inko-pdf-sdk
v1.2.0
Published
Self-hosted PDF SDK with outline bookmarks, review overlays, editing-state export/restore, and host-managed storage.
Maintainers
Readme
Inko
한국어 · Developer documentation · Live demo
Inko is a free, open-source, self-hosted PDF annotation SDK. It lets a host application load a PDF, export and restore editable annotation state, display multiple review states as overlays, and continue editing from a state selected by the host.
Inko is maintained by NextH. The project is published to make the implementation and its limits directly verifiable.
What Inko provides
- PDF rendering powered by PDF.js
- Native PDF text selection/copy plus Unicode literal search across virtualized pages
- PDF.js native annotations, safe internal/external links, and AcroForm display/input
exportPdf()for anArrayBuffercontaining current AcroForm valuesexportFlattenedPdf()for a standalone PDF with AcroForms plus supported Inko drawing types burned into page content; omissions and failures are reported per item- Pen, highlighter, eraser, text, shape, selection, zoom, and thumbnail tools
- A bookmark panel built from the PDF's embedded outline, shown only when the document actually carries one
- Editable state export and restoration through
canvasData - Review-state overlays through
loadUserCanvasOverlay() - Exactly-one version-history selection when one overlay entry declares
isCurrent: true - A browser/iframe SDK exposed through
Inko.mount() - Theme, tool, and Korean/English UI configuration
The viewer uses PDF.js's public TextLayerBuilder and AnnotationLayerBuilder
with one document-level annotationStorage, keeps high-DPI canvas rendering and
DOM layers on the same logical viewport, and virtualizes offscreen pages. These
are the same classes of rendering, text, form-state, and lifecycle concerns
expected from a production PDF integration, while remaining inspectable OSS.
Inko does not provide a server-side repository, authentication, authorization, version numbering, append-only storage, backup, retention, audit logs, Git diff/merge/branch features, or a collaboration backend. Those belong to the host application.
Install
npm install inko-pdf-sdkInko is self-hosted. Serve the package's viewer/ directory from your web
server, and serve sdk/inko-sdk.js from a URL your application can load. A
same-origin deployment is the simplest starting point.
cp -R node_modules/inko-pdf-sdk/viewer public/inko-viewer
cp node_modules/inko-pdf-sdk/sdk/inko-sdk.js public/inko-sdk.js<div id="inko" style="height: 80vh"></div>
<script src="/inko-sdk.js"></script>
<script>
let savedState = ''
const viewer = Inko.mount('#inko', {
src: '/inko-viewer/index.html',
pdfUrl: '/documents/example.pdf',
fileName: 'example.pdf',
initialCanvasData: savedState || undefined,
onChange(canvasData) {
// Debounce and persist this value in the host application's storage.
savedState = canvasData
},
onError(error) {
console.error(error)
},
})
// Separate binary path: native AcroForm values are written into PDF bytes.
const pdfBytes = await viewer.exportPdf()
// Delivery copy: AcroForms + every current Inko drawing, no canvasData embedded.
const { pdfBytes: deliveryPdf, report } = await viewer.exportFlattenedPdf()
if (report.hasFailures) throw new Error('Some annotations could not be flattened')
</script>canvasData, exportPdf(), and exportFlattenedPdf() are deliberately separate contracts.
canvasData preserves Inko's editable Paper.js drawing/review state;
exportPdf() returns PDF.js saveDocument() bytes with native AcroForm state.
It does not merge Inko drawings. exportFlattenedPdf() starts from those saved
AcroForm bytes and writes pen, highlighter, text, rectangle, circle, and line
objects into every affected PDF page. The result is portable but no longer an
editable Inko state, so hosts that need resume-editing must still persist
canvasData. Inspect report.hasFailures; a content rewrite also cannot preserve
an existing CMS/PAdES cryptographic signature. Helvetica-compatible PointText
stays PDF text. Other Unicode PointText is rendered with the bundled OFL
Pretendard font into a high-resolution transparent image and reported as
TEXT_RASTERIZED; that fallback text is visual content rather than selectable
PDF text. Pretendard is loaded only when this fallback is needed.
For cross-origin iframe deployments, configure VITE_ALLOWED_ORIGINS at build
time and apply the required HTTP CSP/CORS headers in the host environment. See
the integration guide for the API and deployment
details.
Responsibility boundary
The adopter is responsible for installation, hosting, integration, origin and CSP policy, authentication, authorization, storage, backups, environment validation, security updates, upgrades, rollback, and maintenance of any fork.
NextH does not provide individual technical support, an SLA, LTS, a guaranteed response or remediation time, or compatibility guarantees for a particular browser, iframe host, PDF collection, infrastructure, or future version. Public issues and pull requests are reviewed on a best-effort basis and are not a support channel.
Develop from source
Requirements: Node.js 22.12 or newer and npm.
npm ci
npm test
npm run check
npm run buildThe production build is written to dist/. The build includes an OSS-boundary
check that rejects unreviewed sample PDFs, development mocks, source maps, and
drift in reviewed PDF.js/font assets.
The repository root is intentionally marked private to block accidental npm
publication of the source workspace. npm run build:pkg creates the allowlisted
public package in release/; only the verified tarball from that directory is
published.
Browser integration tests require Playwright Chromium:
npx playwright install --with-deps chromium
npm run test:e2eVerify a release
Each GitHub release includes the npm tarball, a CycloneDX SBOM, and
SHA256SUMS. Verify the downloaded files before installation:
sha256sum --check SHA256SUMS
npm audit signaturesThe release workflow creates two separate GitHub attestations for the same tarball: SLSA build provenance and a CycloneDX SBOM attestation. Verify their signatures and repository identity with:
gh attestation verify inko-pdf-sdk-1.2.0.tgz --repo sinabin/inko-sdkDocumentation
Security reports
Do not post suspected vulnerabilities in a public issue. Use GitHub's private vulnerability reporting for this repository. See Security policy.
License
Inko is licensed under the Apache License 2.0. Third-party components and assets remain under their respective licenses; see THIRD_PARTY_NOTICES.md.
