Pattern: provider extension using api_out
Use this pattern when Ormuz calls an external service API. The partner then provides the provider contract and the merchant configures the credentials Ormuz needs.
The pattern
Ormuz calls the provider contract through an explicit contribution and a declared api_out channel.
Declare only the required capabilities. A channel api_out does not automatically give the plugin the right to read or modify platform objects.
Declare the configuration
Secrets supplied by the merchant live in the runtime contract configSchema and must be typed secret. Help text is localized separately; do not place a description or example directly on the field. The manifest then references those fields from the channel that consumes them.
configSchema: {
fields: [
{ key: 'api_key', type: 'secret', required: true, channel: 'api_out' }
]
}Declare api_out
In extension.yaml, add the channel under spec.channels :
spec:
channels:
- kind: api_out
auth:
scheme: api_key
secret_fields:
- api_keyThe channel is declarative: it describes the exchange boundary and references the required configuration fields. Provider calls remain runtime behavior and are never serialized in the manifest.
Add a contribution
Start from the business need, then choose the appropriate surface: a node for explicit composition in a process, a Tool for a selectable Agent task. Do not add both for symmetry. See Design a node and Design an Agent Tool.