Tutorials

Use Modyard from an agent

Claude can search Modyard, read a mod's code and publish yours, all over MCP. Reading needs no account. Publishing needs an API key in Claude Code, or OAuth in claude.ai and Claude Desktop.

3 min read

What the endpoint offers

Modyard serves an MCP endpoint at https://mods.gonzaloverdugo.com/mcp. What an agent can do depends on the credential it brings:

ToolWithout a keyWith an API key
modyard_search_modsyesyes
modyard_get_modyesyes
modyard_get_mod_filesyesyes
modyard_list_my_modsyes
modyard_publish_modyes

The three reading tools let Claude find mods, look at their versions and what they can touch, and read every file. That is the useful part even if you never publish: you can ask Claude to review a mod for you before you install it.

Reading, with no account

Add the endpoint to Claude Code as an HTTP server:

bash
claude mcp add --transport http modyard https://mods.gonzaloverdugo.com/mcp

Then ask in plain words, for example:

  • "Search Modyard for a mod that shows Bash commands in the status line, without network access."
  • "Read every file of bash-logger and tell me what each hook does."
  • "Does quiet-band rewrite or block any tool call? Quote the code."

Claude calls modyard_search_mods, modyard_get_mod and modyard_get_mod_files and answers from the actual code. The touch list it sees is the same one the mod page shows, with the same limits: a reading aid, not a review. What a mod can touch explains why the code still matters.

Publishing from Claude Code, with an API key

API keys belong to one publisher. An owner creates them in settings, with one of two scopes: read, or read and write. Keys start with mdy_ and are shown once, so copy yours when it appears.

Add the endpoint with the key in a header. If you already added it without one, remove it first with claude mcp remove modyard:

bash
claude mcp add --transport http modyard https://mods.gonzaloverdugo.com/mcp \
  --header "Authorization: Bearer mdy_..."

With a key, two more tools appear (publishing needs the read and write scope):

  • modyard_list_my_mods lists your publisher's mods, with their versions and whether they are listed.
  • modyard_publish_mod publishes a zip of a plugin folder, exactly as the publish form does.

A typical session, while writing a mod with Claude:

  1. "Validate and test ./bash-logger." Claude runs claude plugin validate and claude plugin test.
  2. "Bump the version to 0.1.1 and publish it." Claude edits plugin.json, zips the folder and calls modyard_publish_mod.
  3. "What does Modyard say it can touch?" Claude reads it back from the result.

Every publishing rule still applies: names unique across Modyard, versions immutable and always higher, size limits. Publish a mod lists them.

Treat the key like a password. Prefer adding the server at user scope on your own machine rather than in a project's shared .mcp.json, where it would end up in the repository.

claude.ai and Claude Desktop, with OAuth

claude.ai and Claude Desktop connect through OAuth, so no key is pasted anywhere. Add a custom connector and give it this URL:

text
https://mods.gonzaloverdugo.com/mcp/publisher

The first time, Modyard asks you to sign in with Google and shows a consent screen where you choose which publisher the connector acts for, if you belong to more than one. The connector gets reading, plus the mods:write scope for publishing to that publisher. To act for another publisher, connect again and choose it at consent. Removing the connector cuts its access.

Then ask the same things as in Claude Code: search, read, list your mods, publish.

The REST API, for scripts

The MCP tools sit on the same rules as a plain REST API, which is handier in CI or a shell script.

Search mods. q is free text, touch keeps mods that touch a category, without drops mods that touch any of the listed ones, and sort is recent, downloads or name:

bash
curl "https://mods.gonzaloverdugo.com/api/v1/mods?q=logger&without=network,processes&sort=downloads"

Read one mod:

bash
curl https://mods.gonzaloverdugo.com/api/v1/mods/bash-logger

Publish a version, with a read and write key:

bash
curl -X POST https://mods.gonzaloverdugo.com/api/v1/mods \
  -H "Authorization: Bearer mdy_..." \
  -F archive=@bash-logger.zip

Delete a mod, which frees its name for anyone:

bash
curl -X DELETE https://mods.gonzaloverdugo.com/api/v1/mods/bash-logger \
  -H "Authorization: Bearer mdy_..."

A minimal CI step that publishes on every tag could look like this, with the key stored as a secret:

bash
VERSION=$(jq -r .version bash-logger/.claude-plugin/plugin.json)
zip -qr bash-logger.zip bash-logger
curl -fsS -X POST https://mods.gonzaloverdugo.com/api/v1/mods \
  -H "Authorization: Bearer $MODYARD_KEY" \
  -F archive=@bash-logger.zip
echo "Published bash-logger $VERSION"

If the version already exists or is not higher than the latest, the request fails and the step fails with it, which is what you want.

Which to use

  • Just looking? The anonymous MCP endpoint, or the mods page.
  • Writing mods with Claude Code? MCP with a read and write key.
  • Working in claude.ai or Claude Desktop? The custom connector with OAuth.
  • Shipping from CI? The REST API with a key kept in your CI's secrets.

Your first mod, installed in two commands

Sign in with Google and you get a publisher with its own marketplace. Upload a zip, read what Modyard found in it, and share the install command.