Sponsored installs and follow-up chips
Short answer: a sponsored install is a labelled chip under a coding agent's reply that, when the developer picks it and confirms, asks the agent to add your npm or PyPI package or MCP server at one pinned version and integrity hash, then do one task with it. It runs on the desktop app's Code mode and in VS Code only, is never offered to an agent on auto-approve, and every command still waits for the developer. It is priced per confirmed install, or per click.
This puts text an advertiser wrote into an agent that can write files and run commands, so it carries more safeguards than any other format. They are all below.
What you supply
| Field | What it takes |
|---|---|
| Company and label | 60 characters each - the label is the chip's text |
| Package source | npm, PyPI, an MCP server published on npm, or a remote MCP server |
| Package name and version | One exact version - 2.45.1, never ^2, a tag or latest. Git, file and URL installs are refused |
| Integrity | npm: the sha512-… integrity from the registry. PyPI: the sha256 of the release file. A remote MCP server gives its https URL and the version it reports instead |
| Follow-on prompt | Up to 400 characters: what the agent does once it is installed |
| Landing URL | On a domain your organisation has verified |
You do not write the install instruction itself. VibeFree builds it from the frozen fields - "Install exactly [email protected]… Do not use any other version, a version range or latest" - and your prompt follows it. The chip states what it does next to your label: "installs [email protected]" or "adds MCP server …".
Before it can run
- A dry run in the sandbox. Your prompt runs against a small template Next.js project with VibeFree's house model and every tool stubbed: files are written in memory, commands are recorded and answered with canned output, and nothing is installed. The transcript shows each step, the files written, the commands, the installs and any MCP server added, and flags an install without an exact version, at a different version, or one that never happened. A passing dry run that matches the creative as it stands is required to submit it.
- A registry check at checkout. The exact version must exist on npm or PyPI, the integrity you gave must match it, and it must not be deprecated or yanked.
- A person reviews it, with the dry-run transcript attached, against the ad policy.
- Frozen at approval. The prompt, package, version, integrity and MCP URL are hashed when approved. Any change sends the creative back to review.
After approval
- A daily package watch reads each pinned package back from its registry. If the version was deprecated, yanked or unpublished, its integrity changed, or a maintainer was added or removed, the install pauses until a person has looked.
- A kill switch. One admin action pulls sponsored actions from every app, checked when a chip is served and again when it is clicked.
Where and when it is offered
- The desktop app in Code mode, and the VS Code extension. Not the web app or the mobile app, which have no agent that runs tools.
- Never on auto-approve, never from Remote Control. A turn whose agent is approving its own tools, or a turn sent from Remote Control, is never offered a sponsored chip.
- Confirmed first. Picking the chip opens "Run this sponsored install?", which repeats what will be installed and what happens next. Nothing is sent to the agent until the developer chooses "Send to the agent".
- Every command still asks. The developer's own approval settings apply to each step; in VS Code a sponsored turn asks before every command, whatever had been always-allowed before.
How a completed install is counted
After the turn, the app looks on disk, never at what the agent said it did: an npm package in the project's node_modules at the pinned version; an npm MCP server in the MCP config at name@version (or in node_modules); a PyPI package as a name-version.dist-info in a virtual environment inside the project (.venv, venv or env) - a global install is not counted, because nothing ties it to the click; a remote MCP server named by URL in the MCP config. A confirmed install is billed once.
Plain follow-up chips
A sponsored follow-up chip without an install sends your reviewed prompt (up to 600 characters) into the agent when the person picks it, beside the ordinary suggested next steps and labelled Sponsored. It runs on every app, is priced per click, and follows the same rules: a passing dry run, frozen at approval, the kill switch, and never on auto-approve or Remote Control. A sponsored template or starter kit is gentler again - its prompt is put in the message box for the person to read and edit before sending. See every placement in the conversation.
Frequently asked questions
Can I pay for developers to install my npm package?
You can pay for an offer to, which the developer chooses. A sponsored install is a labelled chip under a coding agent's reply; if the developer picks it and confirms, the agent is asked to add your npm or PyPI package or MCP server at one pinned version and then do one task with it. It is priced per confirmed install or per click.
Why must a sponsored install pin an exact version?
Because the prompt runs inside an agent that can write files and run commands. An exact version and its integrity hash, frozen at approval, mean every developer gets the release that was reviewed - never latest, a range, a tag or a git branch that could change underneath them.
What happens if my package changes after approval?
A daily watch reads each pinned package back from its registry. If that version is deprecated, yanked or unpublished, its integrity hash changes, or a maintainer is added or removed, the install is paused until a person has looked.
Does the agent install a sponsored package without asking?
No. The chip says what it installs, picking it opens a confirmation, and the developer's own approval settings still apply to every command and file change. Sponsored chips are never offered to an agent on auto-approve or to a turn sent from Remote Control.
Which VibeFree apps show sponsored installs?
The desktop app in Code mode and the VS Code extension - the two with a coding agent that runs tools. Plain sponsored follow-up chips, which only send a prompt, run on every app.
Start a campaign, read what the coding agent asks before it acts, or see the formats and specs.
Related pages
- Sponsored rewards - Opt-in video, quizzes, paid surveys, interviews and trials on the earn page.
- Is VibeFree really free? - What "free forever" means, and what pays for it.
- A no-subscription LLM - Why there is no paid tier to upgrade to.
- Or browse every VibeFree guide.