Six packages across three languages, one open specification, and a full server runtime. Everything you need to produce, distribute, validate, sign, and consume Smart Document Format files — from a single npm install to a self-hosted enterprise deployment.
Architecture
SDF is a ZIP container. Producers bundle a human PDF and machine JSON together, sign the archive, and distribute it.
Consumers call parse() once and get typed, validated data — no OCR, no regex.
Provide your JSON data + existing PDF, or generate the PDF from the data. The SDK assembles the ZIP and signs it with your private key.
A ZIP archive with a .sdf extension. Four layers, always the same structure.
Recipients call parse() once. Schema-validated, fully typed structured data comes back. Verify the signature offline, 20 years from now.
Packages
Every package is independently versioned and installable.
Start with sdf-kit for TypeScript, etapsky-sdf for Python, or the CLI for scripting.
Core producer, reader, validator, and signer. The primary TypeScript/JavaScript library for every SDF operation.
Full-featured CLI: inspect, validate, sign, verify, keygen, wrap, convert, schema. Homebrew tap and binary releases for macOS, Linux, Windows.
Schema lifecycle management: diff engine, migration planner, and offline bundle support. JSON Schema Draft 2020-12 throughout.
Fastify 5 server with multi-tenant REST API, BullMQ async queue, S3/MinIO storage, per-tenant rate limiting, and ERP connectors.
Full-featured Python SDK with producer, reader, validator, and signer. Feature parity with the TypeScript SDK for data science and backend Python workflows.
17 sections, 1,200+ lines. The normative reference for any SDF implementation. Covers container format, signing, schema bundling, verification, and conformance.
Integrations
sdf-server-core ships with production-ready adapters for the most common enterprise infrastructure layers.
Specification
The SDF Format Specification is the source of truth for every implementation. Any conforming producer and consumer can interoperate, regardless of SDK language or version.
Security
Every SDF file is cryptographically signed at production time. Verification requires no network call — the schema and signature are bundled inside the archive.
Default signing algorithm. Compact signature, hardware-accelerated on modern CPUs via Web Crypto API.
Legacy-compatible signing for enterprises that require RSA. Drop-in alternative via config.
The schema bundle inside the archive means consumers can verify 20 years from now with no network call.
Generate, rotate, and revoke keys via the CLI or REST API. Per-tenant key isolation in server deployments.
Roadmap
The TypeScript and Python SDKs are stable and production-ready. Additional language SDKs and the ISO standardization process are underway.
Start with npm install @etapsky/sdf-kit — open source, works offline.
For hosted infrastructure or enterprise support, reach the team.