Skip to main content
Omazy Engineering

Omazy Engineering · Plugins Marketplace

How Omazy plugs into the rest of the world.

A plain-English tour of the marketplace that lets vendors extend the Omazy agent — vendor-hosted, MCP-compatible, with Stripe Connect billing baked in.

RFC 1900 · marketplace MVP // Shopify ships first

Section 01 · history

A short history of platform extensions.

From WordPress folders to MCP endpoints. Each step solved a real distribution problem; the agent era starts here.

  1. 2003

    the original ecosystem

    WordPress plugins

    A plugin folder + a stable hook system. Tens of thousands of contributors. The blueprint for every marketplace since.

  2. 2008

    curated mobile

    Apple App Store

    Submit, review, ship. Apple takes a cut. Set the standard for vendor-curated marketplaces.

  3. 2009

    commerce extensions

    Shopify App Store

    Vendor-hosted apps that read shop data through APIs. Revenue share. Today: ~10,000 listings.

  4. 2012

    no-code glue

    Zapier

    Triggers + actions across thousands of SaaS apps. Operator-friendly, but the model assumes humans pre-author the recipe.

  5. 2014

    message + slash commands

    Slack apps

    Vendor-hosted bots that respond to events. OAuth-scoped, Slack signs every payload. The shape we borrow most heavily.

  6. 2014

    platform monetisation

    Stripe Connect

    A platform-of-platforms layer. Onboard vendors, run charges, split payouts, handle KYC. The financial backbone of every modern marketplace.

  7. 2022

    LLM tool calls

    LangChain tools

    The first wave of "give the model a tool." Code-first, no marketplace, no review queue.

  8. 2024

    open tool protocol

    MCP (Anthropic)

    Model Context Protocol — a standard for "agent calls vendor tool." Vendor-neutral. The wire shape Omazy adopts.

  9. 2026

    agent-native marketplace

    Omazy Plugins

    Omazy Plugins evolved from industry growth and best practices in building cross-platform integration plugins that support vendor-hosted MCP endpoints, ACP contracts, Stripe Connect billing, review queue, and in-app install. The first listing (Shopify) validates the platform.

Section 02 · the closest analog

How Slack apps work.

The shape we borrow most heavily — vendor-hosted, OAuth-scoped, signed payloads. We adapt it for the agent era.

customer workspace
/install
platform Slack signs · scopes · audits
signed payload
vendor Acme bot vendor-hosted runtime
OAuth (vendor → API)
downstream 3rd-party API

The customer authorises the vendor inside Slack; Slack signs every payload to the vendor's runtime; the vendor handles its own downstream OAuth. Omazy plugins follow the same pattern.

What Slack got right.

  • + Vendor-hosted: vendor owns the runtime, the platform owns the contract.
  • + OAuth-scoped: the customer grants specific permissions, never blanket access.
  • + Signed payloads: every request is verifiable, replay attacks mitigated.
  • + Curated marketplace: review queue keeps the catalogue trustworthy.

Where Omazy adapts the model.

  • → Slack apps fundamentally respond to events. Omazy plugins also expose tools the agent can choose to call.
  • → Slack monetisation depends on vendor-side billing. Omazy integrates Stripe Connect natively — one checkout, one invoice.
  • → No conversational reasoning layer — Slack apps are reactive. Omazy plugins are agentic-aware: the harness picks them when relevant.
POSITIONING RFC 1900
  1. OWNERSHIP

    Plugins are vendor-hosted, not Omazy-hosted. Same model as Slack apps and Zapier integrations: the vendor exposes an MCP-compliant HTTPS endpoint, Omazy forwards verified tool calls, vendor returns results.

  2. TRUST

    We own the platform; vendors own their runtime, their downstream OAuth (e.g. with Shopify), and their uptime. Omazy never holds vendor-vendor credentials.

  3. DOGFOOD

    The Omazy-built Shopify plugin ships as the first listing to validate the platform before any external vendor is onboarded.

— RFC 1900 § TL;DR

Section 03 · the capability layer

Every plugin is a new superpower for the agent.

Plugins extend the harness in five distinct ways. Each one is a category, not a single feature.

01

Tools the agent can call

The agent picks the right tool when intent matches. Operators don't script it — the LLM reasons over the tool registry.

  • shopify.search_products
  • stripe.refund_charge
  • zendesk.create_ticket
02

Background sync

Plugins keep workspace data fresh without operator action. Asynq runs the cron; vendor implements the work.

  • catalog reconcile · 6h cron
  • customer list pull
  • inventory snapshot
03

Inbound webhooks

External systems push events to Omazy. Plugins translate them into harness triggers — automations and chats react in real time.

  • order.placed
  • subscription.updated
  • ticket.escalated
04

New data, new insight

Plugins surface domain-specific entities directly in workspace UIs. Operators see the data; agents reference it in context.

  • per-customer purchase history
  • live shipment tracking
  • support ticket sentiment
05

A revenue stream for vendors

Vendors monetise through five billing models. Customers pay once, on Omazy's invoice, with fees split via Stripe Connect.

  • flat · per-use · tiered · freemium
  • Stripe Connect payouts
  • platform fee 20%

Each plugin can ship one, several, or all five. The agent surfaces them through the same harness loop — from the customer's perspective, there's one assistant, calling whichever tools fit the moment.

Section 04 · why this matters

What every audience gets from the marketplace.

A two-sided ecosystem only works if both sides are simpler — and the platform stays trustworthy.

01

Customers extend on click

Browse the marketplace, click Install, authorise. The vendor handles their own OAuth. Three minutes from intent to first agent answer.

02

Vendors keep the platform

No data forwarded through Omazy's code. Vendors own their downstream credentials, their runtime, and their data — Omazy handles the contract and the money.

03

Billing is one invoice

Customers see one charge per period — no separate vendor logins, no scattered receipts. Stripe Connect splits the revenue automatically.

04

Trust is the product

Every plugin signs every reply. Tools outside the manifest are rejected at the gateway. A kill switch can pause any listing in a single click.

Section 05 · vocabulary

A short legend.

Twelve terms that show up across the marketplace docs. One line each.

Vendor

The legal entity behind a plugin. Has a Stripe Connect account, can publish multiple listings.

Listing

A published plugin with a unique slug. Has versions, pricing, an MCP endpoint.

Version

A semver-tagged snapshot. Each one declares its tools, scopes, and pricing.

Install

A workspace's installation of a listing version. Carries an install_id shared with the vendor.

Subscription

The billing relationship for an install. Backed by a Stripe subscription.

Usage event

One metered occurrence — a tool call, sync run, or webhook delivery.

Payout

A monthly transfer from Omazy's Stripe platform account to the vendor, net of platform fee.

MCP gateway

The middleware that signs requests, rate-limits, records usage, and forwards to the vendor.

Manifest

The version-pinned source of truth — declared tools, scopes, MCP URL. Tools outside it are rejected.

Scope

A symbolic capability the listing requests, e.g. shopify:read_products. Reviewed at submission.

Stripe Connect

The payments substrate. Omazy = platform, vendors = Express connected accounts.

Tool call

The unit of work — agent → MCP gateway → vendor → response → agent. Sub-2-second p95.

Section 06 · architecture

A tool call, end to end.

The agent picks a tool. The MCP gateway signs and forwards. The vendor responds. Every hop is auditable.

customer workspace Omazy Agent picks a tool from the registry
MIDDLEWARE · MCP GATEWAY Sign · Rate-limit · Meter · Audit
RS256 JWT· per-install rate limit· circuit breaker· usage event
VENDOR-HOSTED RUNTIME https://plugin.acme.com/mcp verifies signature · resolves install_id · calls downstream
Shopify commerce
Stripe payments
Zendesk helpdesk
Slack messaging
Custom vendor SaaS

The same pipe carries every plugin call. Vendor swaps in and out behind the gateway; the agent's experience never changes.

Section 07 · onboarding

From visitor to active vendor.

Six states, two gates. Stripe Connect Express handles the heavy lifting.

  1. 01

    visitor

    Nothing on Omazy yet.

  2. 02

    signed_up

    Email verified. Can create draft listings.

  3. 03

    kyc_pending

    Stripe Connect onboarding in progress.

  4. 04

    kyc_approved

    Cleared to publish. Can submit listings for review.

  5. 05

    active

    Listings live in the marketplace, payouts running.

  6. 06

    suspended

    Policy violation or compliance hold. Listings paused.

Section 08 · billing

Five ways to charge for a plugin.

Vendors pick the model that fits their product. Stripe Connect handles the mechanics — invoices, payouts, taxes.

no charge

Free

Customer pays nothing. Vendors absorb their own infra cost.

"Slack notifier" plugin

fixed price

Flat monthly

A predictable monthly subscription per workspace install. No metering.

$29 / month per workspace

metered

Pay-per-use

Per-event billing — tool call, sync run, webhook delivery. Vendor sets the unit price.

$0.01 per tool call

subscription + overage

Tiered

A monthly base with included quotas. Overage is metered.

$19 + 1000 calls, $0.005 over

free + paid tier

Freemium

Workspace starts on a generous free tier; auto-upgrades on quota with explicit consent.

100 free calls/mo, then $29

Section 09 · the money flow

Where the dollars go.

A single invoice, an automatic split. Customers see one charge; vendors get paid on schedule; Omazy retains the platform fee.

CUSTOMER

$100.00

paid via Stripe

one invoice for everything

STRIPE PLATFORM

$100.00

charge runs on Omazy's account

application_fee_amount = 20%

OMAZY PLATFORM FEE

$20.00

retained

funds the marketplace, review queue, support

VENDOR PAYOUT

$80.00

transferred via Stripe Connect

monthly, 1st of the month

Every charge transparently splits. The vendor sees the same dollar in their dashboard the moment the customer is invoiced. No reconciliation, no manual transfers.

Section 10 · trust model

Twelve controls that keep the marketplace honest.

A marketplace lives or dies by its trust surface. Each control here addresses a specific failure mode.

Vendor identity
KYC via Stripe Connect Express + signed Vendor Agreement
Omazy → vendor
Signed JWT (RS256, 60s expiry, per-vendor key)
Vendor → Omazy
Vendor-signed JWT for callbacks; pubkey registered at listing
Customer credentials
Vendor handles downstream OAuth; Omazy never holds vendor-vendor tokens
Tool-call replay
60s JWT expiry + X-Omazy-Request-Id idempotency expectation
Scope creep
Manifest is the source of truth; calls outside it rejected at the gateway
Misbehaving plugin
Per-listing rate limit + circuit breaker + admin kill switch
Customer revocation
Workspace uninstall is final; subscription cancels at period end
Plaintext in logs
SDK strips Authorization headers + vendor-declared sensitive fields
Vendor key rotation
Rotate from dashboard; old keys honoured for 24h grace
Omazy key rotation
Quarterly; pubkey served via JWKS with 7-day overlap
Data retention on uninstall
Vendor wipes install state within 30 days (Vendor Agreement clause)

Section 11 · glossary of decisions

Ten decisions that hold the marketplace together.

Each one is a non-obvious choice. If anyone disagrees, RFC 1900 is back open.

Vendor-hosted, not platform-hosted
Omazy never runs vendor code. Vendors run their own infra. Removes a huge sandbox-and-liability surface from v1.
MCP as the wire format
Model Context Protocol — vendor-neutral, already adopted by other agent platforms. Omazy plugins are MCP servers in disguise.
Stripe Connect for billing
Stripe handles KYC, payouts, taxes, and disputes. Omazy focuses on the platform; Stripe handles the financial substrate.
Manifest is law
A plugin can't do anything not declared in its manifest. Tool calls outside the manifest are rejected at the gateway, not the vendor.
20% default platform fee
Standard for marketplaces of this scale. Adjustable per vendor for partner contracts. Free plugins generate no fee.
Vendor handles downstream OAuth
When a customer installs "Shopify by Acme", Acme handles the Shopify OAuth themselves. Omazy gets out of the credential business.
Per-vendor circuit breaker
50% error rate over 30s trips the breaker. Cool-down is 60s. Repeat trips escalate to human review.
Patch versions auto-approve
If the manifest hasn't changed (no new tools, no new scopes, no MCP URL change), patch+minor versions skip review. Major versions always go through full review.
Sandbox before publish
Vendors can install their own listings in their own workspace before review. Usage flows but doesn't bill — full end-to-end test in production conditions.
Shopify ships first
The first-party Shopify plugin (RFC 1901) is the dogfood listing. It validates the entire platform — onboarding, review, billing, payout — before any third party is onboarded.

// sources: docs/rfc1900-plugins-marketplace.md

// related: Omazy Harness → · deep dive →