# Plugins really need access to Adobe ID of user (or really any unique ID)

**URL:** <https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378>\
**Category:** UXP Plugin API\
**Tags:** api-feedback\
**Created:** [November 7, 2018, 10:19pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378 "2018-11-07T22:19:13Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [November 7, 2018, 10:19pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/1 "2018-11-07T22:19:13Z")

</div>

I know we’ve discussed this briefly over on the Adobe-Dev Slack (thanks, Kerri), but I’d like to bring it up here for visibility.

If we’re going to monetize plugins, we’ll need some way of “registering” a plugin on its first use, and thus we’ll need some unique ID for the Xd user.

I realize access to the Adobe ID (which is also an email address?) is fraught, but perhaps the plugin API could just provide a unique identifier (the internal unique ID for the Adobe ID itself, or some transformed version that’s still unique)?

Thoughts?

---

<div class="post-metadata">

**Author:** ![stevekwak](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/stevekwak/32/48_2.png) [@stevekwak](https://forums.creativeclouddeveloper.com/u/stevekwak)\
**Post date:** [April 12, 2019, 2:39pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/2 "2019-04-12T14:39:15Z")

</div>

Other than the purpose of having a unique id for each user, is there any other use case for having access to user’s Adobe ID?

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [April 12, 2019, 3:03pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/3 "2019-04-12T15:03:12Z")

</div>

No, but you had to admit that enabling licensing control is a pretty big deal if you want a thriving commercial market for XD plugins.

Of course, that’s a good question: what does Adobe envision about the plugins market? Commercial or open-source only?

---

<div class="post-metadata">

**Author:** ![afuchs](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/afuchs/32/28_2.png) [@afuchs](https://forums.creativeclouddeveloper.com/u/afuchs)\
**Post date:** [April 12, 2019, 7:29pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/4 "2019-04-12T19:29:36Z")

</div>

Hi @cpryland we’ll be adding support for commercial plugins in the future, though the timeline is still TBD. First step will be linking plugin acquisition to the user’s profile automatically - we do this already for other CC extension types through the Adobe Exchange. This will also ensure that users who install a plugin see that same plugin install on any other device they might be using.

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [April 12, 2019, 7:50pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/5 "2019-04-12T19:50:23Z")

</div>

OK, thanks.

But note that the general sentiment about at least the indie devs about the whole Exchange system is “meh” at best, even with all the improvements made this past year.

Perhaps that’s partly about un-discoverability that’s addressed in XD’s plugins “front and center” approach.

---

<div class="post-metadata">

**Author:** ![afuchs](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/afuchs/32/28_2.png) [@afuchs](https://forums.creativeclouddeveloper.com/u/afuchs)\
**Post date:** [April 15, 2019, 10:02pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/6 "2019-04-15T22:02:52Z")

</div>

Totally understand. While more improvements are coming down the pipe for the Exchange overall, in-app plugin discovery is an area we’re investing heavily in, starting with XD.

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [August 17, 2019, 4:51pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/7 "2019-08-17T16:51:18Z")

</div>

Now that we’re mostly through the panel plugins roll-out, any further thoughts about this, @afuchs?

---

<div class="post-metadata">

**Author:** ![afuchs](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/afuchs/32/28_2.png) [@afuchs](https://forums.creativeclouddeveloper.com/u/afuchs)\
**Post date:** [August 19, 2019, 2:18pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/8 "2019-08-19T14:18:07Z")

</div>

Many thoughts 🙂 Can’t commit to dates, but XD plugins tied to user accounts is something we’re going to be working on for post-MAX.

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [August 19, 2019, 6:32pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/9 "2019-08-19T18:32:57Z")

</div>

Excellent!

But note that if XD simply gave us access to even a hashed Adobe User ID (unique to each user, but non-identifiable), that would be enough for us to hang a whole homegrown licensing scheme on.

As it is, we have nothing that isn’t trivially wiped out (e.g., by uninstalling and re-installing).

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [December 9, 2019, 7:10pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/10 "2019-12-09T19:10:56Z")

</div>

> But note that if XD simply gave us access to even a hashed Adobe User ID (unique to each user, but non-identifiable), that would be enough for us to hang a whole homegrown licensing scheme on.

Ari (@afuchs), Kerri (@kerrishotts), any update on this? It’s going to be critical in the near future for us.

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [January 29, 2020, 7:04pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/11 "2020-01-29T19:04:51Z")

</div>

I haven’t beat this horse for over a month. 😉

This has 8 votes (which isn’t bad for this forum).

Any chance we’ll get something along these lines soon?

@peterflynn?

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [March 7, 2020, 8:29pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/12 "2020-03-07T20:29:53Z")

</div>

Can I drag this up again? This is going to be important for us this year.

---

<div class="post-metadata">

**Author:** ![paolo.agostinetto](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/paolo.agostinetto/32/754_2.png) [@paolo.agostinetto](https://forums.creativeclouddeveloper.com/u/paolo.agostinetto)\
**Post date:** [March 11, 2020, 2:06pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/13 "2020-03-11T14:06:26Z")

</div>

@cpryland I’m not sure if this could help you but you could generate an UUID yourself (eg. using [https://www.npmjs.com/package/uuid-random](https://www.npmjs.com/package/uuid-random)) and store it in the file system, then use that “installation id” to authenticate your users server side while bootstrapping the plugin.

---

<div class="post-metadata">

**Author:** ![cpryland](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/cpryland/32/1172_2.png) [@cpryland](https://forums.creativeclouddeveloper.com/u/cpryland)\
**Post date:** [March 11, 2020, 4:15pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/14 "2020-03-11T16:15:49Z")

</div>

That’s an idea I’ve considered, but it doesn’t solve the problem of someone installing XD on two alternately-used computers.

If Adobe provided the uniqified but anonymous user ID, then we’d know it was the “same” user and thus would have no licensing problems with the second machine.

---

<div class="post-metadata">

**Author:** ![Velara](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/velara/32/1278_2.png) [@Velara](https://forums.creativeclouddeveloper.com/u/Velara)\
**Post date:** [August 7, 2020, 6:53pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/15 "2020-08-07T18:53:30Z")

</div>

I’ve upvoted this for a unique ID. I’m adding a few details:

- unique ID **without** user details (anonymous)
- unique ID **with** user details
- unique anonymous ID can be reset by user
- the unique ID with details must prompt user upon request or at install

---

<div class="post-metadata">

**Author:** ![pklaschka](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/pklaschka/32/3162_2.png) [@pklaschka](https://forums.creativeclouddeveloper.com/u/pklaschka)\
**Post date:** [August 7, 2020, 7:18pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/16 "2020-08-07T19:18:17Z")

</div>

> [@Velara](#):
>
> - unique ID **with** user details

May I ask what the Use-Case of this would be? I can go along with a unique identifier for users (for licensing implementations), but I don’t see why user details would be necessary in a lot of cases:

1. it’s clearer for users what data gets processed by the plugin if they have to enter it in the plugin manually (instead of just clicking _Allow_ for the sake of getting a plugin to work)
2. if user details are relevant for a plugin’s feature, that could probably get achieved with OAuth? (again: making data exposed to the plugin more obvious to users)

In my opinion, the one thing required, as stated in the original request (and your first bullet point) is an anonymous “derived” unique user id. It is required because it can’t be solved by plugins in another way.

User details, on the other hand, can get solved in other ways. It is not the case that plugins require “automatic access”, in a sense, to these details to work. If a plugin needs these details, users can explicitly enter them. This, then, makes it much clearer than a popup _Plugin XY requires access to your user data to work_ which data actually gets processed by the plugin. In my opinion, the manual way, in this case, is the better way. Too big would the implications for user privacy be if access was just one click of a button away.

* * *

Playing the Devil’s Advocate for a bit: The knowledge (that’s not far away with user details) that a user (with a known email-address or something like this) is

- using XD version X
- from country X (in most cases traceable by the IP address of the HTTP request submitting these details to the attacker’s database)
- speaking language X (one of the languages detectable by `application.systemLocale`
- using plugin XY
- opened a document at time XY
- (optional:) the user’s name is X
- probably subscribed to the Creative Cloud (at least the “targets of interest”)
- […]

would be retrievable by a plugin getting “easy” access to user details (e.g., the email) and could make for a pretty convincing phishing email attack (considering a user probably doesn’t think too much about clicking an _Allow_ button regarding such access).

---

<div class="post-metadata">

**Author:** ![Velara](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.creativeclouddeveloper.com/velara/32/1278_2.png) [@Velara](https://forums.creativeclouddeveloper.com/u/Velara)\
**Post date:** [August 7, 2020, 11:02pm UTC](https://forums.creativeclouddeveloper.com/t/plugins-really-need-access-to-adobe-id-of-user-or-really-any-unique-id/378/17 "2020-08-07T23:02:03Z")

</div>

Indeed.

I would not want this feature unless it gave **the user** full control of what info to share with the plugin.

My use case is for where someone purchases a license for a plugin at an external site and to verify the purchase the purchase email is compared to the Adobe user email or something along these lines.

And with both the anonymous or non-anonymous option is to make the **Unique User ID** specific to the plugin.

Meaning each plugin would be able to receive a unique user ID that is specific to their plugin or vendor so that it means nothing outside of the plugin.
