Open source · Apache-2.0 · pre-alpha

Built for independent commerce.

Gildven is a shop system you run yourself. Each shop gets its own container and its own database file, German and EU consumer law sit in the core, and an AI assistant can take over the routine work. When money is involved, it has to ask you first.

Pre-alpha. Logins, roles, 2FA, passkeys, the audit log, backups and German/English work today. Catalog, checkout and invoices are being built.

hafenlicht-roesterei.de

Hafenlicht Rösterei

Filter coffee Nordhang

Washed Arabica, light roast

€9.90

€39.60 per kg · incl. VAT, plus shipping

Size
Grind

24 in stock

Cart 0 Subtotal: €0.00

Your cart is empty. Pick a size and add a bag.

Sketch of planned screens, drawn in HTML. Not a screenshot.

01 Why

Your shop should still be yours in ten years.

Shop platforms change prices, terms and licences. Gildven is built so that you can pack up and leave at any time, with your data in a format you can read.

Built

One shop, one database file

Every shop runs in its own container with its own SQLite file. Litestream copies it continuously, and a daily snapshot goes off site. We test restoring from them regularly.

Container shop shop.db
Off site Litestream snapshot.db
Built

No licence rug pull

Gildven Core is Apache-2.0, with a written promise never to relicense it under something more restrictive. There is no paid edition, no commission on your sales and no mandatory telemetry.

Planned · B5

Updates you can take back

An update shows up in your admin as a suggestion, with plain notes and a warning when checkout, tax or legal texts are affected. Gildven takes a snapshot before every migration. If the health check or the test purchase fails, it rolls back, database included.

  1. Check signed feed
  2. Snapshot
  3. Migrate
  4. Health check and test purchase
  5. Live

Planned · B5

An export you can read

Leaving should be easy. The export is a ZIP with JSON Lines per entity, your media and a published JSON Schema. Password hashes, 2FA secrets, API keys and payment credentials are never included.

hafenlicht-export.zip
├─ manifest.json        formatVersion 1.0.0
├─ entities/
│  ├─ product.jsonl
│  ├─ variant.jsonl
│  ├─ price_history.jsonl
│  └─ order.jsonl
├─ media/<sha256>.webp
└─ schemas/*.schema.json

02 EU law

Consumer law in the core, not in a plugin.

Most shop systems leave German and EU rules to plugins and add-on services. Gildven puts them into the catalog, the checkout and the invoices. Click through the list and try each one.

Planned · B9 § 356a BGB

Withdrawing takes one button, not an email hunt

German law requires a withdrawal function in online shops. Gildven puts it in the customer's order view and asks for no reason. The confirmation goes out right away, with the content of the withdrawal and the date and time.

Order #10431 × Filter coffee Nordhang, 500 g

This is not legal advice. Some questions are still open for a law firm and a tax adviser. They are listed on the roadmap.

03 AI over MCP

Let an assistant do the busywork. Money still needs you.

Every action in Gildven is a command with a permission and a risk class. The admin, the API and the MCP server all call the same commands, so an assistant like Claude can do what you allow and nothing more.

Claude, connected to hafenlicht-roesterei.de over MCP Planned · B3

    Try a request

    Approvals

    Nothing to approve. Requests from your assistant show up here.

    Four risk classes

    1. Read Runs directly. Customer data stays masked unless the key may see it.
    2. Write Runs directly and lands in the audit log and in the change set, so you can undo it.
    3. Destructive Shows a preview first. Runs only with a short-lived confirmation token.
    4. Money Refunds, large price changes, exports of customer data: a person approves in the admin with a passkey.
    • API keys expire after 90 days by default and never get more rights than the person who created them.
    • Customer messages and imported text reach the model wrapped and marked as untrusted.
    • No tool sends freely addressed email or fetches arbitrary URLs.

    04 For merchants

    Made for the person who packs the parcels.

    The admin is built for shop owners, not for developers. It speaks German and English and works on a phone.

    Planned · B9

    A start page called Today

    Orders to pack, withdrawals to handle, products running low. Today shows what needs you and nothing else.

    Built

    The whole team, no extra seats

    Five roles: owner, management, editorial, shipping and stock, accounting. As many accounts as you need. Two-factor login is required for everyone, and passkeys count as the second factor.

    • Owner
    • Management
    • Editorial
    • Shipping & stock
    • Accounting
    Planned · B9

    Market mode on your phone

    At a market or a pop-up you create the order on your phone and take payment by link or in cash. Whether cash sales need a certified till system is still an open legal question.

    Planned · B6

    Moving from Shopify or WooCommerce

    Import products from Shopify and WooCommerce CSV files with a preview that warns about anything that would get lost, plus redirects for your old URLs. Customers and orders come over the API where the old shop allows it.

    Planned · B9

    Bookkeeping that fits

    DATEV and CSV exports for your accountant, and invoice number ranges you define yourself, so an ERP can continue where the shop stops.

    Planned · B7

    Visitor numbers without cookies

    Page views, referrers and the path from product to order are counted on the server. No cookies, no IP stored, and the daily salt is thrown away. Revenue comes only from real orders.

    Not scheduled

    Offers via Telegram or WhatsApp

    Send new products or a market date to customers who signed up for it. Only with their explicit opt-in.

    05 For developers

    A shop server that speaks Astro.

    Gildven runs as its own service, because SQLite wants exactly one writer. Your Astro site talks to it over HTTP, and the integration proxies the Store API on your own origin so cookies stay first party.

    Planned · B7
    // astro.config.mjs
    import { defineConfig } from "astro/config";
    import gildven from "@gildven/astro";
    
    export default defineConfig({
      integrations: [
        gildven({ server: "http://shop:4321" }),
      ],
    });
    
    // src/pages/[slug].astro
    import { Price, AddToCart } from "@gildven/astro/components";
    <Price variant={variant.id} server:defer />
    <AddToCart variant={variant.id} />

    Sketch of the planned interface (ADR 0006). Package names, image names and fields are not final before 1.0.

    Store API v1
    Products, prices, stock and cart under /api/store/v1. JSON Schema and OpenAPI come from the same zod schemas as the commands.
    docker compose up
    One container for a shop with the default theme, or shop, storefront and updater side by side. Release images will be signed with cosign and come with an SBOM.
    No runtime plugins in 1.0
    Extensions use signed webhooks, the Store API or MCP. Code inside the shop process would see the whole database and break on updates.
    Apache-2.0
    Fork it, host it, sell services around it. The name has a trademark policy: "Hosting for Gildven" is fine, "Gildven Hosting" is not.

    Astro 7 · TypeScript (strictest) · SQLite with WAL · Kysely · Better Auth · zod · Litestream

    06 Compared

    How Gildven differs, with sources.

    Only statements from our research notes of 8 October 2026 made it into this table. A dash means we have not checked it. If something is wrong, tell us and we will fix it.

    Comparison of Gildven, Shopify Basic, WooCommerce, Shopware 6 Community Edition and Medusa
    GildvenShopify BasicWooCommerceShopware 6 CEMedusa
    Licence Apache-2.0 not checked GPL MIT MIT; roles and SSO under a proprietary enterprise licence
    Runs on Astro and TypeScript, one SQLite file per shop not checked WordPress PHP and Symfony Node and TypeScript with Postgres
    German consumer law In the core (planned, blocks B4 to B9) not checked Only through plugins such as Germanized Base price in the core not checked
    Withdrawal button § 356a BGB built in Planned (B9) not checked Not found in our research Not found in our research Not found in our research
    Staff accounts Five roles, unlimited accounts, 2FA required (built) None in the Basic plan not checked not checked Role management only in the enterprise licence
    Currencies Fixed prices per currency and market (planned, B4) not checked not checked not checked One currency per region
    Discount code series Planned (B8) not checked not checked not checked One code per promotion
    Moving in Shopify and WooCommerce import with preview (planned, B6) not checked not checked Migration assistant not checked
    Limits None not checked not checked Fair usage policy from €1M GMV not checked

    Sources: shopify.com/pricing (8 Oct 2026), project repositories and licence files, npm registry. Details in docs/research in the Gildven repository.

    07 Roadmap

    Eleven blocks to 1.0. Two are done.

    We plan in work blocks, not dates. Each block goes through plan, build, tests and a review by a second, independent agent before it counts as done.

    2 of 11 blocks done

    1. After B8Repository goes public as a preview, not for production
    2. After B9Public announcement
    3. After B111.0.0, once the first real customer shop runs
    1. B1 Foundation Built

      Astro and TypeScript, migrations, logins with roles, 2FA, passkeys and invitations, audit log, CSRF, rate limits, uploads, jobs, Docker, backups.

    2. B2 Rebuild Built

      Derived keys, migrations only from the CLI with a downgrade lock, route classes, actor model, German and English, error codes, settings, neutral design tokens, mobile bar.

    3. B3 Commands and MCP Planned

      Command registry, API keys, MCP server, approvals by a person, undo.

    4. B4 Markets, currencies, taxes, languages Planned

      Money and tax library, small business schemes, OSS threshold, versioned legal texts per language and country.

    5. B5 Operations and updates Planned

      Signed releases and feed, updater, snapshot before migration, rollback, export format.

    6. B6 Catalog Planned

      Products, variants, media with alt text, GPSR, base price, price history, search, import from Shopify and WooCommerce, redirects.

    7. B7 Store API, Astro and default theme Planned

      Store API v1, Astro integration, starter with docker compose, default theme with contrast check, cookieless analytics.

    8. B8 Checkout Planned

      One-page guest checkout, button solution, stock reservation, Mollie, Stripe and prepayment, discounts, shipping zones DE/AT/EU.

    9. B9 After the sale Planned

      Orders, market mode, customer database with consent records, emails, GoBD invoices, withdrawal function, DATEV export, Today.

    10. B10 Content and marketing Planned

      Page editor, popups, newsletter with double opt-in, SEO, blog, reports.

    11. B11 Hardening and 1.0 Planned

      External security review, API freeze, documentation, live demo, launch.

    08 Open source

    Built in the open, with the weak spots on the table.

    Most of the code is written by AI agents. A human reviews every change and signs it off. We think you should know that, and know who to call when something breaks.

    Built

    Gildven Core

    The open-source shop server. Apache-2.0.

    Planned

    Gildven for Astro

    Integration for existing Astro sites.

    Planned

    Gildven Cloud

    Hosted shops run by the maintainers, clearly labelled as such.

    DCO
    Every commit carries a sign-off by a human under the Developer Certificate of Origin. AI assistants can be credited, but they can't sign.
    Security
    Private reporting. We acknowledge within 72 hours, assess within 7 days and aim for 14 days on critical fixes. If a hole is being exploited, operators hear about it within 24 hours.
    Bus factor
    One maintainer today, plus a second person with emergency access to advisories and releases. We will keep saying so until there are two active maintainers.
    Criticism
    If AI-written code breaks something, label the issue ai-regression. Criticism is welcome and never a reason to block anyone.

    09 FAQ

    Questions people ask first.

    Can I run my shop on Gildven today?

    No. Gildven is pre-alpha. The foundation works, but there is no catalog, checkout or invoicing yet. The repository opens as a preview once checkout works, and 1.0 comes after the first real customer shop has been running on it.

    What does it cost?

    Gildven Core is free under Apache-2.0. There is no paid edition and no commission on sales. A hosted offer, Gildven Cloud, is planned. Setup and care for your own instance are available from Heidrich Digital in Tostedt, the maintainer's studio, and from anyone else: the licence allows it.

    Why SQLite and not Postgres?

    A small shop doesn't need a database server. One file per shop is easy to back up, restore and move. Litestream copies it continuously. The trade-off: one writing process per shop, which is why Gildven runs as its own service.

    Which payment providers?

    Planned for checkout are Mollie as the default, Stripe as an option and prepayment by bank transfer. Payment status always comes from the provider, never from a redirect.

    Does Gildven replace a lawyer or a tax adviser?

    No. It turns known duties into features, and we keep a public list of open legal questions. Before the first customer shop goes live, a law firm and a tax adviser review it.

    Does this website track me?

    No. No cookies, no analytics, no fonts or scripts from other servers. The access log does not store your IP address.