What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
Architects
This guide covers integration patterns for Agility CMS, including frontend frameworks, third-party services, and custom integrations.
This guide covers integration patterns for Agility CMS, including frontend frameworks, third-party services, and custom integrations.
SDK: @agility/nextjs
Features:
Pattern:
import { getContentItem } from "@/lib/cms/getContentItem"
const { fields } = await getContentItem<IPost>({
contentID: 204,
languageCode: "en-us"
})
Agility works with any framework that can make HTTP requests. For new projects we recommend Next.js, or ASP.NET Core with the .NET starter for .NET teams. Other frameworks can use the JavaScript SDK (@agility/content-fetch), the Content Fetch API directly, or the content sync SDK (@agility/content-sync) for a local content cache. To build with the framework of your choice, see Vibe Coding with Agility.
Pattern:
Example:
GET /{instance-guid}/fetch/{locale}/list/posts?take=10&skip=0
Pattern:
Example:
query {
contentList(referenceName: "posts") {
items {
contentID
fields {
heading
slug
}
}
}
}
Pattern:
Example:
const sdk = await getAgilitySDK()
const items = await sdk.getContentList({ referenceName: "posts" })
PostHog:
Google Analytics:
Algolia:
Custom Search:
Azure OpenAI:
Custom AI:
Setup:
Event categories:
Delivery guarantees:
webhook-id header as an idempotency key⚠️ There is no webhook "security key."
AGILITY_SECURITY_KEYis the instance Security Key, used for preview key validation. Agility never sends it with a webhook, and custom headers cannot be configured. Instead, tick Enable secure delivery on the webhook: each webhook gets its ownwhsec_signing secret, and Agility signs every request with it. Agility implements the open Standard Webhooks spec, so you verify with an off-the-shelf library. See Verifying Signed Webhooks.
import { Webhook } from 'standardwebhooks'
export async function POST(request: Request) {
// Read the RAW body - re-serializing the JSON breaks verification
const raw = await request.text()
// The webhook's whsec_... signing secret, from Enable secure delivery
const wh = new Webhook(process.env.AGILITY_WEBHOOK_SIGNING_SECRET!)
try {
wh.verify(raw, {
"webhook-id": request.headers.get("webhook-id")!,
"webhook-timestamp": request.headers.get("webhook-timestamp")!,
"webhook-signature": request.headers.get("webhook-signature")!,
})
} catch {
return Response.json({ error: "Invalid signature" }, { status: 401 })
}
const event = JSON.parse(raw)
// Process event (idempotently - key off the webhook-id header)
// Revalidate cache
return Response.json({ ok: true })
}
Use each webhook's History view in Settings → Webhooks to see delivery attempts, response codes and errors when debugging an integration.
Create custom API routes for:
Use middleware for: