Strapi Remote Backup Pro In development
Back up and restore any Strapi instance without installing a plugin in it. Point the tool at a URL, sign in with admin credentials, and it does the rest — no dependency added to your CMS, no redeploy, no code running inside your production process.
Where it is up to. The engine and the CLI work: backing up a live Strapi v5 instance and restoring it into another runs end to end, verified by a round-trip test against two live instances — content, components, dynamic zones, relations, draft/published pairs and media, compared record by record. The desktop app is not implemented yet, only the local destination is wired up of the eight below, and the v4 dialect is written but has never been run against a v4 instance. Follow progress on GitHub, or get in touch if you have an instance you need backed up sooner.
Every other Strapi backup tool is a plugin
Installing one means adding a dependency to a live CMS, redeploying it, and asking someone to trust code running inside their production process. If you are an agency or a consultant backing up a client's instance, that is often not merely inconvenient — you may have no deploy access at all.
This runs entirely outside the target. It authenticates against the same admin API the Strapi admin panel itself uses, so there is nothing to install, nothing to redeploy, and nothing to uninstall afterwards. It cannot destabilise the CMS it is backing up, because it is not running inside it.
What it does
Everything, or exactly what you choose
Content entries across all collection and single types, drafts and published, every locale. The media library with its folder structure. Content-type and component schemas, captured as they stood at backup time.
Selective, by type and by depth
Pick content types, pick individual records, and choose how many relation hops to follow. Restoring a handful of articles pulls in the authors and categories they point at, so you do not end up with records referencing things that no longer exist.
A reviewable plan before anything is written
Restore writes to a live CMS, so it always produces a diff first — creates, updates, deletes, skips, plus warnings about schema drift and relations that would land unresolved. Nothing is applied without confirmation.
Eight destinations, one wired so far
Local or network folder works today. S3 and anything speaking its API (MinIO, Cloudflare R2, Wasabi, Backblaze), Azure Blob, Google Drive, Dropbox, OneDrive, SFTP and FTPS are behind a provider interface with retention rules per destination — designed and registered, but they still throw when called.
Unattended, as a background service
Designed to run recurring backups as a Windows Service or a systemd daemon, so a machine that slept through three nightly windows produces one catch-up backup on waking rather than three. Scheduling lives in the engine by decision, not in the desktop app — it ships with the app.
Portable, verifiable, encryptable
A plain .zip any operating system can open, with SHA-256 checksums per entry and optional AES-256-GCM encryption. A backup format that needs its own software to inspect fails at exactly the moment it matters most.
Two ways to run it
The command line is a first-class way to use this, not a debugging shortcut. Anything the app can do, an expert can do from a terminal — because the app drives exactly the same engine rather than reimplementing it.
The command line is what exists today: login, backup, restore, inspect and verify, for developers, CI pipelines and headless servers. A bootstrap installer stages a pinned, checksum-verified Node runtime and puts a strapi-backup command on the PATH for anyone who would rather not think about Node at all — measured working on Windows, not yet run on macOS or Linux.
The desktop app is designed and skeletoned, not built. Twenty-four C# files carry the final signatures behind an Avalonia UI, and nothing behind them runs yet. When it lands it adds a visual content-type picker with relation-depth control, the restore diff, scheduling, and secure storage of destination credentials in the operating system's own keystore, bundling its own runtime so there is nothing to install first.
Requires Node.js 20.11 or later for the CLI; the desktop app will bundle its own runtime. Neither the npm package nor the installers are published yet, so the command above will not resolve — build from the source on GitHub in the meantime.
Strapi v5 today, v4 written and unproved
Both majors are behind one dialect boundary, because they disagree about nearly everything structural — how records are identified, whether fields are nested, how draft state is expressed, how locales are linked. Which version an instance speaks is detected by probing its behaviour rather than trusting a version string that may be absent, proxied away, or simply wrong.
v5 is the one that is proved. The round trip has been run repeatedly against two live Strapi 5.52.0 instances and compared record by record. The v4 dialect is written to the same interface but has never been run against a v4 instance, so we describe it as written, not supported — if you have a v4 estate that needs backing up, talk to us and we will prove it against yours rather than ask you to trust a claim.
One limitation that will not go away: Strapi v4 identifies records only by an instance-local numeric id. Restoring a v4 archive into a different instance therefore needs an explicit identity mapping. That is a property of v4 rather than of this tool, and it is reported plainly instead of quietly producing duplicates.
It holds your credentials, so it is built accordingly
Your admin password is never stored
It is exchanged once for a session token and dropped — never written to disk, never into an archive, never into a log.
It will not lock you out
Strapi throttles admin login. A failed sign-in is never retried automatically, because an automatic retry would lock you out of your own CMS.
It is a guest on your production server
Concurrency is capped low by default and rate limiting is honoured with backoff. A backup must never be the reason a site goes down.
Destination credentials go to your OS keystore
Windows DPAPI, macOS Keychain, libsecret on Linux — never a configuration file. Profiles reference secrets rather than containing them, so they are safe to share.
MIT licensed, and the format is documented
Published under the MIT licence, free to use commercially, like the rest of our open-source work. The archive format is specified in full — so if this tool ever disappears, your backups do not become unreadable.
Unzip an archive and you get a manifest describing what is inside, your content as one JSON record per line, and your media files. No proprietary container, and nothing you need us for.
backup-2026-08-18T1430.zip ├── manifest.json always plaintext, always first ├── schemas/ content types & components, as captured ├── content/ │ └── api--article.article.ndjson one JSON record per line ├── media/ │ ├── media.ndjson filenames, folder paths, hashes │ └── files/ named by content hash, de-duplicated └── meta/ ├── locales.json └── run-report.json counts, durations, warnings
The manifest is the one entry that is never encrypted, so an archive can be listed and identified without its passphrase.
Other products
Strapi Content Sync Pro
Copy, migrate and live-sync content between Strapi environments. On the official Strapi Marketplace.
Media infrastructureRutba Media FileServer
An origin server for images and media at scale.
Migration toolingpgrecon
Oracle-to-PostgreSQL migration assessment, on PyPI.