Select the form, declare permissions, and submit for review to put it on the shelves. Signature packaging and instance-sustained tokens ensure security for every installer, so you only need to focus on the capabilities themselves—and revenue sharing.
The form determines the plug-in's running environment, available permissions, and audit path. The closer you are to the core data, the stricter the audit - which is why the installer is willing to trust you.
Use manifests to describe fields, automation rules, or theme styles without running your code. Install immediately after confirmation, with the lowest trust risk.
Your service runs out-of-process and communicates with the instance through a signed API. The access token is self-held by the installer instance, and permissions are granted item by item and can be revoked at any time.
Inject custom UI and widgets into the workbench in an isolated iframe sandbox. The most stringent review, but the richest interface experience.
Select declarative / connected / sandboxed according to capabilities to determine the running environment and audit path.
Declare meta-information, required permission scopes and capability entries, and the editor will verify them in real time.
Submit after signing and packaging, and the operation will conduct security and compliance review according to the form.
After being put on the shelves immediately, the installation and subscription revenue will be divided on a monthly basis.
The manifest is a contract between you and the installer: each scope declared will be presented one by one in the installation pop-up window. It will only take effect after the installer confirms it, and can be revoked at any time. No claims, no access.
Apply to become a developer and get manifest specifications, signing tools and joint debugging guidelines. Deliver your capabilities to thousands of Wukong instances.