Custom capabilities
Register your own private skills, MCP servers and plugins, configure them with secret references, install them at a scope, and version them.
Register
Capabilities → Register capability (permission capability.manage), paste the manifest JSON, or:
curl -X POST "$AO_SERVER/api/v1/orgs/$AO_ORG/capabilities" \
-H "Authorization: Bearer $AO_TOKEN" -H "Content-Type: application/json" \
--data '{"manifest": { … }, "private": true}'Private capabilities are visible only in your organization. Platform administrators can register platform-level capabilities for every organization of the installation.
Configure with secret references
Declare settings in configuration. Mark secret ones secret: true; at installation their values must be
references like secret:NAME to organization secrets — the API refuses inline values.
"configuration": [
{ "key": "url", "description": "Where to send reports", "required": true },
{ "key": "token", "description": "Bearer token", "secret": true }
]Install
POST /api/v1/orgs/:orgId/capability-installations with capabilityId, optional version, scope
(ORGANIZATION, PROJECT, TASK), projectId for project scope, and config. Pending installations are approved
with …/capability-installations/:id/approve; PATCH enables or disables; DELETE uninstalls.
Version
Versions are immutable. Change the manifest, raise version, register again; installations can pin a version.
Other manifest fields
publisher, homepage, platforms, requires (tools, informational), dependencies (other capabilities with a
version range), recommendedMcp, triggers, install / uninstall / healthCheck commands.