# partmode: browser CAD where the kernel is exact, the authority is split, and DXF is a subset

> Parametric CAD on OpenCascade compiled to WebAssembly, in which a person and a permissioned typed agent write to the same document model and the same geometry kernel. The security design separates authentication from authority, and the durability design has one gap it states out loud.

**BOMWiki/partmode** — Open-source, local-first 3D parametric CAD that runs in the browser for people and permissioned typed agents, powered by OpenCascade WASM.

- Repository: https://github.com/BOMWiki/partmode
- Website: https://partmode.com/
- Stars: 511 · Forks: 24
- Language: JavaScript
- License: AGPL-3.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/bomwiki-partmode

## DXF exports a restricted R12 subset while SVG and PDF carry the full sheet

The drawings row of the capability table is the one to read carefully, because it splits three formats into two very different tiers.

SVG and PDF sheets can carry document-owned content. That means dimensions, tolerances, notes, symbols and tables, and it means they are stored in the document rather than added afterwards by a viewer.

DXF gets a restricted subset instead: R12 orthographic or sketch geometry. Not a dimensioned drawing, not a toleranced one. A restricted orthographic projection, or sketch-level geometry at an old interchange revision.

The practical consequence is that a DXF round trip is a geometry exchange, not a drawing exchange. Anything downstream that expects to read your dimensions and tolerances from a DXF will find a drawing with none of them, and the fix is not a setting.

The rest of the interchange story is broader than DXF suggests. STEP goes in and out, there are editable PartMode project bundles, and there are three mesh formats for printing or visualisation.

So the format table is honest about its own shape: full-fidelity sheets exist in two vector-and-page formats, STEP is the interchange path, and DXF is there for legacy geometry consumers.

## Committed headless documents are durable, and there is no per-project delete

The server-headless path is the durable one, and its durability is stated in four separate clauses: committed records survive session expiry, survive key revocation, survive restarts, and survive deployments.

That is a real strength for unattended work. Revoking a key is the obvious response to a compromised credential, and here it does not destroy your committed output.

The same paragraph then states that those records remain until account deletion, and that there is no individual project-delete control yet.

So the gap is precise. There is no way to remove one committed headless document. Either it lives until the account goes, or every document goes with the account.

For a CAD tool this is a narrower problem than it would be for a messaging or storage service, since a document is geometry rather than correspondence. It still matters for two cases: a project a person no longer wants associated with their account, and a compliance situation where deleting one artefact matters more than keeping the rest.

The paragraph is candid about the absence, which is worth something. It is stated in the same breath as the durability guarantee, not in a limitations section further down.

## A key authenticates the agent but grants it no CAD authority

The line that defines the whole agent design is short: a key authenticates the agent but does not grant CAD authority by itself.

Authenticated and authorised are separate, and the second one comes from somewhere else. For the browser path it requires four things at once: an account, a revocable agent key, a signed-in PartMode tab, and visible approval for the project-scoped session.

That is a four-part precondition for letting an agent touch an open project, and only one of the four is the credential. The signed-in tab is what makes approval visible to a person, and the project scope is what keeps a grant from being general.

The headless path is the other side of the same coin, and it is deliberately not an extension of browser access. An edit key has to be created with an explicit, immutable headless grant, and that is described as a separate storage and authority choice rather than an automatic consequence of having browser access.

The word doing the work in both cases is grant. A key identifies who is calling. A grant says what they may change, where, and for how long. The page is careful never to let the first imply the second.

## The relay is not end-to-end encrypted and there is no offline queue

Three limits on the hosted path are stated together, and all three are the kind that get left out.

Approved commands and results cross the hosted relay over HTTPS and remain only in bounded process memory. The relay is not end-to-end encrypted. And the browser project itself is not stored there.

That last one is the reassuring half. The geometry you are modelling anonymously in a browser tab does not sit on someone else's server, so the relay being readable in transit is a narrower exposure than it first appears.

There is no offline queue, which is the other half of the same design. If the relay is unreachable, work in flight does not queue and replay later. It stops.

For an approval workflow that is the right trade. A queued command replayed hours later against a document that has since been revised by hand is a class of bug that offline support would create rather than solve.

The write path is also revision-bound. The agent inspects current state, creates a detached preview, and commits only against the matching document revision, so a stale command fails rather than overwriting. Meanwhile the person on the other side can reject, pause, disconnect, or revoke at any point.

## The only release is a dated snapshot while package.json says 8.0.0

There is exactly one GitHub release, and it is not a version. The tag is a date-based source snapshot, published in August 2026, described as a public source snapshot.

Meanwhile the project metadata declares version 8.0.0.

So the two versioning systems do not correspond. The eight does not appear in any tag, and the tag's date does not appear in the package version. The package is also marked private, so the eight is not a published artifact number either; it is an internal counter.

That counter is doing work. The document schema is separately at version five, and the capability description refers to templates as editable schema-5 starting projects. A number that has reached eight while the schema sits at five suggests the project version tracks releases of the whole application rather than the document format, which is the correct arrangement but one a reader has to infer.

The demo makes the same point in a different way. The eighteen-second video was captured locally from a specific public source snapshot, by commit hash, using the production typed-agent protocol, with the steps and evidence kept alongside the media.

Hashing the commit in the capture note is the right instinct, since it makes the demo reproducible. It also makes visible that there is no single release artefact to point a third party at.

## The license is AGPL-3.0 in one place and AGPL-3.0-only in another

The repository metadata reports AGPL-3.0 and the project manifest declares AGPL-3.0-only. Those are not the same string, and the difference is meaningful.

The bare identifier leaves open the choice between the only-versions form and the later variants that add an autoconflict exception or a larger-work exception. The only suffix removes that choice, which for a copyleft network license is the stricter and more predictable position.

The prose version is looser in wording. It says the project is free to use, inspect, modify and self-host under the GNU AGPL v3, and the self-hosting permission is called out explicitly.

That combination makes sense for what this is. The geometry kernel is OpenCascade compiled to WebAssembly, and OpenCascade ships under a permissive licence with an exception for static linking into GPL-covered software. Vendoring it into a copyleft application is the compatible direction, and there is a third-party notices document at the repository root to account for what came in.

For anyone planning to modify PartMode and offer the result as a service, the only-suffix form is the one to follow, since it is the unambiguous one, and the copyleft obligation to publish modified source travels with network use.

## The contributor gate chains a typecheck, a build, an integrity check and six smoke suites

Running locally needs Node.js 22.13 or newer and five commands:

```sh
git clone https://github.com/BOMWiki/partmode.git
cd partmode
npm ci
npm run build
npm start
```

The server then listens on the loopback interface on port 4401, and browser-local CAD needs no account and no external service.

The test story is more interesting than the start story. There is a focused contributor gate:

```sh
npm run ci:gate
```

That one script chains eight steps: a typecheck, the release build, a static integrity check over the built output, and then six smoke suites covering HTTP, account, identity sign-on, the MCP surface, cloud, and the entrypoint.

The scripts are named after CAD feature areas as well as infrastructure. The visible list includes separate checks for advanced mates, mechanical mates, advanced mates in the user interface, assembly constraints, an assembly drawing plan, assembly drawing runtime, and assembly features in the document. One of them chains two files rather than one.

The build step is also unusually honest about ordering. It cleans first, removing the intermediate build directory and the distribution directory, then typechecks for real rather than with emit suppressed, then runs the build script from that freshly created directory.

## A failed rebuild is reported rather than treated as valid geometry

Two sentences in the capability section are the clearest statement of what this project will not do.

The first: templates are editable schema-5 starting projects, not decorative meshes. That rules out the common shortcut where a browser CAD demo ships a pre-baked mesh and calls it a model.

The second: a failed rebuild is reported instead of being treated as valid geometry.

That second sentence is the whole design in miniature. A parametric model is a feature history, and any edit can invalidate the rebuild that turns that history into a solid. A system that quietly keeps the last good shape while the feature tree is inconsistent will let an agent commit a change that looks fine on screen and is not what the parameters say.

Reporting the failure instead means the geometry on screen and the feature history cannot drift apart silently. Combined with the claim that the shaded scene is a view of the result rather than the source of truth, it is the difference between a viewer and a modeller.

The same paragraph also concedes that exact capability coverage varies by template. So the guarantee is about integrity of evaluation rather than about feature parity, which is the right order to promise things in.

## Conclusion

PartMode is a serious attempt at the thing browser CAD usually avoids, which is refusing to treat the rendered scene as the model, and its agent story is built on separating authority from authentication rather than on handing a model a token. Three things to weigh before you rely on it. There is no individual project-delete control on the durable headless path, so committed documents persist until the account itself is deleted. The hosted relay is stated not to be end-to-end encrypted. And DXF export is limited to a restricted R12 orthographic subset while SVG and PDF carry the full sheet, so plan the downstream tool around that rather than discovering it during a handoff.

## FAQ

### What does partmode run on?

A browser, with OpenCascade compiled to WebAssembly performing the geometry and three.js only rendering the result. Browser-local CAD needs no account and no external service, and the local server listens on port 4401 on the loopback interface.

### How do agents get access to partmode?

Through a revocable key created from the account page and stored in the environment that launches the client, never pasted into a prompt, URL, argument or repository file. A key authenticates the agent but does not grant CAD authority by itself.

### How long do partmode headless sessions last?

Live headless sessions are key-bound, expire within one hour, and do not survive a service restart. Only committed headless documents are durable, and those survive session expiry, key revocation, restarts and deployments.

### Can partmode delete a single project?

Not yet. Committed headless records remain until the account is deleted, and the documentation states plainly that there is no individual project-delete control at present.

### Which export formats does partmode support?

STEP import and export, editable PartMode project bundles, and STL, AMF and 3MF meshes. SVG and PDF sheets can carry document-owned dimensions, tolerances, notes, symbols and tables, while DXF is limited to a restricted R12 orthographic or sketch geometry subset.

## Sources

- [BOMWiki/partmode on GitHub](https://github.com/BOMWiki/partmode)
- [License: AGPL-3.0](https://github.com/BOMWiki/partmode/blob/main/LICENSE)
- [Project website](https://partmode.com/)
- [README](https://github.com/BOMWiki/partmode/blob/main/README.md)
- [Releases](https://github.com/BOMWiki/partmode/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bomwiki-partmode
