How to Configure Dify to Accept Non-Marketplace Plugins Using FORCE_VERIFYING_SIGNATURE
Set the environment variable FORCE_VERIFYING_SIGNATURE to false in your Dify .env file and restart the services to enable installation of plugins from outside the official Dify Marketplace.
The junjiem/dify-plugin-repackaging repository provides utilities for repackaging Dify plugins, but the platform blocks unsigned plugins by default through the FORCE_VERIFYING_SIGNATURE environment variable. When you need to install custom plugins that are not listed in the Dify Marketplace, you must disable mandatory signature verification to allow the platform to accept your .difypkg files.
Understanding FORCE_VERIFYING_SIGNATURE in Dify
Dify employs signature verification to ensure plugin integrity and security. When FORCE_VERIFYING_SIGNATURE is set to true (the default), the backend validates the signature field embedded in every .difypkg archive against the Dify Marketplace's public key. If the signature cannot be verified, the platform rejects the installation request.
Setting the variable to false bypasses this verification entirely. As documented in the repository's README.md at lines 118-119: "Change FORCE_VERIFYING_SIGNATURE to false, the Dify platform will allow the installation of all plugins that are not listed in the Dify Marketplace."
Step-by-Step Configuration Guide
Locate the Dify Environment File
Find the .env file in the root directory of your Dify deployment. For Docker-based installations, this is typically located at ./dify/.env or ./.env in your project root.
Modify the FORCE_VERIFYING_SIGNATURE Variable
Update the environment variable using a text editor or command-line tools. If the variable exists, change its value to false. If it does not exist, append it to the file:
# Update existing variable
sed -i 's/^FORCE_VERIFYING_SIGNATURE=.*/FORCE_VERIFYING_SIGNATURE=false/' .env
# Or append if missing
echo 'FORCE_VERIFYING_SIGNATURE=false' >> .env
Restart Dify Services
The environment variable is read once at server startup. You must restart the services for the configuration change to take effect:
# Docker Compose deployment
docker compose down && docker compose up -d
# Or for systemd-managed services
systemctl restart dify
Install Non-Marketplace Plugins
Once configured, you can install custom plugins using the plugin_repackaging.sh script from the junjiem/dify-plugin-repackaging repository to create .difypkg files.
Via the UI: Navigate to Plugin Management → Local Package File, select your generated .difypkg file, and click Install.
Via API: POST to /api/v1/plugins/upload with your package file as the payload. The server will accept the plugin because signature verification is disabled.
Technical Implementation Details
The verification logic in Dify's backend uses Python's os.getenv to check the environment variable before validating plugin signatures. The implementation follows this pattern:
import os
from dify.plugins import verify_signature, load_plugin
FORCE_VERIFYING_SIGNATURE = os.getenv("FORCE_VERIFYING_SIGNATURE", "true").lower() == "true"
def install_plugin(pkg_path: str):
if FORCE_VERIFYING_SIGNATURE:
if not verify_signature(pkg_path):
raise PermissionError("Plugin signature invalid.")
load_plugin(pkg_path)
Key files in the junjiem/dify-plugin-repackaging repository that support this workflow:
README.md(lines 118-119): Documents theFORCE_VERIFYING_SIGNATUREconfiguration requirementplugin_repackaging.sh: Builds.difypkgarchives that can be installed after disabling verificationDockerfile: Provides a containerized environment for running the repackaging script
Summary
FORCE_VERIFYING_SIGNATUREcontrols whether Dify enforces marketplace signature verification on plugin installations- Set the variable to
falsein your.envfile to allow non-marketplace plugins - You must restart Dify services after modifying the environment variable for changes to take effect
- The
junjiem/dify-plugin-repackagingrepository providesplugin_repackaging.shto create installable.difypkgfiles for use with this configuration
Frequently Asked Questions
What is the default value of FORCE_VERIFYING_SIGNATURE?
The default value is true. When set to true, Dify strictly enforces signature verification against the Dify Marketplace public key, rejecting any plugin that lacks a valid signature or originates from outside the official marketplace.
Do I need to restart Dify after changing the environment variable?
Yes. Dify reads the FORCE_VERIFYING_SIGNATURE variable once at server startup. You must restart your Docker containers or systemd service for the configuration change to take effect. Simply saving the .env file does not update the running instance.
Is it safe to disable signature verification?
Disabling signature verification (FORCE_VERIFYING_SIGNATURE=false) removes a security safeguard that ensures plugin integrity. Only disable this setting in trusted environments or when installing plugins from verified sources, such as those created using the junjiem/dify-plugin-repackaging tools or reputable GitHub repositories.
Where is the FORCE_VERIFYING_SIGNATURE setting documented?
The setting is explicitly documented in the junjiem/dify-plugin-repackaging repository's README.md file at lines 118-119, which states: "Change FORCE_VERIFYING_SIGNATURE to false, the Dify platform will allow the installation of all plugins that are not listed in the Dify Marketplace."
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →