Respan — ChatGPT plugin
Packages the hosted Respan MCP server (https://mcp.respan.ai/mcp) and the
respan skill as an OpenAI plugin, for the ChatGPT plugin directory and Codex.
It uses the portable Agent Plugins format with
OpenAI's listing, review, and publication data under extensions.com.openai.
chatgpt-plugin/
├── plugin.json # manifest + ChatGPT listing, review test cases, release notes
├── mcp.json # the hosted Respan MCP server (OAuth, no secrets)
├── assets/logo.svg # logo and composer icon (128×128)
└── skills/respan/ # GENERATED by scripts/build-plugins.mjs — do not hand-edit
There is no .app.json: OpenAI does not accept ZIPs with app references yet,
so the server is declared in mcp.json and connected in the dashboard.
Authentication
Users sign in with OAuth when ChatGPT first calls a tool. mcp.respan.ai
supports Dynamic Client Registration and PKCE, so ChatGPT registers itself and
there is no client ID or key in this package.
Build the ZIP
node scripts/build-plugins.mjs # refresh skills/respan from respan/skills
node scripts/build-chatgpt-plugin.mjs # check, then write chatgpt-plugin/dist/respan-chatgpt-plugin.zip
build-chatgpt-plugin.mjs checks the package against OpenAI's submission rules
(field lengths, URLs, brand-color contrast, image size, five positive and three
negative test cases, one MCP server) and refuses to zip until every rule
passes. --check validates without zipping.
Submitting
Before the first submission:
- OpenAI org. The submitter needs the Owner role (or a role with Apps Management: Write), and the organization must be verified in platform.openai.com → Settings → Organization.
- MCP server.
respanai/respan-mcp#25must be deployed, so the tool names in the test cases exist (#24, already deployed, added the tool annotations OpenAI requires and the domain-verification endpoint). - Reviewer account. Create an email-and-password Respan login in the Respan Demo organization with no MFA. It goes in the dashboard's Review details, never in this package.
- Fresh demo data. The test cases look back 30 days. Run
respan demoagainst the Respan Demo organization right before submitting (and before any resubmission) so thedemo.*traces are recent. - Demo video. Record ChatGPT running the five positive test cases, upload
it somewhere a reviewer can open, and put the link in
extensions.com.openai.review.demo_recording_url.
Then:
node scripts/build-chatgpt-plugin.mjsand keepchatgpt-plugin/dist/respan-chatgpt-plugin.zip.- At https://platform.openai.com/plugins choose Upload new or existing plugin, pick the verified developer identity, and upload the ZIP.
- Open MCPs, select
respan, and Connect. Copy the domain challenge token into theOPENAI_APPS_CHALLENGE_TOKENenvironment variable of therespan-mcpVercel project, redeploy, and finish verification (https://mcp.respan.ai/.well-known/openai-apps-challengemust return it). - Add the reviewer login under Review details, then Submit for review and confirm the policy attestations.
- After approval, choose Publish plugin.
Tool changes on mcp.respan.ai are picked up by OpenAI's daily scan without
resubmitting. Listing, skill, or test-case changes need a new ZIP and review.
Keeping the test cases current
The positive test cases name the MCP tools they expect (tools_triggered),
using the server's current names (the same noun_verb names the in-product
agent uses, such as trace_list and prompt_create). If a tool is renamed or
removed on mcp.respan.ai, update those names here before the next
submission.