Skip to main content

Publisher Content packages

Publisher Content is a package type that lets you host supplemental game content on your own content delivery network (CDN) while the platform continues to manage installation, background download, integrity validation, and the user experience. Publisher Content packages are supported on XBOX One family consoles, and XBOX Series X|S consoles starting with the October 2026 GDK (GDK 2610). Publisher Content packages behave like downloadable content (DLC) at runtime, they install alongside a base game, mount into your process, and unmount when the game exits. Unlike DLC, they aren’t ingested through Partner Center, have no store ID and aren’t sold or licensed through Microsoft Store. Your service is the source of truth for what content ships, when it updates, and who receives it.

When to use Publisher Content

Consider Publisher Content when you want to do any of the following:
  • Ship small live-service updates (config data, tuning tables, small asset packs) without going through Store ingestion.
  • Deliver publisher-branded add-on content that all players of the base game receive automatically.
  • Reuse an existing CDN and content pipeline that you already operate for your games on other platforms.
  • Keep control over rollout timing, regional targeting, or A/B tests at the CDN layer.
Publisher Content isn’t a replacement for DLC. Continue to use standard DLC packages when you need per-user entitlements, purchase flows, or Microsoft Store licensing.

Requirements and constraints

  • One Publisher Content package per base game.
  • Available to any player who owns the base game. There’s no per-user licensing check.
  • Supported on XBOX One family consoles, and XBOX Series X|S consoles.
  • The base game and the Publisher Content package must use the same package format. For example, if the base game is packaged as MSIXVC2, then the Publisher Content package must also be MSIXVC2.
  • The Publisher Content package must be small, i.e. less than 1 GB in size.
  • The Publisher Content package is signed with publisher-provided signing material, and the base game embeds the corresponding public material so the platform can validate Publisher Content that claims to belong to it. The base game itself is signed the same way as any other title. The signing material differs by package format:
    • XVC and MSIXVC — A raw CNG signing key. RSA-4096 is required.
    • MSIXVC2 — An X.509 certificate with an RSA-4096 key. The certificate must be currently valid, have an accessible RSA private key, and permit digital signatures.
The platform doesn’t provide content secrecy for Publisher Content packages. Unlike Microsoft Store DLC, Publisher Content isn’t encrypted for distribution: anyone who downloads the file from your CDN can inspect its contents. If you need confidentiality for portions of your payload, encrypt those portions inside the content itself before packaging.

How the pieces fit together

At a high level:
  1. You declare a manifest URL on your base game in MicrosoftGame.config. This URL points to a small JSON file that you host on your CDN and can update at any time.
  2. You author a Publisher Content package that references the base game by store ID.
  3. You sign the Publisher Content package with your publisher signing material. The base game embeds the corresponding public material so the platform can validate any Publisher Content that claims to belong to it.
  4. When a player installs the base game, the platform fetches your manifest, reads the CDN URL of the current Publisher Content package, and queues its installation.
  5. At runtime, your game enumerates installed packages and mounts the Publisher Content package the same way it would mount DLC.
To ship a new revision of the content, upload a new package to your CDN and update your manifest to point at it. The platform picks up the change on the next update check.

Set up your base game

In your base game’s MicrosoftGame.config file, add a PublisherContent element with a ManifestUrl child. The URL must be reachable by every device that runs your game.
For more information about these elements, see PublisherContent Element (MicrosoftGame.config) and ManifestUrl Element (MicrosoftGame.config).

Author the Publisher Content package

Create a MicrosoftGame.config alongside your Publisher Content payload. Reference the base game by its store ID with the PublisherContentBaseProduct element.
For more information, see PublisherContentBaseProduct Element (MicrosoftGame.config).
Don’t include an AllowedProducts element in a Publisher Content package. That element identifies a package as standard DLC and is mutually exclusive with PublisherContentBaseProduct.

Author the manifest

Host a small JSON manifest at the ManifestUrl you declared in the base game. The manifest contains a single url field that points to the current Publisher Content package on your CDN. Be sure not to change the Publisher Content at the url once published, and instead publish every new Publisher Content package version to a new url and update the manifest accordingly.

Generate publisher signing material

The publisher signing material lives on your build machine and is referenced by name (or thumbprint) when makepkg packs the base game and the Publisher Content package. The exact form depends on the package format you target.
Treat the publisher signing key or the certificate’s private key as a production secret. Anyone with access to the private material can produce Publisher Content packages that the platform will accept as coming from you.

For XVC and MSIXVC packages

Create an RSA-4096 signing key in a Windows CNG key storage provider on the build machine. The following PowerShell example creates an exportable RSA-4096 signing key named MyTestPubXvcSigningKey in the Microsoft Software Key Storage Provider.
Pass the resulting key name to makepkg pack via /usepublisherkey. If you use a CNG key storage provider other than the default, also pass its name via /publisherkeyprovider.

For MSIXVC2 packages

Create an X.509 certificate whose subject key is an RSA-4096 key, and install the certificate and its private key in the CurrentUser\My certificate store. The following PowerShell example creates a self-signed RSA-4096 certificate in CurrentUser\My and exports its .cer file.
Pass either the exported .cer path or the certificate thumbprint to makepkg pack via /usepublishercert. If the certificate is installed in a store other than My, also pass its name via /publishercertstore.

Package the base game and the Publisher Content

Both pack invocations must reference the same key or certificate.

For XVC and MSIXVC packages

Package the base game:
Package the Publisher Content:
If you use a CNG key storage provider other than the Microsoft Software Key Storage Provider, add /publisherkeyprovider <providername> to both commands.

For MSIXVC2 packages

Package the base game:
Package the Publisher Content:
If the certificate is installed in a store other than CurrentUser\My, add /publishercertstore <store> to both commands. For details, see Make package (makepkg.exe).

Publish and update

Publisher Content packages are hosted on your CDN and can’t be uploaded to Partner Center. makepkg upload rejects Publisher Content packages in both loose and packaged form. The base game package uploads normally through the standard Partner Center flow.
  1. Upload the packaged Publisher Content XVC to your CDN at the URL you referenced in your manifest.
  2. Upload your manifest JSON to the URL you declared in the base game’s ManifestUrl element.
  3. Submit and ship the base game through Partner Center as usual.
To roll out an update:
  1. Upload the new Publisher Content package to your CDN at a new URL. Do not replace the old Publisher Content package.
  2. Update the url value in the manifest to point at the new package.
  3. Upload the updated JSON file to the URL you declared in the base game’s ManifestUrl element.
Installed devices detect the change on the next update check and download the new Publisher Content package in the background.

Access Publisher Content at runtime

At runtime, discover installed Publisher Content the same way you discover DLC, by using XPackageEnumeratePackages, then mounting the returned package with XPackageMountWithUiAsync. Pass XPackageKind::PublisherContent to filter enumeration to Publisher Content only:
If you already have a package identifier from another source, use XPackageGetPackageKind to determine whether it refers to a Publisher Content package:
Because Publisher Content isn’t licensed through Microsoft Store, you don’t need to call XStoreQueryPackageIdByKind or perform a store license check before mounting.

Uninstall behavior

When a player uninstalls the base game, the platform automatically uninstalls the associated Publisher Content package. You don’t need to remove it explicitly from your game code.

See also

Last modified on October 6, 2026