ChatGPT Plugin Submission Guide: What OpenAI Review Requires
TL;DR: A step by step account of submitting a ChatGPT plugin after the DevDay 2026 redesign: developer verification, domain verification, the tool scan, annotations, five positive and three negative test cases, the reviewer account, the walkthrough video, and what happens after approval. Every requirement is linked to the OpenAI page it comes from.
What does OpenAI require to submit a ChatGPT plugin?
As of 9 October 2026, a ChatGPT plugin with an MCP server needs: an OpenAI organization with individual or business identity verification, a public HTTPS MCP endpoint with domain verification, a clean tool scan with readOnlyHint, destructiveHint and openWorldHint set on every tool, five positive and three negative test cases, a reviewer test account that works without MFA, a walkthrough video, and website, support, privacy policy and terms links. OpenAI publishes no review timeline, and approval does not publish the plugin automatically. HouseofMVPs prepares and files this package as part of its plugin builds, from $4,999. Book a 30 minute scoping call.
Submitting a ChatGPT plugin is less like publishing a web page and more like passing an inspection. OpenAI checks who you are, scans what your server exposes, runs the cases you provide, and keeps scanning after you are listed.
This guide follows the process in the order you will meet it. It reflects OpenAI's documentation as read on 9 October 2026. That documentation is undated and changes often, so treat the linked pages as the authority.
Before you start
Three things can stop a submission before any code matters.
Identity verification. The organization that will own the plugin must complete individual or business verification in the OpenAI Platform dashboard. The verified name is the one shown in the directory, and OpenAI says verification is enforced during review.
Permissions. Organization owners can submit. Anyone else needs the Apps Management Write permission, which an owner grants through organization roles.
Data residency. Projects with EU data residency cannot submit MCP plugins for review. You need a project with global data residency.
Also decide now whether the plugin is public at all. OpenAI's review page says to submit only if the plugin will be public in the countries you select. For internal use, a custom MCP server connection inside your workspace is the right route, with no review.
Step 1: A public MCP server
The server must sit on a publicly accessible domain, on HTTPS, using Streamable HTTP. A local or test endpoint will not pass. If the server returns interface elements, it needs a content security policy that lists the exact domains they load from.
Prove you own the host by serving the token the portal gives you, as plain text, at /.well-known/openai-apps-challenge.
One decision here is hard to undo: the origin. Changing the scheme, hostname or port later means a new plugin. Pick the production hostname before you submit.
Want this ChatGPT plugin built for you in 14 days to submission?
HouseofMVPs delivers from $4,999 fixed. 50+ shipped. Same team scopes, builds, and supports.
Step 2: Annotate every tool
Each tool must carry three explicit booleans in its annotations:
| Annotation | Set to true when | Common mistake |
|---|---|---|
readOnlyHint | The tool only reads. Anything that writes, sends, uploads or queues is false. | Marking a tool that logs or triggers a job as read only |
destructiveHint | The tool can delete, overwrite, cancel, revoke access or send something that cannot be recalled | Setting false because the action can be undone. OpenAI says undo alone does not justify false |
openWorldHint | The tool reaches the public internet or open ended outside entities | Leaving it unset on a tool that posts to a public platform |
OpenAI's guidelines add that annotations "do not grant permission or replace authentication". They describe the tool. They do not protect it.
Tool names should be unique, readable and usually verbs, such as get_order_status. Descriptions must match what the tool does, say when to use it and state its limits. Names that include "best" or "official" are out. So is appending "MCP", "MCP Server" or "Plugin" to your product name in the listing.
Step 3: Upload and pass the automated checks
Upload the plugin as a ZIP from the Plugins page. Include the MCP server reference in the first upload, because a server cannot be added later to a plugin that started as skills only. Keep secrets out of the ZIP.
The portal then runs two sets of checks. Metadata and skills checks cover the package. MCP checks connect to your server, authenticate if needed, and scan the tools. The scan imports names, descriptions, schemas, security schemes, annotations, interface resources and server instructions. Fix what it reports, then use Reconnect or Rescan.
Step 4: Write the eight test cases
This is where most of the thinking goes.
Five positive cases. Each has a scenario, the user's prompt, the tools you expect to run and the result you expect. Run every one against the reviewer account before you submit, because OpenAI will.
Three negative cases. Each has a prompt where the plugin should not act, why, and what should happen instead: a refusal, a clarifying question or a safe fallback.
Good negative cases are the ones a careless plugin would get wrong: a request that sounds related but belongs to ChatGPT itself, a request for another user's data, a destructive request with missing details.
OpenAI's review page adds expectations for the results. Output should match the request closely, leave out irrelevant information and personal identifiers, and work on the ChatGPT and Codex surfaces you support.
Step 5: The reviewer account
If the plugin needs sign in, reviewers need a dedicated test account with sample data. It must work with no extra setup: no MFA, no code sent by email or SMS, no magic link, no private network. Enter the credentials in the dashboard's secure form, never in the ZIP. The package format rejects fields such as test_credentials.
Check that the account has not expired on the day you submit. An account that needs a fresh sign up is rejected.
Step 6: The listing and the paperwork
You will need:
- A display name and a short description, each 30 characters or fewer
- A longer description and up to three starter prompts
- Icons in the required sizes
- Website, support, privacy policy and terms of service links
- A walkthrough video at an accessible URL that shows the test cases
- Release notes
- A commerce declaration
The privacy policy has to cover the categories of data collected, why, who receives it, how long it is kept and what control users have. Listing copy must not mention prices, trials or discounts.
Step 7: Submit, then wait
Choose Submit for review and complete the policy attestations. Only one review can be active per plugin.
Feedback arrives by email. If the plugin is rejected, fix what was raised and submit a corrected package, or reply to the rejection email with your reasoning to appeal.
OpenAI publishes no timeline. It also asks developers to contact its press team before any press release or public announcement about a plugin, so hold the launch post.
Step 8: Publish
Approval does not list the plugin. Open the approved version and select Publish plugin. It then appears in the directory shared by ChatGPT and Codex. You cannot request better placement.
After launch: you are still being reviewed
OpenAI scans hosted MCP servers daily and compares what it finds with the approved definitions.
- New tools stay unavailable until they pass checks.
- Changed tools keep their approved definition while the update is held.
- Removed tools disappear after the next scan.
- Each tool is judged separately, so one flagged tool does not block the others.
If you think a held change was flagged wrongly, appeal it from the portal. Automatic updates pause while an appeal is open. If the finding is fair, fixing and rescanning is faster.
Keep the server compatible with the approved schemas at all times. Plugins can be removed for being inactive, unstable or out of compliance.
The requirements that are easiest to miss
This list is drawn from OpenAI's published requirements. These are the ones a careful team still overlooks:
- An annotation that does not match what the tool does
- A reviewer account behind MFA or an email code
- A privacy policy that omits a data category the tools return
- Tools that return internal IDs, logs or more personal data than the request needs
- A description that promises more than the tool supports
- A project in EU data residency
- Starting as skills only and trying to add a server later
If you would rather not do this yourself
HouseofMVPs builds the server and the full submission package, then files it inside your OpenAI organization. Plugin Launch is $4,999 fixed and reaches submission in 14 days. We are independent of OpenAI, and the review itself is theirs.
See ChatGPT plugin development, or start with the readiness checker. For the bigger picture, read what DevDay 2026 means for SaaS companies.
Sources and verification
Each claim below was read from the linked page on the date shown. Vendors change their documentation without notice, so check the source before relying on a detail.
| Claim | Source | Source date | Verified |
|---|---|---|---|
| Submission steps, permissions, domain verification, automated checks, five positive and three negative test cases, reviewer credentials, video walkthrough, publishing, daily scans, appeals, manifest limits | OpenAI developer docs, Upload and submit your pluginFirst party | Undated | 9 Oct 2026 |
| Public hosting, EU data residency restriction, tool scan contents, verification enforced during review, no expedited review, continuous review rules, origin changes, press contact | OpenAI developer docs, Remote MCP server review requirementsFirst party | Undated | 9 Oct 2026 |
| Annotation definitions, naming rules, privacy policy contents, restricted data, commerce limits, no trial or demo plugins | OpenAI developer docs, Plugin guidelinesFirst party | Undated | 9 Oct 2026 |
| OpenAI's own submission helper generates exactly five positive and three negative cases and treats missing hints as a blocker | openai/plugins on GitHub, chatgpt-app-submission skillFirst party | Undated | 9 Oct 2026 |
| OAuth 2.1 requirements for authenticated plugins | OpenAI developer docs, AuthenticationFirst party | Undated | 9 Oct 2026 |
HouseofMVPs is an independent development studio. We are not affiliated with, endorsed by or partnered with OpenAI. ChatGPT is a trademark of OpenAI. We build the plugin and prepare the submission. OpenAI controls review, approval, ranking and publication.
Frequently Asked Questions
Frequently Asked Questions
Turn your product into a ChatGPT plugin
Fixed price from $4,999. Built, tested and submitted for OpenAI review in 14 days. OpenAI controls approval.