Tauri permissions generator

Tauri global-shortcut permission: global-shortcut:default

The global-shortcut plugin (tauri-plugin-global-shortcut) registers keyboard shortcuts with the operating system so they fire even while the app's window is not focused — the pattern behind a launcher hotkey, a push-to-talk key, or a screenshot chord.

global-shortcut:default enables registering, unregistering and checking shortcuts. There is no scope to narrow which keys may be taken, so the responsibility is in the app's code: register a shortcut only when the user turns the feature on, and release it on shutdown, because a chord held by a background app is one the rest of the desktop cannot use.

Global shortcuts at a glance

Permission
global-shortcut:default
Cargo crate
tauri-plugin-global-shortcut
npm bindings
@tauri-apps/plugin-global-shortcut
Builder call
.plugin(tauri_plugin_global_shortcut::init())
What it enables
Register OS-wide keyboard shortcuts, even while unfocused.
What it widens
Registers OS-wide hotkeys that fire while the app is in the background.

The four files that must agree

Capability file

src-tauri/capabilities/default.json
{
  "$schema": "../gen/schemas/desktop-schema.json",
  "identifier": "default",
  "description": "Capabilities granted to the main window.",
  "windows": [
    "main"
  ],
  "permissions": [
    "core:default",
    "global-shortcut:default"
  ]
}

core:default is the baseline every window has; the plugin permission is the one line this page adds.

Cargo dependency

src-tauri/Cargo.toml
[dependencies]
tauri = { version = "2", features = [] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
tauri-plugin-global-shortcut = "2"

Plugin registration

src-tauri/src/lib.rs
#[cfg_attr(mobile, tauri::mobile_entry_point)]
pub fn run() {
    tauri::Builder::default()
        .plugin(tauri_plugin_global_shortcut::init())
        .run(tauri::generate_context!())
        .expect("error while running tauri application");
}

A crate that is declared but never registered is dead weight; one registered without its permission is a runtime denial.

Frontend bindings

terminal
npm install @tauri-apps/plugin-global-shortcut

global-shortcut:default, answered

The longer version is in the guide Tauri 2 permissions: capabilities without the runtime denials.

What does global-shortcut:default grant in Tauri 2?
global-shortcut:default is the default permission set of tauri-plugin-global-shortcut. It register OS-wide keyboard shortcuts, even while unfocused. Tauri 2 denies every command that is not listed in a capability file, so without this line the plugin's commands fail at runtime even though the crate compiles and is registered.
Why does my global shortcuts call fail with a permission error?
Three files have to agree: tauri-plugin-global-shortcut in Cargo.toml, .plugin(tauri_plugin_global_shortcut::init()) in src/lib.rs, and global-shortcut:default in the capability file under src-tauri/capabilities/. The ACL is checked when a command is invoked, not when the app is built, so a missing permission string compiles cleanly and denies at runtime. The frontend also needs @tauri-apps/plugin-global-shortcut installed to call it.
Is global-shortcut:default safe to ship?
Registers OS-wide hotkeys that fire while the app is in the background. Permissions are additive on top of core:default, so the least-privilege shape is to grant only the plugins the app calls, and to prefer the plugin's granular allow-* permissions over the default set wherever a command or path can be named.

Combine it with the rest of your capability file

The Tauri permissions generator builds the whole file from the same catalogue — tick every plugin the app calls, add a custom title bar's window permissions, and copy the capability JSON, Cargo dependencies, builder chain and npm install line together. In the Nodlume workspace the same selection is what the Desktop export writes into src-tauri.

Open the generator

Other Tauri 2 plugin permissions

We'd like to use Google cookies to understand how Nodlume is used and to measure our advertising. Nothing loads until you choose, and declining does not affect anything in the app.