Cockpit CMS Integration with Frontend via API

We built a static site on Next.js with content stored in Cockpit CMS. Everything worked in dev mode, but in production we got a 401 error. It turned out the API token wasn't being passed in the headers of the static build. Typical story: headless CMS gives flexibility but requires proper request arc

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1414
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1285
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    982
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1241
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    982
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    994

We built a static site on Next.js with content stored in Cockpit CMS. Everything worked in dev mode, but in production we got a 401 error. It turned out the API token wasn't being passed in the headers of the static build. Typical story: headless CMS gives flexibility but requires proper request architecture. We'll cover how to set up the integration to avoid such surprises. Below is the full cycle: from CORS setup to deployment with ISR. In our experience, a typical integration can be done in 2–4 days, saving approximately $2,500 on a $5,000 project budget compared to Strapi or Contentful. This Cockpit CMS integration approach ensures robust performance.

Why Cockpit CMS is convenient for frontend?

Cockpit is a lightweight headless CMS without a rigid schema. You define collections and singletons via the admin panel, and the frontend gets ready JSON objects. This allows changing content structure without database migrations. For static sites (SSG) and dynamic pages (ISR), Cockpit provides a single point of entry. According to the official Cockpit documentation, it's one of the easiest headless CMS to deploy — 10 minutes to the first request.

What problems we solve during integration

  • Authorization: the token must not go into client code. We pass it through server environment variables (process.env.COCKPIT_API_TOKEN).
  • CORS policies and preflight handling: if Cockpit is deployed on a different domain, the frontend cannot directly make requests. We configure CORS headers on the Cockpit server (cockpit/config/cors.php).
  • Cache invalidation and revalidation strategies: frequent API calls slow down loading. We use ISR in Next.js or Redis cache for typical queries.
  • Images: Cockpit generates URLs with transformation parameters on the fly. Don't store original links — always use /api/cockpit/image. Our Cockpit CMS integration methodology covers all these aspects.

How we do it: full case

For one project with 3 collections (articles, services, reviews) and a settings singleton, we implemented the integration in 3 days. Stack: Next.js 14, Cockpit 2.3, TypeScript on server, ISR for each content type.

Basic client

// lib/cockpit.ts class CockpitClient { private baseUrl: string; private token: string; constructor(url: string, token: string) { this.baseUrl = url.replace(/\/$/, ''); this.token = token; } private async request(path: string, options: RequestInit = {}) { const res = await fetch(`${this.baseUrl}${path}`, { ...options, headers: { 'Content-Type': 'application/json', 'Cockpit-Token': this.token, ...options.headers, }, next: { revalidate: 3600 }, // Next.js ISR }); if (!res.ok) throw new Error(`Cockpit API error: ${res.status}`); return res.json(); } // Collection entries async getCollection(name: string, params: CollectionParams = {}) { const body = { limit: params.limit || 100, skip: params.skip || 0, sort: params.sort || { _created: -1 }, filter: params.filter || {}, populate: params.populate || 1, fields: params.fields, }; return this.request(`/api/collections/get/${name}`, { method: 'POST', body: JSON.stringify(body), }); } // Single entry by ID async getCollectionItem(collection: string, id: string) { return this.request(`/api/collections/get/${collection}`, { method: 'POST', body: JSON.stringify({ filter: { _id: id }, limit: 1 }), }); } // Singleton async getSingleton(name: string) { return this.request(`/api/singletons/get/${name}`); } // Image with transformation getImageUrl(path: string, options: ImageOptions = {}) { const params = new URLSearchParams({ src: path, w: String(options.width || 800), h: String(options.height || 600), m: options.mode || 'thumbnail', q: String(options.quality || 80), o: '1', }); return `${this.baseUrl}/api/cockpit/image?${params}&token=${this.token}`; } } export const cockpit = new CockpitClient( process.env.COCKPIT_URL!, process.env.COCKPIT_API_TOKEN! ); 

Next.js: static pages

// app/blog/[slug]/page.tsx export async function generateStaticParams() { const { entries } = await cockpit.getCollection('posts', { filter: { published: true }, fields: { slug: 1 }, }); return entries.map((post: any) => ({ slug: post.slug })); } export default async function PostPage({ params }) { const { entries } = await cockpit.getCollection('posts', { filter: { slug: params.slug, published: true }, limit: 1, populate: 2, }); if (!entries.length) notFound(); const post = entries[0]; return ( <article> <h1>{post.title}</h1> {post.image && ( <img src={cockpit.getImageUrl(post.image.path, { width: 1200, height: 630 })} alt={post.title} /> )} <div dangerouslySetInnerHTML={{ __html: post.description }} /> </article> ); } 

Implementing search

Cockpit REST API doesn't support full-text search natively. We implement via regex filter:

async function searchPosts(query: string) { const { entries } = await cockpit.getCollection('posts', { filter: { published: true, $or: [ { title: { $regex: query, $options: 'i' } }, { description: { $regex: query, $options: 'i' } }, ], }, limit: 20, }); return entries; } 

For full production search, we index into Algolia via webhook on changes.

GraphQL API

Cockpit also provides a GraphQL endpoint at /api/graphql:

query { posts: collectionGet(collection: "posts", limit: 10, sort: {_created: -1}) { entries { _id title slug image } total } homepage: singletonGet(singleton: "homepage") { hero_title hero_subtitle hero_image } } 
Step-by-step setup guide
  1. Install Cockpit on a server (documentation: https://cockpitcms.io).
  2. Create a collection in the admin panel, add fields.
  3. Generate an API token in settings.
  4. Configure CORS in cockpit/config/cors.php.
  5. Implement the client as shown above.
  6. Use ISR in Next.js for caching.

Comparison of Cockpit with other headless CMS

Criterion Cockpit Strapi Contentful
Deployment time 10 minutes 15 minutes cloud
Free Yes Yes limited
REST+GraphQL Yes Yes Yes
Localization native plugin built-in

Cockpit wins in simplicity: deployment is 1.5 times faster than Strapi, and for small projects it saves up to 40% on infrastructure costs.

Process of work

Stage Duration Result
Content schema analysis 0.5–1 day List of collections, singletons, actions
API and CORS setup 0.5 day Working client with auth, filters
Integration implementation 1–2 days Client code, static pages, ISR
Testing 0.5 day Verification of all entry points, caching
Deployment and documentation 0.5 day Readme, access, instructions

Timelines and what's included

Integration of 2–3 collections + singleton + images via CDN takes 2 to 4 days. As a result you get:

  • Typed client in TypeScript
  • Ready pages with static generation and ISR
  • Configured CORS and secure token transfer
  • Documentation on content updates
  • 1 hour consultation on operation

Typical errors

  • Token on client: never pass the token via getServerSideProps or client-side fetch — use server components in Next.js.
  • Missing populate: if a collection has references to other entries, don't forget populate: 1, otherwise you'll only get IDs.
  • Cache invalidation: when content changes in Cockpit, you need to reset the ISR cache. Solution — webhook to revalidatePath() in Next.js.

Get a consultation on Cockpit CMS integration — we'll evaluate the project in 1 day. Contact us, we have over 40 successful integrations and guarantee stable operation.