---
title: Shared Sign-In (one Google login across the plugins you allow)
---

# Shared Sign-In (one Google login across the plugins you allow)

## What it is

### The problem it fixes

Every plugin panel used to get its own private browser storage. Google's account picker was
therefore empty inside every plugin, so a person had to type their full email, password and
2-factor code **once per computer, per plugin** — even though they were already signed into
that same account elsewhere in the app. To a non-technical user this reads as "it doesn't
know me", and it generated support questions.

## Where to find it

**Where you see it:** the permission card when you install or re-approve a plugin, and a **Shared
sign-in** card in Settings → Plugins once at least one plugin uses it. The Settings card is also
where the **Sign out** button lives.

## How it behaves

### What the permission does

A plugin that asks for **Shared Sign-In** renders on ONE shared browser session that every
other plugin granted the same permission also uses. Sign in inside any of them and the rest
show a normal, pre-filled account picker instead of a blank sign-in form. It also lets that
plugin open a real sign-in popup, which plugins previously could not do at all.

A plugin that does not ask for it is completely unchanged — its own private storage, no
popups.

### The honest limits, stated on the card

- **The first sign-in still happens once.** The shared session starts empty, so the first
  plugin on a machine is a full sign-in. What disappears is having to repeat it for every
  plugin after that.
- **Plugins sharing the session can see each other's saved sign-in data.** Every plugin is
  served from the same local address, so they share one web origin and are kept apart only
  by that storage. Sharing it is therefore a real trade, which is why the permission is
  marked elevated, why the consent card **names the plugins already sharing it**, and why
  the setting lets you sign out of them all in one click.
- **It is not the in-app Browser's session.** The browser you use inside the app keeps its
  own separate login; nothing here reaches it.
- **Having Gmail connected does not carry over.** That is an account grant made in your
  system browser, not a browser login, so it cannot pre-fill a plugin's account picker.

### Signing out

Settings → Plugins → **Shared sign-in** lists every plugin using it and offers **Sign out**,
which clears the shared session — each of those plugins will ask for a sign-in again next
time it needs one. It never uninstalls anything. The session also clears itself once no
plugin uses it any more, so removing the last one does not leave a login stranded.

### Why the app decides, not the plugin

The plugin's panel asks for the shared session, but the main app never takes that at face
value: it works out which plugin a panel really is from the web address itself and re-checks
its own records before allowing it. If the check is ever left unwired, the answer is no.
A panel loading from disk at startup keeps its own private storage instead, because a disk
path cannot prove which plugin it belongs to.

## For agents

Contract: [webview-oauth-popup-contract.md](../../.claude/memory/contracts/webview-oauth-popup-contract.md)
(`shared-jar-*` invariants).

## Related

Shared Sign-In is one of the permissions a plugin asks for on the same consent card as the document
permissions in [plugin-documents-permission.md](plugin-documents-permission.md). Installing,
approving and removing the plugins themselves is [plugin-marketplace.md](plugin-marketplace.md), and
the plugin screens that benefit from a pre-filled account picker are described in
[plugin-settings-panel.md](plugin-settings-panel.md).
