What Insites Can Do

Last updated on October 10, 2026.

A capability list: sign-in, roles, pages and JSON endpoints, data, email, files, languages, security, deploying and AI, with links.

This page lists what Insites can do, area by area. Each row says one of two things:

  • Yes: Insites has it as a single tag, setting, file type or command.
  • Built from parts: there is no single switch, but you build it from parts Insites has, such as a table, a query, a page and an email. The linked page shows how.

Moving an existing site? Start with Migrating to Insites.

Sign-In and Accounts

CapabilityAnswerHow
Users with a sign-up form and a passwordYesCreating a Sign-Up Form
Sign a person in from your own code, with a session time limit (the sign_in tag with timeout_in_minutes)YesSigning In a User Manually
Sign-in by emailed link, with no passwordBuilt from parts: a short-lived token, a random value stored in a table, an email, and the sign_in tagPasswordless Sign-In
Sign-in by an emailed 6-digit code that expiresBuilt from parts: a code stored as a hash with an expiry time, an email, and the sign_in tagPasswordless Sign-In
An answer that never reveals whether an address has an accountBuilt from parts: the page gives the same answer for every addressPasswordless Sign-In
Password resetYesResetting the Password of an Authenticated User
Sign outYesLogging Out an Authenticated User
Extra fields on every user, and user profilesYesCreating a User Profile
Sign-in with a JWT tokenYesAuthenticating a User with a JWT Token
An email allow-list: only listed addresses may sign inBuilt from parts: a table of allowed addresses, checked before a link or code is sentEmail Allow-List

Roles and Permissions

CapabilityAnswerHow
Protect a page or a form with a rule (an authorization policy)YesAdding an Authorization Policy
Roles such as admin, stored on the userBuilt from parts: a roles field on the user, read by an authorization policyAdmin Role Instead of a Shared Password
An admin area for signed-in admins, in place of one shared passwordBuilt from parts: an admin role and a policy on every admin pageAdmin Role Instead of a Shared Password
Protect a whole page by roleYesAssociating an Authorization Policy with a Page
Show or hide parts of a page by roleBuilt from parts: a role check inside the pageAdmin Role Instead of a Shared Password

Note: A page with no policy is public. There is no default policy that a page inherits.

Pages and Routing

CapabilityAnswerHow
A page at any address you choose, set by its slugYesPages
A JSON endpoint at a clean address, such as /api/auth/request-code, with no .json on the end (format: json in the page front matter)YesLogic Engine: API endpoint rules
GET, POST, PUT and DELETE endpoints, one method per pageYesPages
Layouts and reusable partialsYesReusing Code Across Multiple Pages
RedirectsYesRedirects
Custom error pagesYesCustom Error Pages
A project layout: app/ for your site, modules/<name>/ for code you reuseYesCodebase Introduction

Data and Imports

CapabilityAnswerHow
Your own tables, defined in app/schema/YesDatabase Fields and Tables
Read and write rows with GraphQLYesQuerying Your Databases
Search across rowsYesSearch Introduction
Import a JSON file of data with the CLI (insites-cli data import)YesImporting JSON or CSV Data
Import a CSV file exported from another systemBuilt from parts: convert it to the import JSON first, then import itImporting JSON or CSV Data
Export dataYesExporting Data
Seed or change data when you deploy (migrations)YesMigrating Data
Move a whole site from another platformYes, for the sources the Insites Migration Tool readsMigrating to Insites
Run work later or in the backgroundYesBackground Jobs

Email and SMS

CapabilityAnswerHow
Email notifications from templatesYesCreating an Email Notification
Email layoutsYesUsing Email Layouts
Email attachmentsYesAdding Attachments to an Email Notification
SMS notificationsYesCreating an SMS Notification
Calls to outside services (API call notifications)YesCreating an API Call Notification
Safe testing: a staging instance sends email only to the test recipients you setYesStaging vs. Production
Emails in the person's languageBuilt from parts: one template per language, chosen by the language the person pickedMulti-Language Sites

Files

CapabilityAnswerHow
Static files (images, fonts, styles, scripts) served from a CDNYesUsing Static Assets on Pages
File uploads stored on a row, public or privateYesUploads
Generate a PDFYesGenerating and Uploading a PDF

Note: An upload field with no acl setting makes its files public. Set acl: private for files only signed-in people may open.

Languages

CapabilityAnswerHow
Translation files, one per language, in app/translations/YesTranslations Introduction
Show text in the visitor's language with the t filterYesMulti-Language Sites
Let the visitor choose a language (the language parameter, kept in the session)YesMulti-Language Sites
Send the visitor's language to the server and store it, so emails matchBuilt from parts: a language field on the user or the request rowMulti-Language Sites
Dates in each language's formatYesDate Format

User-facing text does not have to be hardcoded in English.

Security

CapabilityAnswerHow
Read the visitor's IP addressYes: read context.headers.HTTP_X_REAL_IP, which is the same as the first entry of the X-Forwarded-For header. The last entry is an internal address, not the visitor.Rate Limiting by IP
Limit requests per IP addressBuilt from parts: a table that counts requests per address and time windowRate Limiting by IP
Block an IP address after repeated failuresBuilt from parts: the same counter, checked before the request is handledRate Limiting by IP
Lock an account or a form after a number of failed attemptsBuilt from parts: a failed-attempt counter, cleared on successRate Limiting by IP
Spam protection on forms: reCAPTCHA v2, reCAPTCHA v3 or hCaptcha (the spam_protection tag)YesForm Configuration Options
Hash, sign and encrypt values (digest, compute_hmac, encrypt, decrypt)YesFilters: Insites
Secrets kept out of your code (constants)YesInsites CLI Tool Commands and Options

Note: Insites has no built-in rate limit or lockout for your own sign-in pages. Build one from the parts above.

Deploying

CapabilityAnswerHow
Separate staging and production instancesYesStaging vs. Production
Deploy from the command line (insites-cli deploy)YesInsites CLI Tool Commands and Options
Deploy on every push to GitHub, with history and revert (the Insites GitHub App)YesInsites GitHub App
Read your instance logsYesCreating Application Logs
Custom domains with SSLYes, on production instancesInstance Domains

Note: A full insites-cli deploy removes files from the instance that are missing from your local build. Add --partial-deploy to keep them.

AI

CapabilityAnswerHow
Build and deploy with any AI assistant that supports remote MCP servers (Insites CloudShell)YesGetting Set Up with AI
Let your AI deploy, upload files, read logs and set environment variablesYesCloudShell Tools
Public rules that teach your AI how Insites works (the Insites Logic Engine)YesInsites Logic Engine
Have a suggestion for this page?

Didn't quite find what you are looking for or have feedback on how we can make the content better then we would love to hear from you. Please provide us feedback and we will get back to you shortly.