One shop, one database file
Every shop runs in its own container with its own SQLite file. Litestream copies it continuously, and a daily snapshot goes off site. We test restoring from them regularly.
Open source · Apache-2.0 · pre-alpha
Gildven is a shop system you run yourself. Each shop gets its own container and its own database file, German and EU consumer law sit in the core, and an AI assistant can take over the routine work. When money is involved, it has to ask you first.
Pre-alpha. Logins, roles, 2FA, passkeys, the audit log, backups and German/English work today. Catalog, checkout and invoices are being built.
Hafenlicht Rösterei
Filter coffee Nordhang
Washed Arabica, light roast
€9.90
24 in stock
Your cart is empty. Pick a size and add a bag.
Good morning, Mara
Here is what needs you today.
Latest orders
01 Why
Shop platforms change prices, terms and licences. Gildven is built so that you can pack up and leave at any time, with your data in a format you can read.
Every shop runs in its own container with its own SQLite file. Litestream copies it continuously, and a daily snapshot goes off site. We test restoring from them regularly.
Gildven Core is Apache-2.0, with a written promise never to relicense it under something more restrictive. There is no paid edition, no commission on your sales and no mandatory telemetry.
An update shows up in your admin as a suggestion, with plain notes and a warning when checkout, tax or legal texts are affected. Gildven takes a snapshot before every migration. If the health check or the test purchase fails, it rolls back, database included.
Leaving should be easy. The export is a ZIP with JSON Lines per entity, your media and a published JSON Schema. Password hashes, 2FA secrets, API keys and payment credentials are never included.
hafenlicht-export.zip
├─ manifest.json formatVersion 1.0.0
├─ entities/
│ ├─ product.jsonl
│ ├─ variant.jsonl
│ ├─ price_history.jsonl
│ └─ order.jsonl
├─ media/<sha256>.webp
└─ schemas/*.schema.json 02 EU law
Most shop systems leave German and EU rules to plugins and add-on services. Gildven puts them into the catalog, the checkout and the invoices. Click through the list and try each one.
German law requires a withdrawal function in online shops. Gildven puts it in the customer's order view and asks for no reason. The confirmation goes out right away, with the content of the withdrawal and the date and time.
Order #10431 × Filter coffee Nordhang, 500 g
Withdraw from order #1043? You don't need to give a reason.
Withdrawal received
Received:
A confirmation with the date and time is on its way to your inbox.
When you announce a price reduction, the reference price has to be the lowest price of the last 30 days. Gildven reads it from the price history, which only ever gets new rows. A reference price typed in by hand is never shown.
Now €7.92
Lowest price in the last 30 days: €8.90 (−11 % compared with the lowest price)
No price reduction announced.
Goods sold by weight or volume need a base price next to the price. Gildven calculates it from the quantity you enter, also in the feed for Google Merchant.
The General Product Safety Regulation asks for the manufacturer's name and postal and electronic address. If the manufacturer is outside the EU, a responsible person in the EU has to be named too. Gildven stores manufacturers as their own records and links them to each product.
All details presentMissing: responsible person in the EU
The final button must make clear that the order costs money. In Gildven that label is part of the core checkout. Themes can style the button, but they can't rename it.
Not allowed
Not allowed: Continue
Gildven
Order with obligation to payThe label stays the same in every theme.
Gapless invoice numbers in your own number ranges, invoices that can't be changed once issued, and cancellations as separate documents. Business customers can get an e-invoice as ZUGFeRD or XRechnung, which German B2B trade needs from 2027/28.
RE-2026-00142
Next numbers: RE-2026-00143, RE-2026-00144
Readable PDF for consumers
<rsm:ExchangedDocument>
<ram:ID>RE-2026-00142</ram:ID>
<ram:TypeCode>380</ram:TypeCode>
</rsm:ExchangedDocument> If you use the small business scheme, you charge no VAT and say so on the invoice. Gildven knows the domestic § 19 scheme and the EU-wide § 19a scheme and shows the thresholds as a hint. Where the rules overlap, your tax adviser decides.
| 1 × Nordhang 500 g | €18.50 |
|---|---|
| Net | €15.55 |
| VAT 19 % | €2.95 |
| Total | €18.50 |
No VAT charged under § 19 UStG.
Once your distance sales to other EU countries pass 10,000 euros a year, VAT follows the customer's country, reported through the One-Stop-Shop. Gildven counts those sales from real orders and works out tax from tax class, delivery country and date.
Standard rate 19 % DE
Below the threshold: German VAT applies.
The German accessibility law (BFSG) covers many online shops. The Gildven admin is already tested with axe and a keyboard test on every page. The default shop theme comes with a contrast check for your brand colours.
Contrast with white text 11.3 : 1
Passes WCAG AA
This is not legal advice. Some questions are still open for a law firm and a tax adviser. They are listed on the roadmap.
03 AI over MCP
Every action in Gildven is a command with a permission and a risk class. The admin, the API and the MCP server all call the same commands, so an assistant like Claude can do what you allow and nothing more.
Try a request
Approvals
Nothing to approve. Requests from your assistant show up here.
Waiting for a person
Price change via API key "Claude"
€9.90€14.90
More than 30 % change
04 For merchants
The admin is built for shop owners, not for developers. It speaks German and English and works on a phone.
Orders to pack, withdrawals to handle, products running low. Today shows what needs you and nothing else.
Five roles: owner, management, editorial, shipping and stock, accounting. As many accounts as you need. Two-factor login is required for everyone, and passkeys count as the second factor.
At a market or a pop-up you create the order on your phone and take payment by link or in cash. Whether cash sales need a certified till system is still an open legal question.
Import products from Shopify and WooCommerce CSV files with a preview that warns about anything that would get lost, plus redirects for your old URLs. Customers and orders come over the API where the old shop allows it.
DATEV and CSV exports for your accountant, and invoice number ranges you define yourself, so an ERP can continue where the shop stops.
Page views, referrers and the path from product to order are counted on the server. No cookies, no IP stored, and the daily salt is thrown away. Revenue comes only from real orders.
Send new products or a market date to customers who signed up for it. Only with their explicit opt-in.
05 For developers
Gildven runs as its own service, because SQLite wants exactly one writer. Your Astro site talks to it over HTTP, and the integration proxies the Store API on your own origin so cookies stay first party.
// astro.config.mjs
import { defineConfig } from "astro/config";
import gildven from "@gildven/astro";
export default defineConfig({
integrations: [
gildven({ server: "http://shop:4321" }),
],
});
// src/pages/[slug].astro
import { Price, AddToCart } from "@gildven/astro/components";
<Price variant={variant.id} server:defer />
<AddToCart variant={variant.id} /> # compose.yaml
services:
shop:
image: ghcr.io/<org>/gildven:0.x
env_file: .env
volumes:
- shop-data:/data
volumes:
shop-data:
$ docker compose up -d
$ docker compose exec shop node --experimental-strip-types scripts/cli.ts invite-owner you@example.com $ curl https://shop.example/api/store/v1/products?locale=de&market=eu
{
"items": [{
"id": "0192f3c4-…",
"title": "Filterkaffee Nordhang",
"price": { "amount": 990, "currency": "EUR" },
"basePrice": { "amount": 3960, "per": "1 kg" },
"lowest30d": { "amount": 890 }
}],
"nextCursor": null
} Sketch of the planned interface (ADR 0006). Package names, image names and fields are not final before 1.0.
Astro 7 · TypeScript (strictest) · SQLite with WAL · Kysely · Better Auth · zod · Litestream
06 Compared
Only statements from our research notes of 8 October 2026 made it into this table. A dash means we have not checked it. If something is wrong, tell us and we will fix it.
| Gildven | Shopify Basic | WooCommerce | Shopware 6 CE | Medusa | |
|---|---|---|---|---|---|
| Licence | Apache-2.0 | not checked | GPL | MIT | MIT; roles and SSO under a proprietary enterprise licence |
| Runs on | Astro and TypeScript, one SQLite file per shop | not checked | WordPress | PHP and Symfony | Node and TypeScript with Postgres |
| German consumer law | In the core (planned, blocks B4 to B9) | not checked | Only through plugins such as Germanized | Base price in the core | not checked |
| Withdrawal button § 356a BGB built in | Planned (B9) | not checked | Not found in our research | Not found in our research | Not found in our research |
| Staff accounts | Five roles, unlimited accounts, 2FA required (built) | None in the Basic plan | not checked | not checked | Role management only in the enterprise licence |
| Currencies | Fixed prices per currency and market (planned, B4) | not checked | not checked | not checked | One currency per region |
| Discount code series | Planned (B8) | not checked | not checked | not checked | One code per promotion |
| Moving in | Shopify and WooCommerce import with preview (planned, B6) | not checked | not checked | Migration assistant | not checked |
| Limits | None | not checked | not checked | Fair usage policy from €1M GMV | not checked |
Sources: shopify.com/pricing (8 Oct 2026), project repositories and licence files, npm registry. Details in docs/research in the Gildven repository.
07 Roadmap
We plan in work blocks, not dates. Each block goes through plan, build, tests and a review by a second, independent agent before it counts as done.
2 of 11 blocks done
Astro and TypeScript, migrations, logins with roles, 2FA, passkeys and invitations, audit log, CSRF, rate limits, uploads, jobs, Docker, backups.
Derived keys, migrations only from the CLI with a downgrade lock, route classes, actor model, German and English, error codes, settings, neutral design tokens, mobile bar.
Command registry, API keys, MCP server, approvals by a person, undo.
Money and tax library, small business schemes, OSS threshold, versioned legal texts per language and country.
Signed releases and feed, updater, snapshot before migration, rollback, export format.
Products, variants, media with alt text, GPSR, base price, price history, search, import from Shopify and WooCommerce, redirects.
Store API v1, Astro integration, starter with docker compose, default theme with contrast check, cookieless analytics.
One-page guest checkout, button solution, stock reservation, Mollie, Stripe and prepayment, discounts, shipping zones DE/AT/EU.
Orders, market mode, customer database with consent records, emails, GoBD invoices, withdrawal function, DATEV export, Today.
Page editor, popups, newsletter with double opt-in, SEO, blog, reports.
External security review, API freeze, documentation, live demo, launch.
08 Open source
Most of the code is written by AI agents. A human reviews every change and signs it off. We think you should know that, and know who to call when something breaks.
The open-source shop server. Apache-2.0.
Integration for existing Astro sites.
Hosted shops run by the maintainers, clearly labelled as such.
09 FAQ
No. Gildven is pre-alpha. The foundation works, but there is no catalog, checkout or invoicing yet. The repository opens as a preview once checkout works, and 1.0 comes after the first real customer shop has been running on it.
Gildven Core is free under Apache-2.0. There is no paid edition and no commission on sales. A hosted offer, Gildven Cloud, is planned. Setup and care for your own instance are available from Heidrich Digital in Tostedt, the maintainer's studio, and from anyone else: the licence allows it.
A small shop doesn't need a database server. One file per shop is easy to back up, restore and move. Litestream copies it continuously. The trade-off: one writing process per shop, which is why Gildven runs as its own service.
Planned for checkout are Mollie as the default, Stripe as an option and prepayment by bank transfer. Payment status always comes from the provider, never from a redirect.
No. It turns known duties into features, and we keep a public list of open legal questions. Before the first customer shop goes live, a law firm and a tax adviser review it.
No. No cookies, no analytics, no fonts or scripts from other servers. The access log does not store your IP address.