Latest Version 4.0.13 - 04 Aug 2026
Kittox allows to create Rich Internet Applications based on a data model that can be mapped onto any database. The client-side part uses HTMX (through webbroker technology) to create a fully AJAX application, allowing you to build standard and advanced data-manipulating forms in a fraction of the time.
Kittox is aimed at Delphi developers that need to create web or mobile applications without delving into the intricacies of HTML, CSS or Javascript, yet it allows access to the bare metal if required.
Kittox includes a database-agnostic data-access layer, allowing to create applications that work on any database engine and port applications between database engines.
A Kittox application is described as a set of easily maintained YAML files, keeping definitions abstract and declarative and allowing for future extensions. Business rules are enforced either declaratively or through small javascript fragments on the client, or in Delphi code on the server.
- Documentation site with 150+ pages
- Pages for all controllers, filters, data concepts, how-to guides, FAQ
- Three example applications: HelloKitto, TasKitto, KEmployee
Beyond the Apache 2.0 Core, Kittox ships with Enterprise modules and developer tools under commercial license:
-
Enterprise components — interactive Charts (Chart.js), Calendars (EventCalendar), Google Maps with geocoding and markers, Dashboards and FlexPanels — all driven by YAML metadata, no client-side coding required.
-
KIDEx — the visual IDE for designing Kittox applications. Tree-based YAML editor with RTTI-based property discovery, database reverse engineering (FireDAC / DBExpress / ADO), a New Project Wizard that scaffolds complete apps for up to 4 deployment modes (Standalone .exe / Desktop .exe / ISAPI .dll / Apache .dll), and an integrated HTTP server for live preview. Ships with a RAD Studio design-time package (
KittoXIDE.bpl) that integrates the same wizard under File > New > Other > KittoX Projects and adds a YAML syntax highlighter to the IDE editor. -
MCP-KittoX — standalone Model Context Protocol server (
MCPKittoX.exe) that exposes KIDEx functionality to AI agents (Claude Desktop / Code, Codex, LM Studio, any MCP-compatible client). Agents can scaffold complete Kittox apps and reverse-engineer Models from a live database conversationally; metadata validation, locale refresh and view scaffolding tools are on the next-phases roadmap. Bundled with KIDEx: a single OnGuard registration unlocks both.
Kittox uses an Open Core licensing model:
-
Core (List, Form, Wizard, FlexPanel, routing, database, auth): Apache 2.0 — free for any use, commercial or non-commercial.
-
Enterprise Modules (Chart, Calendar, GoogleMap, Dashboard): AGPL-3.0 for open-source applications, or Ethea Commercial License for closed-source applications. Please contact Ethea for detailed informations about commercial license.
-
KIDEX (Visual IDE): commercial license only.
See the Licensing page and Enterprise Edition for full details.
Visit this site for online demos.
- Run a download-file tool (CSV/TXT/XML/Excel, MergePDF, ReportBuilder) as a background job on a worker pool separate from the HTTP threads — opt-in per tool with a single YAML line,
RunMode: Background - A notification center bell shows each job with its status (queued/running %, completed, failed) and lets the user download, cancel or dismiss the result; the badge stays until the job leaves the list
- Jobs are persisted per-user on disk and reloaded on startup, so results survive logout/login and a process restart
- Configurable via
Server/Jobs(PoolSize,Directory,ArtifactRetentionHours)
- License Registration into Registry under HKEY_CURRENT_USER\Software\Ethea\KIDEX
- Updated License procedure (Company Name + developer email)
- Now is possible to use multiple versions of KittoX in the same machine.
- The framework packages folder has been renamed from
Projects/toPackages/.
- New Kitto.Auth.LDAP authenticator (
Auth: LDAP): LDAP simple bind (Active Directory or generic LDAP), no local user table, reads name/e-mail from the directory
Controller: ReportBuilderToolupdated to latest ReportBuilder version
- Expose an app's data views as a REST/JSON web service, by default under
/api/v4/{View}in parallel to the HTMLx GUI, on the same engine, models, rules and ACL — opt-in - Plugin available adding Kitto.Web.Rest unit to UseKitto.pas
- Full CRUD with model-level permissions
- Bearer-token (stateless) auth
- Self-describing OpenAPI 3.0 spec and a built-in Swagger UI
- Configurable base path, opt-in CORS
TEFDBConnection.Openmade idempotent — fixes open datasets being silently emptied when a query is created on a busy connection- Robust date parsing in
ValueToDateTime/ValueToDate(locale dates no longer raiseEConvertError)
- Oracle is now a fully supported backend: new DDL + Data scripts for the HelloKitto and TasKitto examples (Oracle XE 21c), plus
TasKitto_Oracle_ShiftDates.sqlto re-center the demo dashboard dates - Oracle SQL dialect fixes: corrected the top-N pagination off-by-one (Oracle
ROWNUMis 1-based — single-row fetches previously returned 0 rows, full pages were short by one) and reintroduced the portable%DB.CONCAT%macro (||on Oracle/PostgreSQL/Firebird,+on SQL Server); new%DB.FROM_DUAL%and%DB.CURRENT_DATE%macros make hand-written YAML SQL portable across all five dialects - FireDAC Oracle wired up in the examples: the
Oradriver is registered inUseKitto.pasand a ready-to-useFireDAC_Oracleconnection block ships (commented) inConfig.yaml - New optional ODAC backend (
EF.DB.ODAC, ClassIdODAC): an alternative Oracle path built on Devart ODAC, modelled on the FireDAC adapter (connection, commands, queries, transactions, metadata introspection via the Oracle data dictionary). It reuses the existing Oracle dialect and is not in the core package (commercial dependency) — enable it per-app by referencing the unit; the examples ship it defined-but-disabled so they still compile without ODAC installed - Fix
ftUnknownparameter binding under MS ODBC Driver 17/18: withDirectExecutethe driver no longer infers untyped parameter types (as SQL Server Native Client 11 did), which rejected optional/unassigned columns — now bound safely - New
KittoX_Oracle.mddocumenting the full Oracle setup; a note in everyUseKitto.pasclarifies that the client/server FireDAC/DBExpress drivers require Delphi Enterprise/Architect (Professional ships only local/embedded drivers)
- The whole
kx/*request surface is now attribute-routed: after the auth family in 4.0.9, this release migrates the entire view domain (view,data,form,save,delete) and all ancillary endpoints (lookup,tool,blob,upload,notify, master-detaildetail/{i}/data|save|delete,wizard-finish) into typed handlers running under a single shared request-filter chain (error → JWT auth → navigation guard → authorization) - Legacy
TKWebApplication.DoHandleRequestnow serves only the Home page (/); zeroIsKX*Requestmatchers remain (down from ~24) — the monolithic dispatcher is gone - New
TKXResourceRegistry.RegisterOverrideAPI: an application can subclass a framework handler and override a single endpoint or hook (e.g. a customsave) without forking the whole route — register the subclass and it replaces the default for its base path
- Navigation guard: direct browser navigation to an internal
kx/*fragment endpoint (e.g. pasting.../kx/view/SomeChartin the address bar) is now rejected and redirected to login / home. Only in-app HTMX requests are served the partial; typing a fragment URL no longer leaks a bare HTML partial (when logged in) nor returns a bald404(when not)
{MasterRecord.*}macros now resolve in detail-form lookup filters: the detail store is linked to the session master record, so dependent lookups populate correctly instead of coming up empty- Dedicated lookup grids apply the calling field's
LookupFilter(including{MasterRecord.*}), with search/paging state preserved - Detail-record rules fire on save:
HandleDetailSavenow applies each field'sAfterFieldChangerules (calculated fields — avoids NOT NULL violations) andApplyBeforeRules(rules that roll detail values up into the master, e.g. totals) - Reference caption & AutoAddFields resolve on newly-added in-memory records: the derived-values cascade (previously skipped because populate runs with notifications off) now runs via
RefreshDerivedReferenceValues, so a reference column is filled immediately instead of staying blank until reloaded from the DB
- Mobile dashboard fix: cards in a maximized-dialog dashboard (
Controller: Dashboard/ FlexPanel) no longer overflow the screen width and the panel now scrolls vertically, so cards below the fold are reachable
- Framework public-API XMLDoc coverage raised from ~32% to ~74%, spanning the routing namespace, the in-memory store, the metadata system, the web engine/server, the HTMLx controllers,
EF.DB, the config/rules/SQL core, the tool controllers and the third-party integration shims — surfaced in KIDEx through[YamlNode]descriptions
- Double URL-decode of request values — form/query values were URL-decoded twice (a second decode over already-decoded text), silently corrupting any value containing
%,+or (on some RTL versions)?: passwords (login failing), saved form fields (e.g.50%,C++), search/filter terms and record keys. Values are now decoded exactly once
- The authentication family (
kx/login,kx/logout,kx/resetpassword,kx/changepassword) migrated to the attribute-based router — first core group to "bring its own routing" (the login page is still served byHome()at/, unchanged) - Attribute-routed requests now run inside the full per-request context (authenticator, macro engine, and — for
Auth: JWT— a session hydrated from the verified token)
Examples/build_Examples.cmdnow accepts command-line arguments to build a single example / deploy mode / config, e.g.build_Examples.cmd TasKitto Desktop Debug(the interactive menu is kept when run with no arguments)
- User-selectable theme: set
Theme/UserSelection: Trueand drop aController: ThemeSwitcheranywhere in the GUI — the end user picks Light / Auto / Dark live, persisted per-app inlocalStorage, FOUC-safe boot, no page reload Themeis now a structured config block discoverable by KIDEx:Theme/Mode(Auto/Light/Dark), shared font/icon settings, and per-modeLight:/Dark:palettes (each with its ownPrimary-Color) — replaces the old flatTheme: <mode>value (existing configs still load)
- Full-width footer and side-panel layout refinements; optional per-section theme switcher
- Boolean
[YamlNode]defaults now carry the inverse of the runtime default, so the "Add node" menu writes the meaningful value instead of a no-op
- Many new tools added — full CRUD on Models / Views / Layouts, database introspection (connections, tables, columns), config read/update, locale (
.po) reading, metadata validation, and grid/list view scaffolding (40+ tools total, up from 16)
Controller/AutoOpenandController/PagingToolsbased on model'sIsLargeflag- A Reference field whose target Model has
IsLarge: Truerenders as a searchable lookup popup
Auth: JWTno longer emits the legacy<AppName>session-id cookie norkx_db— the JWTsidanddbclaims carry the same info- Server-side ACL enforcement on every
HandleKX*route (view/data/save/delete/form/lookup/blob/upload/tool/detail*/wizard) - New auth gate in
DoHandleRequestreturns 404 on protected routes for unauthenticated requests (public views excluded) - Toolbar Add/Edit/Delete/Dup stay
disabledfor ACL-denied users - Per-thread JWT context cache uses
TObjectDictionary<TThreadID, ...>
- New RAD Studio IDE plugin gallery:
KittoXIDE.bplregisters 4 entries under File > New > Other > KittoX Projects (Standalone .exe / Desktop .exe / ISAPI .dll / Apache .dll) - Three paths to scaffold a new app: KIDEx standalone, the new IDE gallery, and
MCP-KittoX project_create_app - New project default:
Auth: TextFilewith a ready-to-useHome/FileAuthenticator.txt(admin/admin demo accounts) so the generated app authenticates out of the box, no users table required. JWT envelope kept as default.AccessControldefault switched toNullto avoid deny-all post-login on a brand-new project.DB.FD.yamltemplate now setsODBCAdvanced: TrustServerCertificate=yesso SQL Server ODBC Driver 17/18 connects on first try - Model Wizard
Beautify namesoption now also handles DB names with spaces (Northwind-style:Quarterly Orders→QuarterlyOrders,Sales by Category→SalesByCategory); the original name is preserved inPhysicalNamefor the SQL layer - Model Wizard — new editable
DisplayLabelandHintfields on every Add/Update Field action: auto-populated from the database's native column comment when present (MSSQLMS_Description, PostgreSQLpg_description, FirebirdRDB$DESCRIPTION, MySQLCOLUMN_COMMENT, OracleUSER_COL_COMMENTS), fully editable before Apply - Action "New TreeView..." on the Views folder is now idempotent: pointing it at an existing
MainMenu.yamlmerges the Models that aren't yet referenced under theFolder: Menublock, preserving every hand-edited entry, instead of raising a duplicate-object error
- New tool
models_create_from_db— the headless equivalent of the Model Wizard. AI agents can reverse-engineer Models from a database connection conversationally: defaults todry_run: true(preview only); passdry_run: falseto commit. Output is byte-identical to what the visual wizard writes.DisplayLabelauto-populated from the database's native column comments; optionalfield_descriptionsarray lets the agent inject labels from a non-DB source (CSV, glossary, prior YAML) with per-property override precedence - New tools
models_list/models_read/views_list/views_read/resources_list/resources_read— enumerate and read project metadata and static resources headlessly - New tool
menu_generate_main_menu— create or refreshMainMenu.yamlwith one entry per Model under a top-levelFolder: Menu; idempotent (existing entries preserved, only missing Models appended) - Database column comments are now auto-fetched for all 5 supported engines (MSSQL, PostgreSQL, Firebird, MySQL, Oracle) and flow into both the KIDEx wizard and the MCP tool
- 16 tools now implemented (was 9)
- Better error reporting from MCP tools: errors are now propagated verbatim to the JSON-RPC client (class name + message) instead of being replaced by a generic fallback
- Setup installer ships
MCPKittoX.exealongsideKIDEX.exesharing OnGuard license Tools/SetVersion.ps1now also bumps the 12 dprojs of the 3 official examples (HelloKitto, TasKitto, KEmployee — 4 deployment variants each), and inserts<VerInfo_Release>and other VerInfo tags when the .dproj has them stripped (Delphi removes VerInfo tags whose value is 0)
- New
Auth: JWTwrapper authenticator (signedkx_tokencookie, sliding expiration, programmatic key registration) - New
AccessControl: JWTreading grants fromkx_aclclaim snapshotted at login, with optional DB fallback - Updated examples to JWT Auth (TasKitto / HelloKitto / KEmployee)
- Updated TasKitto example with three-tier ACL (
admin/user/viewer) - Multi-database support on TasKitto and HelloKitto: SQL Server / PostgreSQL / Firebird
- Cross-dialect macros:
%DB.TRUE%/%DB.FALSE%,%DB.DATEDIFF,%DB.DATETIME_FROM - Login form with optional "Environment" combo for multi-database apps (
Auth/DatabaseChoices) - Native boolean types on the three sample DBs (
BIT/BOOLEAN); Firebird setup is now SQL-script-only - Firebird Activity Dashboard views translated from the SQL Server originals
- TasKitto SQL Server DDL split (tables / views in separate scripts because of T-SQL batch rules)
- New
Tools/SetVersion.ps1: one-shot version bump across constant, dproj, README and Inno Setup - New
Projects/BuildAllPackagesD{10_4,11,12,13}.ps1wrappers: rebuild Core + Enterprise per Delphi version - YAML metadata files included in every
.dproj(visible in Project Manager, KIDEx highlighting) EF.Logger.TextFileactive out-of-the-box for the standalone Indy hosts
- Architectural refactor: DB connection ownership unified in
TKConfig - New API
TKConfig.DatabaseFor(Name)andTKConfig.CreateStandaloneDBConnection(Name) CreateDBConnectionmoved frompublictoprotectedClearDatabase/DestroyInstancenow clear bothFDatabaseandFDatabases- New
InDBConnection/InDBTransactionhelpers
- Manual column resize in grids
- Tooltip on truncated grid cells (only when actually truncated)
- Fix: in-memory lookup popup closing on resize
- Tooltip on TreePanel menu nodes
- Multi-column sort in grids
- Multi-page form validation
- Edit-mode accent border for combobox and other non-text-editable fields
- SunEditor readonly rendering
- Checkbox styled like other form inputs
- DetailTables Style (Tabs/Bottom/Popup)
- Added CSS
.disabledclass
- Editing-mode field borders
- Form toolbar anchoring
- DateTime field fixes
- Fixed KittoEmailSenderSrvc
- Grid keyboard navigation
- SunEditor theming and resize
- Dialog focus
- DetailTables Style (Tabs/Bottom/Popup)
- ExportExcel / ExportFlexCel
- Fixed Date/time filters SQL conversion
- Date/time filter trigger
- Error dialog consistency
Controller: Windowrestored backward-compatibility
- Simplified Apache/IIS deployment: static resources served internally, no RewriteRule needed
- New deployment mode: Windows Service + reverse proxy (nginx/Apache/IIS) with install/uninstall scripts
- Fixed ViewMode to EditMode save bug in master-detail forms
- Implemented Apply*Rules event chain (EditRecord, NewRecord, Duplicate, AfterShowEditWindow)
- Master-detail: "Confirm" button (save-cache) and "Save All" only visible in ViewMode
- HTTP error feedback (htmx:responseError) with Retry/Reset dialog
- Updated Italian localization (.po/.mo) with all KittoX strings
- Extensive documentation updates (deploy, proxy, localization, form state machine, routing)
- Added DDL and DML script for Example databases
- Fixed Field Rules client-side (ForceUpperCase, ForceCamelCaps, MinValue/MaxValue)
- Fixed PackageGroup
- Fixed modal lookup for Reference fields
- Fixed Example for Apache modules
First public release of Kittox, the fourth generation of the Kitto framework. Complete rewrite of the client-side from ExtJS to HTMX + AlpineJS + TemplatePro, with a new modular server architecture.
- HTMX + AlpineJS client: server-generated HTML fragments with partial page updates via AJAX. No heavy JavaScript framework.
- Attribute-Based Routing (RTTI): URL routing via Delphi custom attributes, inspired by MARS/WiRL. Resource classes register in
initializationsections; the framework discovers them via RTTI. Dependency injection for request context ([TKXContext]). Dynamic JS/CSS injection viaTKXScriptRegistry. - Open Core licensing: Core (Apache 2.0), Enterprise modules (AGPL-3.0 / Commercial), KIDEX (Commercial only). Separate packages:
KittoXCore.dpkandKittoXEnterprise.dpk. - Server-Side Store: persistent in-session data stores with record state tracking (
rsNew,rsClean,rsDirty,rsDeleted), transactional master-detail saving (INSERT/UPDATE/DELETE in a single DB transaction), blob lazy-loading, and store lifecycle management (save/cancel/close/timeout).
- List (grid with CRUD toolbar, server-side paging, sorting, column layouts, row colors, grouping)
- GroupingList (collapsible group headers)
- Form (data-aware editing with field pages, detail tabs, ViewMode/EditMode state machine)
- Wizard (multi-step data-aware with Back/Next/Finish, per-step validation)
- BorderPanel, TabPanel, FlexPanel, TreePanel, TilePanel, HtmlPanel, StatusBar, ToolBar
- Enterprise: ChartPanel (Chart.js), CalendarPanel (EventCalendar), GoogleMap (Google Maps JS API), Dashboard (auto-refresh)
- Card View: List controller with
TemplateFileNamefor custom HTML card layouts with full CRUD - Desktop Embedded Mode: KittoX app inside a WebView2 (TEdgeBrowser) VCL window
- Database agnostic: pluggable via FireDAC (preferred), DBExpress, ADO
- Master-detail transactional save: master + all detail stores persisted in one transaction
- Detail CRUD in memory: add/edit/delete detail records without DB round-trips until final Save All
- Record state after Load: records loaded from DB correctly marked as
rsClean - Server-Side Store cache: blob lazy-load from session store, store released on save/cancel/close/timeout
- Form State Machine: ViewMode (Edit / Save All / Close) and EditMode (Save / Cancel) with CSS-based button toggling
- Save-cache endpoint: saves master to memory without DB persistence, enables Save All workflow
- Detail tables: lazy-loaded tabs, auto-built views, FK pre-fill on Add, transactional cascading save
- Unified Editor Factory (
Kitto.Html.Editors): centralized HTML input generation shared between Form and FilterPanel - Help button: configurable via
Defaults/Help/HRefin Config.yaml, appears in forms (first button) and list toolbar (after Refresh)
- Automatic mobile detection: user agent + screen size cookie
- Fullscreen dialogs on mobile:
IsModal+Maximizedforced for all fragment views/forms viaAdjustControllerForContext - Panel properties:
IsModal(dialog overlay),Maximized(fullscreen viewport),AllowClose(X button and Close button) - Width/Height getters: return 0 when Maximized is True (original values preserved for restore)
kxApp.openView: single JS function for view opening from menus (TreePanel and TilePanel use identical logic)body.kx-mobileCSS class: forces dialog and login fullscreen on mobile devices- TilePanel: tile-based menu controller for mobile home pages, with touch support (
role="button",touch-action: manipulation) - Home view selection:
HomeTinyView(phone),HomeSmallView(tablet),HomeView(desktop)
- Toast notifications: shown after save ("Data saved") and delete ("Data deleted"), auto-dismiss 3 seconds
- Error handling: DB errors (EEFDBError) non-fatal with clean messages (driver prefixes stripped). Session-level errors trigger reload.
- Draggable dialogs: all message boxes and error dialogs draggable by title bar via
kxMakeDraggable - Refresh button: in CRUD toolbar (visible by default, hidden with
PreventRefreshingor on read-only controllers) - Column sorting: click to sort ascending, click again for descending, sort arrows via CSS pseudo-elements
- Double-click to open: automatic edit/view form from grid rows
- Session lost detection: fatal error dialog with reload on server restart
- Timeout handling: configurable
AjaxTimeoutfor both HTMX and fetch channels, Retry/Reset dialog
- Filter Panel with:
FreeSearch,List,DynaList,ButtonList,DynaButtonList DateSearch,TimeSearch,DateTimeSearch,NumericSearch,BooleanSearch- Layout with
ColumnBreakandLabelWidth
- Custom Layout for Grid and Form
- Grid Layout with Column position, alignment
- Form Layout "multipage", with collapsible regions
- Pluggable authenticators:
DB,DBCrypt,TextFile,DBServer,OSDB,Null - Pluggable access controllers:
DB,Null - BCrypt password hashing, Google OTP (TOTP) two-factor authentication, QR code generation
- Session abstraction:
IKXSessionProviderwithTKXCookieSessionProvider(JWT-ready for future)
- CSV export (
ExportCSVTool), Excel export via ADO (ExportExcelTool), SQL tool, file download/upload - FlexCel integration (commercial, Enterprise edition)
- ReportBuilder integration (commercial, Enterprise edition)
- DebenuQuickPDF for PDF merging
- Standalone (VCL desktop or Windows service with embedded Indy HTTP server)
- Desktop Embedded (WebView2 inside VCL window)
- Console (headless server)
- IIS (ISAPI DLL via WebBroker)
- Apache (module via WebBroker)
- RTTI-based property discovery (replaced 215 MetadataTemplate YAML files)
- 6 custom YAML attributes:
YamlNode,YamlRequiredNode,YamlContainer,YamlSubNode,YamlChildType,YamlEnumValue - SVG icon support (Material Design Icons)
- Database reverse engineering (model creation from DB schema)
- Project wizard, validators, tree editors
- HelloKitto: simple party/invitation manager (Parties, Girls, Dolls, Invitations)
- TasKitto: activity tracking with dashboard, charts, calendar, projects, customers
- KEmployee: employee/customer management with master-detail, card views
Available from Delphi 10.4 to Latest (Win32 or Win64 platforms).
Related links: www.embarcadero.com - https://learndelphi.org

