What the ChatGPT app is
A ChatGPT app is a customer-branded MCP connection that OpenAI’s App Store lists separately. It is not the object you edit at the top of the Listing page. Your listing’s first two steps — Identity and What you do — are the shared source for every destination: name, description, website, and the channels and countries you accept. The only things unique to ChatGPT are the two icon sizes OpenAI requires (with a resolved-brand-identity default) and proving domain ownership to OpenAI, described below. The ChatGPT destination is a prerequisite plus an artifact, not a wall: it states what it needs, and once you have it, gives you one thing to take away — the submission package. There is no dedicated ChatGPT hostname, no app-store category to choose on this platform, and no submission-review checkbox here: Apostra sets the directory category to Business for new registrations (a category already saved on an existing registration is kept) and shows the value in the approval preview before you download, and OpenAI’s own portal is where OpenAI runs its review.1. Get Public distribution live
The ChatGPT destination stays dimmed, with a note that apps unlock with that step, until Public distribution — the fourth step on your Listing — is live: add the Distribution package, then point your domain at Apostra with one CNAME. See Publisher domains for the domain walkthrough. Once your domain verifies, the ChatGPT tab in Distribution unlocks. If your app is already registered and still served from its own legacy per-app hostname, the ChatGPT destination (and Claude’s) stays reachable before Public distribution goes live — an existing reviewer grant, your token, and the package stay available and maintainable the whole time. One limit: requesting a new reviewer grant requires Public distribution (a published, public listing) plus the Listing + Distribution entitlements, so a legacy app without a grant finishes step 4 before requesting one. Move to your public listing domain here when you’re ready; the app keeps working until then. Token maintenance is right there in the page — the same input, Publish token, Replace/Remove with a confirm step, and Check status the public path uses, just wired to your app’s own hostname — as well as through the per-app MCP tools (save_chatgpt_app_hostname, activate_chatgpt_app_hostname,
save_chatgpt_app_verification_token, probe_chatgpt_app_verification_token)
until you move the app to your public listing domain in step 4. If that
hostname is still pending or was disabled, the ChatGPT tab unlocks too, but
shows only the one step to finish it (its CNAME and TXT records, plus a
Check hostname action) — reviewer, token, and package controls unlock
once it activates.
Unlisting the storefront (turning off step 3) is a listing-only action and
does not turn this app off: it keeps serving from its own hostname until you
turn that hostname off or move the app to your public listing domain. The
unlist confirmation says so whenever such a hostname is active.
2. Request reviewer access
Once Public distribution is live, Request access appears on the ChatGPT tab (an app still on its active per-app hostname keeps an existing grant there, but a new grant needs Public distribution first) (backed byrequest_chatgpt_reviewer_sandbox). Choose it to
request a bounded reviewer environment owned by this storefront — OpenAI
reviews your app with a test advertiser that cannot spend, and this usually
takes about a day. The request does not expose credentials on the page.
After operator activation, the storefront contains a no-spend System
advertiser and OpenAI receives one advertiser-scoped, read-only buyer
credential through the approved secret handoff.
Requested, provisioning, active, failed, revoked, and expired states appear
on the same control. Choose Revoke reviewer access
(revoke_chatgpt_reviewer_sandbox) as soon as OpenAI no longer needs it. If
the storefront later becomes ineligible for a new request, an existing grant
remains visible and can still be revoked.
The page gets this state from get_chatgpt_app_config:
reviewerSandboxAvailableistrueonly while Public distribution (a published, public listing) and the full entitlement bundle permit a new request — this applies to legacy per-app-hostname apps too; an existing grant on such an app stays usable and revocable without it.reviewerSandboxGrantStatusisloadedwhen both reviewer eligibility and the account-owned grant lookup succeeded. It isunavailablewhen either lookup fails, so the page offers a retry instead of treating an outage as a missing entitlement. Request and revoke actions remain disabled until that retry succeeds.
3. Prove domain ownership to OpenAI
OpenAI gives you a token in their portal. Paste it in the ChatGPT tab and select Publish token (backed byupdate_discovery_openai_challenge) to
publish it at the address OpenAI checks. This proves ownership of the same
domain you verified for Public distribution — it is not a second hostname,
and there is no separate ChatGPT-specific domain to configure. Use Check
status to re-check the published token on demand
(probe_discovery_openai_challenge); this only confirms that the address
returns the exact saved token — OpenAI performs its own domain verification
separately, on its own timeline.
4. Download your OpenAI package
Prepare download becomes available once your app is ready and has a live address: Public distribution on your public listing domain, or, for an existing app still served from its own per-app hostname, that active hostname. Request reviewer access before you submit, because OpenAI’s review needs it. The step shows the app name, subtitle, description, and website OpenAI will see. Select Prepare download to re-read those values, record your approval of exactly that version (approve_chatgpt_app_listing), and request a
short-lived eligible URL from get_chatgpt_app_bundle_url. If the listing
changed since the page loaded, review the refreshed values and prepare it
again. When preparation finishes, select Download package. That second,
direct click opens the prepared URL without a delayed popup request. The page
keeps the URL only in memory and expires it after one minute.
Opening the URL generates and downloads the current snapshot. If generation
is still in progress, the page shows its preparation status so you can try
again. The bundle packages the current listing, tool metadata, the selected
app icons, a readiness report, test cases, and reviewer guidance. The report
can still identify submission blockers such as missing verification. A
package generated before a later listing, domain, or icon change is stale —
prepare and download a fresh one.
The 256 × 256 directory icon and 48 × 48 composer icon default from the
storefront’s resolved brand identity when it has a usable logo. This is a
convenience, not a requirement: every storefront can instead upload
channel-specific PNGs under Use your own icons. The selected source
persists across later saves; upload both sizes again to return to
app-specific icons, or choose Use automatic icons to switch back without
downloading or re-uploading the generated files.
Complete the human checks from the bundle
Use the downloaded bundle to complete the human checks before submission:- Locale review. Read the listing copy in each locale you support and confirm it reads correctly before submitting.
- Media review. Check that your directory and composer logos, plus any promotional screenshots, match the current listing.
- Portal scan. OpenAI’s live tool/skill scan runs in their submission portal, not here — run it there and resolve anything it flags before you submit.
Complete the same setup through MCP
Connect an administrator to the V2 Storefront MCP endpoint and ask the agent to follow the Distribution section of itsskill.md. The agent reads the
same state and uses the same account and confirmation checks as the page:
the shared listing, Public distribution, reviewer access, the domain-ownership
token, and a fresh package URL. It makes at most one mutation per turn and
must stop for owner confirmation before reviewer provisioning or a
replacement token. Neither path can create, submit, or publish an OpenAI
portal draft.