Tauri permissions generator

Tauri clipboard permission: clipboard-manager:default

The clipboard-manager plugin (tauri-plugin-clipboard-manager) reads and writes the system clipboard — text, HTML and images — from the frontend through @tauri-apps/plugin-clipboard-manager. Its permission string is clipboard-manager:default, which is easy to mistype from the shorter plugin name.

Reading the clipboard is the sensitive half: whatever the user last copied, including a password from a manager, is readable by any code with the grant. If the app only ever puts text on the clipboard, prefer the write-only permissions (clipboard-manager:allow-write-text) over the default set.

Clipboard at a glance

Permission
clipboard-manager:default
Cargo crate
tauri-plugin-clipboard-manager
npm bindings
@tauri-apps/plugin-clipboard-manager
Builder call
.plugin(tauri_plugin_clipboard_manager::init())
What it enables
Read and write the system clipboard.
What it widens
Reads and writes the system clipboard, which frequently holds passwords the user copied from elsewhere.

The four files that must agree

Capability file

src-tauri/capabilities/default.json
{
  "$schema": "../gen/schemas/desktop-schema.json",
  "identifier": "default",
  "description": "Capabilities granted to the main window.",
  "windows": [
    "main"
  ],
  "permissions": [
    "core:default",
    "clipboard-manager:default"
  ]
}

core:default is the baseline every window has; the plugin permission is the one line this page adds.

Cargo dependency

src-tauri/Cargo.toml
[dependencies]
tauri = { version = "2", features = [] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
tauri-plugin-clipboard-manager = "2"

Plugin registration

src-tauri/src/lib.rs
#[cfg_attr(mobile, tauri::mobile_entry_point)]
pub fn run() {
    tauri::Builder::default()
        .plugin(tauri_plugin_clipboard_manager::init())
        .run(tauri::generate_context!())
        .expect("error while running tauri application");
}

A crate that is declared but never registered is dead weight; one registered without its permission is a runtime denial.

Frontend bindings

terminal
npm install @tauri-apps/plugin-clipboard-manager

clipboard-manager:default, answered

The longer version is in the guide Tauri 2 permissions: capabilities without the runtime denials.

What does clipboard-manager:default grant in Tauri 2?
clipboard-manager:default is the default permission set of tauri-plugin-clipboard-manager. It read and write the system clipboard. Tauri 2 denies every command that is not listed in a capability file, so without this line the plugin's commands fail at runtime even though the crate compiles and is registered.
Why does my clipboard call fail with a permission error?
Three files have to agree: tauri-plugin-clipboard-manager in Cargo.toml, .plugin(tauri_plugin_clipboard_manager::init()) in src/lib.rs, and clipboard-manager:default in the capability file under src-tauri/capabilities/. The ACL is checked when a command is invoked, not when the app is built, so a missing permission string compiles cleanly and denies at runtime. The frontend also needs @tauri-apps/plugin-clipboard-manager installed to call it.
Is clipboard-manager:default safe to ship?
Reads and writes the system clipboard, which frequently holds passwords the user copied from elsewhere. Permissions are additive on top of core:default, so the least-privilege shape is to grant only the plugins the app calls, and to prefer the plugin's granular allow-* permissions over the default set wherever a command or path can be named.

Combine it with the rest of your capability file

The Tauri permissions generator builds the whole file from the same catalogue — tick every plugin the app calls, add a custom title bar's window permissions, and copy the capability JSON, Cargo dependencies, builder chain and npm install line together. In the Nodlume workspace the same selection is what the Desktop export writes into src-tauri.

Open the generator

Other Tauri 2 plugin permissions

We'd like to use Google cookies to understand how Nodlume is used and to measure our advertising. Nothing loads until you choose, and declining does not affect anything in the app.