“domain_verification_required”
The portal could not read the exact verification token it generated at /.well-known/openai-apps-challenge on your MCP host or an allowed parent host. The three common causes: (1) Nothing is served at https://<your-mcp-host>/.well-known/openai-apps-challenge (a 404, or the MCP route swallows it). To tell: The doctor's domain-verification line shows the status that URL answers. (2) Something is served, but not the bare token: JSON, an HTML page, a list of tokens, or the token with extra text. To tell: The doctor warns at domain-verification and names the content type. (3) The file is right but unreachable to OpenAI: a bot challenge or WAF in front of the host, a redirect to another host, or another plugin's token at the same URL. To tell: The doctor reads it from its own network; test from another network, and use a distinct hostname or an allowed parent origin if the URL is shared. One command shows which: npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory.
Check your server now
npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory
Discovery only: no credential, no tool called. It prints the first broken step, whose it is, and the fix with its source, and shows the view in a sandboxed preview.
Who prints it
OpenAI's plugin submission portal, when Verify Domain has not passed for the MCP host.
The three causes, and how to tell them apart
- Cause 1. Nothing is served at https://<your-mcp-host>/.well-known/openai-apps-challenge (a 404, or the MCP route swallows it).
The check flags it atdomain-verification. The doctor's domain-verification line shows the status that URL answers. - Cause 2. Something is served, but not the bare token: JSON, an HTML page, a list of tokens, or the token with extra text.
The check flags it atdomain-verification. The doctor warns at domain-verification and names the content type. - Cause 3. The file is right but unreachable to OpenAI: a bot challenge or WAF in front of the host, a redirect to another host, or another plugin's token at the same URL.
The check cannot see this one from outside: it happens inside the host or the portal. The doctor reads it from its own network; test from another network, and use a distinct hostname or an allowed parent origin if the URL is shared.
Sources and public reports
- return only the exact token, not JSON or a list of tokens; paths are ignored [source: OpenAI plugin submission, domain verification, read 8 October 2026]
- domain_verification_required [source: OpenAI plugin submission errors, read 8 October 2026]
Keep checking
Other messages
- “MCP App renders blank”
- “Resource not found: ui://”
- “Tool has no UI”
- “Invalid ui.domain format”
- “ui.domain mismatch”
- “Refused to load the script”
- “annotations_required”
- “frame_domain_explanation_required”
- “screenshots_not_allowed”
- “Failed to fetch template”
Written 8 October 2026 from the sources above. The MCP Apps check · MCP Liveness · Terms · Privacy