Is Core enough, or do you need the SDK?
An honest answer, written so you can decide before you talk to us.
Core is free, BSL 1.1, and genuinely production-grade. It is not a crippled trial. A real class of applications ships to production on Core alone, and you should ship them that way. This page draws the honest line: where Core is enough, and where the SDK stops being a convenience and becomes the floor.
Core is enough when…
You can build and ship on free Core when your app is, in essence, a single-audience, code-defined, mostly-read application:
- One organization, one trust boundary — no per-tenant data isolation to enforce.
- Artifacts (apps, dashboards, cards, tiles, reports) are defined in code and deployed with the app.
- Dashboards show static or server-rendered content — a launchpad, KPIs you render once per request, HTML reports.
- Identity and access are handled by your own Laravel middleware — you don't need a governed, time-aware role engine.
- Your OData services expose data that every user of the app may see.
If that describes you, Core is the whole answer. Build it, ship it, and don't pay us anything. When you outgrow it, the SDK is a composer require away: your apps stay, each app's manifest switches to the SDK's base class, and config/ui5.php points at the SDK.
You need the SDK when…
The SDK is the production floor the moment your app becomes multi-user, multi-tenant or governed. These are the walls a serious build hits — what you're trying to do, why Core stops there on purpose, and what the SDK gives you instead.
| You're trying to… | Why Core stops here | What the SDK gives you |
|---|---|---|
| Know who's logged in and adapt to them | Core is stateless by design — it knows nothing about users, roles or partners | A request context that names the acting partner, the authenticated partner, the tenant and the moment |
| Keep tenants apart | Core does not model tenants | One database per tenant, a tenant identity per request, and OData reads scoped to the caller's organisation — never a tenant_id column |
| Enforce role-based access and visibility | Core has the visibility seam but ships no policy | A time-aware role engine: #[Access] gates an app, #[Act] an action, #[Read] a data set — and the same grants decide what each user sees |
| Let business users control access | Core's rules live in code | Partners and Settings apps where administrators manage partners, roles, grants, delegations and settings; the artifacts themselves stay code-defined |
| Add value helps to forms | Core ships only the static control vocabulary | Value helps bound to real data, scoped to what the user may see |
| Let modules from different vendors work together | Core serves one app at a time | LUX Weave: a module declares the concepts it owns, and others link into them without either side changing code |
| Give users a real shell | Core gives the app and the launchpad, not the operator surface | LeanShell: navigation, search, context help and dialogs around every app |
Not yet: live analytic tiles and cards, sliceable analytical tables and a SQL query layer are planned for 1.x. If those are what you need today, talk to us before you buy.
A 30-second self-check
Tick what's true of the app you're building:
- [ ] More than one tenant or organization will run on this codebase
- [ ] Different users must see different data or different apps
- [ ] Business users, not developers, should manage who may do what
- [ ] Access must be provable at a point in time — "who could approve on March 15th?"
- [ ] Modules from different teams or vendors should link into each other
- [ ] Forms need value helps over real, scoped data
- [ ] You want a turnkey shell — search, help, navigation — out of the box
Zero ticks → Core is enough. Ship on the free tier. One or two ticks → you're on the boundary; the SDK will save you from rebuilding the same plumbing — talk to us. Three or more ticks → the SDK is your production floor, not an upsell.
The split, in one sentence
Core gives you reflection-based metadata and stateless execution. The SDK gives you a database, a security engine, a shell, and the tooling to operate them in production.
Core is free because it's how you discover whether this is the right stack for you — on a real app, in your own repository, with nothing hidden. The SDK is what you pay for once that answer is yes and you're going to production with real users, real tenants, and real governance.