Skip to content

Permissions

Declared once, in the manifest. The Node runtime checks the calls it hands you against them, so your code doesn’t have to police itself.

"permissions": {
"network": ["api.example.com"],
"files": ["~/.config/my-extension/state.json"],
"exec": ["/usr/bin/say"]
}
Key Gates Notes
network fetch A list of hostnames (*.example.com matches any subdomain). A fetch to any other host is rejected before it leaves the process, and so is a redirect to one. Empty (or omitted) means fetch reaches nothing. WebSocket follows the same list. Node’s own http, https, net, dns and child_process modules aren’t available to extensions at all, so make every request with fetch and run programs with ctx.exec.
files triggers.watch, and generally any path your code reads Paths, ~ allowed. Not sandboxed: your code can read more than it declares, but the manifest is what people see before they install it. Declare what you actually touch.
exec ctx.exec(file, …) The exact executable paths you’re allowed to run. ctx.exec rejects (throws) a call for anything not listed here. Like fetch, this checks the call the runtime gives you, not Node’s own child_process: run programs only through ctx.exec.

Ask for the minimum you need. permissions.network and permissions.exec are the first thing people see on the install sheet, before anything is installed (Sharing it).