Directory readiness: plugin manifests, registry entry and widget domains for ChatGPT and Claude - #537
Merged
Merged
Conversation
The registry still lists 0.3.9 (and server.json said 0.3.7/0.3.6), so its npm package entry missed the OAuth-by-URL hosted mode, file params and the result widget released in 0.5.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Fix what OpenAI's plugin review would reject in plugin.json and .codex-plugin/plugin.json: the terms URL (now /legal/terms-of-service/), the missing supportURL, a subtitle over 30 characters, a non-square logo and pricing in the listing text. plugin.json also carries the review test cases and release notes. server.json drops the optional Authorization header from the hosted remote, since OAuth is discovered from the 401 challenge, and gains a square icon that transloadit.com already serves. The result widget now sends openai/widgetDomain (TRANSLOADIT_MCP_WIDGET_DOMAIN, default https://transloadit.com) and lists the result and Console origins as redirect_domains. ui.domain stays unset because Claude only accepts its own value. Result domains accept exact origins, are normalized, and a malformed value fails at startup. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Gets
@transloadit/mcp-serverready for the OpenAI plugin directory (ChatGPT and Codex), the Anthropic connectors directory and the official MCP Registry. Nothing is submitted yet: every directory scans the live endpoint, so submissions wait for the hosted OAuth deploy (api2#9320/#9363, content#6207).Registry entry
server.jsonpoints at 0.5.0, the release from MCP server: OAuth discovery, tool annotations, file params and result widget #529/Version Packages #535.Authorizationheader. OAuth clients discover sign-in from the endpoint's401challenge, and an optional header made registry UIs (PulseMCP among them) ask for an API key. Headless clients still pass a bearer token, as the README's "CI and headless agents" section documents.iconswithhttps://transloadit.com/assets/images/square-ogimage.png(400×400 PNG, live), and a description that says the server connects with OAuth (94 characters, limit 100).mcp-publisher validatepasses.OpenAI plugin manifest
plugin.jsonand.codex-plugin/plugin.jsonfix what review would reject:termsOfServiceURLwas/legal/terms/(404); it is now/legal/terms-of-service/(200).supportURL(/support/) was missing.shortDescriptionwas 57 characters; the limit is 30. It is now "Encode, resize and transcribe".logowas the 900×360 wordmark, but logos must be square. Both icons are now the square navy botty (1024 and 512 px).brandColorDark.plugin.jsoncarries the five positive and three negative review test cases and the release notes. The demo video URL is left out so it stays editable in the dashboard.plugin-manifest.test.tsnow checks the listing limits, HTTPS URLs, square icons and pricing words.Result widget
openai/widgetDomain(TRANSLOADIT_MCP_WIDGET_DOMAIN/widgetDomain, defaulthttps://transloadit.com): OpenAI requires a dedicated widget origin for a listing with UI. It is sent only under the ChatGPT alias, because Claude validatesui.domainagainst its own hash-basedclaudemcpcontent.comorigin.ui.domainstays unset.redirect_domainsinopenai/widgetCSP: ChatGPT only trustswindow.openai.openExternaltargets listed there (ui.csphas no equivalent). The server lists the result origins plus the Console origin. Links open withredirectUrl: false, so ChatGPT does not append?redirectUrl=to downloads.TRANSLOADIT_MCP_RESULT_DOMAINS/resultDomainsaccept exact origins and normalize them (https://tmp-us-east-1.transloadit.net/→https://tmp-us-east-1.transloadit.net). A value that is not an http(s) origin now fails at startup. The default stays the three wildcards for self-hosters.Recommended value for the hosted service (api2
scripts/configs/systemd.sh, not changed here). It covers CloudFront for the three S3 tmp buckets plus the three R2 public buckets from api2envs/default-env.sh:Release
The changeset is a patch, so the hosted service picks this up as 0.5.1.
server.jsonstays at 0.5.0, which exists on npm withmcpName. Registry versions are immutable, so the 0.5.0 metadata has to be right on the first publish.Tests
corepack yarn checkpasses (mcp-server: 14 files, 207 tests). New tests cover the widget domain, exact-origin normalization,redirect_domains, startup refusal of malformed origins, the CLI environment variables, the ChatGPTopenExternalpath and the manifest limits.🤖 Generated with Claude Code