* fix(plugins): normalize network runtimes * build(plugins): align network runtime dependencies * test(runtime): stabilize network compatibility checks * fix(codex): route managed transports through runtime owners
67 KiB
| summary | doc-schema-version | read_when | title | ||
|---|---|---|---|---|---|
| Plugin SDK subpath catalog: which imports live where, grouped by area | 1 |
|
Plugin SDK subpaths |
The plugin SDK contains narrow public subpaths and repository-only bundled
helpers under openclaw/plugin-sdk/. This page catalogs every typed public
subpath and labels selected private-local entries explicitly; it is not an
inventory of every internal runtime helper. Four files define the boundary:
scripts/lib/plugin-sdk-entrypoints.json: the maintained entrypoint inventory the build compiles.scripts/lib/plugin-sdk-private-local-only-subpaths.json: internal subpaths excluded from the typed, documented SDK. Production entries remain available as JavaScript-only host runtime exports for separately published official plugins; test-only entries stay unexported.scripts/lib/plugin-sdk-deprecated-public-subpaths.json: public compatibility subpaths retained only through their documented removal windows.scripts/lib/plugin-sdk-entries.mts: derived public/private export metadata, supported bundled facades, and plugin-owned public surfaces.
After changing the entrypoint inventories, run pnpm plugin-sdk:sync-exports,
then pnpm plugin-sdk:check-exports. The same registration command maintains
package exports, private artifact exclusions in package.json's files, and
private workspace declaration aliases in
extensions/tsconfig.package-boundary.paths.json and extensions/xai/tsconfig.json.
It owns literal flat !dist/plugin-sdk/<name>.js and .d.ts exclusions, including
names with underscores, uppercase letters, dots, or Unicode, and removes obsolete
exclusions when entries become public or are removed. Nested paths, glob or escape
syntax, non-entrypoint metadata, and other file rules retain their order; unrelated
mappings and XAI's intentional private-alias omissions are preserved.
These local declaration aliases do not add types to JavaScript-only published
SDK exports; test-only entries remain unexported.
Maintainers audit the public export count with pnpm plugin-sdk:surface and
the compatibility queue with pnpm plugins:boundary-report:summary.
For the plugin authoring guide, see Plugin SDK overview.
Plugin entry
Native feature authoring uses plugin-sdk/feature-contract
(defineFeatureContract, createFeatureClient), plugin-sdk/feature-plugin
(defineFeaturePlugin), and plugin-sdk/control-ui (defineControlUiPlugin,
host and view types). The contract and Control UI subpaths are browser safe;
feature-plugin is backend only. See Feature plugins.
| Subpath | Key exports |
|---|---|
plugin-sdk/plugin-entry |
definePluginEntry, PluginCapabilityCatalog, PluginCapabilityCatalogEntry, PluginCapabilityCatalogContext |
plugin-sdk/core |
defineChannelPluginEntry, createChatChannelPlugin, createChannelPluginBase, defineSetupPluginEntry, buildChannelConfigSchema, buildJsonChannelConfigSchema, resolveTailscalePublishedHost |
plugin-sdk/provider-entry |
Private-local after July 2026; defineSingleProviderPluginEntry |
plugin-sdk/migration |
Private-local after July 2026; Migration provider item helpers such as createMigrationItem, reason constants, item status markers, redaction helpers, and summarizeMigrationItems |
plugin-sdk/migration-runtime |
Private-local after July 2026; Runtime migration helpers such as copyMigrationFileItem, resolvePlannedMigrationTargets, withCachedMigrationConfigRuntime, and writeMigrationReport |
plugin-sdk/health |
Doctor health-check registration, detection, repair, selection, severity, and finding types for bundled health consumers |
plugin-sdk/channel-entry-contract |
Bundled channel entry and setup-entry contracts, feature declarations, and lazy module-loading helpers |
Capability catalog entry
A manifest's capabilityCatalogEntry default export satisfies
PluginCapabilityCatalogEntry from openclaw/plugin-sdk/plugin-entry:
import type { PluginCapabilityCatalogEntry } from "openclaw/plugin-sdk/plugin-entry";
import { buildSpeechProvider } from "./speech-provider.js";
export default {
speechProviders: [buildSpeechProvider()],
} satisfies PluginCapabilityCatalogEntry;
The optional collections are speechProviders, realtimeTranscriptionProviders,
and realtimeVoiceProviders. Use the same provider factories as full registration;
retain their configuration, aliases, readiness functions, execution methods, and
non-enumerable internal methods. The host registers descriptors through the normal
registrar, preserving its ownership and registration lifecycle.
The export may instead be a synchronous factory receiving
PluginCapabilityCatalogContext. It supplies native host operations for readiness,
auth resolution, provider headers, bounded HTTP responses, WebSocket transcription,
and capture/logging. Pass the operations used by a provider into its shared factory;
keep synchronous constructors and invoke the operations only when needed. This
avoids transforming host runtime modules through the plugin source loader during
catalog construction or connection setup. Construction must not query auth stores,
start sessions, or import broad host or plugin runtime modules. Cold discovery does
not receive a live broker; active registrations retain their broker-bound behavior.
See manifest capability catalogs for family coverage, compatibility, artifact selection, and failure behavior.
Compatibility and private-local helpers
Deprecated compatibility subpaths remain exported under their recorded windows
and retention blockers. July 2026 aliases and unused subpaths were deleted,
while bundled-only helpers were excluded from the typed public SDK and are
labeled private-local below. Production-private JavaScript exports remain
available for official plugin runtimes. The maintained list is
scripts/lib/plugin-sdk-deprecated-public-subpaths.json; CI rejects bundled
imports of these compatibility-only subpaths. The broad domain barrels
plugin-sdk/agent-runtime, plugin-sdk/channel-lifecycle,
plugin-sdk/conversation-runtime, plugin-sdk/hook-runtime,
plugin-sdk/media-runtime, plugin-sdk/plugin-runtime, and
plugin-sdk/security-runtime are likewise deprecated in favor of focused
subpaths.
OpenClaw's Vitest-backed test-helper subpaths are repo-local only and are no
longer package exports: agent-runtime-test-contracts,
channel-contract-testing, channel-target-testing, channel-test-helpers,
plugin-state-test-runtime, plugin-test-api, plugin-test-contracts,
plugin-test-runtime, provider-http-test-mocks, provider-test-contracts,
reply-payload-testing, sqlite-runtime-testing, test-env, test-fixtures,
test-live, test-live-auth, test-media-generation,
test-media-understanding, test-node-mocks, and testing.
ssrf-runtime-internal is a JavaScript-only host runtime reserved for exact
trusted local-service plugins; it is not a public plugin authoring API.
Bundled plugin helper subpaths
Bundled-only helper modules are private-local after the July 2026 sweep. Package contract guardrails classify the supported bundled facades that remain public until generic contracts replace them. Those facades are deprecated for new code; see the per-row notes below.
| Subpath | Key exports | | --- | --- | | `plugin-sdk/channel-core` | `defineChannelPluginEntry`, `defineSetupPluginEntry`, `createChatChannelPlugin`, `createChannelPluginBase`, `createChannelConfigUiHints` | | `plugin-sdk/json-schema-runtime` | Private-local after July 2026; Cached JSON Schema validation helper for plugin-owned schemas | | `plugin-sdk/channel-setup` | `defineChannelSetupContract`, channel-owned setup field/input types, `createOptionalChannelSetupSurface`, `createOptionalChannelSetupAdapter`, `createOptionalChannelSetupWizard`, plus `DEFAULT_ACCOUNT_ID`, `createTopLevelChannelDmPolicy`, `setSetupChannelEnabled`, `splitSetupEntries` | | `plugin-sdk/channel-dm-policy` | `createChannelDmPolicy` for account-aware setup policy descriptors | | `plugin-sdk/setup` | Shared setup wizard helpers, setup translator, allowlist prompts, setup status builders | | `plugin-sdk/setup-runtime` | `defineChannelSetupContract`, `createSetupTranslator`, `createPatchedAccountSetupAdapter`, `createEnvPatchedAccountSetupAdapter`, `createSetupInputPresenceValidator`, `noteChannelLookupFailure`, `noteChannelLookupSummary`, `promptResolvedAllowFrom`, `splitSetupEntries`, `createAllowlistSetupWizardProxy`, `createDelegatedSetupWizardProxy` | | `plugin-sdk/setup-tools` | `formatCliCommand`, `detectBinary`, `extractArchive`, `resolveBrewExecutable`, `formatDocsLink`, `CONFIG_DIR` | | `plugin-sdk/archive` | `extractArchive`, `readArchiveEntry`, archive limits and entry kinds | | `plugin-sdk/root-walk` | `walkRootDirectory`, root-walk options and entries | | `plugin-sdk/secret-file` | `createSecretFileAtomic`, synchronous and asynchronous secret reads | | `plugin-sdk/account-core` | Multi-account config/action-gate helpers, default-account fallback helpers | | `plugin-sdk/account-id` | `DEFAULT_ACCOUNT_ID`, account-id normalization helpers | | `plugin-sdk/account-resolution` | Account lookup + default-fallback helpers | | `plugin-sdk/account-helpers` | Narrow account-list/account-action helpers | | `plugin-sdk/access-groups` | Private-local after July 2026; Access-group allowlist parsing and redacted group diagnostics helpers | | `plugin-sdk/channel-pairing` | `createChannelPairingController` | | `plugin-sdk/channel-reply-pipeline` | Retained compatibility facade. `channel-outbound` exports `createChannelMessageReplyPipeline` and `resolveChannelMessageSourceReplyDeliveryMode`; other function names are unchanged, but named types do not all move. See [retained channel mappings](/plugins/sdk-migration#retained-channel-facade-mappings). | | `plugin-sdk/channel-config-helpers` | `createHybridChannelConfigAdapter`, `resolveChannelDmAccess`, `resolveChannelDmAllowFrom`, `resolveChannelDmPolicy`, `normalizeChannelDmPolicy`, `normalizeLegacyDmAliases` | | `plugin-sdk/channel-config-schema` | Shared channel config schema primitives plus Zod and direct JSON/TypeBox builders | | `plugin-sdk/bundled-channel-config-schema` | Private-local after July 2026; Bundled OpenClaw channel config schemas for maintained bundled plugins only | | `plugin-sdk/chat-channel-ids` | Private-local after July 2026; `BUNDLED_CHAT_CHANNEL_IDS`, `BUNDLED_CHAT_CHANNEL_ENVELOPE_PREFIXES`, `ChatChannelId`. Canonical bundled/official chat channel ids plus formatter labels/aliases for plugins that need to recognize envelope-prefixed text without hardcoding their own table. | | `plugin-sdk/channel-policy` | `resolveChannelGroupRequireMention` | | `plugin-sdk/channel-ingress-runtime` | Experimental high-level channel ingress runtime resolver, implicit-mention policy resolver, and route fact builders for migrated channel receive paths. Prefer this over assembling effective allowlists, command allowlists, and legacy projections in each plugin. See [Channel ingress API](/plugins/sdk-channel-ingress). | | `plugin-sdk/channel-lifecycle` | Retained compatibility facade. Selected functions move unchanged to `channel-outbound`; other helpers require behavioral migration or an owner-approved public replacement. Named types do not all move. See [retained channel mappings](/plugins/sdk-migration#retained-channel-facade-mappings). | | `plugin-sdk/channel-outbound` | Message lifecycle contracts plus reply pipeline options, receipts, live preview/streaming, lifecycle helpers, outbound identity, payload planning, durable sends, and message-send context helpers. See [Channel outbound API](/plugins/sdk-channel-outbound). | | `plugin-sdk/channel-message` | Retained compatibility facade. Move outbound exports to `channel-outbound` and its three dispatch aliases to their renamed exports in `channel-inbound`. See [retained channel mappings](/plugins/sdk-migration#retained-channel-facade-mappings). | | `plugin-sdk/inbound-envelope` | Shared inbound route + envelope builder helpers | | `plugin-sdk/inbound-event-delivery` | Process-local correlation between active inbound events and successful channel sends | | `plugin-sdk/inbound-reply-dispatch` | Deprecated compatibility shim for `dispatchInboundReplyWithBase`; its compatibility-ledger gate is the next Plugin SDK major, not a calendar date. Use `plugin-sdk/channel-inbound` for inbound runners and `plugin-sdk/channel-outbound` for message delivery helpers. | | `plugin-sdk/outbound-media` | Private-local after July 2026; Shared outbound media loading and hosted-media state helpers | | `plugin-sdk/poll-runtime` | Private-local after July 2026; Narrow poll normalization helpers | | `plugin-sdk/thread-bindings-runtime` | Private-local after July 2026; Thread-binding lifecycle and adapter helpers | | `plugin-sdk/agent-media-payload` | Deprecated compatibility facade for legacy `Media*` payload projection. Pass ordered facts through `MsgContext.media` / `toInboundMediaFacts(...)`; import local-root policy from `plugin-sdk/media-local-roots`. | | `plugin-sdk/conversation-runtime` | Deprecated broad barrel for conversation/thread binding, pairing, and configured-binding helpers; prefer focused binding subpaths such as `plugin-sdk/thread-bindings-runtime` and `plugin-sdk/session-binding-runtime` | | `plugin-sdk/runtime-group-policy` | Runtime group-policy resolution helpers | | `plugin-sdk/channel-status` | Shared channel status snapshot/summary helpers | | `plugin-sdk/channel-config-primitives` | Narrow channel config-schema primitives | | `plugin-sdk/channel-config-writes` | Private-local after July 2026; Channel config-write authorization helpers | | `plugin-sdk/channel-plugin-common` | Shared channel plugin prelude exports | | `plugin-sdk/allowlist-config-edit` | Allowlist config edit/read helpers | | `plugin-sdk/direct-dm-guard-policy` | Private-local after July 2026; Narrow direct-DM pre-crypto guard policy helpers | | `plugin-sdk/discord` | Deprecated Discord compatibility facade for published `@openclaw/discord@2026.3.13` and tracked owner compatibility; new plugins should use generic channel SDK subpaths | | `plugin-sdk/telegram-account` | Deprecated Telegram account-resolution compatibility facade for tracked owner compatibility; new plugins should use injected runtime helpers or generic channel SDK subpaths | | `plugin-sdk/interactive-runtime` | Semantic message presentation, delivery, and legacy interactive reply helpers. See [Message Presentation](/plugins/message-presentation) | | `plugin-sdk/question-gateway-runtime` | Resolve runtime-authored `ask_user` choices through the Gateway from channel interaction handlers | | `plugin-sdk/channel-inbound` | Shared inbound helpers for event classification, context building, formatting, roots, debounce, mention matching, mention-policy, and inbound logging | | `plugin-sdk/channel-inbound-debounce` | Narrow inbound debounce helpers | | `plugin-sdk/channel-mention-gating` | Private-local after July 2026; Narrow mention-policy, mention marker, and mention text helpers without the broader inbound runtime surface | | `plugin-sdk/channel-streaming-config` | Dependency-light channel streaming config readers (`getChannelStreamingConfigObject`, `resolveChannelStreamingNativeTransport`) for doctor contract closures and other control-plane paths that must not load the reply pipeline | | `plugin-sdk/channel-send-result` | Reply result types | | `plugin-sdk/channel-actions` | Channel message-action helpers, plus deprecated native schema helpers kept for plugin compatibility | | `plugin-sdk/channel-route` | Private-local after July 2026; Shared route normalization, parser-driven target resolution, thread-id stringification, dedupe/compact route keys, parsed-target types, and route/target comparison helpers | | `plugin-sdk/channel-targets` | Private-local after July 2026; Target parsing helpers; route comparison callers should use `plugin-sdk/channel-route` | | `plugin-sdk/channel-contract` | Channel contract types | | `plugin-sdk/channel-feedback` | Feedback/reaction wiring | | `plugin-sdk/reply-payload` | Reply payload types, normalization, content/media inspection, native question option ordering, chunked send helpers, reasoning detection, and reply fan-out |The September channel facades remain public as removal-pending records until
their recorded blockers are resolved; a registry date does not automatically
remove an export. See the removal timeline.
July aliases such as direct-DM access, reply-options, pairing paths, and channel
runtime splinters have been removed; bundled-only helpers are private-local.
createBoundedProviderBinaryStream requires a request cleanup callback.
Stream cancellation and release() start source cancellation, unlock the reader,
and run cleanup once, then wait for both operations. Cancellation propagates
source failures; release() ignores them. Cleanup failures take precedence in
both cases. Overflow preserves its fitting prefix and error without waiting for
cleanup; later release() reports cleanup failure. After EOF or a read error,
the caller must still invoke and await release().
Provider usage snapshots normally report one or more quota windows, each with
a label, percent used, and optional reset time. Providers that expose balance or
account-state text instead of resettable quota windows should return
summary with an empty windows array rather than fabricating percentages.
OpenClaw displays that summary text in status output; use error only when the
usage endpoint failed or returned no usable usage data.
Sensitive text redaction
The retained openclaw/plugin-sdk/security-runtime export and its
@openclaw/plugin-sdk/security-runtime package facade expose
redactSensitiveText(text, options?). It returns the redacted string.
textis a string. Withoutoptions, the function uses logging configuration.modeaccepts"tools"(the default) or"off". Registered exact secrets are masked even when mode is"off".patternsis a readonly array of strings,RegExpobjects, or synchronous matcher objects. An omitted or empty array uses the default string rules. A nonempty array replaces that string list. Built-in form-body, structured-auth, and AWS bare-key protections always apply when mode is"tools". String rules run in order after form-body and structured-auth preprocessing.- String entries accept a regex source (default flags
gi) or/source/flags. Strings pass the config regex safety validator. Regex entries gaingwhen absent. Captures select the value to mask; without captures, the whole match is masked. sensitiveFieldPatternshas the same entry types but is used by structured redaction, not by this text function.
A matcher has source: string (a diagnostic label) and
exec(input): Iterable<{ match: string; groups: string[]; input: string; offset: number }>.
It must finish synchronously and return a fresh iterable for each call. Keep
cursors and other scan state local to that call; the same object can be reused.
Each record must satisfy these requirements:
inputis the current string passed toexec, after registered-secret masking and earlier rules. Do not use offsets from the original user text.offsetis a UTF-16 code-unit index into that current string.matchis a nonempty exact substring beginning there. Emit records in ascending order without overlap.groupscontains capture strings in order, using""for unmatched groups. The last nonempty capture selects the secret's last occurrence withinmatch; an empty capture list selects the whole match. Include only the intended secret in that capture so surrounding text remains intact.
Matcher objects and RegExp objects are programmatic arguments. They are never
serialized into logging.redactPatterns, which remains a string array. OpenClaw
does not persist matcher state or migrate configuration for this argument kind.
Existing string and regex callers remain supported. Older hosts need not support
matcher objects; plugins using them must require a host version that supports them.
For structured SecretRefs, resolveReadOnlyEnvSecretRef returns blocked when the ref cannot be used, including an allowed env ref whose value is missing or empty. Callers may apply their existing fallback only for missing; a blocked ref must not borrow ambient or auth-profile credentials. Its provider check follows source-specific default aliases and explicit env allowlists.
Use isLoopbackHost(host) when a plugin must accept only the local machine. It accepts localhost, IPv4 loopback literals across 127.0.0.0/8, ::1, bracketed IPv6, and IPv4-mapped IPv6 loopback literals. It parses IP literals rather than matching text prefixes, so a DNS name such as 127.0.0.1.evil.com is not loopback. Use isPrivateOrLoopbackHost(host) only when private-network hosts such as RFC 1918 addresses are also valid.
Private process callers declare `using prepared = prepareSecretInputStdio(stdio, secretInput)`
before spawning, then call `await prepared?.deliverTo(child)` once. Delivery closes the writer
and zeroes the transient credential buffer; disposal closes any untransferred descriptors,
including when spawning throws. POSIX uses anonymous pipes that support descriptor-path readers
without credential files; Windows retains its overlapped child pipe. Callers own child cleanup
when delivery fails.
| Subpath | Key exports |
| --- | --- |
| `plugin-sdk/media-runtime` | Deprecated broad media barrel including `saveRemoteMedia`, `saveResponseMedia`, `readRemoteMediaBuffer`, and deprecated `fetchRemoteMedia`; prefer `plugin-sdk/media-store`, `plugin-sdk/media-mime`, `plugin-sdk/outbound-media`, and capability runtime subpaths, and prefer store helpers before buffer reads when a URL should become OpenClaw media |
| `plugin-sdk/media-local-roots` | Focused `getAgentScopedMediaLocalRoots(...)` and policy-aware `getAgentScopedMediaLocalRootsForSources(...)` helpers for plugin-owned local media reads |
| `plugin-sdk/media-mime` | Narrow MIME normalization, file-extension mapping, MIME detection, and media-kind helpers |
| `plugin-sdk/media-store` | Narrow media store helpers such as `saveMediaBuffer`, `saveMediaStream`, and `saveMediaSource` (local path or HTTP(S) URL into managed media with core's SSRF, byte, redirect, and timeout limits) |
| `plugin-sdk/media-generation-runtime` | Private-local after July 2026; Shared media-generation failover helpers, candidate selection, and missing-model messaging |
| `plugin-sdk/media-understanding` | Deprecated compatibility facade for media-understanding provider types and helpers; new providers register through the injected plugin API and keep request helpers plugin-owned |
| `plugin-sdk/media-understanding-runtime` | Channel audio preflight/echo helpers plus image, video, audio, and structured media-understanding runtime functions |
| `plugin-sdk/computer-use` | Computer Use v2 action and snapshot schemas, JSON parsers, validation, capability descriptors, and provider registration |
| `plugin-sdk/native-command-config-runtime` | Dependency-light native command and skill enablement config checks |
| `plugin-sdk/text-chunking` | Outbound text and offset-preserving range chunking, opt-in inline code source maps and renderer syntax through `findCodeRegions(text, { includeSource: true, syntax: "commonmark" })` (GFM by default), the UTF-16 boundary helper `avoidTrailingHighSurrogateBreak`, markdown chunking/render helpers, quote-aware HTML tag tokenization, markdown table conversion, directive-tag stripping, and safe-text utilities |
| `plugin-sdk/speech` | Private-local after July 2026; Speech provider types plus provider-facing directive, registry, validation, OpenAI-compatible TTS builder, and speech helper exports |
| `plugin-sdk/speech-core` | Private-local after July 2026; Shared speech provider types, registry, directive, normalization, and speech helper exports |
| `plugin-sdk/speech-provider` | Private-local JavaScript-only host runtime for official plugins; speech provider types, configuration and directive helpers, and the OpenAI-compatible provider factory without host registry or synthesis imports. |
| `plugin-sdk/speech-settings` | Lightweight TTS config resolution and normalization primitives without provider registries or synthesis runtime |
| `plugin-sdk/realtime-transcription` | Private-local after July 2026; Realtime transcription provider types, registry helpers, and shared WebSocket session helper |
| `plugin-sdk/realtime-transcription-session` | Private-local JavaScript-only host runtime for official plugins; shared WebSocket session construction and types without loading the host provider registry. Use this for provider implementation imports. |
| `plugin-sdk/realtime-bootstrap-context` | Private-local after July 2026; Realtime profile bootstrap helper for bounded `IDENTITY.md`, `USER.md`, and `SOUL.md` context injection |
| `plugin-sdk/realtime-voice-audio-queue` | Private-local JavaScript-only host runtime for bundled or separately published official plugins; narrow bounded audio queue seam for lazy realtime voice provider facades without importing the broader realtime voice runtime; not for third-party plugins |
| `plugin-sdk/realtime-voice-provider` | Private-local JavaScript-only host runtime for official plugins; provider types, audio formats/codecs, response outcomes, and connection lifecycle primitives without host provider registries or agent-consult execution. |
| `plugin-sdk/realtime-voice-activation` | Private-local; dependency-light realtime-voice activation-name helpers (normalize, match, word-count, sort) for doctor contract closures and other control-plane paths that must not load the realtime voice runtime |
| `plugin-sdk/realtime-voice` | Private-local after July 2026; Realtime voice provider types, registry helpers, shared audio-energy/speech-onset gates, and realtime voice behavior helpers, including the transport-independent session harness and output activity tracking. For official runtime consumers, sender-auth contract revision 1 forwards ingress-authenticated `senderId` and `senderIsOwner` unchanged; ingress owns authentication, and consumers requiring the handoff must fail closed on other revisions. |
| `plugin-sdk/meeting-page-script-runtime` | Private-local JavaScript-only host runtime for official browser-meeting plugins; shared transcript and leave page-script source builders; not a third-party plugin API |
| `plugin-sdk/meeting-runtime` | Browser-meeting session runtime, realtime audio engines/transports, `MeetingPlatformAdapter`, browser/node control, agent-consult, voice-call delegation, setup checks, and SoX command helpers |
| `plugin-sdk/image-generation` | Private-local after July 2026; Image generation provider types plus image asset/data URL helpers and the OpenAI-compatible image provider builder |
| `plugin-sdk/image-generation-core` | Private-local after July 2026; Shared image-generation types, failover, auth, and registry helpers |
| `plugin-sdk/music-generation` | Private-local after July 2026; Music generation provider/request/result types |
| `plugin-sdk/video-generation` | Private-local after July 2026; Video generation provider/request/result types |
| `plugin-sdk/transcripts` | Private-local after July 2026; Shared transcript source provider types, registry helpers, meeting-provider bridge factory, session descriptors, and utterance metadata |
| `plugin-sdk/webhook-targets` | Private-local after July 2026; Webhook target registry and route-install helpers |
| `plugin-sdk/web-media` | Shared remote/local media loading helpers |
| `plugin-sdk/plugin-test-api` | Repo-local minimal `createTestPluginApi` helper for direct plugin registration unit tests without importing repo test helper bridges |
| `plugin-sdk/agent-runtime-test-contracts` | Repo-local native agent-runtime adapter contract fixtures for auth, delivery, fallback, tool-hook, prompt-overlay, schema, and transcript projection tests |
| `plugin-sdk/channel-test-helpers` | Repo-local channel-oriented test helpers for generic actions/setup/status contracts, directory assertions, account startup lifecycle, send-config threading, runtime mocks, status issues, outbound delivery, and hook registration |
| `plugin-sdk/channel-target-testing` | Repo-local shared target-resolution error-case suite for channel tests |
| `plugin-sdk/channel-contract-testing` | Repo-local narrow channel contract test helpers without the broad testing barrel |
| `plugin-sdk/plugin-test-contracts` | Repo-local plugin package, registration, public artifact, runtime API, and import side-effect contract helpers |
| `plugin-sdk/plugin-state-test-runtime` | Repo-local plugin state store, ingress queue, and state DB test helpers |
| `plugin-sdk/provider-test-contracts` | Repo-local provider runtime, auth, discovery, onboard, catalog, wizard, media capability, replay policy, realtime STT live-audio, web-search/fetch, and stream contract helpers |
| `plugin-sdk/provider-http-test-mocks` | Private-local after July 2026; Repo-local opt-in Vitest HTTP/auth mocks for provider tests that exercise `plugin-sdk/provider-http` |
| `plugin-sdk/reply-payload-testing` | Repo-local helpers for attaching metadata to reply payload fixtures |
| `plugin-sdk/sqlite-runtime-testing` | Repo-local SQLite lifecycle helpers for first-party tests |
| `plugin-sdk/test-state` | Repo-local isolated OpenClaw state, config, workspace, environment, and auth-profile fixtures for plugin tests |
| `plugin-sdk/test-fixtures` | Repo-local generic CLI runtime capture, direct-import smoke, sandbox context, skill writer, agent-message, system-event, module reload, bundled plugin path, terminal-text, chunking, auth-token, and typed-case fixtures |
| `plugin-sdk/test-node-mocks` | Repo-local focused Node builtin mock helpers for use inside Vitest `vi.mock("node:*")` factories |
For bundled plugins, `markdown-table-runtime` exposes `getMarkdownTableSource(table)` for tables returned by
`markdownToIRWithMeta(text, { tableMode: "block" })`. It returns source `start`/`end`
offsets, a continuation `prefix`, and the original cell Markdown in `headers`/`rows`.
Slice the same input string to preserve table bytes without reparsing Markdown containers.
This metadata is non-enumerable; the getter returns `undefined` for tables without it.
| Subpath | Key exports |
| --- | --- |
| `plugin-sdk/memory-core-host-embedding-registry` | Private-local after July 2026; Lightweight memory embedding provider registry helpers |
| `plugin-sdk/memory-core-host-engine-curated` | Private-local focused curated-memory annotation parsing for doctor and promotion paths |
| `plugin-sdk/memory-core-host-engine-foundation` | Memory host foundation engine exports |
| `plugin-sdk/memory-core-host-engine-fs` | Private-local focused filesystem and user-path helpers for doctor migrations |
| `plugin-sdk/memory-core-host-engine-embeddings` | Private-local after July 2026; Memory host embedding contracts and batch/remote helpers. Providers register through the generic embedding provider API. |
| `plugin-sdk/memory-core-host-engine-sessions` | Private-local after July 2026; Memory session transcript and query helpers |
| `plugin-sdk/memory-core-host-engine-schema` | Private-local focused memory index schema and sqlite-vec helpers for doctor migrations |
| `plugin-sdk/memory-core-host-engine-indexing` | Private-local immutable chunk preparation, annotations, hashes, and embedding input limits for indexing workers |
| `plugin-sdk/memory-core-host-engine-knn` | Private-local read-only SQLite ownership checks, sqlite-vec, and text/vector primitives for isolated retrieval workers and children |
| `plugin-sdk/memory-core-host-engine-storage` | Private-local after July 2026; Memory host storage engine exports |
| `plugin-sdk/memory-core-host-secret` | Private-local after July 2026; Memory host secret helpers |
| `plugin-sdk/memory-core-host-status` | Private-local after July 2026; Memory host status helpers |
| `plugin-sdk/memory-core-host-runtime-cli` | Private-local after July 2026; Memory host CLI runtime helpers |
| `plugin-sdk/memory-core-host-runtime-core` | Private-local after July 2026; Memory host core runtime helpers |
| `plugin-sdk/memory-core-host-runtime-files` | Private-local after July 2026; Memory host file/runtime helpers |
| `plugin-sdk/memory-host-core` | Deprecated compatibility facade for vendor-neutral memory host helpers. New memory plugins use injected memory capabilities and host-prepared prompts; companion plugins still use the retained facade for public-artifact discovery until a focused read seam exists. |
| `plugin-sdk/memory-host-events` | Private-local after July 2026; Vendor-neutral alias for memory host event journal helpers |
| `plugin-sdk/memory-host-markdown` | Private-local after July 2026; Shared managed-markdown helpers for memory-adjacent plugins |
| `plugin-sdk/memory-host-search` | Private-local after July 2026; Active memory runtime facade for search-manager access |
Reserved bundled-helper SDK subpaths are narrow owner-specific surfaces for
bundled plugin code. They are tracked in the SDK inventory so package
builds and aliasing stay deterministic, but they are not general plugin
authoring APIs. New reusable host contracts should use generic SDK subpaths
such as `plugin-sdk/gateway-runtime` and `plugin-sdk/ssrf-runtime`.
| Subpath | Owner and purpose |
| --- | --- |
| `plugin-sdk/codex-mcp-projection` | Private-local after July 2026; Bundled Codex plugin helper for projecting user MCP server config into Codex app-server thread config (default-only package export) |
| `plugin-sdk/codex-session-transcript-runtime` | Private-local bundled Codex plugin helper for serializing transcript-mirror writes (default-only package export) |
| `plugin-sdk/ssrf-runtime-internal` | Private-local host helper for configured loopback requests owned by bundled Ollama/browser and the exact official `@openclaw/llama-cpp-provider` package (default-only package export) |