Open-Source Low-Code and No-Code Platforms for Building Apps
Compare Appsmith, Budibase, ToolJet, Saltcorn, and BESSER by coding depth, data, workflows, deployment, licensing, and app fit.
Open-source low-code and no-code platforms let you build applications visually while connecting databases, APIs, and workflows. The best choice depends on how much code you want to write, where your data lives, which automations you need, and whether your team can operate a self-hosted service.
Quick answer
| Platform | Best fit | Coding depth | Deployment |
|---|---|---|---|
| Appsmith | Developer-built dashboards, admin panels, database GUIs, approval and support tools | Low-code: queries and JavaScript are first-class | Cloud or self-hosted |
| Budibase | Internal tools and workflow automation | Visual builder with extensible blocks and automations | Cloud or self-hosted options |
| ToolJet | Visual applications needing a built-in database, integrations, workflows, or extensions | Low-code visual configuration with extensibility | Cloud and self-hosting options vary by edition |
| Saltcorn | No-code, database-first web applications, portals, dashboards, and forms | No-code point-and-click builder | Self-hosted behind a firewall |
| BESSER | Research and model-driven application generation | Web editor with generated, extensible applications | Check current project documentation before production use |
For a developer-oriented internal application, start with Appsmith. Choose Budibase when reusable blocks and workflow automation are central. Choose ToolJet when its database, integrations, or extension marketplace match your stack. Choose Saltcorn when you want a genuinely no-code, relational, self-hosted web app. Treat BESSER as a project to evaluate for your use case rather than assuming production maturity.
What “open source” means in this category
Open source describes how software is licensed and made available; it does not make every edition, feature, or deployment interchangeable. Before selecting a platform, verify the exact repository, edition, license, and commercial terms you will run. Confirm whether the features you need—such as SSO, audit logs, role controls, or advanced connectors—are included in that edition.
Self-hosting also transfers operational work to you: infrastructure, upgrades, authentication, backups, monitoring, network access, and security response. A managed cloud plan can reduce that work, while a private deployment may be required for sensitive data or network-local systems.
Platform-by-platform comparison
Appsmith
Appsmith describes itself as “an open-source developer tool that enables the rapid development of these applications.” Its documented use cases include internal dashboards, database GUIs, admin panels, approval apps, and customer-support tools. You connect databases or APIs, assemble widgets, and add business logic with queries and JavaScript.
- Choose it when: developers need control over queries, JavaScript, data transformations, and deployment workflows.
- Data: plan around your SQL databases and API services; confirm connector support for your specific systems.
- Delivery: the product supports cloud use and self-hosting on a local machine or private server.
- Governance: the Community Edition is maintained under the Apache 2.0 license and supports Git-based version control and deployment, according to its product documentation.
Read the Appsmith documentation and verify current edition limits before committing.
Budibase
Budibase calls itself “an open-source platform for internal tools and workflow automation.” Its model combines a visual application builder with reusable Blocks and Automations that interact with data and apps.
- Choose it when: internal tools, approvals, recurring jobs, and reusable UI patterns are more important than unrestricted custom code.
- Workflow design: map triggers, actions, retries, credentials, and failure notifications before production use.
- Build-time claim: the quickstart describes a CRUD tutorial taking less than five minutes; treat that as vendor tutorial framing, not an independent benchmark.
Use the Budibase documentation to confirm current deployment and automation behavior.
ToolJet
ToolJet presents a visual app builder with drag-and-drop components, a PostgreSQL-backed ToolJet Database, workflows, integrations, and a marketplace for extensions.
- Choose it when: a built-in database plus integrations and workflow features can shorten delivery.
- Check first: edition-specific security, compliance, user limits, and self-hosting terms can change.
- Production review: test connector permissions, workflow retries, secrets handling, and backup procedures with the exact edition you plan to operate.
Consult the current ToolJet documentation before making a licensing or security decision.
Saltcorn
Saltcorn describes itself as “a platform for building database web applications without writing a single line of code.” It provides point-and-click, drag-and-drop pages, relational data management, forms, dashboards, portals, workflows, themes, plugins, PDF generation, and email features.
- Choose it when: you want a database-first application and a no-code workflow.
- Ownership: Saltcorn states that it is free and open source under the MIT license and can be self-hosted behind a firewall.
- Trade-off: validate the available extensions, authentication model, and operational tooling for your application before exposing it publicly.
BESSER
BESSER is an academic open-source low-code project focused on designing, generating, and deploying applications through a web-based editor while preserving transparency and extensibility. It is more experimental than the mature product platforms above. Review current project documentation, release activity, deployment instructions, and issue history before using it for a production workload.
How to choose: a decision framework
- Define the application boundary. Is this an internal dashboard, CRUD tool, approval flow, customer portal, or public database application?
- Inventory data sources. List SQL databases, REST or GraphQL APIs, SaaS systems, files, and identity providers. Confirm read/write operations, pagination, webhooks, and transaction requirements.
- Set the coding threshold. If JavaScript and SQL are expected, Appsmith is a natural starting point. If configuration should cover almost everything, evaluate Saltcorn or Budibase.
- Map workflows. Write down triggers, schedules, approvals, retries, idempotency, alerts, and audit requirements.
- Choose ownership. Compare vendor cloud with Docker or private-server deployment, network reachability, upgrade windows, backups, and on-call responsibility.
- Review governance. Verify license, edition, role controls, SSO, audit features, secret storage, and commercial restrictions.
- Prototype one vertical slice. Build one real screen end to end: authentication, query, validation, write operation, error state, and deployment.
Use-case recommendations
| Use case | Shortlist | Reason |
|---|---|---|
| Internal dashboards | Appsmith, Budibase, ToolJet | Strong visual components and database/API connectivity |
| CRUD administration | Appsmith, Budibase, ToolJet, Saltcorn | Forms, tables, validation, and relational data workflows |
| Approval workflows | Appsmith or Budibase | Queries or automations can model approval state and actions |
| Database-first public or private app | Saltcorn | No-code relational pages, forms, portals, and workflows |
| Research and generation | BESSER | Model-driven, transparent application generation; verify maturity |
Self-hosting checklist
- Run the platform in a version-controlled environment with pinned image or package versions.
- Place it behind TLS and restrict administrative access by network or identity policy.
- Store database credentials and API tokens in a secret manager or protected environment variables.
- Back up both application configuration and user data; perform a restore drill.
- Define an upgrade process and rollback plan before the first production release.
- Monitor CPU, memory, database latency, worker queues, failed automations, and authentication errors.
- Document outbound network access for connectors and inbound webhook endpoints.
- Review logs for sensitive values and set retention according to your requirements.
Adding screenshots to app documentation
When you publish an internal-tool runbook, screenshots make navigation and state clear. A do-it-yourself browser capture can use Playwright:
import { chromium } from 'playwright';
const browser = await chromium.launch();
const page = await browser.newPage({ viewport: { width: 1440, height: 900 } });
await page.goto('https://your-app.example.com', { waitUntil: 'networkidle' });
await page.screenshot({ path: 'app-dashboard.png', fullPage: true });
await browser.close();
For reliable captures, authenticate with a test account, wait for the dashboard’s key selector, disable animations, and avoid capturing secrets or customer data. Keep the browser and system dependencies patched, and expect cookie banners, chat widgets, bot checks, slow third-party resources, and lazy-loaded images to affect output.
Or skip the browser setup
ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP, or PDF. Cookie and consent banners are accepted and 60+ known consent platforms, newsletter popups, and chat widgets are removed before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo API documentation for the 63 capture options, including full-page and element capture, device presets, retina scale, dark mode, custom CSS and JavaScript, clicks, waits, blocked resources, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture, usage, and PDF settings. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.
ScreenshotNeo is free for 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Performance, reliability, and cost considerations
- Performance: reuse cached captures with a TTL when pages do not change frequently; wait on a specific selector instead of an unnecessarily long fixed delay; block ads, trackers, and irrelevant resource types.
- Reliability: make writes and workflow actions idempotent, record request IDs, handle connector timeouts, and test failure paths. For screenshots, distinguish a bot check, blank page, timeout, failed load, and cache hit from a valid capture.
- Cost: self-hosting replaces subscription spend with infrastructure and operator time. Estimate database, backups, monitoring, upgrades, and support. For screenshot automation, ScreenshotNeo bills only clean shots and exposes
X-Page-VerdictandX-Billedheaders. - Security: use least-privilege database users, isolate production credentials, and prevent arbitrary user input from becoming unrestricted queries or outbound requests.
Troubleshooting
The builder cannot connect to a database
Check network routing, firewall rules, TLS requirements, DNS, and whether the database allows connections from the platform’s actual runtime. Test with a least-privilege account and confirm the connector’s parameter format.
Queries work in development but fail in production
Compare environment variables, secrets, schema versions, permissions, and API allowlists. Pin configuration and run a production-like smoke test before deployment.
Automations run twice
Use an idempotency key or a state check before writes. Inspect retries and webhook delivery behavior, then record a durable execution ID.
Self-hosted upgrades break the app
Back up configuration and data, pin versions, read release notes, test in staging, and keep a rollback image or package available.
A screenshot contains a popup or cookie banner
With Playwright, dismiss it explicitly and wait for the resulting layout. With ScreenshotNeo, consent handling and removal of known consent platforms, newsletter popups, and chat widgets occur before capture; individual steps can be disabled when needed.
The screenshot is blank or times out
Check that the target is reachable without a login, wait for a stable selector, and inspect bot protection or client-side rendering. ScreenshotNeo identifies blank pages, timeouts, failed loads, and bot checks in its response status headers and does not bill those outcomes.
FAQ
Can I build an internal tool without coding?
Yes. Saltcorn is designed for database web applications without writing code, and Budibase and ToolJet support visual construction. Appsmith is better when you expect to add SQL or JavaScript.
Which platform is easiest to self-host?
There is no universal answer. Compare the current Docker or installation path, database requirements, authentication, upgrade process, backups, and documentation for your chosen edition.
Are open-source editions free of licensing concerns?
No. Check the exact license and edition, plus commercial restrictions and features reserved for paid plans.
Should I use a platform’s built-in database?
It can speed up a prototype. For an established system, consider ownership, migration, backup, reporting, and integration requirements before making it your source of truth.
Can AI agents operate these applications?
They can interact with APIs or browser interfaces when you provide suitable permissions and tools. ScreenshotNeo’s MCP server adds screenshot, page-information, and PDF-capture tools for MCP clients.
