OpenAI Plugin Store Requirements: The Complete Technical and Policy Guide
Plugins must satisfy strict technical, security, and policy standards—including a valid ai-plugin.json manifest, complete OpenAPI specification, secure HTTPS endpoints with proper CORS, and compliance with OpenAI's content moderation policies—before being listed in the official store.
The openai/plugins repository serves as the reference implementation for developers building ChatGPT plugins. To qualify for listing in the OpenAI plugin store, developers must implement mandatory configuration files, authentication flows, and privacy safeguards that OpenAI validates during the review process.
Plugin Manifest Configuration
Every submission requires a valid ai-plugin.json file located at the domain root. This manifest must include mandatory fields: schema_version, name_for_human, name_for_model, description_for_human, description_for_model, auth, api, logo_url, contact_email, and legal_info_url.
The auth section declares the authentication type—OAuth 2.0, service authentication, or none—while the api object specifies the OpenAPI specification URL. As shown in the reference repository, the manifest acts as the source of truth for plugin metadata and capabilities.
{
"schema_version": "v1",
"name_for_human": "My Awesome Plugin",
"name_for_model": "my_awesome_plugin",
"description_for_human": "Provides smart analytics on your data.",
"description_for_model": "Offers endpoints to analyze and summarize user data.",
"auth": {
"type": "oauth",
"client_id": "YOUR_CLIENT_ID",
"authorization_endpoint": "https://example.com/oauth/authorize",
"token_endpoint": "https://example.com/oauth/token",
"scopes": ["read", "write"],
"authorization_url": "https://example.com/oauth/authorize?response_type=code&client_id=YOUR_CLIENT_ID&redirect_uri=https://chat.openai.com/oauth/callback"
},
"api": {
"type": "openapi",
"url": "https://example.com/openapi.yaml",
"has_user_authentication": true
},
"logo_url": "https://example.com/logo.png",
"contact_email": "support@example.com",
"legal_info_url": "https://example.com/privacy"
}
OpenAPI Specification Standards
The plugin must expose a complete OpenAPI (Swagger) specification—either openapi.yaml or openapi.json—that accurately describes every endpoint. This file must be reachable via the URL specified in the manifest's api field and define all request parameters, response schemas, and authentication requirements.
According to the source code in openapi.yaml, the specification must declare valid paths, operation IDs, and component schemas to enable ChatGPT to construct proper API calls.
openapi: 3.0.1
info:
title: My Awesome Plugin API
version: '1.0'
paths:
/summarize:
post:
summary: Summarize user data
operationId: summarizeData
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/SummaryRequest'
responses:
'200':
description: Summary result
content:
application/json:
schema:
$ref: '#/components/schemas/SummaryResponse'
components:
schemas:
SummaryRequest:
type: object
properties:
text:
type: string
SummaryResponse:
type: object
properties:
summary:
type: string
Authentication and Security Protocols
OpenAI mandates that plugins implement secure authentication mechanisms. Supported flows include OAuth 2.0 with PKCE for public clients, service-level authentication, or explicit no-auth for public data. The ai-plugin.json manifest must declare the chosen method in the auth section, and tokens must be stored server-side only.
As demonstrated in plugins/zoom/skills/zoom-apps-sdk/concepts/security.md, implementations require secure token storage and proper authorization header handling. Never expose client secrets or access tokens to the frontend.
// Node.js example – store tokens server‑side only
const { getOAuthToken } = require('some-oauth-lib');
app.get('/oauth/callback', async (req, res) => {
const { code } = req.query;
const tokens = await getOAuthToken({ code, client_id: CLIENT_ID, client_secret: CLIENT_SECRET });
// Store tokens in a secure DB – never expose them to the client
await db.tokens.insert({ userId: req.session.userId, ...tokens });
res.redirect('/app');
});
HTTPS, CORS, and Network Requirements
All endpoints must be served over HTTPS with valid TLS certificates. Cross-Origin Resource Sharing (CORS) headers must explicitly allow requests from https://chat.openai.com and any custom domains listed in the manifest. The plugins/zoom/skills/zoom-apps-sdk/concepts/security.md file details the required headers and Content Security Policy configurations.
Plugins must respond with appropriate HTTP status codes—2xx for success, 4xx for client errors, and 5xx for server failures—and declare reasonable rate-limit headers to manage traffic from OpenAI's user base.
Privacy and Compliance Standards
Developers must provide a privacy policy URL via the legal_info_url field in the manifest. The plugin must not log or retain user-provided data beyond what is necessary for functionality, and must comply with GDPR, CCPA, and other applicable data protection regulations.
Additionally, plugins must pass OpenAI's content moderation checks. The implementation must not facilitate disallowed content including illegal activities, hate speech, or adult content, as outlined in the repository's CONTRIBUTING.md and OpenAI's public policy documentation.
Testing and Documentation Requirements
Submissions must include functional test suites that verify each endpoint behaves as documented in the OpenAPI specification. The repository's plugins/**/tests/ directory contains examples using frameworks like Jest to validate API contracts and authentication flows.
Documentation must explain how users authenticate, call the API, and interpret responses. This information should be linked from the manifest's description_for_human field and detailed in the plugin's README.md.
// Example Jest test for the /summarize endpoint
test('POST /summarize returns a summary', async () => {
const response = await request(app)
.post('/summarize')
.send({ text: 'OpenAI provides powerful AI tools.' })
.set('Authorization', `Bearer ${validAccessToken}`);
expect(response.status).toBe(200);
expect(response.body).toHaveProperty('summary');
});
Summary
Meeting OpenAI plugin store requirements demands strict adherence to configuration, security, and policy standards.
- Configuration: Provide a complete
ai-plugin.jsonmanifest at the domain root and a valid OpenAPI specification describing all endpoints. - Security: Implement OAuth 2.0 or service authentication with server-side token storage, HTTPS endpoints, and CORS headers allowing
chat.openai.com. - Compliance: Include a privacy policy at
legal_info_url, follow GDPR/CCPA guidelines, and pass content moderation checks. - Reliability: Return proper HTTP status codes, implement rate limiting, and include functional tests in a
tests/directory. - Documentation: Maintain a
README.mdexplaining installation, authentication, and usage, linked from the manifest.
Frequently Asked Questions
What authentication methods does OpenAI support for plugins?
OpenAI supports OAuth 2.0 with PKCE for public clients, service-level authentication for backend-to-backend communication, and no authentication for plugins accessing public data. The chosen method must be declared in the auth section of ai-plugin.json. For OAuth implementations, tokens must be stored server-side only, as demonstrated in plugins/zoom/skills/zoom-apps-sdk/concepts/security.md.
Where must the ai-plugin.json file be located?
The ai-plugin.json manifest must be hosted at the root of your domain (e.g., https://example.com/ai-plugin.json) and accessible via HTTPS. This file must include all mandatory fields including schema_version, name_for_human, name_for_model, description_for_human, description_for_model, auth, api, logo_url, contact_email, and legal_info_url.
How are plugins tested before store approval?
OpenAI validates the OpenAPI specification against the actual implementation, verifies that endpoints match the documented schemas, and checks that authentication flows work as declared. Developers should include automated tests in a plugins/**/tests/ directory that verify each endpoint returns the expected responses and status codes, ensuring the plugin handles both success and error cases correctly.
What content restrictions apply to plugin submissions?
Plugins must not facilitate disallowed content including illegal activities, hate speech, harassment, or adult content. They must comply with OpenAI's content moderation policies and usage guidelines. Additionally, plugins must handle user data responsibly, providing a privacy policy at the legal_info_url and retaining data only as necessary for the plugin's core functionality.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →