Verentis

Installation & consent

Installation, consent & scopes

Signed package installation, capability-specific consent, and the separate authority of WOPI editors and hosted backends.

Apps declare their contributions and permissions in a manifest, but file registration and trusted installation authority are not the same thing. Marketplace installs a package's files and records its installation provenance. The platform then applies the consent rules for the package's capabilities.

A loose manifest can be useful while developing an ordinary app. It cannot stand in for a signed, consented WOPI or hosted-backend installation.

Signed installation

Publish a verified candidate

The publisher signs the package with an active signing key and publishes it to Marketplace. Publication and moderation do not grant access to any workspace.

Install into the workspace

Marketplace places the manifest and payload according to the install map and registers the exact installed candidate. Files appearing in the workspace do not, by themselves, prove that every authorization step has completed.

Ordinary browser apps can follow the automatic approval path. WOPI and hosted backend capabilities require their explicit authorization flow. The installer reviews the candidate's requested authority, not an editable copy of its metadata.

Launch within current user rights

Approved installation authority enables the declared integration. Each launch still depends on the user's current workspace and document permissions.

For Collabora integration, the signed spec.wopi declaration identifies the wrapper and operator origins, file formats, actions, size/idle limits and optional rename/delete operations. The installer explicitly consents to the external editor processing document content. Both origins matter: the wrapper provider and the CODE operator may be different parties.

No publisher OAuth client registration is required for WOPI alone. A minimal WOPI-only wrapper can declare permissions: []; that does not let it bypass the user's file permissions. The host brokers WOPI launch and session controls.

If the package also declares a hosted backend, that backend retains its separate credential binding and consent. WOPI approval does not activate an unapproved backend, and backend approval alone does not grant WOPI document access.

Ordinary API permissions and OAuth

These fields concern ordinary platform API access or an app's separate OAuth identity, not a mandatory WOPI credential:

spec:
  permissions:                     # platform scopes the app needs
    - node.file.read
    - node.node.create
    - node.node.update

  oauth:
    client-type: public            # public (browser) or confidential (has a backend)
    redirect-uris:
      - https://app.example.com/auth/callback

  scopes:                          # custom scopes the app defines
    - acme-editor.document.export
    - acme-editor.settings.manage
permissions

The scopes you request. These appear on the consent screen and bound the tokens you receive. Request the minimum.

oauth.client-type

public for browser-only apps; confidential if your app has a secure backend that can hold a secret.

scopes

Scopes you define so other extensions or services can be granted permission to call your app — this is the basis of app-to-app authorization.

App-to-app authorization

If your app needs to call another app's API, it must hold a grant for that app's defined scopes — enforced by the same token system that governs service-to-service calls. Define clear, well-named scopes so other developers (and admins) can reason about what they're granting.

Governance & visibility

Admins can see installed apps, the permissions each requests, and the scopes each defines, in the account → workspace views. Designing tight, legible permissions makes your app easier to approve and trust.

Updates, revocation and uninstall

Consent is bound to the exact reviewed candidate. Publish a new signed version for changes to origins, formats, limits, actions or optional operations, and complete the required consent review; changing installed files is not a way to expand authority. Do not assume approval of an old version approves a replacement.

Revoking installation consent invalidates its authority, including both WOPI and hosted-backend authority when both are present. Uninstall through the platform's installation flow rather than treating deletion of a manifest as a consent-only operation. Managed/seed payload handling follows the install-map lifecycle.

An open editor must handle denied or expired authority and preserve unverified edits. Never silently reacquire broader permission or report a pending save as successful after revocation.

Next

Local development

Iterate fast before you install.