Skip to content

Directory readiness: plugin manifests, registry entry and widget domains for ChatGPT and Claude - #537

Merged
kvz merged 2 commits into
mainfrom
mcp-registry-0.5.0
Oct 4, 2026
Merged

kvz merged 2 commits into
mainfrom
mcp-registry-0.5.0

Conversation

@kvz

@kvz kvz commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Gets @transloadit/mcp-server ready for the OpenAI plugin directory (ChatGPT and Codex), the Anthropic connectors directory and the official MCP Registry. Nothing is submitted yet: every directory scans the live endpoint, so submissions wait for the hosted OAuth deploy (api2#9320/#9363, content#6207).

Registry entry

  • server.json points at 0.5.0, the release from MCP server: OAuth discovery, tool annotations, file params and result widget #529/Version Packages #535.
  • The hosted remote no longer declares an Authorization header. OAuth clients discover sign-in from the endpoint's 401 challenge, and an optional header made registry UIs (PulseMCP among them) ask for an API key. Headless clients still pass a bearer token, as the README's "CI and headless agents" section documents.
  • Adds icons with https://transloadit.com/assets/images/square-ogimage.png (400×400 PNG, live), and a description that says the server connects with OAuth (94 characters, limit 100).
  • mcp-publisher validate passes.

OpenAI plugin manifest

plugin.json and .codex-plugin/plugin.json fix what review would reject:

  • termsOfServiceURL was /legal/terms/ (404); it is now /legal/terms-of-service/ (200). supportURL (/support/) was missing.
  • shortDescription was 57 characters; the limit is 30. It is now "Encode, resize and transcribe".
  • logo was the 900×360 wordmark, but logos must be square. Both icons are now the square navy botty (1024 and 512 px).
  • The long description no longer mentions the free plan, because OpenAI rejects pricing in listing text. It also gains capability labels, a third starter prompt and brandColorDark.
  • plugin.json carries the five positive and three negative review test cases and the release notes. The demo video URL is left out so it stays editable in the dashboard.

plugin-manifest.test.ts now checks the listing limits, HTTPS URLs, square icons and pricing words.

Result widget

  • openai/widgetDomain (TRANSLOADIT_MCP_WIDGET_DOMAIN / widgetDomain, default https://transloadit.com): OpenAI requires a dedicated widget origin for a listing with UI. It is sent only under the ChatGPT alias, because Claude validates ui.domain against its own hash-based claudemcpcontent.com origin. ui.domain stays unset.
  • redirect_domains in openai/widgetCSP: ChatGPT only trusts window.openai.openExternal targets listed there (ui.csp has no equivalent). The server lists the result origins plus the Console origin. Links open with redirectUrl: false, so ChatGPT does not append ?redirectUrl= to downloads.
  • Exact origins: TRANSLOADIT_MCP_RESULT_DOMAINS / resultDomains accept exact origins and normalize them (https://tmp-us-east-1.transloadit.net/ → https://tmp-us-east-1.transloadit.net). A value that is not an http(s) origin now fails at startup. The default stays the three wildcards for self-hosters.

Recommended value for the hosted service (api2 scripts/configs/systemd.sh, not changed here). It covers CloudFront for the three S3 tmp buckets plus the three R2 public buckets from api2 envs/default-env.sh:

TRANSLOADIT_MCP_RESULT_DOMAINS=https://tmp-us-east-1.transloadit.net,https://tmp-eu-west-1.transloadit.net,https://tmp-ap-southeast-1.transloadit.net,https://pub-6d24529af5b6438f895cf5350a9bd511.r2.dev,https://pub-9974528f53db4a839e95f7e6ce9adb68.r2.dev,https://pub-e8fef8c0e03b44acb340577811800829.r2.dev

Release

The changeset is a patch, so the hosted service picks this up as 0.5.1. server.json stays at 0.5.0, which exists on npm with mcpName. Registry versions are immutable, so the 0.5.0 metadata has to be right on the first publish.

Tests

corepack yarn check passes (mcp-server: 14 files, 207 tests). New tests cover the widget domain, exact-origin normalization, redirect_domains, startup refusal of malformed origins, the CLI environment variables, the ChatGPT openExternal path and the manifest limits.

🤖 Generated with Claude Code

kvz and others added 2 commits October 4, 2026 14:07
The registry still lists 0.3.9 (and server.json said 0.3.7/0.3.6), so its npm package entry
missed the OAuth-by-URL hosted mode, file params and the result widget released in 0.5.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Fix what OpenAI's plugin review would reject in plugin.json and
.codex-plugin/plugin.json: the terms URL (now /legal/terms-of-service/),
the missing supportURL, a subtitle over 30 characters, a non-square logo
and pricing in the listing text. plugin.json also carries the review test
cases and release notes.

server.json drops the optional Authorization header from the hosted
remote, since OAuth is discovered from the 401 challenge, and gains a
square icon that transloadit.com already serves.

The result widget now sends openai/widgetDomain (TRANSLOADIT_MCP_WIDGET_DOMAIN,
default https://transloadit.com) and lists the result and Console origins
as redirect_domains. ui.domain stays unset because Claude only accepts its
own value. Result domains accept exact origins, are normalized, and a
malformed value fails at startup.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@kvz kvz changed the title Point the MCP Registry entry at @transloadit/mcp-server 0.5.0 Directory readiness: plugin manifests, registry entry and widget domains for ChatGPT and Claude Oct 4, 2026
@kvz
kvz merged commit 938c4b1 into main Oct 4, 2026
14 checks passed
@kvz
kvz deleted the mcp-registry-0.5.0 branch October 4, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant