Publish and install
Host an activity package on a NuGet feed, install it in Studio, and make it available to your Robots through the tenant's package feeds.
An activity package reaches people in two places: Studio, where authors install it into projects, and Robots, which restore it when a job that uses it runs. Both restore it from NuGet package sources, so the first step is to put it on one. Choose where to host the package# Host your package on a NuGet feed you control, such as a NuGet v3 server in your network, a hosted package registry, or a shared folder: PowerShellCopydotnet nuget push .\out\Contoso.Invoices.Activities.1.2.0.nupkg --source https://packages.example.com/contoso/v3/index.json --api-key <key> The Orchestrator's own feed does not take activity packagesThe built-in orchestrator feed of your tenant accepts automation packages and workflow libraries. It refuses code activity packages, so host yours on a feed of your own and add that feed to Studio and to the tenant's package feeds. Your package's dependencies must be restorable from the same places: third-party libraries from nuget.org or a mirror, and Velophex.Workflow.Sdk at the version you built against. Install in Studio# In Studio, open the Package Manager (Ctrl + P) and select Settings. Under Add a source, enter a name and the feed URL or folder, then select Add. For a private feed, select the source, enter User name and Password, and select Sign in. Studio stores the password in Windows Credential Manager. Select Trusted only if you trust every package on that source. Studio runs a package's design assembly only when the package comes from a trusted source or is signed by a pinned signer. In All packages > Browse, find your package, pick a version and select Install, then Review and Apply. Studio resolves the package and its dependencies, writes the exact version to project.json and the whole resolved set, with content hashes, to project.lock.json, then restores. Applying is all or nothing: if any package cannot be restored, Studio undoes the change. See Manage packages. When an author installs a package that is unsigned, comes from an untrusted source or asks for new capabilities, Studio asks for consent and shows the capabilities your activities declare. Make the package available to Robots# When you publish an automation that uses your activities, the automation package records the exact version and hash of your package. A Robot restores that version when it runs a job, from its own installed feed first and then from the tenant's package feeds in order. Add your feed to the tenant: In the Orchestrator, go to Tenant ▸ Settings ▸ Package feeds and select Add feed. Enter a Name, choose Remote feed (NuGet v3) (or Local folder for a share every Robot can reach) and enter the Location. Under Package patterns, limit the feed to your packages, for example Contoso.*. Choose Authentication: None, or Username and password with the password or API key. Robots receive the credential only while they restore for a job. Select Add feed, then place it in the list with the arrows in the Order column. Every enrolled Robot of the tenant receives the change. See Tenant settings. A single machine can also be pointed at one feed of its own, with PACKAGEFEED at install time or --feed when enrolling; that feed replaces the tenant's own feed as the machine's second source. Prefer tenant package feeds, which apply to every Robot. See Install on Windows. Reserved package idsA package whose id starts with VeloPhex. or Velophex. must carry the VeloPhex signature and is refused otherwise. Never publish your own packages under those prefixes. Verify# In Studio, install the package from your feed into a project, use an activity and run the workflow. See Run and debug. Publish the project to the Orchestrator. See Publish to Orchestrator. Start a job on a Robot that has not used the package before. It should succeed. If it fails while restoring, the job's error names the package that could not be found; check the feed, its package patterns and its credentials. Ship an update# Pack a new version and push it to your feed. Never replace an existing version. In each Studio project that should use it, update the package in the Package Manager (Updates tab), then test and publish the project again. Jobs of automations published before keep running the version they pinned, until you publish a new automation version that uses the update. Next steps# Troubleshooting Signing packages
Choose where to host the package
Install in Studio
Make the package available to Robots
Verify
Ship an update
Next steps