One API key — articles land as real pages in your flat-file site.
Grav keeps a page as a folder with one Markdown file in it, and the API plugin that ships with Grav 2.0 lets DraftSEO create exactly that. You install the plugin once, generate an API key in your own Grav admin, and paste it here. Articles then appear under your blog page as ordinary Grav pages, rendered by your own theme, with each article’s pictures sitting in that article’s folder the way Grav expects. There is nothing to map: a Grav page is a title, some frontmatter and a body on every site.
| Connection | Your site address + an API key — Admin → your own user profile → API Keys |
|---|---|
| Grav version | Grav 2.0 and newer — the API plugin does not exist for Grav 1.7, and 1.7 has no in-place upgrade |
| API plugin | Installed once, by you — bin/gpm install api, or Admin → Plugins → Add |
| Image hosting | The article’s own page folder — pushed onto your server, never hot-linked |
| Body | Written as HTML, processing off — so your Markdown and Twig settings cannot change the article |
| Publish modes | Auto · draft · scheduled |
Who does what
Nothing, after the one-time plugin install and key. Pages appear under your blog and your theme renders them like any other. Want to read them first? Send them unpublished and flip published: true yourself.
No field mapping — a Grav page has the same shape on every site.
Setup
Grav 2.0 arrived in June 2026 and is the first version with a REST API. On Grav 1.7 there is no API plugin to install, so no tool can publish into it — and 1.7 has no in-place upgrade, so moving up is real work rather than a button. DraftSEO checks your version before anything else and tells you plainly if this is where you are.
~1 minute
Admin → Plugins → Add → API, or bin/gpm install api on the server. It is a first-party Grav plugin, not something we wrote. Grav 2.0 also wants PHP 8.3 and a current Login plugin, which the same check reports on.
~2 minutes
In your Grav admin open your own user profile and find API Keys, then create one named DraftSEO. Grav hashes it and shows it exactly once, so copy it before you leave the page. An admin user has everything we need; a limited user needs page and media read and write.
~2 minutes
Connect a site → Grav → paste your site’s address and the key. DraftSEO reads your pages, finds the blog page articles should go under, picks up the template your existing posts use, and connects. Your Grav install is your website, so there is no second address to give.
~1 minute
FAQ
No, and nor can anything else: Grav 1.7 has no REST API at all, so there is no way in. The API plugin only exists for Grav 2.0. Grav also has no in-place upgrade from 1.7 to 2.0 — it is a migration, with plugin and theme work to do — so treat it as a project rather than an afternoon. DraftSEO tells you this at connect instead of letting you hunt for a key that cannot exist.
Into the article’s own page folder, which is where Grav looks for a page’s media. That means a published article serves its pictures from your own server, and nothing on your live page points at DraftSEO storage. Because a folder has to exist before anything can be dropped in it, the page is created first and the finished article is written a moment later — so at worst an article is briefly live without its images.
No. Articles are created without the numeric folder prefix Grav uses for menu ordering, so they are fully routable and indexable while staying out of your nav bar — exactly like hand-written blog posts. Your blog page picks them up in its collection, ordered by date.
The same page is updated at the same route, so the article’s address never changes. DraftSEO reads the page first and merges onto what is there, so frontmatter your theme relies on — a hero image, a menu label, your own custom keys — survives untouched. The original date and tags are left alone too: moving a live article’s date reshuffles your blog, and re-adding a tag you deleted would undo your own edit.
No. Every article is written with page processing switched off for that page, so the body renders as the HTML we sent regardless of how your site is configured. That is also a safety line: a site with Twig processing on for page content would treat braces in an article as template code, and articles legitimately contain braces.
Then Cloudflare can stop DraftSEO before Grav sees the request. DraftSEO sends an X-DraftSEO-Site-Token header on every call for exactly this — add a WAF Skip rule matching it, and switch Bot Fight Mode off on the Free plan.
Yes. DraftSEO only touches the pages it created, and it never overwrites a page it did not make — if a route is already taken by someone else’s page it picks the next one along rather than writing over your work.
No card required. Grav 2.0+. Images stored on your own server.