Availability
Resource Provider plugins allow you to register custom resource types that integrate into the App creation flow, participate in privacy scoring, and work with the group-based access control model. This enables plugins to extend the platform’s governance model with new kinds of resources beyond the built-in LLMs, Datasources, and Tools.
Overview
By default, Apps in AI Studio bundle three built-in resource types: LLMs, Datasources, and Tools. The Resource Provider capability lets plugins register additional resource types that:- Appear in the Create App form as selectable resources. In the AI Portal, each type has its own tab in the Add access picker. In the admin App form, the type uses a plugin-provided Web Component or a platform-rendered multi-select.
- Participate in privacy scoring with the generalized rule: no resource privacy score may exceed the maximum LLM privacy score in the app
- Integrate with group-based access control so admins can assign resource instances to groups, and users only see resources available to their groups
- Support the community submission workflow so end-users can submit new resource instances for admin review
- Propagate to gateways via the config snapshot, so gateway plugins can access resource associations at runtime
Use Cases
- MCP Server Registry: Register MCP servers as a resource type, let users bundle them into Apps
- Vector Store Catalog: Expose vector databases with privacy scores for RAG pipelines
- API Connectors: Custom API integrations that need governance and access control
- Knowledge Bases: Document collections with sensitivity classifications
How It Works
Implementing a Resource Provider
1. Implement the ResourceProvider Interface
Expandable
2. Declare in the Manifest
Add theresource_types section to your plugin manifest:
Expandable
GetResourceTypeRegistrations() method provides a runtime fallback and can return additional types not in the manifest.
Access Class: Does an App Credential Give Access?
From v2.2.0, each type declares if an App credential gives access to its instances. For example, an App credential gives access to an MCP server behind the plugin’s gateway proxy. The proxy checks the bindings of the calling App on every request. An App credential does not give access to a cataloged agent or prompt. A developer reads it, or requests access through the plugin’s own workflow, and an App binding grants nothing.access_granted_via_app records this difference for each type. Only types where the value is true:
- Appear in the App forms (AI Portal builder and admin form)
- Can be bound to an App
- Show the Build app action in the AI Portal catalog
- Go to the gateway configuration snapshot (
plugin_resources)
false still appear in the AI Portal catalog, and you can assign them to Teams for visibility. If such a type sets portal_detail_path, the catalog card opens the plugin’s own page instead of the built-in detail page. Types where the value is true can also set portal_detail_path. They keep the built-in page and Build app, and the built-in page adds a View in … link to the plugin page.
If you leave out the key, AI Studio decides from the plugin hooks. The value is true when the plugin declares resource_provider and custom_endpoint, and false if not. Existing plugins need no change. A resource instance can override the value of its type with ResourceInstance.AccessGrantedViaApp (nil uses the type value).
AI Studio stores the value each time it registers the type (plugin load, or SyncResourceTypes). After you upgrade AI Studio, the types of an installed plugin read as false until the plugin loads again. This occurs on the first start after the upgrade.
3. Serve the Plugin
ResourceProvider Interface Reference
SDK Types
ResourceTypeRegistration
ResourceInstance
Security: Do not store secrets, credentials, or PII in the Metadata field. Metadata is propagated to all gateways via config snapshots, cached in database join tables, and may appear in logs or be accessible to other plugins with access to the app configuration.
ResourceFormComponent
Privacy Scoring
WhenHasPrivacyScore is true, each resource instance carries a privacy score (0-100). The platform enforces a generalized rule during app creation and updates:
No resource privacy score may exceed the maximum LLM privacy score in the app.This applies to both built-in datasources and plugin resources. For example:
The plugin sets privacy scores on instances via the
PrivacyScore field in ResourceInstance. Admins review and approve these scores through the submission workflow.
Access Control
Plugin resource instances use direct group mapping instead of the catalogue pattern used by built-in types. This is simpler and sufficient since plugins organize their own resources.Access Chain
Admin Workflow
- Admin navigates to Teams (Groups) in the admin UI
- Opens a group and scrolls to the Plugin Resources section
- For each registered resource type, selects which instances this group can access
- Saves the group
User Experience
When a user creates an App, they only see resource instances accessible via their group memberships. Admins bypass this filter and see all instances.Default Access
By default (default_access: auto), AI Studio grants every active instance to the Default Team, so every user sees it. From v2.2.1, AI Studio grants a new auto instance immediately. In earlier versions, the instance was not visible until the plugin loaded again.
In the Enterprise Edition, a type can set default_access: explicit. Its instances then reach only the Teams that they are granted to. An administrator grants them on the Teams page, or the plugin grants them with SetResourceInstanceGroups (scope resource-access.manage). Refer to Team Access to Resource Instances. The Community Edition always uses auto.
From v2.2.1, the Teams page lists each plugin resource type and its published instances.
Custom Form Components
For richer selection UX, plugins can provide a Web Component instead of the platform’s standard multi-select. Declare it in theFormComponent field:
Injected Properties
Events to Dispatch
Example Web Component
Expandable
Gateway Integration
Plugin resource associations are included in the config snapshot sent to gateways. EachAppConfig includes a plugin_resources field:
plugin_resources field.
The snapshot includes only types where access_granted_via_app is true. Bindings to other types stay on the App record in AI Studio, but AI Studio does not send them to gateways.
Community Submissions
WhenSupportsSubmissions is true, community users can submit new resource instances through the existing submission workflow:
- The AI Portal submission form lists the type next to Data Source and Tool. If the type declares a
SubmissionSchema, AI Studio builds the form from the schema. If not, the user enters a name and free-form JSON. - The user submits with
resource_type: "plugin",plugin_resource_type_id, and aresource_payload. AI Studio validates the payload againstSubmissionSchemaand refuses invalid payloads with400. - An administrator reviews the submission in the Submission Queue, and sets the final privacy score.
- On approval, AI Studio calls the plugin’s
CreateResourceInstance(ctx, slug, payload). Thepayloadis a JSON submission envelope:
plugin_sdk.ParseSubmissionEnvelope(payload). This function also accepts a bare payload from older callers.
5. The plugin creates the instance and returns it. The RPC runs outside the database transaction of AI Studio, so use submission_id as an idempotency key. If an instance already exists for the submission, return that instance.
6. The instance becomes available for selection in the App form.
AI Studio does not support update proposals (POST /common/submissions/update) for plugin resource types. Plugins version their own instances.
Declare a Submission Schema
ErrInvalidSubmissionSchema if it is not valid.
Runtime Registration
AI Studio registers the manifestresource_types at load time. If the plugin defines its types at runtime (for example, administrators define them inside the plugin), call plugin_sdk.SyncResourceTypes(ctx, regs) each time the set changes. The call registers the types in the list and deactivates the plugin’s other types. It needs the resource-types.manage scope. During the call, AI Studio calls ListResourceInstances for each type, so return an empty list (not an error) while your state is still loading.
Manifest Reference
Expandable
API Endpoints
These endpoints are available for frontend integration:Set Group Plugin Resources
Combining with Other Capabilities
Resource Provider plugins often combine with other capabilities for a complete solution:Example: Complete MCP Registry Plugin
Expandable