Skip to content
GUIDE / CHATGPT AND CODEX PLUGINS

ChatGPT plugins are back.
Here's how to build one.

BY RAVI SOJITRAUPDATED 29 SEP 202610 MIN READ

On July 9, OpenAI renamed ChatGPT apps to plugins and opened the Plugin Directory. At DevDay on September 29, it added plugin extensions and plugin picks inside the conversation. One package now runs in ChatGPT and Codex.

This guide covers what goes in a plugin, how to build one, what review asks for, and how ChatGPT decides to use it. Rather have it built? That's what we do.

BOOK A 30-MINUTE CALL
THE NEWS

Apps are plugins now.

One directory for ChatGPT and Codex. DevDay 2026 added plugin extensions and in-chat recommendations.

THE PACKAGE

Skills, tools, UI.

A plugin.json ties SKILL.md files, an MCP server and optional interface into one install.

THE CATCH

Review is real.

Test cases, a demo video, a test account and domain proof. Skills-only plugins skip most of it.

02 / What changed

What changed,
and when.

Plugins died in 2024. They came back in 2026 with a new engine. Here is the short history.

DATEWHAT HAPPENED
MAR 2023The first ChatGPT plugins launch in beta. A manifest file and an OpenAPI spec the model could call.
APR 2024Those plugins shut down for good. GPTs take their place.
OCT 2025OpenAI launches the Apps SDK at DevDay 2025. Apps run inside the chat, built on MCP.
JUL 9, 2026Codex merges into the ChatGPT desktop app. Apps are renamed plugins. The App Directory becomes the Plugin Directory.
SEP 29, 2026DevDay 2026: plugin extensions, plugin recommendations in conversation, Plugin Creator, and a redesigned submission flow.

Same name as 2023. Nothing else in common. The old plugins were an API spec the model called. The new ones bundle tools, instructions and interface, and they install in two products at once.

Publish once and the plugin is listed in one directory that serves both ChatGPT and Codex. Users can browse it, call a plugin with @, or have ChatGPT suggest it mid-conversation.

03 / What goes in a plugin

Six parts.
Most plugins use two.

A plugin can be skills only, an MCP server only, or both. Everything else is optional and earns its place.

SKILLS

Instructions the model follows

A folder with a SKILL.md. Its description decides when it fires. Scripts, references and templates sit beside it.

MCP SERVER

Tools that do real work

Your API, exposed over Streamable HTTP. Search, create, update. This is how the plugin touches your product.

UI

Cards inside the chat

Built on the open MCP Apps standard. Inline card, carousel, fullscreen or picture-in-picture.

PLUGIN EXTENSIONS

Your app, inside ChatGPT

New at DevDay 2026. Sidebar apps, side panels, file viewers, composer mentions. Canva, Figma and Adobe are the launch examples.

HOOKS

Scripts on lifecycle events

Run a command at session start and similar moments. A Codex feature, and users must trust a hook before it runs.

CHECKOUT

Physical goods only

External checkout or saved payment methods. Digital goods, subscriptions and upsells are off limits.

THE FOLDERTEXT
acme-orders/
├── plugin.json          # name, version, description
├── mcp.json             # your MCP server (optional)
├── skills/
│   └── find-orders/
│       └── SKILL.md     # when and how to use your tools
├── assets/              # logo, composer icon, screenshots
└── hooks/
    └── hooks.json       # lifecycle hooks (optional)
PLUGIN.JSONJSON
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "acme-orders",
  "version": "1.0.0",
  "description": "Find, track and update Acme orders.",
  "extensions": {
    "com.openai": {
      "interface": {
        "displayName": "Acme Orders",
        "category": "Productivity",
        "privacyPolicyURL": "https://acme.com/privacy",
        "logo": "./assets/logo.png"
      }
    }
  }
}

The manifest follows the open Agent Plugins schema. Only name, version and description are required. OpenAI-specific listing fields live under extensions.com.openai. Skills are found automatically from the skills/ folder, so you don't register them anywhere.

Codex still reads the older .codex-plugin/plugin.json overlay, and even a .claude-plugin/marketplace.json. If you built a Claude plugin already, you are closer than you think.

04 / How to build one

How to build a
ChatGPT plugin.

Seven steps, from idea to directory. Step one is where most plugins go wrong, so don't skip it.

  1. STEP 01

    Pick one job

    Not your whole product. One job people already bring to ChatGPT. "Where's my order?" "Draft a quote." "Book the room." Write 20 real prompts for it before you write any code. They become your test set.

  2. STEP 02

    Build the MCP server

    Expose that job as a few tools over Streamable HTTP. Name them domain first, like orders.search. Start every description with "Use this when". Set readOnlyHint, destructiveHint and openWorldHint honestly, because review checks them.

    MCP.JSONJSON
    {
      "$schema": "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json",
      "mcpServers": {
        "acme": {
          "type": "streamable-http",
          "url": "https://mcp.acme.com/mcp"
        }
      }
    }
  3. STEP 03

    Write the skills

    A skill tells the model how to run the job with your tools: what to ask for, the steps, the output format, and when to stop. The description in the frontmatter decides when it triggers, so write it like a search query.

    SKILLS/FIND-ORDERS/SKILL.MDMARKDOWN
    ---
    name: find-orders
    description: Use when the user asks where an Acme order is, or wants to change one.
    ---
    
    1. Ask for the order number, or the email on the order.
    2. Call orders.search. Never guess an order number.
    3. Show status, carrier and delivery date.
    4. Offer an address change only if the order has not shipped.
  4. STEP 04

    Add UI only where it earns it

    Text is fine for most answers. Add a card when the user has to compare, pick or edit. Build on MCP Apps first, then layer ChatGPT extras from window.openai, like callTool and setWidgetState. Keep every tool working without the UI.

  5. STEP 05

    Package it

    plugin.json at the root, mcp.json beside it, skills under skills/, art under assets/. Every path is relative and starts with ./. No secrets in the folder, ever.

  6. STEP 06

    Test it in Developer Mode

    Turn on Developer Mode in ChatGPT under Settings, Security and login. Register your MCP server, ask @plugin-creator to scaffold a local marketplace entry, restart the desktop app, and install the plugin from your personal plugins. Run your 20 prompts. Fix. Run them again.

  7. STEP 07

    Submit it

    Upload a ZIP on the plugins dashboard. Fill in the listing, fix every automated finding, verify your domain, and send it to review. Once approved, you pick the publish date.

SKIP THE SEVEN STEPS

We build it. You own it.

MCP server, skills, UI, listing and review packet. Built in your repo, tested in your ChatGPT, submitted under your name.

BOOK A 30-MINUTE CALL
05 / What review asks for

What review
asks for.

Every plugin gets automated checks. Plugins with an MCP server also get tested by a person. Here is the packet.

ITEMWHAT OPENAI WANTS
DISPLAY NAME30 characters max. Specific and tied to your brand, not a dictionary word.
SHORT DESCRIPTION30 characters max. Plain facts, no pricing, no hype.
LONG DESCRIPTIONUp to 4,000 characters.
LINKSPrivacy policy, terms, support and website URLs.
ARTA logo and a composer icon.
TEST CASES5 positive and 3 negative, each with a prompt, the expected tool and the expected result. MCP plugins only.
DEMOA video walkthrough URL. MCP plugins only.
TEST ACCOUNTWorking credentials with no MFA, no email codes and no private network. Entered in the dashboard, never in the ZIP.
DOMAIN PROOFA challenge token served as plain text at /.well-known/openai-apps-challenge on your MCP host.
IDENTITYIndividual or business verification on your OpenAI organization.
WHY PLUGINS GET BOUNCED

Six easy ways to fail review.

The server won't connectTest credentials that only work on your office network, or need MFA.
A test case missesOutput has to match what you said it would, with nothing extra.
The privacy policy has gapsEvery type of user data your tools return has to be disclosed.
The hints lieA tool marked read-only that writes anything is a rejection.
It asks for too muchTools can't request the full conversation or broad context fields.
It sells the wrong thingDigital products, subscriptions and upsells are not allowed.

How long does it take? OpenAI doesn't publish a timeline and doesn't expedite. Only one review can be open per plugin. After launch, changes to your hosted MCP tools are picked up by daily scans. New skills or listing changes need a new ZIP and another review.

06 / How ChatGPT picks a plugin

How ChatGPT
picks a plugin.

ChatGPT now suggests plugins mid-conversation, and it decides from your metadata. Treat it like SEO, with a model as the reader.

Name tools domain first
calendar.create_event beats create. The model reads the name before anything else.
Say when, and when not
Open each description with "Use this when". Then say what it's not for: "Do not use for reminders."
Describe every argument
Add examples. Use allowed values for anything with a fixed set of options.
Test three kinds of prompt
Direct ("use Acme to find my order"), indirect ("where's my package?"), and negative: prompts that should not trigger you.
Measure precision and recall
Did the right tool run? Did it run when it should have? Fix precision on the negatives first.
Change one field at a time
Otherwise you won't know what helped. Then check tool-call analytics weekly for drift.
07 / Should you build one

Should you
build one?

Not every product needs a plugin. Here is the test we run before we quote one.

SIGNAL 01

People already paste your stuff into ChatGPT

Order numbers, CRM records, docs, tickets. That's demand. A plugin meets it where it already is.

SIGNAL 02

You have an API

The MCP server wraps what you already expose. No API means building one first, and that is the bigger job.

SIGNAL 03

One job is worth doing in chat

Lookups, drafts, bookings, quotes. Quick in, quick out, and the answer is useful on its own.

SIGNAL 04

You already have a Claude plugin

OpenAI publishes a guide to port it. Commands become skills, Claude-only features come out, most of the work carries over.

THE OTHER SIDE

When to skip it.

You want to sell a plan inside the chatNot allowed. Existing customers can sign in and use what they pay for. Nobody can buy a subscription through your plugin.
Your data can't pass a privacy reviewIf your tools return data you can't disclose in a policy, fix that before you build anything.
Nobody will own it after launchModels change, metadata drifts, updates go back through review. Somebody has to watch it, or pay us to.
Sources

Where this
comes from.

OpenAI's own docs, plus DevDay 2026 coverage. Checked on 29 September 2026.

08 / What we build

We build it.
You ship it.

The whole plugin, from the first prompt to the directory listing. Code in your repo from day one.

01 / BUILD

MCP server

Your API as clean, well-named tools over Streamable HTTP, with sign-in where users need it.

02 / BUILD

Skills

SKILL.md workflows that tell the model how to use your tools, and when to stop and ask.

03 / BUILD

In-chat UI

Cards, carousels and fullscreen views on MCP Apps, only where they beat plain text.

04 / BUILD

Plugin extensions

Sidebar apps, side panels and file viewers, for products that need a real workspace in ChatGPT.

05 / SHIP

Review packet

Listing copy, test cases, demo video, test account and domain proof. Filed, answered, fixed.

06 / TUNE

Discovery tuning

Golden prompt sets, precision and recall runs, and metadata changes one field at a time.

07 / PORT

Claude plugin port

Already on Claude? We adapt your skills and manifest for ChatGPT and Codex.

08 / BUILD

Internal plugins

Workspace-only plugins for your team's own tools. Published by your admin, never listed publicly.

09 / RUN

Upkeep

Tool changes, metadata drift and resubmissions, on a monthly arrangement if you want one.

ONE JOB FIRST

We don't wrap your whole product on day one. We ship the one job people already ask ChatGPT for, check that it gets picked, then add the next.

09 / How it runs

From idea to
the directory.

Four stages. You use the plugin in your own ChatGPT before anything goes to review.

01

Pick the job

One call. What your users ask, what your API can do, and whether a plugin is worth building at all.

OUTCOME / ONE JOB, 20 PROMPTS
02

Scope and price

Tools, skills, UI and sign-in, in writing. Fixed scope, fixed price, before any code.

OUTCOME / A SCOPE AND A PRICE
03

Build in Developer Mode

You install it while it's being built and run the prompts yourself. Nothing is submitted until you like it.

OUTCOME / A WORKING PLUGIN
04

Submit and follow through

We file the listing, test cases and demo, answer review, and fix whatever comes back.

OUTCOME / SUBMITTED, NOT ABANDONED

Approval is OpenAI's call.

We can't promise it. We can hand review a packet with no easy reasons to say no.
10 / Questions

What people ask before they build one.

Are these the same as the 2023 ChatGPT plugins?

No. Same name, new engine. The 2023 plugins were an OpenAPI spec, and they shut down in April 2024.

Today's plugins bundle skills, an MCP server and optional UI, and they run in ChatGPT and Codex.

What's the difference between a ChatGPT app and a plugin?

On July 9, 2026, OpenAI renamed apps to plugins and moved the App Directory into the Plugin Directory.

An Apps SDK app is now the MCP server and UI inside a plugin. Skills sit beside it.

Do I need an MCP server?

Only if the plugin has to reach your product or your data. Skills-only plugins are allowed.

They also skip the test cases, the demo video and the test account at review.

Can I charge for my plugin?

Not for digital goods. Subscriptions, upsells and in-chat checkout for them are not allowed.

Existing paying customers can sign in and use what they already pay for. Physical goods can use checkout.

How long does review take?

OpenAI doesn't publish a timeline and doesn't expedite.

What we control is the packet: complete, tested, and with no easy reasons to bounce it.

Does the same plugin work in Codex?

Yes. Public plugins are published once and listed for both ChatGPT and Codex.

Some parts, like hooks, are Codex features, so we test every piece on both surfaces.

We already have a Claude plugin. Can you port it?

Yes. OpenAI publishes a guide for exactly this.

Commands become skills, Claude-specific wording and artifacts come out, and user config gets replaced. The core skills usually survive.

Can we keep the plugin inside our company?

Yes. A workspace admin can publish it to your ChatGPT workspace and pick which roles get it.

No public listing, and it never leaves your org.

Do we own the code?

Yes. The repository, the MCP server and the listing live in your accounts from the first commit.

You can take it in-house the day it ships.

11 / Book a call

Bring the idea.
Leave with a plan.

Thirty minutes on your product and your users. You leave knowing whether a plugin is worth building.

WHAT TO BRING

What your product does, what people ask ChatGPT about it, and whether you have an API.

WHAT WE DO ON THE CALL

Pick the one job worth putting in chat, and check it against OpenAI's rules.

WHAT YOU LEAVE WITH

The job, the tools it needs, and a fixed price to build and submit it.

LIVE AVAILABILITY
30 MIN / VIDEO
YOUR TIMEZONE
OPEN IN NEW TAB

Free, and there is no follow-up sequence. If a plugin is the wrong move for you, the call will say so.

12 / Send the idea

Or write it down
first.

Four fields. It rides along with your booking, so the call starts on your product instead of introductions.

BEFORE THE CALL

Tell us what your product does, the job you want in ChatGPT, and whether you have an API. We read it before we join.

Nothing is sent until you confirm a time on the calendar above.

NEW PROJECT / FIRST CONTACT

Outline your project.

Who it is for, what is broken, and what you already run.

This fills in the booking calendar. Your brief reaches the studio when you confirm a time, and not before.