> ## Documentation Index
> Fetch the complete documentation index at: https://differentai-fix-signin-code-field-label.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create plugin

> Creates a plugin and can also create components, share org-wide, and publish to a marketplace in one request. An mcp component may carry the same connection setup as the Connections page (authentication, credential mode, API key, OAuth app), or instead reference an existing organization connection by connectionId, so its server is configured immediately; owners and admins only.



## OpenAPI

````yaml /openapi.json post /v1/plugins
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - bearerAuth: []
  - denApiKey: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Inference Providers
    description: >-
      Organization inference Gateway providers, model groups, credential sets,
      access grants, member connections, and usage.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/plugins:
    post:
      tags:
        - Plugins
      summary: Create plugin
      description: >-
        Creates a plugin and can also create components, share org-wide, and
        publish to a marketplace in one request. An mcp component may carry the
        same connection setup as the Connections page (authentication,
        credential mode, API key, OAuth app), or instead reference an existing
        organization connection by connectionId, so its server is configured
        immediately; owners and admins only.
      operationId: postV1Plugins
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 255
                description:
                  anyOf:
                    - type: string
                      minLength: 1
                    - type: 'null'
                sourceRepositoryUrl:
                  type: string
                  minLength: 1
                  maxLength: 1024
                components:
                  maxItems: 100
                  type: array
                  items:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - skill
                          - agent
                          - command
                          - tool
                          - mcp
                          - hook
                          - context
                          - custom
                          - script
                          - workflow
                          - app
                      input:
                        type: object
                        properties:
                          rawSourceText:
                            type: string
                            minLength: 1
                          normalizedPayloadJson:
                            type: object
                            properties: {}
                            additionalProperties: {}
                          parserMode:
                            type: string
                            minLength: 1
                            maxLength: 100
                          schemaVersion:
                            type: string
                            minLength: 1
                            maxLength: 100
                          metadata:
                            type: object
                            properties: {}
                            additionalProperties: {}
                      connection:
                        type: object
                        properties:
                          authType:
                            default: oauth
                            type: string
                            enum:
                              - oauth
                              - apikey
                              - none
                          credentialMode:
                            type: string
                            enum:
                              - shared
                              - per_member
                          apiKey:
                            type: string
                            minLength: 1
                            maxLength: 4096
                          oauthClient:
                            type: object
                            properties:
                              clientId:
                                type: string
                                minLength: 1
                                maxLength: 512
                              clientSecret:
                                type: string
                                minLength: 1
                                maxLength: 4096
                            required:
                              - clientId
                      connectionId:
                        type: string
                        minLength: 1
                        maxLength: 160
                    required:
                      - type
                orgWide:
                  type: boolean
                marketplaceId:
                  description: >-
                    Den TypeID with 'mkt_' prefix and a 26-character base32
                    suffix.
                  format: typeid
                  type: string
                  minLength: 30
                  maxLength: 30
              required:
                - name
      responses:
        '201':
          description: Plugin created successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PluginArchPluginMutationResponse'
        '400':
          description: The plugin creation request was invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidRequestError'
        '401':
          description: The caller must be signed in to create plugins.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: The caller lacks permission to create plugins.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
        '404':
          description: The marketplace could not be found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFoundError'
      security:
        - bearerAuth: []
        - denApiKey: []
components:
  schemas:
    PluginArchPluginMutationResponse:
      type: object
      properties:
        ok:
          type: boolean
          const: true
        item:
          $ref: '#/components/schemas/PluginArchPlugin'
      required:
        - ok
        - item
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    NotFoundError:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
      required:
        - error
    PluginArchPlugin:
      type: object
      properties:
        id:
          description: Den TypeID with 'plg_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        organizationId:
          description: Den TypeID with 'org_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        name:
          type: string
          minLength: 1
          maxLength: 255
        description:
          anyOf:
            - type: string
              minLength: 1
            - type: 'null'
        sourceRepositoryUrl:
          anyOf:
            - type: string
              minLength: 1
              maxLength: 1024
            - type: 'null'
        sourceFormat:
          anyOf:
            - type: string
              enum:
                - agent-plugin
                - openwork-builtin
                - openwork-extension-manifest
                - claude-plugin
                - opencode-plugin
                - mcp-directory
                - manual
            - type: 'null'
        sourceSchemaVersion:
          anyOf:
            - type: string
              minLength: 1
              maxLength: 100
            - type: 'null'
        status:
          type: string
          enum:
            - active
            - inactive
            - deleted
            - archived
        createdByOrgMembershipId:
          description: Den TypeID with 'om_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 29
          maxLength: 29
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        deletedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            - type: 'null'
        memberCount:
          type: integer
          minimum: 0
          maximum: 9007199254740991
        marketplaces:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  Den TypeID with 'mkt_' prefix and a 26-character base32
                  suffix.
                format: typeid
                type: string
                minLength: 30
                maxLength: 30
              name:
                type: string
                minLength: 1
                maxLength: 255
            required:
              - id
              - name
        extension:
          anyOf:
            - $ref: '#/components/schemas/PluginArchExtensionProjection'
            - type: 'null'
      required:
        - id
        - organizationId
        - name
        - description
        - sourceRepositoryUrl
        - sourceFormat
        - sourceSchemaVersion
        - status
        - createdByOrgMembershipId
        - createdAt
        - updatedAt
        - deletedAt
    PluginArchExtensionProjection:
      type: object
      properties:
        id:
          description: Den TypeID with 'plg_' prefix and a 26-character base32 suffix.
          format: typeid
          type: string
          minLength: 30
          maxLength: 30
        name:
          type: string
          minLength: 1
          maxLength: 255
        description:
          anyOf:
            - type: string
              minLength: 1
            - type: 'null'
        sourceFormat:
          type: string
          enum:
            - agent-plugin
            - openwork-builtin
            - openwork-extension-manifest
            - claude-plugin
            - opencode-plugin
            - mcp-directory
            - manual
        manifest:
          anyOf:
            - $ref: '#/components/schemas/OpenWorkExtensionManifest'
            - type: 'null'
      required:
        - id
        - name
        - description
        - sourceFormat
        - manifest
    OpenWorkExtensionManifest:
      type: object
      properties:
        schemaVersion:
          type: number
          const: 1
        id:
          type: string
          minLength: 1
          maxLength: 255
        name:
          type: string
          minLength: 1
          maxLength: 255
        description:
          type: string
          minLength: 1
          maxLength: 2048
        source:
          type: object
          properties:
            format:
              type: string
              enum:
                - agent-plugin
                - openwork-builtin
                - openwork-extension-manifest
                - claude-plugin
                - opencode-plugin
                - mcp-directory
                - manual
            trusted:
              type: boolean
            origin:
              type: string
              enum:
                - builtin
                - den
                - workspace
                - local
            reference:
              type: string
              minLength: 1
              maxLength: 512
          required:
            - format
            - trusted
        resources:
          type: array
          items:
            type: object
            properties: {}
            additionalProperties: {}
        contributions:
          type: array
          items:
            type: object
            properties: {}
            additionalProperties: {}
        setup:
          type: object
          properties: {}
          additionalProperties: {}
        lifecycle:
          type: object
          properties: {}
          additionalProperties: {}
      required:
        - schemaVersion
        - id
        - name
        - description
        - source
        - resources
      additionalProperties: {}
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes.
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.

````