/docs / mcp-publishing

Publishing

You publish to the NeboAI marketplace through the NeboAI MCP server. Connect an MCP client, create the artifact, upload its files, and submit a version for review. The same tools serve skills, employees, plugins and apps.

Connect

Add https://neboai.com/mcp to any MCP client that supports remote servers. The client discovers the authorization server, registers itself, and signs you in with OAuth and PKCE. Any NeboAI account can connect. Access tokens last one hour and refresh for 30 days.

Developer account

Anyone with a NeboAI account can publish. Submitting a version and uploading files use your developer account, which is set up for you, free, the first time you submit or ask for an upload token. There is no fee and no approval step.

To publish for a team instead of yourself, select the team's account for the session. You must be a member of the team.

developer(resource: "account", action: "list")
developer(resource: "account", action: "select", slug: "example-team")

developer can also set up your account ahead of time (action: "create", optional) and lists and selects namespaces (resource: "namespace"). The selected namespace becomes part of every qualified name you publish.

Tools

The skill, agent and plugin tools share one set of actions. Apps are published with the agent tool.

ActionDeveloper accountDoes
createnot neededCreates the artifact and its install code.
updatenot neededChanges fields, content, version or visibility.
get, list, deletenot neededReads or removes your artifacts.
installnot neededInstalls on one of your bots: id, botId, and cascade to include dependencies.
bundle-tokenset up automaticallyA token for uploading a zip of text files.
binary-tokenset up automaticallyA token for uploading binaries, plugin.json, agent.json and app UIs.
list-binaries, delete-binaryset up automaticallyManages uploaded binaries.
submitset up automaticallySubmits a version for review.
FieldMeaning
nameDisplay name. The slug is made from it.
descriptionOne line, 10 to 500 characters to submit.
manifestContentThe artifact’s main file: SKILL.md, AGENT.md or PLUGIN.md.
versionSemantic version. Default 0.1.0.
visibilityprivate (default), loop (shared with your Loops) or public.
categoryMarketplace category.
longDescriptionThe marketplace “What it does” text (update only).
sourceUrl, manifestUrlOptional links.
dependenciesEmployees only. See Dependencies.

The marketplace tool searches the marketplace and lists categories. The pricing tool sets a price on an artifact; paid artifacts require completing payout onboarding.

Publish a skill

Create the skill with its SKILL.md as the content.

skill(action: "create", name: "invoice-totals",
      description: "Add up invoice line items, apply tax, and report the totals.",
      category: "finance", version: "1.0.0", manifestContent: "<contents of SKILL.md>")

Name the skill with its frontmatter name. Its qualified name is @<namespace>/skills/<slug>, with the slug made from the display name, and bots resolve qualified names against the frontmatter name, so the two must match.

If the skill has other files, upload the folder as a zip. A single top-level folder in the zip is removed automatically, and build and version-control folders are skipped.

skill(action: "bundle-token", id: "<skill id>")

cd invoice-totals && zip -r ../invoice-totals.zip . && cd ..
curl -X POST "https://neboai.com/api/v1/skills/<skill id>/bundle" \
  -H "Authorization: Bearer <token>" \
  -F file=@invoice-totals.zip
Bundle ruleLimit
Zip size50 MB
Each file10 MB
All files50 MB
File typesText, code, data, images, PDF and fonts, such as .md, .py, .js, .ts, .json, .yaml, .csv, .html. Anything under scripts/, bin/ or dist/ is accepted.
PathsNo .. and no absolute paths.

Make the skill public and submit a version.

skill(action: "update", id: "<skill id>", visibility: "public")
skill(action: "submit", id: "<skill id>", version: "1.0.0")

Publish an employee

Create the employee with its AGENT.md as the content and its marketplace dependencies.

agent(action: "create", name: "Support Coordinator",
      description: "Answers every customer message the day it arrives and escalates what it cannot settle.",
      version: "1.0.0", manifestContent: "<contents of AGENT.md>",
      dependencies: { skills: [ { qualifiedName: "@example-studio/skills/reply-drafting", id: "<skill id>", name: "reply-drafting" } ] })

Upload agent.json with a binary token. Employees need no binary; config is enough. To include the employee's own skills/ folder, upload the package as a bundle instead: AGENT.md, agent.json and skills/ in one zip.

agent(action: "binary-token", id: "<agent id>")

curl -X POST "https://neboai.com/api/v1/developer/apps/<agent id>/binaries" \
  -H "Authorization: Bearer <token>" \
  -F config=@support-coordinator/agent.json

Keep dependencies in agent.json. An uploaded agent.json replaces the stored configuration, including dependencies set with create or update, and an update with dependencies replaces the stored agent.json. When you use both, put the same dependencies object inside agent.json.

Dependencies

dependencies has skills, agents and connectors lists. Each entry is {qualifiedName, id, name}; NeboAI checks the qualified name first, then the id. A plugin is listed under skills. Plugins required by skills named in agent.json are added automatically. When an owner installs your employee from the marketplace or with its code, the bot installs its skill, plugin and employee dependencies with it.

Publish a plugin or an app

Plugins upload one binary per platform with the plugin's plugin.json and skills; see Shipping a Plugin. A page-only app needs no binary: upload one bundle with bundle-token holding AGENT.md (with artifact_type: app), agent.json, manifest.json, ui/ and any skills/. An app with a sidecar uses the same binary upload with the agent tool: the sidecar binary as file with its platform, and the page as ui, a .tar.gz of the ui/ folder. See Apps.

Review

submit needs the main file's content and a description of 10 to 500 characters. Each submission is scanned. A clean scan can be approved automatically; anything flagged goes to manual review. Approval signs any binaries and makes the version active. A rejected version returns to draft.

Artifact statusMeaning
draftNot submitted, or rejected.
pending_review, reviewWaiting for review.
activeApproved. Listed on the marketplace when visibility is public.
revokedWithdrawn.

Install codes

Every artifact gets its install code when it is created: SKIL-, AGNT-, PLUG-, APPS-, CONN- or COLL- followed by eight characters. Typing the code as a message in a Nebo chat installs the artifact; see Core Concepts.