Moodle Marketplace API
Programmatic access to the Moodle Marketplace: browse the plugin catalogue and submit new versions of the plugins you maintain.
Authenticating
Every request needs a bearer token. Create one from your account's security settings, under API tokens.
The raw token is shown once, in a dialog that stops offering it after 60 seconds. It is stored hashed and cannot be retrieved later, only replaced. You may hold up to 10 active tokens; past that, revoke one before creating another.
Send it on every call:
Authorization: Bearer YOUR_TOKEN
To try the endpoints from this page, click Authorize above and paste the raw token — with
no Bearer prefix, Swagger adds it for you.
A missing, malformed, expired or revoked token gives 401. Tokens act as you: an endpoint
returns exactly what your user account is allowed to see or do.
Responses
Everything is plain JSON (application/json). Collections are bare JSON arrays.
There is no pagination: a collection returns everything you are allowed to see in one response.
Errors
Failures answer with the appropriate status code and an
RFC 9457 application/problem+json body. There is no
success flag to check in the body — the status code is the answer.
{
"status": 422,
"title": "An error occurred",
"detail": "file: The archive does not contain a valid version.php.",
"violations": [
{ "propertyPath": "file", "message": "The archive does not contain a valid version.php." }
]
}
| Status | Meaning |
|---|---|
400 Bad request | The request itself was malformed. |
401 Unauthorized | No token, or the token is not valid. |
403 Forbidden | Authenticated, but not allowed to see or change this resource. |
404 Not found | No such resource. |
406 Not acceptable | You asked for a media type this API does not serve. |
409 Conflict | The resource is in a state that does not allow this operation. |
422 Unprocessable Content | The request was well formed but its contents were rejected. See violations. |
violations lists one entry per problem, each with the offending propertyPath and a
human-readable message. Show those to the user; do not parse the messages.
Stability
This is version 1 of a young API and it will grow. New fields may be added to any response
without notice, so parse defensively and ignore what you do not recognise. Fields will not be
removed or change meaning within v1.
Authentication
- HTTP: Bearer Auth
Value for the http bearer parameter.
Security Scheme Type: | http |
|---|---|
HTTP Authorization Scheme: | bearer |
Bearer format: | Opaque token |