Skip to main content
drupalreleases
Release: Drupal 11.4.9 — Update released for Drupal core (11.4.9)! Release: Better Exposed Filters 7.2.0 — Minor update available for module better_exposed_filters (7.2.0). Release: Bootstrap 8.x-3.43 — Minor update available for theme bootstrap (8.x-3.43). Release: Svg Image 3.2.5 — Minor update available for module svg_image (3.2.5). Release: Book 3.0.8 — Minor update available for module book (3.0.8). Release: Tagify 2.0.5 — Minor update available for module tagify (2.0.5). Release: Editoria11y Accessibility Checker 3.0.11 — Minor update available for module editoria11y (3.0.11). Release: Events Log Track 5.0.1 — Minor update available for module events_log_track (5.0.1). Module Revived: @font-your-face 4.3.0 — Module fontyourface updated after 7 months of inactivity (4.3.0). Security Coverage: Open Y Branch Selector — Module openy_branch_selector now has official Drupal security advisory coverage.

Decoupled Settings

2 sites No security coverage

Part of the Decoupled ecosystem · 20 projects

View on drupal.org

This module allows decoupled Drupal applications to access basic site settings like the site name, slogan, and theme logo through JSON:API. It exposes these settings from Drupal's configuration and allows individual frontends to override them, ensuring that each frontend behaves like its own distinct site while sharing a single backend configuration.

A decoupled Drupal site cannot read its own basic settings over JSON:API. Site name, slogan, front page, theme logo and favicon all live in simple config, and core JSON:API is entity based, so there is no resource to expose them. Decoupled Settings fills that gap: it reads the global values from the config objects that already hold them, and lets each consumer sparsely override individual settings. One backend, many frontends, each rendering as its own site.

Features

  • Global values are read in place. There is no second copy of the site name to drift or sync.
  • A consumer stores only the settings it overrides. Everything else is inherited and follows the site value. An override set to an empty value stays empty, and clearing it restores inheritance.
  • Exposure is bounded twice: an administrator lists which config objects are exposed, and typed config schema decides which keys within them appear. An exclusion list removes the rest, with the site email address excluded by default.
  • Theme logo and favicon arrive as resolved URLs, from core's own theme settings resolution.
  • Responses carry the config cache tags of every object read, and cache contexts for both consumer negotiation mechanisms.
  • Other modules can contribute computed settings through an alter hook, per-consumer overridable like everything else.

Post-Installation

Configure the exposure list at Configuration > Web services > Decoupled Settings. Config objects are added from a list, and a review table shows exactly what a frontend will read, including unsaved changes. Per-consumer overrides are edited on the consumer itself, on its Settings tab. Grant the Read decoupled settings permission to whoever may read: the anonymous role for public data, or a role reachable through an OAuth2 scope for protected data.

Additional Requirements

Simple OAuth works with no extra setup: it identifies the consumer from the access token, so an authenticated app resolves its own overrides with the token alone.

Similar projects

  • JSON:API Basic Site Settings serves a fixed, hardcoded key list from one controller, with no cacheability metadata and unresolved logo paths. This module supersedes it.
  • Config Pages and Site Settings and Labels model settings as entities, which suits editorial values with no core config equivalent. They cannot reach the settings core already stores, so using them for the site name means a second copy of it.
  • JSON:API Extras reshapes resources JSON:API already produces. Simple config is not an entity, so there is nothing for it to reshape.
  • Consumer Image Styles is the pattern this module extends, for image styles only and with no global layer.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Aug 2026
Latest release
1 month ago
Releases (12 mo)
2 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.0.0-beta2 Pre-release 10–11 Aug 26, 2026
1.0.0-beta1 Pre-release 10–11 Aug 25, 2026