# Skill and Plugin Publishing Architecture in OpenWork's Den Marketplace System

> Explore OpenWork's Den marketplace architecture for skill and plugin publishing. Understand the four layers enabling role-based content creation and distribution.

- Repository: [Different AI/openwork](https://github.com/different-ai/openwork)
- Tags: architecture
- Published: 2026-08-17

---

**OpenWork's Den marketplace system uses a four-layer architecture—persistence, API contracts, business logic, and client helpers—to enable role-based publishing of skills through plugins and marketplaces.**

The **Den** control-plane in [different-ai/openwork](https://github.com/different-ai/openwork) provides a complete skill and plugin publishing architecture that separates storage, contracts, and access control. This article examines how config objects (skills), plugins, and marketplaces interact through granular access grants.

---

## How the Four-Layer Architecture Works

| Layer | Responsibility | Core Source File |
|-------|----------------|------------------|
| **Persistence** | MySQL tables for config objects, plugins, marketplaces, and grants | [`ee/packages/den-db/src/schema/sharables/plugin-arch.ts`](https://github.com/different-ai/openwork/blob/main/ee/packages/den-db/src/schema/sharables/plugin-arch.ts) |
| **API Contracts** | Zod-typed REST endpoint definitions | [`ee/apps/den-api/src/routes/org/plugin-system/contracts.ts`](https://github.com/different-ai/openwork/blob/main/ee/apps/den-api/src/routes/org/plugin-system/contracts.ts) |
| **Business Logic** | Server handlers for RBAC enforcement and mutation | [`ee/apps/den-api/src/routes/org/plugin-system/store.ts`](https://github.com/different-ai/openwork/blob/main/ee/apps/den-api/src/routes/org/plugin-system/store.ts) |
| **Client Helpers** | Convenience wrappers for API invocation | [`evals/packages/behaviors/src/cloud-plugins.ts`](https://github.com/different-ai/openwork/blob/main/evals/packages/behaviors/src/cloud-plugins.ts) |

**Core entities in the publishing model:**

- **Skill**: A `config_object` with `object_type = "skill"` containing markdown body ([`SKILL.md`](https://github.com/different-ai/openwork/blob/main/SKILL.md))
- **Plugin**: Container owning one-to-many config objects via `plugin_config_object` junction table
- **Marketplace**: Container owning plugins via `marketplace_plugin` junction table
- **Access Grant**: `*_access_grant` tables controlling `viewer | editor | manager` permissions at org, team, or member scope

---

## Step-by-Step Publishing Flow

### 1. Create a Marketplace (Admin Only)

Admins initialize marketplaces as the top-level sharing boundary:

```bash
POST /v1/marketplaces
{
  "name": "Team Marketplace",
  "description": "Plugins shared within the team"
}

```

**Implementation**: `createMarketplace` in [`store.ts`](https://github.com/different-ai/openwork/blob/main/store.ts) inserts into the `marketplace` table and returns the generated `id`.

---

### 2. Create a Plugin Containing a Skill

Members bundle skills into plugins that can optionally attach to marketplaces immediately:

```bash
POST /v1/plugins
{
  "name": "My Demo Plugin",
  "description": "Demo plugin for a skill",
  "orgWide": true,
  "marketplaceId": "<marketplace-id>",
  "components": [
    {
      "type": "skill",
      "input": {
        "rawSourceText": "---\nname: demo-skill\ndescription: Demo skill\n---\nThe skill body…"
      }
    }
  ]
}

```

**Implementation chain:**
- `createPluginWithSkill` in [`cloud-plugins.ts`](https://github.com/different-ai/openwork/blob/main/cloud-plugins.ts) POSTs to `/v1/plugins`
- [`store.ts`](https://github.com/different-ai/openwork/blob/main/store.ts) → `createPlugin` creates the `plugin` row and related `config_object` via the `plugin_config_object` junction

---

### 3. Assign Existing Plugin to Marketplace

For plugins created independently, admins attach them to marketplaces:

```bash
POST /v1/marketplaces/{marketplaceId}/plugins
{
  "pluginId": "<plugin-id>"
}

```

**Implementation**: `assignPluginToMarketplace` in [`cloud-plugins.ts`](https://github.com/different-ai/openwork/blob/main/cloud-plugins.ts) invokes this endpoint; [`store.ts`](https://github.com/different-ai/openwork/blob/main/store.ts) inserts into `marketplace_plugin` with a unique (`marketplaceId`, `pluginId`) constraint.

---

### 4. Grant Marketplace Access

Admins control visibility through explicit grants:

```bash
POST /v1/marketplaces/{marketplaceId}/access
{
  "role": "viewer",
  "orgMembershipId": "<member-id>"
}

# Alternative: { "orgWide": true } for organization-wide access

```

**Implementation**: `grantMarketplaceAccess` in [`cloud-plugins.ts`](https://github.com/different-ai/openwork/blob/main/cloud-plugins.ts) creates a `marketplace_access_grant` row. [`store.ts`](https://github.com/different-ai/openwork/blob/main/store.ts) enforces role requirements via `requirePluginArchResourceRole`.

---

### 5. Resolve Visible