Install a Plugin from the marketplace
The marketplace publishes reviewed VibeX Plugins. Settings → Plugins → Marketplace reads the same Catalog. The same install command also accepts a Git repository, a GitHub Release, or a local .vxp. The package stays on that Host; it is not copied to other machines.
Start at the plugin marketplace and the Host marketplace tab. The contract is in the developer docs. Enable, disable, and uninstall are in Install and enable a Plugin.
Before you start
- VibeX desktop is running, or
npx vibex servehas started a Host. - The shell can run
npx vibex. - If desktop or
npx vibex serveis running,plugin addfinds the local Host token and imports into the catalog. If no Host is up, snapshots land in~/.vibex/imports/and linked development directories go to~/.vibex/imports/links.jsonl. Desktop or Server imports them on the next launch. Default URL ishttp://127.0.0.1:17891; override withVIBEX_URL/VIBEX_TOKEN. list,update, andremoveneed a running Host.
Install command
Open the plugin marketplace, open the plugin page, and copy the Installation command:
npx vibex plugin add https://vibex.xforever.xin/marketplace/<author>/<plugin>Replace the URL with the plugin page on the site you are using. A local preview host is http://127.0.0.1:3100/marketplace/<author>/<plugin>. The explicit form is equivalent:
npx vibex plugin add --web https://vibex.xforever.xin/marketplace/<author>/<plugin>Git repositories use --web. Pin the tree with #tag, #branch, or #commit:
npx vibex plugin add --web https://github.com/<owner>/<repo>#v1.0.0
npx vibex plugin add --web github:<owner>/<repo>#v1.0.0Without #, the default branch is installed and the source is unlocked. To follow later versions with plugin update, reinstall from a URL that includes #.
A GitHub Release that ships a .vxp is downloaded as that asset. A GitHub digest or a sibling .sha256 is verified when present:
npx vibex plugin add --web https://github.com/<owner>/<repo>/releases/tag/v1.0.0A local .vxp, zip, or other plugin archive:
npx vibex plugin add --profile ~/plugins/search.vxpIf the archive contains more than one package, add --plugin <plugin-id>. Use --yes when stdin is not a TTY.
After the command, open Settings → Plugins. A new install starts disabled. After enable, UI and Provider contributions appear immediately; Skills and MCP enter later new or rebound sessions. If the command says Desktop will import on next launch, quit VibeX fully and open it again.
The marketplace tab shows a Full Trust confirmation before install. Origin lock is marketplace or github. When a newer tag or semver appears remotely, Installed shows Update available. Marketplace installs ask the Catalog; GitHub installs ask that repository.
Prefer the marketplace page URL when the listing exists. Linking a development directory is an author path: add --dev only links; hot reload is vibex plugin run dev. See Development workflow.
Import a package file
The plugin page offers Download package. After you have a .vxp (or zip / tar.gz):
- Open Settings → Plugins.
- Choose Add plugin or Import plugin and pick the file.
- Confirm identity and permissions, then install.
- Enable the row in the catalog.
Dropping a .vxp onto the plugins page is the same as choosing a file. One identity cannot use two sources at once; if the ID is already in the catalog, keep the current source or replace it.
What the command does
plugin add runs in this order:
- Detect a marketplace page, a Git repository, a GitHub Release, an archive URL, or a local file.
- For a marketplace page, call
/api/marketplace/v1/artifact/<author>/<plugin>?tag=and follow the published download URL, sha256, and identity tuple. - Clone a Git repository at
#ref; download a Release.vxpand verify SHA-256 when a digest is present; unpack a local archive. - Look for
.vibex-plugin/plugin.json, validate the product package, and write~/.vibex/imports/<plugin-id>-<version>.vxp. - Record origin, gitRef, gitSha, and whether the source is locked. If a token is present and install is confirmed, call Host
plugin_control_import.
Unpublished submissions have no marketplace download URL, so the command fails. A broken layout, an unreadable archive, or a Release with no .vxp fails the same way. A download that advertises a digest and does not match SHA-256 aborts.
List and update
npx vibex plugin list
npx vibex plugin update <plugin-id>
npx vibex plugin update <plugin-id> --ref v1.3.0list is the Installed catalog, including source and lock. update fetches another snapshot from the locked origin; --ref selects a new tag, branch, or commit. Linked development plugins do not use update: edit the source directory and the Host reloads when the digest changes. A snapshot with no locked origin must be reinstalled from a URL that includes #tag.
After install
The catalog lists the plugin. Marketplace, Git, and local-archive installs can be uninstalled. Config, disable, and uninstall are in Install and enable a Plugin.
To ship your own package, follow Development workflow, run pack, then npx vibex plugin publish. Git distribution puts the tag in the install command. A GitHub Release includes both the .vxp and a .sha256.

