Plugin manifest & handlers
Manifest fields, HTTP handlers, schemas, and return values.
Manifest reference
| Field | Purpose |
|---|---|
| id / name | Set a stable machine ID and a readable name. A name is required; an omitted ID is derived. |
| version / author / description / category / icon | Distribution and display metadata. |
| enabled | Defaults to enabled unless explicitly false. |
| tools | Required array; use [] for a UI-only bundle. |
| tools[].name / description | Required tool identity and model-facing description. Names are not automatically prefixed for plugins. |
| tools[].parametersJsonSchema | Object JSON schema; parameters is also accepted. |
| tools[].handler | javascript, http, or echo. Supply only documented handler types. |
| permissions | Stored metadata, not an enforced capability allowlist. |
| ui_extension / quick_actions / lifecycle | Declared in types; see current loader limitations below. |
Implementation sources
Paths in your AI Plate source checkout:
core/types.tscore/plugin-manager.ts
JavaScript handlers
The runtime injects params, ctx, context, fetch, console, fs, shell, storage, rag, crypto, Buffer, and env. ctx and context refer to the same PluginContext. Return a plain object; exceptions are converted into error objects. Avoid returning secrets, huge payloads, or non-serializable objects.
const previous = storage.get('count', 0);
storage.set('count', previous + 1);
return { count: previous + 1 };javascriptHTTP handlers
URL placeholders {{name}} or {{params.name}} are URL-encoded. bodyTemplate replacements use JSON.stringify, so do not add another pair of quotes around a string placeholder. Headers are literal; environment-variable interpolation in headers is not implemented.
{
"type": "http",
"method": "POST",
"url": "http://127.0.0.1:8787/notes",
"headers": {
"Content-Type": "application/json"
},
"bodyTemplate": "{\"title\": {{title}}}"
}jsonThis POST example requires a service with a POST /notes endpoint; the read-only starter only implements GET. HTTP handlers return { status, data }, including non-2xx status codes. Use a JavaScript handler if you need custom timeout, authentication, or error policy.
Current loader limitations
JavaScript handlers are compiled with AsyncFunction inside the application process. The permissions array and the “sandbox” working directory do not create an OS security boundary. Install trusted code and validate all paths, shell arguments, and remote inputs.
Implementation sources
Paths in your AI Plate source checkout:
core/plugin-manager.ts
