Documentation Plugins

Plugins

Plugin permissions and safety

designer builder

Last updated Sep 29, 2026

The install confirmation lists the permissions a plugin requests. Read them in light of the document and workspace where the plugin will run. A plugin that draws objects needs different access from one that only reads the current selection.

Permission What it allows
content:read Read the open document and selection through the plugin API.
content:write Create or change document content; this includes read access.
ui Open a plugin panel and exchange messages with it.
network Fetch from the domains named in the plugin manifest.
export Export supported image data through the plugin API.
brand:read Read the active workspace's brand kit.

A plugin does not get unrestricted access to the editor. It runs through a limited API, and its network permission must name allowed domains. Still, a plugin with both document access and network access can send information to those domains. Install plugins only when you trust their publisher and understand the requested access.

To stop a catalog plugin, open Plugins → Manage → Installed and switch Enable off. Uninstall it to remove it from the workspace. A plugin loaded through Developer is stored only in this browser; remove it from the Developer tab. For how the manifest declares permissions, see building a plugin.