Manifest format
Every plugin ships fluxplug.json beside its packaged entry. The manifest is validated before code runs.
Minimal manifest
Section titled “Minimal manifest”{ "schemaVersion": 1, "apiVersion": 2, "id": "standalone-demo", "name": "My first plugin", "version": "1.0.0", "entry": "dist/index.js", "capabilities": ["ui"], "settings": [], "integrity": { "sha256": "0000000000000000000000000000000000000000000000000000000000000000" }}The zeros are a build-time placeholder. The packager replaces them with the real SHA-256; do not distribute an unbuilt manifest.
Fields
Section titled “Fields”| Field | Contract |
|---|---|
| schemaVersion | 1; manifest-format version |
| apiVersion | Set to 2 for current executable plugins; missing or incompatible API versions cannot execute |
| id | 1–64 lowercase letters, numbers, dots, underscores, or hyphens; first character is a letter or number; runtime is reserved |
| name | Nonempty display name, maximum 80 characters |
| version | Nonempty plugin version, maximum 40 characters |
| entry | Relative .js path inside the package, with no leading slash or .. |
| capabilities | Requested permissions, each at most once, maximum 32 entries |
| settings | Setting definitions with unique keys, maximum 100 |
| network.hosts | Required exactly when capabilities lists network: 1–16 unique lowercase public DNS names, no IPs, wildcards or ports |
| integrity.sha256 | 64 lowercase hexadecimal characters matching the built entry |
| description / author | Optional, maximum 500 / 120 characters |
| integrity.signature | Optional metadata; publisher signatures are not verified in this release |
Setting definitions
Section titled “Setting definitions”Each setting has key, title, kind, and defaultValue, with optional description. The kind is boolean, string, or number and must match the default’s type. Keys are bounded safe identifiers; reserved prototype names are rejected. A string setting can set secret: true to be masked on screen; any other kind with secret is rejected. See settings and storage.
Network hosts
Section titled “Network hosts”A plugin that declares network lists the servers it may reach in network.hosts. A manifest with network in capabilities but no hosts, or hosts without the capability, fails with invalid_plugin_network. The hosts are confirmed together with the code hash and capabilities. See network requests for the naming rules.
Identity and trust
Section titled “Identity and trust”The ID must match definePlugin’s identity. Keep it stable across upgrades so data remains associated with the same plugin. A matching integrity hash proves the code matches the reviewed manifest, not that its author is trustworthy.
Manifest schema version, SDK API version, and product version 0.5.0-beta.1 are separate compatibility concepts.
