BOSS's plugin store client and plugin lifecycle manager, in a left sidebar panel.
Users see this as Toolbox. The plugin id, panel id, package, repository and jar all
deliberately keep the older plugin-manager name so existing installs and the host's store
bootstrap keep working. Expect both names when reading the code.
- Browse and install from the plugin store, with search and a live progress bar in the status bar at the bottom of the window. On BOSS 9.4.35 and later that bar is the host's, shared with every other transfer in the app: clicking it opens a dialog with Cancel, and an install started from a toast or from the host's own prompt shows there too. On earlier hosts the Toolbox still draws its own bar, without the dialog.
- Manage installed plugins: enable, disable, uninstall, inspect required permissions, view version history, and downgrade to an earlier version.
- Updates arrive on their own, even with the panel closed, as toasts. "Update all" applies them, and the panel tells you what applying actually needs: nothing, a reset of running instances, a full BOSS restart, or an API-layer hot swap.
- Install from outside the store: pick a local
.jarwith a file picker, or paste a GitHub release URL. - MCP tab: toggle individual plugin-contributed MCP tools on and off, see which are permission-locked, start and stop the MCP server, and attach it to Claude Code, Codex, Gemini or OpenCode in one click.
- Create tab: publish your own plugin, or install Tool Creator if you do not have it. Gated
on the
plugins.createpermission and hidden otherwise.
Tabs are Installed, Store, Updates, MCP and Create. Updates appears only when updates exist; Create only when you may publish.
| Tool | Purpose |
|---|---|
plugins_list |
List installed plugins with id, version, enabled and system flags |
plugin_enable |
Enable an installed plugin by id |
plugin_disable |
Disable an installed plugin by id |
plugin_enable and plugin_disable both require admin. plugin_disable additionally refuses
to disable terminal-tab (it hosts the MCP server, so disabling it would cut the channel the
call arrived on), itself, and any system or non-unloadable plugin.
The manifest declares none. Gating happens in impl/PluginPermissions.kt:
plugins.creategates the Create tab. This is deliberately notplugins.admin.publish, whose RLS policy has no author scoping.canInstallWith(...)mirrors the server-side download gate so the UI never offers an install that would come back 403.- Permission claims are read from the JWT without verifying the signature. That is for UI affordances only. Every gated action is re-checked server side, and an unreadable token denies.
- The admin "Delete from Store" action sits behind an additional build-time password hash. It is anti-fat-finger, not an authorization boundary.
- BOSS >= 9.2.33, boss-plugin-api >= 1.0.57
- Supabase at
https://api.risaboss.comfor the store catalog, theplugin-storeedge function, and the Realtime channel that pushes store updates. - Plugins install to
PluginLoaderDelegate.getPluginsDirectory(), falling back to~/.boss/plugins, with aninstalled.jsonindex and<jar>.sigsignature sidecars. - Optional and null-guarded:
McpToolRegistry,McpServerController(from terminal-tab),RoleManagementProvider,PanelEventProvider,ApplicationEventBus.
./gradlew buildPluginJarThe build fails hard if SUPABASE_ANON_KEY is unset: generateBuildConfig needs it to
write BuildConfig.kt.
This is a bundled system plugin (loadPriority: 5, canUnload: false), so it ships with
BossConsole rather than being installed from the store. It also cannot hot-reload itself.
PluginManagerCoreruns fromregister()todispose(), independent of the panel. It owns the Supabase client and the Realtime connection and runs the update prompt service, which is why update toasts fire whether or not the panel is ever opened.- Three plugins are treated as non-hot-reloadable when applying an update: Toolbox itself,
ai.rever.boss.plugin.api(which triggers a process-wide API-layer swap), andai.rever.boss.microkernel.runtime.
See AGENTS.md for architecture and conventions.
Licensed under the Apache License, Version 2.0.