Shaduf.Research preview
OpenAI Plugin Marketplace Guide/OpenAI plugins: package, access and publication

Research report · checked 29 September 2026

OpenAI plugins: package, access and publication

The first bounded study establishes a useful path from task to workflow to distribution. It deliberately stops short of claiming account eligibility, tested invocation or public approval.

Method: current primary documentation, upstream package files/provider pricing, read-only account-scoped directory observation and narrow static/ZIP checks. No external accounts connected; no install or product workflow invoked.

Current answer

A plugin packages reusable skills and optional connections. The shared directory distributes packages for supported ChatGPT/Codex hosts. Skills guide tasks; MCP servers expose tools/data; providers keep their own permissions; UI is optional. A normal prompt can remain the right answer.

Plugins overview, Plugin architecture, Skills, MCP server. Checked 29 Sep 2026.

What was verified—and how

Present access
The current user guide describes eligible ChatGPT Chat/Work web/desktop/mobile and Codex desktop/CLI, with plugin-specific restrictions. It excludes IDE plugins despite a historical March note. Raw workspace-imported MCP configurations are Desktop-only, even over HTTPS.
Small listing sample
Exact names Superpowers, GitHub and Canva appeared in our account-scoped read-only search. GitHub was pre-existing installed metadata, not authenticated. Apple Messages did not appear in those non-exhaustive queries; the user guide documents its Apple Silicon macOS desktop Work/Codex route. None was tested.
Original package
Meeting Evidence contains a portable root manifest and one skill. Narrow source checks and a genuine two-file ZIP passed. The artifact does not prove activation, output quality, full schema conformance, skill safety or submission eligibility.

Current plugins user guide, Workspace plugin management, Superpowers curated manifest, GitHub manifest, Package your plugin. Checked 29 Sep 2026.

Our task records include prerequisites, safe illustrative prompts, inspection/removal steps and dated provider costs. Canva’s observed plugin listing requires account connection, AI credits and eligible Enterprise for Bulk Create; general Canva product features do not establish plugin entitlement. No exact ChatGPT/Codex tiers or full web/mobile parity were established for the coding/cloud packages.

Read the four full task records · Inspect/reproduce the package. Provider price context: GitHub pricing, Canva pricing, Canva AI allowance.

Chronology: the missing date is still missing

  • 6 October 2025: dated API DevDay release context; the 10 October retrospective calls Apps SDK a DevDay launch. Associating the SDK with that event date is a cross-source inference.
  • 25 March 2026: installable Codex plugins/local catalogs and Apps SDK integration distribution are dated in changelogs. Plugins were Codex-only at that launch.
  • 29 September 2026: the current docs describe a universal directory. Our retrieval date is not its launch date.

Bounded official-source searches did not establish the current universal-directory rollout date or a new DevDay relationship. Exact older launch/retirement dates and GPT Store chronology were not established and are omitted.

API changelog, DevDay 2025 retrospective, ChatGPT & Codex changelog, Plugin UI changelog. Checked 29 Sep 2026.

Current publication and policy boundaries

  • Local/repo catalogs and authorized workspace sharing are distinct from public publication. Complete ZIP → checks → submit → review → approval → developer chooses Publish.
  • Adding MCP to an existing skills-only public plugin is currently unsupported. Local composition is not a promise of that public upgrade route.
  • Skill safety scans remain necessary. Skills-only does not require the MCP tool-review credentials/video or five-positive/three-negative cases; public MCP does.
  • Production endpoints/auth, accurate tool metadata, least privilege, injection defenses and irreversible-action consent remain engineering obligations.

Upload and submit, MCP review and distribution, Submission error reference, Security & Privacy. Checked 29 Sep 2026.

Contradictions we did not smooth over

IDE support
Present user-guide exclusion takes precedence over March launch support language for current advice.
Annotation justifications
Guidelines say no longer required; the error reference still requires them. Check the live portal/support.
MCP URL updates
Submission guidance directs changes to support; review guidance describes origin/path options. Preserve the production endpoint pending clarification.
Package variants
Inspected upstream GitHub wiring differs from the pre-existing cache. Curated Superpowers has empty hooks/no declared MCP, while upstream has optional hooks/visual companion. Do not treat variants as byte-identical.

Current plugins user guide, ChatGPT & Codex changelog, Plugin guidelines, Submission error reference, Upload and submit, MCP review and distribution, GitHub manifest, Superpowers upstream. Checked 29 Sep 2026.

Money and migration: qualified, not universal

Current policy permits physical-goods commerce, not in-plugin digital subscription/service/content/credit sales or upsells. Existing paid account use and neutral entitlement information are different from checkout. Instant Checkout is beta for selected partners; no universal plugin-sale payout was verified.

Plugin guidelines. Checked 29 Sep 2026.

The fetched custom-GPT migration page addresses Enterprise admins/creators and affected public Enterprise GPTs. Other-plan public sharing/timelines may differ; no calendar deadline is given. Actions require rebuilding and selected models do not transfer. No all-plan retirement or forum URL workaround is endorsed here.

Custom GPT migration guidance. Checked 29 Sep 2026.

Platform analysis

Inference: packaging may reduce repeated setup, but its value depends on a reliable workflow. OpenAI controls review/enhanced placement, admins control access, hosts select tools and providers enforce service entitlements. Exact-name/direct-link routes do not guarantee recommendation or revenue. A SaaS provider can offer an authorized customer task; a specialist can maintain a narrow skill. Both need genuine utility, compatible capabilities, maintenance and distribution—not a listing alone.

MCP review and distribution, Workspace plugin management, MCP server. Checked 29 Sep 2026.

Limitations and next evidence

This study did not measure popularity, demand, time savings, latency, safety rates or revenue. No screenshots/video, protected analytics, purchases, installs, authenticated outputs or public submissions were produced. Prices are dated provider observations, not checkout quotes; account entitlements and exact scopes remain unverified.

Next: test two contrasting lawful workflows with precise client/account/version conditions, authentic redacted outputs/screenshots and failure records. Recheck live policies and account-dependent access. Text explanation precedes any rendered video.

Primary source index

All sources checked 29 September 2026. We publish original synthesis with direct links; we do not republish full documentation, provider listing copy or the private audience corpus.

Back to Research · Read the practical guide

Search published pools, pages, reports, and evidence.