extension.*
The host side of the extension-app platform. These methods back the ht extension CLI and the command-palette entries. They are the management surface — an extension’s own backend/frontend drives the rest of τ-mux through the @tau-mux/sdk, which calls the regular surface.*, notification.*, sidebar.*, workspace.*, and browser.* methods.
Registry
Section titled “Registry”| Method | Params | Result |
|---|---|---|
extension.list | {} | [{ id, name, version, icon, description, enabled, hasBuild, running, path }] |
extension.templates | {} | string[] — bundled scaffold-template names |
extension.enable | { id: string } | "OK" — allow the extension to be opened (v0.4.12) |
extension.disable | { id: string } | "OK" — stops running surfaces; extension.open refuses until re-enabled (v0.4.12; the flag existed before but was never enforced) |
extension.reload | {} | "OK" — re-scan the extensions dir + rebuild the registry |
Surfaces
Section titled “Surfaces”| Method | Params | Result |
|---|---|---|
extension.open | { id: string, split?: boolean, direction?: "right"|"down" } | "OK" |
extension.split | { id: string, direction?: "right"|"down" } | "OK" |
extension.stop | { surface_id: string } | "OK" — stop one running extension backend |
extension.open / extension.split mint a fresh ext:-prefixed surface id, start the extension’s backend (and Vite dev server, in dev mode), and mount its iframe.
Authoring
Section titled “Authoring”| Method | Params | Result |
|---|---|---|
extension.new | { id: string, template: string, name?: string } | { id, path } |
extension.install | { path: string } | { id, path } |
extension.remove | { id: string } | "OK" |
extension.new clones a bundled template (see extension.templates) into <config>/extensions/<id>/ and rewrites its manifest id. extension.install copies an external directory containing a valid manifest.json. extension.remove stops any running surfaces, then deletes the folder.
- All methods require an
ExtensionManagerto be wired in; in processes without it (some test fixtures) they throwextensions are not available. - Extensions are fully trusted — manifest
permissionsare advisory. The RPC socket token (if enabled) still gates the socket, so only legitimately-connected clients can call these. See the trust model.