We built a static site on Next.js with content stored in Cockpit CMS. Everything worked in dev mode, but in production we got a 401 error. It turned out the API token wasn't being passed in the headers of the static build. Typical story: headless CMS gives flexibility but requires proper request architecture. We'll cover how to set up the integration to avoid such surprises. Below is the full cycle: from CORS setup to deployment with ISR. In our experience, a typical integration can be done in 2–4 days, saving approximately $2,500 on a $5,000 project budget compared to Strapi or Contentful. This Cockpit CMS integration approach ensures robust performance.
Why Cockpit CMS is convenient for frontend?
Cockpit is a lightweight headless CMS without a rigid schema. You define collections and singletons via the admin panel, and the frontend gets ready JSON objects. This allows changing content structure without database migrations. For static sites (SSG) and dynamic pages (ISR), Cockpit provides a single point of entry. According to the official Cockpit documentation, it's one of the easiest headless CMS to deploy — 10 minutes to the first request.
What problems we solve during integration
- Authorization: the token must not go into client code. We pass it through server environment variables (
process.env.COCKPIT_API_TOKEN). - CORS policies and preflight handling: if Cockpit is deployed on a different domain, the frontend cannot directly make requests. We configure CORS headers on the Cockpit server (
cockpit/config/cors.php). - Cache invalidation and revalidation strategies: frequent API calls slow down loading. We use ISR in Next.js or Redis cache for typical queries.
- Images: Cockpit generates URLs with transformation parameters on the fly. Don't store original links — always use
/api/cockpit/image. Our Cockpit CMS integration methodology covers all these aspects.
How we do it: full case
For one project with 3 collections (articles, services, reviews) and a settings singleton, we implemented the integration in 3 days. Stack: Next.js 14, Cockpit 2.3, TypeScript on server, ISR for each content type.
Basic client
// lib/cockpit.ts class CockpitClient { private baseUrl: string; private token: string; constructor(url: string, token: string) { this.baseUrl = url.replace(/\/$/, ''); this.token = token; } private async request(path: string, options: RequestInit = {}) { const res = await fetch(`${this.baseUrl}${path}`, { ...options, headers: { 'Content-Type': 'application/json', 'Cockpit-Token': this.token, ...options.headers, }, next: { revalidate: 3600 }, // Next.js ISR }); if (!res.ok) throw new Error(`Cockpit API error: ${res.status}`); return res.json(); } // Collection entries async getCollection(name: string, params: CollectionParams = {}) { const body = { limit: params.limit || 100, skip: params.skip || 0, sort: params.sort || { _created: -1 }, filter: params.filter || {}, populate: params.populate || 1, fields: params.fields, }; return this.request(`/api/collections/get/${name}`, { method: 'POST', body: JSON.stringify(body), }); } // Single entry by ID async getCollectionItem(collection: string, id: string) { return this.request(`/api/collections/get/${collection}`, { method: 'POST', body: JSON.stringify({ filter: { _id: id }, limit: 1 }), }); } // Singleton async getSingleton(name: string) { return this.request(`/api/singletons/get/${name}`); } // Image with transformation getImageUrl(path: string, options: ImageOptions = {}) { const params = new URLSearchParams({ src: path, w: String(options.width || 800), h: String(options.height || 600), m: options.mode || 'thumbnail', q: String(options.quality || 80), o: '1', }); return `${this.baseUrl}/api/cockpit/image?${params}&token=${this.token}`; } } export const cockpit = new CockpitClient( process.env.COCKPIT_URL!, process.env.COCKPIT_API_TOKEN! ); Next.js: static pages
// app/blog/[slug]/page.tsx export async function generateStaticParams() { const { entries } = await cockpit.getCollection('posts', { filter: { published: true }, fields: { slug: 1 }, }); return entries.map((post: any) => ({ slug: post.slug })); } export default async function PostPage({ params }) { const { entries } = await cockpit.getCollection('posts', { filter: { slug: params.slug, published: true }, limit: 1, populate: 2, }); if (!entries.length) notFound(); const post = entries[0]; return ( <article> <h1>{post.title}</h1> {post.image && ( <img src={cockpit.getImageUrl(post.image.path, { width: 1200, height: 630 })} alt={post.title} /> )} <div dangerouslySetInnerHTML={{ __html: post.description }} /> </article> ); } Implementing search
Cockpit REST API doesn't support full-text search natively. We implement via regex filter:
async function searchPosts(query: string) { const { entries } = await cockpit.getCollection('posts', { filter: { published: true, $or: [ { title: { $regex: query, $options: 'i' } }, { description: { $regex: query, $options: 'i' } }, ], }, limit: 20, }); return entries; } For full production search, we index into Algolia via webhook on changes.
GraphQL API
Cockpit also provides a GraphQL endpoint at /api/graphql:
query { posts: collectionGet(collection: "posts", limit: 10, sort: {_created: -1}) { entries { _id title slug image } total } homepage: singletonGet(singleton: "homepage") { hero_title hero_subtitle hero_image } } Step-by-step setup guide
- Install Cockpit on a server (documentation: https://cockpitcms.io).
- Create a collection in the admin panel, add fields.
- Generate an API token in settings.
- Configure CORS in
cockpit/config/cors.php. - Implement the client as shown above.
- Use ISR in Next.js for caching.
Comparison of Cockpit with other headless CMS
| Criterion | Cockpit | Strapi | Contentful |
|---|---|---|---|
| Deployment time | 10 minutes | 15 minutes | cloud |
| Free | Yes | Yes | limited |
| REST+GraphQL | Yes | Yes | Yes |
| Localization | native | plugin | built-in |
Cockpit wins in simplicity: deployment is 1.5 times faster than Strapi, and for small projects it saves up to 40% on infrastructure costs.
Process of work
| Stage | Duration | Result |
|---|---|---|
| Content schema analysis | 0.5–1 day | List of collections, singletons, actions |
| API and CORS setup | 0.5 day | Working client with auth, filters |
| Integration implementation | 1–2 days | Client code, static pages, ISR |
| Testing | 0.5 day | Verification of all entry points, caching |
| Deployment and documentation | 0.5 day | Readme, access, instructions |
Timelines and what's included
Integration of 2–3 collections + singleton + images via CDN takes 2 to 4 days. As a result you get:
- Typed client in TypeScript
- Ready pages with static generation and ISR
- Configured CORS and secure token transfer
- Documentation on content updates
- 1 hour consultation on operation
Typical errors
- Token on client: never pass the token via
getServerSidePropsor client-side fetch — use server components in Next.js. - Missing populate: if a collection has references to other entries, don't forget
populate: 1, otherwise you'll only get IDs. - Cache invalidation: when content changes in Cockpit, you need to reset the ISR cache. Solution — webhook to
revalidatePath()in Next.js.
Get a consultation on Cockpit CMS integration — we'll evaluate the project in 1 day. Contact us, we have over 40 successful integrations and guarantee stable operation.







