How to Change Security Level Comfyui
The ComfyUI-Manager error “This action is not allowed with this security level configuration.” usually means Manager has blocked the action under its current policy. You may see it while installing a custom node, using an install button, or running another Manager action.
The setting lives in ComfyUI-Manager's `config.ini` file. The fix is usually to find that file, change `security_level`, save it, and restart ComfyUI. If changing it to `low` has no effect, the most likely problem is that you edited the wrong file or ComfyUI is using a different user directory.
What the ComfyUI security-level error means
ComfyUI-Manager uses a security level to decide which actions it can perform. Some actions are blocked unless the current level allows them. Installing custom nodes is one situation where this can show up.
The message may appear as:
> This action is not allowed with this security level configuration.
This doesn't necessarily mean your custom node is broken. It means Manager refused the action before, or while, trying to carry it out.
The exact names you may see include:
- `weak`
- `low`
- `middle`
These values represent different security settings. A less restrictive setting can allow actions that a stricter setting blocks, but you shouldn't treat `low` or `weak` as automatically safe. The setting changes what Manager is permitted to do.
If you only need to install a custom node, change the setting for that task, then consider returning to the level you normally use.
Find ComfyUI-Manager's `config.ini` file
Start with the most common location:
```text
ComfyUI\custom_nodes\ComfyUI-Manager\config.ini
```
On a typical Windows installation, the full path may look like this:
```text
C:\ComfyUI\custom_nodes\ComfyUI-Manager\config.ini
```
Your main ComfyUI folder may have a different name, such as a folder inside your Downloads directory. The key part is the folder sequence:
```text
ComfyUI
└── custom_nodes
└── ComfyUI-Manager
└── config.ini
```
Find it through ComfyUI's File Browser
If you don't know where ComfyUI is installed, use ComfyUI's File Browser, if your version provides one. Search for:
```text
config.ini
```
Then check the path around the result. You want the file inside the ComfyUI-Manager folder, not an unrelated `config.ini` belonging to another program or custom node.
This matters because editing a different file won't change Manager's behavior. The file name alone is not enough. Confirm that its parent folder is:
```text
ComfyUI-Manager
```
What if `config.ini` is missing?
A missing file can mean several things:
- ComfyUI-Manager has not created it yet.
- Manager is installed in a different folder.
- Your installation uses a user directory instead of the main ComfyUI folder.
- Your Manager version uses a different setup or creates the file after startup.
Don't create several copies in random folders. First search both the main ComfyUI directory and the user directory described below. If Manager has a configuration screen or file browser, use that to confirm which location it is reading.
Change the `security_level` setting
Make a backup copy of `config.ini` before editing it. For example, copy it as:
```text
config.ini.backup
```
Open the original `config.ini` in a plain text editor. Look for a setting named:
```ini
security_level = middle
```
The spacing may differ. You might instead see:
```ini
security_level=middle
```
Change the value after the equals sign. For example:
```ini
security_level = low
```
The important part is the setting name:
```ini
security_level
```
Don't change the section name, remove unrelated lines, or save the file as a rich-text document. It needs to remain a normal plain-text `.ini` file.
If your version uses `weak` as an available value, that may also appear in its configuration. The supported values can vary by ComfyUI-Manager version, so use the levels shown by your installation or its existing configuration. Don't assume that every version accepts every value.
Should you use `low`, `weak`, or `middle`?
Use the least permissive setting that still allows the action you need. If Manager rejects the action at `middle`, changing to `low` may be the reported fix in some installations. Other versions or setups may use `weak` as a separate level.
There isn't one setting that is universally safe for every installation. A lower level can permit actions that were blocked by policy. Only use it with custom nodes and install sources you trust.
If you are installing a node from a Git URL, the same rule applies. The ComfyUI install via git URL security level is controlled by Manager's security configuration. If the Git URL action is blocked, changing `security_level` may allow it, but review the repository before installing it.
Save the file and restart or reload ComfyUI
Save `config.ini` after changing the value. Make sure the file still ends in `.ini`.
A common Windows problem is accidentally saving it as:
```text
config.ini.txt
```
If file extensions are hidden, the name can look correct even when it isn't. Check the full file name if the setting does not work.
Next, restart ComfyUI. A full restart is the safer choice because Manager may read its configuration only when it starts.
- Stop the ComfyUI process.
- Close the terminal or launcher if it keeps the process running.
- Start ComfyUI again.
- Open ComfyUI-Manager.
- Try the blocked action again.
Some versions may reload Manager settings without a full restart, but restarting avoids confusion about whether the old setting is still in memory.
What to check if the new level is ignored
If you changed the value to `low` and Manager still says it requires `middle`, follow this troubleshooting path.
1. Confirm you edited the active file
Check the full path of the file you changed. It should normally be one of these:
```text
ComfyUI\custom_nodes\ComfyUI-Manager\config.ini
```
or a Manager configuration file inside ComfyUI's user directory.
If you found several files named `config.ini`, compare their surrounding folders. The active one is tied to the ComfyUI-Manager installation that your running ComfyUI instance uses.
2. Check the spelling and format
The setting should be written as `security_level`. Watch for:
- `security level` with a space
- `security-level` with a hyphen
- a misspelled value
- quotation marks added around the value
- two copies of `security_level`, where one later line overrides the first
Use the style already present in the file. If it contains a section header, leave that structure unchanged.
3. Check for a user-directory setting
ComfyUI-Manager can use a protected system path set with:
```text
--user-directory <USER_DIRECTORY>
```
When this option is used, Manager may read or write configuration data in that user directory instead of the folder you expected. The setting may be part of a launcher command, shortcut, startup script, or command-line instruction.
Look for the `--user-directory` option in the way you start ComfyUI. Then inspect that directory for a Manager configuration path. This is one reason changing the file under `custom_nodes` can appear to do nothing.
4. Restart the right ComfyUI instance
You may have more than one ComfyUI copy on your computer. For example, a desktop launcher may start one installation while a terminal command starts another.
After editing the file, check that the running ComfyUI process points to the same installation folder. Stop every old instance before starting the one you want to test.
5. Check for an update or rewrite
If the file changes back after startup, Manager or a launcher may be regenerating it. Save the file, restart ComfyUI, and then open it again to see whether the value stayed in place.
Config.ini locations that appear in ComfyUI installations
There are two main location patterns to check.
Standard custom-nodes path
The usual Windows-style location is:
```text
ComfyUI\custom_nodes\ComfyUI-Manager\config.ini
```
This is the first place to look when Manager was installed as a custom node in the main ComfyUI directory.
ComfyUI user-directory path
Some installations use a user configuration folder. A path that appears in ComfyUI setups is:
```text
ComfyUI\user\default\Comfyui-Manager
```
The capitalization may appear as `ComfyUI-Manager` or `Comfyui-Manager`, depending on the installation and platform. Look for the Manager folder and then check whether it contains `config.ini`.
The exact path can change when ComfyUI is launched with a custom `--user-directory` value. That option takes priority over a location you may have assumed from a standard install.
Using the File Browser
When the paths don't match what you see on disk, search from ComfyUI's File Browser for `config.ini`. Open the result's location and verify that it belongs to ComfyUI-Manager.
If you find no file at all, check whether Manager is installed, start ComfyUI once, and search again. The file may not exist until Manager has initialized. Version differences can also affect when and where it is created.
Security-level issues on Mac and with custom-node installation
On a Mac, the same configuration idea applies: edit ComfyUI-Manager's `config.ini` and change `security_level`. The folder may not use Windows backslashes, though. A user-directory layout may look more like:
```text
ComfyUI/user/default/Comfyui-Manager/config.ini
```
Treat that as a path pattern, not a guaranteed location. Mac installations can be placed in different folders, and the active user directory may be set with:
```text
--user-directory <USER_DIRECTORY>
```
Use Finder, Terminal, or ComfyUI's File Browser to locate the `ComfyUI-Manager` folder. Search for the file rather than assuming it is inside Applications or your home folder.
After editing on Mac:
- Save the file as plain text.
- Confirm it is still named `config.ini`.
- Fully quit and restart ComfyUI.
- Try the custom-node action again.
If you are installing from a Git URL, check that you edited the Manager configuration used by the same ComfyUI process that is showing the error. A second ComfyUI installation can make the change look ineffective.
The supplied ComfyUI setup information does not provide a separate Android method. Don't apply Mac or Windows paths to Android without confirming how that build stores its user directory and Manager files.
When to update ComfyUI or ComfyUI-Manager instead
Editing the configuration is the direct fix for a security-level block, but it isn't always the best next step. Update ComfyUI or ComfyUI-Manager when:
- the setting keeps reverting;
- the file is missing from every expected location;
- Manager shows a security level that doesn't match the file;
- the error started after a partial installation;
- the current version handles configuration differently from the instructions you are following.
Before changing the level again, verify your ComfyUI-Manager version and confirm the exact `config.ini` location used by that installation. That quick check can save you from repeatedly editing a file that the running ComfyUI process never reads.