Latest Updates to OpenAI Plugin Development Guidelines: 2024 Compliance Requirements

OpenAI has significantly tightened its plugin development guidelines with mandatory CSP metadata, explicit tool impact hints, and strict submission requirements including privacy policies and public HTTPS endpoints.

The openai/plugins repository recently refreshed its internal reference documentation to reflect stricter security, metadata, and submission standards for developers building ChatGPT plugins. These updates, captured primarily in the Apps SDK workflow files, raise the bar for production-ready integrations and align the developer experience with the latest external documentation.

Mandatory Metadata and CSP Requirements

The latest guidelines introduce several new mandatory metadata keys in the plugin manifest. According to plugins/openai-developers/skills/build-chatgpt-app/references/apps-sdk-docs-workflow.md (lines 73‑78), every plugin must now specify:

  • _meta.ui.domain – The exact domain the plugin runs on, required for the review process.
  • openai/widgetDescription – A concise description used for model-side rendering.
  • _meta.ui.csp.connectDomains – Whitelist of domains the plugin will contact via API calls.
  • _meta.ui.csp.resourceDomains – Whitelist of domains for loading external resources.

These Content Security Policy (CSP) fields replace previously optional configurations and are now strictly enforced during submission review.

Submission Checklist and Security Standards

The submission checklist now explicitly requires production-grade security configurations. As documented in the workflow reference (lines 106‑112), plugins must meet the following criteria:

  • Public HTTPS endpoint – The API must be reachable via a publicly accessible HTTPS URL; localhost or temporary tunnel URLs are prohibited for final submission.
  • Privacy policy URL – A link to a comprehensive privacy policy must be provided in the manifest.
  • Support contact information – Valid contact details for user support are mandatory.
  • Demo credentials – If authentication is required, review-safe demo credentials must be supplied without exposing real user data.

Tool Design and Implementation Standards

The guidelines now require granular impact hints for every tool to help the model decide when to invoke functions. In apps-sdk-docs-workflow.md (lines 50‑57), developers must declare:

  • readOnlyHint – Set to true if the tool does not modify data.
  • destructiveHint – Set to true if the tool performs irreversible operations.
  • openWorldHint – Set to true if the tool interacts with external systems beyond the immediate context.

Additionally, handlers must be idempotent because the model may retry calls (lines 44‑48). The guidelines also stress splitting data-only tools from UI-render tools to optimize performance and clarity.

Development and Deployment Workflow

For local testing, the updated guidelines specify a Developer-Mode workflow (lines 80‑86). Developers must:

  1. Run the MCP server locally.
  2. Expose it via a public HTTPS tunnel.
  3. Add the tunnel URL to ChatGPT’s Developer-Mode settings.

Before scaffolding, developers should classify their app into a primary archetype (e.g., "connector", "company-knowledge") and reuse the smallest upstream example that matches the request (lines 37‑41).

For production deployment (lines 98‑102), the guidelines emphasize stable, TLS-secured hosting with clear logging and metrics expectations. Secrets must be handled using environment-variable placeholders in .env files rather than hardcoded values.

Example: Compliant Plugin Manifest

Below is a minimal plugin.json configuration that satisfies the new OpenAI plugin development guidelines:

{
  "name": "my-awesome-plugin",
  "description": "A demo plugin that shows the latest guideline compliance.",
  "version": "0.1.0",
  "api": {
    "base_url": "https://my-awesome-plugin.example.com"
  },
  "metadata": {
    "_meta": {
      "ui": {
        "domain": "my-awesome-plugin.example.com",
        "csp": {
          "connectDomains": ["api.example.com"],
          "resourceDomains": ["cdn.example.com"]
        }
      },
      "openai": {
        "widgetDescription": "Shows a simple data card for user queries."
      }
    }
  },
  "tools": [
    {
      "name": "searchData",
      "description": "Searches the data store and returns JSON results.",
      "type": "function",
      "input_schema": {
        "type": "object",
        "properties": {
          "query": { "type": "string", "description": "The search term." }
        },
        "required": ["query"]
      },
      "hints": {
        "readOnlyHint": true,
        "destructiveHint": false,
        "openWorldHint": false
      }
    },
    {
      "name": "renderCard",
      "description": "Renders a card widget from a list of IDs.",
      "type": "function",
      "input_schema": {
        "type": "object",
        "properties": {
          "ids": {
            "type": "array",
            "items": { "type": "string" },
            "description": "IDs returned by `searchData`."
          }
        },
        "required": ["ids"]
      },
      "hints": {
        "readOnlyHint": false,
        "destructiveHint": false,
        "openWorldHint": true
      }
    }
  ],
  "privacy_policy": "https://my-awesome-plugin.example.com/privacy",
  "support_contact": "support@example.com"
}

This manifest demonstrates proper CSP configuration, tool impact hints, and submission-ready metadata including the privacy policy and support contact fields.

Summary

  • CSP metadata (_meta.ui.csp.connectDomains, resourceDomains) and domain verification (_meta.ui.domain) are now mandatory in plugin.json.
  • Submissions require a public HTTPS endpoint, privacy policy URL, support contact, and review-safe demo credentials.
  • Tools must include explicit impact hints (readOnlyHint, destructiveHint, openWorldHint) to guide model invocation behavior.
  • Handlers must be idempotent to handle model retries safely.
  • Local development requires Developer-Mode configuration with HTTPS tunneling, while production requires stable TLS hosting and proper secrets management.

Frequently Asked Questions

What metadata keys are now mandatory in the plugin manifest?

Developers must include _meta.ui.domain for domain verification, openai/widgetDescription for model-side rendering, and _meta.ui.csp.connectDomains plus _meta.ui.csp.resourceDomains for Content Security Policy enforcement. These fields are required as of the latest updates to apps-sdk-docs-workflow.md.

How do I test plugins locally under the new guidelines?

Run your MCP server locally and expose it via a public HTTPS tunnel. Add the tunnel URL to ChatGPT’s Developer-Mode settings for testing. Localhost URLs are no longer acceptable for final submission, but tunnels allow safe pre-submission validation.

What are tool impact hints and why are they required?

Impact hints are boolean flags (readOnlyHint, destructiveHint, openWorldHint) declared in each tool’s schema. They inform the model about the tool’s side effects, helping it decide whether to invoke the tool during conversation flow. This requirement improves safety and predictability in plugin interactions.

What submission artifacts are required besides the code?

Submissions must include screenshots of the plugin in action, a link to a privacy policy, support contact information, and test prompts with expected responses. If your plugin requires authentication, you must provide demo credentials that are safe for the review team to use without accessing real user data.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →