Open Plugin/App submission management under organization Rumbo.
Prove project residency is global and record the selected project.
Prove Apps Management Write and publisher identity.
Upload the canonical logo from the packet.
Once production-host authority exists, enter the authorized production MCP URL — never the staging URL merely to clear a form.
Generate the domain-verification challenge token. Configure the exact token as OPENAI_APPS_CHALLENGE_TOKEN on the authorized production host and verify /.well-known/openai-apps-challenge returns it verbatim.
Run Scan Tools; require exactly four tools with expected names, schemas and annotations. Save the scan snapshot/diagnostics.
Enter the three starter prompts, listing metadata, five positive tests, three negative tests, release notes, and public support/privacy/terms/website URLs.
Choose availability/countries only with separate distribution authority.
Complete policy attestations only after all displayed facts are rechecked.
STOP. Do not select Submit for Review without separate explicit submission authority. Do not publish after review without separate publication authority.
Evidence-to-blocker mapping
Verified global project -> clears global_data_residency_unverified.