Overview
Creating and distributing a marketplace involves:- Create plugins: build one or more plugins with skills, agents, hooks, MCP servers, or LSP servers. This guide assumes you already have plugins to distribute; see Create plugins for details on how to create them.
- Create the marketplace file: define a
marketplace.jsonthat lists your plugins and where to find them. See Create the marketplace file. - Host the marketplace: push to GitHub, GitLab, or another git host. See Host and distribute marketplaces.
- Share with users: users add your marketplace with
/plugin marketplace addand install individual plugins. See Discover and install plugins.
/plugin marketplace update.
Walkthrough: create a local marketplace
This example creates a marketplace with one plugin: aquality-review skill for code reviews. You’ll create the directory structure, add a skill, create the plugin manifest and marketplace catalog, then install and test it.
1
Create the directory structure
2
Create the skill
Create a
SKILL.md file that defines what the quality-review skill does.my-marketplace/plugins/quality-review-plugin/skills/quality-review/SKILL.md
3
Create the plugin manifest
Create a
plugin.json file that describes the plugin. The manifest goes in the .claude-plugin/ directory.my-marketplace/plugins/quality-review-plugin/.claude-plugin/plugin.json
Setting
version means users only receive updates when you change this field, so bump it on every release. A plugin with a command source isn’t pinned by this field. If you omit version, the version comes from the next source in version management.4
Create the marketplace file
Create the marketplace catalog that lists your plugin.
my-marketplace/.claude-plugin/marketplace.json
5
Add and install
From the directory that contains
my-marketplace, start Claude Code and run the following commands. The install command opens a plugin details view where you select an installation scope to confirm the install. Check the install summary: if it reports Run /reload-plugins to activate., run that command.6
Try it out
Select some code in your editor and run your new skill. Plugin skills are namespaced with the plugin name.
How plugins are installed: when users install a plugin, Claude Code copies the plugin directory to a cache location, except for a
command source in link mode, which is used in place. Copied plugins can’t reference files outside their directory using paths like ../shared-utils, because those files won’t be copied.If you need to share files across plugins, use symlinks. See Plugin caching and file resolution for details.Create the marketplace file
Create.claude-plugin/marketplace.json in your repository root. This file defines your marketplace’s name, owner information, and a list of plugins with their sources.
Each plugin entry needs at minimum a name and a source that tells Claude Code where to fetch it from. See the full schema below for all available fields.
Marketplace schema
Required fields
Reserved names: the following marketplace names are reserved for official Anthropic use and can’t be used by third-party marketplaces:
claude-code-marketplace, claude-code-plugins, claude-plugins-official, claude-plugins-community, claude-community, anthropic-marketplace, anthropic-plugins, agent-skills, anthropic-agent-skills, knowledge-work-plugins, life-sciences, claude-for-legal, claude-for-financial-services, financial-services-plugins, first-party-plugins, healthcare. Names that impersonate official marketplaces, such as official-claude-plugins or anthropic-plugins-v2, are also blocked. Reserving these names prevents a third-party marketplace from presenting itself as an Anthropic-published source.Claude Code re-checks reserved names every time it loads a marketplace, not only when you add one. A marketplace that was registered under one of these names before the name became reserved stops loading and reports that it is registered from an untrusted source. Remove that marketplace and re-add it from the official Anthropic source. A third-party marketplace affected by a newly reserved name loads again as soon as you re-add it under a different name. Before v2.1.205, first-party-plugins and healthcare weren’t reserved, and a marketplace already registered under a reserved name kept loading.Owner fields
Optional fields
description and version are also accepted under metadata for backward compatibility.
Plugin entries
Each plugin entry in theplugins array describes a plugin and where to find it. You can include any field from the plugin manifest schema, such as description, version, author, commands, and hooks, plus these marketplace-specific fields: source, category, tags, strict, and relevance.
Required fields
Optional plugin fields
Standard metadata fields:
Component configuration fields:
Plugin sources
Plugin sources tell Claude Code where to get each individual plugin listed in your marketplace. These are set in thesource field of each plugin entry in marketplace.json.
Claude Code copies each installed plugin into the local versioned plugin cache at ~/.claude/plugins/cache, except for a command source in link mode, which Claude Code uses in place. Claude Code also installs the plugin’s eligible Node.js package dependencies into the cached copy.
Marketplace sources vs plugin sources: These are different concepts that control different things.
- Marketplace source: where to fetch the
marketplace.jsoncatalog itself. Set when users run/plugin marketplace addor inextraKnownMarketplacessettings. Git-based marketplace sources supportref(branch/tag) but notsha. - Plugin source: where to fetch an individual plugin listed in the marketplace. Set in the
sourcefield of each plugin entry insidemarketplace.json. Git-based plugin sources support bothref(branch/tag) andsha(exact commit).
acme-corp/plugin-catalog (marketplace source) can list a plugin fetched from acme-corp/code-formatter (plugin source). The marketplace source and plugin source point to different repositories and are pinned independently.github, url, and git-subdir. When both ref and sha are set on any of them, the sha is the effective pin. Claude Code fetches and checks out the pinned commit directly.
On most git hosts, including GitHub, GitLab, and Bitbucket, this means installation succeeds even if the branch or tag named by ref has since been deleted upstream, as long as the commit is still reachable from the repository. Some servers, such as AWS CodeCommit, don’t support fetching commits by SHA. On those servers the ref must still exist and the pinned commit must be reachable from it.
If you distribute this marketplace through Organization settings > Plugins on a Team or Enterprise plan, different source rules apply:
- The marketplace repository must be private or internal. Organization sync reads it through the Claude GitHub App or your organization’s GitHub Enterprise App.
- Each plugin source must be of type
github,url, orgit-subdir, or a relative path within the marketplace repository. - A plugin source can be private in two cases: a github.com source that shares the marketplace repository’s owner, or a source on your organization’s GitHub Enterprise host with the GHE App installed on the repository. Organization sync fetches every other source without credentials, so github.com repositories under a different owner and repositories on other hosts, such as GitLab or Bitbucket, must be public.
Relative paths
For plugins in the same repository, use a path starting with./:
.claude-plugin/. In the example above, ./plugins/my-plugin points to <repo>/plugins/my-plugin, even though marketplace.json lives at <repo>/.claude-plugin/marketplace.json. Don’t use ../ to reference paths outside the marketplace root.
A bare name is a single directory name with no /, such as "formatter". To write bare names instead of ./ paths, set metadata.pluginRoot to the directory they resolve under. With "pluginRoot": "./plugins", Claude Code resolves "source": "formatter" to ./plugins/formatter. Requires Claude Code v2.1.239 or later.
metadata.pluginRoot must itself be a relative path inside the marketplace. Claude Code ignores it for a source that already starts with ./. A source that contains a /, such as team-a/formatter, isn’t a bare name and still needs the ./ prefix, even when metadata.pluginRoot is set.
Claude Code resolves relative paths against a local copy of the marketplace, so they work when users add your marketplace from a git source or a local directory. If users add your marketplace via a direct URL to the
marketplace.json file, relative paths won’t resolve, because Claude Code downloads only that file. For URL-based distribution, use any other plugin source instead. See Troubleshooting for details.GitHub repositories
Git repositories
Git subdirectories
Usegit-subdir to point to a plugin that lives inside a subdirectory of a git repository. Claude Code uses a sparse, partial clone to fetch only the subdirectory, minimizing bandwidth for large monorepos.
url field also accepts a GitHub shorthand (owner/repo) or SSH URLs (git@github.com:owner/repo.git).
npm packages
Plugins distributed as npm packages are installed usingnpm install. This works with any package on the public npm registry or a private registry your team hosts.
version field:
registry field:
Zip archives
Usearchive to distribute a plugin as a zip file that Claude Code downloads over HTTPS, so installs work without git or npm on the user’s machine. Host the file on any static file server or artifact repository, such as an S3 bucket, an Artifactory generic repository, or nginx. Requires Claude Code v2.1.224 or later. On versions v2.1.120 through v2.1.223, installing the plugin fails with This plugin uses a source type your Claude Code version does not support. Update Claude Code and try again.; on older versions, a marketplace containing an archive entry fails to load entirely.
This entry installs the plugin from a zip file on an artifact server:
.claude-plugin/ at the top of the archive, then inside a single top-level folder, so both layouts install:
sha256 field with the archive’s digest:
Plugin archive integrity check failed.
Archive sources accept these fields:
The
sha256 digest also serves as the plugin’s version when neither plugin.json nor the marketplace entry declares one. See Version management. If you declare a version, that version string is the update signal, so after changing the zip and its digest, bump the version too, or users keep the cached copy.
If you register the marketplace from a URL source with headers, such as an extraKnownMarketplaces entry, Claude Code sends those headers with archive downloads whose URL shares the marketplace URL’s origin: the same scheme, host, and port. Claude Code downloads an archive on a different origin without the headers, and drops them when a redirect leaves the origin, so it never sends a marketplace credential to a third-party host.
Command sources
Usecommand when a locally installed tool produces the plugin directory, such as an IDE that renders its plugin for the currently selected toolchain. Claude Code runs the command when the user installs the plugin and re-runs it in the background once per session, so your users pick up the tool’s changed output without reinstalling. Requires Claude Code v2.1.229 or later. On v2.1.120 through v2.1.228, installing the plugin fails with This plugin uses a source type your Claude Code version does not support. Update Claude Code and try again., and on older versions the whole marketplace fails to load.
This entry installs the plugin from whatever directory the tool prints:
sh on macOS and Linux or cmd.exe on Windows, from the user’s home directory. The command must print exactly one line on stdout and exit with code 0. That line is the absolute path of a directory that contains the complete plugin by the time the command exits, and the path may change between runs.
Claude Code stops a command that runs longer than timeout seconds, and the install or update fails. Claude Code also refuses the printed path in these cases, and the install or update fails the same way:
- The directory has no plugin content at its top level, such as a
.claude-plugin/directory or askills/,commands/,agents/, orhooks/directory - The directory is the one Claude Code was started in, or one of its parents
- On Windows, the path is a UNC path
Copy mode and link mode
With the default"mode": "copy", Claude Code copies the printed directory into the versioned plugin cache and derives the plugin version from a hash of the directory’s contents. Your tool can delete or rewrite the directory after the command exits, and a re-run that produces identical content counts as up to date. Claude Code refuses to install a directory larger than 256 MiB or containing more than 20,000 entries.
Set "mode": "link" for large plugin directories that shouldn’t be copied, such as a rendered SDK export. Claude Code fills the plugin’s cache entry with a link to each top-level entry of the printed directory and uses the files in place, so nothing is copied, file contents aren’t hashed, and the size limits don’t apply. The install fails if a top-level entry is a symlink that points outside the printed directory. Claude Code also skips the Node.js package dependency install for a link-mode plugin, so print a directory that already contains any node_modules the plugin needs.
Keep the printed directory in place for as long as the plugin stays installed, because Claude Code loads the plugin through those links at every startup. Claude Code derives the plugin version from the printed directory’s real path and its top-level entries, not the files inside, so print a different path to signal new content. In a session started in the printed directory or anywhere below it, Claude Code doesn’t load the plugin at all.
Claude Code doesn’t support link mode on Windows and refuses to install a link-mode plugin there. Declare "mode": "copy" instead.
How users accept the command
Claude Code runs your command on the user’s machine, so it binds every run to the user’s explicit acceptance:- When users install the plugin from its details screen in
/plugin, or install or update it withclaude plugin installorclaude plugin updatein an interactive terminal, Claude Code shows them the exact command string first and records the accepted command for that installation. In a non-interactive shell, such as a provisioning script, pass--yestoclaude plugin installorclaude plugin updateto accept the command it prints. - Every other path runs only the command the user already accepted. This includes updates started from
/pluginand the background runs described in When Claude Code re-runs the command. When none was accepted, Claude Code refuses to run the command and tells the user how to review it. Claude Code never installs a command-sourced plugin as a dependency of another plugin, so users install it themselves first. - If you change the entry’s
command, or switch itsmode, users keep the version they already have and Claude Code stops re-running the command. In interactive sessions, the/pluginErrors tab shows the new command until the user reviews and accepts it by runningclaude plugin update <plugin>@<marketplace>.
disableCommandPluginSources. If an organization sets allowManagedHooksOnly, Claude Code blocks command sources by default.
When Claude Code re-runs the command
The printed directory reflects the tool’s state at the time the command ran, so Claude Code runs the command again at these times:- Every time the user installs or updates the plugin
- Once per session for each enabled command-sourced plugin, in the background, shortly after the session starts. This run doesn’t go through marketplace auto-update, so it doesn’t depend on the marketplace’s auto-update setting
- At startup or on
/reload-plugins, when an enabled plugin’s installed version is missing from the plugin cache
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC. Explicit installs and updates still run the command with that variable set.
When the command’s hashed output has changed, Claude Code installs the result as a new version and reloads it in the running interactive session, switching the same components that /reload-plugins switches. The user sees a notification that the plugin was reloaded. If reloading in place would invalidate the session’s prompt cache, Claude Code instead prompts the user to run /reload-plugins, which warns about the cache cost and applies when rerun with --force.
Advanced plugin entries
This example shows a plugin entry using many of the optional fields, including custom paths for commands, agents, hooks, and MCP servers:commandsandagents: you can specify multiple directories or individual files. Paths are relative to the plugin root.${CLAUDE_PLUGIN_ROOT}: use this variable in hook commands and MCP server configs to reference files within the plugin’s installation directory.- See the substitution table for which config fields substitute it per server type
- For dependencies or state that should survive plugin updates, use
${CLAUDE_PLUGIN_DATA}instead
strict: false: since this is set to false, the plugin doesn’t need its ownplugin.json. The marketplace entry defines everything. See Strict mode below.
skills/ directory under its source. Paths listed in the skills field add to that scan:
skills/ folder at the marketplace root (source: "./"), list specific subdirectories instead so each entry loads only its own skills:
source, the listed paths are the complete set for that entry, and other directories in the shared skills/ folder don’t load. Listing ./skills/ itself, or the plugin root, keeps the full scan. If none of the listed paths exist, the default scan runs instead.
Strict mode
Thestrict field controls whether plugin.json is the authority for component definitions (skills, agents, hooks, MCP servers, output styles).
When to use each mode:
strict: true: the plugin has its ownplugin.jsonand manages its own components. The marketplace entry can add extra skills or hooks on top. This is the default and works for most plugins.strict: false: the marketplace operator wants full control. The plugin repo provides raw files, and the marketplace entry defines which of those files are exposed as skills, agents, hooks, etc. Useful when the marketplace restructures or curates a plugin’s components differently than the plugin author intended.
Host and distribute marketplaces
Host on GitHub (recommended)
GitHub is the recommended way to host and distribute a marketplace:- Create a repository: set up a new repository for your marketplace
- Add marketplace file: create
.claude-plugin/marketplace.jsonwith your plugin definitions - Share with teams: users add your marketplace with
/plugin marketplace add owner/repo
Host on other git services
Any git hosting service works, such as GitLab, Bitbucket, and self-hosted servers. Users add with the full repository URL:Private repositories
Claude Code supports installing plugins from private repositories. If you distribute your marketplace through Organization settings > Plugins instead, your git credentials aren’t involved: organization sync reads the marketplace repository through the Claude GitHub App or your organization’s GitHub Enterprise App, and a plugin source it can’t authenticate to must be public. The note under Plugin sources has the full rules.Commands you run
When you run/plugin marketplace add, /plugin install, /plugin update, or /plugin marketplace update, Claude Code uses your existing git credential helpers, so HTTPS access via gh auth login, macOS Keychain, or git-credential-store works the same as in your terminal. SSH access works as long as the host is already in your known_hosts file and the key is loaded in ssh-agent, since Claude Code suppresses interactive SSH prompts for the host fingerprint and key passphrase. GitHub owner/repo shorthand sources clone over SSH by default; set CLAUDE_CODE_PLUGIN_PREFER_HTTPS=1 to clone them over HTTPS instead.
Background auto-updates
By default, the background refresh disables git credential helpers for itsgit pull, so the pull can’t authenticate to private repositories over HTTPS even when a helper is configured. SSH remotes aren’t affected: a key loaded in ssh-agent authenticates background pulls the same way as the commands you run. When the background pull fails, Claude Code falls back to re-cloning the marketplace from scratch. The re-clone does use your stored git credentials, but it can time out on large repositories, so private-marketplace auto-updates may fail intermittently.
Two settings make private marketplaces behave predictably:
- Set
CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE=1to keep the existing clone when the background pull fails, instead of deleting and re-cloning. Your plugins keep working from the last synced state, and manual updates with/plugin marketplace updatestill pull with your credentials. - Configure a git credential helper, for example with
gh auth setup-gitfor GitHub, so the re-clone fallback can authenticate without prompting.
GITHUB_TOKEN in your environment doesn’t by itself enable background authentication. Tokens take effect only through a configured credential helper, for example the gh CLI’s helper, which reads GH_TOKEN and GITHUB_TOKEN.
To make the background pull itself authenticate over HTTPS, configure a global git URL rewrite. The rewrite embeds a token in the remote URL, so it takes effect even though the background pull disables credential helpers, and a successful pull skips the re-clone fallback. The following example rewrites the marketplace repository’s URL to include an access token:
The rewrite stores the token in plaintext in your gitconfig, so use a token with read-only access to the marketplace repository.
In CI/CD environments, configure a git credential helper before installing plugins from private repositories. On GitHub Actions, export a token with read access to the marketplace repository as
GH_TOKEN, then run gh auth setup-git. The default workflow token can only access the workflow’s own repository, so a private marketplace in another repository needs a personal access token or app token. A global URL rewrite configured in the pipeline also authenticates the background pull directly.Require marketplaces for your team
You can configure your repository so Claude Code adds your marketplace for team members once they trust the project folder, with no separate prompt. Add your marketplace to.claude/settings.json:
If you use a local
directory or file source with a relative path, the path resolves against your repository’s main checkout. When you run Claude Code from a git worktree, the path still points at the main checkout, so all worktrees share the same marketplace location. Marketplace state is stored once per user in ~/.claude/plugins/known_marketplaces.json, not per project.Pre-populate plugins for containers
For container images and CI environments, you can pre-populate a plugins directory at build time so Claude Code starts with marketplaces and plugins already available, without cloning anything at runtime. Set theCLAUDE_CODE_PLUGIN_SEED_DIR environment variable to point at this directory.
To layer multiple seed directories, separate paths with : on Unix or ; on Windows. Claude Code searches each directory in order and uses the first seed that contains a given marketplace or plugin cache.
The seed directory mirrors the structure of ~/.claude/plugins:
~/.claude/plugins directory into your image and point CLAUDE_CODE_PLUGIN_SEED_DIR at it.
To skip the copy step, set CLAUDE_CODE_PLUGIN_CACHE_DIR to your target seed path during the build so plugins install directly there:
CLAUDE_CODE_PLUGIN_SEED_DIR=/opt/claude-seed in your container’s runtime environment so Claude Code reads from the seed on startup.
At startup, Claude Code registers marketplaces found in the seed’s known_marketplaces.json into the primary configuration, and uses plugin caches found under cache/ in place without re-cloning. This works in both interactive mode and non-interactive mode with the -p flag.
Behavior details:
- Read-only: the seed directory is never written to. Auto-updates are disabled for seed marketplaces since git pull would fail on a read-only filesystem.
- Seed entries take precedence: marketplaces declared in the seed overwrite any matching entries in the user’s configuration on each startup. To opt out of a seed plugin, use
/plugin disablerather than removing the marketplace. - Path resolution: Claude Code locates marketplace content by probing
$CLAUDE_CODE_PLUGIN_SEED_DIR/marketplaces/<name>/at runtime, not by trusting paths stored inside the seed’s JSON. This means the seed works correctly even when mounted at a different path than where it was built. - Mutation is blocked: running
/plugin marketplace removeor/plugin marketplace updateagainst a seed-managed marketplace fails with guidance to ask your administrator to update the seed image. - Composes with settings: if
extraKnownMarketplacesorenabledPluginsdeclare a marketplace that already exists in the seed, Claude Code uses the seed copy instead of cloning.
Managed marketplace restrictions
For organizations requiring strict control over plugin sources, administrators can restrict which plugin marketplaces users are allowed to add using thestrictKnownMarketplaces setting in managed settings. To also reject the CLI flags that sideload plugins, agents, and MCP servers for a single run, pair it with disableSideloadFlags. To allowlist which marketplaces’ plugins can appear as contextual install suggestions, set pluginSuggestionMarketplaces.
strictKnownMarketplaces matches the marketplace a plugin comes from, not the entries inside it, so users can still install a plugin with a command source from an allowed marketplace. To block command sources as well, set disableCommandPluginSources.
When strictKnownMarketplaces is configured in managed settings, the restriction behavior depends on the value:
Common configurations
Disable all marketplace additions, including the official Anthropic marketplace:ref or path variants of the same repository:
- Non-interactive environments that run before the machine’s first interactive launch.
- Machines where Claude Code already ran interactively under a policy that blocked the marketplace, such as the empty-array lockdown. Claude Code records the blocked attempt and doesn’t retry after the policy changes.
extraKnownMarketplaces in the same managed-settings.json so Claude Code registers it automatically, or run claude plugin marketplace add anthropics/claude-plugins-official.
Allow specific marketplaces only:
".*" as the pathPattern to allow any filesystem path while still controlling network sources with hostPattern.
strictKnownMarketplaces restricts what users can add, but doesn’t register marketplaces on its own. To register an allowed marketplace for users automatically, add it to extraKnownMarketplaces in the same managed-settings.json.The official Anthropic marketplace is the only one Claude Code registers on its own, and only when the allowlist allows it. Automatic registration also misses some machines, such as non-interactive environments and machines where an earlier policy blocked it. To cover those machines, add the official marketplace to extraKnownMarketplaces as well. For the two settings side by side, see the strictKnownMarketplaces reference.How restrictions work
Restrictions are checked before any network or filesystem operation. The check runs on marketplace add and on plugin install, update, refresh, and auto-update. If a marketplace was added before the policy was configured and its source no longer matches the allowlist, Claude Code refuses to install or update plugins from it. The same enforcement applies toblockedMarketplaces.
To block every marketplace repository under a GitHub owner, use the owner-wildcard form in a blockedMarketplaces entry: { "source": "github", "repo": "untrusted-org/*" }. Requires Claude Code v2.1.223 or later. For the matching rules, which differ between the blocklist and the allowlist, see Owner wildcards.
When a user adds an https:// repository URL that Claude Code clones rather than fetches, such as a bare github.com or gitlab.com repository URL, Claude Code also checks it against the url entries in blockedMarketplaces. Claude Code blocks the addition if an entry names the same URL. In that comparison, Claude Code ignores the .git suffix and any ref the user appends after #. Requires Claude Code v2.1.232 or later. Before v2.1.232, Claude Code matched a url entry only against a URL it fetched as a hosted marketplace.json file.
The allowlist uses exact matching for most source types, apart from owner-wildcard github entries. For a marketplace to be allowed, all specified fields must match:
- For GitHub sources:
repois required, either naming one repository or using the owner-wildcard formowner/*to cover every repository under that owner. For how wildcard entries match, including the case rules, see Owner wildcards. For single-repository entries,refmust match exactly or be absent from both the marketplace source and the allowlist entry, and the same rule applies topath - For URL sources: the full URL must match exactly
- For
hostPatternsources: the marketplace host is matched against the regex pattern - For
pathPatternsources: the marketplace’s filesystem path is matched against the regex pattern
.git suffix, or ssh:// versus https:// form are treated as different values. If your organization’s marketplace can be cloned by more than one URL form, prefer a hostPattern entry over a literal URL so all forms match.
Because strictKnownMarketplaces is set in managed settings, individual users and project configurations can’t override these restrictions.
For complete configuration details including all supported source types and comparison with extraKnownMarketplaces, see the strictKnownMarketplaces reference.
Version resolution and release channels
Plugin versions determine cache paths and update detection: if the resolved version matches what a user already has,/plugin update and auto-update skip the plugin. For git-based sources, if you omit version, Claude Code uses the source’s resolved commit SHA, so users get an update whenever that commit changes; this is the simplest setup for internal or actively developed plugins. See Version management for the full resolution order, including archive sources.
Set up release channels
To support “stable” and “latest” release channels for your plugins, you can set up two marketplaces that point to different refs or SHAs of the same repo. You can then assign the two marketplaces to different user groups through managed settings.Example
Assign channels to user groups
Assign each marketplace to the appropriate user group through managed settings. For example, the stable group receives:latest-tools instead:
Pin dependency versions
A plugin can constrain its dependencies to a semver range so that updates to a dependency don’t break the dependent plugin. See Constrain plugin dependency versions for the{plugin-name}--v{version} git-tag convention, range syntax, and how multiple constraints on the same dependency are combined.
Rename or remove a plugin
A plugin’sname is its stable identifier. Users reference it in enabledPlugins, pluginConfigs, and /plugin install commands, so changing it breaks every existing install. To change the label shown in the UI without breaking installs, set displayName and keep name unchanged.
If you must change a plugin’s name, or you remove a plugin from the plugins array, add a top-level renames entry so existing users migrate instead of seeing a plugin-not-found error. Automatic migration requires Claude Code v2.1.193 or later. Map each former name to its current name, or to null if the plugin no longer exists. The following example renames formatter to code-formatter and records that legacy-linter was removed:
renames map:
- If the entry points to a new name, Claude Code loads the plugin under its new name and shows a one-line notice such as
Renamed to "code-formatter" in the "acme-tools" marketplace. It then rewrites the old key to the new key in the user, project, and local settings scopes for bothenabledPluginsandpluginConfigs, so the notice appears once. - For a
nullentry, Claude Code drops the old key and the notice reports that the plugin was removed from the marketplace. - If the renamed plugin uses a remote source such as
githubornpm, Claude Code reportsplugin-cache-missafter the rename and the user must run/plugin installonce to fetch it under the new name.
renames as append-only history: keep old entries in place even after you expect every user to have migrated. Claude Code follows chains, so if you later rename code-formatter to formatter-pro, add a second entry rather than editing the first. A user who still has the original formatter enabled then resolves through both entries to formatter-pro.
Run claude plugin validate . after editing the map; it rejects any entry whose chain forms a cycle or doesn’t terminate at null or a name listed in plugins.
Managed and policy settings are read-only to Claude Code, so plugins enabled there can’t be rewritten automatically. The renamed plugin still loads each session, but the rename notice recurs until an administrator updates
enabledPlugins in the managed settings file to use the new name. The same applies to plugins enabled through other read-only sources such as --add-dir.renames field and report plugin-not-found for the old name.
Validation and testing
Test your marketplace before sharing. From your marketplace directory, validate the JSON syntax:Manage marketplaces from the CLI
Claude Code provides non-interactiveclaude plugin marketplace subcommands for scripting and automation. These are equivalent to the /plugin marketplace commands available inside an interactive session.
Plugin marketplace add
Add a marketplace from a GitHub repository, git URL, remote URL, or local path.<source>: GitHubowner/reposhorthand, git URL, remote URL to amarketplace.jsonfile, or local directory path. To pin to a branch or tag, append@refto the GitHub shorthand or#refto a git URL
gitlab.example.com/team/plugins, is rejected as an invalid owner/repo shorthand and the error tells you to add https:// or use ./ for a local path. Earlier versions misread it as a GitHub repository path and fail at clone time with a GitHub not-found error.
Options:
Add a marketplace from GitHub using
owner/repo shorthand:
@ref:
marketplace.json file directly:
.claude/settings.json:
Plugin marketplace list
List all configured marketplaces.
With
--json, each entry includes name, source, an installLocation field with the local cache path where the marketplace is stored, and source-specific fields: repo for GitHub sources, url for git and URL sources, and path for local sources. GitHub and git sources also include a ref field when the marketplace was added with a pinned branch or tag.
Plugin marketplace remove
Remove a configured marketplace. The aliasrm is also accepted.
<name>: marketplace name to remove, as shown byclaude plugin marketplace list. This is thenamefrommarketplace.json, not the source you passed toadd
Plugin marketplace update
Refresh marketplaces from their sources to retrieve new plugins and version changes. A marketplace added with a branch or tagref updates to the latest commit of that ref, not the repository’s default branch.
[name]: marketplace name to update, as shown byclaude plugin marketplace list. Updates all marketplaces if omitted
remove and update fail when run against a seed-managed marketplace, which is read-only. When updating all marketplaces, seed-managed entries are skipped and other marketplaces still update. To change seed-provided plugins, ask your administrator to update the seed image. See Pre-populate plugins for containers.
Troubleshooting
Marketplace not loading
Symptoms: Can’t add marketplace or see plugins from it Solutions:- Verify the marketplace URL is accessible
- Check that
.claude-plugin/marketplace.jsonexists at the specified path - Ensure JSON syntax is valid using
claude plugin validate .or/plugin validate .from the marketplace directory. To check skill, agent, and command frontmatter, see Validate a plugin or a directory without a manifest - For private repositories, confirm you have access permissions
Marketplace validation errors
Runclaude plugin validate . or /plugin validate . from your marketplace directory to check for issues. When pointed at a marketplace directory, the validator checks marketplace.json for schema errors, duplicate plugin names, and source path traversal. For each entry whose source is a local path, it also validates that plugin’s own plugin.json and warns when the entry’s version doesn’t match the one in plugin.json. Problems found in a plugin’s plugin.json are prefixed with the entry index, in the form plugins[2] plugin.json →.
As of Claude Code v2.1.196, the per-entry pass also:
- includes plugins whose
sourceis. - runs when
marketplace.jsonis outside a.claude-plugindirectory, resolving sources against the file’s own directory - reports each entry’s problems even when another part of the file has schema errors
.claude-plugin/marketplace.json.
From a marketplace directory, Claude Code doesn’t open the plugins’ skill, agent, command, or hook files. To find errors in those files, see Validate a plugin or a directory without a manifest. The table below lists the most common errors from a marketplace directory, with the cause and fix for each:
Warnings (non-blocking):
Marketplace has no plugins defined: add at least one plugin to thepluginsarrayNo marketplace description provided: add a top-leveldescriptionto help users understand your marketplacePlugin name "x" is not kebab-case: the plugin name contains uppercase letters, spaces, or special characters. Rename to lowercase letters, digits, and hyphens only (for example,my-plugin). Claude Code accepts other forms, but the claude.ai marketplace sync rejects them.Marketplace name "x" is reserved in Claude Desktop: the marketplace is namedorg,org-provisioned, orunknown, in any casing. Claude Code accepts these names, but Claude Desktop’s managed marketplace sync rejects the whole marketplace. Rename the marketplace. Before v2.1.221,claude plugin validatedidn’t run this check.Marketplace name "x" is not accepted by Claude DesktoporPlugin name "x" is not accepted by Claude Desktop: Claude Desktop accepts names of up to 128 characters made of letters, digits,.,_, and-, starting with a letter or digit. Claude Code accepts other forms, but Claude Desktop’s managed marketplace sync rejects a marketplace whose name fails the check and silently drops a plugin entry whose name does. Rename the marketplace or plugin. Before v2.1.221,claude plugin validatedidn’t run these checks.
Validate a plugin or a directory without a manifest
To find skill, agent, and command files whose frontmatter doesn’t parse, runclaude plugin validate and name the directory that holds them. Claude Code doesn’t look outside the directory you name. Every run except one against a plugin that has a plugin.json requires Claude Code v2.1.233 or later.
Pick the directory to name
Claude Code checks different files depending on which directory you name. Find what you want to check in the first column, and run that row’s command:Check a plugin whose skill is its root SKILL.md
When you run claude plugin validate against a plugin directory, Claude Code doesn’t check a SKILL.md at the plugin root. When the plugin sits in a directory named skills, run the command twice:
- Name that
skillsdirectory to check the plugin’s rootSKILL.md. - Name the plugin directory to check the rest.
plugins/, the skills-directory run isn’t available, and no run checks its root SKILL.md.
Check files behind symlinks
When you runclaude plugin validate, Claude Code doesn’t follow symlinks inside the directory you name. What it does depends on where the link is:
- A linked
skills,agents, orcommandsdirectory under the plugin or.clauderoot: Claude Code warns that nothing in it was read. - A linked entry inside a
skills,agents, orcommandsdirectory: Claude Code skips it and warns, per directory, how many entries it skipped that a session would load. - The
skills,agents, orcommandsdirectory you name is itself a symlink, or its parent.claudedirectory is: Claude Code reports an error and checks nothing in it. Name the real directory instead.
- A plugin whose
skillsdirectory links to a sibling plugin’s skills: name the sibling plugin’s directory. - A symlinked skill entry in
~/.claude/skillsor.claude/skills: Claude Code follows the entry in a session. To check it, name a directory calledskillsthat holds the real folder.
Read the validation results
A clean run ends withValidation passed.
No manifest found in directory means Claude Code found no plugin.json or marketplace.json there, and no skill, agent, or command file in the directories it probes under it. Name the skills, agents, or commands directory that holds your files instead.
Two of the errors Claude Code reports from these runs, with the fix for each:
YAML frontmatter failed to parse: ...: fix the YAML in the frontmatter block of the skill, agent, or command file. Until you do, a session reads no frontmatter fields from the fileInvalid JSON syntax: ...onhooks/hooks.json: fix the JSON syntax. Until you do, a session loads the plugin without the hooks in that file. Claude Code reports this error only in a plugin run
CLAUDE.md at the plugin root. For paths you set through the component path fields in plugin.json, Claude Code checks that each path exists but doesn’t read the files there.
Plugin installation failures
Symptoms: Marketplace appears but plugin installation fails Solutions:- Verify plugin source URLs are accessible
- Check that plugin directories contain required files
- For GitHub sources, ensure repositories are public or you have access
- Test plugin sources manually by cloning/downloading
- If the source pins both
refandsha, a deleted upstream branch or tag doesn’t block installation on most git hosts, including GitHub, GitLab, and Bitbucket. On servers that don’t support fetching commits by SHA, such as AWS CodeCommit, therefmust still exist and the pinned commit must be reachable from it. If the install still fails, confirm the pinned commit still exists in the repository
Private repository authentication fails
Symptoms: Authentication errors when installing plugins from private repositories Solutions: For manual installation and updates:- Verify you’re authenticated with your git provider (for example, run
gh auth statusfor GitHub) - Check that your credential helper is configured:
git config --global credential.helper - Run
git ls-remote <marketplace-url>to test whether git can authenticate on its own. If git asks for a username or password, store the credential first: for GitHub over HTTPS, rungh auth setup-git, and for SSH remotes, load your key intossh-agent
- By default, background refreshes disable git credential helpers for the pull, so the pull can’t authenticate over HTTPS. SSH remotes with a key loaded in
ssh-agentstill authenticate. A failed pull triggers a re-clone from scratch, which uses your stored credentials but may time out on large repositories - Set
CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE=1to keep the existing clone when the background pull fails - Configure a git credential helper, for example
gh auth setup-git, so the re-clone fallback can authenticate - If the re-clone times out on a large repository, increase the limit with
CLAUDE_CODE_PLUGIN_GIT_TIMEOUT_MS - Configure a git URL rewrite scoped to the marketplace repository so the background pull authenticates directly
- Or update private marketplaces manually with
/plugin marketplace update <name>, which uses your credentials
Marketplace updates fail in offline environments
Symptoms: Marketplacegit pull fails in the background and Claude Code repeatedly attempts a re-clone that can’t succeed.
Cause: By default, when a git pull fails, Claude Code attempts a re-clone from scratch. In offline or airgapped environments, re-cloning fails the same way, and the restore of the previous cache afterward is best-effort. The refresh runs in the background after startup, so it doesn’t delay startup, but each session repeats the failed attempts and each git operation can wait out the 120-second timeout.
Solution: Set CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE=1 to skip the re-clone attempt and keep using the existing cache when the pull fails:
CLAUDE_CODE_PLUGIN_SEED_DIR to pre-populate the plugins directory at build time instead.
Git operations time out
Symptoms: Plugin installation or marketplace updates fail with a timeout error like “Git clone timed out after 120s” or “Git pull timed out after 120s”. Cause: Claude Code uses a 120-second timeout for all git operations, including cloning plugin repositories and pulling marketplace updates. Large repositories or slow network connections may exceed this limit. Solution: Increase the timeout using theCLAUDE_CODE_PLUGIN_GIT_TIMEOUT_MS environment variable. The value is in milliseconds:
Plugins with relative paths fail in URL-based marketplaces
Symptoms: Added a marketplace via URL (such ashttps://example.com/marketplace.json), but plugins with relative path sources like "./plugins/my-plugin" fail to install with “path not found” errors.
Cause: URL-based marketplaces only download the marketplace.json file itself. They don’t download plugin files from the server. Relative paths in the marketplace entry reference files on the remote server that were not downloaded.
Solutions:
- Use external sources: change plugin entries to any plugin source other than a relative path:
- Use a Git-based marketplace: Host your marketplace in a Git repository and add it with the git URL. Git-based marketplaces clone the entire repository, making relative paths work correctly.
Files not found after installation
Symptoms: Plugin installs but references to files fail, especially files outside the plugin directory Cause: Plugins are copied to a cache directory rather than used in place, except for acommand source in link mode. Paths that reference files outside a copied plugin’s directory (such as ../shared-utils) won’t work because those files aren’t copied.
Solutions: See Plugin caching and file resolution for workarounds including symlinks and directory restructuring.
For additional debugging tools and common issues, see Debugging and development tools.
See also
- Discover and install prebuilt plugins - Installing plugins from existing marketplaces
- Plugins - Creating your own plugins
- Plugins reference - Complete technical specifications and schemas
- Plugin settings - Plugin configuration options
- strictKnownMarketplaces reference - Managed marketplace restrictions