Registry schema and deploy contracts
alchemy.new deploys versioned packages from its registry. Each release publishes alchemy.new.jsonc next to the archive. That file is the project contract. The live JSON Schema is the machine source of truth. This page describes schema version 1.
Project manifest
Place alchemy.new.jsonc at the package root and publish it as its own object. Do not put it in the archive. alchemy.new reads the stored manifest, never a branch. The file can use JSON with comments. The app rejects a release with a missing or invalid manifest.
Set $schema to https://alchemy.new/schema/project.json so editors can validate the file.
Schema fields
The tables below come from the live schema at /schema/project.json. Do not add fields that the schema does not declare. Unknown fields fail validation.
ProjectManifest fields
Publisher
publisher is a required object. Only name is required inside that object.
ProjectPublisher fields
Deployment
deployment names the Alchemy entrypoint and the default run. The registry archive is the artifact. alchemy.new does not install dependencies or build the app.
ProjectDeployment fields
Packages and releases
source names an alchemy.new package. Publishers upload a ready archive and a separate manifest. alchemy.new resolves org/project to an exact version and reads the manifest stored with that version. A manifest whose source names a different package fails.
Registry package
org and project name the package. A deploy without a pinned version uses the latest non-yanked stable version. The archive root contains the entrypoint, built output, and node_modules/alchemy/bin/cli.js. It must not contain alchemy.new.jsonc. The runner downloads the archive, checks its sha256, and writes the stored manifest into the package root. It does not install dependencies.
RegistryPackageSource fields
Container images
The sandbox has no Docker daemon, so alchemy.new cannot build container images. A stack that uses Cloudflare Containers must reference a prebuilt image in a public registry with image, pinned by digest. A container that builds from main, context, or dockerfile fails the deploy.
During the deploy, alchemy.new copies each image into the deployer's Cloudflare registry, so Cloudflare starts containers from its own cache. Publish images from release CI to a registry such as GitHub Container Registry. Docker Hub works, but it limits anonymous pulls for each IP address.
Parameters
Each parameter declares an environment variable name and a display label. The one-click defaults and the Customize form come from this list. required and secret are required booleans. type is optional.
A select input can declare options. A secret field uses a masked control. Secret values stay out of shared URL state and short links.
Every listed project deploys in one click. With the default choices applied, each active required parameter needs a default or a generate rule. alchemy.new rejects a manifest that breaks this rule. Feature environment variables should stay optional, with a safe public default or a fail-open description.
generate: "password" creates a 24-character password at deploy time when the field is empty. Use it for a password that a person signs in with. The deploy result shows it to the deployer once, and it never appears in logs, share links, or deployment output. Every deploy creates a new one, so use it only when the app reads the variable on every deploy.
Create machine secrets, such as signing and encryption keys, in the stack with Alchemy.Random when the variable is empty, and declare the parameter with required: false. Alchemy keeps the value in state, so later deploys reuse it.
ProjectParameter fields
Implementation paths
Use paths when one detail has more than one implementation. The first case is a database select with d1 and planetscale. Cloudflare D1 is the default. PlanetScale is not a cloud provider and must not appear in deployment.providers.
Gate path-scoped secrets with when. Those fields stay hidden and are not required until the matching path is selected. The default path stays one-click.
ImplementationPath fields
ParameterWhen fields
Example
This example matches schema version 1 and deploys in one click. It includes a public string with a default, a generated password, an optional secret, a simple select, and a database implementation-path select with a gated PlanetScale secret. The file can include comments when you store it as JSONC.
Publisher skill
Copy the publish-to-alchemy-new skill into an Alchemy repository. The skill writes or updates alchemy.new.jsonc, checks the one-click rule, and prepares a ready archive plus the manifest upload. The local write does not need a live registry session.
A deploy link works only after a release that contains alchemy.new.jsonc and a ready deploy artifact is published. alchemy.new reads the manifest from the release, so a committed but unreleased file is not deployable. After the release, the skill asks whether to upload the package for review. Upload is optional.
Start from an empty parameters list when the stack can deploy without project-specific env:
Listing and verification
Submit an alchemy.new package (org/project) from the alchemy.new home page. alchemy.new checks the latest release before it accepts the submission: the release must ship a ready deploy artifact, and the manifest must deploy in one click. A submission does not grant verification.
alchemy.new reviews publisher identity in a separate step. After that review, a project can receive a verified badge and a higher search rank. Featured and verified projects rank before unverified projects.
Deploy links
Open the latest published version of a registry package:
Add version to pin an exact semantic version.
Add action=deploy to start a one-click deploy as soon as the visitor connects a cloud account.
Do not put secrets in a URL. Share links exclude secret parameters, provider credentials, and GitHub tokens.
For agents
Agents can read the compact or full machine guide, or connect directly to the MCP endpoint for registry search, deployment planning, and deployment tools.
- llms.txt
Short agent index for the registry and MCP endpoint.
- llms-full.txt
Longer agent guide for search, plan, and deploy tools.
- MCP endpoint
Streamable HTTP server at the API base URL, https://alchemy-new-api-pre-130.jonbeckman.workers.dev/mcp.
Brand kit
Live text experiment: the Manrope wordmark is rendered as a responsive puffy cloud field with pointer dissolve controls.