Cloee Docs
Paymenter ExtensionsPageDesigner

Administration, permissions, and advanced code

Settings, least-privilege permissions, license behavior, AI queue, and page-level code.

Configure PageDesigner settings, assign least-privilege permissions, understand license behavior, maintain the AI queue, and control page-level code.

This page is for the Paymenter owner, role administrator, or developer responsible for PageDesigner.

Administrative responsibilities

  • Install and upgrade the extension.
  • Maintain the license and Hosted settings.
  • Assign PageDesigner permissions.
  • Run the queue worker for durable AI jobs.
  • Review shared/public packages.
  • Control MCP tokens.
  • Review custom components and page-level executable code.
  • Back up and recover PageDesigner tables.

Extension settings

Hosted and license

SettingGuidance
Enable component library and MarketplaceRequired for Hosted management features; published pages remain local
License keyServer-side secret; never share it with page editors
Account email or IDOptional license account binding
Install nameFriendly environment identifier
Public server IPPublic egress IP for NAT/proxy environments; never loopback/private

Updates

SettingGuidance
Update channelStable for production; Beta only for deliberate testing
Auto-check hosted library updatesCompares the reusable cache with current metadata
Auto-update downloaded library cacheRefreshes reusable templates only; never rewrites placed page content

Direct AI provider

SettingGuidance
Use custom OpenAI-compatible AI endpointEnables the direct server-side provider path
Endpoint URLHTTPS base URL or chat-completions URL
API keyStored server-side; a non-empty key also enables and prioritizes this path
ModelExact provider model ID
Timeout30–180 seconds
Temporarily allow HTTPLocal/testing only; keep off in production

Permissions

PageDesigner registers:

PermissionGrants
admin.page_designer.viewView Page Designer
admin.page_designer.createCreate pages
admin.page_designer.updateUpdate pages and use the editor
admin.page_designer.deleteDelete pages
admin.page_designer.hosted.viewView Hosted library and marketplace data
admin.page_designer.hosted.downloadDownload Hosted components and page packages
admin.page_designer.custom_components.manageCreate, fork, upload, and delete local custom components
admin.page_designer.components.shareShare components
admin.page_designer.pages.shareShare pages
admin.page_designer.license.manageManage or recover licensing
admin.page_designer.updates.runRun Hosted update checks
admin.page_designer.ai.useUse the built-in AI agent
admin.page_designer.mcp.manageCreate and revoke MCP access tokens

The default administrator role receives the PageDesigner permissions during install/upgrade unless it already uses wildcard access.

Page reviewer

  • View.
  • Update only when the reviewer is expected to edit.
  • No delete, sharing, custom component, AI Full access policy, license, or MCP management.

Page editor

  • View, create, update.
  • Hosted view/download as needed.
  • Custom component manage only for trusted component maintainers.
  • AI use when the organization permits AI processing.

Publisher

  • View and update, with an organizational publishing approval process.
  • Page sharing only when this role owns distribution.

PageDesigner administrator

  • All relevant permissions, including license, updates, and MCP.
  • Limit this role to trusted administrators.

A license never grants a Paymenter permission. A permission never bypasses a failed license decision.

License and offline behavior

The locally stored signed grant is bound to the license-key hash and install UUID. It contains entitlement and timing data and is verified with bundled public-key material.

When the Hosted service cannot be reached, a previously verified grant can authorize management only through its signed offline-grace deadline.

Already-published local pages continue rendering when management is blocked. This avoids turning a licensing or Hosted outage into a storefront outage.

Queue worker for AI

AI runs dispatch ProcessAiRun jobs to Laravel's configured default queue.

Operational requirements:

  • Run a persistent queue worker.
  • Monitor failed jobs.
  • Restart workers after relevant deploys.
  • Allow jobs longer than the configured provider timeout; PageDesigner jobs allow up to 300 seconds.
  • Avoid a restrictive queue allow-list that excludes the default queue used by the application.

Each job makes one model-response step, checkpoints it, and dispatches the next step when necessary.

Page-level Custom Code

The page record contains five slots:

SlotRender location
Custom Head HTMLPage document head
Custom HTML (Before Content)Before PageDesigner canvas content
Custom HTML (After Content)After canvas content
Custom CSSAfter PageDesigner page styles
Custom JavaScriptAfter page content; script tags optional

Normal editor policy

Leave these slots empty unless a trusted developer has provided and reviewed the exact content.

Review requirements

  • Read the existing slot before changing it.
  • Keep a backup of the previous value.
  • Understand public execution and data exposure.
  • Prefer append for a new independent script.
  • Replace only with explicit intent and complete review.
  • Use head scripts only when load timing genuinely requires it.
  • Do not duplicate SEO tags already managed by PageDesigner.
  • Avoid selectors or scripts that affect the Paymenter shell globally.
  • Test signed-out, mobile, and both themes.

Custom JavaScript executes for public visitors. Never place credentials, license keys, MCP tokens, provider keys, private API endpoints, or server-only data in page code.

Page deletion and bulk deletion

Deletion is permanent in the normal page list and MCP requires explicit confirmation. Before deletion:

  • unpublish when temporary removal is enough;
  • inventory inbound links;
  • save a reviewed share/export or database backup when recovery may be needed;
  • confirm the page is not a source for an active campaign;
  • ensure bulk selection is correct.

Sharing governance

Define who may:

  • share unlisted packages;
  • publish a package to Page Marketplace;
  • import community packages;
  • approve custom code contained in a page package;
  • redistribute media and copy.

Imported pages must remain drafts until review.

Backup and recovery

Back up the database before:

  • extension upgrades;
  • uninstall;
  • bulk deletion;
  • major MCP or Full access AI migrations;
  • schema or infrastructure changes.

Retain the PageDesigner ZIP that matches the backup.

For rollback, restore the database and previous ZIP together. Do not selectively delete or recreate PageDesigner tables.

Audit and diagnostics

PageDesigner records hosted lifecycle, download, sharing, import, AI, and related events in its audit table when available. Application logs and the hosted diagnostic response are also important.

Do not include raw secrets in tickets or screenshots. Redact:

  • license keys;
  • custom AI keys;
  • MCP tokens;
  • Authorization headers;
  • private package links;
  • customer data.

Security checklist

  • HTTPS application URL is correct.
  • Public server IP is correct when required.
  • Stable update channel is used in production.
  • Page editor roles have least privilege.
  • Queue workers are monitored.
  • Direct provider uses HTTPS.
  • Custom components are reviewed as code.
  • Page-level scripts contain no secrets.
  • Each MCP client has a separate token.
  • Unused MCP tokens are revoked.
  • Public marketplace sharing has an approval owner.
  • Database and previous ZIP backups exist.

On this page