Skip to main content

Built-in Plugins

The platform ships with 105 plugins under packages/plugins/, spanning 21 of the 27 categories declared by PLUGIN_CATEGORIES in packages/plugin/src/contracts/plugin-manifest.types.ts: AI provider, search, content extractor, screenshot, git provider, deployment, data source, pipeline, storage, database, vector store, DNS, secret store resolver, job runtime, email provider, notification channel, connector, metrics, utility, build, and identity. (form, integration, theme, memory, rag, and app-dependency are declared as contracts but have no shipped plugin yet.) This page documents the most widely used ones, with configuration and environment variables for each.

Plugin count by category​

Counted from each package's everworks.plugin.category field.

CategoryCountPlugin IDs
pipeline14activepieces, agent-pipeline, claude-code, claude-managed-agent, codex, composio, gemini, gtm-pipeline, hermes-agent, make, opencode, sim-ai, standard-pipeline, zapier
ai-provider11anthropic, google, grok, groq, lm-studio, mistral, ollama, openai, openrouter, vercel-ai-gateway, vllm
connector11bluesky-connector, discord-connector, google-workspace-connector, hubspot-connector, jira-connector, linear-connector, mastodon-connector, notion-connector, pipedrive-connector, slack-connector, zoom-connector
utility11agentmemory, browser-automation, comparison-generator, everworks-playbooks, everworks-skills, everworks-task-tracker, langfuse, local-workspace, memory-pipeline-modifier, pty-local, sandbox-workspace
search9brave, brightdata, exa, firecrawl, linkup, perplexity, serpapi, tavily, valyu
secret-store-resolver7secret-store-aws-sm, secret-store-azure-kv, secret-store-doppler, secret-store-gcp-sm, secret-store-infisical, secret-store-k8s, secret-store-vault
job-runtime6job-runtime-bullmq, job-runtime-inngest, job-runtime-node, job-runtime-pgboss, job-runtime-temporal, job-runtime-trigger
content-extractor6jina, local-content-extractor, notion-extractor, officecli-extractor, pdf-extractor, scrapfly
notification-channel5discord-channel, novu-channel, slack-channel, telegram-channel, whatsapp-channel
email-provider5mailchimp-transactional, mailgun, postmark, resend, sendgrid
storage4aws-s3, github-storage, local-fs, minio
metrics4custom-http-metrics, google-analytics-metrics, posthog-metrics, stripe-metrics
vector-store2pgvector, qdrant
screenshot2screenshotone, urlbox
deployment2k8s, vercel
git-provider1github
database1postgres-db
data-source1apify
dns1cloudflare-dns
build1github-actions-build
identity1oidc-identity

A plugin's capabilities are independent of its category: scrapfly sits in content-extractor but also advertises screenshot, and every search plugin except brave, perplexity and serpapi also advertises content-extractor.

EW-693 — Core vs distributable​

As of EW-693 (Dynamic Plugin Distribution), every plugin is classified as either core (always bundled in the platform image, present in both bundled and dynamic modes) or distributable (published to the npm registry under @ever-works/*, installable at runtime when PLUGIN_DISTRIBUTION_MODE=dynamic). The classification lives on the plugin's manifest (everworks.plugin.distribution); when absent, the default is core for systemPlugin: true and registry otherwise.

Core (27): agent-pipeline, comparison-generator, github, job-runtime-bullmq, job-runtime-inngest, job-runtime-node, job-runtime-pgboss, job-runtime-temporal, job-runtime-trigger, k8s, local-content-extractor, local-fs, local-workspace, openrouter, pgvector, postgres-db, sandbox-workspace, secret-store-aws-sm, secret-store-azure-kv, secret-store-doppler, secret-store-gcp-sm, secret-store-infisical, secret-store-k8s, secret-store-vault, standard-pipeline, tavily, vercel. These are bundled in every image. local-fs is the default boot-storage so the API can serve without any distributable storage plugin enabled (FR-4).

Distributable (78): every other plugin under packages/plugins/*. In bundled mode these still ship in the image (so a fresh deploy behaves byte-for-byte the same as pre-EW-693); in dynamic mode they are stripped from the image and pulled from @ever-works/<id>-plugin on first enable via the per-replica installer. The full split is generated from each plugin's package.json everworks.plugin manifest — see scripts/strip-non-core-plugins.js for the runtime classification rule.

27 core plus 78 distributable accounts for all 105 plugins. Sixteen plugins state distribution: 'core' explicitly (the six job runtimes, the seven secret stores, local-fs, pgvector, postgres-db); the other eleven inherit core from systemPlugin: true. Everything added since — including hermes-agent, gtm-pipeline, officecli-extractor, grok, qdrant, cloudflare-dns, the connectors, the email providers, the notification channels and the metrics providers — is registry, so it is stripped from a dynamic-mode image and installed on demand.

See docs/specs/features/dynamic-plugin-distribution/spec.md for the full feature spec and docs/internal/EW-693-deployment.md for the operator runbook.

AI Providers​

AI provider plugins implement ai-provider capability and power all content generation, chat, and structured output features.

OpenAI​

Use OpenAI models (GPT-5.1, GPT-5-nano, GPT-4o-mini) for content generation and AI features.

FieldValue
Plugin IDopenai
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—OpenAI API key (required, secret)
defaultModelstringgpt-5.1Default model for all tasks
simpleModelstringgpt-5-nanoModel for tags, short descriptions
mediumModelstringgpt-4o-miniModel for summaries, reformatting
complexModelstringgpt-5.1Model for full page generation
temperaturenumber0.7Response variability (0–2)
maxTokensnumber4096Max response length
baseUrlstringhttps://api.openai.com/v1API endpoint

Anthropic​

Use Anthropic Claude models for content generation.

FieldValue
Plugin IDanthropic
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—Anthropic API key (required, secret)
defaultModelstringclaude-sonnet-4-5-20250514Default model
simpleModelstringclaude-haiku-4-5-20251001Simple tasks model
mediumModelstringclaude-sonnet-4-5-20250929Standard tasks model
complexModelstringclaude-sonnet-4-5-20250514Complex tasks model
temperaturenumber0.7Response variability
maxTokensnumber4096Max response length
baseUrlstringhttps://api.anthropic.com/v1/API endpoint

Google Gemini​

Use Google Gemini models for content generation.

FieldValue
Plugin IDgoogle
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—Google API key (required, secret)
defaultModelstringmodels/gemini-2.5-flashDefault model
simpleModelstringmodels/gemini-2.0-flashSimple tasks model
mediumModelstringmodels/gemini-2.5-flashStandard tasks model
complexModelstringmodels/gemini-2.5-proComplex tasks model
temperaturenumber0.7Response variability
maxTokensnumber4096Max response length
baseUrlstringhttps://generativelanguage.googleapis.com/v1beta/openai/API endpoint

Groq​

Use Groq for fast AI inference with open-source models.

FieldValue
Plugin IDgroq
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—Groq API key (required, secret)
defaultModelstringmeta-llama/llama-4-scout-17b-16e-instructDefault model
baseUrlstringhttps://api.groq.com/openai/v1API endpoint

Grok (xAI)​

Use xAI's Grok models through the OpenAI-compatible xAI API — 131,072-token context, vision input, tool calling and structured output. Assign a different Grok model per task tier.

FieldValue
Plugin IDgrok
Categoryai-provider
Configuration Modeuser-required
Auto EnableNo
Distributionregistry

Settings:

SettingTypeDefaultDescription
apiKeystring—xAI API key (required, secret, user-scoped; env fallback XAI_API_KEY)
defaultModelstringgrok-2-latestDefault model for all AI tasks (required)
simpleModelstringgrok-2-latestTags, short descriptions, quick classifications
mediumModelstringgrok-2-latestListings, summaries, content reformatting
complexModelstringgrok-2-latestFull page generation and multi-step analysis
baseUrlstringhttps://api.x.ai/v1API endpoint (advanced, hidden by default)
temperaturenumber0.7Response variability (0–2, hidden)
maxTokensnumber4096Max response length (hidden)

Get a key at console.x.ai, then enable the plugin at Settings → Plugins → AI Provider (/settings/plugins/ai-provider) and paste it into xAI API Key.

Ollama​

Use locally running models via Ollama. No API key required.

FieldValue
Plugin IDollama
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
baseUrlstring—Ollama URL (required, e.g., http://localhost:11434/v1)
defaultModelstringllama2Default model
apiKeystringollamaAPI key (optional, defaults to ollama)

LM Studio​

Use locally running models via the LM Studio local server. No API key required.

FieldValue
Plugin IDlm-studio
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
baseUrlstring—LM Studio URL (required, e.g., http://localhost:1234/v1)
apiKeystringlm-studioAPI key (optional; only for an auth proxy in front of LM Studio)
defaultModelstring—Loaded model id (required; populated via the model picker)

vLLM​

Use a self-hosted vLLM OpenAI-compatible server (typically GPU-hosted).

FieldValue
Plugin IDvllm
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
baseUrlstring—vLLM URL (required, e.g., http://localhost:8000/v1)
apiKeystringEMPTYAPI key (secret; only required if started with --api-key)
defaultModelstring—Model id passed to vllm serve --model (required; via model picker)

Mistral​

Use Mistral AI models for content generation.

FieldValue
Plugin IDmistral
Configuration Modeuser-required
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—Mistral API key (required, secret)
defaultModelstringmistral-small-latestDefault model for all tasks
simpleModelstringmistral-small-latestModel for tags, short descriptions
mediumModelstringmistral-medium-latestModel for summaries, reformatting
complexModelstringmistral-large-latestModel for full page generation
temperaturenumber0.7Response variability (0–2)
maxTokensnumber4096Max response length
baseUrlstringhttps://api.mistral.ai/v1API endpoint

AI Gateways​

AI gateway plugins route requests through multi-provider services, giving access to many models through a single API key.

OpenRouter​

Access 400+ models from multiple providers through OpenRouter.

FieldValue
Plugin IDopenrouter
Configuration Modehybrid
Auto EnableYes
Default Forai-provider
System PluginYes

Environment Variables:

VariableRequiredDescription
PLUGIN_OPENROUTER_API_KEYYesOpenRouter API key
PLUGIN_OPENROUTER_DEFAULT_MODELNoOverride default model
PLUGIN_OPENROUTER_SIMPLE_MODELNoOverride simple tasks model
PLUGIN_OPENROUTER_MEDIUM_MODELNoOverride medium tasks model
PLUGIN_OPENROUTER_COMPLEX_MODELNoOverride complex tasks model
PLUGIN_OPENROUTER_BASE_URLNoAPI endpoint (default: https://openrouter.ai/api/v1)

Settings:

SettingTypeDefaultDescription
apiKeystring—OpenRouter API key (secret)
defaultModelstringopenai/gpt-5.1Default model
simpleModelstringopenai/gpt-5-nanoSimple tasks model
mediumModelstringopenai/gpt-4oStandard tasks model
complexModelstringopenai/gpt-5.1Complex tasks model

Vercel AI Gateway​

Route AI requests through Vercel's AI Gateway.

FieldValue
Plugin IDvercel-ai-gateway
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_VERCEL_AI_GATEWAY_API_KEYYesAPI key
PLUGIN_VERCEL_AI_GATEWAY_BASE_URLNoEndpoint (default: https://ai-gateway.vercel.sh/v1)

Search plugins power web research during the generation pipeline.

Tavily​

Web search and content extraction optimized for AI applications. This is the default search provider.

FieldValue
Plugin IDtavily
Configuration Modehybrid
Auto EnableYes
Default Forsearch
System PluginYes
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_TAVILY_API_KEYNoTavily API key (can be set in user settings instead)

Settings:

SettingTypeDefaultDescription
apiKeystring—Tavily API key (required, secret)

Web search using the Brave Search API.

FieldValue
Plugin IDbrave
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_BRAVE_API_KEYNoBrave Search API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Brave API key (required, secret)
maxResultsnumber10Results per search (1–20)

SerpAPI​

Web search using SerpAPI with support for multiple search engines.

FieldValue
Plugin IDserpapi
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_SERPAPI_API_KEYNoSerpAPI key

Settings:

SettingTypeDefaultDescription
apiKeystring—SerpAPI key (required, secret)
enginestringgoogleSearch engine: google, bing, yahoo, duckduckgo, baidu, yandex
maxResultsnumber10Results per search (1–100)

Exa​

AI-native search with neural and keyword modes.

FieldValue
Plugin IDexa
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_EXA_API_KEYNoExa API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Exa API key (required, secret)
searchTypestringautoSearch type: auto, neural, keyword
maxResultsnumber10Results per search (1–100)
categorystring—Filter by category: company, research paper, news, tweet, personal site, github

Perplexity​

AI-powered web search with citations via the Perplexity API.

FieldValue
Plugin IDperplexity
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_PERPLEXITY_API_KEYNoPerplexity API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Perplexity API key (required, secret)

Bright Data​

Web search and content extraction via the Bright Data SERP API and Web Scraper.

FieldValue
Plugin IDbrightdata
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_BRIGHTDATA_API_KEYNoBright Data API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Bright Data API key (required, secret)

Firecrawl​

Web search and markdown content extraction via the Firecrawl API.

FieldValue
Plugin IDfirecrawl
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_FIRECRAWL_API_KEYNoFirecrawl API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Firecrawl API key (required, secret)

Valyu​

AI-native multi-source search and content extraction via the Valyu API.

FieldValue
Plugin IDvalyu
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_VALYU_API_KEYNoValyu API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Valyu API key (required, secret)
responseLengthstringmediumContent volume per result: short, medium, large, max

Linkup​

Web search and content extraction via the Linkup API. Optimized for AI-precision results and clean content extraction from any URL.

FieldValue
Plugin IDlinkup
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

See Linkup Plugin for setup. Refer to packages/plugins/linkup/src/ for the current settings schema.

Git Provider​

GitHub​

Repository management, cloning, pushing, pull requests, and OAuth authentication. This is the default git provider and is always enabled.

FieldValue
Plugin IDgithub
Configuration Modeadmin-only
Auto EnableYes
Default Forgit-provider
System PluginYes
Capabilitiesgit-provider, oauth

Environment Variables:

VariableRequiredDescription
PLUGIN_GITHUB_CLIENT_IDNoGitHub OAuth App client ID
PLUGIN_GITHUB_CLIENT_SECRETNoGitHub OAuth App client secret

Settings:

SettingTypeDefaultDescription
clientIdstring—GitHub OAuth client ID
clientSecretstring—GitHub OAuth client secret (secret)
apiBaseUrlstringhttps://api.github.comGitHub API endpoint

Deployment​

Vercel​

Deploy work websites to Vercel. This is the default deployment provider and is always enabled.

FieldValue
Plugin IDvercel
Configuration Modeuser-required
Auto EnableYes
Default Fordeployment
System PluginYes

Settings:

SettingTypeDefaultDescription
apiTokenstring—Vercel API token (required, secret)
defaultTeamScopestring—Default Vercel team scope (optional)

Kubernetes​

Deploy work websites to any Kubernetes cluster you control as an alternative to Vercel. Selectable per-work via deployProvider: k8s (dashboard or .works/works.yml). Supports a pluggable container registry (GitHub Container Registry by default) and ingress controller strategies (nginx, Traefik, plus a generic fallback). See Kubernetes Deployment for the full user guide.

FieldValue
Plugin IDk8s
Configuration Modeuser-required
Auto EnableYes
Default For—
System PluginYes

Settings:

SettingTypeDefaultDescription
kubeconfigstring—Full kubeconfig YAML (required, secret, user-scoped)
kubeContextstring—Override the kubeconfig's current-context
namespacestringever-worksTarget Kubernetes namespace
registry.kindstringgithubOne of github, dockerhub, generic
registry.ownerstring(auto)GHCR owner; defaults to your connected GitHub account
registry.visibilitystringautoauto mirrors the website repo, or public / private
ingressClassstring(cluster default)Detected at validation time; populated from IngressClass list
ingressHoststring—Default ingress host when a work has no custom domain
tlsIssuerstring—cert-manager ClusterIssuer name
replicasinteger1Pod replicas (1–10)

Screenshot​

Screenshot plugins capture website images for work item previews.

ScreenshotOne​

Website screenshots via the ScreenshotOne API.

FieldValue
Plugin IDscreenshotone
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_SCREENSHOTONE_ACCESS_KEYNoScreenshotOne access key
PLUGIN_SCREENSHOTONE_SECRET_KEYNoScreenshotOne secret key

Settings:

SettingTypeDefaultDescription
accessKeystring—Access key (required, secret)
secretKeystring—Secret key (secret)
viewportWidthnumber1280Viewport width
viewportHeightnumber1024Viewport height
formatstringpngImage format
blockAdsbooleantrueBlock ads
blockTrackersbooleantrueBlock trackers

URLBox​

Website screenshots via the URLBox API.

FieldValue
Plugin IDurlbox
Configuration Modehybrid
Auto EnableNo

Environment Variables:

VariableRequiredDescription
PLUGIN_URLBOX_API_KEYNoURLBox API key
PLUGIN_URLBOX_API_SECRETNoURLBox API secret

Settings:

SettingTypeDefaultDescription
apiKeystring—URLBox API key (required, secret)
apiSecretstring—URLBox API secret (secret)
viewportWidthnumber1280Viewport width (320–3840)
viewportHeightnumber1024Viewport height (200–2160)
formatstringpngImage format
blockAdsbooleantrueBlock ads
hideCookieBannersbooleantrueHide cookie consent banners

Content Extractors​

Content extractor plugins fetch and parse web page content for the generation pipeline.

Local Content Extractor​

Built-in HTML content extraction using fetch and HTML parsing. No external API needed. This is the default content extractor and is always enabled.

FieldValue
Plugin IDlocal-content-extractor
Configuration Modeadmin-only
Auto EnableYes
Default Forcontent-extractor
System PluginYes

Settings:

SettingTypeDefaultDescription
timeoutnumber15000Request timeout in ms (1000–60000)
minContentLengthnumber200Minimum content length (0–10000)
userAgentstring—Custom user agent string

Notion Extractor​

Extract content from Notion pages (both public and private).

FieldValue
Plugin IDnotion-extractor
Configuration Modehybrid
Auto EnableNo

Settings:

SettingTypeDefaultDescription
apiKeystring—Notion API key (optional, secret — needed for private pages)
useSplitbeeForPublicPagesbooleantrueUse Splitbee API for public pages
timeoutnumber15000Request timeout in ms

Jina AI​

Web search and content extraction via Jina AI's reader and search APIs.

FieldValue
Plugin IDjina
Configuration Modehybrid
Auto EnableNo
Capabilitiessearch, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_JINA_API_KEYNoJina API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Jina API key (required, secret)

Scrapfly​

Website screenshot capture and content extraction via the Scrapfly API.

FieldValue
Plugin IDscrapfly
Configuration Modehybrid
Auto EnableNo
Capabilitiesscreenshot, content-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_SCRAPFLY_API_KEYNoScrapfly API key

Settings:

SettingTypeDefaultDescription
apiKeystring—Scrapfly API key (required, secret)

PDF Content Extractor​

Extract text content from PDF files. Uses text-layer extraction by default, with optional OCR fallback via Mistral AI for scanned or image-based PDFs.

FieldValue
Plugin IDpdf-extractor
Auto EnableNo
Capabilitiescontent-extractor

Environment Variables:

VariableRequiredDescription
PLUGIN_PDF_EXTRACTOR_API_KEYNoMistral AI API key (only needed for OCR fallback)

Settings:

SettingTypeDefaultDescription
mistralApiKeystring—Mistral API key for OCR fallback (optional, secret)

OfficeCLI Extractor​

Extract text from Office documents — Word .docx, Excel .xlsx, PowerPoint .pptx — via the OfficeCLI tool and its official @officecli/sdk Node SDK. Off by default; enable it only when you need Office source material. It has zero URL overlap with the PDF extractor, and OfficeCLI ships musl binaries so it runs on the platform's node:22-alpine base image.

FieldValue
Plugin IDofficecli-extractor
Categorycontent-extractor
Auto EnableNo
System PluginNo
Capabilitiescontent-extractor

Settings:

SettingTypeDefaultDescription
renderModestringtextOutput format: text or markdown
maxBytesnumber26214400Max document size to download and process, 25 MB (env OFFICECLI_EXTRACTOR_MAX_BYTES)
timeoutnumber30000HTTP download + OfficeCLI command timeout in ms (5000–300000, hidden)
binaryPathstring—Absolute path to a specific officecli binary; blank uses the bundled one (hidden)

When a source URL points at an Office document, the content-extractor facade delegates to this plugin: it downloads the file behind an SSRF guard and the byte cap, writes it to a private temp file, opens it with OfficeCLI, and always cleans up the temp file and the OfficeCLI resident afterwards.

The bundled OfficeCLI binary and SDK are Apache-2.0; the Ever Works wrapper is AGPL-3.0. See packages/plugins/officecli-extractor/README.md for the full attribution notice.

Data Source​

Apify​

Import data from external sources using Apify web scraping actors.

FieldValue
Plugin IDapify
Capabilitiesdata-source, form-schema-provider

Settings:

SettingTypeDefaultDescription
apiTokenstring—Apify API token (required, secret)
defaultFieldMappingobject—Field mapping (name, description, source_url, category, image_url)

Storage​

Storage plugins implement the storage capability plus the object verbs (put-object, get-object, presigned-put where the backend supports pre-signed uploads, and put-object-stream / get-object-stream where the backend can write and read an object as a stream rather than as one buffer). They back every file the dashboard accepts — Knowledge Base documents, item images, avatars. Pick one at Settings → Plugins → Storage (/settings/plugins/storage). Introduced in EW-637; the Git LFS and data-repo work landed in EW-644; the two streaming verbs were added by the workspace-backup archive (AW-22), which can run to gigabytes and so may never pass through memory. Both are optional: a consumer probes for the method rather than checking a backend id, and a backend without them simply carries a smaller size ceiling. See Storage Backends for the user-facing guide.

Local Filesystem​

Writes objects to a directory on the API server. This is the default boot storage (FR-4): the API can serve with no distributable storage plugin enabled at all.

FieldValue
Plugin IDlocal-fs
Categorystorage
Auto EnableYes
System PluginYes
Distributioncore
Capabilitiesstorage, put-object, get-object, put-object-stream, get-object-stream

Settings:

SettingTypeDefaultEnvironment variableDescription
uploadsDirstring<tmpdir>/ever-works-uploadsUPLOADS_DIRAbsolute path on the API server for objects
maxBytesnumber5242880 (5 MiB)UPLOADS_MAX_BYTESPer-object size cap in bytes

Streaming writes go to a temporary name inside the same owner directory and are renamed into place, so the on-disk layout (<UPLOADS_DIR>/<ownerId>/<sha256>.<ext>) is identical whichever verb wrote the object.

Single-node only — the directory is local to the API pod, so a multi-replica deployment needs S3, MinIO, or GitHub storage instead.

AWS S3​

FieldValue
Plugin IDaws-s3
Categorystorage
Auto EnableNo
Distributionregistry
Capabilitiesstorage, put-object, get-object, presigned-put

Settings (required: region, bucket):

SettingTypeDefaultEnvironment variableDescription
regionstring—AWS_S3_REGIONRegion of the bucket, e.g. us-east-1
bucketstring—AWS_S3_BUCKETBucket name
accessKeyIdstring—AWS_ACCESS_KEY_IDIAM access key (secret); omit to use the AWS credential chain
secretAccessKeystring—AWS_SECRET_ACCESS_KEYIAM secret (secret); omit to use the AWS credential chain
presignExpiresSecondsnumber600AWS_S3_PRESIGN_EXPIRES_SECONDSPre-signed upload URL TTL, 60–3600

Leaving both key fields blank is the recommended production setup: the plugin then falls back to the default AWS credential chain (instance role, IRSA, or the ambient profile).

MinIO​

S3-compatible object storage you host yourself. Same verb set as AWS S3, pointed at your own endpoint.

FieldValue
Plugin IDminio
Categorystorage
Auto EnableNo
Distributionregistry
Capabilitiesstorage, put-object, get-object, presigned-put

Settings (required: endpoint, bucket):

SettingTypeDefaultEnvironment variableDescription
endpointstring—MINIO_ENDPOINTFull endpoint URL, e.g. https://minio.example.com:9000
regionstringus-east-1MINIO_REGIONRegion label sent in S3 requests (MinIO ignores it)
bucketstring—MINIO_BUCKETBucket name
accessKeystring—MINIO_ACCESS_KEYMinIO access key (secret)
secretKeystring—MINIO_SECRET_KEYMinIO secret key (secret)
presignExpiresSecondsnumber600MINIO_PRESIGN_EXPIRES_SECONDSPre-signed upload URL TTL, 60–3600

GitHub Storage​

Stores uploads as files in a GitHub repository, with optional Git LFS. Keeps every asset inside the Git-native ownership model — the same repos you already own.

FieldValue
Plugin IDgithub-storage
Categorystorage
Auto EnableNo
Distributionregistry
Capabilitiesstorage, put-object, get-object, lfs

Modes (the mode setting):

ModeBehaviour
separate-repo (default)One operator-owned repository holds every upload. Owner and repo come from the settings UI (the same OAuth-connected selectors as work creation) or from the env vars.
data-repoUploads land in each Work's own data repo, resolved per upload from the Work's owner and storage config, authenticated with that Work owner's OAuth token.

data-repo mode requires the API to inject a WorkRepoResolver into the plugin context at boot (apps/api/src/uploads/storage-backend.factory.ts does this) and requires every upload to carry workId — anonymous uploads are rejected with a configuration error rather than silently misfiled.

Git LFS. With lfsEnabled on, the blob goes to GitHub's LFS storage via the LFS Batch API and only a pointer file is committed; the plugin also keeps an idempotent .gitattributes entry tracking <pathPrefix>/**. It defaults to true for fresh deployments and false for deployments that already had the legacy env vars set without an explicit mode, so existing setups keep a byte-for-byte identical commit shape. LFS deletes are best-effort — removing the pointer commit drops the file from the branch tree, but GitHub's public API exposes no LFS object purge, matching git lfs rm.

Transport settingValuesNotes
lfsTransportapi (default), git-cliapi calls the LFS Batch API over HTTPS via the Octokit token — no binaries needed. git-cli shells out and needs git ≥ 2.40 + git-lfs ≥ 3.4 on PATH.
transport (non-LFS commit path)auto (default), contents-api, clone-and-pushauto picks contents-api for separate-repo and clone-and-push (isomorphic-git) for data-repo.

Environment Variables:

VariableRequiredDescription
GITHUB_STORAGE_MODENoseparate-repo (default) or data-repo
GITHUB_STORAGE_TOKENYes in separate-repoPAT with contents:write on the storage repo
GITHUB_STORAGE_OWNERYes in separate-repoRepository owner
GITHUB_STORAGE_REPOYes in separate-repoRepository name
GITHUB_STORAGE_BRANCHNoDefault main
GITHUB_STORAGE_PATH_PREFIXNoDefault uploads
GITHUB_STORAGE_LFS_ENABLEDNotrue / false — see the default rule above
GITHUB_STORAGE_LFS_TRANSPORTNoapi (default) or git-cli
GITHUB_STORAGE_TRANSPORTNoauto / contents-api / clone-and-push
GITHUB_STORAGE_PUBLIC_URL_BASENoPublic raw URL base (e.g. a CDN in front of a public repo); unset routes reads through the authenticated API

The matching settings keys are mode, token, owner, repo, branch, pathPrefix, lfsEnabled, lfsTransport and transport — the settings form and the environment variables above are two views of the same values.

Database​

PostgreSQL DB​

Holds the relational database connection used by deployed Works. Distinct from storage (object storage): this is the SQL server a Work's site talks to. The plugin owns the tenant-level backend choice and provisions or derives a database per Work.

FieldValue
Plugin IDpostgres-db
Categorydatabase
Configuration Modehybrid
Auto EnableYes
System PluginYes
Distributioncore
Capabilitiesdatabase, datastore

Settings:

SettingTypeScopeDefaultDescription
modestringuserever-works-dbever-works-db — a managed database provisioned for you, one per Work, no setup. custom — connect your own Postgres server.
customConnectionStringstringuser—postgresql://user:password@host:5432/db, used as the server for all your Works. A database is created per Work when the role allows CREATE DATABASE; otherwise the connection is used as-is. Secret; stored encrypted and shown masked. Visible only when mode is custom.
overrideConnectionStringstringwork—Override the database for THIS Work only. Secret; writable from the Work's Deploy page (/works/:id/deploy) — the scope guards enforce that. Blank falls back to the account-level setting.

See Managed Hosting for how the managed ever-works-db mode fits with *.ever.works subdomains.

Vector Store​

Vector-store plugins hold the Knowledge Base chunk embeddings and answer retrieval queries. Every plugin normalises its raw vendor score into [0, 1] (higher is better) so the retrieval contract stays backend-independent, and declares how it isolates one Work from another (namespacePerWork).

pgvector​

The default vector store. Keeps embeddings in the same Postgres the API already uses, in the work_knowledge_chunks table created by the agent migrations — zero extra infrastructure.

FieldValue
Plugin IDpgvector
Categoryvector-store
Default Forvector-store
Auto EnableYes
System PluginYes
Distributioncore
Tenancy moderowFilter (per-Work via SQL)

Settings:

SettingTypeDefaultEnvironment variableDescription
embeddingModelstringtext-embedding-3-smallKB_EMBEDDING_MODELMust match the model that produced the existing rows — a mismatch retrieves from a mixed vector space and recall drops sharply
embeddingDimensionsnumber1536KB_EMBEDDING_DIMENSIONSvector(N) column dimension (1–16000). Changing it needs a column-altering migration plus a full re-embed
indexTypestringivfflatKB_PGVECTOR_INDEX_TYPEivfflat or hnsw; hnsw is faster at query time but needs pgvector ≥ 0.5.0 and a separate index build
listsnumber100KB_PGVECTOR_LISTSivfflat inverted lists — tune to about sqrt(rows)
efSearchnumber40KB_PGVECTOR_EF_SEARCHHNSW recall-vs-latency knob; ignored when indexType is ivfflat

Every retrieval applies WHERE work_id = $1, so per-Work isolation holds even though all Works share one table.

Qdrant​

Stores embeddings in a Qdrant cluster (Qdrant Cloud or self-hosted) with one collection per Work — deleteByWork becomes a single collection drop instead of a whole-index payload-filter delete, and HNSW parameters can be tuned per tenant.

FieldValue
Plugin IDqdrant
Categoryvector-store
Auto EnableNo
Distributionregistry (install-on-demand)
Tenancy modecollection (one per Work)
Supports filterYes (payload filter pushdown)
Supports hybridNo (vector-only retrieval)

Settings:

SettingTypeDefaultEnvironment variableDescription
qdrantUrlstringhttp://localhost:6333QDRANT_URLHTTP(S) endpoint of the Qdrant instance
qdrantApiKeystring—QDRANT_API_KEYSecret. Required for Qdrant Cloud and any cluster behind auth
collectionPrefixstringever-works-kbQDRANT_COLLECTION_PREFIXFinal collection name is {prefix}-{workId}
embeddingModelstringtext-embedding-3-smallKB_EMBEDDING_MODELMust match the model that produced the points already in the collection
vectorSizenumber1536QDRANT_VECTOR_SIZEChanging it requires re-creating the collection
distancestringcosineQDRANT_DISTANCEcosine, dot, or euclid — drives both the collection config and the score normalisation
upsertBatchSizenumber128QDRANT_UPSERT_BATCH_SIZEPoints per POST /points request

Score normalisation branches on the distance metric: cosine maps (raw + 1) / 2, dot applies a sigmoid, euclid uses 1 / (1 + raw) — every branch clamped to [0, 1].

Pipeline​

The platform ships 14 pipeline plugins — three first-party engines plus eleven that delegate generation to an external agent or automation platform. See AI & Generation for a comparison.

Standard Pipeline​

The default 15-step structured generation pipeline. Uses LangChain for AI operations with configurable search, extraction, and content generation steps.

FieldValue
Plugin IDstandard-pipeline
Configuration Modedefault
Auto EnableYes
Default Forpipeline
System PluginYes
Capabilitiespipeline, form-schema-provider

The 15 pipeline steps, organized into 8 phases:

  1. Prompt Comparison
  2. Prompt Processing
  3. Domain Detection
  4. AI First Items Generation
  5. Search Queries Generation
  6. Web Search
  7. Content Retrieval
  8. Content Filtering
  9. Items Extraction
  10. Deduplication and Data Aggregation
  11. Categories and Tags Processing
  12. Sources Validation
  13. Badges Processing
  14. Image Capture
  15. Markdown Generation

Agent Pipeline​

Autonomous AI agent pipeline using the Vercel AI SDK with tool calling. The agent independently researches and generates work items using a parent/worker model architecture.

FieldValue
Plugin IDagent-pipeline
Configuration Modehybrid
Auto EnableNo
Capabilitiespipeline, form-schema-provider

Settings:

SettingTypeDefaultDescription
maxStepsinteger50Maximum agent tool-calling steps (10–2000)

Claude Code Generator​

Generation pipeline that uses the Claude Code CLI to autonomously research and generate work items. Requires either an OAuth token or Anthropic API key.

FieldValue
Plugin IDclaude-code
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

Settings:

SettingTypeDefaultDescription
oauthTokenstring—Claude Code OAuth token (secret, from claude setup-token)
apiKeystring—Anthropic API key (secret, alternative to OAuth)
modelstring—Model alias or full name (e.g., sonnet, opus)
versionstring2.1.37Claude Code CLI version
maxTurnsnumber500Maximum conversation turns (1–100)
maxBudgetUsdnumber—Maximum budget in USD

Environment Variables:

VariableRequiredDescription
PLUGIN_CLAUDE_CODE_OAUTH_TOKENNoOAuth token (can be set in user settings instead)

Claude Managed Agent​

Hosted Claude Managed Agent pipeline. Delegates the full work generation to Anthropic's managed agent runtime instead of orchestrating the steps locally.

FieldValue
Plugin IDclaude-managed-agent
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Claude Managed Agent Plugin for setup, settings, and the full list of environment variables. Refer to packages/plugins/claude-managed-agent/src/ for the latest schema.

Codex Generator​

Pipeline plugin that delegates the full generation to OpenAI Codex. Useful when you want Codex's tool-using behaviour to drive the entire generation flow.

FieldValue
Plugin IDcodex
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Codex Plugin for setup. Refer to packages/plugins/codex/src/ for the current settings schema.

Gemini Generator​

Pipeline plugin that delegates the full generation to the Gemini CLI agent. Distinct from the google AI provider plugin: Gemini Generator runs as an autonomous CLI-driven pipeline, while the google plugin exposes Gemini models for use as a regular AI provider in the Standard or Agent pipelines.

FieldValue
Plugin IDgemini
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Gemini Plugin for setup. Refer to packages/plugins/gemini/src/ for the current settings schema.

OpenCode Generator​

Pipeline plugin that delegates the full generation to OpenCode, an open-source code agent.

FieldValue
Plugin IDopencode
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See OpenCode Plugin for setup. Refer to packages/plugins/opencode/src/ for the current settings schema.

Make.com Workflows​

Pipeline plugin that triggers Make.com (formerly Integromat) scenarios via webhooks to handle work generation. Use this to plug in a no-code/low-code workflow as the source of generated items.

FieldValue
Plugin IDmake
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Make.com Plugin for setup. Refer to packages/plugins/make/src/ for the current settings schema.

SIM AI Workflows​

Pipeline plugin that delegates work generation to a SIM AI workflow defined in the SIM Studio platform.

FieldValue
Plugin IDsim-ai
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See SIM AI Workflows Plugin for setup. Refer to packages/plugins/sim-ai/src/ for the current settings schema.

Zapier Automation​

Pipeline plugin that triggers Zapier actions during work generation. Lets you wire generation events to any of Zapier's 7000+ integrations.

FieldValue
Plugin IDzapier
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Zapier Plugin for setup. Refer to packages/plugins/zapier/src/ for the current settings schema.

Composio Integrations​

Pipeline plugin that executes Composio tools during work generation. Gives Ever Works access to 500+ third-party app integrations (Gmail, Slack, GitHub, Notion, Linear, Salesforce, …) with OAuth brokered per user by Composio.

FieldValue
Plugin IDcomposio
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Composio Plugin for setup. Refer to packages/plugins/composio/src/ for the current settings schema.

Activepieces Automation​

Pipeline plugin that delegates work generation to Activepieces flows. It triggers a flow webhook at the execute stage and collects structured items from the flow's Return Response action — an AI-first, open-source alternative to Make.com and Zapier that you can self-host or run on Activepieces Cloud.

FieldValue
Plugin IDactivepieces
Configuration Modeuser-required
Auto EnableNo
Capabilitiespipeline, form-schema-provider

See Activepieces Plugin for setup. Refer to packages/plugins/activepieces/src/ for the current settings schema.

Hermes Agent​

Pipeline plugin that uses a preconfigured Hermes Agent installation on the API host as the generation engine. Ever Works provisions an isolated workspace for the run, launches Hermes in one-shot CLI mode against it, and validates the structured result file Hermes writes back before storing the generated items.

FieldValue
Plugin IDhermes-agent
Categorypipeline
Configuration Modeuser-required
Auto EnableNo
Distributionregistry
Capabilitiespipeline, form-schema-provider

Settings (required: profile):

SettingTypeDefaultDescription
profilestringdefaultHermes profile already configured on the backend via hermes model (user-scoped)
providerstring—Optional Hermes provider override passed to the CLI for each run
modelstring—Optional Hermes model override passed to the CLI for each run
toolsetsstringweb,skillsComma-separated Hermes toolsets to enable for generation
skillsstring—Optional comma-separated Hermes skills to preload
maxTurnsnumber90Maximum Hermes tool-calling turns per run (1–500)
yolobooleantrueBypass Hermes approval prompts so unattended runs do not stall
binaryPathstringhermesCLI executable path, resolved against the host PATH (hidden; env PLUGIN_HERMES_BINARY_PATH)

Backend prerequisites:

  1. Install Hermes Agent on the machine running the Ever Works API.
  2. Run hermes model for the profile you intend to use.
  3. Enter that profile name in the plugin's settings page, then select hermes-agent as the pipeline for the Work at /works/:id/plugins.

Hermes provider secrets stay in Hermes' own profile configuration — this plugin does not manage them. Hermes runs do not persist checkpoints (only standard-pipeline does), so a host restart mid-run means cancelling and re-triggering generation.

Go-to-Market Pipeline​

The engine behind Campaign Works. Runs the go-to-market stage set — research → qualify → draft → review → act → follow-up → enrich → measure — with every stage declaring its requires / provides keys so hand-offs are explicit and auditable. Review is a human gate placed before any outbound action, and the act stage only stages approved drafts for delivery: it never sends.

FieldValue
Plugin IDgtm-pipeline
Categorypipeline
Auto EnableNo
Distributionregistry
Capabilitiespipeline, form-schema-provider

Generator form fields (resolved from the Work's generator config; out-of-range values clamp to the default):

FieldTypeDefaultRange / valuesDescription
target_channelstagsemailemail, blog, social, newsletter, communityChannels to prepare content for
toneselectprofessionalprofessional, friendly, direct, enthusiasticVoice used for drafted content
cadenceselectweeklydaily, weekly, biweekly, monthlyHow often the pipeline is expected to run
max_contacts_per_runnumber201–200Upper bound of contacts drafted per run
qualify_min_scorenumber400–100Minimum qualify score required to keep a contact
risk_exclude_thresholdnumber70–10Contacts at or above this risk score are excluded
review_requiredbooltrue—Human gate before any outbound action (drafts-not-sends)
follow_up_quiet_daysnumber41–90Days of silence after which a prepared action queues a follow-up

Creating a Campaign Work at /works/new/campaign provisions the Work, its Goal, the GTM Agents and the seeded Tasks in one call, with this pipeline already selected. See Campaigns.

Prompt Management​

Langfuse​

External prompt management plugin. Lets you store, version, label, and A/B-test all pipeline prompts in Langfuse instead of shipping them in-repo.

FieldValue
Plugin IDlangfuse
Categoryutility
Auto EnableYes
Default Forprompt-provider
Distributionregistry
Capabilitiesprompt-provider

Environment Variables:

VariableRequiredDescription
PLUGIN_LANGFUSE_SECRET_KEYNoLangfuse secret key for API authentication
PLUGIN_LANGFUSE_PUBLIC_KEYNoLangfuse public key for API authentication
PLUGIN_LANGFUSE_BASE_URLNoLangfuse base URL (for self-hosted instances)

See Langfuse Plugin for setup, label conventions, and fallback behaviour. Refer to packages/plugins/langfuse/src/ for the current settings schema.

Email Providers​

Email-provider plugins implement email-outbound and, where the vendor supports it, email-inbound. They send every platform email — notifications, digests, and Agent mailboxes — and parse replies back in. Configure them at Settings → Integrations → Emails (/settings/integrations/emails). Every provider de-dupes on EmailSendInput.messageRef, so a retried send is never delivered twice.

Plugin IDCapabilitiesTransport
resendemail-outboundOfficial resend SDK with native idempotency keys
sendgridemail-outboundOfficial @sendgrid/mail SDK, v3 Mail Send
mailchimp-transactionalemail-outboundOfficial @mailchimp/mailchimp_transactional SDK (Mandrill)
mailgunemail-outbound, email-inboundOfficial mailgun.js SDK + signed inbound routes
postmarkemail-outbound, email-inboundPostmark Server API + Inbound Streams webhook parser

Settings by provider:

PluginSettingRequiredSecretEnvironment variableNotes
resendapiKeyYesYesRESEND_API_KEYResend API key
resenddefaultSenderDomainNoNo—Default from domain
sendgridapiKeyYesYesSENDGRID_API_KEYA fresh MailService per send keeps the key request-scoped
sendgriddefaultSenderDomainNoNo—Default From domain
mailchimp-transactionalapiKeyYesYesMANDRILL_API_KEYTransactional (Mandrill) product, not the Marketing API
mailchimp-transactionaldefaultSenderDomainNoNo—Default From domain
mailgunapiKeyYesYesMAILGUN_API_KEY—
mailgundomainYesNoMAILGUN_DOMAINSending domain
mailgunregionNoNoMAILGUN_REGIONus (default) or eu
mailgunwebhookSigningKeyNoYesMAILGUN_WEBHOOK_SIGNING_KEYEnables inbound HMAC-SHA256 verification; unset skips it
postmarkapiKeyYesYesPOSTMARK_API_KEYPostmark Server API token
postmarkdefaultSenderDomainNoNo—Default From domain
postmarkinboundWebhookSecretNoYesPOSTMARK_INBOUND_SECRETBasic-Auth secret for inbound webhook verification
postmarkinboundStreamIdNoNo—Specific inbound stream id

Inbound webhook URLs (register these in the provider's dashboard):

ProviderPurposeURL
PostmarkInbound emailhttps://<your-domain>/api/email/inbound/postmark
PostmarkDelivery eventshttps://<your-domain>/api/email/events/postmark

Postmark surfaces Delivery, Bounce, SpamComplaint, Open and Click events. Mailgun verifies inbound with HMAC(signingKey, timestamp + token) compared in constant time and decodes both JSON and form-urlencoded webhook bodies. Resend inbound is not supported yet — Resend's inbound product is still in private beta.

Notification Channels​

Notification-channel plugins are outbound-only delivery surfaces for platform notifications. Add and test them at Settings → Integrations → Channels (/settings/integrations/channels); each channel row has a Send test action backed by POST /api/notification-channels/:id/test. See Notifications.

Each plugin declares a shape — broadcast (a room everyone sees), direct (one recipient), or workflow (the vendor fans out itself) — plus per-channel targetConfig and tenant-wide default settings.

Plugin IDShapeTransport
slack-channelbroadcastOfficial @slack/webhook SDK over an incoming webhook
discord-channelbroadcastDiscord incoming webhook URL (plain HTTPS POST)
telegram-channeldirectOfficial grammy SDK (Api.sendMessage)
whatsapp-channeldirectWhatsApp Business Cloud API (/{phoneNumberId}/messages)
novu-channelworkflowNovu Trigger API (POST /v1/events/trigger)

Per-channel targetConfig:

PluginKeyRequiredDescription
slack-channelwebhookUrlYesSlack incoming webhook URL (https://hooks.slack.com/...)
slack-channelusernameNoOverride sender username for this channel
slack-channeliconEmojiNoOverride sender icon emoji for this channel
discord-channelwebhookUrlYesDiscord channel incoming webhook URL
discord-channelusernameNoOverride sender username for this channel
discord-channelavatarUrlNoOverride sender avatar for this channel
telegram-channelbotTokenYesBot token from @BotFather
telegram-channelchatIdYesDestination chat id
whatsapp-channelaccessTokenYesMeta system-user access token
whatsapp-channelphoneNumberIdYesWhatsApp Business phone-number id
whatsapp-channeltoYesRecipient phone in E.164, e.g. +15551234567
novu-channelapiKeyYesNovu API key (environment-scoped)
novu-channelworkflowIdYesNovu workflow trigger identifier (the workflow's name field)
novu-channelsubscriberIdYesNovu subscriber to deliver to

Plugin-level defaults (tenant-wide fallbacks used when a channel does not override them):

PluginSettingDescription
slack-channeldefaultUsernameFallback sender username
slack-channeldefaultIconEmojiFallback icon emoji, e.g. :robot_face:
discord-channeldefaultUsernameFallback sender username
discord-channeldefaultAvatarUrlFallback sender avatar
telegram-channeldisableNotificationSend silently — no sound or vibration
whatsapp-channelapiVersionGraph API version, defaults to v21.0
novu-channelapiBaseDefaults to https://api.novu.co; set for self-hosted or EU (https://eu.api.novu.co)

Rich payloads. Slack accepts Block Kit via the slack-blocks payload kind, Discord accepts embeds via discord-embeds, Telegram accepts MarkdownV2 via telegram-markdown, and WhatsApp accepts a pre-approved template via whatsapp-template ({ name, language, components }).

Finding a Telegram chat id:

  1. Create a bot with @BotFather and copy the botToken.
  2. Send any message to the bot, or add it to a group.
  3. GET https://api.telegram.org/bot<botToken>/getUpdates and read result[].message.chat.id.
  4. Paste that value into chatId — verifyTarget calls getMe before the first send to confirm the token.
WhatsApp's 24-hour window

WhatsApp only allows free-form text within 24 hours of the recipient's last message. Outside that window you must send a pre-approved template via the whatsapp-template payload kind; plain text is best-effort and in-window only.

Connectors​

Connectors are bidirectional communication plugins: they send outbound messages or records and pull inbound activity into the event-ingest spine as IngestedEventEnvelopes. A connector is a superset of a notification-channel — both families coexist, and both are distinct from the third-party automation aggregators in the Pipeline section. Manage them at Settings → Plugins → Connector (/settings/plugins/connector); see Connectors and Integrations.

Every connector with the event-source capability supports an opt-in historical backfillDays window (default 0 = off, max 90) that widens the first pull only, bounded to a per-phase page cap. Re-delivery is free — the ingest pipeline dedupes on (source, sourceEventId). Connectors that also expose the optional backfill() method can import history at any time over an explicit window rather than only as a side effect of the first pull.

Plugin IDCapabilitiesSDKOutbound
slack-connectorconnector, connector-slack, event-source@slack/web-apichat.postMessage with a bot token
discord-connectorconnector, connector-discorddiscord.js REST clientPOST /channels/:id/messages with a bot token
linear-connectorconnector, connector-linear, event-source@linear/sdkComment on a Linear issue
notion-connectorconnector, connector-notion, event-source@notionhq/clientComment on a Notion page
jira-connectorconnector, event-sourcejira.jsComment on a Jira issue
hubspot-connectorconnector, connector-hubspot, event-source@hubspot/api-clientNote engagement on a CRM record
pipedrive-connectorconnector, connector-pipedrive, event-sourcepipedriveNote on a deal, person, or organization
google-workspace-connectorconnector, event-source@googleapis/drive, @googleapis/calendarDrive + Calendar sweep (ingest-focused)
zoom-connectorconnector, event-source@zoom/rivetCloud-recording + transcript sweep
bluesky-connectorconnector, connector-bluesky, event-source@atproto/apiPost, or a threaded reply
mastodon-connectorconnector, connector-mastodon, event-sourcemastoStatus at the configured visibility

Settings by connector:

PluginSettingSecretEnvironment variableDescription
slack-connectorbotTokenYesSLACK_BOT_TOKENBot User OAuth token (xoxb-…)
slack-connectorsigningSecretYesSLACK_SIGNING_SECRETFor the inbound Events API
slack-connectorappIdNo—Slack app id
slack-connectordefaultChannelIdNo—Default destination channel, e.g. C0123456789
slack-connectoreventChannelIdsNo—Channels to ingest events from (comma-separated ids); defaults to the default channel
discord-connectorbotTokenYesDISCORD_BOT_TOKENBot token
discord-connectorpublicKeyYesDISCORD_PUBLIC_KEYApplication public key for the inbound Interactions API
discord-connectorapplicationIdNo—Discord application (client) id
discord-connectorguildIdNo—Default guild/server id
discord-connectordefaultChannelIdNo—Default destination channel
linear-connectorapiKeyYesLINEAR_API_KEYLinear API key (lin_api_…)
linear-connectorteamIdsNo—Comma-separated team-id filter for the pull
linear-connectordefaultIssueIdNo—Default issue for outbound comments
notion-connectorapiKeyYesNOTION_API_KEYNotion integration token
notion-connectordatabaseIdsNo—Comma-separated database filter; empty falls back to workspace search
notion-connectordefaultPageIdNo—Default page for outbound comments
jira-connectorbaseUrlNoJIRA_BASE_URLJira site URL, https:// only — validated against SSRF before every call
jira-connectoremailNoJIRA_EMAILAtlassian account email (API-token basic auth)
jira-connectorapiTokenYesJIRA_API_TOKENAtlassian API token
jira-connectorprojectKeysNo—Comma-separated project-key filter, whitelisted against Jira's key alphabet
jira-connectordefaultIssueKeyNo—Default issue for outbound comments
hubspot-connectoraccessTokenYesHUBSPOT_ACCESS_TOKENPrivate-app token
hubspot-connectorobjectTypesNo—Comma-separated sweep list; contacts, companies, deals when empty
hubspot-connectorportalIdNo—Portal (hub) id — enables record deep links on every envelope
hubspot-connectordefaultObjectTypeNo—Default object type for createRecord and the verify probe
hubspot-connectordefaultAssociatedObjectIdNo—Default CRM record outbound notes attach to
pipedrive-connectorapiTokenYesPIPEDRIVE_API_TOKENAPI token
pipedrive-connectorentityTypesNo—Comma-separated sweep list; deals, persons, organizations by default
pipedrive-connectorcompanyDomainNo—acme for acme.pipedrive.com — enables record deep links
pipedrive-connectordefaultDealIdNo—Default deal outbound notes attach to
google-workspace-connectorclientIdNoGOOGLE_WORKSPACE_CLIENT_IDGoogle OAuth client id
google-workspace-connectorclientSecretYesGOOGLE_WORKSPACE_CLIENT_SECRETOAuth client secret
google-workspace-connectorrefreshTokenYesGOOGLE_WORKSPACE_REFRESH_TOKENOAuth refresh token
google-workspace-connectorsurfacesNo—drive, calendar, or both (default both)
google-workspace-connectordriveFolderIdsNo—Comma-separated Drive folder filter
google-workspace-connectorcalendarIdsNo—Comma-separated calendar ids, default primary
google-workspace-connectormeetTranscriptsNo—Export Meet transcript docs into meeting envelopes (default true)
zoom-connectoraccountIdNoZOOM_ACCOUNT_IDZoom account id of the Server-to-Server OAuth app (required)
zoom-connectorclientIdNoZOOM_CLIENT_IDClient id of the Server-to-Server OAuth app (required)
zoom-connectorclientSecretYesZOOM_CLIENT_SECRETClient secret of the Server-to-Server OAuth app (required)
bluesky-connectoridentifierNo—Handle or DID of the connected account
bluesky-connectorappPasswordYesBLUESKY_APP_PASSWORDAlways an app password, never the account password
bluesky-connectorserviceNo—PDS URL, defaults to https://bsky.social, SSRF-guarded
mastodon-connectorinstanceUrlNo—Instance base URL, SSRF-guarded before every call
mastodon-connectoraccessTokenYesMASTODON_ACCESS_TOKENApplication token
mastodon-connectordefaultVisibilityNo—public, unlisted, private, or direct

Every event-source connector also accepts backfillDays (0–90) as described above. Required settings, from each plugin's settingsSchema.required: botToken (Slack, Discord); apiKey (Linear, Notion); apiToken (Pipedrive); accessToken (HubSpot); baseUrl + email + apiToken (Jira); clientId + clientSecret + refreshToken (Google Workspace); accountId + clientId + clientSecret (Zoom); identifier + appPassword (Bluesky); instanceUrl + accessToken (Mastodon). Per-send overrides such as Slack's and Discord's channelId, Linear's issueId, Notion's pageId or HubSpot's associatedObjectId travel on the send's targetConfig, not on plugin settings.

Inbound status. The Slack and Discord connectors ship the outbound leg first; inbound message routing (signature verify → pair → route to an Agent → reply in-thread) is a documented follow-up in each plugin's README, with the signingSecret / publicKey settings already captured so no reconfiguration is needed when it lands.

Metrics​

Metrics plugins implement the read-only metrics-provider capability. The MetricsFacadeService in @ever-works/agent routes listMetrics and getMetricValue through them so Goals can evaluate targets like "keep signups above 100" without any vendor being hard-coded into the platform.

Plugin IDReadsNotes
stripe-metricsStripe balance and income via the official stripe SDKValues reported in the configured currency
google-analytics-metricsGA4 Data API via @google-analytics/data (runReport)Active users, conversions, and other GA4 metrics
posthog-metricsPostHog Query APIposthog-node is ingestion-only, so this plugin uses the documented Query API
custom-http-metricsAny JSON HTTP endpoint you controlOne metric per configured endpoint, supportedWindows: ['point']

Settings:

PluginSettingRequiredDefaultEnvironment variableDescription
stripe-metricssecretKeyYes—STRIPE_SECRET_KEYStripe secret key (a restricted rk_... key is recommended)
stripe-metricscurrencyNousd—Lowercase ISO-4217 code metric values are reported in
google-analytics-metricspropertyIdYes—GOOGLE_ANALYTICS_PROPERTY_IDNumeric GA4 property id; properties/123456789 also accepted
google-analytics-metricsserviceAccountJsonYes—GOOGLE_ANALYTICS_SERVICE_ACCOUNT_JSONFull JSON service-account key file (secret)
posthog-metricsprojectIdYes—POSTHOG_PROJECT_IDNumeric project id
posthog-metricspersonalApiKeyYes—POSTHOG_PERSONAL_API_KEYPersonal API key (secret)
posthog-metricsapiHostNohttps://us.posthog.com—EU Cloud is https://eu.posthog.com; self-hosted URLs work too
custom-http-metricsendpointsYes——Array of endpoint definitions (below)

A custom-http-metrics endpoint entry:

{
"endpoints": [
{
"id": "mrr", // stable metric id, referenced by Goals
"label": "Monthly recurring revenue",
"url": "https://metrics.example.com/mrr",
"unit": "usd", // optional, defaults to "count"
"valuePath": "data.metrics[0].value",
"method": "GET", // optional; GET is the only allowed value
"headers": {
// optional; values are stored as secrets
"Authorization": "Bearer …"
}
}
]
}

DNS​

Cloudflare DNS​

Creates, updates, and removes DNS records for the subdomains and custom domains your Works are served from. Implements IDnsProvider and runs alongside the legacy concrete provider in packages/agent/src/ever-works-providers/cloudflare-dns.provider.ts — this plugin is additive, not a replacement.

FieldValue
Plugin IDcloudflare-dns
Categorydns
Auto EnableNo
Visibilityuser-only
Distributionregistry
Capabilitiesdns, dns-ensure-record, dns-remove-record, dns-record-exists, dns-root-domain

Two modes, side by side:

ModeWho configures itWhere credentials live
Managed (*.ever.works)Platform operatorEnvironment variables — the x-envVar schema entries forward them into plugin settings, so no per-user setup is needed.
Bring your own (your apex)The account ownerEncrypted user-scoped plugin settings. Records are created with the Cloudflare proxy off so you keep serving your TLS.

Settings (required: apiToken, zoneId):

SettingTypeDefaultEnvironment variableDescription
apiTokenstring—CLOUDFLARE_API_TOKENScoped token with DNS:Edit on the target zone (secret, user-scoped)
zoneIdstring—CLOUDFLARE_ZONE_IDZone id that owns the root domain
rootDomainstringever.worksEVER_WORKS_DOMAINThe DNS zone this provider manages
targetHostnamestring—EVER_WORKS_DEPLOY_LB_HOSTNAMECNAME target — the ingress load-balancer hostname public Work subdomains resolve to (admin-only)
proxiedbooleantrue—Create records behind the Cloudflare proxy (Universal SSL out of the box); set false for custom domains you already terminate TLS for

Create the token at https://dash.cloudflare.com/profile/api-tokens with DNS:Edit on the target zone.

Capability methods:

CapabilityMethodBehaviour
dns-ensure-recordensureRecord({ host, type, target, proxied? })Idempotent create-or-update; patches drifted records in place
dns-remove-recordremoveRecord({ host, type? })Idempotent delete; omitting type probes both CNAME and A
dns-record-existsrecordExists(host)Uniqueness probe — true if any CNAME or A record exists for the host
dns-root-domainrootDomain()Returns the zone's root domain

See Custom Domains and Managed Hosting.

Identity​

OpenID Connect identity (Ever ID)​

Adds Sign in with Ever ID as an additional sign-in method, next to every existing one: e-mail and password, magic link, GitHub and Google keep working exactly as before. It is an OpenID Connect relying party (authorization code flow with PKCE S256), works with any standards-compliant provider, and never stores a provider token. See Ever ID for what people see.

FieldValue
Plugin IDoidc-identity
Categoryidentity
Auto EnableNo — off until a platform administrator turns it on
ConfiguredPlatform-wide only (admin-only)
Distributionregistry
Capabilitiesidentity-provider

Off by default, and quiet while off. Configuring the plugin does not turn anything on. Until a platform administrator runs Test connection and turns Ever ID on (on the administration page, /settings/admin/ever-id), the sign-in button is not shown, every sign-in route answers 404 and the API makes no request to the provider. Turning it off again takes effect within seconds on every API replica; people can still list and disconnect connected identities, and sign-out notices from the provider are still honoured.

Settings (required: issuerUrl, clientId, clientSecret):

SettingTypeDefaultEnvironment variableDescription
issuerUrlstring—EVER_ID_ISSUER_URLThe provider's issuer (https; http://localhost only outside production)
clientIdstring—EVER_ID_CLIENT_IDThe client this installation is registered as
clientSecretstring—EVER_ID_CLIENT_SECRETClient secret (client_secret_basic); write-only, never returned
allowedIssuersarray[issuer]EVER_ID_ALLOWED_ISSUERS1–3 exact issuer strings accepted at once
apiAudiencestringever-worksEVER_ID_API_AUDIENCEThe audience delegated and terminal access tokens must carry
signUpAllowedbooleantrueEVER_ID_SIGN_UP_ALLOWEDWhether an unknown, verified identity may create an account after confirming
clockSkewSecondsinteger60EVER_ID_CLOCK_SKEW_SECONDSTolerance for token time checks (0–120)
localClientsarray[]—Up to 5 public clients (cli / node) allowed to exchange a device sign-in for a session
delegatedClientNamesarray[]—Names shown for apps that read a person's App Works with a delegated permission
accountManagementUrlstring——Target of the Manage in Ever ID link on the Connected identities card
displayNamestringEver ID—The button and heading label

The last four are managed on the administration page (or PATCH /api/auth/ever-id/admin/settings); the environment-bound settings are operator configuration.

Register at the provider: one redirect address, <WEB_URL>/api/auth/ever-id/callback; the sign-out return address <WEB_URL>/api/auth/ever-id/logout-return; and, for sign-out notices, the back-channel logout address <API_URL>/api/auth/ever-id/backchannel-logout.

Job Runtimes​

Job-runtime plugins implement IJobRuntimeProvider — the seam every background job in the platform goes through. One provider is active per instance, selected with EVER_WORKS_JOB_RUNTIME; the rest stay loaded but inert so a hot swap stays cheap. Tenants can override the instance default from Settings → Job Runtime (/settings/job-runtime), bounded by the operator allow-list EVER_WORKS_TENANT_RUNTIME_ALLOWED_PROVIDERS. See Job Runtimes.

All six declare the same capability set — job-runtime-enqueue, job-runtime-cancel, job-runtime-status, job-runtime-schedule, job-runtime-bind-tenant — and all six ship as core (bundled in every image). job-runtime-node additionally declares job-runtime-worker-host.

Plugin IDEVER_WORKS_JOB_RUNTIMEBrokerPeer dependency the operator installsPer-tenant isolation
job-runtime-triggertriggerTrigger.dev (push)@trigger.dev/sdkPer-tenant projectAccessToken
job-runtime-bullmqbullmqRedisbullmq, ioredisRedis queuePrefix per tenant
job-runtime-pgbosspgbossPostgrespg-bossPostgres schema per tenant
job-runtime-temporaltemporalTemporal@temporalio/client, @temporalio/workerTemporal namespace per tenant
job-runtime-inngestinngestInngest (serverless)inngestPer-tenant eventKey + signingKey
job-runtime-nodenodeYour enrolled FleetnoneStructural — the lease query only returns the owner's own work

Environment variables by runtime:

RuntimeVariables
triggerTRIGGER_SECRET_KEY (prod tr_prod_*), TRIGGER_PROJECT_REF, optional TRIGGER_API_URL for self-hosted
bullmqBULLMQ_REDIS_URL, BULLMQ_QUEUE_PREFIX
pgbossPGBOSS_CONNECTION_STRING, PGBOSS_SCHEMA
temporalTEMPORAL_ADDRESS, TEMPORAL_NAMESPACE, TEMPORAL_TLS_CERT + TEMPORAL_TLS_KEY (mTLS recommended)
inngestINNGEST_EVENT_KEY, INNGEST_SIGNING_KEY
nodeFLEET_NODE_API_URL, FLEET_NODE_LEASE_TTL_SECONDS, FLEET_NODE_REQUIRED_CAPABILITIES, FLEET_NODE_AGENT_TASK_COMMAND, FLEET_NODE_AGENT_TASK_WORKSPACE, FLEET_NODE_AGENT_TASK_ENV_PASSTHROUGH

None of the plugin packages depend on their broker SDK: operators pin and inject the real dispatchers themselves, and the shipped defaults are throwing stubs so a half-configured deployment fails loudly at first dispatch instead of silently dropping work. job-runtime-trigger and job-runtime-inngest keep startWorkerHost a deliberate no-op — both are push/serverless models where the vendor invokes your deployed code, so there is no worker process to start.

The node runtime — the queue is the fleet. Instead of an external broker, enqueue writes a lease-able fleet_jobs row and the machines you enrolled in Fleet poll for it over the same outbound-only HTTP channel enrollment and heartbeat already use — no inbound port is ever opened on a user's machine.

A lease is a deadline, not a lock: if a node dies mid-job nothing has to notice, because leaseExpiresAt passes and the work returns to the pool (or fails once the attempt budget is spent). Claiming is a conditional UPDATE pinned to status = 'queued', so two nodes racing the same row produce exactly one winner. JobEnqueueOptions.tags entries prefixed cap: become real scheduling requirements — a node may only lease a job whose every required tag is in its advertised capability set — while ordinary tags stay observability labels and never narrow eligibility. registerSchedules is intentionally a no-op: recurrence belongs to the platform cron, because anchoring a wall-clock schedule to intermittently-online machines would elect "whichever node happened to be awake" as the only one that ever fires.

Secret Stores​

Secret-store plugins implement the secret-store-resolve capability. They turn an opaque credentialsSecretRef pointer stored on a tenant row into a plaintext credential bag at the moment a job runtime needs it, so no third-party credential is ever persisted in the platform database. All seven ship as core. The defaults inline: and env: need no plugin at all — they are handled in-process by packages/agent/src/tasks/in-process-secret-store-resolver.service.ts. See Secret Stores.

Each plugin claims exactly one pointer scheme and fails open — an unrecognised scheme or any error returns null with a warning rather than throwing.

Plugin IDBackendPointer formatExample
secret-store-vaultHashiCorp Vault KVvault:<path after /v1/>vault:secret/data/tenants/acme/trigger
secret-store-k8sKubernetes Secretsk8s:<name> or k8s:<namespace>/<name>k8s:tenant-acme-creds
secret-store-aws-smAWS Secrets Manageraws-sm:<region>/<secretName>aws-sm:us-east-1/prod/tenants/acme
secret-store-gcp-smGCP Secret Managergcp-sm:<projectId>/<secretName>gcp-sm:my-project/tenant-acme
secret-store-azure-kvAzure Key Vaultazure-kv:<vault>/<secretName>azure-kv:my-vault/prod-tenant-acme
secret-store-dopplerDopplerdoppler:<project>/<config>doppler:ever-works/prd_tenants_acme
secret-store-infisicalInfisicalinfisical:<workspaceId>/<environment>/<secretPath>infisical:ws-abc/prod/tenants/acme

Settings (all resolved from environment variables):

PluginSettingSecretEnvironment variableDescription
secret-store-vaultvaultAddrNoVAULT_ADDRVault server URL, e.g. https://vault.internal:8200
secret-store-vaultvaultTokenYesVAULT_TOKENToken with read permission on the requested paths
secret-store-k8skubernetesServiceHostNoKUBERNETES_SERVICE_HOSTIn-cluster API server IP, set by the kubelet automatically
secret-store-k8skubernetesServicePortNoKUBERNETES_SERVICE_PORTIn-cluster API server port, defaults to 443
secret-store-aws-smawsAccessKeyIdNoAWS_ACCESS_KEY_IDOmit to use the ambient AWS credential chain
secret-store-aws-smawsSecretAccessKeyYesAWS_SECRET_ACCESS_KEYOmit to use the ambient AWS credential chain
secret-store-aws-smawsSessionTokenYesAWS_SESSION_TOKENFor temporary STS credentials
secret-store-gcp-smgcpAccessTokenYesGCP_ACCESS_TOKENOAuth2 access token with the secretmanager.secretAccessor role
secret-store-azure-kvazureKvTokenYesAZURE_KV_TOKENAzure AD bearer token, scope https://vault.azure.net/.default
secret-store-dopplerdopplerTokenYesDOPPLER_TOKENService Token or Service Account token with read access
secret-store-infisicalinfisicalTokenYesINFISICAL_TOKENService Token or Machine Identity token with read access
secret-store-infisicalinfisicalHostNoINFISICAL_HOSTBase URL for self-hosted instances; defaults to https://app.infisical.com

The Vault resolver auto-detects the KV version: it tries KV v2 first (json.data.data is an object) and falls back to KV v1. The Kubernetes resolver reads its bearer token, CA cert and default namespace from the service-account mount at /var/run/secrets/kubernetes.io/serviceaccount/ and base64-decodes every Secret value; running out of cluster it returns null and warns, so local development should use inline: instead. GCP deliberately takes a pre-fetched GCP_ACCESS_TOKEN rather than signing service-account JWTs itself — operators provision it out of band via Workload Identity, a refresher sidecar, or a cron.

Utility​

Comparison Generator​

Auto-generates SEO-optimized A vs B comparison pages between work items.

FieldValue
Plugin IDcomparison-generator
Configuration Modehybrid
Auto EnableNo
System PluginYes
Capabilitiesform-schema-provider

Settings:

SettingTypeDefaultDescription
cadence_overridestringuse_workGeneration cadence: use_work, daily, weekly, monthly
max_comparisons_modestringcustomcustom or unlimited
max_comparisonsnumber50Max total comparisons (1–500, only used in Custom mode)
min_items_for_comparisonnumber3Min items in category before generating (2–20)
ai_providerstring—Override AI provider for comparison generation
ai_modelstring—Override AI model for comparison generation
custom_promptstring—Additional instructions appended to comparison prompts
extended_analysisbooleanfalseEnable deep-dive 7-section extended analysis

See Comparisons for the full feature documentation.

Ever Works Skills​

First-party skills-provider capability plugin (ADR-012). Sources the curated Skills catalog from the ever-works/skills GitHub repo (per ADR-014). Ships v1 with a built-in fallback catalog (cron-defaults / secret-handling / commit-message-style) so the plugin works before the upstream repo is created — the platform self-recovers when it appears.

FieldValue
Plugin IDeverworks-skills
Package@ever-works/everworks-skills-plugin
LicenseMIT (ADR-014 catalog split)
Configuration Modeadmin-only
Auto EnableYes (default skills-provider)
Capabilitiesskills-provider

Settings:

SettingTypeDefaultDescription
catalogRepostringever-works/skillsGitHub owner/repo of the catalog source.
catalogBranchstringmainBranch to read from.
cacheTtlSecondsnumber3600How long to cache the cloned catalog.

See Skills feature for the platform-side data model + resolver + injection pipeline.

Ever Works Playbooks​

First-party playbook-provider capability plugin. Supplies the built-in Playbook catalogue shown in the Playbooks section of the capability catalogue (/catalog): eight packaged outcomes, each naming its trigger, its steps, the capabilities it needs (never a provider id), what it produces and when it stops to ask. Every entry is sanitised and validated before it is served, and five of the eight need no connection at all. PlaybookCatalogFacadeService merges the entries of every enabled playbook-provider; a later provider replaces an entry only with a strictly higher version.

FieldValue
Plugin IDeverworks-playbooks
Package@ever-works/everworks-playbooks-plugin
LicenseMIT
Configuration Modeadmin-only
Auto EnableYes (default playbook-provider)
Distributionregistry
Capabilitiesplaybook-provider

No settings.

Ever Works Task Tracker​

First-party task-tracker capability plugin (ADR-013). Thin shim over the platform's own DB-backed Tasks family — when this plugin is enabled, TasksFacadeService routes every Task operation through it. Community plugins (Linear / Jira / GitHub Issues) drop in by implementing the same ITaskTrackerPlugin contract.

FieldValue
Plugin IDeverworks-task-tracker
Package@ever-works/everworks-task-tracker-plugin
LicenseMIT (ADR-014 catalog split)
Configuration Modeadmin-only
Auto EnableNo — declared default for task-tracker
Distributionregistry
Capabilitiestask-tracker

Settings: none — the plugin binds to the platform's DB-backed service at boot via a runtime setPlatformTaskBackend() delegate.

See Task tracking feature for the full data model + state machine + chat thread + recurrence pipeline.

Agent Memory​

First-party implementation of the agent-memory capability. Talks to a standalone agentmemory REST server — the same one Claude Code, Codex, OpenCode and MCP clients already use — so one memory store can be shared across every agent an operator runs. The AgentMemoryFacadeService dispatches to whichever agent-memory plugin the user or Work has resolved.

FieldValue
Plugin IDagentmemory
Categoryutility
Auto EnableNo
Distributionregistry
Capabilitiesagent-memory

Settings:

SettingTypeScopeDefaultEnvironment variableDescription
baseUrlstringuserhttp://localhost:3111AGENTMEMORY_BASE_URLREST endpoint of the agentmemory server
apiKeystringuser—AGENTMEMORY_API_KEYBearer token (secret). Must match the server's AGENTMEMORY_SECRET; empty is fine for a localhost dev server
projectIdstringworkever-worksAGENTMEMORY_PROJECTNamespace sent as project on every request
timeoutMsnumberuser30000—Per-request timeout

Three ways to run the backend, same plugin code:

ModeWhenSetup
Local devHacking on Ever Works on a laptopnpx @agentmemory/agentmemory in a second terminal — the default baseUrl already points at it
Self-hosted in clusterPlatform and memory store in the same Kubernetes namespaceApply .deploy/k8s/agentmemory.optional.yaml and set baseUrl to http://agentmemory.<ns>.svc.cluster.local:3111
HostedYou already run agentmemory elsewhereSet baseUrl to the HTTPS endpoint and apiKey to the server's AGENTMEMORY_SECRET

The plugin uses only the documented REST subset — /agentmemory/health (which also drives validateConnection), /session/start, /session/end, /remember, /smart-search, /context, and /forget for governance deletes. See Memory.

Memory Pipeline Modifier​

A pipeline-modifier plugin that injects two steps into whatever pipeline a Work runs: one at the start that fetches prior agent-memory context, and one at the end that saves a digest of what was generated. That is what makes consecutive generation runs build on each other instead of starting cold. Requires an agent-memory provider to be enabled.

FieldValue
Plugin IDmemory-pipeline-modifier
Categoryutility
Auto EnableNo
Distributionregistry
Capabilitiespipeline-modifier

Settings (all work-scoped):

SettingTypeDefaultDescription
enabledbooleanfalseInject the memory hooks into this Work's pipeline
purposestringwork-generationHint passed to the memory backend to bias retrieval, e.g. fix-bug or research
maxContextTokensnumber—Upper bound on the injected memory context payload (100–32000)
saveSummarybooleantrueLet the last pipeline step save a short observation about what was generated so the next run can recall it

The injected step ids are memory-fetch-context and memory-save.

Local Workspace​

The workspace provider for self-hosted and desktop installs. Maintains a pool of real git worktree checkouts on the host so an Agent task gets an isolated working tree without a fresh clone every time. Each worktree carries a binding stamp written inside the gitdir, so it can never be committed and never appears in the working tree. See Task Isolation.

FieldValue
Plugin IDlocal-workspace
Categoryutility
Auto EnableNo
System PluginYes
Distributioncore
Capabilitiesworkspace

Settings (all hidden/advanced):

SettingTypeDefaultDescription
baseDirstringEW_WORKSPACES_DIR or the OS temp dirDirectory the worktree pool lives under
fetchDepthnumber1Shallow fetch depth for the base-ref fetch (1–1000)
committerNamestringEver Works AgentCommit author name
committerEmailstringagent@ever.worksCommit author email

Sandbox Workspace​

The cloud-default workspace provider. Runs plain git in an ephemeral job sandbox: every provision is a fresh shallow clone and the remote task branch is the durable identity, so a re-run fetches the pushed branch instead of re-cutting it and nothing is lost when the sandbox evaporates.

FieldValue
Plugin IDsandbox-workspace
Categoryutility
Auto EnableYes
System PluginYes
Distributioncore
Capabilitiesworkspace

Settings are identical to Local Workspace (baseDir, fetchDepth, committerName, committerEmail). The checkout's origin remote is always token-free: credentials arrive per operation and are injected into the URL of that single command invocation only — never written into git config, the stamp file, or the working tree, because the checkout runs untrusted repository code. Tokens are scrubbed from every error message before it can reach a log.

PTY Local​

Backs the streaming Terminal tab on an Agent's detail page. Implements terminal-stream by spawning a local pseudo-terminal and relaying it to attached viewers, with driver and viewer roles enforced by apps/api/src/terminal/terminal-attach.controller.ts (/api/agents/:id/runs/:runId/terminal). See Agent Terminals.

FieldValue
Plugin IDpty-local
Categoryutility
Auto EnableNo
Capabilitiesterminal-stream

Settings:

SettingTypeDescription
defaultColsnumberInitial terminal width before the client sends a resize
defaultRowsnumberInitial terminal height before the client sends a resize

node-pty is loaded as a runtime require rather than a static import, so a worker image without the native prebuild degrades instead of crashing at module load.

Browser Automation​

Headless Chromium automation via Playwright, behind a default-deny navigation allowlist that is re-checked on every redirect hop. Exposes exactly four verbs so an Agent can research a page it cannot simply fetch.

FieldValue
Plugin IDbrowser-automation
Categoryutility
Auto EnableNo
Distributionregistry
Capabilitiesbrowser-automation
VerbPurpose
navigateGo to a URL; returns the final URL, HTTP status, title and the full redirect chain
extractPull text / html / attribute values out of the rendered DOM by CSS selector
screenshotCapture the viewport, the full page, or one element as base64 PNG or JPEG
actRun a bounded ordered list of click / fill / select / press / hover / wait

Settings:

SettingTypeDefaultDescription
allowedHostsarray[]The navigation allowlist. Empty refuses every navigation. Falls back to PLUGIN_BROWSER_AUTOMATION_ALLOWED_HOSTS (comma-separated)
timeoutMsnumber30000Wall-clock budget for navigation and each action, clamped to 1000–120000
headlessbooleantrueLeave on for any server runtime
subresourcePolicystringpublic-onlypublic-only lets a page load assets from any public host while still blocking internal targets; allowlist restricts assets too
allowPrivateNetworkbooleanfalseAdvanced escape hatch for internal staging hosts. Requires an explicit host list — the * entry is dropped while it is on, so it can never open the whole internal network
executablePathstring—Absolute path to a Chromium binary; empty uses the Playwright-managed browser
channelstring—Optional Playwright channel (chrome, msedge) instead of the bundled Chromium

Allowlist syntax:

PatternMatches
example.comthat host exactly (not its subdomains), on any port
*.example.comany subdomain, but not the apex
example.com:8443that host, only on port 8443
*any public host — private and internal targets stay blocked

Anything else (a scheme, a path, an @, an embedded wildcard) is rejected as a configuration error rather than interpreted loosely. Refusals throw BrowserNavigationBlockedError with a stable code: invalid_url, scheme_blocked, credentials_in_url, private_address, not_allowlisted, dns_private_ip, or dns_lookup_failed. The SSRF guard sits underneath the allowlist, so an allowlisted hostname that resolves to 127.0.0.1 is still refused — a DNS-rebinding defence. Sessions opened with open() must be released with close(); the last close shuts the shared browser down.

How to enable and configure a plugin​

  1. Open Settings → Plugins (/settings/plugins) and pick the category tab — the URL is /settings/plugins/<category>, e.g. /settings/plugins/ai-provider, /settings/plugins/storage, /settings/plugins/connector.
  2. Toggle the plugin on. Plugins with configurationMode: user-required stay inactive until their required settings are filled; admin-only plugins are configured by an instance administrator; hybrid plugins accept either environment variables or per-user settings.
  3. Fill the settings form. Fields marked secret are encrypted at rest and rendered masked; fields with an environment-variable fallback show the resolved value when the env var is set, so you can leave them blank on a self-hosted instance.
  4. Use the plugin's Test / Verify action where one exists — notification channels have Send test (POST /api/notification-channels/:id/test), and any plugin can be probed with POST /api/plugins/:pluginId/validate-connection or read back from GET /api/plugins/:pluginId/connection-status. GET /api/plugins lists every discovered plugin with its manifest and health.
  5. Set a capability default where the platform needs one winner (AI provider, search, pipeline, storage, vector store, task tracker). Per-Work overrides live on the Work's own plugins page at /works/:id/plugins, backed by POST /api/works/:workId/plugins/:pluginId/capability.
  6. From the CLI: ever-works plugins catalog lists what is installable, ever-works plugins install <id> pulls a distributable plugin (optionally --version and --integrity sha512-…), ever-works plugins install-status <id> reports the per-replica installer state, and ever-works plugins uninstall <id> removes it. See CLI Quickstart.