Skip to content
Documentation: Plugin marketplaces

Plugin marketplaces

Installing released items as plugins: in Claude Code from this website, in Codex and Cursor from a git mirror.

From the Documentation in Ronne AI Marketplace 0.3.0.

What it is

This marketplace offers its released items to Claude Code as a plugin marketplace. Once it's added, you browse and install items from /plugin in Claude Code like any other plugin, without rmk install.

  • Nothing about publishing changes: only released versions are offered, after review, and each item at the version the catalogue lists (latest's).
  • Each plugin is the item with the dependencies it would install with, resolved when the plugin is first built; a bundle is a plugin with its members. Its name is the item's, with a dot: @team/secure-coding is team.secure-coding.
  • A deprecated version says so at the start of its description. A yanked version disappears from the marketplace the next time Claude Code refreshes it.
  • Items with no place in a plugin aren't offered: status lines, permission policies, and rules that are always on or follow file patterns. Install those with rmk.
  • Each plugin download counts as an install of the item, as an rmk download does.

Claude Code is the only tool that can read a marketplace straight from this website. Codex and Cursor add marketplaces from git repositories only, so they read a git mirror of it.

Claude Code

  1. Log in with rmk login, if you haven't: Installing with rmk.
  2. Add the marketplace to Claude Code:
rmk plugin-setup claude-code                    # for you, in ~/.claude/settings.json
rmk plugin-setup claude-code --scope project    # for a project, in .claude/settings.json
rmk plugin-setup claude-code --remove

It adds the marketplace ronne-ronne-example, which Claude Code reads from:

https://ronne.example/api/v1/feeds/claude-code/marketplace.json

With --scope project, commit .claude/settings.json to share it: Claude Code reads a project's marketplaces once you trust the folder, and each person still logs in with rmk.

Then install: run /plugin in Claude Code and pick items from the marketplace, or install one by name:

/plugin install team.secure-coding@ronne-ronne-example

An item's page shows this command in its Install panel when it can be installed as a plugin. A plugin's skills and commands run with its name first, such as /team.secure-coding:secure-coding.

Claude Code fetches the marketplace again when you run /plugin marketplace update, or by itself once you turn on auto-update for it under Marketplaces in /plugin. A new release then shows as an update.

It needs Claude Code 2.1.238 or later, and this website on an https:// address: Claude Code won't download plugins over http:// or from localhost.

Tokens

The marketplace needs a token, like the rest of the API. Claude Code gets yours by running rmk auth headers, which rmk plugin-setup names in the settings as the marketplace's headersHelper. It prints the token rmk login saved (or RMK_TOKEN), and Claude Code sends it when it reads the marketplace and downloads plugins from it.

  • Claude Code runs it from ~/.claude, without your shell's setup, so a Node.js from nvm isn't on its PATH. In your own settings, rmk plugin-setup names the Node.js and the rmk you ran it with by their full paths: run it again after you switch or upgrade Node.js.
  • A project's settings name plain rmk, since they're shared: there, rmk and Node.js must be on the PATH Claude Code starts with. --command names another command, such as --command /opt/homebrew/bin/rmk.
  • When the token expires or is revoked, the marketplace stops refreshing, and Claude Code shows it as failing to load. The plugins you installed keep working. Run rmk login again to fix it.
  • For a project's settings, Claude Code hides variables that look like secrets from the command, so RMK_TOKEN isn't seen there: use rmk login.
  • For an older Claude Code, --static-headers writes the token itself into your user settings (never a project's, which usually goes into git). Run the command again after you log in again.

Codex and Cursor (git mirror)

Codex and Cursor add plugin marketplaces only from git repositories. So rmk writes this marketplace's plugins as a repository, a mirror, that you push to your git host, and the tools add that.

git clone [email protected]:your-org/ronne-plugins.git && cd ronne-plugins
rmk feed build --out .
git add --all && git commit -m 'Update the plugin feed' && git push
  • It writes each tool's marketplace file (.agents/plugins/marketplace.json for Codex, .cursor-plugin/marketplace.json for Cursor, .claude-plugin/marketplace.json for Claude Code), each plugin under plugins/<tool>/, and .rmk-feed.json, its record of what it wrote.
  • It holds the same plugins as the Claude Code marketplace, each in the layout of its tool: Codex plugins carry no agents, and only Cursor's carry rules that are always on or follow file patterns.
  • Anyone who can read the repository can install every plugin in it. Keep it private, and let your git host decide who reads it.

Then add it in each tool:

  • Codex: codex plugin marketplace add your-org/ronne-plugins (or the repository's git URL), then install plugins from it. codex plugin marketplace upgrade fetches it again. Codex clones it with git, so for a private repository, git on that machine must be able to clone it.
  • Cursor: a team admin (Teams or Enterprise plan) imports it in the dashboard, under Settings › Plugins › Team Marketplaces › Import, from GitHub, GitLab, Bitbucket or Azure DevOps, and chooses who sees it. On a GitHub import, Enable Auto Refresh brings each push in.
  • Claude Code can add it too, with /plugin marketplace add your-org/ronne-plugins: for people who can read the repository but have no account here.

Keeping the mirror current

A new release reaches the mirror the next time rmk feed build runs. Let CI run it:

rmk feed build --print-workflow github > .github/workflows/ronne-plugin-feed.yml
rmk feed build --print-workflow gitlab > .gitlab-ci.yml
  • The GitHub workflow runs daily and when you start it, installs the same rmk version that printed it, builds, and commits and pushes only when something changed. The comments at its top say what to set: the RMK_REGISTRY and RMK_TOKEN secrets.
  • The GitLab job does the same; you add its daily schedule in Build › Pipeline schedules, and it also needs RMK_PUSH_TOKEN, a project access token that can push.
  • Make RMK_TOKEN on an account made for the mirror: the build reads what that account can read. When the token expires or is revoked, the build fails and the mirror stays as it was, so the tools keep their plugins; make a new token and update the secret.
  • A run with nothing new released changes nothing, so there's no commit. A new release replaces that plugin's folder whole; a yanked one's folder is removed.
  • rmk writes only the paths it records: a README or the CI file stays as you wrote it. If something under plugins/ isn't its own, or changed since it wrote it, the build stops and lists it (--force writes over its own paths). --tools codex,cursor builds only some tools.

Large marketplaces

Claude Code reads a marketplace from an address only if it's at most 5 MiB and arrives within 10 seconds. Each item takes about half a kilobyte, so this website's Claude Code marketplace reaches 5 MiB near 10,000 items.

  • The marketplace is built once, then answered from memory until something is released, tagged, deprecated or yanked. The first request after a change builds it again.
  • Each plugin is built the first time anyone asks for it. When a request runs out of time, it lists what's built, and the rest is built right after, so the next refresh lists everything.
  • Root sees each tool's last build under Admin › Settings › Plugin feeds: its size, plugins and build time, with a warning once Claude Code's marketplace passes 4 MiB or a build takes 5 seconds.
  • Past 5 MiB, Claude Code's marketplace answers an error instead. Add the git mirror in Claude Code then: a marketplace in a git repository has no such limit. Codex's and Cursor's have no limit here, since only rmk feed build reads them.

Plugins or rmk

  • Plugins install from inside Claude Code, for you, and Claude Code keeps them in its own folder. They suit trying items out, and people who only use Claude Code.
  • rmk install works for every tool, writes the files into the project, and pins versions in rmk.lock so teammates get the same. Usage is reported only for items rmk installed.

Install an item one way, not both: Claude Code would load it twice. When rmk install writes an item for Claude Code that's also enabled as a plugin from this marketplace, it warns, and installs it anyway. Uninstall the plugin in /plugin, or run rmk remove.