Toolaby

Toolaby for coding agents

Sell your extensionfrom one prompt.

Your coding agent sets up the pricing, gates the paid code, checks its own work and proves on Test that the paid feature unlocks, before you load it.

npx -y toolaby@latest agents
Claude Code~/word-counterWorking

Make exporting data a Pro feature for $5 once.

A real session, replayed

Works with your coding agent

  • Claude Code
  • Codex
  • Cursor
  • VS Code
  • Gemini CLI
  • Windsurf

Set up

Once, for every project.

The plugin in Claude Code. One command for Codex, Cursor, VS Code and Gemini CLI. Any other agent, by hand.

/plugin marketplace add toolaby/claude-plugin

/plugin install toolaby@toolaby

It brings

  • Toolaby's MCP server, on Test
  • Seven skills, from selling a feature to moving from ExtensionPay, and one that picks among them
  • /toolaby:sell · /toolaby:check · /toolaby:test-unlock · /toolaby:ship · /toolaby:move-from-extensionpay

Node.js 20 or laterOn Test unless told --live

Every agent, step by step

Sign in once

Your agent calls toolaby_sign_in and gives you a link and a code. Approve it in the browser: it acts as you, with your roles.

TOOLABY.md and seven skills

wire writes them into your project: how this extension sells, where gate() goes, how to check it, and what only you can do.

A command for every tool

Each of the 30 MCP tools is also npx -y toolaby@latest <command> --json, for an agent without MCP.

What it can do

From the first plan to the store zip.

30 tools over MCP, each also a command, on Test until you say Live.

Arguments

{ "tool": "acme--word-counter", "billing": "one_time", "amount": 5, "currency": "usd", "name": "Pro" }

Result

{ "ok": true, "message": "Price created on your Stripe account.", "plan": { "id": "default", "name": "Pro · Lifetime" } }

Plans and prices, on your Stripe

One-time or a subscription, with a trial, devices and seats. Each plan is a price on your own Stripe account, and each feature names the plans that unlock it.

1import { toolaby } from './toolaby.js';
2
3toolaby.startBackground({
4handlers: {
5async exportAll({ tableIds }) {
6const permit = await toolaby.gate({ feature: 'export' });
7if (!permit.allowed) return { permit };
8return { ok: true, file: await buildExport(tableIds) };
9},
10},
11});

The gate, where the paid work is

One call before the paid action: gate() asks, and showPaywall() answers a refusal with your plans, in your extension’s own popup.

npx -y toolaby@latest check --jsonexit1
{  "ok": false,  "side": "Test",  "findings": [    …    {      "code": "FEATURE_KEY_UNKNOWN",      "level": "error",      "message": "The code gates on \"export\", which is not a feature of the tool: every buyer would be refused. …",      "file": "popup.js",      "fix": "npx -y toolaby@latest features acme--word-counter --features '[{\"key\":\"export\",\"name\":\"export\"}]'",      "docs": "https://toolaby.app/docs/gating"    }  ]}

It checks its own work

Each finding has a code that never changes and says what to fix, with the command when there is one. The agent fixes it and checks again, until no error is left.

Verify0 of 5
  1. 1check --json
  2. 2toolaby_get_tool
  3. 3check --browser --built
  4. 4test-unlock acme--word-counter --plan default
  5. 5check --browser --as defaultUNLOCK_OK

Proof on Test, before you load it

test-unlock gives your Test buyer the plan, with no card and no person. Then check loads the extension in Chromium as that buyer, and the paid feature has to unlock.

Your customers, from the chat

Look a buyer up, give access, make a coupon for the store’s reviewer, refund or cancel. What takes something away says so, and on Live asks you first.

  1. toolaby_copy_to_liveFree plan, features, plans and identity, on Live
  2. upgrade acme--word-counter --livethe Live key, before the store build
  3. check --jsonno TEST_KEY_IN_LIVE_BUILD
  4. packthe store zip, without a Test key or a secret
  5. Upload and reviewyours

Ready for the Chrome Web Store

Copy to Live, the Live key, then pack makes the zip and refuses secrets and Test keys. The upload and the review stay yours.

Safe by design

Test by default. Live asks you first.

Your agent works where nothing charges anyone, and a change real buyers would see waits for your word.

toolaby_refundtoolaby-live

Refund a licence on Live (https://toolaby.app) with {"tool":"acme--word-counter","email":"rosa@example.com"}. This takes something away and cannot be undone here.Ask the person to confirm, then call toolaby_refund again with the same arguments and confirm: "4f2a9c" (valid 5 minutes).

Needs your word

Refund a licence on Live

This takes something away and cannot be undone here.

toolaby_refund({
  "tool": "acme--word-counter",
  "email": "rosa@example.com"
})

confirm: "4f2a9c"valid 5 minutes, for these arguments only

  • Test by default

    Every command and the MCP server act on Test unless told --live. Test buyers, cards and keys never reach Live by themselves.

  • Live asks first

    On Live, every change answers a summary and a confirm code first, valid for 5 minutes and for those arguments only.

  • No secret in the chat

    api-keys create writes TOOLABY_API_KEY into your .env and never prints it. The extension holds only the tool key, which is public.

  • Your roles hold

    Every change goes through the same checks as the dashboard. A member whose role cannot change a tool is refused.

Yours, once

Your agent is told these are yours, and never to report them as done.

  1. 01

    Approve the sign-in

    Once, on each side

  2. 02

    Connect Stripe on Live

    Configure → Payments

  3. 03

    Upload to the Chrome Web Store

    And submit it for review

  4. 04

    Make the first real purchase

    On Live

The session above ends: “I can run the Live-copy steps when you're ready, but the Stripe connection, store upload, and first real purchase are yours to do.”

Docs for agents

Docs your agent reads first.

Every page is Markdown at its own address, and all of them are one file. The skills tell your agent to search them before it writes Toolaby code, over MCP or by address.

https://toolaby.app/llms.txt

# Toolaby > Toolaby runs accounts, licences, subscriptions, trials, seats and the paywall for Chrome extensions that sell, on the developer's own Stripe account. A developer wires an extension to a tool with `npx -y toolaby@latest`, sets plans and features in the dashboard or from a coding agent, and gates paid work with `gate()`. Every page below is also Markdown at its address with `.md`. ## Instructions for agents - Set up once: `npx -y toolaby@latest agents` registers Toolaby's MCP server (`npx -y toolaby@latest mcp`) in Claude Code, Codex, Cursor, VS Code and Gemini CLI. These docs alone, with no sign-in, are an MCP server at https://toolaby.app/api/mcp.- Before writing Toolaby code, search these docs (`toolaby_search_docs`, or `npx -y toolaby@latest docs search <query>`) and read the page. Every page is Markdown at its address with `.md`. The client's methods are in https://toolaby.app/docs/reference/client.md: never guess one.- In an extension wired to Toolaby, read `TOOLABY.md` at the project's root first. Never edit the `toolaby*` files: `npx -y toolaby@latest upgrade <tool>` replaces them.- Gate paid work with `gate()` in the code that does the work; `has()` is for display only. A feature key in code must exist on the tool, and a plan must sell it.- Everything acts on Test unless told `--live`. On Live, a change first answers a `confirm` code: send it only on the person's word. …

On every docs page, under its title. Here, for the agents guide:

Questions

Before you hand it over.

Answered the way the docs answer them.

Any agent that connects to MCP servers. npx -y toolaby@latest agents sets Toolaby up in Claude Code, Codex, Cursor, VS Code and Gemini CLI at once, and Claude Code also has a plugin with the skills and five commands. Windsurf and any other client take the server by hand: the command npx, with -y toolaby@latest mcp. Set up your agent