Provider package format
Reference for CredentialProvider manifests, archives, Git sources, immutable builds, and private catalog publication.
CredentialProvider packages use the managed deployment workflow and publish immutable code packages into the provider catalog. Uploading code does not install a provider instance.
Required files
| File | Purpose |
|---|---|
constal.credential-provider.json | Package identity, version, namespace, entrypoint, expected revision |
package.json | Exact runtime dependency contract |
schema.json | Provider-installation configuration schema |
| TypeScript entrypoint | Default export from credentialProvider(...) |
| Source modules | Provider protocol implementation |
The archive root must contain the manifest directly. Do not wrap it in an extra directory. Do not include node_modules, development dependencies, lifecycle scripts, symlinks, or unrelated executables.
Manifest
{
"schemaVersion": 2,
"kind": "credential-provider",
"id": "example-token",
"namespace": "providers",
"version": "1.0.0",
"entry": "index.ts"
}Archive upload
The Console accepts ZIP and tar.gz archives up to the deployment limit. The isolated builder extracts safely, installs exact dependencies, type-checks the SDK contract, bundles the provider, computes integrity evidence, publishes an immutable executable artifact, and verifies its identity and operation catalog.
Git source
Provide a public HTTPS GitHub, GitLab, or Bitbucket repository and a full commit SHA. Branches and tags are not immutable inputs. Constal resolves the immutable source snapshot and subjects it to the same validation and build workflow as a local archive.
Catalog publication
A successful custom build publishes a private catalog entry visible only to the publisher tenant. Installation later binds namespace configuration, bootstrap Credentials, Policies, and a provider instance name. Community publication is not exposed through the tenant Console.
Integrity
The catalog entry pins package hash, implementation hash, deployment revision, executable artifact, configuration schema, lifecycle metadata, egress, rotation, and interaction origins. Re-uploading different code under the same apparent identity cannot mutate an existing immutable package.