# OpenAI Plugin Store Requirements: The Complete Technical and Policy Guide

> Discover essential OpenAI plugin store requirements. Learn about manifest, OpenAPI spec, HTTPS, CORS, and policy compliance to get your plugin listed.

- Repository: [OpenAI/plugins](https://github.com/openai/plugins)
- Tags: guide
- Published: 2026-07-12

---

**Plugins must satisfy strict technical, security, and policy standards—including a valid [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json) manifest, complete OpenAPI specification, secure HTTPS endpoints with proper CORS, and compliance with OpenAI's content moderation policies—before being listed in the official store.**

The openai/plugins repository serves as the reference implementation for developers building ChatGPT plugins. To qualify for listing in the OpenAI plugin store, developers must implement mandatory configuration files, authentication flows, and privacy safeguards that OpenAI validates during the review process.

## Plugin Manifest Configuration

Every submission requires a valid [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json) file located at the domain root. This manifest must include mandatory fields: `schema_version`, `name_for_human`, `name_for_model`, `description_for_human`, `description_for_model`, `auth`, `api`, `logo_url`, `contact_email`, and `legal_info_url`.

The `auth` section declares the authentication type—OAuth 2.0, service authentication, or none—while the `api` object specifies the OpenAPI specification URL. As shown in the reference repository, the manifest acts as the source of truth for plugin metadata and capabilities.

```json
{
  "schema_version": "v1",
  "name_for_human": "My Awesome Plugin",
  "name_for_model": "my_awesome_plugin",
  "description_for_human": "Provides smart analytics on your data.",
  "description_for_model": "Offers endpoints to analyze and summarize user data.",
  "auth": {
    "type": "oauth",
    "client_id": "YOUR_CLIENT_ID",
    "authorization_endpoint": "https://example.com/oauth/authorize",
    "token_endpoint": "https://example.com/oauth/token",
    "scopes": ["read", "write"],
    "authorization_url": "https://example.com/oauth/authorize?response_type=code&client_id=YOUR_CLIENT_ID&redirect_uri=https://chat.openai.com/oauth/callback"
  },
  "api": {
    "type": "openapi",
    "url": "https://example.com/openapi.yaml",
    "has_user_authentication": true
  },
  "logo_url": "https://example.com/logo.png",
  "contact_email": "support@example.com",
  "legal_info_url": "https://example.com/privacy"
}

```

## OpenAPI Specification Standards

The plugin must expose a complete OpenAPI (Swagger) specification—either [`openapi.yaml`](https://github.com/openai/plugins/blob/main/openapi.yaml) or [`openapi.json`](https://github.com/openai/plugins/blob/main/openapi.json)—that accurately describes every endpoint. This file must be reachable via the URL specified in the manifest's `api` field and define all request parameters, response schemas, and authentication requirements.

According to the source code in [`openapi.yaml`](https://github.com/openai/plugins/blob/main/openapi.yaml), the specification must declare valid paths, operation IDs, and component schemas to enable ChatGPT to construct proper API calls.

```yaml
openapi: 3.0.1
info:
  title: My Awesome Plugin API
  version: '1.0'
paths:
  /summarize:
    post:
      summary: Summarize user data
      operationId: summarizeData
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SummaryRequest'
      responses:
        '200':
          description: Summary result
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SummaryResponse'
components:
  schemas:
    SummaryRequest:
      type: object
      properties:
        text:
          type: string
    SummaryResponse:
      type: object
      properties:
        summary:
          type: string

```

## Authentication and Security Protocols

OpenAI mandates that plugins implement secure authentication mechanisms. Supported flows include OAuth 2.0 with PKCE for public clients, service-level authentication, or explicit no-auth for public data. The [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json) manifest must declare the chosen method in the `auth` section, and tokens must be stored server-side only.

As demonstrated in [`plugins/zoom/skills/zoom-apps-sdk/concepts/security.md`](https://github.com/openai/plugins/blob/main/plugins/zoom/skills/zoom-apps-sdk/concepts/security.md), implementations require secure token storage and proper authorization header handling. Never expose client secrets or access tokens to the frontend.

```javascript
// Node.js example – store tokens server‑side only
const { getOAuthToken } = require('some-oauth-lib');

app.get('/oauth/callback', async (req, res) => {
  const { code } = req.query;
  const tokens = await getOAuthToken({ code, client_id: CLIENT_ID, client_secret: CLIENT_SECRET });
  // Store tokens in a secure DB – never expose them to the client
  await db.tokens.insert({ userId: req.session.userId, ...tokens });
  res.redirect('/app');
});

```

## HTTPS, CORS, and Network Requirements

All endpoints must be served over HTTPS with valid TLS certificates. Cross-Origin Resource Sharing (CORS) headers must explicitly allow requests from `https://chat.openai.com` and any custom domains listed in the manifest. The [`plugins/zoom/skills/zoom-apps-sdk/concepts/security.md`](https://github.com/openai/plugins/blob/main/plugins/zoom/skills/zoom-apps-sdk/concepts/security.md) file details the required headers and Content Security Policy configurations.

Plugins must respond with appropriate HTTP status codes—2xx for success, 4xx for client errors, and 5xx for server failures—and declare reasonable rate-limit headers to manage traffic from OpenAI's user base.

## Privacy and Compliance Standards

Developers must provide a privacy policy URL via the `legal_info_url` field in the manifest. The plugin must not log or retain user-provided data beyond what is necessary for functionality, and must comply with GDPR, CCPA, and other applicable data protection regulations.

Additionally, plugins must pass OpenAI's content moderation checks. The implementation must not facilitate disallowed content including illegal activities, hate speech, or adult content, as outlined in the repository's [`CONTRIBUTING.md`](https://github.com/openai/plugins/blob/main/CONTRIBUTING.md) and OpenAI's public policy documentation.

## Testing and Documentation Requirements

Submissions must include functional test suites that verify each endpoint behaves as documented in the OpenAPI specification. The repository's `plugins/**/tests/` directory contains examples using frameworks like Jest to validate API contracts and authentication flows.

Documentation must explain how users authenticate, call the API, and interpret responses. This information should be linked from the manifest's `description_for_human` field and detailed in the plugin's [`README.md`](https://github.com/openai/plugins/blob/main/README.md).

```javascript
// Example Jest test for the /summarize endpoint
test('POST /summarize returns a summary', async () => {
  const response = await request(app)
    .post('/summarize')
    .send({ text: 'OpenAI provides powerful AI tools.' })
    .set('Authorization', `Bearer ${validAccessToken}`);

  expect(response.status).toBe(200);
  expect(response.body).toHaveProperty('summary');
});

```

## Summary

Meeting OpenAI plugin store requirements demands strict adherence to configuration, security, and policy standards.

- **Configuration**: Provide a complete [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json) manifest at the domain root and a valid OpenAPI specification describing all endpoints.
- **Security**: Implement OAuth 2.0 or service authentication with server-side token storage, HTTPS endpoints, and CORS headers allowing `chat.openai.com`.
- **Compliance**: Include a privacy policy at `legal_info_url`, follow GDPR/CCPA guidelines, and pass content moderation checks.
- **Reliability**: Return proper HTTP status codes, implement rate limiting, and include functional tests in a `tests/` directory.
- **Documentation**: Maintain a [`README.md`](https://github.com/openai/plugins/blob/main/README.md) explaining installation, authentication, and usage, linked from the manifest.

## Frequently Asked Questions

### What authentication methods does OpenAI support for plugins?

OpenAI supports OAuth 2.0 with PKCE for public clients, service-level authentication for backend-to-backend communication, and no authentication for plugins accessing public data. The chosen method must be declared in the `auth` section of [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json). For OAuth implementations, tokens must be stored server-side only, as demonstrated in [`plugins/zoom/skills/zoom-apps-sdk/concepts/security.md`](https://github.com/openai/plugins/blob/main/plugins/zoom/skills/zoom-apps-sdk/concepts/security.md).

### Where must the ai-plugin.json file be located?

The [`ai-plugin.json`](https://github.com/openai/plugins/blob/main/ai-plugin.json) manifest must be hosted at the root of your domain (e.g., `https://example.com/ai-plugin.json`) and accessible via HTTPS. This file must include all mandatory fields including `schema_version`, `name_for_human`, `name_for_model`, `description_for_human`, `description_for_model`, `auth`, `api`, `logo_url`, `contact_email`, and `legal_info_url`.

### How are plugins tested before store approval?

OpenAI validates the OpenAPI specification against the actual implementation, verifies that endpoints match the documented schemas, and checks that authentication flows work as declared. Developers should include automated tests in a `plugins/**/tests/` directory that verify each endpoint returns the expected responses and status codes, ensuring the plugin handles both success and error cases correctly.

### What content restrictions apply to plugin submissions?

Plugins must not facilitate disallowed content including illegal activities, hate speech, harassment, or adult content. They must comply with OpenAI's content moderation policies and usage guidelines. Additionally, plugins must handle user data responsibly, providing a privacy policy at the `legal_info_url` and retaining data only as necessary for the plugin's core functionality.