emploidai Marketplace

Marketplace documentation

How catalog discovery, verification, installation, and updates work.

Discover products

Search and filter plugins, applets, and add-ons by type, category, publisher, compatibility, and popularity. Catalog pages are served by Marketplace and do not read your workspace or installed-plugin state.

Review before installing

Each detail page shows the publisher verification level, package validation state, minimum platform version, declared permissions, dependencies, data-handling information, and available publisher policies. A limited-listing notice means that some recommended disclosures are unavailable.

Install into emploidai

  1. Select Install on a compatible product.
  2. Choose your emploidai workspace and review the permissions.
  3. Confirm the installation. emploidai then streams the distribution-signed .empkg or .empbundle from Marketplace, verifies it against the installed emploidai trust root, and installs it in the selected tenant.

Marketplace never sends a package during browsing. Package bytes are transferred only for an authenticated install or upgrade operation.

The public discovery contract is available as an OpenAPI document.

Publish a plugin

Publishing follows the same stages as other application stores. Everything happens in the Publisher Console; sign in with your emploidai account.

  1. Become a publisher. Apply with your legal organization name and the namespace you want (for example acme). emploidai operations reviews the application; approval creates the publisher and makes you its first owner.
  2. Register a signing key. Generate an RSA-3072 key in the browser (the private key is encrypted with your passphrase and downloaded once) or register the public key of an HSM or CI signer. Marketplace stores only public keys and issues a publisher certificate for each.
  3. Create the plugin. Reserve the permanent plugin ID namespace/name, set the display name, category and short description, and accept the publishing declarations. The plugin starts in the Draft stage and is not visible in the catalog yet.
  4. Build and sign the artifact. Produce the release with the publisher CLI in portal delivery mode. Runtime-only plugins produce .empkg; releases with an applet or worker image produce .empbundle. The manifest must declare the reserved plugin ID and a new version.
  5. Create a release. From the plugin dashboard choose Create release, confirm the readiness checks, and upload the artifact. CI pipelines can submit the same artifact through the release API with a scoped release token.
  6. Verification. Marketplace checks the publisher signature, package digest, pinned images and compatibility, then adds its own distribution signature. Progress is shown live; failures include the reason and the same version can be resubmitted.
  7. Live. A verified release publishes the listing with the icon and metadata from the package and becomes installable. Updates are offered to workspaces automatically.

Owners can revoke keys and tokens at any time; revocations are published in a signed trust snapshot that emploidai installations refresh.

Updates

emploidai compares installed package identifiers with Marketplace’s current verified versions. Updates are offered only when a newer verified package is available and compatible with the running platform.