Permissions and consent
Declare the actions your app needs and request access to selected projects.
A full app declares web.requestedActions in octonode.app.json. A workspace administrator reviews and accepts those permissions when installing the app into a workspace. Project access is optional: an app can be installed and opened without any projects or grants. Project operations require explicit project/action grants, which an administrator can add later by updating consent.
| Action | Allows |
|---|---|
projects:read | Read selected project names and IDs |
data:read | Read tables and rows in selected projects |
data:write | Insert, update and delete rows in selected projects |
workflows:run | Run workflows in selected projects |
A project directory only needs projects:read. A product-table browser also needs data:read. Data grants cover a project's tables; they are not limited to one product table. Project definition writes are not currently an app capability. Read and write actions are explicit; do not assume one grants the other.
{
"web": {
"entry": "src/server.ts",
"platform": "vite",
"requestedActions": ["projects:read"]
}
}This is the web portion of the descriptor, not a complete manifest.
Selected projects
Call the result Granted projects. New projects are excluded until an administrator changes consent. The limit is 100 action/project pairs, so two actions on one project consume two grants.
Every data call checks the active installation, pinned release, current user membership, granted action, project and session. Scope increases require renewed consent. Disabling, uninstalling or revoking access stops subsequent calls.
A framed page has no authority by itself. Development previews require separate, temporary consent. Extension-only apps remain static and cannot request these actions.