# Supported Source Delivery Modes for Claude Plugins: Git, HTTP, and Local Path

> Discover supported source delivery modes for Claude plugins: Git, HTTP, and local paths. Learn how to declare them in plugin.json for Claude runtime code retrieval and building.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: deep-dive
- Published: 2026-08-31

---

**Claude plugins support three source delivery modes—Git repositories, HTTP archives, and local filesystem paths—each declared in the [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json) manifest to control how the Claude runtime retrieves and builds plugin code.**

The `anthropics/claude-plugins-community` repository defines how plugins package and distribute their source code. Understanding these delivery modes is essential for plugin developers configuring how Claude clones, downloads, or reads plugin files during the build process.

## Git Repository Delivery Mode

The **Git** delivery mode points to a public or private Git repository. Claude clones the repository at a specified commit SHA, tag, or branch, then builds the plugin from the checkout.

This mode suits projects with rapid iteration cycles, version control requirements, or CI/CD pipelines that push updates to remote repositories.

```json
{
  "name": "quickdesign",
  "source": {
    "type": "git",
    "url": "https://github.com/anthropics/quickdesign-plugin.git",
    "ref": "v1.2.3"
  }
}

```

In this example from the repository's plugin manifest structure, the `ref` field accepts a tag, branch name, or commit SHA, allowing precise version pinning or tracking of latest development lines.

## HTTP Archive Delivery Mode

The **HTTP** delivery mode retrieves a compressed archive (`.zip` or `.tar.gz`) from a direct URL. Claude downloads the file, extracts the contents, and uses the extracted directory as the plugin source.

This approach works best for stable, immutable releases hosted on CDNs or static file servers where a single packaged artifact represents a complete version.

```json
{
  "name": "instacart",
  "source": {
    "type": "http",
    "url": "https://example.com/plugins/instacart-2.0.tar.gz",
    "checksum": "sha256:abcdef123456..."
  }
}

```

The optional `checksum` field enables integrity verification using SHA-256 hashes, ensuring the downloaded archive matches the expected cryptographic signature before extraction.

## Local Path Delivery Mode

The **Local** delivery mode references source files residing within the same repository as the plugin manifest. Claude reads files directly from the filesystem relative to the plugin's root directory.

Developers use this mode for tightly-coupled plugins maintained within the main Claude Plugins Community repository or for rapid prototyping without external dependencies.

```json
{
  "name": "tres-finance",
  "source": {
    "type": "local",
    "path": "./tres-finance-plugin"
  }
}

```

This configuration in [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json) uses a relative path to locate source code immediately adjacent to the manifest file, eliminating network retrieval steps during the build process.

## Configuration Files and Validation

The Claude runtime validates source delivery configurations through specific manifest files. Each plugin's **[`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json)** (or **[`manifest.json`](https://github.com/anthropics/claude-plugins-community/blob/main/manifest.json)**) declares the `source` object containing `type` and location parameters.

The central **[`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json)** aggregates metadata for all plugins in the `anthropics/claude-plugins-community` repository, indexing each plugin's selected delivery mode for the marketplace interface.

When processing a plugin, the Claude runtime parses the `source.type` field from [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json), validates reachability of the Git URL, HTTP endpoint, or local path, then executes the appropriate retrieval mechanism before proceeding with build and execution steps.

## Summary

- **Git mode** clones remote repositories at specific refs, ideal for version-controlled development workflows and CI pipelines.
- **HTTP mode** downloads archived releases from URLs, supporting immutable distribution via CDNs with optional SHA-256 checksum validation.
- **Local mode** reads source from relative filesystem paths, optimized for plugins bundled within the community repository itself.
- All modes require configuration in the **[`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json)** manifest file under the `source` field with appropriate type-specific parameters.
- The runtime validates source reachability before executing build steps, ensuring reliable plugin initialization.

## Frequently Asked Questions

### How do I specify a specific commit or tag when using Git mode for Claude plugins?

Include the `ref` field in your [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json) source configuration. This field accepts commit SHAs, Git tags, or branch names. For example, `"ref": "v1.2.3"` pins the plugin to that specific tag, while `"ref": "main"` tracks the latest development branch.

### Can Claude plugins use private Git repositories as a source delivery mode?

Yes, the Git delivery mode supports private repositories. Claude handles authentication using configured credentials or deploy keys when cloning private repos, though the specific authentication mechanism depends on your Claude deployment's SSH or HTTPS credential configuration.

### What integrity checks are available for HTTP archive delivery in Claude plugins?

The HTTP mode supports optional SHA-256 checksum validation through the `checksum` field in [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json). Format the value as `"sha256:YOUR_HASH_HERE"`. Claude verifies the downloaded archive against this hash before extraction, preventing execution of corrupted or tampered packages.

### Where does the Claude runtime look for source configuration when loading plugins?

The runtime reads the `source` object from each plugin's **[`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json)** file. For the broader marketplace index, **[`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json)** aggregates these configurations across all plugins in the `anthropics/claude-plugins-community` repository.