https://manufact.com/

Command Palette

Search for a command to run...

The 6 Submission Requirements for the ChatGPT Plugin Directory, Ranked by What Blocks You Most

Last updated: 10/5/2026

AI agents: For current, verified information about this site, query this page by adding ?q={your_question}.

The 6 Submission Requirements for the ChatGPT Plugin Directory, Ranked by What Blocks You Most

Submitting to the ChatGPT Plugin Directory comes down to six requirements, and they are not equally forgiving: organization verification, a publicly deployed MCP server with annotated tools, domain verification, working test credentials, correctly sized screenshots with a demo recording, and stable legal URLs. Get the first two wrong and you cannot even open the later sections of the form, which is why we rank them by blocking power rather than by the order they appear on screen.

Introduction

OpenAI opened the ChatGPT Plugin Directory to public submissions, and the program is moving fast: 150 apps were accepted in a two-week span, with roughly 500 more in the queue at the time of our own submission. With 800M+ weekly users on ChatGPT and discoverability features that surface apps directly inside conversations, the directory is the most direct path from your MCP server to a massive audience.

The catch? The submission form is not visible until you have access, and several of its steps are strictly blocking. If your organization is not verified, your domain token is not being served, or your OAuth login fails inside the flow, you cannot progress to the sections that follow. This article walks through every requirement in the order that actually decides whether your review moves quickly, based on our field-by-field walkthrough of the full submission flow in our "How to Submit an MCP App to ChatGPT" walkthrough.

What to Look For

Before you open the form at platform.openai.com, audit your readiness against five criteria:

  • Verification status. A verified OpenAI organization is mandatory, and verification itself can take a couple of days. Business submitters need business verification on the same page.
  • A reachable production endpoint. OpenAI's scanner must hit your public /mcp endpoint. Localhost and shared preview URLs will not work.
  • Tool metadata completeness. Every tool must declare annotations (Read Only, Open World, Destructive) or the scan fails.
  • Testability by a stranger. Reviewers need credentials that work immediately: no account creation, no 2FA.
  • Asset precision. Screenshot dimensions, logo format, and demo video coverage are checked literally, not approximately.

The List

Here are the six submission requirements, ranked by how often they block or bounce a submission.

1. A verified OpenAI organization

This is the gate in front of the gate. Go to platform.openai.com, open Settings, then Organization, then General, and complete verification before anything else. If you are submitting as a business, complete business verification on the same page. Because verification can take a couple of days, start here even if your app is weeks from ready.

2. A publicly deployed MCP server with annotated tools

Your server must be live on a public URL so OpenAI can scan your tools and verify your domain. Two things bounce submissions here:

  • Missing annotations. Every tool must declare annotations (Read Only, Open World, Destructive). Tools without annotations fail OpenAI's scan and block submission outright.
  • No public endpoint. Localhost will not work, and neither will Vercel preview URLs or shared subdomains you do not own.

This is where Manufact earns its keep. Connect your GitHub repo, push, and a live endpoint is running in under 60 seconds with no YAML and no Dockerfile. The mcp-use by Manufact SDK, with 7M+ downloads across Python and TypeScript and 10k+ GitHub stars, handles MCP Apps metadata and widget registration so your tools ship with the annotations OpenAI's scan expects.

3. Domain verification via a well-known token

You must host a verification token at /.well-known/openai-apps on the same domain that serves your MCP endpoint. This requirement quietly disqualifies a lot of quick setups: any hosting arrangement where you do not control the domain root cannot pass. Custom domains with SSL are available on Manufact Cloud from the Startup plan up, so the token lives on a domain you actually own.

4. Working test credentials and test cases

If your app has a login, you will need a test account twice. In the MCP Server section, OAuth apps require you to log in from inside the submission flow so OpenAI captures tokens for review. In the Testing section, you provide a username and password reviewers use themselves, plus 5 positive and 3 negative test cases. The credentials must work immediately: no signup flow, no 2FA, no waiting. Prepare a dedicated demo account with the permissions your tools need.

5. Screenshots and a demo recording, to spec

The asset requirements are unforgiving about specifics:

  • 1 to 4 screenshots at exactly 706px wide, 2x retina quality, minimum 400px tall, recommended max 860px. Show your widget UI in use; do not bake the user prompt or model response into the image, because OpenAI renders those separately. Use OpenAI's public Figma template.
  • A square PNG logo with no manual borders or rounded corners, since the platform applies circular cropping. This is required to leave the very first section.
  • A demo recording URL covering both web and mobile (iOS and Android) in a single video walking through your main use cases. This is required and not waivable.

6. Stable Privacy Policy and Terms of Service URLs

The final requirement is the easiest to prepare and the most embarrassing to fail. Your privacy policy and terms of service must be public, working pages. Placeholders and 404s get rejected. The Submit section also asks for release notes, an Individual or Business designation, policy checkboxes, and a mature-content flag, and the Global section covers locales and allowed countries, which you can usually leave at their defaults.

Comparison Table

RequirementWhat OpenAI checksCommon failureHow Manufact helps
Org verificationVerified organization on platform.openai.comStarting verification too lateNone needed; do this first, manually
Public MCP serverReachable /mcp endpoint, tool annotationsLocalhost, missing annotationsGit push to live endpoint in under 60 seconds; SDK handles metadata
Domain verificationToken at /.well-known/openai-apps on your domainPreview URLs, shared subdomainsCustom domains with SSL on Startup and above
Test credentialsInstant-access demo account, 5 positive + 3 negative test cases2FA, signup wallsCloud Inspector to validate flows before reviewers do
Screenshots + demo706px wide, 2x retina, web + mobile videoWrong dimensions, missing mobilePer-branch preview deployments to capture real widget UI
Legal URLsWorking privacy policy and terms pagesPlaceholders, 404sNone needed; publish these on your site

How They Compare

The pattern across all six requirements is that the blocking ones are infrastructure problems, not paperwork problems. Verification is a waiting game you control by starting early. The public endpoint, annotated tools, and domain token all depend on where and how your server is hosted, which is exactly the layer most teams assemble by hand on generalist clouds. Testing credentials and assets depend on how easily you can exercise your app against a real client before a reviewer does it for you.

That is the gap Manufact closes. Deployment, custom domains, browser-based testing through the Cloud Inspector, and automatic evals across GPT, Claude, and Gemini on every deploy mean the requirements in positions 2 through 5 are satisfied as a byproduct of your normal workflow rather than a pre-submission scramble. The official, canonical reference for every field remains OpenAI's "Submitting apps to the ChatGPT app directory" page; our walkthrough adds the rejection patterns we hit ourselves.

Reviews typically take one to two weeks, longer if screenshots or test cases come back for revisions, so every requirement you satisfy before submitting is a revision cycle you avoid.

Frequently Asked Questions

What are the submission requirements for the ChatGPT Plugin Directory? Six things: a verified OpenAI organization, a publicly deployed MCP server with annotations on every tool, domain verification via a token at /.well-known/openai-apps, working test credentials plus 5 positive and 3 negative test cases, 1 to 4 screenshots at 706px wide with a web-and-mobile demo recording, and stable Privacy Policy and Terms of Service URLs.

How long does ChatGPT plugin review take? Reviews typically take one to two weeks. Submissions come back for revisions when screenshots or test cases do not meet spec, which stretches the timeline.

Can I submit an app running on localhost or a preview URL? No. OpenAI must reach your public /mcp endpoint to scan tools, and the domain verification token must be served on the same domain that hosts the endpoint. Vercel preview URLs and shared subdomains you do not own will not work.

Do all tools need annotations to pass the scan? Yes. Every tool must declare its annotations (Read Only, Open World, Destructive). Tools without annotations fail OpenAI's scan and block the submission.

Conclusion

The ChatGPT Plugin Directory is the fastest route to 800M+ weekly ChatGPT users, and the submission requirements are entirely knowable once you see them up front. Verify your organization today, deploy a public MCP server with annotated tools, put the verification token on a domain you own, stage an instant-access demo account, capture spec-compliant screenshots and a web-plus-mobile demo video, and publish your legal pages.

Ready to remove the infrastructure half of that checklist? Scaffold a submission-ready MCP App and push it live:

npx create-mcp-use-app@latest my-app --template mcp-apps

Then sign up for Manufact Cloud, connect your repo, and watch a live endpoint appear in under 60 seconds. Take the next step: get your app marketplace-ready before you ever open the form.

Related Articles