YOLO Studio
Developers
DocsHome
YOLO Apps for developers, in early access

Build App Tiles that run inside people's AI workspaces

An App Tile is a small app that sits on a YOLO Studio workspace grid, beside the agents doing the work. It reaches the workspace only through permissions the user grants, and every third-party release is signed by its publisher and reviewed by us before anyone can install it.

Apply for early accessBuild a personal app today

Marketplace publishing isn't open to outside developers yet. Personal apps, visible only to you, are live for every YOLO Studio user.

{
  "id": "standup-digest",
  "version": "1.2.0",
  "publisher": "acme",
  "surface": { "kind": "iframe",
               "entry": "index.html" },
  "permissions": {
    "required": ["llm.invoke"],
    "optional": ["net:api.linear.app"]
  },
  "signature": "MEUCIQ…"
}

Standup Digest

3 updates

Agent lane 2

Merged retry fix for the upload queue

Agent lane 4

Waiting on review: billing webhook tests

Linear

2 issues moved to In Progress

Verified publisher

llm.invokenet:api.linear.app

What an App Tile is

One manifest declares who you are, what your app is, and exactly what it may touch. The rest is a web app.

UI-only tiles

A static bundle of HTML, CSS and JavaScript rendered in a sandboxed iframe. No server to run. This is the simplest kind of app and the one every publisher can start with.

Runtime tiles

Ship a container image and the platform launches it for each user and proxies your UI to it. The image is pinned by content digest in the signed manifest, so what was reviewed is what runs. Available to verified publishers.

A permission-gated bridge

Your iframe talks to the host over postMessage through the App SDK. Each call goes to the capability broker, which checks the user's grant on the server. Ask for optional permissions at the moment you need them; if the user declines, your app keeps working with less.

Permissions are plain strings

Read a workspace folder, call one named host, invoke a model, send a notification. Each permission has a risk tier the user sees at install, and a network permission always names a specific host.

import { createTileApp } from '@yolo-labs/app-sdk';

const app = createTileApp();
const { workspaceId } = await app.getContext();

// needs "llm.invoke" in the manifest
const res = await app.llmInvoke({ /* model, messages */ });

// optional permission, asked for in context
await app.requestPermissions(['net:api.linear.app']);

app.titleBar.setStatus('3 updates');

Why build for YOLO Studio

Workspaces are where people run their coding agents all day. An App Tile puts your product in that room.

Distribution inside the workspace

Approved apps are listed in the in-product app store with your publisher badge, one click from the grid where people already work.

Next to the agents

Workspace agents can list, install and place app tiles through the workspace MCP server, and with the user’s permission your app can call workspace tools itself.

Models without API keys

With the llm.invoke permission your app picks a model per call from the platform catalog. Usage runs on the user’s credits under a per-app monthly spend cap.

Brokered credentials

Need a vendor API? A granted credential is attached server-side by a gateway bound to that vendor’s host. Your code never sees the secret.

Native host features

Send notifications, show a status in the tile header, set a dock preview, and expand into Zen Mode, all through the same bridge.

An offline dev loop

yolo tileapp validate lints your manifest with the same rules the server enforces. yolo tileapp dev serves your bundle with a mock broker, no account needed.

How publishing works

Five steps from your editor to the store. Every third-party release is signed by its publisher and reviewed by us.

Step 01

Build

Write a manifest and your UI (plus an image, for runtime tiles). Lint with yolo tileapp validate and run it locally against a mock broker with yolo tileapp dev.

Step 02

Sign

yolo tileapp sign has the platform sign your manifest with your publisher key, which lives in Cloud KMS. You never handle the private key. The signature covers the whole manifest, including your permissions and your image digest.

Step 03

Submit

yolo tileapp publish creates an immutable release. Submission verifies the signature, that you own the app ID, that your permissions fit your tier’s ceiling, and that runtime images are digest-pinned.

Step 04

Review

Automated checks run first, then a person on the YOLO team reviews the release. Nothing is auto-approved, and every runtime app gets a manual review.

Step 05

Publish

An approved release goes live in the store. Each new version is a new release and goes through review again; if it asks for new required permissions, users consent again before it runs.

Signing and submission aren't open to outside publishers yet. Early-access partners are set up with a publisher account and key as part of onboarding. Until then you can build, validate and run the same app as a personal app.

Trust is built into the pipeline

Your verification tier sets a ceiling on what your app may ask for, and users see that tier before they install.

Unverified publisher

UI-only tiles

Normal-tier permissions only

Users confirm an extra warning at install

Verified publisher

UI-only and runtime tiles

Permissions up to the restricted tier; sensitive and restricted requests get closer review

Verified badge on your listing and install screen

What users can count on

The people installing your app are trusting it with their workspace. These rules hold for every app you publish.

Consent first

People see every permission, with its risk level, before they install. Optional permissions can be declined, and access can be narrowed or revoked at any time.

Checked on every call

Apps reach the workspace only through the capability broker, which checks the grant server-side on each request. The app never receives the user’s token.

Hard limits

Permissions that drive agents, git credentials or the shell are never grantable to a marketplace app, whatever the publisher’s tier. Risky combinations, like a secret plus egress to another host, are rejected.

A real kill switch

We can revoke an app’s grants, delist it and stop its running instances. Revoking a publisher key removes that publisher’s apps from the store, and a release that crashes too often is pulled automatically.

For companies and ISVs

If your product already has an API, an App Tile is a way to put it in front of developers while they work, with their agents a call away.

Early-access partners work with us directly: we set up your publisher account, talk through verification, and review your first releases with you.

Verified publisher tier

Runtime tiles, a higher permission ceiling, and the verified badge on your listing.

Bring your own backend

Ship a container image pinned by digest, or keep a UI-only tile that calls your API on a named host.

Keys you never handle

Your publisher signing key lives in Cloud KMS — no private keys to store or leak.

A person on the other end

Tell us about your product when you apply and we’ll be in touch to talk it through.

Apply as a company

Questions

Can I publish to the marketplace today?

Not yet. The submission and review pipeline is built, but it isn’t open to outside publishers. We’re onboarding a small group of early-access partners first. Apply below and we’ll be in touch.

What can I build right now?

Personal apps. Any YOLO Studio user can build an app tile for their own workspaces with the same manifest, permissions and dev loop, and publish it with yolo tileapp publish --personal. No signing or review, but only you can see and install it.

Do I have to manage signing keys?

No. Your publisher key is created and held in Cloud KMS, and the platform signs on your behalf when you run yolo tileapp sign. You never handle or store the private key material yourself.

What decides whether I’m verified or unverified?

Verification is granted by YOLO Labs. During early access we work with each partner directly, so tell us about yourself or your company when you apply.

How long does review take?

We don’t publish a turnaround time yet. Every release is reviewed by a person during early access, and we’ll keep you posted on where yours stands.

Can I charge for my app?

Not yet. Paid apps and payouts aren’t available in the marketplace today.

Is the App SDK on npm?

Yes: npm i @yolo-labs/app-sdk. It handles the bridge so you don’t hand-roll postMessage. The yolo CLI, which includes the tileapp commands, is available too.

Does it cost anything to apply?

No. Applying for early access is free.

Apply for early access

Marketplace publishing opens to a small group of developers and companies first. Leave your email and we'll follow up to learn what you want to build.

​
We collect your email address, plus standard request data (IP address, browser and referring page) used to prevent abuse, and use it only to follow up about developer access. See our privacy page.

Want to start now? Build an App Tile for your own workspaces. No review, no waiting.

Build a personal app today
YOLO Labs

© 2026

YOLO Studio


Security


Docs


yololabs.ai