Teable
Teable is spending this release cycle making computed fields and admin recovery trustworthy
A side-by-side editorial comparison of BookStack and Document360 — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | BookStack | Document360 |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 5.0 | 6.3 |
| Sparks · 30d | 0 | 1 |
| Top themes | self-hosted, security-releases, permissions, documentation | api, oauth, mcp, knowledge base |
| Last editorial update | 13d ago | 1d ago |
| Website | Visit → | — |
BookStack's release stream is mostly security patches with feature drops in between.
Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.
Document360 rebuilds its public API and turns docs into an agent-readable surface.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.
Cadence is set by responsible disclosures — a named researcher credited in nearly every patch — and the feature work leans the same way, toward finer permissions and content security controls. For a self-hosted wiki that users routinely expose publicly, hardening is the roadmap, with quarterly feature releases sitting between patch runs.
Expect another patch on the 26.05 line next. The permission and CSP work visible in v26.05 is the thread the following minor most plausibly continues, though the entries give no signal on timing.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
The product is being rebuilt around programmatic access rather than portal usage. MCP made the knowledge base writable by an assistant, llms.txt made it discoverable to crawlers, copy-as-Markdown and open-in-ChatGPT made articles portable, and API v3 now gives all of that a permission-aware substrate the old v1/v2 endpoints could not support. The same permission model is showing up on the reader side too — Eddy AI features are now gated per reader group — so authorization is becoming the shared spine across API, AI, and reader access.
Expect the advanced API v3 endpoints to keep expanding as a paid add-on and the MCP server to be re-plumbed onto v3's scoped-key model, since MCP currently sits outside the new authorization scheme. A v1/v2 deprecation notice is the other likely follow-up.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Document360.
Teable is spending this release cycle making computed fields and admin recovery trustworthy
Copilot's model roster churns weekly while GitHub quietly rewires policy and billing plumbing
Governance and cross-workspace plumbing, not new AI surface
A nightly canary train where the AI platform work hides between dependency bumps
Self-hosted dashboard that finished its feature arc and stopped shipping in 2023.
A self-hosted RSS reader that now spends most of its release notes on security.
See all BookStack alternatives → · See all Document360 alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.
Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.