{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "$id": "https://cognitive-delivery.github.io/contract/1.x/plugin-marketplace.schema.json",
  "title": "CDF Plugin Marketplace",
  "description": "A marketplace's `marketplace.json`, read from `.claude-plugin/marketplace.json`. Models every key the Claude Code plugin manifest and marketplace references, read 2026-10-05 document: owner, metadata, renames, forceRemoveDeletedPlugins, allowCrossMarketplaceDependenciesOn and the `plugins[]` entries with Claude Code's seven `source` forms, plus two CDF extensions the README names: a `local` source form for a marketplace that lists plugins already on disk, and an optional per-entry `cdf` block carrying a declared digest and the capabilities the entry expects. Every source form is DECLARED here, including the three the harness cannot yet fetch, because a marketplace that uses one must parse and be reported rather than fail to load. A listing is not an installation, and a declared digest is a claim to be checked, never a verdict.",
  "definitions": {
    "author": {
      "description": "Who publishes the plugin. An object is the documented form; a bare string is accepted because marketplaces in the wild carry one, and a reader that refused it would refuse a real plugin.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "object",
          "required": [
            "name"
          ],
          "properties": {
            "name": {
              "type": "string",
              "minLength": 1
            },
            "email": {
              "type": "string"
            },
            "url": {
              "type": "string"
            }
          },
          "additionalProperties": true
        }
      ]
    },
    "capabilities": {
      "type": "object",
      "description": "What the plugin's own code asks to be allowed when the harness runs it out of process. This is the lease manifest's `allow` shape, property for property, because a plugin worker's lease is generated from it and narrowed against the workspace root policy. It is deliberately NOT the store-listing `interface.capabilities` vocabulary a plugin may also carry: that is a shelf label, this is an authorisation request. Every list is optional here — an absent list is a plugin that asks for nothing, which is the correct default — whereas the granted manifest requires all five.",
      "properties": {
        "tools": {
          "type": "array",
          "description": "Governed tool names the agent may call.",
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "read_paths": {
          "type": "array",
          "description": "Workspace-relative POSIX globs the agent may read. Refused here, without lookahead so any RE2 or I-Regexp validator can load the rule: a leading `/`, any `..` segment, a leading `~`, a drive-letter prefix and any backslash. The registry re-checks the resolved path against the workspace root.",
          "items": {
            "type": "string",
            "minLength": 1,
            "allOf": [
              {
                "not": {
                  "pattern": "^/"
                }
              },
              {
                "not": {
                  "pattern": "(^|/)\\.\\.(/|$)"
                }
              },
              {
                "not": {
                  "pattern": "^~"
                }
              },
              {
                "not": {
                  "pattern": "^[A-Za-z]:"
                }
              },
              {
                "not": {
                  "pattern": "\\\\"
                }
              }
            ]
          }
        },
        "write_paths": {
          "type": "array",
          "description": "Workspace-relative POSIX globs the agent may change. Refused here, without lookahead: a leading `/`, any `..` segment, a leading `~`, a drive-letter prefix and any backslash. The registry re-checks the resolved path against the workspace root, and a change outside the granted set is a scope violation that revokes the lease.",
          "items": {
            "type": "string",
            "minLength": 1,
            "allOf": [
              {
                "not": {
                  "pattern": "^/"
                }
              },
              {
                "not": {
                  "pattern": "(^|/)\\.\\.(/|$)"
                }
              },
              {
                "not": {
                  "pattern": "^~"
                }
              },
              {
                "not": {
                  "pattern": "^[A-Za-z]:"
                }
              },
              {
                "not": {
                  "pattern": "\\\\"
                }
              }
            ]
          }
        },
        "hosts": {
          "type": "array",
          "description": "Hostnames the agent may reach, with an optional leading wildcard label (`*.example.com`). Enforced by the egress proxy once it keys off the lease.",
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "commands": {
          "type": "array",
          "description": "Executable names the agent may run.",
          "items": {
            "type": "string",
            "minLength": 1
          }
        }
      },
      "additionalProperties": true
    },
    "componentPath": {
      "description": "A component directory or file, or a list of them. Claude Code accepts a single string or an array of strings for `skills`, `commands`, `agents`, `outputStyles`, `workflows` and `experimental.themes`, and scans the default folder when the key is absent, so an absent key is not an empty contribution. Every path starts with `./` (`skills` also accepts `\".\"`). Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          }
        }
      ]
    },
    "componentSource": {
      "description": "A component declared inline as an object, a path to a `.json` file that declares it, or an array mixing both. Claude Code accepts all three for `hooks`, `mcpServers` and `lspServers`; for `mcpServers` the string may also be an `.mcpb` or `.dxt` bundle path or an `https://` bundle URL. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "anyOf": [
        {
          "type": "object"
        },
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "array",
          "items": {
            "anyOf": [
              {
                "type": "object"
              },
              {
                "type": "string",
                "minLength": 1
              }
            ]
          }
        }
      ]
    },
    "entry": {
      "type": "object",
      "description": "One plugin listed by the marketplace. `name` and `source` are required: a listing that names nothing cannot be addressed, and one that resolves to nothing cannot be fetched. Every other key overrides or supplements what the fetched manifest says.",
      "required": [
        "name",
        "source"
      ],
      "properties": {
        "name": {
          "type": "string",
          "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]*$"
        },
        "source": {
          "$ref": "#/definitions/source"
        },
        "displayName": {
          "type": "string"
        },
        "description": {
          "type": "string"
        },
        "version": {
          "type": "string"
        },
        "author": {
          "$ref": "#/definitions/author"
        },
        "homepage": {
          "type": "string"
        },
        "repository": {
          "$ref": "#/definitions/repository"
        },
        "license": {
          "type": "string"
        },
        "keywords": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "category": {
          "type": "string"
        },
        "tags": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "defaultEnabled": {
          "type": "boolean"
        },
        "strict": {
          "type": "boolean",
          "description": "Whether the entry must match the fetched manifest exactly. Absent means true: the stricter reading is the default, so a marketplace relaxes it deliberately."
        },
        "skills": {
          "$ref": "#/definitions/componentPath"
        },
        "commands": {
          "$ref": "#/definitions/commands"
        },
        "agents": {
          "$ref": "#/definitions/componentPath"
        },
        "hooks": {
          "$ref": "#/definitions/componentSource"
        },
        "mcpServers": {
          "$ref": "#/definitions/componentSource"
        },
        "lspServers": {
          "$ref": "#/definitions/lspServers"
        },
        "headers": {
          "type": "object",
          "description": "Request headers for an archive or url source. Never credentials: a value that needs a secret belongs in `headersHelper`, which the host runs and whose output the marketplace file never sees.",
          "additionalProperties": {
            "type": "string"
          }
        },
        "headersHelper": {
          "type": "string",
          "minLength": 1,
          "description": "A path or command that produces this entry's archive-download headers at fetch time. Claude Code requires the entry to set `\"strict\": false`, and the schema enforces that with if/then. Claude Code plugin manifest and marketplace references, read 2026-10-05."
        },
        "relevance": {
          "$ref": "#/definitions/relevance"
        },
        "dependencies": {
          "$ref": "#/definitions/dependencies"
        },
        "metadata": {
          "type": "object",
          "description": "Free-form publisher metadata on the entry. Carried, never interpreted."
        },
        "settings": {
          "type": "object",
          "additionalProperties": true
        },
        "userConfig": {
          "$ref": "#/definitions/userConfig"
        },
        "channels": {
          "type": "array",
          "items": {
            "$ref": "#/definitions/channel"
          }
        },
        "outputStyles": {
          "$ref": "#/definitions/componentPath"
        },
        "workflows": {
          "$ref": "#/definitions/componentPath"
        },
        "themes": {
          "$ref": "#/definitions/componentPath"
        },
        "experimental": {
          "$ref": "#/definitions/experimental"
        },
        "types": {
          "type": "string",
          "minLength": 1,
          "allOf": [
            {
              "not": {
                "pattern": "^/"
              }
            },
            {
              "not": {
                "pattern": "(^|/)\\.\\.(/|$)"
              }
            },
            {
              "not": {
                "pattern": "^~"
              }
            },
            {
              "not": {
                "pattern": "^[A-Za-z]:"
              }
            },
            {
              "not": {
                "pattern": "\\\\"
              }
            }
          ]
        },
        "cdf": {
          "$ref": "#/definitions/entryCdf"
        }
      },
      "additionalProperties": true,
      "if": {
        "required": [
          "headersHelper"
        ]
      },
      "then": {
        "required": [
          "strict"
        ],
        "properties": {
          "strict": {
            "const": false
          }
        }
      }
    },
    "entryCdf": {
      "type": "object",
      "description": "The additive CDF block for one entry. Absent in a plain Claude Code marketplace.",
      "properties": {
        "digest": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$",
          "description": "The sha256 the fetched tree must hash to, lower-case hex. A claim the loader checks; a mismatch is a refusal with both digests named, never a warning."
        },
        "capabilities": {
          "$ref": "#/definitions/capabilities"
        }
      },
      "additionalProperties": true
    },
    "metadata": {
      "type": "object",
      "description": "Marketplace-wide defaults.",
      "properties": {
        "pluginRoot": {
          "type": "string",
          "description": "The directory relative paths in `source` resolve from."
        },
        "description": {
          "type": "string"
        },
        "version": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "owner": {
      "type": "object",
      "description": "Who publishes the marketplace. Required: a marketplace with no owner is an anonymous list of things to execute.",
      "required": [
        "name"
      ],
      "properties": {
        "name": {
          "type": "string",
          "minLength": 1
        },
        "email": {
          "type": "string"
        },
        "url": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "repository": {
      "description": "The source repository, as a URL string or as an object carrying one.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "object"
        }
      ]
    },
    "source": {
      "description": "Where a listed plugin comes from: a relative path inside the marketplace, or one of the seven object forms. The harness fetches `local`, `github`, `url` and `git-subdir` in v1; `npm`, `archive` and `command` parse and are reported as an unsupported source form, because a reader that threw on them would refuse a whole marketplace over one entry it could not fetch.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "$ref": "#/definitions/sourceLocal"
        },
        {
          "$ref": "#/definitions/sourceGithub"
        },
        {
          "$ref": "#/definitions/sourceUrl"
        },
        {
          "$ref": "#/definitions/sourceGitSubdir"
        },
        {
          "$ref": "#/definitions/sourceNpm"
        },
        {
          "$ref": "#/definitions/sourceArchive"
        },
        {
          "$ref": "#/definitions/sourceCommand"
        }
      ]
    },
    "sourceArchive": {
      "type": "object",
      "description": "A downloadable archive. Declared, not fetched in v1: no archive reader exists, and hand-rolling one is where path traversal, absolute entries, symlinks and zip-slip get written wrong.",
      "required": [
        "source",
        "url"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "archive"
          ]
        },
        "url": {
          "type": "string",
          "minLength": 1
        },
        "sha256": {
          "type": "string",
          "pattern": "^[0-9a-fA-F]{64}$",
          "description": "The archive digest as 64 hex characters, upper or lower case as Claude Code accepts. Claude Code plugin manifest and marketplace references, read 2026-10-05."
        }
      },
      "additionalProperties": true
    },
    "sourceCommand": {
      "type": "object",
      "description": "A command the host runs to produce the plugin. Declared, not fetched in v1: the harness does not run a marketplace-supplied command to obtain code it is about to run.",
      "required": [
        "source",
        "command"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "command"
          ]
        },
        "command": {
          "type": "string",
          "minLength": 1
        },
        "timeout": {
          "type": "integer",
          "minimum": 1,
          "maximum": 600,
          "description": "Seconds, 1 to 600; Claude Code defaults to 60. Claude Code plugin manifest and marketplace references, read 2026-10-05."
        },
        "mode": {
          "type": "string",
          "enum": [
            "copy",
            "link"
          ],
          "description": "`copy` (default) copies the printed directory; `link` loads it in place. Claude Code plugin manifest and marketplace references, read 2026-10-05."
        }
      },
      "additionalProperties": true
    },
    "sourceGitSubdir": {
      "type": "object",
      "description": "One directory of a git repository. `path` is repository-relative and may not escape it.",
      "required": [
        "source",
        "url",
        "path"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "git-subdir"
          ]
        },
        "url": {
          "type": "string",
          "minLength": 1
        },
        "path": {
          "type": "string",
          "minLength": 1,
          "allOf": [
            {
              "not": {
                "pattern": "^/"
              }
            },
            {
              "not": {
                "pattern": "(^|/)\\.\\.(/|$)"
              }
            },
            {
              "not": {
                "pattern": "^~"
              }
            },
            {
              "not": {
                "pattern": "^[A-Za-z]:"
              }
            },
            {
              "not": {
                "pattern": "\\\\"
              }
            }
          ]
        },
        "ref": {
          "type": "string",
          "minLength": 1,
          "description": "A branch, tag or other revision. A branch is not a pin."
        },
        "sha": {
          "type": "string",
          "pattern": "^[0-9a-f]{7,40}$",
          "description": "A commit sha. The only ref that cannot move."
        }
      },
      "additionalProperties": true
    },
    "sourceGithub": {
      "type": "object",
      "description": "A GitHub repository.",
      "required": [
        "source",
        "repo"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "github"
          ]
        },
        "repo": {
          "type": "string",
          "pattern": "^[^/\\s]+/[^/\\s]+$",
          "description": "owner/repo."
        },
        "ref": {
          "type": "string",
          "minLength": 1,
          "description": "A branch, tag or other revision. A branch is not a pin."
        },
        "sha": {
          "type": "string",
          "pattern": "^[0-9a-f]{7,40}$",
          "description": "A commit sha. The only ref that cannot move."
        }
      },
      "additionalProperties": true
    },
    "sourceLocal": {
      "type": "object",
      "description": "A path already on disk. A CDF extension, not a Claude Code source form: Claude Code's only local form is the relative-path string. CDF's own marketplace lists first-party plugins that ship in the repository, and a local source is the one with nothing to fetch and nothing to pin. The README names it as such.",
      "required": [
        "source",
        "path"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "local"
          ]
        },
        "path": {
          "type": "string",
          "minLength": 1
        }
      },
      "additionalProperties": true
    },
    "sourceNpm": {
      "type": "object",
      "description": "An npm package. Declared, not fetched in v1: the same missing archive reader, plus a registry the egress policy would have to permit.",
      "required": [
        "source",
        "package"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "npm"
          ]
        },
        "package": {
          "type": "string",
          "minLength": 1
        },
        "version": {
          "type": "string"
        },
        "registry": {
          "type": "string"
        }
      },
      "additionalProperties": true
    },
    "sourceUrl": {
      "type": "object",
      "description": "A git repository at an arbitrary URL.",
      "required": [
        "source",
        "url"
      ],
      "properties": {
        "source": {
          "type": "string",
          "enum": [
            "url"
          ]
        },
        "url": {
          "type": "string",
          "minLength": 1
        },
        "ref": {
          "type": "string",
          "minLength": 1,
          "description": "A branch, tag or other revision. A branch is not a pin."
        },
        "sha": {
          "type": "string",
          "pattern": "^[0-9a-f]{7,40}$",
          "description": "A commit sha. The only ref that cannot move."
        }
      },
      "additionalProperties": true
    },
    "dependencies": {
      "type": "array",
      "description": "Plugins that must be enabled for this one to work. Each entry is `\"name\"`, `\"name@marketplace\"`, or an object with `name`, `marketplace` and `version`. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "items": {
        "anyOf": [
          {
            "type": "string",
            "minLength": 1
          },
          {
            "type": "object",
            "required": [
              "name"
            ],
            "properties": {
              "name": {
                "type": "string",
                "minLength": 1
              },
              "marketplace": {
                "type": "string"
              },
              "version": {
                "type": "string"
              }
            },
            "additionalProperties": true
          }
        ]
      }
    },
    "userConfigOption": {
      "type": "object",
      "description": "One user-configuration option. A STRICT object in Claude Code: an unknown key stops the plugin loading, so the contract refuses it too, which is the one place the contract closes a content model to mean what Claude Code means. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "required": [
        "type",
        "title",
        "description"
      ],
      "properties": {
        "type": {
          "type": "string",
          "enum": [
            "string",
            "number",
            "boolean",
            "directory",
            "file"
          ]
        },
        "title": {
          "type": "string",
          "minLength": 1
        },
        "description": {
          "type": "string"
        },
        "required": {
          "type": "boolean"
        },
        "default": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "number"
            },
            {
              "type": "boolean"
            },
            {
              "type": "array",
              "items": {
                "type": "string"
              }
            }
          ]
        },
        "options": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64
          }
        },
        "multiple": {
          "type": "boolean"
        },
        "sensitive": {
          "type": "boolean"
        },
        "min": {
          "type": "number"
        },
        "max": {
          "type": "number"
        }
      },
      "additionalProperties": false
    },
    "userConfig": {
      "type": "object",
      "description": "Values Claude Code prompts the user for when the plugin is enabled. Keys are identifiers of letters, digits and underscores not starting with a digit. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "propertyNames": {
        "pattern": "^[A-Za-z_][A-Za-z0-9_]*$"
      },
      "additionalProperties": {
        "$ref": "#/definitions/userConfigOption"
      }
    },
    "channel": {
      "type": "object",
      "description": "A message channel bound to one of the plugin's MCP servers. A STRICT object in Claude Code. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "required": [
        "server"
      ],
      "properties": {
        "server": {
          "type": "string",
          "minLength": 1
        },
        "displayName": {
          "type": "string"
        },
        "userConfig": {
          "$ref": "#/definitions/userConfig"
        }
      },
      "additionalProperties": false
    },
    "lspServer": {
      "type": "object",
      "description": "One language server. A STRICT object in Claude Code: `command` and `extensionToLanguage` are required and an unknown key fails validation. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "required": [
        "command",
        "extensionToLanguage"
      ],
      "properties": {
        "command": {
          "type": "string",
          "minLength": 1
        },
        "extensionToLanguage": {
          "type": "object",
          "minProperties": 1,
          "propertyNames": {
            "pattern": "^\\."
          },
          "additionalProperties": {
            "type": "string",
            "minLength": 1
          }
        },
        "args": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "transport": {
          "type": "string",
          "enum": [
            "stdio",
            "socket"
          ]
        },
        "env": {
          "type": "object",
          "additionalProperties": {
            "type": "string"
          }
        },
        "initializationOptions": {
          "type": "object"
        },
        "settings": {
          "type": "object"
        },
        "workspaceFolder": {
          "type": "string"
        },
        "startupTimeout": {
          "type": "integer",
          "minimum": 1,
          "maximum": 9007199254740991
        },
        "shutdownTimeout": {
          "type": "integer",
          "minimum": 1,
          "maximum": 9007199254740991
        },
        "requestTimeout": {
          "type": "integer",
          "minimum": 1,
          "maximum": 9007199254740991
        },
        "restartOnCrash": {
          "type": "boolean"
        },
        "maxRestarts": {
          "type": "integer",
          "minimum": 0,
          "maximum": 9007199254740991
        },
        "diagnostics": {
          "type": "boolean"
        }
      },
      "additionalProperties": false
    },
    "lspServers": {
      "description": "`.json` LSP config files, an inline map of server name to config, or an array of either. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/definitions/lspServer"
          }
        },
        {
          "type": "array",
          "items": {
            "anyOf": [
              {
                "type": "string",
                "minLength": 1
              },
              {
                "type": "object",
                "additionalProperties": {
                  "$ref": "#/definitions/lspServer"
                }
              }
            ]
          }
        }
      ]
    },
    "commandEntry": {
      "type": "object",
      "description": "One command in the `commands` object map. Exactly one of `source` (a path) or `content` (inline Markdown) is set. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "properties": {
        "source": {
          "type": "string",
          "minLength": 1
        },
        "content": {
          "type": "string"
        },
        "description": {
          "type": "string"
        },
        "argumentHint": {
          "type": "string"
        },
        "model": {
          "type": "string"
        },
        "allowedTools": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          }
        }
      },
      "oneOf": [
        {
          "required": [
            "source"
          ]
        },
        {
          "required": [
            "content"
          ]
        }
      ],
      "additionalProperties": true
    },
    "commands": {
      "description": "Flat `.md` command files, directories of them, or an object map of command name to `source` or `content`. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "anyOf": [
        {
          "type": "string",
          "minLength": 1
        },
        {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        {
          "type": "object",
          "additionalProperties": {
            "$ref": "#/definitions/commandEntry"
          }
        }
      ]
    },
    "monitor": {
      "type": "object",
      "description": "One background monitor. A STRICT object in Claude Code. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "required": [
        "name",
        "command",
        "description"
      ],
      "properties": {
        "name": {
          "type": "string",
          "minLength": 1
        },
        "command": {
          "type": "string",
          "minLength": 1
        },
        "description": {
          "type": "string",
          "minLength": 1
        },
        "when": {
          "type": "string"
        }
      },
      "additionalProperties": false
    },
    "experimental": {
      "type": "object",
      "description": "Container for `themes`, `monitors` and `evals`, whose manifest shape Claude Code says may still change. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "properties": {
        "themes": {
          "$ref": "#/definitions/componentPath"
        },
        "monitors": {
          "anyOf": [
            {
              "type": "string",
              "minLength": 1
            },
            {
              "type": "array",
              "items": {
                "$ref": "#/definitions/monitor"
              }
            }
          ]
        },
        "evals": {
          "$ref": "#/definitions/componentPath"
        }
      },
      "additionalProperties": true
    },
    "relevance": {
      "type": "object",
      "description": "Signals that tell Claude Code when to suggest the plugin: `topic` and `signals`. Carried, not interpreted. Claude Code plugin manifest and marketplace references, read 2026-10-05.",
      "properties": {
        "topic": {
          "type": "string"
        },
        "signals": {}
      },
      "additionalProperties": true
    }
  },
  "type": "object",
  "required": [
    "name",
    "owner",
    "plugins"
  ],
  "properties": {
    "$schema": {
      "type": "string"
    },
    "name": {
      "type": "string",
      "pattern": "^[A-Za-z0-9][A-Za-z0-9._-]*$",
      "description": "The marketplace id: letters, digits, `.`, `_` and `-`, starting with a letter or digit, no `..`, as Claude Code accepts. Claude Code plugin manifest and marketplace references, read 2026-10-05."
    },
    "owner": {
      "$ref": "#/definitions/owner"
    },
    "description": {
      "type": "string"
    },
    "version": {
      "type": "string"
    },
    "metadata": {
      "$ref": "#/definitions/metadata"
    },
    "allowCrossMarketplaceDependenciesOn": {
      "type": "array",
      "description": "Marketplace names this one permits its plugins to depend on. Absent means none.",
      "items": {
        "type": "string",
        "minLength": 1
      }
    },
    "renames": {
      "type": "object",
      "description": "Old plugin name to new name, or to null when the plugin is withdrawn. A rename does not carry a decision forward: the subject hash changes and the plugin is undecided again.",
      "additionalProperties": {
        "type": [
          "string",
          "null"
        ]
      }
    },
    "plugins": {
      "type": "array",
      "description": "The listed plugins. Required, and may be empty: an empty marketplace is a marketplace that lists nothing, not a malformed one.",
      "items": {
        "$ref": "#/definitions/entry"
      }
    },
    "forceRemoveDeletedPlugins": {
      "type": "boolean",
      "description": "When true, a plugin removed from `plugins` is uninstalled on users' machines. Claude Code plugin manifest and marketplace references, read 2026-10-05."
    }
  },
  "additionalProperties": true
}
