How authorization works
1
The app requests access
A plugin or agent starts an authorization session and opens Pixio in your browser.
2
You approve while signed in
You land on the Pixio authorization page. Because you’re signed in, Pixio knows which account is granting access. Approve, and that session is linked to the requesting app.
3
The app picks it up
The app polls until authorization completes, then holds its own session — no key copied by hand, no key sitting in a config file.
4
You keep working
From then on it acts on your account, spending your credits and writing into your assets.
Nothing is granted until you approve in a signed-in browser. An app can start the request, but it can’t complete it on your behalf.
What an authorized app can do
The same things you can, subject to your plan:- Generate media and spend your credits
- Read and write your assets
- Read your credit balance and plan
- Run workflows you’ve saved
Before you approve
Worth asking:- Did I start this? An authorization page you didn’t trigger is a red flag.
- Do I trust it with credits? Approval is account access, not a read-only peek.
- Can I revoke it? Yes — see below. Approval is reversible.
Revoking access
Signing out of the granting session ends the app’s access. If you’re unsure what’s connected or want a clean slate:- Change your password, which invalidates existing sessions.
- Review your integration keys in Integrations and disable any you don’t recognize.
