Text · HTML macro

The layout Confluence will not let you build, with an admin who says yes

With the HTML macro you get the table, the widget or the branded callout the editor does not offer - and your admin gets markup that is sanitised on the way in. Reaching for HTML stops meaning opening a hole, so the request to install it comes back approved.

You stop fighting the editor

A landing page for a space, a comparison table with the columns you actually want, a layout that survives on a phone: write it once in markup you already know instead of coaxing the wiki editor into an approximation of it.

Your admin can say yes

Everything is cleaned with DOMPurify before it reaches the page and scripts are stripped, so the macro is not the script-injection point an HTML macro usually is. That is the difference between an admin allowing this and an admin refusing to - you get the safety built in, not as a policy you have to enforce.

You get the modal without giving up the guarantee

Because scripts do not run, interaction comes from declarative attributes instead: hook a click, a hover or another DOM event to a command that opens or closes a dialog, straight from your markup. You get the modal or the reveal you wanted, and your security team keeps the guarantee they wanted.

Your styles and embeds still work, from wherever the markup lives

Inline styles and stylesheets are allowed, and so are iframes with the attributes real embeds need - each one sandboxed on the way in - so a third-party widget or a video from another service still lands on your page. Write the markup here, or point the macro at a file: URL, attachment, Git repository, Google Drive, or a credentialed S3, SFTP or database connection.

What the other HTML apps cost you in the security review

The established HTML macros are built to run JavaScript on your pages - one of them makes it a global admin switch. That is why your request to install one so often comes back refused: an app that executes arbitrary script in your instance is a standing invitation to XSS, and no security team enjoys signing it off. This macro takes the argument off the table. Markup is sanitised before it renders and its scripts never run, while clicks, hovers and dialogs still work through declarative attributes - so you get the layout you wanted and your admin gets an answer they can live with.

HTML is one of 31 macros in Macro Pack

One app to install, one licence to renew, one place your team learns - and 30 more formats it already reads, from spreadsheets and diagrams to API specs and documents.

See every macro in the pack