ComfyUI's security level controls what the interface can do with your files and network
ComfyUI has three security levels — normal, restricted, and high — that determine whether the interface can read files outside its folder, write to your disk, or connect to the internet. You change the security level by editing the comfy.yaml configuration file and restarting ComfyUI. The level you choose depends on whether you're running ComfyUI alone on your own machine, sharing it with others, or exposing it to a network.
Most people running ComfyUI locally for personal use leave it at the default normal level. If you're running it on a shared machine, a server, or anywhere untrusted users might access the interface, you should move to restricted or high. Understanding what each level blocks helps you decide which one fits your setup without breaking workflows that depend on file access.
Key Takeaways
- The security level is set in the comfy.yaml file under the key security, with options of normal, restricted, or high.
- Normal level allows the interface to read and write files anywhere on your system and connect to external URLs, which is the default and works for local personal use.
- Restricted level prevents the interface from accessing files outside the ComfyUI folder and blocks certain network operations, protecting your system if untrusted people have access to the interface.
- High level is the most locked-down option and blocks nearly all file system access outside ComfyUI's own directories, plus blocks external network connections entirely.
- After you change the security level in comfy.yaml, you must restart ComfyUI for the change to take effect.
Where to find and edit the comfy.yaml file
The comfy.yaml file lives in your ComfyUI root directory — the main folder where you installed ComfyUI. On Windows, this is usually C:\Users\[YourUsername]\ComfyUI or wherever you extracted it. On Mac or Linux, it's typically in your home directory as ~/ComfyUI or /opt/ComfyUI, depending on how you installed it.
Open comfy.yaml with any text editor — Notepad on Windows, TextEdit on Mac (set to plain text), or nano or vim on Linux. Look for a line that says security: followed by the current level. If the line doesn't exist, you can add it. The file uses YAML format, which means indentation matters: the security line should be at the same indentation level as other top-level settings like server: or models_dir:.
Understanding normal security level
Normal is the default and least restrictive level. At this level, ComfyUI can read files from anywhere on your system, write output files to any folder you specify, and make connections to external URLs. This means workflows can load images from your Documents folder, save results to a network drive, or fetch models from the internet without hitting any security barriers.
Normal level is safe for personal machines where only you have access to the ComfyUI interface. It becomes a risk if you're running ComfyUI on a shared computer, a server accessible over a network, or anywhere someone else could reach the web interface. A person with access to the interface could potentially read sensitive files from your system or use ComfyUI to connect to external services.
Understanding restricted security level
Restricted level tightens file access significantly. ComfyUI can still read and write files, but only within its own directory structure — typically the ComfyUI folder and its subfolders. It cannot access files in your Documents, Downloads, Desktop, or anywhere else on the system. External network connections are also limited: the interface cannot fetch files from URLs or connect to external APIs, though it can still reach localhost connections on your own machine.
Restricted level is the right choice if you're running ComfyUI on a shared machine or a home server that multiple people might access. It prevents someone from using the interface to snoop through your files or use your computer's network connection to reach external services. Workflows that depend on loading images from outside the ComfyUI folder will fail, so you'll need to move those files into the ComfyUI directory structure first.
Understanding high security level
High level is the most restrictive. It blocks nearly all file system access outside ComfyUI's own directories and disables external network connections entirely. The interface can read and write only within ComfyUI's folder structure and cannot make any outbound connections to the internet or to external services. This is the appropriate level for public-facing servers or any environment where you don't trust the people who might access the interface.
High level will break most workflows that depend on external resources — loading models from URLs, fetching images from the internet, or connecting to external APIs. It's rarely necessary for personal or small-team setups. Use it only if ComfyUI is exposed to untrusted users or if you're running it in an environment where security is the primary concern over functionality.
How to change the security level and restart ComfyUI
Edit the comfy.yaml file and change the line security: normal to security: restricted or security: high, depending on your needs. Save the file. Then stop ComfyUI completely — close the terminal window or command prompt where it's running, or use Ctrl+C if it's running in the foreground. Wait a few seconds to make sure the process has fully shut down.
Restart ComfyUI by running the startup script or command you normally use. On Windows, this might be run_nvidia_gpu.bat or run_cpu.bat. On Mac or Linux, it's usually ./launch.sh or a Python command. ComfyUI will read the updated comfy.yaml file and apply the new security level. You can verify the change took effect by checking the terminal output — ComfyUI often logs the security level at startup.
Common workflows that break at restricted or high levels
If you move to restricted or high security, certain workflows will stop working. Any workflow that loads images or models from outside the ComfyUI folder will fail — for example, loading a checkpoint from your Downloads folder or an image from your Desktop. Workflows that fetch models from URLs or download checkpoints from the internet will also fail because external network access is blocked.
The fix is to move the files you need into the ComfyUI directory structure. Models go in ComfyUI/models/checkpoints, images go in ComfyUI/input, and so on. If you have workflows that absolutely require external network access or file system access outside ComfyUI's folder, restricted and high levels won't work for you — you'll need to stay at normal level and rely on other security measures, like running ComfyUI only on trusted networks or behind authentication.
Frequently Asked Questions
Do I need to change the security level if I'm the only one using ComfyUI?
No. If ComfyUI is running only on your personal machine and only you have access to it, normal level is fine. Security levels matter when other people might reach the interface — either over a network or on a shared computer.
Will changing the security level delete my models or workflows?
No. Changing the security level only changes what ComfyUI is allowed to access, not what files exist on your system. Your models, workflows, and images remain untouched. Workflows that depend on files outside ComfyUI's folder will fail to run, but the files themselves are still there.
Can I switch between security levels without restarting?
No. ComfyUI reads the security level from comfy.yaml when it starts up. You must fully restart ComfyUI for a security level change to take effect. Editing the file while ComfyUI is running won't apply the change until you stop and restart it.
What if I set the security level too high and my workflows break?
Change the security level back to normal in comfy.yaml, restart ComfyUI, and your workflows will work again. You can also move the files your workflows need into the ComfyUI folder structure and try restricted level instead of high.
Is there a way to set different security levels for different users?
No. The security level in comfy.yaml applies to the entire ComfyUI instance. If you need different access levels for different users, you would need to run separate ComfyUI instances with different configurations, which is not a common setup.