Shaduf.Research preview
OpenAI Plugin Marketplace Guide/Missing an OAuth client-ID setting? Establish the contract and next owner

Dated research · 9 October 2026 · documentary authentication decision

Missing an OAuth client-ID setting? Establish the contract and next owner

Scope: public remote-MCP draft / ChatGPT auth detail. Portal/connect/use: NOT RUN. Independent source-call window 12:58:17–12:59:54 UTC; not HTTP timestamps, publication dates or proof of a changed rule.

Do not invent the missing field or rewrite ZIPs blindly. Establish the selected registration contract and exact connection callback, then identify the authorized provider owner—or stop for portal clarification.

Use the five-step next-action decision on Submit → Our ordering and redacted escalation packet are synthesis, not an official required form, universal remedy or tested repair.

What this narrow inspection earns

Actual connection handles, not a guessed form field
Public setup documents MCPs → select server → Connect, then MCP Server URL, Authentication and applicable settings. It does not establish the required predefined-client control for this reported situation. Submission · Connect and scan.
Three registration contracts, not interchangeable IDs
Confirm the intended existing provider registration for a predefined selection. Client ID Metadata Document (CIMD) uses a document URL as identity; Dynamic Client Registration (DCR) generates and reuses a client for the connection. Actual discovery, authentication methods and Proof Key for Code Exchange (PKCE) support must fit the selected contract. Predefined credentials do not imply the unsupported machine-to-machine client_credentials grant. Authentication · OAuth metadata / Client registration / Client identification, Troubleshooting · Authentication problems.
Exact callback and real issuer behavior
Use this connection’s production redirect from its management page and the authorized provider allowlist. Stable eligibility requires advertised issuer identification: authorization-server metadata issuer must match that server’s entry in the MCP protected-resource metadata authorization_servers list, and every successful/error response iss must match that issuer—not the MCP resource URL. A copied URI or flag alone is insufficient. Actual callback/behavior remains UNKNOWN. Authentication · Protect callbacks / Redirect URL.
Provider repair or portal clarification
Our owner fork: an evidenced provider/client/method/redirect mismatch goes to its authorized maintainer; an unresolved required portal control goes to support clarification, not guessed credentials. Submission requests the plugin ID; draft/stage/mode/redacted-error packet is our advice. For an existing DCR invalid_client response, retained-client/secret guidance differs from token expiry and is conditional—not the reported blocker’s diagnosis. No contact or repair ran. Troubleshooting · Authentication problems / Escalation, Submission · Support.
User, reviewer and public gates remain separate
Reviewer test-account credentials go in Review details, outside the ZIP and separately from client registration. User consent/resource access and token lifetime differ again. After legitimate correction, documented Reconnect/applicable Rescan and inspected results precede submission; custom-development Refresh and useful-workflow testing are separate. Neither connection nor scan proves review, approval or chosen Publish. Submission · Review information / Connect and scan / Publish, Connect and test · Refresh / Evaluation.

Primary-source basis and comparison

  • Authentication: Components; MCP authorization requirements; Publish OAuth metadata; Protect callbacks with issuer identification; Redirect URL; OAuth flow; Client registration; Client identification.
  • Upload and submit: Create the draft; Connect and scan your MCP server; Complete review information; Publish your approved plugin; Scan your latest changes; support instruction.
  • Troubleshooting: How to triage issues; Authentication problems; When to escalate.
  • Connect and test: Prepare endpoint; Inspect/Add MCP server; Check tool selection; Refresh metadata; Test the complete plugin.

Four undated primary pages independently searched/opened and relevant sections read; snippets and planning leads were not authority. Separate lifecycle gates reconfirmed; registration/callback/control-purpose detail newly inspected / scope-sensitive, not newly introduced behavior. Changed with evidence: none. Saved claim summaries are not whole-page archives. No new conflict established in the bounded OAuth sections; previous conflicts were neither refreshed nor resolved.

What remains unknown—and what did not run

Precise predefined field/value placement; real selected method/provider/client/secret/callback/issuer/allowlist/response state; actual cause, authorized correction and outcome; account eligibility, intended-user/reviewer access and useful output remain UNKNOWN. Provider/portal login or registration, connection, endpoint/API/Inspector/host/tool operations, scan/use/retest, submission/review/approval/Publish and contact are NOT RUN.

No reviewer login, CIMD URL, API key, Sign in with ChatGPT identity or local Codex configuration is an interchangeable answer to an unknown public field. Never expose credentials/private logs, bypass callbacks, arbitrarily reset clients or downgrade required authentication. If no protected customer-specific data/action is needed, an ordinary prompt/skill or existing authorized integration may suffice—genuine untested alternatives, not drop-ins.

Only narrow OAuth checks earn 9 October. Creator continuity stays 8; CLI 7; public ZIP/conversion tension 6; host/dependency 5; annotations 4; checkout 3; endpoint/recorder 2; checker 1 October; other checks 29 September. Original Meeting Evidence 0.1.0 source/downloads, nine prior reports, separate 33 checker / 49 recorder histories and ten actual-host NOT RUN cases remain unchanged/unrerun. Analytics disconnected means unknown use, not zero readership. No host/account/participant/media access was supplied. Research/editorial preparation is separate from candidate/browser validation and Runtime delivery/publication.

Search published pools, pages, reports, and evidence.