Install Certification Data API

Single-plugin install-verification level queries (L5 smoke preferred, L4 sandbox-install fallback). One plugin per request

Endpoints
URLDescriptionUpdate
/data/install/@author/plugin.jsonSingle-plugin install-verification result (L5 smoke preferred, L4 fallback) — passed / failed / unknown / stale / untested states with a verified flag and evidence metadatarebuilt on each site build (records are append-only)
/data/install.schema.jsonJSON Schema for the install endpointappend-only updates

JSON endpoints allow cross-origin reads: Access-Control-Allow-Origin: *. No API key or registration is required.

Install verification states

Per-plugin install verification (L5 smoke preferred, L4 sandbox-install fallback), derived at build time from append-only verification records. On the current dsh version the newest real L5 verdict wins; versions without an L5 verdict fall back to their newest L4 verdict — a later focused run that left a level as not-tested never masks an earlier verdict, and verdicts from older dsh versions are returned as-is with a stale marker.

StateMeaning
passedThe install command ran successfully inside the isolated sandbox with no dependency errors (level=L4); with an L5 smoke pass too this is level=L5 install-verified
failedThe sandboxed install/smoke ran and failed — recorded as a quality signal for install decisions
unknownA record exists but no conclusion could be drawn (kept unknown, never silently upgraded)
staleThe verdict comes from an older dsh version — retained as history, pending retest (installTest.staleVersion=true)
untestedNo install-verification record — usually no parseable install command (L2 not passed) or queued for a later scan. Untested never means failed.
Response fields
FieldTypeSemantics
schemastringAbsolute URL of the JSON Schema validating this record
idstringPlugin id (matches plugins.json ids and an artifact slug)
namestringDisplay name of the plugin
installTest.statepassed|failed|unknown|stale|untestedDerived install-verification state (see states above)
installTest.levelL4|L5Runtime level backing this verdict: L5 when a real L5 smoke verdict exists, otherwise L4; ecosystem plugins (installed but declaring no dsh.bundle, shown as L5 · ecosystem plugin) always report L5
installTest.verifiedbooleantrue = L5 real-test passed (the only verdict counted as install-verified on the site)
installTest.staleVersionboolean (optional)true = the verdict comes from an older dsh version, retained as history, pending retest
installTest.verdictpassed|failed|unknown (absent when untested)Raw verdict from the winning record
installTest.channelnpm|source (optional)Whether the install came from a published npm package or the GitHub repo directly
installTest.profileIdstring (optional)Verification profile that produced the result (e.g. l4-sandbox)
installTest.checkedAtstring (ISO) (optional)When the winning record was captured
installTest.sourceRecordIdstring (optional)Append-only record id backing this verdict (audit trail)
installTest.environmentobject (optional)Recorded environment — dshVersion / dshCliVersion / os / arch / adapterId, quoted verbatim, never invented. adapterId names the verification tier (e.g. dsh-0.1-sandbox), not sandbox internals
linksobjectplugin detail, per-dsh-version install badge SVGs (badgeVersioned, plugin-name-level badge kept frozen (no longer updated) since 2026-09-20), and verification-levels page
licenseobjectProvenance and reuse terms — CC BY 4.0 (SPDX CC-BY-4.0), attribution required, freshness markers (checkedAt) must be preserved

Honesty rule: when state is untested, verdict / checkedAt / environment are omitted rather than filled with defaults.

Usage

Query one plugin (or open /data/install/@dsh-so/dsh-plugin-finder.json in a browser):

curl https://www.dsh.so/data/install/@dsh-so/dsh-plugin-finder.json

Install-test states are derived from append-only sandbox verification records (spec v1.1) bundled with each site build. Fields are append-only: existing fields are never removed or renamed. The JSON is free to reuse with attribution to dsh.so; check changelog for additions.

Was this page helpful?