Inputs and temporary results
Uploaded and downloaded source PDFs are temporary processing inputs. They are not kept as permanent uploads. Generated PDFs are stored for download for up to one hour, then expire. Processing failures can cause earlier cleanup.
Results use unpredictable UUID filenames under https://pdf.pokt.online/results/. A result URL acts as a bearer link: anyone who obtains it can download that PDF until it expires. Expiration is not a substitute for access control. Download needed results promptly and share links deliberately.
Passwords
Generated PDFs are unencrypted unless the encrypt operation is selected, even when an input is encrypted. Anyone who obtains an unencrypted output link can read its PDF until the link expires.
Send a password only when an input is encrypted or the encrypt operation needs new passwords. The browser console uses password controls, does not save them to local storage, does not log or render the request body, and clears the controls after a request. No wallet credentials are needed.
Passwords still travel to the processing service over HTTPS. Use the service only for PDFs you are authorized to process, and choose documents appropriate for a public test environment.
Restricted URL fetching
URL inputs must use public HTTPS destinations. Loopback, private, link-local and other non-public addresses are prohibited. Destination addresses are checked to limit server-side request forgery; redirects are restricted and checked as well. Byte and time limits apply while downloading.
Only allowlisted operations and fixed JSON parameters are accepted. Requests cannot specify command-line arguments, executable names, local paths or arbitrary filesystem destinations. The console proxy permits only the supported PDF contract and bounded uploads.
PDF operations have boundaries
- Rewriting a PDF invalidates its existing digital signatures. Retain signed originals when signatures matter.
- Encryption protects access with passwords; it does not remove malicious, private or unwanted content.
- Metadata removal covers document information (DocInfo) and XMP metadata. It is not redaction and does not remove visible text, embedded attachments or all possible identifying content.
- Structural checking is not a malware scan, a full conformance certification or a guarantee that every viewer will render the same result.
- Repair can rewrite recoverable structure. It cannot recreate missing or lost content.
- Linearization and structural optimization can increase file size and do not guarantee better rendering or compression.
Bounded browser demo
The Test Console sends requests through a same-origin proxy with a temporary browser session token. Its limits are 10 MB per input, 20 MB combined, 5 merge inputs, 100 combined pages, a 30-second deadline and one in-flight request. It sends no blockchain relays.
The API contract allows up to 50 MB per input, 100 MB combined, 10 merge inputs, 500 combined pages and a 60-second deadline. Excess work is rejected rather than allowed to run without bounds. See the limits and error guide for integration behavior.