Date: 2026-09-13 UTC — V16 requirements
Budget: USD 0
Candidate SHA: 9152f5a50de42be55508f0effed5ed09aee44c60
Status: PRE-SUBMISSION HANDOFF ONLY — DO NOT SUBMIT OR PUBLISH
Current portal session: LOGIN_REQUIRED in the instrumented RumboNexus Brave profile; no cookie, localStorage, or credential extraction is permitted.
Before entering data, confirm in OpenAI Platform/Apps Management:
https://platform.openai.com/plugins in the OpenAI Platform organization that owns RUMBO IA, and confirm the acting account has Apps Management: Write (organization owners already have it).GLOBAL data residency. Current MCP review requirements state that EU-residency projects cannot submit MCP plugins for review.submission_gate.ts. Current Val Town surfaces are PASS and use the same candidate SHA.Submission type: remote MCP-only / With MCP MCP URL mode: Universal Authentication: None Custom UI: None Reviewer credentials: Not applicable for bounded public v1
Use the exact listing and release-note fields from PORTAL_PACKET.json after its fail-closed fields have been resolved.
Use exactly the three starter prompts in PORTAL_PACKET.json; do not add a fourth prompt.
Use the current 5 positive and 3 negative reviewer cases from SUBMISSION_TESTS.md; they satisfy the current minimum requirement of at least 5 positive and 3 negative cases.
A demo-recording URL is not a mandatory field in the current public submission or remote-MCP review documentation; do not block submission readiness on the historical DEMO_RECORDING_PLAN.md artifact.
When Apps Management supplies the exact domain challenge token:
OPENAI_APPS_CHALLENGE_TOKEN using the secret/environment-variable mechanism; do not place it in source or chat logs.GET /.well-known/openai-apps-challenge returns HTTP 200 with only the exact token as plaintext.verify.ts and submission_gate.ts again.Run Scan Tools in Apps Management against the authorized production MCP URL. Review every discovered tool and confirm the catalog contains exactly:
crm_get_service_readinesscrm_prepare_notecrm_prepare_lead_stage_changecrm_prepare_outreach_draftFor each discovered tool confirm:
readOnlyHint=trueopenWorldHint=falsedestructiveHint=falseIf the scanned catalog differs, stop and reconcile source/host before continuing.
Select only countries/regions where the publisher, product, support and legal terms are actually ready. Do not infer worldwide availability from technical reachability.
Enter the starter prompts and release notes from PORTAL_PACKET.json and the reviewer test cases from SUBMISSION_TESTS.md.
Before pressing Submit for Review, return the portal evidence to the control plane and update these fields:
APPS_MANAGEMENT_WRITE=PASSPUBLISHER_IDENTITY=PASS_VERIFIED_AND_MATCHEDPROJECT_DATA_RESIDENCY=PASS_GLOBALLOGO_ASSET=PASSLOGO_PORTAL_UPLOAD=PASSSUPPORT_MCP_SEMANTICS=PASSPRIVACY_MCP_DISCLOSURE=PASSTERMS_BOUNDED_SEMANTICS=PASSDOMAIN_VERIFICATION=PASS_COMPLETEDSCAN_TOOLS=PASS_EXACT_FOUR_TOOLS_CURRENT_PRODUCTION_SNAPSHOTSTARTER_PROMPTS=PASS_PACKET_CONSTRAINTSDISTRIBUTION_SCOPE=SET_EXPLICITLYPOLICY_ATTESTATIONS=COMPLETED_AFTER_FINAL_REVIEWPRODUCTION_MCP_URL=AUTHORIZED_AND_PROVENThen rerun submission_gate.ts, verify_portal_packet.ts, validate_submission_import.ts, review_case_server_validation.ts, and verify_portal_evidence_v16.ts.
Only public_directory_state=READY_TO_SUBMIT with no technical or governance failures may establish technical submission readiness. It still does not grant authority to submit or publish.
SUBMISSION_GATE_PASS != SUBMISSION_AUTHORITY != REVIEW_APPROVAL != PUBLICATION_AUTHORITY