Developer Tools & APIs

Anthropic opens a self-serve plugin submission portal for Claude

Anthropic's new portal at claude.ai/directory/manage lets paid-plan developers submit, track, and publish Claude plugins, with MCP 2.0 support built in.

developer tools apis category

On 25 September 2026, Anthropic opened claude.ai/directory/manage, a self-serve portal where developers on paid Claude plans can submit plugins to the Claude directory, track them through review, and see usage analytics once they go live. No partner agreement required. If you have a Pro, Max, Team, or Enterprise subscription, you can submit.

At the same time, Anthropic formally established Plugins as the official extension model for Claude and shipped full support for MCP 2.0 (spec 2026-07-28). These two things are connected, and together they represent a meaningful shift in how third-party extensions for Claude are built, distributed, and managed.

What a plugin actually is

A Plugin is a package. It can contain MCP connectors, Agent Skills, or both. In Claude Code, plugins can also bundle LSPs, commands, hooks, and agents. The idea is that a plugin gives you a single, versioned unit to publish, update, and distribute across every Claude surface: claude.ai, the desktop and mobile apps, Cowork, and Claude Code.

Skills and MCP connectors still exist as standalone building blocks, and the directory will continue to list them. What has changed is that Skills can no longer be submitted on their own. Going forward they need to live inside a plugin. Local MCP servers and the deprecated MCPB desktop extension format are also not accepted.

How the submission process works

There are two paths into the directory. You can submit a single remote MCP connector, which suits developers exposing one specific tool or data source, or you can submit a full plugin bundle hosted on GitHub, which is better for integrations that package multiple components together.

When you hit Validate in the submission form, the portal checks your plugin’s files immediately. After submission, the same scan runs again on each new commit from the branch or tag the directory follows. Each finding is categorised: Blocks (fix it before you can submit), Policy hold (an Anthropic reviewer reads this version before it goes live, though a hold is not a rejection), Warning (you can submit without fixing it), or Note (informational only).

Once your plugin clears review, you decide when to publish. That control over release timing is new. Previously, the process was largely manual, with limited visibility into where a submission stood or why it might have stalled. The portal now shows you exactly where you are, what the scan found, and what changes are recommended.

After publication, you get install analytics broken down by product surface and version, plus discovery analytics showing how often your listing is viewed and which searches led people to it.

MCP 2.0: what changed under the hood

The MCP 2026-07-28 specification drops the initialisation handshake and session state. Every request is now self-contained. That might sound like an internal detail, but the practical consequence is significant: MCP servers can run on serverless and edge infrastructure and scale horizontally behind load balancers without sticky sessions. MCP usage across Claude products has grown 110x in 2026, so the architecture needed to hold up under that kind of load.

Beyond the stateless core, the spec defines optional extensions that both client and server need to explicitly support. Two are shipping with this release.

MCP Apps lets plugins surface interactive UI directly inside Claude’s chat interface, not just tool call results. Users can see what a connector is doing and interact with it inline, without switching tabs.

Enterprise Managed Auth (EMA) handles zero-touch OAuth for enterprise organisations using Okta. Admins provision access once, users inherit it through existing identity provider groups, and authentication happens via a signed JWT with no browser redirect or per-connector consent screen. EMA is in beta for Claude Team and Enterprise customers.

The security context matters here

The timing of automated safety scanning on every submission is not accidental. In the weeks before this launch, the security community had been dealing with concrete MCP-related vulnerabilities, including Plugin4Shell, a zero-click flaw that affected Claude Code alongside several other AI coding tools, and a separate disclosure of over 143,000 flaws across 25,000 MCP servers. A directory where every version is scanned at submission and on every subsequent commit is a direct response to the reality that most users install extensions without reading the underlying code.

Remote services are also required to provide a privacy policy, and plugins must not collect conversation data they do not need for their stated function.

What this means if you’re building on Claude

If you have been waiting for a structured release path for Claude extensions, this is it. The combination of a self-serve portal, automated scanning, review tracking, and post-launch analytics gives you the kind of visibility that the old form-based process simply did not provide.

For Claude Code specifically, the claude plugin validate command checks your manifest and component files locally. claude --plugin-dir loads a plugin from a local folder for a single session, and claude plugin eval runs developer-written eval cases comparing Claude’s behaviour with and without the plugin installed. Inside a session, /skill-doctor reports what each installed skill costs in context and how often Claude has invoked it. These are practical tools for iterating before you submit.

What this means if you’re in IT or procurement

Enterprise Managed Auth removes the objection that has held back many MCP deployments in compliance-sensitive organisations. If your organisation uses Okta, you can now provision MCP connectors centrally, have users inherit access through existing groups, and avoid the per-user OAuth consent flow entirely. That is a meaningful operational difference from asking users to connect external tools themselves.

The Claude Marketplace, announced on 23 September 2026, was already listing over 2,000 tools by the time the developer portal launched two days later. The directory and the marketplace are complementary: the marketplace is where end users and organisations discover and install extensions, the directory portal is where developers manage the full submission and publishing lifecycle.

If you have an existing skill, connector, or plugin already listed in the Claude directory, you do not need to make any changes. Anthropic has said that in future, developers will be able to convert an existing connector listing into a plugin directly.