`url` vs `git-subdir` Source Types in `marketplace.json`: What's the Difference?
The url source type clones an entire repository at a specific commit, while git-subdir isolates a single folder from a larger repository—letting you publish plugins from monorepos without exposing unrelated code.
The marketplace.json file in the anthropics/claude-plugins-community repository controls how the Claude Marketplace fetches plugin source code. When adding your plugin, you must choose between two source types that differ fundamentally in scope: one captures a whole repository, the other extracts a specific sub-directory. Both resolve to an exact commit SHA for reproducible builds.
How the url Source Type Works
The url source type is the simpler option. It clones the entire Git repository and treats the repository root as the plugin's base directory.
Required Fields for url
| Field | Description |
|---|---|
url |
Full HTTPS Git URL to the repository |
sha |
Exact commit SHA to checkout |
Real-World Example: 0x Plugin
In .claude-plugin/marketplace.json (lines 17–20), the 0x plugin uses url because its code lives at the repository root:
"source": {
"source": "url",
"url": "https://github.com/0xProject/0x-ai.git",
"sha": "0167bbb411cc972b966127d23c23de801061fa99"
}
Use url when your plugin occupies the entire repository—this is the most common case for standalone plugins.
How the git-subdir Source Type Works
The git-subdir source type targets a specific folder inside a repository. This is essential for monorepos that contain multiple plugins, shared libraries, or unrelated code you don't want exposed as part of your plugin.
Required Fields for git-subdir
| Field | Description |
|---|---|
url |
HTTPS Git URL or short <owner>/<repo> format |
path |
Relative path inside the repo to the plugin folder |
ref |
Branch, tag, or commit reference to checkout |
sha |
Resolved exact commit SHA for immutability |
Real-World Example: 42Crunch API Security Testing
In .claude-plugin/marketplace.json (lines 57–62), this plugin extracts only the plugins/api-security-testing folder from a larger repository:
"source": {
"source": "git-subdir",
"url": "42Crunch-AI/claude-plugins",
"path": "plugins/api-security-testing",
"ref": "v1.0.1",
"sha": "30287f5e3f122a646d1ac5ca3ab96e130c52a3ad"
}
Notice the shortcut URL format: 42Crunch-AI/claude-plugins resolves to the full HTTPS URL automatically. The ref field provides readability (humans see v1.0.1), while sha guarantees the exact code that runs.
Side-by-Side Comparison
| Aspect | url |
git-subdir |
|---|---|---|
| Scope | Entire repository | Single sub-directory |
| Use case | Standalone plugin repos | Monorepos with multiple plugins |
| URL format | Full HTTPS only | Full HTTPS or <owner>/<repo> shortcut |
| Path specification | Implicit (repo root) | Explicit path field required |
| Version reference | sha only |
ref (human-readable) + sha (resolved) |
| Example repos | 0x, single-purpose plugins | 42Crunch, multi-plugin repositories |
Adding a New Plugin: Code Templates
Template for Standalone Repository (url)
{
"name": "my-awesome-plugin",
"description": "A plugin that lives at the repo root",
"source": {
"source": "url",
"url": "https://github.com/example/my-awesome-plugin.git",
"sha": "a1b2c3d4e5f67890123456789abcdef123456789"
},
"homepage": "https://github.com/example/my-awesome-plugin"
}
Template for Monorepo Sub-Directory (git-subdir)
{
"name": "my-subdir-plugin",
"description": "A plugin inside a larger monorepo",
"source": {
"source": "git-subdir",
"url": "example/monorepo",
"path": "plugins/my-subdir-plugin",
"ref": "main",
"sha": "1234567890abcdef1234567890abcdef12345678"
},
"homepage": "https://github.com/example/monorepo"
}
Key Implementation Details from Source
The .claude-plugin/marketplace.json file is the authoritative source for plugin discovery in the Claude Marketplace. Each entry's source field determines how the Marketplace fetches code:
shaimmutability: Both source types resolve to a concrete SHA. Even whengit-subdiruses areflikev1.0.1, theshafield locks the exact commit.- Path isolation: With
git-subdir, only files under the specifiedpathare exposed as the plugin; sibling directories remain inaccessible. - URL flexibility: The
git-subdirshortcut format reduces repetition for GitHub-hosted repositories.
The companion plugin.json file (located within each plugin's directory) provides per-plugin metadata, but marketplace.json controls the fetch mechanism.
Summary
url— Clone entire repo, root directory is plugin. Use for standalone repositories.git-subdir— Clone repo, isolate specific folder. Use for monorepos with multiple plugins.- Both require a resolved
shafor reproducible, immutable builds. git-subdiraddspathandreffields for sub-directory targeting and human-readable versioning.- Real implementations live in
.claude-plugin/marketplace.jsonin theanthropics/claude-plugins-communityrepository.
Frequently Asked Questions
Can I use git-subdir with a full HTTPS URL instead of the shortcut?
Yes. The url field in git-subdir accepts either full HTTPS URLs (https://github.com/owner/repo.git) or the abbreviated <owner>/<repo> format. Both resolve to the same repository.
Why does git-subdir require both ref and sha?
The ref field provides a human-readable pointer—like main or v2.1.0—that helps developers understand which version is intended. The sha field guarantees immutability by locking the exact commit hash, protecting against tag changes or branch updates.
What happens if I use url for a plugin that isn't at the repository root?
The Marketplace will treat the repository root as your plugin, potentially exposing unwanted files or failing validation if plugin.json isn't found at that level. Use git-subdir with the correct path instead.
Is there a performance difference between url and git-subdir?
Both clone the full repository internally. The git-subdir type simply restricts which files are exposed to the plugin system after checkout. Network and storage costs are identical; the difference is purely organizational convenience.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →