Permissions and consent

Download all docs

Declare the actions your app needs and request access to selected projects.

A full app declares web.requestedActions in octonode.app.json. A workspace administrator reviews and accepts those permissions when installing the app into a workspace. Project access is optional: an app can be installed and opened without any projects or grants. Project operations require explicit project/action grants, which an administrator can add later by updating consent.

ActionAllows
projects:readRead selected project names and IDs
data:readRead tables and rows in selected projects
data:writeInsert, update and delete rows in selected projects
workflows:runRun workflows in selected projects

A project directory only needs projects:read. A product-table browser also needs data:read. Data grants cover a project's tables; they are not limited to one product table. Project definition writes are not currently an app capability. Read and write actions are explicit; do not assume one grants the other.

{
  "web": {
    "entry": "src/server.ts",
    "platform": "vite",
    "requestedActions": ["projects:read"]
  }
}

This is the web portion of the descriptor, not a complete manifest.

Selected projects

Call the result Granted projects. New projects are excluded until an administrator changes consent. The limit is 100 action/project pairs, so two actions on one project consume two grants.

Every data call checks the active installation, pinned release, current user membership, granted action, project and session. Scope increases require renewed consent. Disabling, uninstalling or revoking access stops subsequent calls.

A framed page has no authority by itself. Development previews require separate, temporary consent. Extension-only apps remain static and cannot request these actions.