Skip to content

Permissions

A plugin's manifest asks; the user grants; the capability gate enforces. A plugin's ctx simply has no attribute for a capability it was not given, so a mistake shows up the first time you run the plugin rather than silently in a user's installation.

Capability Grants Narrowed by
files Read and write inside one folder show, episode, or a path the user picks
network HTTP requests A host list in the manifest, held to at the gate
llm.local Calls to Ollama on this machine A model name, or a capability such as summarise
llm.remote Calls to an external provider on the user's key A monthly ceiling in euros
transcription The built-in transcription service —
audio Decode, filter and mix the show's audio —
native Widgets in the UI process Bundled plugins only

What this is, and is not

Running a plugin in its own process stops it hanging the window, confines a crash, and lets the user kill it. Permissions make what a plugin reaches visible and revocable.

It is not a security sandbox. A determined plugin still runs with your user account. Treating the gate as a guardrail rather than a jail is the honest description. Podlibre shows where a plugin came from, so trust stays the user's decision, and asks again when a plugin that has been running reaches for something new.

Asking well

Ask for the least that works, and narrow it. network = ["api.castopod.org"] tells a user what you will do; network = ["*"] tells them nothing. A publisher that names its host can be held to it by the gate, and the user can see at a glance that it is not phoning somewhere else.