Plugins
Plugin permissions and safety
The install confirmation lists the permissions a plugin requests. Read them in light of the document and workspace where the plugin will run. A plugin that draws objects needs different access from one that only reads the current selection.
| Permission | What it allows |
|---|---|
content:read |
Read the open document and selection through the plugin API. |
content:write |
Create or change document content; this includes read access. |
ui |
Open a plugin panel and exchange messages with it. |
network |
Fetch from the domains named in the plugin manifest. |
export |
Export supported image data through the plugin API. |
brand:read |
Read the active workspace's brand kit. |
A plugin does not get unrestricted access to the editor. It runs through a limited API, and its network permission must name allowed domains. Still, a plugin with both document access and network access can send information to those domains. Install plugins only when you trust their publisher and understand the requested access.
To stop a catalog plugin, open Plugins → Manage → Installed and switch Enable off. Uninstall it to remove it from the workspace. A plugin loaded through Developer is stored only in this browser; remove it from the Developer tab. For how the manifest declares permissions, see building a plugin.