An App Tile is a small app that sits on a YOLO Studio workspace grid, beside the agents doing the work. It reaches the workspace only through permissions the user grants, and every third-party release is signed by its publisher and reviewed by us before anyone can install it.
Marketplace publishing isn't open to outside developers yet. Personal apps, visible only to you, are live for every YOLO Studio user.
One manifest declares who you are, what your app is, and exactly what it may touch. The rest is a web app.
A static bundle of HTML, CSS and JavaScript rendered in a sandboxed iframe. No server to run. This is the simplest kind of app and the one every publisher can start with.
Ship a container image and the platform launches it for each user and proxies your UI to it. The image is pinned by content digest in the signed manifest, so what was reviewed is what runs. Available to verified publishers.
Your iframe talks to the host over postMessage through the App SDK. Each call goes to the capability broker, which checks the user's grant on the server. Ask for optional permissions at the moment you need them; if the user declines, your app keeps working with less.
Read a workspace folder, call one named host, invoke a model, send a notification. Each permission has a risk tier the user sees at install, and a network permission always names a specific host.
import { createTileApp } from '@yolo-labs/app-sdk';
const app = createTileApp();
const { workspaceId } = await app.getContext();
// needs "llm.invoke" in the manifest
const res = await app.llmInvoke({ /* model, messages */ });
// optional permission, asked for in context
await app.requestPermissions(['net:api.linear.app']);
app.titleBar.setStatus('3 updates');Workspaces are where people run their coding agents all day. An App Tile puts your product in that room.
Approved apps are listed in the in-product app store with your publisher badge, one click from the grid where people already work.
Workspace agents can list, install and place app tiles through the workspace MCP server, and with the user’s permission your app can call workspace tools itself.
With the llm.invoke permission your app picks a model per call from the platform catalog. Usage runs on the user’s credits under a per-app monthly spend cap.
Need a vendor API? A granted credential is attached server-side by a gateway bound to that vendor’s host. Your code never sees the secret.
Send notifications, show a status in the tile header, set a dock preview, and expand into Zen Mode, all through the same bridge.
yolo tileapp validate lints your manifest with the same rules the server enforces. yolo tileapp dev serves your bundle with a mock broker, no account needed.
Five steps from your editor to the store. Every third-party release is signed by its publisher and reviewed by us.
Step 01
Write a manifest and your UI (plus an image, for runtime tiles). Lint with yolo tileapp validate and run it locally against a mock broker with yolo tileapp dev.
Step 02
yolo tileapp sign has the platform sign your manifest with your publisher key, which lives in Cloud KMS. You never handle the private key. The signature covers the whole manifest, including your permissions and your image digest.
Step 03
yolo tileapp publish creates an immutable release. Submission verifies the signature, that you own the app ID, that your permissions fit your tier’s ceiling, and that runtime images are digest-pinned.
Step 04
Automated checks run first, then a person on the YOLO team reviews the release. Nothing is auto-approved, and every runtime app gets a manual review.
Step 05
An approved release goes live in the store. Each new version is a new release and goes through review again; if it asks for new required permissions, users consent again before it runs.
Signing and submission aren't open to outside publishers yet. Early-access partners are set up with a publisher account and key as part of onboarding. Until then you can build, validate and run the same app as a personal app.
Your verification tier sets a ceiling on what your app may ask for, and users see that tier before they install.
UI-only tiles
Normal-tier permissions only
Users confirm an extra warning at install
UI-only and runtime tiles
Permissions up to the restricted tier; sensitive and restricted requests get closer review
Verified badge on your listing and install screen
The people installing your app are trusting it with their workspace. These rules hold for every app you publish.
People see every permission, with its risk level, before they install. Optional permissions can be declined, and access can be narrowed or revoked at any time.
Apps reach the workspace only through the capability broker, which checks the grant server-side on each request. The app never receives the user’s token.
Permissions that drive agents, git credentials or the shell are never grantable to a marketplace app, whatever the publisher’s tier. Risky combinations, like a secret plus egress to another host, are rejected.
We can revoke an app’s grants, delist it and stop its running instances. Revoking a publisher key removes that publisher’s apps from the store, and a release that crashes too often is pulled automatically.
If your product already has an API, an App Tile is a way to put it in front of developers while they work, with their agents a call away.
Early-access partners work with us directly: we set up your publisher account, talk through verification, and review your first releases with you.
Runtime tiles, a higher permission ceiling, and the verified badge on your listing.
Ship a container image pinned by digest, or keep a UI-only tile that calls your API on a named host.
Your publisher signing key lives in Cloud KMS — no private keys to store or leak.
Tell us about your product when you apply and we’ll be in touch to talk it through.
Not yet. The submission and review pipeline is built, but it isn’t open to outside publishers. We’re onboarding a small group of early-access partners first. Apply below and we’ll be in touch.
Personal apps. Any YOLO Studio user can build an app tile for their own workspaces with the same manifest, permissions and dev loop, and publish it with yolo tileapp publish --personal. No signing or review, but only you can see and install it.
No. Your publisher key is created and held in Cloud KMS, and the platform signs on your behalf when you run yolo tileapp sign. You never handle or store the private key material yourself.
Verification is granted by YOLO Labs. During early access we work with each partner directly, so tell us about yourself or your company when you apply.
We don’t publish a turnaround time yet. Every release is reviewed by a person during early access, and we’ll keep you posted on where yours stands.
Not yet. Paid apps and payouts aren’t available in the marketplace today.
Yes: npm i @yolo-labs/app-sdk. It handles the bridge so you don’t hand-roll postMessage. The yolo CLI, which includes the tileapp commands, is available too.
No. Applying for early access is free.
Marketplace publishing opens to a small group of developers and companies first. Leave your email and we'll follow up to learn what you want to build.
Want to start now? Build an App Tile for your own workspaces. No review, no waiting.
Build a personal app today