Install Certification Data API
Single-plugin install-verification level queries (L5 smoke preferred, L4 sandbox-install fallback). One plugin per request
| URL | Description | Update |
|---|---|---|
/data/install/@author/plugin.json | Single-plugin install-verification result (L5 smoke preferred, L4 fallback) — passed / failed / unknown / stale / untested states with a verified flag and evidence metadata | rebuilt on each site build (records are append-only) |
/data/install.schema.json | JSON Schema for the install endpoint | append-only updates |
JSON endpoints allow cross-origin reads: Access-Control-Allow-Origin: *. No API key or registration is required.
Per-plugin install verification (L5 smoke preferred, L4 sandbox-install fallback), derived at build time from append-only verification records. On the current dsh version the newest real L5 verdict wins; versions without an L5 verdict fall back to their newest L4 verdict — a later focused run that left a level as not-tested never masks an earlier verdict, and verdicts from older dsh versions are returned as-is with a stale marker.
| State | Meaning |
|---|---|
passed | The install command ran successfully inside the isolated sandbox with no dependency errors (level=L4); with an L5 smoke pass too this is level=L5 install-verified |
failed | The sandboxed install/smoke ran and failed — recorded as a quality signal for install decisions |
unknown | A record exists but no conclusion could be drawn (kept unknown, never silently upgraded) |
stale | The verdict comes from an older dsh version — retained as history, pending retest (installTest.staleVersion=true) |
untested | No install-verification record — usually no parseable install command (L2 not passed) or queued for a later scan. Untested never means failed. |
| Field | Type | Semantics |
|---|---|---|
schema | string | Absolute URL of the JSON Schema validating this record |
id | string | Plugin id (matches plugins.json ids and an artifact slug) |
name | string | Display name of the plugin |
installTest.state | passed|failed|unknown|stale|untested | Derived install-verification state (see states above) |
installTest.level | L4|L5 | Runtime level backing this verdict: L5 when a real L5 smoke verdict exists, otherwise L4; ecosystem plugins (installed but declaring no dsh.bundle, shown as L5 · ecosystem plugin) always report L5 |
installTest.verified | boolean | true = L5 real-test passed (the only verdict counted as install-verified on the site) |
installTest.staleVersion | boolean (optional) | true = the verdict comes from an older dsh version, retained as history, pending retest |
installTest.verdict | passed|failed|unknown (absent when untested) | Raw verdict from the winning record |
installTest.channel | npm|source (optional) | Whether the install came from a published npm package or the GitHub repo directly |
installTest.profileId | string (optional) | Verification profile that produced the result (e.g. l4-sandbox) |
installTest.checkedAt | string (ISO) (optional) | When the winning record was captured |
installTest.sourceRecordId | string (optional) | Append-only record id backing this verdict (audit trail) |
installTest.environment | object (optional) | Recorded environment — dshVersion / dshCliVersion / os / arch / adapterId, quoted verbatim, never invented. adapterId names the verification tier (e.g. dsh-0.1-sandbox), not sandbox internals |
links | object | plugin detail, per-dsh-version install badge SVGs (badgeVersioned, plugin-name-level badge kept frozen (no longer updated) since 2026-09-20), and verification-levels page |
license | object | Provenance and reuse terms — CC BY 4.0 (SPDX CC-BY-4.0), attribution required, freshness markers (checkedAt) must be preserved |
Honesty rule: when state is untested, verdict / checkedAt / environment are omitted rather than filled with defaults.
Query one plugin (or open /data/install/@dsh-so/dsh-plugin-finder.json in a browser):
Install-test states are derived from append-only sandbox verification records (spec v1.1) bundled with each site build. Fields are append-only: existing fields are never removed or renamed. The JSON is free to reuse with attribution to dsh.so; check changelog for additions.