-
-
Notifications
You must be signed in to change notification settings - Fork 2
cmd plugin
Install, remove, update, and manage ɳSelf plugins.
nself plugin <subcommand> [flags]
nself plugin manages the ɳSelf plugin ecosystem. Plugins extend the CLI and your backend stack with new capabilities. Free plugins (MIT licensed) install without a key. Pro plugins require a valid membership license key, set one with nself license set.
When you install a plugin, ɳSelf checks your license tier against the plugin's requirements, downloads the plugin binary and Docker image, registers the plugin with the stack, and prepares database migrations. Run nself build and nself restart after installing plugins to include them in the generated docker-compose.yml.
Unknown subcommands are proxied to the matching plugin binary: nself plugin ai <action> calls nself-ai <action>. This allows installed plugins to expose their own subcommands through the ɳSelf CLI namespace.
Plugins carry a status field in the registry. The list subcommand shows badges for non-stable plugins:
ai [installed]
browser [beta]
nfamily [planned]
Install behavior by status:
- stable, installs without warnings (default for most plugins)
- experimental, prints a warning to stderr, then installs
- beta, prints a warning to stderr, then installs
- deprecated, prints a deprecation warning with EOL date and migration guide, then installs
-
eol, install is blocked; use
--allow-eolto override (not recommended) - planned, install is rejected with a "coming soon" message and a link to the release timeline
EOL plugins are hidden from nself plugin list by default. Use --show-eol to include them.
See Plugin-Status-Badges for the full reference.
After a successful nself plugin install, the CLI sends a single fire-and-forget event to plugins.nself.org/plugins/:name/install-event. This increments the public download counter shown in the plugin marketplace.
The event body contains one field: instanceId, which is an opaque SHA-256 hash of a machine-local identifier. No hostname, IP address, username, or project name is transmitted. The event is deduplicated per (instance, plugin) per ISO week, so reinstalling the same plugin in the same week does not double-count. If the network is unavailable, the event is silently dropped with no retry.
To opt out, set NSELF_DISABLE_TELEMETRY=1 in your environment or .env.local.
A small number of plugins (cron, notify) ship as a genuine free/pro pair: the same product, listed twice in the registry under one slug. nself plugin install cron resolves which entry to install like this:
- If your license entitles the bundle the pro entry belongs to (checked via the same bundle-entitlement path
nself bundle installuses), you get pro. - Otherwise, or with no license key configured, you get free. Free never requires a key.
- Pass
--tier freeor--tier proto force a side.--tier freealways succeeds.--tier prostill runs the entitlement check — it is a way to ask for pro, not a way to bypass licensing — and fails with a clear "buy the bundle" error if you're not entitled.
Run nself plugin list --available to see every tier of every such slug side by side, with the tier a plain nself plugin install <name> would resolve to today marked in the Default column.
Any other slug collision — two unrelated registry entries that happen to share a name, not a declared tier pair — is refused outright with an error naming both entries. The CLI never silently installs "whichever one came first" for an ambiguous slug.
nself plugin install <name> resolves against the official plugins.nself.org registry: license-checked for pro tiers, and its tarball is Ed25519-signature-verified against a registry-pinned author key.
nself plugin install <https-url> installs directly from an arbitrary URL instead, for plugins that aren't in the registry. This path:
- Never contacts the official registry — no license check, no EOL/deprecation lifecycle handling, no install telemetry.
- Is not signature-verified. There is no registry-pinned key to check an arbitrary URL's tarball against.
- Verifies a checksum only when you pass
--checksum <sha256>yourself (obtained out-of-band, e.g. from the plugin's README or release notes) — the same trust model aspip install --hash=or a Homebrew formula. Without--checksum, the download's integrity is unverified and the CLI says so. - Always prints a warning naming the source host and asks for interactive confirmation before downloading anything, unless you pass
--yes(for CI/non-interactive use). - Requires
https://(plainhttp://is rejected, except againstlocalhost/127.0.0.1for local development).
nself plugin outdated and nself plugin list --detailed skip plugins that came from a third-party URL when comparing against the registry — there's nothing registered to compare them to.
nself plugin list --detailed prints an Updated column per plugin, sourced from the registry entry's (or local plugin.json's) updated_at field when present. As of the current plugins.nself.org registry, no plugin carries a per-plugin updated_at — only a registry-wide snapshot timestamp, which --detailed prints as a Registry snapshot: <timestamp> header line instead of a per-row value. The column is plumbing ready for the day the registry starts sending a per-plugin value; it never fabricates one.
nself plugin outdated compares every installed plugin's version against the registry and lists the ones behind, with --json for scripting. It exits 0 when everything is current and 1 when at least one plugin is outdated, so it composes in CI.
With no plugins installed it answers from local state and never contacts the registry, so it stays fast and works offline. The registry is only consulted once there is something to compare.
nself plugin info <name> lists the permissions a plugin declares, and every
one of them is checked against a fixed allowlist before the plugin installs. An
unrecognised permission blocks the install; the check is fail-closed on purpose.
Manifests declare permissions in one of two forms. The canonical form is a flat list of the allowlist's own vocabulary:
"permissions": ["db:read", "network:internet", "fs:write:uploads"]Most published plugins use a more specific descriptive form instead, naming the hosts, paths and operations rather than the categories:
"permissions": {
"database": ["create", "read"],
"network": ["api.stripe.com"],
"filesystem": ["logs"]
}Both are enforced. The descriptive form is reduced to the canonical vocabulary
before validation, and the reduction always widens: a plugin naming one host
is enforced as general internet access, and any database verb that is not
plainly a read is enforced as a write. So nself plugin info prints what a
declaration is enforced as, not only what it says:
Permissions:
database:create
network:api.stripe.com
Enforced as:
db:write
network:internet
The gap between the two lines is the point. A declaration that looks narrow is enforced broadly, because under-stating a permission is the one direction a fail-closed check must never take.
| Flag | Default | Description |
|---|---|---|
--help, -h
|
— | Show help |
| Name | Description |
|---|---|
audit-tables |
Audit np_* table row counts and multi-tenant isolation compliance |
compat-check |
Check installed plugins against the current CLI version |
count |
Show the authoritative plugin counts (free, pro, advertised) |
debug |
Attach a dlv debugger to a running plugin process |
dev |
Start a plugin in development mode with hot-reload |
disable |
Disable a plugin (excluded from compose on next build) |
enable |
Re-enable a previously disabled plugin |
info |
Show detailed plugin information |
init |
Scaffold a new plugin project |
install |
Install one or more plugins (license check for pro); a plugin arg may be a name or an https:// URL |
inventory |
List installed plugins with version, tier, and status |
link |
Register a local plugin directory as a shadow override |
list |
List available and installed plugins |
logs |
Tail logs from a plugin container |
marketplace |
Browse the ɳSelf plugin marketplace |
new |
Scaffold a new plugin project (deprecated: use 'init') |
outdated |
List installed plugins with a newer version available |
refresh |
Force refresh the registry cache |
remove |
Remove a plugin |
search |
Search plugins by name, description, or tag |
start |
Start a plugin service |
status |
Show plugin status |
stop |
Stop a plugin service |
submit |
Validate a plugin for submission to the registry |
test |
Run a plugin's test suite (unit + smoke install/uninstall) |
unlink |
Remove a local plugin shadow, restoring the registry version |
update |
Update a specific plugin or all plugins |
updates |
Check for available plugin updates |
# List all available plugins
nself plugin list
# List only installed plugins
nself plugin list --installed
# Filter by category
nself plugin list --category ai
# Install a free plugin
nself plugin install notify
# Install multiple plugins in one command
nself plugin install ai claw mux
# Install a pro plugin (uses saved license key)
nself plugin install ai
# Install a pro plugin with an inline key
nself plugin install livekit --key nself_pro_xxxxx...
# Install a specific version
nself plugin install recording --version 1.2.0
# See both tiers of a slug served twice (e.g. cron: free + pro), with the
# resolved default marked
nself plugin list --available
# Force the free entry of a free/pro slug, ignoring entitlement
nself plugin install cron --tier free
# Ask for the pro entry explicitly (still requires an entitled license)
nself plugin install cron --tier pro
# Remove a plugin
nself plugin remove ai
# Remove a plugin but keep its database data
nself plugin remove livekit --keep-data
# Force remove (ignores dependents)
nself plugin remove recording --force
# Update a specific plugin
nself plugin update ai
# Update all plugins
nself plugin update
# Check for available updates without installing
nself plugin updates
# List installed plugins that are behind the registry version (exits 1 if any are)
nself plugin outdated
# Same, as JSON for scripting
nself plugin outdated --json
# Show freshness (Updated column + registry snapshot timestamp)
nself plugin list --detailed
# Install a third-party plugin directly from a URL (prompts for confirmation)
nself plugin install https://example.com/releases/my-plugin-1.0.0.tar.gz
# Same, verifying against a checksum you obtained from the source yourself
nself plugin install https://example.com/releases/my-plugin-1.0.0.tar.gz --checksum <sha256>
# Same, non-interactively for CI (still prints the third-party warning)
nself plugin install https://example.com/releases/my-plugin-1.0.0.tar.gz --yes
# Show installed plugins with version and tier
nself plugin inventory
# Refresh registry cache
nself plugin refresh
# Start/stop a plugin service
nself plugin start ai
nself plugin stop ai
# Show plugin status
nself plugin status
nself plugin status ai --detailed
# Check compatibility after a CLI upgrade
nself plugin compat-check
# List all plugins including EOL ones
nself plugin list --show-eol
# Install an EOL plugin (not recommended — use only when a replacement is unavailable)
nself plugin install old-plugin --allow-eol- cmd-plugin-compat-check — compatibility check reference
- cmd-plugin-dev — plugin author dev mode
- cmd-plugin-link — link a local plugin directory into the stack
- cmd-plugin-unlink — remove a plugin from the linked set
- cmd-plugin-test — run unit and smoke tests
- cmd-plugin-debug — attach a Delve debugger
- cmd-plugin-logs — tail plugin container logs
- cmd-plugin-marketplace — browse the marketplace
- Plugin-Status-Badges — lifecycle status reference
- Plugin-Licensing — license tiers and key format
ɳSelf CLI v1.0.9. MIT licensed. Docs CC BY 4.0.
GitHub · Issues · Discussions · nself.org · nself.org/docs
Getting Started
Commands
- Commands, Overview
- Lifecycle: cmd-init · cmd-build · cmd-start · cmd-stop · cmd-restart · cmd-dev
- Monitoring: cmd-status · cmd-logs · cmd-health · cmd-urls · cmd-doctor · cmd-monitor · cmd-alerts · cmd-sentry · cmd-watchdog
- Data: cmd-db · cmd-backup · cmd-dr · cmd-queue · cmd-webhooks
- Config: cmd-config · cmd-service · cmd-env · cmd-promote
- Networking: cmd-ssl · cmd-trust · cmd-dns-setup
- Security: cmd-access · cmd-security · cmd-secrets
- Tenancy: cmd-tenant · cmd-billing
- Plugins: cmd-plugin · cmd-license · cmd-dogfood (extracted, CLI-R11) · cmd-k8s (extracted, CLI-R11) · cmd-encryption (extracted, CLI-R11) · cmd-waf (extracted, CLI-R11) · cmd-federation (extracted, CLI-R11) · cmd-mail (extracted, CLI-R11) · cmd-dlq (extracted, CLI-R11)
- AI: cmd-ai · cmd-claw · cmd-model
- Templates: cmd-template
- Utilities: cmd-exec · cmd-clean · cmd-reset · cmd-update · cmd-upgrade · cmd-version · cmd-admin · cmd-migrate · cmd-migrate-firebase · cmd-migrate-supabase · cmd-completion
Features
- Features, Overview
- Feature-Auth
- Feature-Storage
- Feature-Search
- Feature-Functions
- Feature-Email
- Feature-Monitoring
- Feature-Plugins
- Feature-nClaw, AI Assistant
- Feature-nChat, Messaging
- Feature-nTV, Media Player
- Feature-nFamily, Family Social
- Feature-nCloud, Managed Hosting
- Feature-Memory-Rooms, Knowledge Organization
- Feature-Agent-Dashboard, Agent Metrics
- Feature-Image-Generation, AI Image Generation
Configuration
- Configuration, Overview
- Config-Env-Vars
- Config-Postgres
- Config-Hasura
- Config-Auth
- Config-Nginx
- Config-Optional-Services
- Config-Custom-Services
- Config-System
Plugins (87 + 10 monitoring)
Free (25)
- plugin-backup
- plugin-content-acquisition
- plugin-content-progress
- plugin-cron
- plugin-donorbox
- plugin-feature-flags
- plugin-github
- plugin-github-runner
- plugin-invitations
- plugin-jobs
- plugin-link-preview
- plugin-mdns
- plugin-mlflow
- plugin-monitoring
- plugin-notifications
- plugin-notify
- plugin-paypal
- plugin-search
- plugin-shopify
- plugin-stripe
- plugin-subtitle-manager
- plugin-tokens
- plugin-torrent-manager
- plugin-vpn
- plugin-webhooks
Pro (62)
- plugin-access-controls
- plugin-activity-feed
- plugin-admin-api
- plugin-nself-ai-gateway
- plugin-nself-ai-mcp
- plugin-nself-ai-mcp
- plugin-analytics
- plugin-auth
- plugin-backup-pro
- plugin-bots
- plugin-browser
- plugin-calendar
- plugin-cdn
- plugin-chat
- plugin-claw
- plugin-claw-budget
- plugin-claw-news
- plugin-claw-web
- plugin-cloudflare
- plugin-cms
- plugin-compliance
- plugin-cron-pro
- plugin-ddns
- plugin-devices
- plugin-documents
- plugin-donorbox-pro
- plugin-entitlements
- plugin-epg
- plugin-file-processing
- plugin-game-metadata
- plugin-geocoding
- plugin-geolocation
- plugin-google
- plugin-home
- plugin-idme
- plugin-knowledge-base
- plugin-linkedin
- plugin-livekit
- plugin-media-processing
- plugin-meetings
- plugin-moderation
- plugin-mux
- plugin-notify-pro
- plugin-object-storage
- plugin-observability
- plugin-paypal-pro
- plugin-photos
- plugin-podcast
- plugin-post
- plugin-realtime
- plugin-recording
- plugin-retro-gaming
- plugin-rom-discovery
- plugin-shopify-pro
- plugin-social
- plugin-sports
- plugin-stream-gateway
- plugin-streaming
- plugin-stripe-pro
- plugin-support
- plugin-tmdb
- plugin-voice
- plugin-web3
- plugin-workflows
Planned (26)
plugin-auditplugin-blogplugin-checkoutplugin-commerceplugin-drmplugin-exportplugin-flowplugin-importplugin-ldapplugin-mailgunplugin-mediaplugin-oauth-providersplugin-pagesplugin-postmarkplugin-rate-limitplugin-reportsplugin-samlplugin-schedulerplugin-sendgridplugin-ssoplugin-subscriptionplugin-thumbplugin-transcoderplugin-twilioplugin-wafplugin-watermark
Guides
- Guide-Production-Deployment
- Guide-SSL-Setup
- Guide-Multi-Tenancy
- Guide-Security-Hardening
- Guide-Monitoring-Setup
- Guide-Backup-Restore
- Guide-Custom-Services
- Guide-Migration-from-v1
Architecture
Reference
- API-Reference
- error-codes, Error Codes
Licensing
Security
Brand
Operations
- operations/release-cascade, Release Cascade
- operations/self-healing, Self-Healing Schema
- operations/redis-tuning, Redis Pool Tuning
- operations/meilisearch-warmup, MeiliSearch Warm-Up
- operations/jwt-rotation, JWT Key Rotation
- operations/windows-wsl2-setup, Windows / WSL2 Setup
- operations/gemini-oauth-reauth, Gemini OAuth Reauth
Contributing
Admin
- USER-ACTION-QUEUE, Pending Admin Actions
All commands (52)
- A: cmd-access · cmd-account · cmd-admin
- B: cmd-backup · cmd-build · cmd-bundle
- C: cmd-ci · cmd-clean · cmd-completion · cmd-config
- D: cmd-db · cmd-deploy · cmd-dev · cmd-doctor
- E: cmd-env · cmd-exec
- F: cmd-functions
- G: cmd-generate
- H: cmd-health · cmd-help-topics
- I: cmd-init · cmd-install
- L: cmd-license · cmd-login · cmd-logout · cmd-logs
- M: cmd-man · cmd-mcp · cmd-migrate
- O: cmd-oauth · cmd-ops
- P: cmd-plugin · cmd-promote
- R: cmd-remove · cmd-reset · cmd-restart · cmd-runner
- S: cmd-secrets · cmd-security · cmd-self-heal · cmd-server · cmd-service · cmd-start · cmd-status · cmd-stop
- T: cmd-telemetry · cmd-template · cmd-trust
- U: cmd-update · cmd-urls
- V: cmd-verify-sbom · cmd-version