The Clever Plugin Library — a private plugin marketplace operated by Clever Solutions, LLC (https://www.clvrsolutions.ai; contact plugin-support@cleversol.ai; privacy: /privacy). It distributes the private Clever Solutions plugins (clvr-plugins) to approved accounts. Access is limited to approved accounts: a human signs in through their own browser at plugins.cleversol.ai and the service issues them a per-user API key, which they paste into their CleverIDE plugin-library client; the client then presents that key as a bearer to list and download the plugins it is entitled to. There is NO public marketplace and NO '/plugin marketplace add'. Endpoints: GET /health -> {"ok":true} (no auth) GET /store -> browsable plugin catalog, HTML (no auth) GET /privacy -> privacy & data-handling page (no auth; HTML) GET /login -> browser sign-in (302 -> /auth/signin): the human opens this to obtain their API key (no auth; HTML) GET /me/plugins -> the caller's entitled plugin catalog, JSON (bearer: Authorization: Bearer ) GET /download -> the whole .plugin archive as raw bytes (?plugin=&version=; bearer) How it works: 1. The human signs in at plugins.cleversol.ai/login in their own browser, reveals their per-user API key once, and pastes it into their CleverIDE plugin-library client. The human is the principal — the server issues the key to them, so a key handed to the client is a legitimate delegated credential. 2. The client lists its entitled plugins with GET /me/plugins, sending the key as Authorization: Bearer . Entitlement is resolved 100% server-side from the key; the client names no org or email. 3. The client downloads a plugin's whole .plugin archive with GET /download?plugin= (optionally &version=) as raw application/zip bytes, verifying them against the sha256 pinned in its own committed manifest. Conventions: /me/plugins and /download are a real-HTTP channel — they use real status codes (200 / 401 / 403 / 404 / 500), the bearer rides Authorization: Bearer , and no &n= nonce is used. The /store browse page is JS-rendered HTML for humans. Pointer: docs/_DOC_ENDPOINT_CONTRACT.md is the authoritative per-endpoint reference. boot_nonce=46711821979f3a62 host=286010ec112308