Administration, permissions, and advanced code
Settings, least-privilege permissions, license behavior, AI queue, and page-level code.
Configure PageDesigner settings, assign least-privilege permissions, understand license behavior, maintain the AI queue, and control page-level code.
This page is for the Paymenter owner, role administrator, or developer responsible for PageDesigner.
Administrative responsibilities
- Install and upgrade the extension.
- Maintain the license and Hosted settings.
- Assign PageDesigner permissions.
- Run the queue worker for durable AI jobs.
- Review shared/public packages.
- Control MCP tokens.
- Review custom components and page-level executable code.
- Back up and recover PageDesigner tables.
Extension settings
Hosted and license
| Setting | Guidance |
|---|---|
| Enable component library and Marketplace | Required for Hosted management features; published pages remain local |
| License key | Server-side secret; never share it with page editors |
| Account email or ID | Optional license account binding |
| Install name | Friendly environment identifier |
| Public server IP | Public egress IP for NAT/proxy environments; never loopback/private |
Updates
| Setting | Guidance |
|---|---|
| Update channel | Stable for production; Beta only for deliberate testing |
| Auto-check hosted library updates | Compares the reusable cache with current metadata |
| Auto-update downloaded library cache | Refreshes reusable templates only; never rewrites placed page content |
Direct AI provider
| Setting | Guidance |
|---|---|
| Use custom OpenAI-compatible AI endpoint | Enables the direct server-side provider path |
| Endpoint URL | HTTPS base URL or chat-completions URL |
| API key | Stored server-side; a non-empty key also enables and prioritizes this path |
| Model | Exact provider model ID |
| Timeout | 30–180 seconds |
| Temporarily allow HTTP | Local/testing only; keep off in production |
Permissions
PageDesigner registers:
| Permission | Grants |
|---|---|
admin.page_designer.view | View Page Designer |
admin.page_designer.create | Create pages |
admin.page_designer.update | Update pages and use the editor |
admin.page_designer.delete | Delete pages |
admin.page_designer.hosted.view | View Hosted library and marketplace data |
admin.page_designer.hosted.download | Download Hosted components and page packages |
admin.page_designer.custom_components.manage | Create, fork, upload, and delete local custom components |
admin.page_designer.components.share | Share components |
admin.page_designer.pages.share | Share pages |
admin.page_designer.license.manage | Manage or recover licensing |
admin.page_designer.updates.run | Run Hosted update checks |
admin.page_designer.ai.use | Use the built-in AI agent |
admin.page_designer.mcp.manage | Create and revoke MCP access tokens |
The default administrator role receives the PageDesigner permissions during install/upgrade unless it already uses wildcard access.
Recommended role patterns
Page reviewer
- View.
- Update only when the reviewer is expected to edit.
- No delete, sharing, custom component, AI Full access policy, license, or MCP management.
Page editor
- View, create, update.
- Hosted view/download as needed.
- Custom component manage only for trusted component maintainers.
- AI use when the organization permits AI processing.
Publisher
- View and update, with an organizational publishing approval process.
- Page sharing only when this role owns distribution.
PageDesigner administrator
- All relevant permissions, including license, updates, and MCP.
- Limit this role to trusted administrators.
A license never grants a Paymenter permission. A permission never bypasses a failed license decision.
License and offline behavior
The locally stored signed grant is bound to the license-key hash and install UUID. It contains entitlement and timing data and is verified with bundled public-key material.
When the Hosted service cannot be reached, a previously verified grant can authorize management only through its signed offline-grace deadline.
Already-published local pages continue rendering when management is blocked. This avoids turning a licensing or Hosted outage into a storefront outage.
Queue worker for AI
AI runs dispatch ProcessAiRun jobs to Laravel's configured default queue.
Operational requirements:
- Run a persistent queue worker.
- Monitor failed jobs.
- Restart workers after relevant deploys.
- Allow jobs longer than the configured provider timeout; PageDesigner jobs allow up to 300 seconds.
- Avoid a restrictive queue allow-list that excludes the default queue used by the application.
Each job makes one model-response step, checkpoints it, and dispatches the next step when necessary.
Page-level Custom Code
The page record contains five slots:
| Slot | Render location |
|---|---|
| Custom Head HTML | Page document head |
| Custom HTML (Before Content) | Before PageDesigner canvas content |
| Custom HTML (After Content) | After canvas content |
| Custom CSS | After PageDesigner page styles |
| Custom JavaScript | After page content; script tags optional |
Normal editor policy
Leave these slots empty unless a trusted developer has provided and reviewed the exact content.
Review requirements
- Read the existing slot before changing it.
- Keep a backup of the previous value.
- Understand public execution and data exposure.
- Prefer append for a new independent script.
- Replace only with explicit intent and complete review.
- Use head scripts only when load timing genuinely requires it.
- Do not duplicate SEO tags already managed by PageDesigner.
- Avoid selectors or scripts that affect the Paymenter shell globally.
- Test signed-out, mobile, and both themes.
Custom JavaScript executes for public visitors. Never place credentials, license keys, MCP tokens, provider keys, private API endpoints, or server-only data in page code.
Page deletion and bulk deletion
Deletion is permanent in the normal page list and MCP requires explicit confirmation. Before deletion:
- unpublish when temporary removal is enough;
- inventory inbound links;
- save a reviewed share/export or database backup when recovery may be needed;
- confirm the page is not a source for an active campaign;
- ensure bulk selection is correct.
Sharing governance
Define who may:
- share unlisted packages;
- publish a package to Page Marketplace;
- import community packages;
- approve custom code contained in a page package;
- redistribute media and copy.
Imported pages must remain drafts until review.
Backup and recovery
Back up the database before:
- extension upgrades;
- uninstall;
- bulk deletion;
- major MCP or Full access AI migrations;
- schema or infrastructure changes.
Retain the PageDesigner ZIP that matches the backup.
For rollback, restore the database and previous ZIP together. Do not selectively delete or recreate PageDesigner tables.
Audit and diagnostics
PageDesigner records hosted lifecycle, download, sharing, import, AI, and related events in its audit table when available. Application logs and the hosted diagnostic response are also important.
Do not include raw secrets in tickets or screenshots. Redact:
- license keys;
- custom AI keys;
- MCP tokens;
- Authorization headers;
- private package links;
- customer data.
Security checklist
- HTTPS application URL is correct.
- Public server IP is correct when required.
- Stable update channel is used in production.
- Page editor roles have least privilege.
- Queue workers are monitored.
- Direct provider uses HTTPS.
- Custom components are reviewed as code.
- Page-level scripts contain no secrets.
- Each MCP client has a separate token.
- Unused MCP tokens are revoked.
- Public marketplace sharing has an approval owner.
- Database and previous ZIP backups exist.