Getting listed in the ChatGPT Plugins Directory
ChatGPT and Codex list MCP-backed plugins, formerly ChatGPT apps, in one Plugins Directory. To submit one, you verify your domain and your identity, and you provide five positive and three negative test cases, release notes and a demo recording. Projects with EU data residency can't submit MCP plugins yet.
Below is each requirement we track, with its source and the date we last checked it.
Reviewed by Mohd. Ashhar · Last verified:
Invokary is an independent studio. We are not affiliated with or endorsed by Anthropic, OpenAI or Anysphere.
Requirements
Submission
A domain verification token is served at /.well-known/openai-apps-challenge on the MCP server's host or a parent host.
The submission includes exactly five positive and three negative test cases.
Official sourceSource: OpenAI Developers: Plugin submission errors; OpenAI Developers: Submit pluginsCheckedThe submission includes a demo recording.
The submission includes release notes that summarize the version being submitted and what changed.
Official sourceSource: OpenAI Developers: Submit plugins; OpenAI Developers: Plugin submission errorsCheckedThe submission lists website, support, privacy policy and terms of service URLs.
Reviewer test credentials work without MFA, SMS or email confirmation, or private-network access.
Who can submit
The submitter has a verified individual or business identity.
The submitter has Apps Management write access.
Auth
To restrict access by workspace domain, the OAuth server has a UserInfo endpoint that returns email_verified, and it offers the openid and email scopes.
Review rules
Every MCP tool sets readOnlyHint, openWorldHint and destructiveHint to match what it does, with a justification for each.
Official sourceSource: OpenAI Developers: Plugin submission errors; OpenAI Developers: Remote MCP server review requirementsCheckedAfter publication, OpenAI periodically fetches your MCP tools. Deleted tools are removed as soon as a scan finds them, and changed tools go live once they pass automated checks.
Official sourceSource: OpenAI Developers: Submit plugins; OpenAI Developers: Remote MCP server review requirementsChecked
Limits
Projects with EU data residency cannot currently submit MCP plugins.
Distribution
Published plugins appear in the Plugins Directory shared by ChatGPT and Codex.
Official sourceSource: OpenAI Developers: Submit plugins; OpenAI Developers: Remote MCP server review requirementsChecked
Common rejection risks
More or fewer than five positive and three negative test cases
Requirement: The submission includes exactly five positive and three negative test cases.
A verification token that is not served on the MCP server's host or a parent host
Reviewer credentials that ask for MFA
Requirement: Reviewer test credentials work without MFA, SMS or email confirmation, or private-network access.
A missing website, support, privacy policy or terms URL
Requirement: The submission lists website, support, privacy policy and terms of service URLs.
A workspace domain restriction without a UserInfo endpoint that returns email_verified
Submitting from a project with EU data residency
Requirement: Projects with EU data residency cannot currently submit MCP plugins.
Already rejected?
How we handle it
- Our eval suite runs in CI with 5 positive and 3 negative prompts per platform, matching OpenAI's required test-case format.
- You provide a reviewer test account with realistic data and no MFA, and complete OpenAI identity verification in your name.
- We draft the privacy and security documentation your listing links to.
- We prepare the ChatGPT plugin submission and submit it from your accounts.