> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apostra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a white-label ChatGPT app

> Get Public distribution live, request reviewer access, and download the submission package for OpenAI.

This is the seller-facing walkthrough for how to set up your ChatGPT app: the
**ChatGPT app** destination on
the [Listing page](/v2/setup/seller-pages#listing--four-steps-and-destinations).
It covers everything you do on this platform to prepare a customer-branded
ChatGPT app: reviewer access, proving domain ownership to OpenAI, and the
submission bundle. It does not cover OpenAI's own review process, which
happens entirely on OpenAI's side — see
[Understand the white-label boundary](/v2/reference/white-label-chatgpt-app#understand-the-white-label-boundary)
for what Apostra can and cannot generate on your behalf, and
[Create a white-label ChatGPT app](/v2/reference/white-label-chatgpt-app) for
the developer-mode testing and submission-portal steps that happen in
ChatGPT and OpenAI's portal.

This replaced the **Storefront** and **Discovery & distribution** tabs in
Account Settings, and later the retired **Branding & distribution** page
(AI-7225/AI-7434/AI-8891). The Listing page and MCP agents use the same tools
and account checks, so you can complete the same setup visually or
conversationally.

## What the ChatGPT app is

A ChatGPT app is a customer-branded MCP connection that OpenAI's App Store
lists separately. It is not the object you edit at the top of the Listing
page. Your listing's first two steps — Identity and What you do — are the
shared source for every destination: name, description, website, and the
channels and countries you accept. The only things unique to ChatGPT are the
two icon sizes OpenAI requires (with a resolved-brand-identity default) and
proving domain ownership to OpenAI, described below.

The ChatGPT destination is a prerequisite plus an artifact, not a wall: it
states what it needs, and once you have it, gives you one thing to take
away — the submission package. There is no dedicated ChatGPT hostname, no
app-store category to choose on this platform, and no submission-review
checkbox here: Apostra sets the directory category to Business for new
registrations (a category already saved on an existing registration is
kept) and shows the value in the approval preview before you download, and
OpenAI's own portal is where OpenAI runs its review.

## 1. Get Public distribution live

The ChatGPT destination stays dimmed, with a note that apps unlock with that
step, until **Public distribution** — the fourth step on your Listing — is
live: add the Distribution package, then point your domain at Apostra
with one CNAME. See [Publisher domains](/v2/storefront/publisher-domains) for
the domain walkthrough. Once your domain verifies, the ChatGPT tab in
Distribution unlocks.

If your app is already registered and still served from its own legacy
per-app hostname, the ChatGPT destination (and Claude's) stays reachable
before Public distribution goes live — an existing reviewer grant, your
token, and the package stay available and maintainable the whole time. One
limit: requesting a *new* reviewer grant requires Public distribution (a
published, public listing) plus the Listing + Distribution entitlements, so a
legacy app without a grant finishes step 4 before requesting one. Move to your public listing domain here when you're
ready; the app keeps working until then. Token maintenance is right there in
the page — the same input, **Publish token**, **Replace**/**Remove** with a
confirm step, and **Check status** the public path uses, just wired to your
app's own hostname — as well as through the per-app MCP tools
(`save_chatgpt_app_hostname`, `activate_chatgpt_app_hostname`,
`save_chatgpt_app_verification_token`, `probe_chatgpt_app_verification_token`)
until you move the app to your public listing domain in step 4. If that
hostname is still pending or was disabled, the ChatGPT tab unlocks too, but
shows only the one step to finish it (its CNAME and TXT records, plus a
**Check hostname** action) — reviewer, token, and package controls unlock
once it activates.

Unlisting the storefront (turning off step 3) is a listing-only action and
does not turn this app off: it keeps serving from its own hostname until you
turn that hostname off or move the app to your public listing domain. The
unlist confirmation says so whenever such a hostname is active.

## 2. Request reviewer access

Once Public distribution is live, **Request access** appears on the
ChatGPT tab (an app still on its active per-app hostname keeps an existing
grant there, but a new grant needs Public distribution first) (backed by `request_chatgpt_reviewer_sandbox`). Choose it to
request a bounded reviewer environment owned by this storefront — OpenAI
reviews your app with a test advertiser that cannot spend, and this usually
takes about a day. The request does not expose credentials on the page.
After operator activation, the storefront contains a no-spend System
advertiser and OpenAI receives one advertiser-scoped, read-only buyer
credential through the approved secret handoff.

Requested, provisioning, active, failed, revoked, and expired states appear
on the same control. Choose **Revoke reviewer access**
(`revoke_chatgpt_reviewer_sandbox`) as soon as OpenAI no longer needs it. If
the storefront later becomes ineligible for a new request, an existing grant
remains visible and can still be revoked.

The page gets this state from `get_chatgpt_app_config`:

* `reviewerSandboxAvailable` is `true` only while Public distribution (a
  published, public listing) and the full entitlement bundle permit a new
  request — this applies to legacy per-app-hostname apps too; an existing
  grant on such an app stays usable and revocable without it.
* `reviewerSandboxGrantStatus` is `loaded` when both reviewer eligibility and
  the account-owned grant lookup succeeded. It is `unavailable` when either
  lookup fails, so the page offers a retry instead of treating an outage as a
  missing entitlement. Request and revoke actions remain disabled until that
  retry succeeds.

## 3. Prove domain ownership to OpenAI

OpenAI gives you a token in their portal. Paste it in the ChatGPT tab and
select **Publish token** (backed by `update_discovery_openai_challenge`) to
publish it at the address OpenAI checks. This proves ownership of the same
domain you verified for Public distribution — it is not a second hostname,
and there is no separate ChatGPT-specific domain to configure. Use **Check
status** to re-check the published token on demand
(`probe_discovery_openai_challenge`); this only confirms that the address
returns the exact saved token — OpenAI performs its own domain verification
separately, on its own timeline.

## 4. Download your OpenAI package

**Prepare download** becomes available once your app is ready and has a live
address: Public distribution on your public listing domain, or, for an existing
app still served from its own per-app hostname, that active hostname. Request
reviewer access before you submit, because OpenAI's review needs it.

The step shows the app name, subtitle, description, and website OpenAI will
see. Select **Prepare download** to re-read those values, record your approval
of exactly that version (`approve_chatgpt_app_listing`), and request a
short-lived eligible URL from `get_chatgpt_app_bundle_url`. If the listing
changed since the page loaded, review the refreshed values and prepare it
again. When preparation finishes, select **Download package**. That second,
direct click opens the prepared URL without a delayed popup request. The page
keeps the URL only in memory and expires it after one minute.

Opening the URL generates and downloads the current snapshot. If generation
is still in progress, the page shows its preparation status so you can try
again. The bundle packages the current listing, tool metadata, the selected
app icons, a readiness report, test cases, and reviewer guidance. The report
can still identify submission blockers such as missing verification. A
package generated before a later listing, domain, or icon change is stale —
prepare and download a fresh one.

The 256 × 256 directory icon and 48 × 48 composer icon default from the
storefront's resolved brand identity when it has a usable logo. This is a
convenience, not a requirement: every storefront can instead upload
channel-specific PNGs under **Use your own icons**. The selected source
persists across later saves; upload both sizes again to return to
app-specific icons, or choose **Use automatic icons** to switch back without
downloading or re-uploading the generated files.

## Complete the human checks from the bundle

Use the downloaded bundle to complete the human checks before submission:

* **Locale review.** Read the listing copy in each locale you support and
  confirm it reads correctly before submitting.
* **Media review.** Check that your directory and composer logos, plus any
  promotional screenshots, match the current listing.
* **Portal scan.** OpenAI's live tool/skill scan runs in their submission
  portal, not here — run it there and resolve anything it flags before you
  submit.

## Complete the same setup through MCP

Connect an administrator to the V2 Storefront MCP endpoint and ask the agent
to follow the Distribution section of its `skill.md`. The agent reads the
same state and uses the same account and confirmation checks as the page:
the shared listing, Public distribution, reviewer access, the domain-ownership
token, and a fresh package URL. It makes at most one mutation per turn and
must stop for owner confirmation before reviewer provisioning or a
replacement token. Neither path can create, submit, or publish an OpenAI
portal draft.

## 5. Submit in OpenAI's portal

Everything past this point happens on OpenAI's side, not on this platform.
Apostra cannot complete OpenAI's reviewer-identity verification, policy
attestations, the portal's confirmation of the category your package declares, review-video approval, or the live portal scan for you. Follow
[Create a white-label ChatGPT app](/v2/reference/white-label-chatgpt-app) for
the developer-mode testing steps and the exact submission-portal checklist
before you hand the bundle to OpenAI.
