Context card
Extension points of a platform
How does a platform SDK let outside code extend a host application?
The short answer
A platform SDK defines where and how outside code may plug into a host application: named extension points, a manifest that declares what the extension contributes and which permissions it needs, APIs the extension may call and usually a sandbox that isolates it. The host loads the extension and calls it at the declared points — control stays with the host.
For: Developers and technical writers building or documenting extensions
Key points
- Extension points are the places where the host accepts contributions — commands, views, data hooks.
- A manifest declares what the extension adds and which permissions it requests.
- The host calls the extension (inversion of control), not the other way round.
- Sandboxing and permission scopes limit what an extension can reach.
- Compatibility promises and deprecation paths decide how long an extension keeps working.
The context
Host and extension
A platform SDK is a software framework in the strict sense: the host application defines the structure and calls the extension. The SDK documents the extension points, supplies the APIs the extension may call and tools to build, test and publish it.
Manifest and permissions
A manifest lists the extension's contributions and the scopes it needs. Authorization is enforced by the host: an extension that has not requested access to data does not get it. Many platforms run extensions in a sandbox or on the platform's own runtime.
Why the contract matters
Extensions depend on the host's interface contract. Backward compatibility and published deprecation paths decide whether an extension survives the next host release.
See the encyclopedia article Platform SDKs.
Questions readers ask next
- Is a plug-in the same as an extension?
- In most platforms the words are used for the same thing: code that the host loads at a defined extension point. Some platforms reserve one of the terms for a particular packaging format.
- Why can an extension not simply call any internal function of the host?
- Only documented APIs are part of the contract. Internal functions can change without notice, and the sandbox usually blocks them.
Sources
- Extension API — Visual Studio Code
- Forge — Atlassian Developer
Review log and changes
Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.
Reviewed
No corrections or additions since publication.