This project is not covered by Drupal’s security advisory policy.
Editors spend their day translating an intention into CMS mechanics: find the right menu, open the right View, apply the right filters, run the right bulk operation. AI A2UI inverts that. The editor states an outcome — "show me everything unpublished from last month that still needs a reviewer" — and receives an interface built for exactly that task: a queue, a form, a dashboard, an approval flow.
The interface is generated through Drupal AI and rendered with the official A2UI protocol renderer. The model does not write code and does not touch your data. It selects components from a trusted catalog, and every action it offers is a named intent that Drupal validates, permission-checks, and executes itself.
Features
- Intent-first workspace at
/a2ui-cms: describe a task in natural language, get an interactive surface for it. - Provider independent. Nothing is bundled or hardcoded. Generation runs through Drupal AI's provider abstraction, so any installed provider plugin implementing the Chat operation works — OpenAI, Anthropic, Ollama, or anything else. The module can follow Drupal AI's default Chat provider or pin its own.
- The model proposes; Drupal decides. Generated output is treated as untrusted. Messages are schema-validated, component types are allowlisted, and actions are restricted to a configured list of named intents. Routes, PHP, JavaScript, SQL, and raw HTML are never accepted from a model.
- Extensible through events. Domain behaviour lives in your code: subscribe to the A2UI action event and implement what a given intent should do, with your own access checks and entity validation.
- Resource limits you control — maximum prompt length, messages per response, and components per surface.
- Deterministic fallback. When no provider is configured or generated output fails validation, the module can show a curated surface instead of an error. Useful for presentations; it is not a production execution path.
- No build toolchain. The compiled A2UI Lit runtime ships with the module, so sites do not need Node.js.
Post-Installation
- Install and configure Drupal AI with at least one provider that supports the Chat operation, including its API key.
- Enable this module:
drush en ai_a2ui -y - Visit Configuration → AI → A2UI settings (
/admin/config/ai/a2ui). Either follow Drupal AI's default Chat provider, or select a specific provider and model. Review the safety and resource limits while you are there. - Grant permissions at
/admin/people/permissions: Access the A2UI CMS for anyone who will use the workspace, Administer the A2UI CMS for configuration. - Open
/a2ui-cmsand describe what you want to do.
The Allowed action names setting is the important one. It is the allowlist of intents a generated interface may offer. Out of the box these map to safe, non-mutating demonstration responses; to make actions actually do something, implement an event subscriber for them. See docs/action-subscribers.md in the module.
Additional Requirements
- Drupal 10.3+ or Drupal 11
- PHP 8.1+
- AI (Drupal AI) 1.4+ or 2.x
- Any Drupal AI provider plugin supporting the Chat operation, plus credentials for it
Model inference happens through whichever provider you configure, so its costs, rate limits, and data-handling terms apply. A locally hosted provider keeps everything on your own infrastructure.
Recommended modules/libraries
- Key — store provider API keys properly instead of in settings.
- AI provider submodules for whichever service you use.
Similar projects
Most AI modules for Drupal put a conversation next to the interface — a chatbot in a sidebar, an assistant in the editor, a field that generates text. AI A2UI generates the interface itself: the output is a rendered, interactive surface with its own controls and actions, not a block of text or a suggestion to apply.
It is complementary to those modules rather than a replacement, and shares the same Drupal AI provider configuration.
Community Documentation
docs/ARCHITECTURE.md— runtime flow and the security boundarydocs/OPENAI-DEMO.md— a Docker environment with Drupal 11, Drupal AI, and a provider, for trying it end to enddocs/action-subscribers.md— implementing your own domain actions- The repository also includes a dependency-free showcase for demonstrating the concept without a provider
Project status
Alpha. Provider integration and the official A2UI renderer are functional. Generation is currently restricted to the official A2UI Basic Catalog. A versioned CMS-specific catalog (content queues, moderation state, entity selectors, revisions, media, translation readiness) is the next milestone, along with Drupal kernel tests and concrete domain-action modules for Content Moderation, Media, and Workflows.
Unattended content mutation is deliberately outside the alpha scope: the bundled subscribers respond without changing data.
Project information
Seeking co-maintainer(s)
Maintainers are looking for help reviewing issues.- Project categories: Administration tools, Artificial Intelligence (AI), Content display
- Created by akshayram1 on , updated
This project is not covered by the security advisory policy.
Use at your own risk! It may have publicly disclosed vulnerabilities.
