Installation & consent
Installation, consent & scopes
Signed package installation, capability-specific consent, and the separate authority of WOPI editors and hosted backends.
Apps declare their contributions and permissions in a manifest, but file registration and trusted installation authority are not the same thing. Marketplace installs a package's files and records its installation provenance. The platform then applies the consent rules for the package's capabilities.
A loose manifest can be useful while developing an ordinary app. It cannot stand in for a signed, consented WOPI or hosted-backend installation.
Signed installation
Publish a verified candidate
The publisher signs the package with an active signing key and publishes it to Marketplace. Publication and moderation do not grant access to any workspace.
Install into the workspace
Marketplace places the manifest and payload according to the install map and registers the exact installed candidate. Files appearing in the workspace do not, by themselves, prove that every authorization step has completed.
Apply capability-specific consent
Ordinary browser apps can follow the automatic approval path. WOPI and hosted backend capabilities require their explicit authorization flow. The installer reviews the candidate's requested authority, not an editable copy of its metadata.
Launch within current user rights
Approved installation authority enables the declared integration. Each launch still depends on the user's current workspace and document permissions.
WOPI consent
For Collabora integration, the signed
spec.wopi declaration identifies the wrapper and operator origins, file
formats, actions, size/idle limits and optional rename/delete operations.
The installer explicitly consents to the external editor processing document
content. Both origins matter: the wrapper provider and the CODE operator may
be different parties.
No publisher OAuth client registration is required for WOPI alone. A minimal
WOPI-only wrapper can declare permissions: []; that does not let it bypass
the user's file permissions. The host brokers WOPI launch and session controls.
If the package also declares a hosted backend, that backend retains its separate credential binding and consent. WOPI approval does not activate an unapproved backend, and backend approval alone does not grant WOPI document access.
Ordinary API permissions and OAuth
These fields concern ordinary platform API access or an app's separate OAuth identity, not a mandatory WOPI credential:
spec:
permissions: # platform scopes the app needs
- node.file.read
- node.node.create
- node.node.update
oauth:
client-type: public # public (browser) or confidential (has a backend)
redirect-uris:
- https://app.example.com/auth/callback
scopes: # custom scopes the app defines
- acme-editor.document.export
- acme-editor.settings.manage
permissionsThe scopes you request. These appear on the consent screen and bound the tokens you receive. Request the minimum.
oauth.client-typepublic for browser-only apps; confidential if your app has a secure backend that can hold a secret.
scopesScopes you define so other extensions or services can be granted permission to call your app — this is the basis of app-to-app authorization.
App-to-app authorization
If your app needs to call another app's API, it must hold a grant for that app's defined scopes — enforced by the same token system that governs service-to-service calls. Define clear, well-named scopes so other developers (and admins) can reason about what they're granting.
Governance & visibility
Admins can see installed apps, the permissions each requests, and the scopes each defines, in the account → workspace views. Designing tight, legible permissions makes your app easier to approve and trust.
Updates, revocation and uninstall
Consent is bound to the exact reviewed candidate. Publish a new signed version for changes to origins, formats, limits, actions or optional operations, and complete the required consent review; changing installed files is not a way to expand authority. Do not assume approval of an old version approves a replacement.
Revoking installation consent invalidates its authority, including both WOPI and hosted-backend authority when both are present. Uninstall through the platform's installation flow rather than treating deletion of a manifest as a consent-only operation. Managed/seed payload handling follows the install-map lifecycle.
An open editor must handle denied or expired authority and preserve unverified edits. Never silently reacquire broader permission or report a pending save as successful after revocation.
Next
Iterate fast before you install.