npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

inko-pdf-sdk

v1.2.0

Published

Self-hosted PDF SDK with outline bookmarks, review overlays, editing-state export/restore, and host-managed storage.

Readme

Inko

CI npm License

한국어 · Developer documentation · Live demo

Inko is a free, open-source, self-hosted PDF annotation SDK. It lets a host application load a PDF, export and restore editable annotation state, display multiple review states as overlays, and continue editing from a state selected by the host.

Inko is maintained by NextH. The project is published to make the implementation and its limits directly verifiable.

What Inko provides

  • PDF rendering powered by PDF.js
  • Native PDF text selection/copy plus Unicode literal search across virtualized pages
  • PDF.js native annotations, safe internal/external links, and AcroForm display/input
  • exportPdf() for an ArrayBuffer containing current AcroForm values
  • exportFlattenedPdf() for a standalone PDF with AcroForms plus supported Inko drawing types burned into page content; omissions and failures are reported per item
  • Pen, highlighter, eraser, text, shape, selection, zoom, and thumbnail tools
  • A bookmark panel built from the PDF's embedded outline, shown only when the document actually carries one
  • Editable state export and restoration through canvasData
  • Review-state overlays through loadUserCanvasOverlay()
  • Exactly-one version-history selection when one overlay entry declares isCurrent: true
  • A browser/iframe SDK exposed through Inko.mount()
  • Theme, tool, and Korean/English UI configuration

The viewer uses PDF.js's public TextLayerBuilder and AnnotationLayerBuilder with one document-level annotationStorage, keeps high-DPI canvas rendering and DOM layers on the same logical viewport, and virtualizes offscreen pages. These are the same classes of rendering, text, form-state, and lifecycle concerns expected from a production PDF integration, while remaining inspectable OSS.

Inko does not provide a server-side repository, authentication, authorization, version numbering, append-only storage, backup, retention, audit logs, Git diff/merge/branch features, or a collaboration backend. Those belong to the host application.

Install

npm install inko-pdf-sdk

Inko is self-hosted. Serve the package's viewer/ directory from your web server, and serve sdk/inko-sdk.js from a URL your application can load. A same-origin deployment is the simplest starting point.

cp -R node_modules/inko-pdf-sdk/viewer public/inko-viewer
cp node_modules/inko-pdf-sdk/sdk/inko-sdk.js public/inko-sdk.js
<div id="inko" style="height: 80vh"></div>
<script src="/inko-sdk.js"></script>
<script>
  let savedState = ''

  const viewer = Inko.mount('#inko', {
    src: '/inko-viewer/index.html',
    pdfUrl: '/documents/example.pdf',
    fileName: 'example.pdf',
    initialCanvasData: savedState || undefined,

    onChange(canvasData) {
      // Debounce and persist this value in the host application's storage.
      savedState = canvasData
    },

    onError(error) {
      console.error(error)
    },
  })

  // Separate binary path: native AcroForm values are written into PDF bytes.
  const pdfBytes = await viewer.exportPdf()

  // Delivery copy: AcroForms + every current Inko drawing, no canvasData embedded.
  const { pdfBytes: deliveryPdf, report } = await viewer.exportFlattenedPdf()
  if (report.hasFailures) throw new Error('Some annotations could not be flattened')
</script>

canvasData, exportPdf(), and exportFlattenedPdf() are deliberately separate contracts. canvasData preserves Inko's editable Paper.js drawing/review state; exportPdf() returns PDF.js saveDocument() bytes with native AcroForm state. It does not merge Inko drawings. exportFlattenedPdf() starts from those saved AcroForm bytes and writes pen, highlighter, text, rectangle, circle, and line objects into every affected PDF page. The result is portable but no longer an editable Inko state, so hosts that need resume-editing must still persist canvasData. Inspect report.hasFailures; a content rewrite also cannot preserve an existing CMS/PAdES cryptographic signature. Helvetica-compatible PointText stays PDF text. Other Unicode PointText is rendered with the bundled OFL Pretendard font into a high-resolution transparent image and reported as TEXT_RASTERIZED; that fallback text is visual content rather than selectable PDF text. Pretendard is loaded only when this fallback is needed.

For cross-origin iframe deployments, configure VITE_ALLOWED_ORIGINS at build time and apply the required HTTP CSP/CORS headers in the host environment. See the integration guide for the API and deployment details.

Responsibility boundary

The adopter is responsible for installation, hosting, integration, origin and CSP policy, authentication, authorization, storage, backups, environment validation, security updates, upgrades, rollback, and maintenance of any fork.

NextH does not provide individual technical support, an SLA, LTS, a guaranteed response or remediation time, or compatibility guarantees for a particular browser, iframe host, PDF collection, infrastructure, or future version. Public issues and pull requests are reviewed on a best-effort basis and are not a support channel.

Develop from source

Requirements: Node.js 22.12 or newer and npm.

npm ci
npm test
npm run check
npm run build

The production build is written to dist/. The build includes an OSS-boundary check that rejects unreviewed sample PDFs, development mocks, source maps, and drift in reviewed PDF.js/font assets.

The repository root is intentionally marked private to block accidental npm publication of the source workspace. npm run build:pkg creates the allowlisted public package in release/; only the verified tarball from that directory is published.

Browser integration tests require Playwright Chromium:

npx playwright install --with-deps chromium
npm run test:e2e

Verify a release

Each GitHub release includes the npm tarball, a CycloneDX SBOM, and SHA256SUMS. Verify the downloaded files before installation:

sha256sum --check SHA256SUMS
npm audit signatures

The release workflow creates two separate GitHub attestations for the same tarball: SLSA build provenance and a CycloneDX SBOM attestation. Verify their signatures and repository identity with:

gh attestation verify inko-pdf-sdk-1.2.0.tgz --repo sinabin/inko-sdk

Documentation

Security reports

Do not post suspected vulnerabilities in a public issue. Use GitHub's private vulnerability reporting for this repository. See Security policy.

License

Inko is licensed under the Apache License 2.0. Third-party components and assets remain under their respective licenses; see THIRD_PARTY_NOTICES.md.