparency for self-hosted licence, sales call required

Locked: summary and evidence are part of Sprint Pass and Pro

Pricing & plansCauses churn1 source2025-02
Custom extension crashes the whole instance on upsertOne

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsCauses churn1 source2023-09
Existing S3 assets return 403 after upgrade

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesCauses churn1 source2023-01
Schema changes wipe M2M content in SQLite

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsCauses churn1 source2022-01
Upgrade breaks login because of a missing relations column

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesCauses churn1 source2021-05
Directus described as buggy, very slow and missing features

Locked: summary and evidence are part of Sprint Pass and Pro

PerformanceCauses churn1 source2021-04
Multi-database support blocks use of Postgres-specific features

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2025-02
Fundamental validation logic still missing even in paid cloud

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2025-02
Foreign keys with different type or NOT NULL not detected on existing DB

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingBlocks work1 source2025-02
Content versions return only the delta, not relational data

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2024-06
Session auth mode lacks documentation for native apps

Locked: summary and evidence are part of Sprint Pass and Pro

DocumentationBlocks work1 source2024-05
Headless CMS plus static site rebuild adds too much complexity

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingBlocks work1 source2023-12
BSL licence contradicts open-source claims on homepage and README

Locked: summary and evidence are part of Sprint Pass and Pro

Pricing & plansBlocks work1 source2023-04
Collection field edits not shown after Docker update

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesBlocks work1 source2023-04
User logged out on every app reload

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2023-03
Schema snapshot apply leaves collections forbidden until a dummy change

Locked: summary and evidence are part of Sprint Pass and Pro

Data export & migrationBlocks work1 source2023-01
Token-based auth too complex for server-side Next.js use

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2022-07
Cannot set a permission check on create across relations

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityBlocks work1 source2022-02
GraphQL schema ignores required fields so types are wrong

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2021-12
Save as copy does not copy O2M and M2M related items

Locked: summary and evidence are part of Sprint Pass and Pro

UI & usabilityBlocks work1 source2021-11
Deleting a user who uploaded files hits a foreign key error

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2021-11
Date fields display one day earlier than stored

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2021-08
GraphQL create with existing relation demands create fields

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2021-08
CORS fails when several domains use one Directus instance

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingBlocks work1 source2021-05
Install fails with Couldn't Reach API and no useful logs

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingBlocks work1 source2019-12
Hard PHP extension dependencies complicate dev environments and CI/CD

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingBlocks work1 source2018-07
Docs do not explain how to register public users

Locked: summary and evidence are part of Sprint Pass and Pro

DocumentationBlocks work1 source2018-03
Hook payload differs depending on UI, API or CSV trigger

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceAnnoyance1 source2025-09
Slow to notice schema changes made directly in the database

Locked: summary and evidence are part of Sprint Pass and Pro

UI & usabilityAnnoyance1 source2025-02
Flow notification links to a null page

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsAnnoyance1 source2022-06

Feature requests 9

ItemAreaSeveritySupportLast seen
Support additional OAuth2 and OpenID client parameters for any provider

Twitch login through OAuth2 and OIDC does not work; the user expects the universal protocols to work with arbitrary providers or at least have supported ones documented.

Affects: admins configuring SSO

IntegrationsBlocks work2 sources2023-09

“Setting up openID and try to use custom FIRST_NAME_KEY, since it is hardcoded it does not work”

“Oauth2 and OpenID are supposed to be universal protocols... you should be able to make your own or use an unpopular one”

Conditional fields driven by values of other fields

Request to change a field's options, including hidden or visible state, based on the values of other fields.

CustomizationBlocks work2 sources2021-09

“I want to hide a field if there is a item selected in a `m2m` relation”

“The ability to change a field's options (including hidden/visible) based on conditional values from other fields”

Need a version identifier when replacing files

Replacing a file keeps the same ID and leaves no clear signal, so CDNs keep serving the old image. A version or similar value would allow cache invalidation.

Affects: teams serving assets through a CDN

IntegrationsBlocks work1 source2024-05

“This causes issues with external CDN providers where images are not updated to reflect the new changes”

Allow logging in to one account through several auth providers

The requester wants SSO usable as a convenience for login on existing accounts, with admin options to restrict registration and login methods for security.

Affects: admins configuring SSO

Permissions & securityBlocks work1 source2021-11

“I would like to support all combinations of the above (if at all possible)”

Wants a UI specialised in one database rather than a generalist

The commenter wishes for an admin UI built for a single database such as Postgres, arguing generalist tools like Directus cannot exploit database-specific strengths.

Affects: Postgres users

API & developer experienceAnnoyance1 source2024-07

“These database engines are so powerful now, but generalist UIs can never take advantage of the specializations”

Support the mysql2 database client

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesAnnoyance1 source2023-08
Generate TypeScript types from the schema endpoint

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceAnnoyance1 source2023-04
Use UUIDs for system data and default new tables

Locked: summary and evidence are part of Sprint Pass and Pro

Data export & migrationAnnoyance1 source2022-10
Allow editing the default robots.txt

Locked: summary and evidence are part of Sprint Pass and Pro

CustomizationAnnoyance1 source2022-09

Workarounds 2

ItemAreaSeveritySupportLast seen
Re-linking flow operations fails unless unlinked first

Inserting an operation between two existing flow operations raises a uniqueness error on the resolve field; unlinking, saving and then re-linking works.

Affects: users building Flows

UI & usabilityAnnoyance1 source2022-06

“If we first unlink the flow, save it and then re-link it everything works”

Static-site content changes require a manual Netlify deploy

Using Directus as a headless CMS for Jekyll sites, the user saves a post then manually triggers a deployment, noting build hooks could automate it.

Affects: developer running static sites with a headless CMS

IntegrationsAnnoyance1 source2020-08

“I wrote the post in a simple editor, save it, and manually trigger a deployment on Netlify”

Switching reasons 3

ItemAreaSeveritySupportLast seen
Agency replaced headless CMSs including Directus with custom backends

A developer found using off-the-shelf CMSs painful and now builds custom backends with sqlite and bun for tighter control and independence from CMS maintainers.

Affects: freelance web developer serving clients

API & developer experienceCauses churn1 source2026-09

“Be it Payload, Strapi, Directus. It was always painful, I've never enjoyed it”

Team moved from Directus to Django over auth complexity

After struggling with refresh-token handling, the team switched to Django, where a plain http-only secure cookie proxied through Next.js was enough.

Affects: team building a Next.js app

API & developer experienceCauses churn1 source2022-07

“We ended up switching to Django, where just an traditional http only secure cookie”

Weak migration and CI/CD story pushes user off Directus with SQLite

A user running Directus with SQLite and Litestream lacks a good migration and CI/CD approach and plans to move to something custom.

Affects: solo developer self-hosting on fly.io

Self-hosting & upgradesBlocks work1 source2022-10

“I don't have a good story regarding migration and ci/cd”