All skills

Tauri v2+ cross-platform app development with Rust backend. Use when configuring tauri.conf.json, implementing Rust commands (#[tauri::command]), setting up IPC patterns (invoke, emit, channels), configuring permissions/capabilities, troubleshooting build issues, or deploying desktop/mobile apps. Triggers on Tauri, src-tauri, invoke, emit, capabilities.json.

Use this Skill: https://skilld.dev/gh/nodnarbnitram/claude-code-extensions/tauri-v2

This session only. Nothing lands on disk.

referencescapabilities-reference.md

≈2.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Tauri v2+ Capabilities & Permissions Reference

Contents

  • Security Model: v1 vs v2
  • Overview
  • Capability File Structure
  • Core Permissions
  • Plugin Permissions
  • Scopes
  • Permission Sets
  • Window and Webview Targeting
  • Capability Best Practices
  • Common Capability Patterns
  • Anti-Patterns

Security Model: v1 vs v2

Tauri v2 replaces the v1 allowlist with a capabilities-first security model. In v1, you listed allowed API calls in tauri.conf.json's allowlist. In v2, permissions must be explicitly granted via capability files in src-tauri/capabilities/.

Three-layer security model:

  • Capability: A named collection of permissions, scoped to specific windows/webviews. Lives in src-tauri/capabilities/*.json.
  • Permission: An identifier that grants access to a specific command or feature (e.g., fs:allow-read-file). Defined per-plugin.
  • Scope: Optional constraint on a permission that limits what it can access (e.g., only $APPDATA/* paths). Part of a permission object.

Overview

Tauri v2+ uses a capabilities-based security model. By default, nothing is allowed - you must explicitly grant permissions through capability files.

Last verified: 2026-04-02. Check the official Tauri changelog when capability semantics or permission names change.

Capability File Structure

Location: src-tauri/capabilities/

{
    "$schema": "../gen/schemas/desktop-schema.json",
    "identifier": "capability-name",
    "description": "What this capability allows",
    "windows": ["main", "settings"],
    "webviews": [],
    "permissions": [
        "core:default",
        "plugin-name:permission-name"
    ]
}

Core Permissions

Essential (Almost Always Needed)

{
    "permissions": [
        "core:default",
        "core:window:default",
        "core:event:default"
    ]
}

Window Permissions

Permission Description
core:window:default Basic window operations
core:window:allow-close Allow closing windows
core:window:allow-set-title Allow changing window title
core:window:allow-minimize Allow minimizing
core:window:allow-maximize Allow maximizing
core:window:allow-set-size Allow resizing
core:window:allow-set-position Allow repositioning
core:window:allow-set-fullscreen Allow fullscreen toggle

Event Permissions

Permission Description
core:event:default Basic event listening
core:event:allow-emit Allow emitting events
core:event:allow-listen Allow listening to events

Plugin Permissions

File System (tauri-plugin-fs)

{
    "permissions": [
        "fs:default",
        "fs:allow-read-dir",
        "fs:allow-read-file",
        "fs:allow-write-file",
        "fs:allow-create-dir",
        "fs:allow-remove-file",
        "fs:allow-rename"
    ]
}

With Scopes:

{
    "permissions": [
        {
            "identifier": "fs:allow-read-file",
            "allow": [
                { "path": "$APPDATA/*" },
                { "path": "$HOME/Documents/*" }
            ]
        }
    ]
}

Dialog (tauri-plugin-dialog)

{
    "permissions": [
        "dialog:default",
        "dialog:allow-open",
        "dialog:allow-save",
        "dialog:allow-message",
        "dialog:allow-ask",
        "dialog:allow-confirm"
    ]
}

Shell (tauri-plugin-shell)

{
    "permissions": [
        "shell:default",
        "shell:allow-open",
        "shell:allow-execute"
    ]
}

Scoped Execute:

{
    "permissions": [
        {
            "identifier": "shell:allow-execute",
            "allow": [
                { "name": "git", "args": true },
                { "name": "npm", "args": ["install", "run"] }
            ]
        }
    ]
}

HTTP (tauri-plugin-http)

{
    "permissions": [
        "http:default"
    ]
}

With URL Scopes:

{
    "permissions": [
        {
            "identifier": "http:default",
            "allow": [
                { "url": "https://api.example.com/*" },
                { "url": "https://*.myapp.com/*" }
            ]
        }
    ]
}

Store (tauri-plugin-store)

{
    "permissions": [
        "store:default",
        "store:allow-get",
        "store:allow-set",
        "store:allow-delete",
        "store:allow-keys",
        "store:allow-clear"
    ]
}

Clipboard (tauri-plugin-clipboard-manager)

{
    "permissions": [
        "clipboard-manager:default",
        "clipboard-manager:allow-read",
        "clipboard-manager:allow-write"
    ]
}

Notification (tauri-plugin-notification)

{
    "permissions": [
        "notification:default",
        "notification:allow-send",
        "notification:allow-request-permission"
    ]
}

Global Shortcut (tauri-plugin-global-shortcut)

{
    "permissions": [
        "global-shortcut:default",
        "global-shortcut:allow-register",
        "global-shortcut:allow-unregister"
    ]
}

Permission Sets

Permission sets allow grouping multiple permissions into a single reusable identifier. You can use preset permission sets provided by plugins (like fs:default) or define your own in src-tauri/permissions/.

{
  "permissions": [
    "fs:default",          // Permission set: includes common fs operations
    "fs:allow-read-file",  // Individual permission: specific operation
    {
      "identifier": "fs:allow-read-file",  // Permission with scope
      "allow": [{ "path": "$APPDATA/*" }]
    }
  ]
}

Platform-Specific Capabilities

{
    "identifier": "desktop-only",
    "platforms": ["linux", "macos", "windows"],
    "permissions": ["global-shortcut:default"]
}
{
    "identifier": "mobile-only",
    "platforms": ["iOS", "android"],
    "permissions": ["biometric:default", "haptics:default"]
}

Windows and Webviews Targeting

Capabilities are applied to specific windows and webviews by their labels. A window or webview can be part of multiple capabilities, in which case their permissions are merged.

{
  "identifier": "main-window-cap",
  "windows": ["main"],        // Target by window label
  "webviews": [],             // Or target specific webviews
  "permissions": ["core:default", "fs:default"]
}

Remote URL Access

Allow Tauri commands from remote URLs:

{
    "identifier": "remote-access",
    "remote": {
        "urls": ["https://*.myapp.com"]
    },
    "permissions": ["http:default"]
}

Custom Permission Files

Create custom permissions in src-tauri/permissions/:

custom.toml:

[[permission]]
identifier = "allow-home-documents"
description = "Allow access to home documents"
commands.allow = ["read_file", "write_file"]

[[scope.allow]]
path = "$HOME/Documents/**"

Reference in capability:

{
    "permissions": ["custom:allow-home-documents"]
}

Capability Best Practices

  1. Principle of Least Privilege: Only grant what's needed
  2. Use Scopes: Limit file/URL access to specific paths
  3. Separate Capabilities: Create focused capability files for different features
  4. Platform-Specific: Use platform filtering for platform-specific features
  5. Document: Add descriptions to explain why permissions are needed

See also: Plugin Reference for plugin-specific permission strings | Advanced Runtime for tray/sidecar capabilities

Anti-Pattern: Missing Capability

Plugin installed but NOT in capabilities = silent permission denied at runtime. Always add plugin permissions to a capability file that targets the window using the plugin.

Common Capability Patterns

Minimal App

{
    "identifier": "minimal",
    "windows": ["main"],
    "permissions": ["core:default"]
}

File Manager

{
    "identifier": "file-manager",
    "windows": ["main"],
    "permissions": [
        "core:default",
        "fs:default",
        "dialog:allow-open",
        "dialog:allow-save"
    ]
}

Web-Connected App

{
    "identifier": "web-app",
    "windows": ["main"],
    "permissions": [
        "core:default",
        "http:default",
        "shell:allow-open"
    ]
}

Full Desktop App

{
    "identifier": "full-desktop",
    "windows": ["main"],
    "permissions": [
        "core:default",
        "core:window:default",
        "core:event:default",
        "fs:default",
        "dialog:default",
        "shell:default",
        "clipboard-manager:default",
        "notification:default",
        "global-shortcut:default",
        "store:default"
    ]
}

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides comprehensive and legitimate documentation for Tauri v2 development. It emphasizes the framework's security-first approach, particularly the new capabilities and permissions model. All described behaviors, including plugin usage and the update mechanism, are standard for Tauri and accompanied by appropriate security guidance.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    1/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3493e21. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
version
1.0.1
  • Rust
  • tauri
  • desktop-apps
  • mobile-apps
  • ipc
  • cross-platform
  • capabilities
  • serde
  • webview

README badge

README badge for nodnarbnitram/claude-code-extensions/tauri-v2

Builds cross-platform desktop and mobile apps with Rust backends and web frontends using Tauri v2+. Covers command registration, IPC patterns (invoke/emit/channels), capability configuration, state management, and common build/deployment issues. Prevents 8+ typical Tauri setup errors including permission denials, unregistered commands, and mobile build failures.

Generated from the current SKILL.md.

Does this skill work with Tauri v1?
No. This skill is for Tauri v2+ only. It covers the v2 API (e.g., `@tauri-apps/api/core`, the `lib.rs` split for mobile, and v2 capability system).
Can I use this for mobile apps?
Yes. The skill covers both desktop and mobile Tauri builds, including the required `#[cfg_attr(mobile, tauri::mobile_entry_point)]` pattern and Rust target setup.
What IPC patterns does this cover?
The skill documents commands, events, channels, and state management. Deeper IPC decision guidance is in the bundled `references/ipc-patterns.md` file.
Does this cover plugin setup?
Yes. The skill explains how to add plugin permissions to capabilities and references the bundled `references/plugin-reference.md` for official Tauri plugins.
What are the minimum Rust changes needed to add a command?
Add a `#[tauri::command]` function in `lib.rs`, register it in `tauri::generate_handler![]`, add required permissions to `capabilities/default.json`, and call it from frontend with `invoke()`.

Generated from the current SKILL.md. These answers refresh after source changes.