# Plugin permissions and security

Review provider scopes, Foxora assignment, agent tools, autonomy, and external target together; minimize each layer and audit consequential activity.

![Plugin permissions and security in Foxora v5.0.3](/docs/images/v5.0.3/settings/plugins-catalog.webp)

## Where this lives

Open **studio → Plugins** or **Settings → Plugins**.

Plugins connect Foxora to third-party applications through Composio. Composio manages the application authorization, and Foxora exposes the approved actions as tools for selected agents, bots, or workflows.

> **Safety:** Never paste application passwords or access tokens into a prompt. Review Composio authorization scopes and disconnect unused accounts from Foxora and the provider when necessary.

## Steps

1. Open **studio → Plugins** or **Settings → Plugins**.
2. Review provider scopes, Foxora assignment, agent tools, autonomy, and external target together; minimize each layer and audit consequential activity.
3. **Confirm the result.** Run a read-only tool first, verify the connected account and returned record, then test any write action in a safe destination with approvals enabled.

## Choose the right path

- Use a plugin for a supported SaaS application.
- Use MCP for a custom tool server or internal service.
- Use a provider connection or BYOK only for AI model access.


## Confirm it worked

- Run a read-only tool first, verify the connected account and returned record, then test any write action in a safe destination with approvals enabled.
- The screen, command, file, run, or destination named in this guide reflects the expected state.
