Here is the awkward truth that most "tldraw is open source" blog posts get wrong: as of tldraw SDK 4.0, released in September 2025, the tldraw SDK is source-available, not open source. The source is public on GitHub and you can read it, fork it, and learn from it. You cannot, however, use it in production without a license key โ a commercial license for commercial use, or a free hobby license for non-commercial use. Development requires no key at all. If you are building a whiteboard feature into a product, that distinction is the entire article.
Why review a not-quite-open-source project in a series about open-source tools? Because the tldraw story is exactly the kind of license trap this series exists to flag, sitting right next to Cal.com's retreat behind a private repository and Directus's shift to a source-available license. tldraw has roughly 47,500 GitHub stars, ships a genuinely excellent infinite-canvas engine, and is used in products you have probably touched. Pretending it is "just another MIT whiteboard" would be the disservice; explaining precisely what you can and cannot do with it is the service.
This review covers what tldraw is, the September 2025 license change and what it broke, the dev-versus-production key model, the watermark that follows your key, how the real-time sync engine actually works (spoiler: not Yjs), what self-hosting still buys you, how it compares to Excalidraw (truly open) and Figma (unapologetically closed), the real cost, and the honest verdict for a sovereignty-minded operator. By the end you should know whether tldraw is a tool you can adopt or a license you must budget for.
1. What tldraw Actually Is
tldraw is an infinite-canvas SDK for building canvas applications in React. You embed the
<Tldraw> component and you get a feature-complete whiteboard engine: draw and diagram with pressure-sensitive strokes, geometric shapes, rich text, arrows, snapping, image and video support, and image export. On top of the raw canvas it layers a runtime editor API, a fully extensible shape-and-tool system, and AI-integration primitives for canvas-aware agents.
The job tldraw takes is "give my app a whiteboard." Where Excalidraw hands you a ready-made open-source whiteboard, tldraw hands you the engine to build your own โ custom shapes, custom tools, custom UI, custom interactions. That is a different product category: Excalidraw is an app you deploy; tldraw is a kit you compile into your app. The 47.5k stars reflect how many developers reached for that kit.
Crucially, tldraw.com โ the hosted product โ is a separate thing built on the SDK, and the SDK is what changed license. When you read "tldraw is open source" on older pages, that was true before v4.0 and is no longer true for the SDK. The rest of this review is about that change and what it means for you.
2. The 47k-Star Paradox
Popularity and license freedom are not the same axis, and tldraw is the cleanest illustration in this series. With 47,500 stars it is one of the most-starred canvas projects on GitHub โ more popular than many unquestionably open-source tools. Yet those stars do not buy you the right to use the SDK in production without a key. Stars measure interest; licenses measure permission, and the two have officially diverged here.
This paradox trips up AI assistants and humans alike. When tldraw audited six major models in mid-2026, every one misstated the license: ChatGPT claimed MIT with checkmarks, GPT-5.5 claimed Apache 2.0, and one model invented a "$20,000 annual revenue threshold" that has never existed in any tldraw license. The models were describing the pre-2025 reality, which is stale now. If you are relying on a chatbot to tell you whether you can ship tldraw, you are relying on a memory of a license that no longer applies.
The lesson is not specific to tldraw: star count is not a license signal, and license pages change. Verify against the current LICENSE.md and FAQ, not against training data or a blog from two years ago. tldraw publishes an llms.txt specifically so assistants can get current info โ use it, and check the date.
3. The License Change of September 2025
In September 2025, with tldraw SDK 4.0, the project moved from its prior open license to the "tldraw license" โ a custom, source-available license. The source remains public on GitHub; use is licensed rather than granted under a permissive or copyleft OSI license. The official framing: "Is the tldraw SDK free to use? In development, yes. In production, mostly no."
What triggered this? The same economics that pushed Cal.com and others: a popular open-source project whose hosted competitors (Figma, Miro) monetize the exact use case the SDK enables, while the SDK's own free availability capped the company's ability to capture value. Rather than go fully closed (like Cal.com's main product), tldraw chose source-available: keep the code public and forkable, gate production use behind a key. It is the softer exit from open source, and it is worth understanding as its own category.
For you, the practical effect: any project that adopted tldraw SDK before v4.0 under the old license kept those rights for that version, but upgrading to 4.0+ means accepting the new license terms. If you are maintaining an older integration, do not blindly bump the version without reading the new LICENSE.md โ the permission you had is not the permission you get.
4. Source-Available, Not Open Source: What That Means Exactly
"Source-available" means the human-readable source code is published and you can read, study, and modify it โ but the license restricts how you may use the modified or unmodified software, typically forbidding commercial production use without a grant. It is not OSI-approved open source, because open source by definition permits use, modification, and distribution for any purpose, including commercial.
tldraw's source-available license lets you: fork the repo, read the code, learn from it, build and test in development, and contribute. It does not let you: deploy it to production for commercial purposes without a commercial license key, or (depending on terms) remove the attribution/watermark without the appropriate key. The exact prohibitions live in LICENSE.md, and that is the document that governs, not a summary.
Contrast with the spectrum in this series: Excalidraw is MIT (permissive open source, do anything), BookStack is MIT, Wiki.js is AGPL-3.0 (open source with network copyleft), and tldraw is now source-available (public code, restricted use). tldraw sits outside the open-source set by the strict definition, which is why this review carries the caveat in its first sentence rather than its last.
5. License Keys: Development Is Free, Production Needs One
The key model is two-tier. In development, the tldraw SDK requires no license key at all โ you install it, build locally, iterate, and ship nothing. This is deliberate: the project wants developers to learn and prototype without friction, and the friction only appears at the deployment boundary.
In production, you need a key. For commercial use, that means a commercial license, which is a paid arrangement with tldraw, LLC. For non-commercial use (a personal project, a classroom tool, an internal non-revenue effort depending on the terms), a free hobby license exists. The key is supplied to the SDK via a
licenseKey prop on the <Tldraw> component, and it determines both permission and branding.
The operational takeaway: "free to try" is real and generous; "free to ship" is conditional. Budget for a license decision before you architect tldraw into a revenue product, because the cost appears at launch, not at install. Discovering the key requirement in production is the classic, avoidable mistake.
6. The Watermark and What Your Key Controls
The "made with tldraw" watermark is the visible marker of the license tier. With the free hobby license, the watermark appears on the canvas. With a commercial license, the watermark is removed via the same
licenseKey prop โ there is no separate hideWatermark toggle (a commonly suggested but nonexistent API). The watermark follows the key, not a configuration flag.
This is a clean, honest model: the attribution is the price of free non-commercial use, and paying removes it. For a hobby or educational canvas, the watermark is a fair trade. For a polished commercial product, you will want it gone, which means the commercial key. There is no hiding it through a prop that does not exist, and any tutorial suggesting otherwise is stale or wrong.
The sovereignty angle: the watermark is a branding signal, not a data-exfiltration mechanism. It tells viewers the canvas is powered by tldraw; it does not (per the published model) send your drawing contents anywhere. Your shapes and strokes are yours; only the attribution is tldraw's. Keep that distinction clear when evaluating the trust posture.
7. tldraw Sync: Its Own Engine, Not Yjs
Real-time multiplayer in tldraw runs on tldraw sync โ the
@tldraw/sync and @tldraw/sync-core packages โ not on Yjs, despite what several AI models confidently claimed. The server keeps the authoritative document and reconciles diffs from clients; it is deliberately not a CRDT, because the maintainers argue general-purpose CRDTs are a poor fit for canvas data. (This is the same OT-versus-CRDT philosophical split seen in HedgeDoc elsewhere in this series.)
You can bring your own collaboration backend. tldraw sync is the recommended engine, but the store exposes change listeners that let you bridge to anything โ Liveblocks ships an official integration, and you can pair tldraw with Yjs if your stack already depends on it. The SDK is collaboration-backend-agnostic at the integration layer even though its first-party engine is sync.
For the operator, multiplayer means running a sync server (the
@tldraw/sync service) or using a managed/hosted sync, and owning the persistence of document state. The self-hosted story for collaboration is real but is a deployment you run, not a feature that appears by installing the component.
8. The SDK and the React Component Model
tldraw is a React-first SDK. You render
<Tldraw /> inside a positioned div, import the CSS, and the canvas is live. The extensibility model is the differentiator: custom shapes (your own node types), custom tools (your own interactions), custom bindings, custom UI (panels, menus, side effects), and event hooks. This is why tldraw is a kit, not an app โ you compose it into your product's look and behavior.
The cost of that power is React coupling and a learning curve. If your stack is not React, tldraw is the wrong tool; it assumes React as the host. The editor API is rich but large, and building a polished custom shape system takes real engineering, not a config file. For "drop in a whiteboard," Excalidraw's embed is lighter; for "build a canvas app that is unmistakably ours," tldraw is the stronger foundation.
Version currency matters: tldraw moves fast (v5.0.2 in May 2026, after the v4 license change), and the API has evolved. Pin a version, read the migration notes between majors, and treat the editor API as a surface you track, not a stable constant you can ignore for years.
9. Starter Kits: The MIT-Licensed Escape Hatch
One nuance worth stating: tldraw's starter kits โ the prebuilt custom-shape, tool, and UI templates that accelerate building common canvas apps โ are MIT-licensed. So the scaffolding and examples you learn from are permissively open, even though the core SDK is source-available. You can use, modify, and redistribute the kits freely; the restriction is on the core engine in production.
This matters because the starter kits are how most people actually start.
npx create-tldraw@latest scaffolds a project using MIT-licensed templates, and you build your app on top. The license boundary is between "the kit (MIT)" and "the engine it imports (source-available)." Knowing that line prevents the confusion of "the starter is MIT, so the whole thing is free to ship" โ it is not; the engine still needs a key.
For learning and prototyping, the MIT kits mean the barrier to understanding tldraw is essentially zero. For shipping, the engine license is the gate. Hold both facts; do not let one cancel the other.
10. Self-Hosting the Canvas: Where Your Data Goes
Here is the part that preserves tldraw's appeal for sovereignty-minded builders: when you self-host, your canvas data lives on your infrastructure. The shapes, strokes, documents, andๅๆญฅ state persist where you put them โ your server, your database, your object store. tldraw the company does not harvest your users' drawings through the SDK. There is no mandatory cloud round-trip for the content you create.
The nuance is persistence and sync. If you use tldraw's hosted sync service, document state lives with tldraw; if you self-host
@tldraw/sync and persist to your own store, it lives with you. The sovereignty outcome is therefore a deployment choice, exactly like every other tool in this series: self-host the sync and storage, and the data is yours; use the managed sync, and a slice lives with the vendor.
For a team that wants a whiteboard on owned infrastructure, self-hosting tldraw sync is viable and keeps custody. The license gate is about permission to ship, not about where bytes reside โ and that distinction is why tldraw can still fit a sovereignty strategy even though it is not open source.
11. Multiplayer Architecture: Bring Your Own Backend
The collaboration model deserves its own section because it shapes your deployment. tldraw sync keeps the server authoritative: clients send changes, the server holds the canonical document, and reconciles. This is simpler to reason about than a peer-to-peer CRDT mesh and gives you a single place to enforce persistence and access control โ but it means you run a sync service, not just a static bundle.
You have options. Run the first-party
@tldraw/sync server (self-hosted, your data). Use a managed sync offering if you would rather not operate it. Or bridge to an existing realtime backend via the store's change listeners. Each trades operational burden against control; the self-hosted first-party path maximizes sovereignty and minimizes vendor dependency, at the cost of running another service.
The architectural honesty: multiplayer is never free. Whether it is tldraw sync, Yjs, Liveblocks, or a custom websocket, real-time collaboration is a stateful service you operate or pay for. tldraw makes the self-hosted option first-class, which is a point in its favor even within the license caveat โ they did not lock collaboration behind the paid tier's servers exclusively.
12. tldraw Versus Excalidraw: The Honest Open-Source Contrast
This is the comparison every reader of this series wants, and it is stark. Excalidraw (covered earlier here) is MIT-licensed, genuinely open source, and ships as a deployable whiteboard app you can self-host freely with no license key and no watermark. tldraw's SDK is source-available, requires a production key, and shows a watermark on the free tier. If "must be OSI open source, no strings" is your hard requirement, Excalidraw wins outright.
But the tools are not substitutes in capability. Excalidraw is a hand-drawn-style whiteboard app โ great for sketching, diagrams, and quick shared boards, with an open-source app you deploy. tldraw is an SDK for building custom canvas applications with rich extensibility. If you need to embed a whiteboard as-is, Excalidraw is lighter and freer. If you need to build a canvas product with custom shapes and tools, tldraw's engine is the stronger kit โ at the license cost.
The strategic read: use Excalidraw when "open-source whiteboard app" is the job; evaluate tldraw when "canvas engine for our product" is the job, and price the license into the build. Do not choose tldraw expecting Excalidraw's freedom, and do not dismiss tldraw because it lacks that freedom โ they solve different problems at different license costs.
13. tldraw Versus Figma and Miro: The Closed Competition
Against the proprietary incumbents, tldraw's source-available model looks almost open. Figma and Miro are fully closed SaaS: your designs and whiteboards live on their infrastructure, their formats are proprietary, and your only exit is export. tldraw, even licensed, gives you public source, forkability, self-hosted data, and an open-ish format (the document is a JSON you control).
This is why tldraw still belongs in a sovereignty conversation: relative to Figma/Miro, it is dramatically more owner-friendly. You can self-host, you can read the code, you can persist your own documents, and you are not locked to a vendor's format or uptime. The license key is a toll on the bridge, but the road on either side is yours โ unlike the walled garden of the closed competitors.
For a team evaluating "should we use Figma/Miro or build on tldraw," the calculus is: closed SaaS convenience and polish versus owned infrastructure and a license fee. tldraw is the sovereign-leaning option among the three, even with its source-available caveat. That nuance is the whole point of reviewing it here rather than dismissing it for not being MIT.
14. The Real Cost: Free to Build, Priced to Ship
Let us be concrete about money. Development with tldraw is free โ no key, no watermark, no meter. Non-commercial production may be free under the hobby license, subject to its terms and with the watermark. Commercial production requires a commercial license, the price of which is set by tldraw, LLC and depends on your arrangement; treat it as a line item to request a quote for, not a published number you can plan around blindly.
The hidden costs are operational. Running tldraw sync, persisting documents, scaling WebSocket connections, and maintaining a React app are real engineering and infrastructure expenses regardless of the license fee. For a small team, the total cost of a self-hosted tldraw canvas can exceed the license fee many times over in engineering time. The license is the visible tip; the build-and-run cost is the iceberg.
Compared to "just use Figma," tldraw's total cost of ownership is higher for a simple need and potentially lower for a deeply integrated one โ because you avoid per-seat SaaS pricing at scale. The honest framing: tldraw is cheap to try and expensive to do well, with a license toll at the production gate.
15. The Open-Source Expectation Versus the License Reality
The uncomfortable lesson tldraw teaches is about expectation drift. A project earns 47k stars as "the open-source whiteboard," and when it changes license, the stars remain but the permission changes. Developers who adopted it under the old terms, or who read old tutorials, carry an entitlement the current license does not grant. That gap between reputation and terms is where expensive mistakes happen.
This is precisely why this series documents license changes rather than assuming them. Cal.com went private-repo-and-closed; Directus moved to a source-available license; InfluxDB split core-open from enterprise-closed; tldraw went source-available with a key. Each is a different shape of the same phenomenon: open-source momentum does not guarantee open-source permanence, and the license file at your version is the only truth.
For your own stack, the discipline is to re-verify licenses on every major version bump, not once at adoption. A tool that was free to ship two years ago may not be today, and the diff lives in LICENSE.md, not in the star count or the old blog post. tldraw is the clearest case study in this series of that rule.
16. When You Should Still Use tldraw
Despite the license caveat, there are clear cases for tldraw. If you are prototyping or building a non-commercial canvas and never shipping it for revenue, the free dev and hobby tiers cover you with no cost. If you are building a commercial canvas product and the source-available license's terms fit your budget, the engine's quality and extensibility are best-in-class. If sovereignty of data matters and you self-host sync, your users' drawings stay on your infrastructure.
The decision is cleanest when framed as: do I need a customizable canvas engine, and am I willing to either stay non-commercial or pay for the commercial key? If yes to both, tldraw is an excellent choice. If you need a free-to-ship open-source whiteboard specifically, Excalidraw or a self-hosted alternative is the honest pick instead.
The trap to avoid is adopting tldraw on open-source assumptions and discovering the key requirement at launch. Decide the license posture before you write the first shape, and tldraw's quality shines without surprises.
17. Data Sovereignty With tldraw Sync
Sovereignty with tldraw is a deployment decision, and it is worth stating precisely. Self-host
@tldraw/sync, persist documents to your own database or object store, and your canvas content never leaves your infrastructure. The SDK does not phone your users' drawings home to tldraw; custody is yours by architecture, not by favor.
The boundaries to enforce: use self-hosted sync, not the managed service, if vendor custody is unacceptable; encrypt the document store at rest; back it up like any production datastore; and control access at your own auth layer, since tldraw sync is the server you operate. These are the same sovereignty practices every self-hosted tool demands, and tldraw fits them when you operate the sync yourself.
The residual dependency is the license, not the data path. Even with a commercial key, a self-hosted tldraw deployment keeps your content on your systems โ you are paying for permission, not for custody. That separation is why tldraw can satisfy a data-sovereignty requirement even while failing a strict open-source-purity requirement.
18. Security and Supply-Chain Posture
A source-available project with public code has a supply-chain advantage: you can read exactly what the SDK does, audit the sync server, and pin to a specific commit or version. tldraw maintains modern tooling hygiene โ supply-chain release gates, dependency updates via Renovate, and a public changelog โ which is reassuring for an ingredient you embed in a product.
The caveat is the license boundary's interaction with modification. Because the SDK is not OSI open source, modifying and redistributing it in production is governed by the tldraw license, not by a permissive grant. If your security response to a vulnerability requires forking and shipping a patched SDK, you need to do so within the license's terms โ which may mean coordinating with tldraw rather than unilaterally redistributing. For most, staying current on the official releases is the path; just know your fork-and-fix rights are narrower than with MIT.
Operational security is standard: run sync behind your reverse proxy and auth, encrypt transport, and monitor the WebSocket service like any stateful endpoint. The engine itself is well-engineered; your job is the perimeter and the persistence layer.
19. tldraw.com Versus Self-Hosted
tldraw.com is the hosted product built on the SDK, and it is a different relationship from self-hosting. Using tldraw.com means your boards live on tldraw's infrastructure under their terms โ convenient, polished, and vendor-custodied, much like Figma. Self-hosting the SDK means you run the canvas and sync yourself, owning the data but owning the operations too.
The choice mirrors the Excalidraw decision: hosted Excalidraw versus self-hosted Excalidraw. Convenience and zero-ops versus custody and control. With tldraw, the self-hosted path additionally requires the production license key, so the "self-hosted" option is not the "free" option โ it is the "owned-data, licensed-engine" option. Name that clearly so nobody conflates self-hosting with license-free.
For most readers building a product, self-hosted tldraw (with key and sync) is the sovereignty-preserving path; tldraw.com is the quick-start that trades custody for speed. Both are legitimate; the mistake is assuming they share a license and a data story when they do not.
20. Governance: A Single Vendor
tldraw is a single-vendor project of tldraw, LLC โ a company, not a foundation. That is the same governance shape as VictoriaMetrics, InfluxDB, and most commercial-open-source hybrids in this series, and it carries the same implication: the license and roadmap follow one company's business needs, which is exactly why the v4.0 license change happened.
The counterweight is transparency. tldraw publishes its license plainly, maintains public source, ships an llms.txt for current docs, and communicates changes through official channels. A single vendor that changes license abruptly but openly is preferable to one that does so silently โ and tldraw's change was explicit and dated. You can plan around a known change; you cannot plan around a hidden one.
For your stack, single-vendor governance means the license could change again. Build with the assumption that the terms you accept today are not guaranteed permanent, and keep an exit path (your document format is JSON; migration is a data-transformation problem, not a format-lock problem). That exit path is your insurance against the next license shift.
21. Who Should Use tldraw โ and Who Should Not
Use tldraw if you are building a custom canvas application and accept the license model: non-commercial free, commercial licensed. It is the best-extensible canvas engine in this comparison, and self-hosted sync keeps your data sovereign. If your team lives in React and needs custom shapes and tools, it is the right kit.
Do not use tldraw if you require an OSI open-source whiteboard with no key and no watermark โ that is Excalidraw, not tldraw. Do not adopt it on stale "it's MIT" information; verify the current LICENSE.md. And do not assume self-hosting equals free; the engine still needs a production key.
The aggregate verdict: tldraw is not open source by the strict definition, but it is source-available, self-hostable, data-sovereign, and excellent โ a qualified yes for builders who price the license deliberately, and a clear no for those who need unconditional open-source freedom. It belongs in this series precisely as the cautionary, nuanced case.
22. Migration and Exit Strategy
The strongest sovereignty guarantee tldraw offers is format ownership. A tldraw document is a JSON structure โ shapes, pages, and metadata โ that you persist yourself when you self-host sync. That means your whiteboard content is not trapped in a proprietary binary; it is data you can transform. If you ever need to leave tldraw (a future license change, a business decision), the exit is a JSON-to-JSON migration, not a format breakout.
The practical discipline is to keep your document store exportable. Snapshot the JSON regularly, and write a small transformer if you need to move shapes into another canvas system. Because the schema is documented and public, this is a tractable engineering task, not a vendor-lock extraction project. Contrast that with Figma, where the source of truth is the vendor's format and your exit is export-and-lose-fidelity.
This exit path is your insurance against the single-vendor governance risk named above. tldraw can change its license again; your data does not have to move an inch when it does, because you already hold it in a portable form. That is the difference between being licensed and being locked, and tldraw keeps you in the former camp as long as you self-host the store.
23. Performance and Scale
A canvas app lives or dies on interaction smoothness, and tldraw's engine is built for it: it renders to the DOM canvas, supports pressure-sensitive input, and handles thousands of shapes with viewport culling. For typical collaborative whiteboarding โ tens to low hundreds of participants and moderate shape counts โ it is fluid. The limits appear at extreme scale: enormous boards, very high shape counts, or hundreds of simultaneous editors stress the sync server and the client render loop.
Scaling multiplayer means scaling your sync deployment. tldraw sync is a stateful service; more concurrent rooms and editors mean more connections, more memory, and more reconciliation work on the server. Horizontal scale requires running multiple sync instances behind a router and a shared persistence layer, which is standard real-time infrastructure but is real operations. Plan capacity from expected concurrent rooms, not from total registered users.
The honest note is that tldraw gives you the engine, not the autoscaling. At small and mid scale it is effortless; at company-all-hands-on-one-board scale it is an infrastructure project. Size it like any stateful service, and the canvas stays smooth exactly as far as your sync tier reaches.
24. The Bottom Line
tldraw is the 47.5k-star infinite-canvas SDK that you can read, fork, and prototype with for free โ but cannot ship to production without a license key, because since v4.0 (September 2025) it is source-available, not open source. Development is free, non-commercial production may use the free hobby tier with a watermark, and commercial production requires a commercial license. The watermark follows your key; the sync engine is tldraw's own, not Yjs; and self-hosting keeps your canvas data on your infrastructure.
Place it on the license spectrum honestly: to the right of Excalidraw's MIT freedom and to the left of Figma's closed garden. It is the cautionary, nuanced entry in this series โ proof that star count is not a license signal and that verifying LICENSE.md at your version is the only truth. Use it when you need a customizable canvas engine and will price the key; reach for Excalidraw when you need a free, open-source whiteboard app. Either way, own the decision before you ship, because tldraw will not tell you after. The stars will still say 47k; only the LICENSE.md will say what you may do, and that is the document that should decide. Read it at the version you deploy, not the version you remember, and the 47k-star whiteboard becomes a calculated choice instead of a surprise bill.
Related
For the rest of a sovereignty-minded, license-aware stack, these pieces from our series travel with tldraw:
- Excalidraw: The Open-Source Whiteboard You Can Actually Ship โ the MIT-licensed alternative when unconditional open source is the requirement tldraw no longer meets.
- Cal.com: The AGPL Star That Went Closed Source โ the companion cautionary tale of a beloved open project retreating behind a paid wall.
- Directus: The Database-First CMS That Changed Its License โ another source-available pivot, and how to evaluate the threshold that triggers a paid license.
- InfluxDB: The Rust Rewrite That Split Open and Closed โ the core-open, enterprise-closed split as a different shape of the same phenomenon.
- Caddy: The Web Server That Encrypts for You โ the reverse proxy to publish your self-hosted tldraw sync over TLS without touching Certbot.
Comments (0)
No comments yet. Be the first to comment!