Skip to main content
Version: v1

acton-plugin CLI

The CLI covers the whole plugin lifecycle. Build it from the SDK repo:

go build -o acton-plugin ./cmd/acton-plugin/
acton-plugin version

Run acton-plugin <command> --help for flag defaults.


new / init​

Scaffold a project.

acton-plugin new <name> [--type=tool|channel|connector] [--dir=target_directory]
FlagDefaultMeaning
--typetooltool, channel, or connector
--dirthe plugin nameOutput folder

Writes manifest.json, main.go, main_test.go, README.md, .gitignore.


build​

Compile to WebAssembly.

acton-plugin build [--source=.] [--output=dist/plugin.wasm] [--tinygo]
FlagAliasDefault
--source--src.
--output--outdist/plugin.wasm
--tinygostandard Go (GOOS=wasip1 GOARCH=wasm -buildmode=c-shared)

TinyGo uses -target=wasi -opt=2.


validate​

acton-plugin validate [--manifest=manifest.json]

Checks required fields, id/semver patterns, capability consistency, and noisy permissions (net_outbound: ["*"] is a warning).


test​

Run the .wasm in an embedded Wazero mock host (fake vault, KV, event bus, domain firewall).

acton-plugin test [--wasm=dist/plugin.wasm] [--manifest=manifest.json] [--tool=tool_name] [--input='{"param":"value"}']
FlagDefault
--wasmdist/plugin.wasm
--manifestmanifest.json
--toolfirst tool in the manifest, if any
--input{}

Secrets listed in the manifest are filled with mock_secret_value_for_<key>.


sign​

Ed25519 signatures over SHA-256(manifest.json || plugin.wasm).

acton-plugin sign --gen-key [--key=plugin_ed25519.key]
acton-plugin sign [--key=plugin_ed25519.key] [--manifest=manifest.json] [--wasm=dist/plugin.wasm] [--output=dist/signature.sig]
FlagAliasDefault
--gen-keygenerate a key pair and exit
--keyplugin_ed25519.key
--manifestmanifest.json
--wasmdist/plugin.wasm
--output--outdist/signature.sig

--gen-key also writes plugin_ed25519.key.pub. The private key is 0600 hex.


pack / package​

Zip a distributable .actonpkg.

acton-plugin pack [--manifest=manifest.json] [--wasm=dist/plugin.wasm] [--sig=dist/signature.sig] [--output=dist/<id>-<version>.actonpkg]

Archive contents:

  1. manifest.json
  2. plugin.wasm
  3. signature.sig if --sig exists
  4. README.md if present in the working directory

build-all / pack-all​

Batch-compile every plugin under plugins/ into dist/. Used by the official SDK repo; not required for a single custom plugin.


version​

Prints the CLI / SDK version (currently 1.3.0).


Typical sequence​

acton-plugin new weather-tool --type=tool
cd weather-tool
acton-plugin validate
acton-plugin build
acton-plugin test --input='{"city":"Tokyo"}'
acton-plugin sign --gen-key
acton-plugin sign
acton-plugin pack

Upload the resulting .actonpkg on Plugins.