Skip to main content
Version: 1.0.0

Moodle Marketplace API

Programmatic access to the Moodle Marketplace: browse the plugin catalogue and submit new versions of the plugins you maintain.

Authenticating​

Every request needs a bearer token. Create one from your account's security settings, under API tokens.

The raw token is shown once, in a dialog that stops offering it after 60 seconds. It is stored hashed and cannot be retrieved later, only replaced. You may hold up to 10 active tokens; past that, revoke one before creating another.

Send it on every call:

Authorization: Bearer YOUR_TOKEN

To try the endpoints from this page, click Authorize above and paste the raw token — with no Bearer prefix, Swagger adds it for you.

A missing, malformed, expired or revoked token gives 401. Tokens act as you: an endpoint returns exactly what your user account is allowed to see or do.

Responses​

Everything is plain JSON (application/json). Collections are bare JSON arrays.

There is no pagination: a collection returns everything you are allowed to see in one response.

Errors​

Failures answer with the appropriate status code and an RFC 9457 application/problem+json body. There is no success flag to check in the body — the status code is the answer.

{
"status": 422,
"title": "An error occurred",
"detail": "file: The archive does not contain a valid version.php.",
"violations": [
{ "propertyPath": "file", "message": "The archive does not contain a valid version.php." }
]
}
StatusMeaning
400 Bad requestThe request itself was malformed.
401 UnauthorizedNo token, or the token is not valid.
403 ForbiddenAuthenticated, but not allowed to see or change this resource.
404 Not foundNo such resource.
406 Not acceptableYou asked for a media type this API does not serve.
409 ConflictThe resource is in a state that does not allow this operation.
422 Unprocessable ContentThe request was well formed but its contents were rejected. See violations.

violations lists one entry per problem, each with the offending propertyPath and a human-readable message. Show those to the user; do not parse the messages.

Stability​

This is version 1 of a young API and it will grow. New fields may be added to any response without notice, so parse defensively and ignore what you do not recognise. Fields will not be removed or change meaning within v1.

Authentication​

Value for the http bearer parameter.

Security Scheme Type:

http

HTTP Authorization Scheme:

bearer

Bearer format:

Opaque token