# draw.io: running the client-side diagram editor yourself

> draw.io is a browser-based diagramming editor whose source ships in jgraph/drawio under Apache-2.0, with self-hosting through GitHub Pages, Docker or a packaged .war. The licence covers the code, not the icon and stencil libraries, and the project does not accept pull requests.

**jgraph/drawio** — draw.io is a JavaScript, client-side editor for general diagramming.

- Repository: https://github.com/jgraph/drawio
- Website: https://www.drawio.com
- Stars: 8,474 · Forks: 1,275
- Language: JavaScript
- License: Apache-2.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/jgraph-drawio

## What draw.io solves, and who ends up hosting it

General diagramming tends to split into two bad options. Desktop tools keep files in a proprietary format that is awkward to diff or embed in a web page. Hosted services solve that but put your architecture diagrams on someone else's servers. draw.io sits in between: it is a JavaScript, client-side editor, so the drawing work happens in the browser, and the repository gives you the source to serve it yourself.

The README describes it as "a configurable diagramming and whiteboarding application, jointly owned and developed by draw.io Ltd (previously named JGraph) and draw.io AG." The same team runs a production deployment at app.diagrams.net, so the public instance and the self-hosted build come from the same codebase. The audience is therefore fairly specific: engineers and platform teams who want diagramming inside their own network, plus anyone who wants a free editor and does not care where it runs. If you only need to draw a flowchart occasionally, the hosted app is the shorter path.

## Client-side rendering and where the integrations live

The editor runs in the browser. The repository is dominated by a src/ directory alongside etc/, docs/ and a handful of top-level files such as VERSION, ChangeLog and LICENSE. Nothing in the README describes a server-side rendering component, which matches the client-side description: the browser holds the model and draws the canvas, and a static file host is enough to serve it.

That shape explains the deployment options. Forking the repository and publishing it to GitHub Pages gives what the README calls a "fully functional editor" at the path src/main/webapp/index.html, explicitly "without integrations". The integrations, meaning the connectors that let draw.io open inside other products, are not part of that static build. If your requirement is Confluence or VS Code embedding, the self-hosted static copy is not the thing that provides it; the README points those questions at the issue tracker and discussions rather than documenting a self-hosted integration path.

One scope note matters for expectations. The README states plainly that draw.io "is not an SVG editor" and that SVG export is for embedding in web pages, not for editing in other tools. If your pipeline needs round-tripping through another vector editor, this is the wrong layer.

## Installing draw.io: GitHub Pages, Docker or a .war

The README lists three ways to run it. The first is a fork published to GitHub Pages, which the README links to a working example at jgraph.github.io/drawio/src/main/webapp/index.html. The second is the official Docker image, which lives in a separate repository, jgraph/docker-drawio. The third is draw.io Desktop, downloaded from get.diagrams.net. Packaged .war files are published on the releases page.

The Docker route is the one most teams will reach for, but note the boundary: the image is built and documented in jgraph/docker-drawio, not in this repository, so the run command and its environment variables belong to that project. What jgraph/drawio gives you is the source and the release artifacts.

If you go the Pages route, the working tree is served as static files and the entry point is the file the README names:

```bash
git clone https://github.com/jgraph/drawio.git
cd drawio
# serve the webapp directory as static files, entry point:
# src/main/webapp/index.html
```

The README also pins the browser floor, which is worth checking before you roll this out to a fleet: Chrome 123+, Firefox 120+, Safari 17.5+, Opera 109+, Edge 123+, WebView Android 137+ and Safari iOS 18.5+. Older browsers are outside the supported set, and the README does not describe a fallback mode for them.

## The licence covers the code, not the stencils

Apache-2.0 applies to the source code. The icon sets, stencil libraries and diagram templates are carved out with a separate restriction, quoted in the README: they "may not be used as software assets in, distributed for use with, or incorporated into Atlassian products or products distributed through the Atlassian marketplace or plugin ecosystem, without explicit written permission." The carve-out explicitly covers derivatives, conversions, traced reproductions, substantially similar visual representations and AI-generated images made using the icons as reference or training input.

The escape hatch is the output. The same clause says the restriction "does not apply to end-user diagram output (such as exported images or documents) created using this software." So a diagram you export and ship is fine; the stencil library itself is not something you can repackage. The README adds that some icons originate with third-party copyright holders whose licences were checked for compatibility, and that bundled JavaScript libraries are all Apache-2.0 compatible with no GPL or AGPL among them. It also states the project makes no copyright claim on diagrams you create.

Trademark is separate again. draw.io is a registered EU trademark (#018062448), and the README prohibits using the name or logo in ways suggesting affiliation, endorsement or sponsorship, using the logos for your own business or domain, or modifying them, all without prior written permission. If you fork and host this internally, the branding rules still apply to how you present it. This is a summary of what the README says, not legal advice.

## No pull requests, and no real-time collaboration

The contributions policy is the sharpest limitation. The README states: "We do not accept pull requests. The project is developed entirely by the core team." If your team patches the editor, you are maintaining a fork. Upstream will not carry your change, and every release you rebase onto is your problem. That is a real cost for anyone whose requirements diverge from the core team's roadmap, and it is the main reason to think twice before building a product on top of this repository.

The second limitation is stated just as directly. The README notes that draw.io "does not support real-time collaborative editing in this version, currently." Two people cannot edit the same diagram live in the way a shared document works. Teams that need that behaviour have to look elsewhere or accept sequential editing and file handoff.

The third is scope. Because it is a diagramming and whiteboarding application and not an SVG editor, and because the static Pages build ships "without integrations", anyone expecting a drop-in Confluence or IDE plugin from this repository will not find it here. The README routes those questions to the issue tracker and discussions rather than promising a self-hosted integration path.

## How draw.io differs from Excalidraw and from diagram-as-code tools

The closest alternative in spirit is Excalidraw, another browser-based, client-side drawing tool. The difference is in what the canvas is for. Excalidraw's visual language is a hand-drawn sketch, which suits whiteboarding and early architecture conversations. draw.io's model is structured diagramming with stencil libraries, which suits UML, network topology and flowcharts that need to look deliberate. The repository's own topic list, diagram, javascript, whiteboard, covers both ends, but the stencil libraries are the part Excalidraw does not try to match, and they are also the part under the extra licence restriction described above.

A different comparison is diagram-as-code tooling such as Mermaid or Graphviz. Those take text and render a diagram, which makes the source reviewable in a pull request. draw.io is a direct-manipulation editor; the file is the artifact, not the source text. If your team wants diagrams to live in version control as readable diffs, a text-first tool fits better. If you want to place shapes precisely and reuse a stencil set, the editor model wins. Neither approach substitutes for the other, and the README makes no claim about a text-based workflow.

## Upgrade cost and who should adopt it

Maintenance looks steady. The last push to the dev branch was on 2026-09-16, and releases v31.4.4, v31.4.5 and v31.4.6 were published between 2026-09-06 and 2026-09-16. The repository is not archived. What the README does not document is a supported upgrade path: there is no migration guide, no versioned API contract and no rollback procedure described. Packaged .war files appear on the releases page, so a redeploy is the assumed mechanism, but the README does not say what happens to stored diagrams across a version jump.

That is the practical cost. Because pull requests are not accepted, an upgrade means taking the new source or the new .war and reapplying whatever local changes you made. Because the integrations are out of scope for the static build, an upgrade does not bring them along. Because the stencil and icon terms are separate from Apache-2.0, an upgrade can change what you are allowed to redistribute without changing the code licence.

Adopt it if you want a self-hosted, client-side diagram editor and you are comfortable running a fork you do not upstream. Do not adopt it if real-time collaboration is a requirement, if you need a text-based diagram format, or if you intend to bundle the stencil libraries into an Atlassian product. Before you commit, check the browser floor against your fleet, read the icon and stencil clause against your distribution model, and decide how you will track the releases page for rebuilds.

## Conclusion

Adopt jgraph/drawio if you need a general diagramming and whiteboarding editor you can host yourself and you accept that the core team develops it without outside pull requests. Do not adopt it expecting real-time collaborative editing, which the README says this version does not support, or if you plan to redistribute its icon sets inside Atlassian products without written permission. Before committing, verify three things: that your browser meets the minimum versions listed in the README, that the icon and stencil terms fit your distribution model, and how you will rebuild after an upstream release, since the repository ships .war files on its releases page rather than a package manager.

## FAQ

### Is draw.io still free?

The source code in the repository is licensed under Apache License 2.0, and the project runs a production deployment at app.diagrams.net. The icon sets, stencil libraries and templates carry a separate restriction on redistribution, but the README says that restriction does not apply to end-user diagram output you create.

### Is draw.io safe to install?

The README does not make a security claim about the installers. It does state that bundled third-party JavaScript libraries all have licences compatible with Apache 2.0, with no GPL or AGPL among them, and the repository includes a SECURITY.md file.

### What can I open a drawio file with?

The README does not document the file format or list other applications that can open it. It does say draw.io is not an SVG editor and that SVG export is intended for embedding in web pages rather than for editing in other tools.

### how to install drawio

The README lists three options: fork the repository and publish it to GitHub Pages for a fully functional editor without integrations, use the official Docker image from jgraph/docker-drawio, or download draw.io Desktop from get.diagrams.net. Packaged .war files are also available on the releases page.

### how to use drawio in confluence

The README does not document a Confluence integration. It notes that the GitHub Pages build is a fully functional editor "without integrations", and it directs issues or questions about the editor in any draw.io product to the issue tracker and discussions.

### what is drawio

The README describes draw.io as a configurable diagramming and whiteboarding application, jointly owned and developed by draw.io Ltd and draw.io AG. It is a JavaScript, client-side editor for general diagramming, and the same team runs a production deployment at app.diagrams.net.

## Sources

- [jgraph/drawio on GitHub](https://github.com/jgraph/drawio)
- [License: Apache-2.0](https://github.com/jgraph/drawio/blob/dev/LICENSE)
- [Project website](https://www.drawio.com)
- [README](https://github.com/jgraph/drawio/blob/dev/README.md)
- [Releases](https://github.com/jgraph/drawio/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/jgraph-drawio
