Plugins
How StoreOS plugins work — couriers, payments, notifications, analytics, support, and SEO integrations attached to a tenant.
What a plugin is
A plugin is a third-party integration attached to one tenant. Installing a plugin means storing that provider's credentials or public IDs on the tenant, under a fixed path:
plugins.<category>.<provider>Nothing is deployed and no code runs on StoreOS's side. A plugin is configuration that changes how the platform behaves:
| Kind | Effect when configured |
|---|---|
| Courier | Orders can be booked with that courier; webhooks update shipment status |
| Payment | The gateway becomes selectable for ONLINE checkout |
| Notification | Order events are delivered over that channel |
| Analytics / Support / SEO | Public IDs are returned to your storefront so you can inject the script or tag |
Categories
The catalog ships as its own package, @storeos/plugins, shared by the merchant console and storeos.dev. Six categories:
| Category | PluginCategoryId | What it does |
|---|---|---|
| Delivery | delivery | Courier partners for booking and tracking parcels |
| Payments | payments | Online gateways for checkout |
| Notifications | notifications | Order alerts over WhatsApp, SMS, email |
| Analytics | analytics | Traffic, behavior, and ad pixels |
| Marketing | marketing | Popups, catalogs, and growth tools |
| Support | support | Live chat and messaging widgets |
23 plugins are in the catalog today. 20 are installable; 3 are preview-only (comingSoon). See the catalog reference for every entry and its fields.
Where secrets live
This is the important split, and it decides what you can read from your app:
| Plugin data | Stored on | Reaches your storefront? |
|---|---|---|
| Courier API keys, payment secrets, SMTP passwords, OAuth tokens | Tenant document, core-api only | Never |
| Public IDs — GA4 measurement ID, GTM container, Meta Pixel, Clarity project, Intercom app ID, Tawk.to IDs, WhatsApp number | Tenant document | Yes, via getTenant() |
The storefront API builds a deliberately narrow tenant payload. Secrets are not omitted by accident — they are never mapped into it. See Reading plugins from your storefront.
Lifecycle
Browse catalog → Install → Configure (credentials) → Validate → Live
↓
Uninstall → $unset plugins.<category>.<provider>- Install — the merchant picks a plugin in the console at
/merchant/{tenant}/plugins. - Configure — credentials are written with
plugin__configure, one plugin per call. The mutation$sets only that plugin's path, so configuring Pathao can never clobber Steadfast. - Validate — couriers have
plugin__validateCourier; payments haveplugin__paymentProviderConfigurationStatus; notifications haveplugin__testNotificationDeliveries. - Uninstall —
plugin__uninstall$unsets that one path. Other plugins are untouched.
Google Analytics and Google Tag Manager are the exception: they use OAuth, not pasted credentials, and plugin__configure rejects them. See Plugin API.
Who configures plugins
Plugins are a merchant-facing, console-side concern. The mutations live on core-api (https://core-api.storeos.dev/graphql), not on the storefront API, and require an authenticated merchant session plus an x-tenant header.
Your storefront never installs or configures plugins. It reads the resulting public IDs and renders what it needs to.
| You are building | Read this next |
|---|---|
| A storefront that must load GA4, GTM, a pixel, or a chat widget | Reading plugins from your storefront |
| Console-side tooling or automation over plugins | Plugin API |
| A courier or payment integration and need callback URLs | Webhooks & callbacks |
| A list of every plugin and its exact fields | Catalog reference |
Storage paths
Every installable plugin maps to exactly one document path. This is the same table the API uses for both $set and $unset:
| Plugin ID | Path |
|---|---|
steadfast | plugins.courier.steadfast |
pathao | plugins.courier.pathao |
bkash | plugins.payment.bkash |
sslcommerz | plugins.payment.sslcommerz |
waland | plugins.notification.waland |
bulksmsbd | plugins.notification.bulksmsbd |
smtp | plugins.notification.smtp |
google-tag-manager | plugins.analytics.gtm |
google-analytics | plugins.analytics.ga |
hotjar | plugins.analytics.hotjar |
meta-pixel | plugins.analytics.metaPixel |
microsoft-clarity | plugins.analytics.clarity |
lucky-orange | plugins.analytics.luckyOrange |
sharechat-pixel | plugins.analytics.shareChatPixel |
google-search-console | plugins.seo.searchConsole |
facebook-domain-verification | plugins.seo.facebookDomainVerification |
popupsmart | plugins.marketing.popupsmart |
intercom | plugins.support.intercom |
tawk-to | plugins.support.tawkTo |
whatsapp-chat | plugins.support.whatsappChat |
Note that catalog categories (what the merchant browses) and storage paths are not identical: Google Search Console and Facebook domain verification are browsed under Marketing and Analytics but stored under plugins.seo.