CSPP WOPI

How Does SuperDoc v2 Compare to CSPP WOPI? Choosing an Embedded Document Editing Architecture

How Does SuperDoc v2 Compare to CSPP WOPI? Choosing an Embedded Document Editing Architecture

If you want users to edit Word documents inside your product, two very different architectures are on the table.

One is WOPI, the protocol that lets Microsoft’s own Office for the web edit files your service stores. For third-party storage, it is available through the Microsoft 365 Cloud Storage Partner Program (CSPP).

The other is SuperDoc, a DOCX editor that runs as a JavaScript component inside your own web application, with no Microsoft service in the editing path. Its v2 release moved the editor onto an OOXML-native document engine.

Both put Word editing inside your product. They differ in almost everything else:

  • who provides the editor
  • who may use it
  • what your users need to be licensed for
  • where the document is processed
  • how much of the experience you control
  • what it takes to reach production

McKenna Consultants has implemented WOPI in .NET Framework, .NET Core, Java, Node and PHP for many years, and we are currently implementing SuperDoc for a SaaS company in the audit sector. This CSPP WOPI comparison sets the two side by side on the dimensions that decide real projects. If either is new to you, start with What Is WOPI? and What Is SuperDoc?

The Two Architectures in Brief

CSPP WOPI. In Microsoft’s words, “The WOPI protocol lets Microsoft 365 for the web access and change files that are stored in your service.” Your service becomes a WOPI host, with two jobs.

First, it implements “REST endpoints that Microsoft 365 for the web uses to learn about, fetch, and update files”. At a minimum that means CheckFileInfo and GetFile, and editing adds PutFile and the lock operations.

Second, it provides a host page “that contains an iframe element within it” pointing at Office for the web. Microsoft’s servers fetch the file from your endpoints, run Word, Excel or PowerPoint for the web, and save changes back. Every request is signed: “Microsoft 365 for the web signs every WOPI request with a private key”, and your host verifies the signature with the proof key published in Microsoft’s discovery XML.

SuperDoc v2. SuperDoc is a library you install from npm and mount in your page. Its documentation says “The Editor runs in the browser and needs no SuperDoc server to render or edit a document.” Your application loads the DOCX bytes, SuperDoc’s engine reads the OOXML package into editable state, and your application saves the exported bytes wherever it likes. As SuperDoc puts it, “Your application decides where documents come from, who can access them, and where changes are saved.”

The fundamental difference follows from that. With WOPI, you integrate Microsoft’s editor service with your storage. With SuperDoc, you embed an editor component in your application.

SuperDoc vs WOPI at a Glance

Dimension CSPP WOPI (Office for the web) SuperDoc v2
Editor Microsoft’s Word, Excel and PowerPoint for the web SuperDoc’s DOCX editor, hosted by you
File types Word, Excel and PowerPoint Word documents (DOCX)
Who can adopt it CSPP members: ISVs “whose business is cloud storage”, reviewed individually by Microsoft Anyone; AGPLv3 or commercial licence, plus the proprietary DOCX Engine licence
Route to production Application, onboarding, Microsoft verification, domain allow-listing Your own release process
End-user licensing Editing requires a Microsoft 365 licence; read-only does not No Microsoft licence involved
Where documents are processed Microsoft 365 for the web, which “keeps a temporary copy of the file being viewed and edited” In the browser and on infrastructure you choose
Interface control Microsoft’s interface inside your host page Built-in UI, configured UI, or entirely your own
Co-authoring Built in, and mandatory for CSPP hosts Yjs-based rooms through a provider you run or subscribe to
Programmatic editing File-level protocol Document API, shared by browser and headless SDKs
Office add-ins Possible, with conditions Not applicable: SuperDoc is not an Office application

The rest of this article unpacks each row.

Eligibility and the Route to Production

This is often the deciding factor, so it comes first.

The CSPP is a partner programme, not a product you buy. Microsoft states that “The Microsoft 365 - Cloud Storage Partner Program is for independent software vendors whose business is cloud storage. It’s not open to Microsoft 365 customers directly.”

Its overview sets out criteria that include being an ISV that “develops, owns, and operates a product or service including cloud file storage”. Applicants must also store “all end users’ files at rest in a cloud location entirely owned or leased by the partner”, own the WOPI host domains, manage identity, and serve “more than one external customer”. Microsoft adds that “Every application is individually reviewed for suitability by the CSPP team.” Participants “must support upload, download, viewing, and editing in Microsoft Word, Excel and PowerPoint for the web”, even if their published solution only shows a subset.

The road to production is long:

  • Approval, then agreement to the Program Terms.
  • Development against a Microsoft test environment.
  • Testing with Microsoft’s WOPI Validator, which “executes a test suite against a host’s WOPI implementation”.
  • Microsoft verification. “Microsoft will perform a verification of your WOPI implementation”, and “Each verification pass will take up to 10 days.” Co-authoring is not optional: “multi-user co-authoring must be implemented in all CSPP WOPI hosts.”
  • Production domain allow-listing. Microsoft states that environment configuration changes “typically take 4-5 weeks each and is not something that can be expedited.”

The Program Terms also shape your product. Among other things, partners agree to “present the respective Microsoft 365 Technologies as the first listed option or default for editing.”

SuperDoc has no gatekeeper. You install the package, accept the licence terms that apply to you, and ship on your own schedule. The licensing still needs care. SuperDoc is dual-licensed under AGPLv3 and a commercial licence, and v2’s engine, @superdoc/docx-engine, “is proprietary software and is not open source”. But there is no application, no external verification and no third-party allow-list in your release path.

Here is our reading. If documents are a feature of your product rather than your business being cloud storage, Microsoft’s criteria suggest the CSPP may not be open to you. In that case the realistic choices are SharePoint Embedded (below) or a non-Microsoft editor such as SuperDoc. If you are a storage business and eligible, the CSPP gives you something no third-party editor can: the real Office, under your product.

Licensing and Cost Model

WOPI. Microsoft’s integration overview is direct: “To edit documents, users require an Microsoft 365 license.” The business-user guidance adds that “CSPP partners are responsible for ensuring that all users have a valid Microsoft 365 license to edit files in Microsoft 365 for the web applications”. It also confirms that “Licenses are not required for read-only file operations.”

For products whose users already hold Microsoft 365 licences, this is no obstacle. For products serving users who do not, such as external clients, auditees or occasional reviewers, editing access becomes a licensing question rather than a product decision. We did not find a programme fee stated in Microsoft’s CSPP documentation, and we make no claim either way.

SuperDoc. Microsoft 365 is not involved, so editing does not depend on your users’ Microsoft licences. The cost model is whatever you agree with SuperDoc under its commercial licence, if you take one, plus the infrastructure you run: storage, a collaboration server if you need real-time editing, and your own application.

Data Flow and Residency

For regulated buyers, and particularly for the UK and European organisations we work with, this row often settles the matter.

WOPI. Office for the web runs in Microsoft’s cloud, so it has to fetch the document from your host. The GetFile operation is defined so that “The response body must be the full binary contents of the file”. Microsoft’s Program Terms state that “Microsoft 365 for the web keeps a temporary copy of the file being viewed and edited for the purposes of rendering and making changes to the file.”

On location, Microsoft’s CSPP FAQ is explicit that it “does not guarantee that data will stay within a particular geographical region when used to view and edit documents stored in external (non-Microsoft) storage.” We have written about the implications in our guide to WOPI data residency and geo-fencing.

SuperDoc. The editor and its engine are self-hosted. SuperDoc’s trust documentation says “Your documents stay on your infrastructure. The SuperDoc team cannot access your content”, and the DOCX Engine licence confirms that it “is self-hosted by Customer”. Documents are parsed and edited in the user’s browser and stored wherever your application stores them.

That is a strong default, but it is not automatic. SuperDoc’s own security guidance lists what can still carry content or metadata elsewhere:

  • collaboration providers (a hosted service such as Liveblocks is a third party)
  • network proofing, AI and logging integrations
  • telemetry, which is “enabled by default” and sends document-open metadata, though not content

Each needs a deliberate configuration decision.

User Experience and Document Fidelity

WOPI gives users genuine Office: Microsoft’s Word for the web, with the interface and rendering they already know. You get familiarity and Microsoft’s own handling of the format. The trade-off is control. The editor is Microsoft’s interface inside your host page, subject to Microsoft’s branding requirements, and you cannot redesign it.

SuperDoc gives you the opposite balance. The editing surface is yours to shape:

  • Keep SuperDoc’s built-in toolbar and comments, configure them, or replace them with your own controls.
  • Choose among editing, suggesting and viewing modes.
  • Wire document review into your own workflow, for example a tracked-change panel that knows about your approval states.

The trade-off is that it is not Word. SuperDoc’s v2 engine edits the OOXML package directly rather than converting it to HTML, which is the right foundation for fidelity. But fidelity is a property of SuperDoc’s engine, not Microsoft’s. SuperDoc’s frequent releases include fidelity fixes; 2.13.0’s notes, for example, record that “Heading levels 7–9 now round-trip correctly”. That shows active investment, and it is also a reminder to test.

Our advice is the same as for any document engine: run your users’ real documents through it and compare the exports in Microsoft Word.

Co-Authoring

WOPI. Co-authoring is part of the deal. Microsoft requires that participants “must support document editing and multi-user co-authoring”. Office for the web provides “real-time content updates between all users editing the document, as well as presence information and real-time cursor tracking”. Your host’s job is to implement the locking and file operations correctly. Microsoft handles the rest, including autosave, which for Word happens “Every 30 seconds if document is updated”. Our technical guide to WOPI co-authoring covers the host side in depth.

SuperDoc. Real-time collaboration is available, and you operate it. Editors join a room, and a provider carries the changes. SuperDoc v2 supports Hocuspocus and Liveblocks providers, and it manages the provider connection itself. Your server owns authentication, room authorisation, persistence and recovery. SuperDoc’s server guidance notes that its minimal example “deliberately has no authentication or durable storage”. That is more work than WOPI. In exchange, collaboration traffic stays on infrastructure you choose (unless you choose a hosted provider), and you control the rules.

Automation and AI

This is where the architectures diverge most for product teams building intelligent document features.

WOPI is a file-access protocol: Microsoft’s documentation describes endpoints Office for the web uses “to learn about, fetch, and update files”. Our reading is that changing document content from your own code happens outside the editor, typically by processing the file on your servers between editing sessions.

SuperDoc v2 exposes the document itself through its Document API, the same operation contract in the browser and in its Node.js and Python SDKs. Your code can query the document, apply edits as direct changes or tracked changes, and read a receipt confirming what was applied. That makes workflows like AI-assisted review natural: a model’s proposals arrive in the document as tracked changes for a person to accept or reject, in the editor your users already have open.

Office Add-Ins

WOPI. Add-ins can run in Office for the web through a WOPI host, with conditions:

  • “By default, Add-ins are not enabled for users connecting to Microsoft 365 through a WOPI host.”
  • Enabling them requires an environment change request through Microsoft.
  • The add-in store is unavailable to WOPI-connected users: “Add-ins must be either preinstalled or sideloaded.”
  • “only Add-ins with Add-in commands are supported.”
  • Preinstalled add-ins “must be in available in AppSource.”

SuperDoc. Office add-ins are built for Office applications. Microsoft describes where they run: “Office Add-ins run in Office on the web, Windows, Mac, and iPad.” SuperDoc is not an Office application, so the question of running add-ins inside it does not arise in the same way. Extending SuperDoc means building on its own APIs.

File Formats

WOPI covers Word, Excel and PowerPoint. Office for the web edits the modern formats, and for legacy binary files Microsoft notes that it “doesn’t support editing files in binary formats such as doc, ppt, and xls, directly”, though it can convert them.

SuperDoc is a DOCX editor. If spreadsheet or presentation editing is part of your requirement, SuperDoc does not cover it on its own.

Where SharePoint Embedded Fits

There is a third option, and for many WOPI hosts it is the most relevant one. SharePoint Embedded stores documents in Microsoft 365, in containers your application owns, and opens them in Office. Microsoft’s own planning guidance addresses existing WOPI hosts directly:

“If you already integrate Office through a Web Application Open Platform Interface (WOPI) host, you can keep files in SharePoint Embedded and move to the built-in Office launch patterns instead of maintaining your own host.”

We have compared SharePoint Embedded and WOPI in a separate decision framework. The short version: if you want Microsoft’s editors without being a storage business, look at SharePoint Embedded before you look at the CSPP.

Which Should You Choose?

Our view, summarised:

Choose CSPP WOPI when:

  • your business is cloud storage and you meet Microsoft’s partner criteria
  • users expect genuine Office, including Excel and PowerPoint
  • your users hold, or can be required to hold, Microsoft 365 licences for editing
  • Office add-ins in the browser matter to your customers
  • your customers accept Microsoft’s cloud processing their documents, including its stated position on data location

Choose SuperDoc v2 when:

  • your documents are Word documents and the DOCX is the system of record
  • you need to own the editing interface and the review workflow
  • documents must be processed on infrastructure you control
  • your users do not all hold Microsoft 365 licences
  • you want automation and AI to edit through the same engine as your users
  • you are not eligible for the CSPP, or cannot wait for its onboarding timeline

The two are not mutually exclusive. Because SuperDoc reads and writes the DOCX package itself, a product can offer in-app editing and review in SuperDoc while keeping files fully usable by people who prefer to open them in desktop Word. The file, not the editor, is the contract.

How McKenna Consultants Can Help

Few consultancies have delivered both sides of this comparison. McKenna Consultants has been implementing WOPI for clients for many years, including for Kendox and Workiro. We are currently implementing SuperDoc for a SaaS company in the audit and compliance sector, and we work with SharePoint Embedded too. That breadth lets us give a recommendation grounded in your constraints rather than in a preferred technology.

We can help you test eligibility and requirements against each option, prototype on your own documents, and design and build whichever architecture fits. Talk to our team or read about our WOPI integration services.

Sources

Have a question about this topic?

Our team would be happy to discuss this further with you.