Docs

Publishing tools

The wilow-market CLI, publisher requirements, the verification pipeline, and public, private-source, and enterprise publishing.

You publish tools with the wilow-market CLI. It ships on your PATH with the Wilow desktop app, and is also available as a standalone install for developers who don't run the app. The CLI is the paved road; the relay is the security boundary — every publish is independently re-verified server-side regardless of what the CLI did locally.

Publisher requirements

  • A Wilow account with a confirmed email.
  • A minimum account age (a few days) before your first publish — a basic anti-abuse gate.
  • For public tools: a linked GitHub identity, and artifacts hosted as GitHub release assets under your account or organization. For private-source tools: none of the above — no GitHub needed at all (see below).

Quick start

  1. Log in — wilow-market login opens your browser to approve (like gh auth login); no password is typed in the terminal. Use --no-browser for a copy-paste code over SSH, or --email/--password in CI.
  2. Analyze first — wilow-market advise inspects the project (web UI? local backend? deploy config?) and recommends the tool type and shape. Default to its recommendation.
  3. Create a manifest — wilow-market init --name … --slug … --type … --version … writes a wilow-tool.json. See the Manifest reference.
  4. Check it — wilow-market validate, then wilow-market scan (a local first-pass secret/injection scan).
  5. Publish — wilow-market publish. Confirm the prompt (or pass --yes in automation).

Choosing the type: website vs app

  • website — the tool has a user-facing web UI. Inside Wilow it gets an App / Chat toggle and the UI embeds inline. The UI is the product: homepage is required and must be the UI itself. Prefer this shape (paired with a Wilow-powered backend) whenever feasible — the user controls everything without leaving Wilow.
  • app — a runnable local program. If it has a UI (a local web block or a hosted homepage), Wilow shows an "Open App" button instead of embedding.
  • URL discipline: the homepage must come from your actual deployment (e.g. the vercel --prod output) — never constructed from the slug. validate verifies it: reachable, embeddable (no X-Frame-Options/frame-ancestors block), and — on Vercel-linked projects — that it's a deployment you own.
  • Multi-device by default: one listing serves every device — a phone opens the same page inside the Wilow app, so the UI must be responsive (mobile-first). validate and the publish preflight fail a website homepage without a <meta name="viewport">. Publish once and your tool works on desktop, web, Android, and iPhone — no per-platform builds, no app-store accounts.
  • Sign-in: websites should declare wilow_login and implement Log in with Wilow — third-party OAuth does not work inside the embed.

The verification pipeline

Your publish passes through, in order:

  • Local scan (advisory): the CLI scans agent/skill payloads and the shipped source for secrets and prompt-injection. This is a fast filter, not the gate.
  • Server re-verification (the gate): the relay independently obtains every artifact, recomputes its SHA-256, enforces size and host rules, and re-runs the scan server-side. A hash mismatch or a scan hit rejects the publish.
  • Catalog write: the version, its artifacts, and their pinned hashes are recorded. Installers verify against those hashes forever after.

Wilow-powered tools

Add --wilow-powered (and a --repo) to publish a tool that runs on the installer's machine using their own AI setup. Declare its setup commands (--setup, restricted to npm install|npm ci|npm run <name>|uv sync), the network hosts it needs (--network), any connectors (--connector), and --runs-local-code. These become the disclosures on the install consent screen. Your code is what runs — see the Runtime contract for what your app can rely on.

Private source: publish without exposing code

wilow-market publish --private uploads your packed source directly to Wilow's private escrow instead of a public GitHub release. The listing is public and installable, but your code is never public: no repository, no downloadable release, nothing to fork. Installers receive short-lived signed URLs and the same SHA-256 integrity guarantee. No GitHub account or linked forge identity is required for private publishing.

Honest scope of private source

Private source keeps your code off the public web — nobody can browse, clone, or search it. But a Wilow-powered tool still extracts its source locally on each installer's machine to run (like an app you install), so a determined installer could read what they installed. For truly hidden logic, keep it server-side behind an endpoint your tool calls. Private source is the right layer for “don't let people copy my tool”, and it pairs with an enterprise enterprise-only install policy for internal software.

Enterprise publishing

Editors (and above) in an Enterprise publish to the enterprise section with--enterprise <id>. Enterprise tools must be hosted in the enterprise's own GitHub org — this is what keeps them alive after an individual leaves. --enterprise and --private are mutually exclusive (an enterprise tool already has its own private model).

Updating & unpublishing

  • wilow-market update --version x.y.z ships a new version (versions must increase).
  • wilow-market unpublish --slug <slug> is the kill-switch: it delists the tool and stops running instances on installers' machines.
  • wilow-market stats shows your tools' install counts and latest versions.

CLI reference

The authoritative command list, generated from the shipping CLI (run wilow-market --help locally for the same output):

wilow-market <command> [flags]

Commands:
  login      [--no-browser]                       approve in your browser — no password in the terminal
             [--email <e> [--password <p>]]       password sign-in for CI (prompts when a terminal is present)
  setup      [--dry-run]                          install the publishing skill + slash command, register the MCP server
  upgrade                                         update the CLI (no-op when the Wilow desktop app manages it)
  init       --name <n> --slug <s> --type <t> --version <x.y.z>
             [--tagline <t>] [--description <d>] [--homepage <u>] [--repo <u>] [--license <spdx>]
             [--agent <path>] [--skill <path>] [--platform <p>] [--tag <t>]
             Wilow-powered tools: [--wilow-powered] [--setup <cmd>] [--network <host>]
                                  [--connector <name>] [--runs-local-code]
             Private source:      [--private]
  advise     [--dir <path>]                       analyze the project and recommend a tool type/shape
  validate   [--dir <path>]
  scan       [--dir <path>]
  pack       [--dir <path>]
  publish    [--dir <path>] [--changelog <text>] [--enterprise <id>] [--private] [--yes]
  update     [--dir <path>] --version <x.y.z> [--changelog <text>] [--enterprise <id>] [--private] [--yes]
  unpublish  --slug <s> [--enterprise <id>] [--yes]
  stats

Flags:
  --private      share the source with Wilow's escrow ONLY — no GitHub repo, release, or gh needed;
                 the listing is public, the code never is (installs get sha256-pinned signed URLs)
  --version, -v  print the CLI version
  --dir <path>   project directory (default: cwd)
  --json         machine-readable output
  --yes          skip the confirmation prompt for publish/update/unpublish
  --dry-run      setup: report what would be written, touch nothing

Repeatable (pass once per value): --agent --skill --platform --tag --setup --network --connector
  --platform     android | ios | windows | macos | linux
  --setup        npm install | npm ci | npm run <name> | uv sync