Confirmed requirements for this remote MCP-only submission
Submission access
Submitter must have plugin submission write access (api.apps.write / Apps Management: Write).
Organization owners have this permission automatically; non-owners require an assigned role.
Publisher identity
Public submissions require a verified individual or business identity in OpenAI Platform.
The selected identity must match the public listing/publisher surfaces.
Remote MCP host
Must be publicly accessible.
Must not be a local or testing endpoint.
Universal is the appropriate URL type when one fixed endpoint works for all users and organizations.
The Universal value entered for review must be the production MCP Server URL.
Domain verification
When the portal issues a challenge, the exact token must be served from /.well-known/openai-apps-challenge on the MCP host or an allowed parent host.
The challenge response must contain only that plugin's token.
Scan Tools
Portal imports server-advertised tool names, titles, descriptions, input/output schemas, security schemes, _meta, annotations, UI/CSP metadata, and MCP server instructions.
Server metadata must be corrected and rescanned if validation reports a mismatch.
Tool annotations
Every tool must accurately advertise readOnlyHint, openWorldHint, and destructiveHint according to real behavior.
Submission justifications do not override incorrect server annotations.
Listing and policies
Required materials include name, short/long descriptions, production-ready logo, category, website, support URL, privacy URL, terms URL, starter prompts, release notes, and country/region availability.
Public URLs must match the publisher and disclose relevant data handling.
Review tests
OpenAI requires at least five positive test cases and three negative test cases; this candidate currently prepares exactly five positive and three negative cases.
Tests must state prompts, expected tool/workflow behavior and expected results/refusals/fallbacks.
Privacy / response hygiene
User-related data categories returned by MCP tools must be covered by the public privacy policy.
Unnecessary personal data, auth secrets, debug payloads, internal identifiers, and undisclosed user-related fields should be removed from tool responses rather than merely disclosed.
Project context and data residency
The current Remote MCP server review requirements explicitly state that projects with EU data residency cannot submit plugins with MCP servers for review.
Submission must use an OpenAI project with global data residency; if the current project is EU-resident, create or select a global-residency project in the same organization.
The submission must also use the correct organization/project context so Apps Management permissions and the verified publisher identity resolve consistently.
RUMBO fail-closed mapping
apps_management_write_unverified
publisher_identity_unverified
global_data_residency_unverified
domain_verification_portal_status_unverified — conditional portal gate; challenge is required only when the portal reports that the domain is not verified.
logo_portal_upload_not_executed
scan_tools_not_executed
distribution_scope_unset
production_mcp_url_not_authorized
The technical candidate remains separate from submission authority: