Plugin marketplaces
Installing released items as plugins: in Claude Code from this website, in Codex and Cursor from a git mirror.
From the Documentation in Ronne AI Marketplace 0.3.0.
What it is
This marketplace offers its released items to Claude Code as a plugin marketplace. Once it's added, you browse and install items from /plugin in Claude Code like any other plugin, without rmk install.
- Nothing about publishing changes: only released versions are offered, after review, and each item at the version the catalogue lists (
latest's). - Each plugin is the item with the dependencies it would install with, resolved when the plugin is first built; a bundle is a plugin with its members. Its name is the item's, with a dot:
@team/secure-codingisteam.secure-coding. - A deprecated version says so at the start of its description. A yanked version disappears from the marketplace the next time Claude Code refreshes it.
- Items with no place in a plugin aren't offered: status lines, permission policies, and rules that are always on or follow file patterns. Install those with
rmk. - Each plugin download counts as an install of the item, as an
rmkdownload does.
Claude Code is the only tool that can read a marketplace straight from this website. Codex and Cursor add marketplaces from git repositories only, so they read a git mirror of it.
Claude Code
- Log in with
rmk login, if you haven't: Installing with rmk. - Add the marketplace to Claude Code:
rmk plugin-setup claude-code # for you, in ~/.claude/settings.json rmk plugin-setup claude-code --scope project # for a project, in .claude/settings.json rmk plugin-setup claude-code --remove
It adds the marketplace ronne-ronne-example, which Claude Code reads from:
https://ronne.example/api/v1/feeds/claude-code/marketplace.json
With --scope project, commit .claude/settings.json to share it: Claude Code reads a project's marketplaces once you trust the folder, and each person still logs in with rmk.
Then install: run /plugin in Claude Code and pick items from the marketplace, or install one by name:
/plugin install team.secure-coding@ronne-ronne-example
An item's page shows this command in its Install panel when it can be installed as a plugin. A plugin's skills and commands run with its name first, such as /team.secure-coding:secure-coding.
Claude Code fetches the marketplace again when you run /plugin marketplace update, or by itself once you turn on auto-update for it under Marketplaces in /plugin. A new release then shows as an update.
It needs Claude Code 2.1.238 or later, and this website on an https:// address: Claude Code won't download plugins over http:// or from localhost.
Tokens
The marketplace needs a token, like the rest of the API. Claude Code gets yours by running rmk auth headers, which rmk plugin-setup names in the settings as the marketplace's headersHelper. It prints the token rmk login saved (or RMK_TOKEN), and Claude Code sends it when it reads the marketplace and downloads plugins from it.
- Claude Code runs it from
~/.claude, without your shell's setup, so a Node.js from nvm isn't on itsPATH. In your own settings,rmk plugin-setupnames the Node.js and thermkyou ran it with by their full paths: run it again after you switch or upgrade Node.js. - A project's settings name plain
rmk, since they're shared: there,rmkand Node.js must be on thePATHClaude Code starts with.--commandnames another command, such as--command /opt/homebrew/bin/rmk. - When the token expires or is revoked, the marketplace stops refreshing, and Claude Code shows it as failing to load. The plugins you installed keep working. Run
rmk loginagain to fix it. - For a project's settings, Claude Code hides variables that look like secrets from the command, so
RMK_TOKENisn't seen there: usermk login. - For an older Claude Code,
--static-headerswrites the token itself into your user settings (never a project's, which usually goes into git). Run the command again after you log in again.
Codex and Cursor (git mirror)
Codex and Cursor add plugin marketplaces only from git repositories. So rmk writes this marketplace's plugins as a repository, a mirror, that you push to your git host, and the tools add that.
git clone [email protected]:your-org/ronne-plugins.git && cd ronne-plugins rmk feed build --out . git add --all && git commit -m 'Update the plugin feed' && git push
- It writes each tool's marketplace file (
.agents/plugins/marketplace.jsonfor Codex,.cursor-plugin/marketplace.jsonfor Cursor,.claude-plugin/marketplace.jsonfor Claude Code), each plugin underplugins/<tool>/, and.rmk-feed.json, its record of what it wrote. - It holds the same plugins as the Claude Code marketplace, each in the layout of its tool: Codex plugins carry no agents, and only Cursor's carry rules that are always on or follow file patterns.
- Anyone who can read the repository can install every plugin in it. Keep it private, and let your git host decide who reads it.
Then add it in each tool:
- Codex:
codex plugin marketplace add your-org/ronne-plugins(or the repository's git URL), then install plugins from it.codex plugin marketplace upgradefetches it again. Codex clones it with git, so for a private repository, git on that machine must be able to clone it. - Cursor: a team admin (Teams or Enterprise plan) imports it in the dashboard, under Settings › Plugins › Team Marketplaces › Import, from GitHub, GitLab, Bitbucket or Azure DevOps, and chooses who sees it. On a GitHub import, Enable Auto Refresh brings each push in.
- Claude Code can add it too, with
/plugin marketplace add your-org/ronne-plugins: for people who can read the repository but have no account here.
Keeping the mirror current
A new release reaches the mirror the next time rmk feed build runs. Let CI run it:
rmk feed build --print-workflow github > .github/workflows/ronne-plugin-feed.yml rmk feed build --print-workflow gitlab > .gitlab-ci.yml
- The GitHub workflow runs daily and when you start it, installs the same
rmkversion that printed it, builds, and commits and pushes only when something changed. The comments at its top say what to set: theRMK_REGISTRYandRMK_TOKENsecrets. - The GitLab job does the same; you add its daily schedule in Build › Pipeline schedules, and it also needs
RMK_PUSH_TOKEN, a project access token that can push. - Make
RMK_TOKENon an account made for the mirror: the build reads what that account can read. When the token expires or is revoked, the build fails and the mirror stays as it was, so the tools keep their plugins; make a new token and update the secret. - A run with nothing new released changes nothing, so there's no commit. A new release replaces that plugin's folder whole; a yanked one's folder is removed.
rmkwrites only the paths it records: a README or the CI file stays as you wrote it. If something underplugins/isn't its own, or changed since it wrote it, the build stops and lists it (--forcewrites over its own paths).--tools codex,cursorbuilds only some tools.
Large marketplaces
Claude Code reads a marketplace from an address only if it's at most 5 MiB and arrives within 10 seconds. Each item takes about half a kilobyte, so this website's Claude Code marketplace reaches 5 MiB near 10,000 items.
- The marketplace is built once, then answered from memory until something is released, tagged, deprecated or yanked. The first request after a change builds it again.
- Each plugin is built the first time anyone asks for it. When a request runs out of time, it lists what's built, and the rest is built right after, so the next refresh lists everything.
- Root sees each tool's last build under Admin › Settings › Plugin feeds: its size, plugins and build time, with a warning once Claude Code's marketplace passes 4 MiB or a build takes 5 seconds.
- Past 5 MiB, Claude Code's marketplace answers an error instead. Add the git mirror in Claude Code then: a marketplace in a git repository has no such limit. Codex's and Cursor's have no limit here, since only
rmk feed buildreads them.
Plugins or rmk
- Plugins install from inside Claude Code, for you, and Claude Code keeps them in its own folder. They suit trying items out, and people who only use Claude Code.
rmk installworks for every tool, writes the files into the project, and pins versions inrmk.lockso teammates get the same. Usage is reported only for itemsrmkinstalled.
Install an item one way, not both: Claude Code would load it twice. When rmk install writes an item for Claude Code that's also enabled as a plugin from this marketplace, it warns, and installs it anyway. Uninstall the plugin in /plugin, or run rmk remove.