Part 1: your OpenAI organization
Do these in order. Business verification has to be submitted before you send any invite, because an unverified organization does not carry the permissions an invited seat needs. Verification also takes the longest, so start it the day you read this.1
Create the account and organization
Sign up at platform.openai.com. Use an address your company controls, such as a shared or role mailbox, since this account will own the plugin listing for as long as it exists. One organization per company is enough.
2
Submit business verification, before anything else
OpenAI blocks plugin submission until the organization has a verified developer or business identity, so submit individual or business verification from your organization settings as soon as the account exists. It can take days and sometimes asks for documents.
3
Invite Waniwani into the organization
Once verification is submitted and the organization shows as verified, invite the addresses your Waniwani contact gives you under Settings → Organization → People. The seat needs a role with the “Apps Management” permission set to “Write”, which is what the plugin form checks. Roles are configured at organization roles.We only need that permission. Nothing about your API keys, billing, or usage is part of this.
4
Tell us when both are done
Message us once verification has cleared and the invite is accepted. We check we can reach the plugins portal in your org before you spend time on Part 2.
Part 2: what you send us
Send it in one batch to your Waniwani contact, or to contact@waniwani.ai. Anything missing blocks the submission, so it is worth doing in one pass.1
Two logos, light and dark
PNG, square, one light-mode version and one dark-mode version. Leave off borders and rounded corners, since ChatGPT applies circular cropping itself. The icon needs enough contrast to read on a dark background.
2
Listing copy
Four fields, all public:
- Name. The customer-facing product or workflow name.
- Subtitle. 30 characters maximum, and the limit is strict. Describe what the app does in plain words; marketing language gets flagged.
- Description. Two to three sentences on what the app does and why someone wants it, then three to five bullets of key capabilities. Factual, no hype. See how to structure it.
- Category. One of ChatGPT’s predefined categories, matching your primary function.
3
Four live URLs
- Website. The root URL, since deep links get flagged.
- Support. A monitored URL or email address. Reviewers may test it.
- Privacy policy. A live page on your domain.
- Terms of service. Same.
4
Three decisions
- Regional availability. All ChatGPT-supported countries, or a specific list. Restrict it if your service only operates in certain regions.
- Commerce. If your app touches purchasing, tell us what you sell and where the transaction completes. For regulated products such as insurance, the chat shows a quote estimate and the user is redirected to your site to finalize.
- Release notes. One short paragraph describing this version. It may be shown publicly.
Your checklist
- OpenAI account created on a company-controlled address
- Business verification submitted and cleared, before any invite goes out
- Waniwani invited afterwards, with “Apps Management” set to Write
- Verification and invite acceptance confirmed to us
- Light and dark PNG logos, square, no borders
- Name, 30-character subtitle, description, category
- Translations per extra locale, if any
- Website, support, privacy policy, and terms URLs, each verified in a private window
- Regional availability decided
- Commerce flow described, if applicable
- Release notes written
What we do next
- We create the plugin in your organization and enter your production MCP server URL, authentication, and content security policy on the MCP tab.
- We complete domain verification and run the tool scan. OpenAI issues a token that has to sit at
/.well-known/openai-apps-challengeon the challenge host. We host it ourselves on awaniwani.rundomain, and when the host is yours we send you the token to serve at that exact path, where it stays for the whole review. - We fill every remaining tab: Info, Skills, Prompts, Testing, Global, Submit.
- We send you everything we produced for your sign-off: the tool justifications, the test cases, the starter prompts, the recording, and the screenshots. Check them against how the app behaves, since reviewers run the test cases live against it.
- We submit, and OpenAI’s review begins. Reviewer questions come to us first, and we come back to you only when the answer is yours to give.
- On approval, nothing appears in the store until you give the go-ahead. Publishing is a separate step and we take it on your word.
- Deploying your app at a stable versioned MCP URL.
- Tool annotations and CSP metadata in the server code.
- Domain verification and the tool scan.
- The demo recording and the widget screenshots, produced to OpenAI’s specs and sent to you for approval.
- Reviewer demo credentials, if your app requires sign-in. We prepare an account a reviewer can use without MFA, SMS codes, email confirmation, or private-network access, since an auth flow with extra confirmation steps is one a reviewer cannot finish.
- The first draft of your tool justifications, test cases, and starter prompts.
- The eleven tabs of the form, and the back and forth during review.
Everything sits in your organization, so you keep the plugin entry whatever happens to our working relationship. Remove our seat and the listing stays where it is, editable by your own team. The self-serve guide is the same form, documented tab by tab, if you ever take it over.
The form, tab by tab
What we fill in on your behalf, and the guide to follow if you take the form over yourself.
Claude submission
Anthropic requires the final submit from an Owner of your own Claude workspace, so that one works differently.