# drawio-desktop | draw.io | Knowledge Base | Instagit

Official electron build of draw.io

GitHub Stars: 59.7k

Repository: https://github.com/jgraph/drawio-desktop

---

## Articles

### [Understanding the Preload Script and ContextBridge API Exposure in draw.io Desktop](/jgraph/drawio-desktop/what-is-architecture-of-preload-script-and-contextbridge-api-exposure)

Explore the draw.io desktop preload script and contextBridge API. Learn how it securely exposes a minimal API for IPC communication, employing least privilege for enhanced security.

- Tags: architecture
- Published: 2026-03-05

### [How to Configure URL Parameters at Startup in Draw.io Desktop Using urlParams.json](/jgraph/drawio-desktop/how-to-configure-url-parameters-at-startup-using-urlparams-json)

Learn how to configure urlParams.json at startup in Draw.io Desktop. Easily set startup URL parameters for custom editor configurations. Get started now.

- Tags: how-to-guide
- Published: 2026-03-05

### [How draw.io Desktop Implements Security-First Design: A Deep Dive into Electron Hardening](/jgraph/drawio-desktop/how-does-drawio-desktop-implement-its-security-first-design-principle)

Discover draw.io Desktop's security-first design. Learn how contextBridge, IPC validation, CSP, and Electron fuses protect against Node.js attack vectors.

- Tags: deep-dive
- Published: 2026-03-05

### [How Platform-Specific Build Configurations Work in drawio-desktop](/jgraph/drawio-desktop/how-are-platform-specific-build-configurations-structured)

Understand drawio-desktop platform-specific build configurations. Learn how electron-builder JSON files define packaging rules for Windows macOS Linux and more.

- Tags: internals
- Published: 2026-03-05

### [How to Run draw.io Desktop in Development Mode with DevTools Enabled](/jgraph/drawio-desktop/how-to-run-drawio-desktop-in-development-mode-with-devtools-enabled)

Learn to run draw.io Desktop in development mode with DevTools enabled. Set DRAWIO_ENV=dev to automatically open Chrome DevTools for debugging.

- Tags: how-to-guide
- Published: 2026-03-05

### [How Draw.io Desktop Implements Window Management with Multiple Displays](/jgraph/drawio-desktop/how-does-drawio-desktop-implement-window-management-with-multiple-displays)

Discover how Draw.io Desktop manages multiple displays using Electron's screen module. Learn how it handles disconnected monitors and recenters windows for seamless multi-monitor setups.

- Tags: internals
- Published: 2026-03-05

### [Draw.io Desktop electron.js Main Process File Structure and IPC Handlers Explained](/jgraph/drawio-desktop/what-is-structure-of-electron-js-main-process-file-and-key-ipc-handlers)

Explore the electron.js main process file structure in Draw.io Desktop. Understand key IPC handlers bridging renderer process and native OS features.

- Tags: internals
- Published: 2026-03-05

### [How drawio-desktop PDF Export Works Using @cantoo/pdf-lib](/jgraph/drawio-desktop/how-does-pdf-export-functionality-work-using-cantoo-pdf-lib)

Discover how drawio-desktop PDF export merges rasterized buffers using webContents printToPDF and @cantoo/pdf-lib to create PDFs with embedded metadata and original diagram XML.

- Tags: internals
- Published: 2026-03-05

### [How to Enable or Disable Spell Check in draw.io Desktop](/jgraph/drawio-desktop/how-does-spell-check-feature-work-and-how-can-it-be-enabled-disabled)

Learn how to enable or disable spell check in draw.io Desktop. Control the spell check setting via the Electron store for Windows, macOS, and Linux. Easy steps to customize your diagramming experience.

- Tags: how-to-guide
- Published: 2026-03-05

### [How the Google Fonts Toggle Works in Draw.io Desktop: Implementation and Persistence Guide](/jgraph/drawio-desktop/how-is-google-fonts-toggle-implemented-and-persisted-in-settings)

Discover how Draw.io Desktop implements and persists the Google Fonts toggle. Learn about electron-store, CSP headers, and IPC communication for seamless font management.

- Tags: internals
- Published: 2026-03-05

### [How to Control Hardware Acceleration in draw.io Desktop: Disabling GPU Rendering](/jgraph/drawio-desktop/how-does-drawio-desktop-handle-hardware-acceleration-and-how-to-disable-it)

Learn how to disable hardware acceleration in draw.io Desktop using the --disable-acceleration flag. Force software rendering for improved stability and control over GPU usage for your diagrams.

- Tags: how-to-guide
- Published: 2026-03-05

### [How Draw.io Desktop Implements a Custom Context Menu with Paste and Match Style](/jgraph/drawio-desktop/how-is-custom-context-menu-implemented-with-options-like-paste-and-match-style)

Discover how Draw.io Desktop implements a custom context menu with Paste and Match Style using electron-context-menu and webContents pasteAndMatchStyle for seamless formatting control.

- Tags: internals
- Published: 2026-03-05

### [Where Does draw.io Desktop Store Local and Session Data on macOS and Windows](/jgraph/drawio-desktop/where-does-drawio-desktop-store-local-and-session-data-on-macos-and-windows)

Find out where drawio Desktop stores local and session data on macOS and Windows. Learn about appData and Electron userData directories for efficient data management.

- Tags: internals
- Published: 2026-03-05

### [How to Build draw.io Desktop for Different Platforms Using electron-builder Configurations](/jgraph/drawio-desktop/how-to-build-drawio-desktop-for-different-platforms-using-electron-builder-configurations)

Learn how to build draw.io Desktop for Windows macOS and Linux using electron-builder configurations. Automate your build pipeline with npm scripts for signed installers.

- Tags: how-to-guide
- Published: 2026-03-05

### [How the draw.io Submodule Version Sync Script (sync.cjs) Works](/jgraph/drawio-desktop/how-does-version-sync-script-sync-cjs-work-to-synchronize-drawio-submodule-versions)

Discover how the drawio desktop sync.cjs script synchronizes submodule versions, ensuring package.json mirrors the canonical drawio VERSION while managing Electron auto-updates.

- Tags: internals
- Published: 2026-03-05

### [Draw.io Desktop Environment Variables: Controlling Dev Mode and Updates with DRAWIO_ENV and DRAWIO_DISABLE_UPDATE](/jgraph/drawio-desktop/what-environment-variables-control-drawio-desktop-behavior)

Control draw.io Desktop with DRAWIO_ENV and DRAWIO_DISABLE_UPDATE. Enable DevTools, verbose logging, or disable updates for a customized experience.

- Tags: how-to-guide
- Published: 2026-03-05

### [How the draw.io Web Application Is Loaded and Initialized in the Electron Renderer](/jgraph/drawio-desktop/how-is-drawio-web-application-loaded-and-initialized-in-electron-renderer)

Discover how draw io desktop loads its web app in Electron renderer. Learn about file URLs, BrowserWindow, preload scripts, and IPC bridging for secure initialization.

- Tags: internals
- Published: 2026-03-05

### [How draw.io Desktop Handles the `--disable-update` and `--silent-update` Command-Line Arguments](/jgraph/drawio-desktop/how-does-drawio-desktop-handle-command-line-arguments-like-disable-update-and-silent-update)

Discover how draw.io Desktop uses --disable-update and --silent-update command-line arguments to control application updates. Learn about startup flag handling for seamless management.

- Tags: internals
- Published: 2026-03-05

### [How to Configure Persistent Settings Using electron-store in draw.io Desktop](/jgraph/drawio-desktop/how-to-configure-persistent-settings-using-electron-store-in-drawio-desktop)

Learn how to configure persistent settings in draw.io Desktop with electron-store. This guide shows you how to manage user preferences for a seamless experience.

- Tags: how-to-guide
- Published: 2026-03-05

### [How draw.io Desktop Validates IPC Message Senders for Security](/jgraph/drawio-desktop/how-does-drawio-desktop-validate-ipc-message-senders-for-security)

draw.io Desktop secures IPC messages by validating sender frame URLs against trusted base URLs. Learn how this prevents unauthorized access to privileged functions.

- Tags: security
- Published: 2026-03-05

### [How Draw.io Desktop Configures Content Security Policy (CSP) to Prevent External Script Execution](/jgraph/drawio-desktop/how-is-content-security-policy-configured-to-prevent-external-script-execution)

Learn how Draw.io Desktop configures Content Security Policy to block external scripts. Discover its robust security measures for preventing unauthorized code execution.

- Tags: internals
- Published: 2026-03-05

### [How draw.io Desktop Implements IPC Communication Between Renderer and Main Process](/jgraph/drawio-desktop/how-does-drawio-desktop-implement-ipc-communication-between-renderer-and-main-process)

Discover how draw.io Desktop secures IPC communication between renderer and main processes using contextBridge. Learn about request/response channels and whitelisted actions for enhanced security.

- Tags: internals
- Published: 2026-03-05

### [How the draw.io Desktop Auto-Update Mechanism Works (and How to Disable It)](/jgraph/drawio-desktop/how-does-auto-update-mechanism-work-in-drawio-desktop-and-how-can-it-be-disabled)

Understand draw io Desktop auto update functionality. Learn how electron-updater checks GitHub releases and discover methods to disable automatic updates using environment variables or Flatpak.

- Tags: internals
- Published: 2026-03-05

