Live probe vs my Plane spec: two assumptions died in 27 minutes
My 905-line Plane sync spec lost two assumptions to a live probe: HTML markers stripped by server-side sanitization, archive endpoint 404.
TL;DR
A live probe against Plane Community Edition broke two assumptions in a 905-line sync spec before any code was written. Hidden HTML comments for identity were stripped by server sanitization, and the archive endpoint returned 404 because CE trails cloud. Fix stores metadata in visible text and a config file, uses Done instead of archive, and hashes normalized text.
Twenty-seven minutes after finishing my 905-line sync spec, I sat back down at the terminal. Not to write, but to read the results of a live probe: one disposable work item I created, retrieved, updated, and commented on directly against my Plane Community Edition instance. Two of the spec's core assumptions died on that same screen.
The identity marker I hid inside an HTML comment? Gone. The archive endpoint my cleanup flow relied on? The server answered 404. Nine hundred lines of design, and two of its foundations collapsed before a single line of integration code existed.
The guess that missed
The original design was neat: every document mirrored into a Plane work item carried a machine marker <!-- plane-doc-sync:v2 path=.pm/DECISIONS.md --> at the top of the description. From that marker, the skill knew which document paired with which item, plus the last synced hash.
Cleanup was already pictured too: finished items get archived through the API, and the board stays clean. My reasoning was simple, the server just stores what I send. The official docs list a description_html field, I send HTML, surely nothing touches it.
What was actually stored
The probe broke both assumptions at once. The create response echoed exactly the HTML I sent, so the first few seconds felt safe. But when I retrieved the same item, a different version came back: the HTML comment was gone entirely, and the multi-element fragment had been rewrapped into a single <div>. What I sent is not what got stored.
The archive endpoint? On this CE build the answer was 404. Not a permission error, not a validation failure. The endpoint simply is not there.
Read from the source-code side, it all makes sense. Plane sanitizes HTML server-side with nh3, using allowlists for tags, attributes, and URL schemes [3]. HTML comments are obviously not on that list. The comment and intake paths were only closed in the June 2026 security fix that made validate_html_content() mandatory in the related serializers [2]. Before that date, some paths still stored raw HTML.
The stable field is not the raw HTML at all. The API docs ship description_stripped, the stripped version of the HTML description auto generated by the application [1]. The server always derives a plain-text form of the description. If you need identity or hashing, that plain text is the layer to trust, not HTML whose shape can be silently rearranged.
As for that 404, it follows from their release model. The Community Edition is a separate codebase with its own release cycle, and new features land there last [5]. This edition sits at parity with the Cloud Free tier, not the paid tiers [4]. Meanwhile the official docs and tool surface, the MCP server with its 28 tools and 183 actions [6], describe the cloud surface. Treat a cloud endpoint as automatically present on CE and you get exactly what I got: a 404 at the worst possible moment.
Decisions after the probe
The spec was amended immediately. The marker moved to a visible first line, plain plane-doc-sync:v2 path=... with no HTML comment, and the item identity (the work item ID per document) moved into the .pm/plane.json config file. Machine metadata has to live where the sanitizer will never clean.
Cleanup without archive: finished mirror items just move to the Done status, and a disposable probe item may only be deleted if the probe itself created it. Drift detection uses updated_at, which advances on every write, while hashes are computed over normalized extracted text. Never again over raw HTML whose shape the server rearranges.
One disposable probe item, ten minutes of work, and two pages of spec were saved from an implementation that was guaranteed to break. Probe first, then trust. Especially when the target is a self-hosted edition that always receives features last.