---
title: "Content Protection"
description: "Control which parts of a Tiptap document users can edit or read."
canonical_url: "https://tiptap.dev/docs/composable-docs/content-protection/getting-started/overview"
---

# Content Protection

Control which parts of a Tiptap document users can edit or read.

Content Protection controls which parts of a document users can edit or read. Define permissions for Nodes, Marks, attributes and content with a policy.

> **Client-side only:**
>
> Content protection is applied only client-side. For server-side content protection, [contact
> us](https://tiptap.dev/contact-sales?form=pilot-program).

## Install

First, [contact our team](https://tiptap.dev/contact-sales?form=pilot-program) for access to the Content Protection pilot program.

After gaining access, follow the [private registry setup guide](https://tiptap.dev/docs/guides/pro-extensions.md), then install the package:

```bash
npm install @tiptap/core @tiptap/starter-kit @tiptap/y-tiptap yjs @tiptap-pro/extension-content-protection
```

Add the extension to your editor.

```ts
import { Editor } from '@tiptap/core'
import StarterKit from '@tiptap/starter-kit'
import {
  ContentProtection,
  type ContentProtectionPolicy,
} from '@tiptap-pro/extension-content-protection'

const policy: ContentProtectionPolicy = {
  version: 1,
  rules: [
    {
      selector: { target: 'node', node: { types: ['heading'] } },
      permissions: { edit: false },
    },
  ],
}

const editor = new Editor({
  extensions: [StarterKit, ContentProtection.configure({ policy })],
})
```

Provide a [policy](https://tiptap.dev/docs/composable-docs/content-protection/api-reference/policy.md) that defines what can be edited.

You can also update the content protection rules while the editor is running:

```ts
editor.commands.setContentProtectionPolicy({ policy })
```

See the [API reference](https://tiptap.dev/docs/composable-docs/content-protection/api-reference/extension.md) and [policy language](https://tiptap.dev/docs/composable-docs/content-protection/api-reference/policy.md).

## Collaboration

Content Protection supports [Tiptap Collaboration](https://tiptap.dev/docs/editor/extensions/functionality/collaboration.md). Each collaborator can have a different local policy. Local edits are checked against that policy; updates from the collaboration binding are accepted so all editors stay synchronized with the shared document. This includes initial synchronization and collaborative undo/redo, even if the current local policy would reject the corresponding edit. Read permissions still control what each collaborator sees and copies.

```ts
import Collaboration from '@tiptap/extension-collaboration'

const editor = new Editor({
  extensions: [
    StarterKit.configure({ undoRedo: false }),
    Collaboration.configure({ document: ydoc }),
    ContentProtection.configure({ policy: localPolicy }),
  ],
})
```

Here, `ydoc` is the shared Y.Doc connected to your collaboration provider, and `localPolicy` is the policy your application assigns to this user. Install `@tiptap/extension-collaboration` to use this setup. Policies remain local and are not stored in the shared document. These client-side permissions do not authorize incoming collaboration updates; enforce access to the shared document in your application and collaboration service.
