Update to Plugin Creator
Snapshot Oct 9, 2026 · 00:02 UTC · version 0.1.23
Package or technical metadata updated
Package contents changed in 7 files: .codex-plugin/plugin.json, plugin.json, skills/create-plugin/SKILL.md, …. Open the file diff to inspect the edits.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Package file
c0d78be13e4befc150c3b61656cbd75ea15ce622770904d93e15e37d84175bf4
f8788b5bc444bebc878f23a5e159b001e490e22d9a01966602bf2bd6ef1d31c8
Package file
d467bc0032ae28e6ea96f99f7b827291bfb4269d2ed00d8fe3144bd934a6e2c3
1594d7904293e4b1eda8d9ab679c8dfafd36a60e1d74950303387f42e2867b86
Package file
73ec9774b56b8f8b8a0d240fd4afac24488b50bfd4d3e4a9e9d47fbc0cf9b0fd
7f5273ca28cf96062efe2158946ae20960179e00247e283c9af4056be79b9e00
Package file
c811c2a534f094c454da6efff014a45a21051712aa31ed1d74e773dc9b50721e
d9df446176c188b4b364125508322857e5b71b8288d6e70439be0680d0aab7c0
Compare saved observations
Download comparison JSONChanged files
skills/create-plugin/SKILL.md →
skills/create-plugin/references/extensions.md →
skills/prepare-plugin-submission/references/submission-lifecycle.md →
skills/create-plugin/references/extensions.md
--- before +++ after @@ -1,90 +1,13 @@ # MCP Apps and Extensions -Use the workflow table in [Create a plugin](../SKILL.md#extensions) to choose -Extensions, then follow the relevant SDK and example implementation. +## Development -## Read the relevant implementation docs +After installing a plugin, check that its tools are available. If they have not +appeared yet, retry briefly before reporting that installation is pending. -Read the relevant sections of the -[protocol spec](https://github.com/openai/mcp-extensions/blob/main/docs/spec.md) -and the SDK guide for the app's stack: -[Python](https://github.com/openai/mcp-extensions/blob/main/python/README.md) or -[TypeScript](https://github.com/openai/mcp-extensions/blob/main/typescript/README.md). -Keep a Python MCP server in Python; its browser UI can use the TypeScript app -SDK without changing the server's language. -Use the installed release tag or source commit for SDK APIs instead of `main`; -for a new project, choose a supported [release](https://github.com/openai/mcp-extensions/releases). -Use the current support table when available; do not copy a fixed platform matrix -into the plugin. If remote docs are unavailable or omit a capability, use installed -types, bundled docs, and host capabilities, and flag support you cannot verify. -Keep protocol mechanics in those docs. - -## Learn from Bits & Bolts - -Use [Bits & Bolts](https://github.com/openai/mcp-extensions/tree/main/plugins/bits-and-bolts) -as a guiding reference for Extension integration patterns: - -- Its Parts Library opens from global navigation, while the Parts Tray stays - beside a conversation. A project tracker can use the same pattern for a - project browser and the current conversation's selected tasks. -- Its settings view persists measurement units and grid preferences. A charting - app can expose its own display preferences through a settings entrypoint. -- Its file viewer reads a host-managed CAD file, attaches a selected surface - as model context, and saves edits with version checks. A CSV editor can adapt - that pattern for a selected row and an edited file. - -Follow the relevant server metadata and UI bridge usage; adapt the patterns to -the app's language and workflow rather than copying the example's full stack. - -## Implement in the app's server and UI - -New apps default to a cloud plugin hosted by [Sites MCP](sites-mcp.md). -Add Extensions to that same Site's MCP server and UI, and use the Sites MCP -publishing and connection workflow. For an existing app or an explicitly local -workflow, preserve its source, hosting, runtime, and authentication. - -For a catalog browser like Bits & Bolts, register the HTML view as an MCP -resource and associate an opener tool through the installed MCP Apps SDK's -metadata. Connect the view with the SDK's host bridge so the UI and chat tools -work with the same persisted catalog. Add a global entrypoint if users should -open it from navigation; keep catalog search usable without opening the view. -A website URL or JSON tool result alone does not register an app view. - -For **every widget**, explicitly choose its supported display modes and preferred -mode using the installed SDK and [display-preference specification](https://github.com/openai/mcp-extensions/blob/main/docs/spec.md#preferred-model-display-mode). -Use that version's metadata fields and placement; do not mix API versions. - -Default to fullscreen only; in a Codex conversation this is the side panel. -Include inline only when the interaction belongs in the conversation, -such as a confirmation card, a one-time action, or a simple, ephemeral visual. -Supporting a compact layout alone is not a reason to enable inline. Declare -both modes only when each offers a useful experience; prefer inline for an -inline-only widget. Verify actual placement rather than relying on the preference. - -For file access, use the host's resource bridge and granted write capability. -Sending a filesystem path to a remote server does not grant it local access. -Preserve unsaved changes and version checks when saving. For context and -mentions, resolve the selected record under its access rules and attach only -the relevant data. Attaching context does not send a message or authorize an -action on that data. - -## Open and verify - -Once connected, invoke the app's opener in the intended host. Use its launch -result instead of calling the opener again from the UI for the same data. -Check the requested controls, placement, and data changes; a JSON result alone -does not prove the view rendered. Report unverified host behavior separately. - -Display-mode preferences are hints. If fullscreen was intended but the host -starts inline, check host context after `app.connect()` and request fullscreen -once only when the host advertises it. Use the installed SDK's API and accept -the returned mode. Do not expand a widget intentionally designed for inline use. - -Retry tool discovery briefly after installation before reporting it pending. -If the host requires a fresh task, offer one with the existing plugin; create -it only when authorized. Obtain the exact plugin reference through discovery -and include `[@Plugin name](plugin://<name>@<marketplace>)` in the task prompt; -a plain-text name does not preselect the plugin. Include the user's request, -source location, Site ID when applicable, current state, and remaining work. -Verify tool availability there before claiming success. Do not create a -replacement plugin or repeatedly create tasks to refresh tools. +If the tools require a new task, offer to open one with the existing plugin and +create it only when authorized. Find the exact plugin reference and include +`[@Plugin name](plugin://<name>@<marketplace>)` in the task prompt to select it. +Carry over the user's request, source location, Site ID when applicable, and +remaining work. Check that the tools are available before claiming success. +Do not recreate the plugin or repeatedly open tasks to refresh its tools.
Full technical diff · 11 changed fields
changed /files/.codex-plugin~1plugin.json/sha256
"c0d78be13e4befc150c3b61656cbd75ea15ce622770904d93e15e37d84175bf4"
"f8788b5bc444bebc878f23a5e159b001e490e22d9a01966602bf2bd6ef1d31c8"
changed /files/plugin.json/sha256
"d467bc0032ae28e6ea96f99f7b827291bfb4269d2ed00d8fe3144bd934a6e2c3"
"1594d7904293e4b1eda8d9ab679c8dfafd36a60e1d74950303387f42e2867b86"
changed /files/skills~1create-plugin~1SKILL.md/sha256
"73ec9774b56b8f8b8a0d240fd4afac24488b50bfd4d3e4a9e9d47fbc0cf9b0fd"
"7f5273ca28cf96062efe2158946ae20960179e00247e283c9af4056be79b9e00"
changed /files/skills~1create-plugin~1references~1extensions.md/sha256
"c811c2a534f094c454da6efff014a45a21051712aa31ed1d74e773dc9b50721e"
"d9df446176c188b4b364125508322857e5b71b8288d6e70439be0680d0aab7c0"
changed /files/skills~1create-plugin~1references~1extensions.md/size
5275
663
changed /files/skills~1prepare-plugin-submission~1references~1submission-lifecycle.md/sha256
"48a681720b4812f342e985fa4e6d1e48d4a9e634a1bd2d1aaadd8274c7d2ca8a"
"0ac4eff6acd676a2c8031b1b4b188e526c2a9d47a9a8c6172b24b1999dc594c7"
changed /files/skills~1prepare-plugin-submission~1references~1submission-lifecycle.md/size
3721
5324
changed /files/skills~1update-plugin~1SKILL.md/sha256
"1abcf21c8fb7dd52aae593b36a56ea5c811e51f3ad505a724acef5ae3e48d3ae"
"9d98c2eb626551bc41458e4384eeab0fd5aa79ddad0dfb3bbc89dfa46a587dde"
changed /files/skills~1update-plugin~1SKILL.md/size
2846
2890
changed /files/skills~1update-plugin~1references~1account-updates.md/sha256
"8b46a3170270cd20350283f832d5f54427dbb246e38e986f5263ac0d3369dc10"
"44f88d71d62815a0c59cbdeeeb648e9b806838e20231de36260a9c187bd0e41d"
changed /files/skills~1update-plugin~1references~1account-updates.md/size
5100
5724
Full snapshot data
{
"files": {
".app.json": {
"sha256": "3c60fdb8f355bc7a5f26a0e035aa48b9dd5ccfbbafcd1556ce5753660c3cdc92",
"size": 95
},
".codex-plugin/plugin.json": {
"sha256": "f8788b5bc444bebc878f23a5e159b001e490e22d9a01966602bf2bd6ef1d31c8",
"size": 1642
},
"assets/composer-icon.png": {
"sha256": "ad3d5b05b0b004a7e4ce1de5b4648650f124afefc5ef23441ac69c427d52574c",
"size": 45952
},
"assets/logo.png": {
"sha256": "4ba3224335d123d5f53d9aab895a96b87f0d717cd51da22fb8f98a9a3b623d79",
"size": 135269
},
"assets/openai-platform.png": {
"sha256": "776310bcb0f0f191c616f31a13fcb8de8cc94d920c77625c271b3a034199ac43",
"size": 2699
},
"assets/plugin-creator-icon.png": {
"sha256": "ad3d5b05b0b004a7e4ce1de5b4648650f124afefc5ef23441ac69c427d52574c",
"size": 45952
},
"assets/plugin-creator.png": {
"sha256": "4ba3224335d123d5f53d9aab895a96b87f0d717cd51da22fb8f98a9a3b623d79",
"size": 135269
},
"plugin.json": {
"sha256": "1594d7904293e4b1eda8d9ab679c8dfafd36a60e1d74950303387f42e2867b86",
"size": 1833
},
"skills/create-plugin/SKILL.md": {
"sha256": "7f5273ca28cf96062efe2158946ae20960179e00247e283c9af4056be79b9e00",
"size": 5128
},
"skills/create-plugin/assets/starter-plugin/README.md": {
"sha256": "f200c6abeff607b6f854d34f89fec15c5d12cb2260aea15351c0c00392edf258",
"size": 557
},
"skills/create-plugin/assets/starter-plugin/plugin.json": {
"sha256": "a363e514a3fd950bc13cc518381c6ac92d31328f4aaa4bd0c799c056f0a09ee4",
"size": 839
},
"skills/create-plugin/assets/starter-plugin/skills/starter-workflow/SKILL.md": {
"sha256": "b69d712258ce8a88203e911fc762bbc376da38f34851f2fc18ee978cfe0fc32f",
"size": 311
},
"skills/create-plugin/references/extensions.md": {
"sha256": "d9df446176c188b4b364125508322857e5b71b8288d6e70439be0680d0aab7c0",
"size": 663
},
"skills/create-plugin/references/local-plugins.md": {
"sha256": "26fc90c88b6160bcca7d64f66f90345a573c1e3ba87bfc66162a1b372b2735aa",
"size": 1953
},
"skills/create-plugin/references/plugin-packages.md": {
"sha256": "987e8bc12359c03d7e36759e843d02fb0f908f4929433674ab416f2c0d9745ce",
"size": 6908
},
"skills/create-plugin/references/server-access.md": {
"sha256": "3a7a61da4cdfcd39ac20b1403a94b78f16e8181c4423cf24cd2c99b37979c13c",
"size": 1264
},
"skills/create-plugin/references/sites-mcp.md": {
"sha256": "4e971720d0c40751e866b3687c5694f3f145e2afa89f24624aaf050c7a94b625",
"size": 1899
},
"skills/prepare-plugin-submission/SKILL.md": {
"sha256": "31ce3516d89e1d86f967e23d61db0509fe5c3a1fedb5a18d27d3b73895d885a3",
"size": 7185
},
"skills/prepare-plugin-submission/references/listing.md": {
"sha256": "a0096d0520246e4fcc0715e68b29e97e7f2e71de1aeb5cd0c642e52a5242db0e",
"size": 6190
},
"skills/prepare-plugin-submission/references/review-materials.md": {
"sha256": "bd361a69856bb59d1bb4797e9ec6806559b224f54c7464be7db1a1b472cbd415",
"size": 9519
},
"skills/prepare-plugin-submission/references/submission-lifecycle.md": {
"sha256": "0ac4eff6acd676a2c8031b1b4b188e526c2a9d47a9a8c6172b24b1999dc594c7",
"size": 5324
},
"skills/update-plugin/SKILL.md": {
"sha256": "9d98c2eb626551bc41458e4384eeab0fd5aa79ddad0dfb3bbc89dfa46a587dde",
"size": 2890
},
"skills/update-plugin/references/account-updates.md": {
"sha256": "44f88d71d62815a0c59cbdeeeb648e9b806838e20231de36260a9c187bd0e41d",
"size": 5724
},
"skills/update-plugin/references/legacy-manifest-migration.md": {
"sha256": "dabf08d8467562b0e8f7abb095158d03b1081628399c9b1cb97499b4e61f6d84",
"size": 6437
}
}
}SHA-256 of public snapshot: ad508d0baa418c607f40b61aee038ab8af5e5e439ef5c7e8eb9d24c4c96ef935