How to Restrict Plugins to Specific Codex Products Using the Marketplace

To restrict plugins to specific Codex products, add a products array to the plugin's policy object in the .agents/plugins/marketplace.json manifest file.

The openai/plugins repository uses a centralized marketplace manifest to control plugin availability across different Codex product variants. By configuring the products field in the marketplace configuration, you can whitelist exactly which Codex deployments are permitted to load and execute specific plugins.

How the Marketplace Manifest Controls Product Access

The Codex runtime parses .agents/plugins/marketplace.json during initialization to determine which plugins are available for the current session. Each plugin entry contains a policy object that governs installation, authentication, and product restrictions.

When the runtime loads the marketplace, it evaluates the optional products array inside each plugin's policy. If this array is present, the runtime checks whether the current product identifier (e.g., CODEX) is included in the list. Plugins without a products field remain available to all Codex products, while plugins with the field are filtered out unless the current product matches one of the specified identifiers.

This mechanism prevents unauthorized AI agents from accessing sensitive or product-specific functionality, ensuring that plugins only load in the environments they were designed for.

Step-by-Step: Adding Product Restrictions

Follow these steps to restrict a plugin to specific Codex products:

  1. Open the marketplace manifest at .agents/plugins/marketplace.json.
  2. Locate the plugin entry you want to restrict (e.g., game-studio or superpowers).
  3. Inside the "policy" object, add a "products" array containing the allowed product identifiers as strings.
  4. Save the file. The restriction takes effect the next time the Codex product loads the marketplace configuration.

If you need to support multiple products, simply add additional identifiers to the array (e.g., ["CODEX", "CODAI"]).

Code Example: Restricting Plugins to CODEX

The following JSON snippet from the marketplace manifest (around lines 172–189) demonstrates how to restrict the game-studio and superpowers plugins to the CODEX product only:

{
  "name": "game-studio",
  "source": {
    "source": "local",
    "path": "./plugins/game-studio"
  },
  "policy": {
    "installation": "AVAILABLE",
    "authentication": "ON_INSTALL",
    "products": [
      "CODEX"
    ]
  },
  "category": "Developer Tools"
},
{
  "name": "superpowers",
  "source": {
    "source": "local",
    "path": "./plugins/superpowers"
  },
  "policy": {
    "installation": "AVAILABLE",
    "authentication": "ON_INSTALL",
    "products": [
      "CODEX"
    ]
  },
  "category": "Developer Tools"
}

In this configuration, both plugins specify "products": ["CODEX"], meaning they will only be available when the Codex runtime identifies itself with the CODEX product identifier. Attempting to load these plugins in a different product context (such as a hypothetical CODAI deployment) will cause the runtime to exclude them from the session.

Key Files and Their Roles

Understanding the relationship between these files helps you manage product restrictions effectively:

  • .agents/plugins/marketplace.json: The central manifest that lists all plugins and their policies. This file contains the products restriction array that controls which Codex products can access each plugin.

  • plugins/<plugin>/.codex-plugin/plugin.json: The individual plugin descriptor that defines the plugin's local configuration. The marketplace entry overrides or supplements this file's policy settings, making the marketplace the authoritative source for product restrictions.

  • .agents/skills/plugin-creator/scripts/create_basic_plugin.py: A helper script that can generate or update marketplace entries. When creating new plugins, this script can automatically populate the products field if you supply the target product identifiers during generation.

Summary

  • Add a products array inside the policy object in .agents/plugins/marketplace.json to whitelist specific Codex products.
  • Plugins without a products field are available to all Codex products by default.
  • The runtime filters plugins at startup based on the current product identifier.
  • Changes to the marketplace manifest require a reload of the Codex product to take effect.

Frequently Asked Questions

What happens if I don't specify a products array?

If you omit the products field from a plugin's policy object, the plugin becomes available to all Codex products. The runtime treats the absence of this field as universal availability, loading the plugin regardless of which product variant is running.

Can I restrict a plugin to multiple products?

Yes. The products field accepts an array of strings, allowing you to whitelist multiple product identifiers. For example, "products": ["CODEX", "CODAI", "CODEX_ENTERPRISE"] permits the plugin to load in any of those three product contexts while blocking it from others.

Where is the product identifier defined?

The product identifier is configured in the Codex runtime environment itself, not in the plugin repository. The runtime passes its product identifier (such as CODEX) when initializing the marketplace loader, which then compares this value against the products arrays in marketplace.json.

Do changes to the marketplace take effect immediately?

No. The Codex runtime parses .agents/plugins/marketplace.json during startup or initialization. You must restart or reload the Codex product for changes to the products restrictions to apply to new sessions.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →