StoreOSv0.15.0
Plugins

Plugins

How StoreOS plugins work — couriers, payments, notifications, analytics, support, and SEO integrations attached to a tenant.

What a plugin is

A plugin is a third-party integration attached to one tenant. Installing a plugin means storing that provider's credentials or public IDs on the tenant, under a fixed path:

plugins.<category>.<provider>

Nothing is deployed and no code runs on StoreOS's side. A plugin is configuration that changes how the platform behaves:

KindEffect when configured
CourierOrders can be booked with that courier; webhooks update shipment status
PaymentThe gateway becomes selectable for ONLINE checkout
NotificationOrder events are delivered over that channel
Analytics / Support / SEOPublic IDs are returned to your storefront so you can inject the script or tag

Categories

The catalog ships as its own package, @storeos/plugins, shared by the merchant console and storeos.dev. Six categories:

CategoryPluginCategoryIdWhat it does
DeliverydeliveryCourier partners for booking and tracking parcels
PaymentspaymentsOnline gateways for checkout
NotificationsnotificationsOrder alerts over WhatsApp, SMS, email
AnalyticsanalyticsTraffic, behavior, and ad pixels
MarketingmarketingPopups, catalogs, and growth tools
SupportsupportLive chat and messaging widgets

23 plugins are in the catalog today. 20 are installable; 3 are preview-only (comingSoon). See the catalog reference for every entry and its fields.


Where secrets live

This is the important split, and it decides what you can read from your app:

Plugin dataStored onReaches your storefront?
Courier API keys, payment secrets, SMTP passwords, OAuth tokensTenant document, core-api onlyNever
Public IDs — GA4 measurement ID, GTM container, Meta Pixel, Clarity project, Intercom app ID, Tawk.to IDs, WhatsApp numberTenant documentYes, via getTenant()

The storefront API builds a deliberately narrow tenant payload. Secrets are not omitted by accident — they are never mapped into it. See Reading plugins from your storefront.


Lifecycle

Browse catalog  →  Install  →  Configure (credentials)  →  Validate  →  Live
                                      ↓
                                  Uninstall  →  $unset plugins.<category>.<provider>
  1. Install — the merchant picks a plugin in the console at /merchant/{tenant}/plugins.
  2. Configure — credentials are written with plugin__configure, one plugin per call. The mutation $sets only that plugin's path, so configuring Pathao can never clobber Steadfast.
  3. Validate — couriers have plugin__validateCourier; payments have plugin__paymentProviderConfigurationStatus; notifications have plugin__testNotificationDeliveries.
  4. Uninstall — plugin__uninstall $unsets that one path. Other plugins are untouched.

Google Analytics and Google Tag Manager are the exception: they use OAuth, not pasted credentials, and plugin__configure rejects them. See Plugin API.


Who configures plugins

Plugins are a merchant-facing, console-side concern. The mutations live on core-api (https://core-api.storeos.dev/graphql), not on the storefront API, and require an authenticated merchant session plus an x-tenant header.

Your storefront never installs or configures plugins. It reads the resulting public IDs and renders what it needs to.

You are buildingRead this next
A storefront that must load GA4, GTM, a pixel, or a chat widgetReading plugins from your storefront
Console-side tooling or automation over pluginsPlugin API
A courier or payment integration and need callback URLsWebhooks & callbacks
A list of every plugin and its exact fieldsCatalog reference

Storage paths

Every installable plugin maps to exactly one document path. This is the same table the API uses for both $set and $unset:

Plugin IDPath
steadfastplugins.courier.steadfast
pathaoplugins.courier.pathao
bkashplugins.payment.bkash
sslcommerzplugins.payment.sslcommerz
walandplugins.notification.waland
bulksmsbdplugins.notification.bulksmsbd
smtpplugins.notification.smtp
google-tag-managerplugins.analytics.gtm
google-analyticsplugins.analytics.ga
hotjarplugins.analytics.hotjar
meta-pixelplugins.analytics.metaPixel
microsoft-clarityplugins.analytics.clarity
lucky-orangeplugins.analytics.luckyOrange
sharechat-pixelplugins.analytics.shareChatPixel
google-search-consoleplugins.seo.searchConsole
facebook-domain-verificationplugins.seo.facebookDomainVerification
popupsmartplugins.marketing.popupsmart
intercomplugins.support.intercom
tawk-toplugins.support.tawkTo
whatsapp-chatplugins.support.whatsappChat

Note that catalog categories (what the merchant browses) and storage paths are not identical: Google Search Console and Facebook domain verification are browsed under Marketing and Analytics but stored under plugins.seo.

On this page