Outline Technologies — SEO, AEO & GEO Agency
Back to Blog
AI VisibilityField Tested

How to Get Your Product Into ChatGPT, Step by Step

Putting your product inside ChatGPT is not the same as getting ChatGPT to cite your website. It means a person asks ChatGPT to do something, and ChatGPT calls your tool to do it. We submitted one of our own tools in the autumn of 2026 and it went live on the 2nd of October. This guide walks through what OpenAI asks for, in the order you will need it, including the rules on selling that catch most software companies by surprise.

Abd Shanti 14 min readOctober 2, 2026
In This Guide
The short answerWhat being in ChatGPT means nowWhat you need readyDesign tools a model can chooseAuthentication a reviewer can useWrite a listing that survives reviewThe eight test casesThe rules on sellingProhibited categories and dataWhat happened when we submittedAfter you are liveCommon rejection reasonsFAQ

The Short Answer

To get a product into ChatGPT you build a server that ChatGPT can call, using the Model Context Protocol, then submit it through the OpenAI developer platform with a listing, a working test account, eight written test cases and a short video. A reviewer tests it against published guidelines. If it passes, you choose when it goes live, and people can then find it in ChatGPT and use it inside their conversations. We went through this in the autumn of 2026 with one of our own tools, and the parts that take time are not the code. They are the test account, the test cases and the rules on selling.

The one sentence version

Build a server whose tools do one clear job, make it testable by a stranger in five minutes, describe it without a single claim you cannot back, and do not try to sell digital subscriptions through it.

What Being in ChatGPT Means Now

The vocabulary has moved several times, so it helps to pin it down. Today a third party integration in ChatGPT is a package that points at a server you host. OpenAI's developer documentation currently calls the submitted package a plugin, while most people, and most of the press, still say ChatGPT app. Either way the moving part is the same: an MCP server exposing tools, plus a listing that tells ChatGPT and its users what those tools do.

That is different from being cited by ChatGPT. Citation is ChatGPT quoting your website in an answer, which we cover in our guide to getting cited by ChatGPT. Being in ChatGPT means a person can ask ChatGPT to do something and ChatGPT calls your tool to do it. One is a source. The other is a capability. A product can have both, and they reinforce each other, but the work is entirely different.

Term you will hearWhat it actually isWhere you deal with it
MCP serverYour service, speaking the Model Context Protocol, exposing named toolsYour own infrastructure
ToolOne action the server offers, with a name, a description and typed inputsYour server code
Plugin or appThe package and listing that point ChatGPT at your serverThe OpenAI developer platform
DirectoryWhere people browse and add approved integrationsInside ChatGPT, after approval
ReviewOpenAI testing your submission against its guidelinesBetween submission and publishing

Before You Start: What You Need Ready

Most delays come from things that are not code. Gather these before you open the submission form, because the form will stop you at each one.

RequirementWhat it meansWhere people get stuck
A verified organizationIndividual or business verification in your OpenAI organization settings, so the listing can carry your nameVerification can take longer than the build
The right permissionOrganization owners can submit; other members need the Apps Management Write permissionA developer without the permission sees no submit option
A public secure serverYour MCP server reachable on the open internet over an encrypted connection with a valid certificateServers behind a login wall or an IP allow list fail review
Four live URLsWebsite, support, privacy policy and terms of service, all on secure addressesA privacy policy that does not mention the integration
A demo accountA login and password for a fully featured account a reviewer can useDemo accounts with limits that block the features being tested
Eight test casesFive that should trigger your tools and three that should notWriting them after the fact, vaguely
A video walkthroughA recording of the integration working, linked by URLRecording before the final version is deployed

Step 1: Design Tools a Model Can Choose Correctly

A model decides whether to call your tool by reading its name and description, so those two strings do more work than any line of your code. OpenAI's guidelines ask for human readable, specific names written as verbs, like get_order_status, and descriptions that say what the tool does, when to use it and what its limits are. A tool that does three things should usually be three tools.

Every tool also needs three explicit annotations. They tell ChatGPT how careful to be before calling it, and reviewers check that they are honest.

AnnotationSet it to true whenSet it to false when
readOnlyHintThe tool only retrieves or previews somethingThe tool changes state anywhere
destructiveHintThe tool deletes something or has an effect that cannot be undoneThe tool only adds or creates
openWorldHintThe tool works with public or open ended things, such as the webThe tool works inside a bounded account

Ask for the minimum input each tool needs. The guidelines are explicit that a tool should not request chat history or broad context just in case. On our own servers, agents sent short inputs: the median text sent to the main action was 153 characters. Design for a sentence, not a chapter, and return results fast enough that a person waiting in a chat does not think it broke. Our wider guide to MCP servers for business covers the server side in more depth.

Ship the boring helper tools

On our servers, the tools that list options, report remaining allowance and suggest a choice were called 314 times, against 931 calls to the main action. Agents plan before they act. Give them the tools to plan with.

Step 2: Authentication a Reviewer Can Actually Use

If your tools need an account, ChatGPT connects through OAuth, and you supply the OAuth details and a domain verification token with the submission. The rule that catches people is in the guidelines: provide a login and password for a fully featured demo account, and integrations that require additional login steps will be rejected. The reviewer must be able to sign in once and test everything.

What worked for us was splitting the tools in two. Basic actions work for a guest with no account, metered by address, so ChatGPT can use the tool immediately for anyone. Anything tied to a person's data sits behind OAuth, and the connect page asks for the user's existing API key in one field. The demo account we gave the reviewer was a full paid account, so nothing they tried was blocked by a plan limit.

01

Decide which tools need an account

If a tool can work anonymously with a limit, let it. Fewer login prompts means more people try it.

02

Keep the connect step to one screen

One field and one button. Extra verification steps are a common reason for rejection.

03

Return a clear message when a login is needed

A protected tool called anonymously should answer with a plain request to connect, not a vague error.

04

Give the reviewer a real account

Full features, no trial expiry during review, and credentials kept out of the package itself.

Step 3: Write a Listing That Survives Review

The listing has hard limits that are easy to miss. The display name can be at most 30 characters, and so can the short description. The long description can run to 4,000. Icons and screenshots can be PNG, JPEG, WebP or SVG, up to 5 MiB each.

The guidelines ask for names and descriptions that are clear, accurate and straightforward, without comparisons to other products, without disparagement and without claims that cannot be verified. That rules out most marketing copy. Write the long description like documentation: what the tools do, what they do not do, what an account adds, and what the limits are. It is the same discipline as writing a page that AI can extract cleanly, because a model reads it to decide when to call you.

FieldLimitWhat to put there
Display name30 charactersYour product name, nothing else
Short description30 charactersThe single job, as a verb phrase
Long description4,000 charactersEvery tool, its limits, what needs an account, what data you keep
ScreenshotsPNG, JPEG, WebP or SVG, 5 MiB eachReal conversations using the tool, not mockups
CountriesOptional list of country codesLeave it empty unless you have a legal reason to restrict

Step 4: The Eight Test Cases

You submit five positive test cases, each a prompt that should trigger your tools with the expected tool call and result, and three negative ones that should not trigger anything. This is where reviewers spend their time, so write them as if a stranger will paste them in word for word, because one will.

Positive cases cover the main job

At least two prompts for your core action, one for each helper tool, and one that needs an account, so the reviewer sees the login flow work.

Negative cases prove restraint

A prompt that is near your topic but not your job, a request your tool should refuse, and an unrelated question. The right result for all three is no call.

Expected results are specific

Name the tool that should be called and describe the result in a sentence, so the reviewer can tell at a glance whether it passed.

Record the video walkthrough last, on the exact version you are submitting, running through two or three of the positive cases and the login. If anything changes after recording, record again.

The Rules on Selling Are Stricter Than You Expect

This is the section most product teams read too late. The current guidelines allow commerce for physical goods only. Digital products, subscriptions and upsells are prohibited, and an integration cannot link directly to a checkout or other transactional page. It can explain that a feature is unavailable.

For a software company that sells subscriptions, that changes the design. The integration cannot be a sales funnel. It has to be useful on its own terms, with a free tier that does real work, and the paid version reached by the person through your own website, not through a link pushed inside the chat. Plan your free limits so a reviewer and an ordinary user both get genuine value before they hit them.

Do not borrow the brand

Trademark care matters on your own pages too. When we built a landing page for our integration we kept the ChatGPT name in plain text, with no logo styling, and added a short trademark notice. A review is not the only place a brand owner looks.

Prohibited Categories and Data You Must Not Collect

Some products cannot be submitted at all. The guidelines list prohibited categories including sexual services, gambling, illegal drugs, counterfeit goods, malware, weapons, fake identification, unregulated financial services and speculative or fraudulent crypto schemes. Integrations must be suitable for people aged 13 to 17 and cannot target children under 13.

Separately, some data must never be collected through the integration: payment card details, health records, government identification and authentication credentials. Behavioural tracking and profiling are not allowed unless they are disclosed and under the user's control. Your privacy policy has to explain what you collect, why, who receives it, how long you keep it and what control the user has.

What Happened When We Submitted

We submitted one of our own tools in the autumn of 2026 and it went live on the 2nd of October. Three things from that experience are worth passing on.

The reviewer tests immediately

Within minutes of approval our server log showed the reviewer making 17 calls with the demo account. Make sure the demo account works the moment you press submit, not the next morning.

Review sessions show up in your log

Review traffic arrives under a distinctive client name, so you can watch exactly what the reviewer tried and fix anything that failed before they finish.

Chat traffic is real traffic

Over nine days across two of our servers, chat assistant clients made 849 tool calls from 960 connections, close to one call per connection. Coding agents and directory robots connect far more and call far less.

The last point is the one to remember once you are live. Most connections to an agent server are robots checking it is alive, and coding tools reconnecting at the start of every session. Count tool calls, split by client type, and judge adoption by the calls that came from a person asking for something.

After You Are Live

01

Publish when you are ready

Approval does not publish automatically. You choose when, so line it up with your landing page and support.

02

Treat every update as a new release

Publishing an update replaces the previous version, so test the new package as carefully as the first.

03

Give the integration its own page

A page on your site that explains what it does, with real examples, helps people find it and helps assistants describe it accurately.

04

Watch calls, errors and logins

Calls per client type, failed calls and login requests tell you what people try and where they give up.

If you also sell physical products, the integration can sit alongside the product feeds that agents read, which is a separate route into assistant shopping. And because ChatGPT now shows ads to some users, it is worth knowing how ads and citations interact before you plan any paid promotion around your listing.

Common Reasons Integrations Get Rejected

A login the reviewer cannot pass

Extra verification, expiring trials or a demo account without the features being tested.

Tools that do too much

One tool with several modes and a vague description, which a model cannot choose reliably.

Annotations that are not honest

A tool that changes data marked as read only, or a deletion not marked as destructive.

Selling inside the chat

Upsell messages, subscription offers or direct checkout links for digital products.

A listing that oversells

Comparisons with competitors, superlatives and claims that cannot be checked.

A privacy policy that ignores the integration

The policy must cover what the integration collects, not only the website.

The Bottom Line

Getting into ChatGPT is less about clever code and more about being easy to test and honest to describe. Build tools that each do one job, mark them truthfully, give the reviewer a real account, write eight test cases a stranger can run, and keep selling out of the conversation. Then count what actually happens: tool calls from people, not connections from robots. The documentation and its terms will keep changing, so read the current guidelines on the day you submit. The principles above have held through every version so far.

Frequently Asked Questions

How do I get my app into ChatGPT?

Build an MCP server whose tools ChatGPT can call, then submit it through the OpenAI developer platform with a listing, a demo account, five test prompts that should trigger your tools, three that should not, and a short video walkthrough. A reviewer tests it against the published guidelines, and after approval you choose when to publish.

What does OpenAI require to submit a ChatGPT app?

A verified organization, the Apps Management Write permission or owner role, a public MCP server on a secure address, website, support, privacy policy and terms pages, a fully featured demo login, eight test cases and a video walkthrough. The display name and short description are limited to 30 characters each, and the long description to 4,000.

Can I sell subscriptions through a ChatGPT app?

No, not under the current guidelines. Commerce is limited to physical goods, and digital products, subscriptions and upsells are prohibited, as are direct links to a checkout page. An integration can explain that a feature is unavailable, so give it a free tier that does real work and let people upgrade on your own website.

Why do ChatGPT app submissions get rejected?

Common reasons are a demo login the reviewer cannot pass, tools that do several jobs under one vague description, annotations that misstate whether a tool changes data, upsell messages inside the chat, listings with comparisons or unverifiable claims, and a privacy policy that does not cover the integration.

How soon does OpenAI test a submitted app?

Quickly, in our experience. When one of our tools went live on 2 October 2026, our server log showed the reviewer making 17 calls with the demo account within minutes, so the demo account has to work the moment you submit.

Want your product callable from ChatGPT?

We design the tools, the authentication and the listing, write the test cases and get the integration through review, then measure the calls that matter.

Get an AI visibility audit