Review times
← Claude Connectors
Rejection library

Why Claude connectors get rejected

What Anthropic has said when it turned Claude connectors down, what causes each reason, and how to fix it before you submit.

12 reasons
0 rejections reported, 0 with a reason

How rejections arriveSince 25 September 2026 the submission portal shows review status and safety-scan results. “Changes requested” means a reviewer left a note to address; “Not approved” comes with notes saying why. Either way you can edit the listing and resubmit.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Couldn’t connect to the serverChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI
Reviewer couldn’t sign inChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI
Tool scan failedChatGPT Plugins, Claude Connectors–Server check
Tool hints missing or wrongChatGPT Plugins, Claude Connectors–Server check
Descriptions instruct the modelClaude Connectors, Claude Plugins, ChatGPT Plugins, Microsoft 365 Agent Store, Grok Plugins, ClawHub–Server check
Description doesn’t matchChatGPT Plugins, Claude Connectors, Grok Plugins–mcplane CLI
Privacy policyChatGPT Plugins, Claude Connectors, Claude Plugins, Muse Connectors, Cursor Marketplace, Microsoft 365 Agent Store–Server check
Field too long or invalidChatGPT Plugins, Claude Connectors, Claude Plugins, Microsoft 365 Agent Store–Server check + CLI
Tools need titlesClaude Connectors, Claude Plugins–Server check
Catch-all request toolClaude Connectors, ChatGPT Plugins, Grok Plugins–Server check
Writes use a token in the chatClaude Connectors, ChatGPT Plugins–Server check
Icon or faviconChatGPT Plugins, Claude Connectors–Server check

Reaching your server

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“Unable to connect to your MCP server to conduct further testing.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We’re unable to connect to your MCP server using the MCP URL and/or test credentials we were given.”
ChatGPT Plugins · OpenAI’s help centre, quoted on the developer forum
“ERR_CONNECTION_RESET before connection established”
ChatGPT Plugins · First-hand: one of our own submissions; OpenAI’s answer to an appeal

The server works for you but not from the reviewer’s network. Review traffic goes through TLS-inspecting proxies and automated clients, which fail on things a browser at home never hits: Encrypted ClientHello advertised in DNS (the proxy resets the handshake, so nothing reaches your logs), a firewall or bot rule that answers scripts with 403, a 403 instead of a 401 for calls without a token, or a URL pasted with a trailing slash that 404s. ECH alone cost one developer three ChatGPT rejections. OpenAI uses the same wording when the test credentials don’t work, so check sign-in too.

How to fix it

  • Turn off Encrypted ClientHello for the MCP host. On Cloudflare it’s a zone setting, and only reachable through the API on the free plan.
  • Let automated clients through on the MCP path: no bot challenge, no user-agent or country rules.
  • Answer calls without a token with 401 and a WWW-Authenticate header, never 403.
  • Serve /mcp/ as well as /mcp.
  • Test from outside your own network, with a TLS 1.2 client as well as a browser.
  • Appeal by replying to the rejection email with your case ID, and ask what error the reviewer saw.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers advertise Encrypted ClientHello in DNS (505 of 3,185), and 39% of servers stop working when the URL has a trailing slash (221 of 562).

Caught by

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“If any tools are flagged for missing titles or annotations, fix them on your server before submitting.”
Claude Connectors · Anthropic’s submission guide
“Tool scan failed: Internal service error”
ChatGPT Plugins · An error posted on the OpenAI developer forum
“Tool scan failed: method not implemented: server/discover”
ChatGPT Plugins · First-hand: one of our own submissions; ChatGPT’s submission portal

Before a person looks at it, the store scans your tools. ChatGPT’s scan calls methods beyond tools/list, such as server/discover, which isn’t in the MCP spec, and a server that answers an unknown method with HTTP 500 or error -32603 looks crashed. One developer’s scan only passed once tools/list was under about 32,000 tokens. A server behind OAuth that answers initialize without a token but refuses tools/list leaves the connector with no actions. Claude’s portal flags tools without titles or annotations at this step.

How to fix it

  • Answer methods you don’t implement with JSON-RPC error -32601 (method not found) at HTTP 200.
  • Keep tools/list compact: trim long descriptions and schemas.
  • Behind OAuth, pick one: 401 for everything until sign-in, or list tools without a token and require one to call them.
  • Give every tool a title and explicit hints before you submit to Claude.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers crash or return a non-standard error for a method they don’t implement (92 of 562).

Caught by

Signing in

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“Test credentials: required, and they must be for a fully populated account”
Claude Connectors · Anthropic’s connector checklist
“We’re unable to complete your sign-in or OAuth flow. Please ensure valid, working credentials are included and that they require no additional setup or verification to access your service.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We were unable to proceed through the OAuth flow. The authorization URL loaded a blank page with no login or consent interface available to enter the submitted test credentials.”
ChatGPT Plugins · First-hand: one of our own submissions; a ChatGPT rejection email
“Plugins that require additional login steps, such as a new account sign-up or 2FA through an inaccessible account, will be rejected.”
ChatGPT Plugins · OpenAI’s plugin guidelines

Reviewers sign in as strangers, on a network you don’t control, with the account you gave them. It breaks when the account needs an emailed code, a magic link, MFA or a Google login, when the sign-in page waits on JavaScript from another domain that is slow or blocked (they see a blank page), when that domain sits behind a bot challenge, or when OAuth discovery or client registration fails.

How to fix it

  • Give reviewers a dedicated account with a login and password that works immediately: no MFA, no email or SMS codes, no magic links, not your Google or SSO login, and seeded with data for every test case.
  • Sign in once as a brand-new user, in a fresh browser, from outside your network. Make the page show something before any JavaScript loads.
  • Keep bot challenges off your sign-in and auth domains, not just the MCP path.
  • Serve protected-resource metadata on the MCP host, authorisation-server metadata and PKCE (S256), and Dynamic Client Registration that accepts the store’s redirect URIs.
  • Accept private-use redirect schemes such as cursor:// in client registration, or desktop clients can’t sign in at all.

Caught by

  • auth.prm Protected-resource metadata resolves on the MCP hostServer check
  • auth.as-metadata Authorization-server metadata resolvesServer check
  • auth.pkce PKCE (S256) is supportedServer check
  • auth.dcr Dynamic Client Registration is offeredServer check
  • auth.dcr-native Registration accepts native redirect URIs (with --register)mcplane CLI
  • A reviewer account a stranger can use, and a sign-in page that renders without third-party scriptsBy hand

Tool definitions

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“Every tool must include a title and the applicable hint: readOnlyHint: true for read-only tools, and destructiveHint: true for tools that modify or delete data.”
Claude Connectors · Anthropic’s connector checklist
“One or more of your tool’s annotations do not appear to match the tool’s behavior. Please confirm annotations are explicitly set to true or false (not null) for every tool.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“Use true for public or open-ended entities, including read-only web search and arbitrary destinations. A tool confined to a bounded private account, workspace, or catalog may use false, even when externally hosted.”
ChatGPT Plugins · OpenAI’s plugin guidelines, on openWorldHint

ChatGPT and Claude use readOnlyHint, destructiveHint and openWorldHint to decide when to ask the user before a tool runs, and both reviews check the hints against what each tool does. OpenAI wants all three set to true or false on every tool, and its definitions are stricter than many developers expect: a tool that posts, sends or uploads is not read-only; destructiveHint covers irreversible sends and transactions, and being able to undo something doesn’t make it non-destructive; openWorldHint depends on where the tool reaches, not on whether it calls an external API.

How to fix it

  • Set readOnlyHint, destructiveHint and openWorldHint to true or false on every tool, never null.
  • Mark tools that post, send or upload as readOnlyHint: false, and destructiveHint: true when the effect can’t be taken back.
  • Use openWorldHint: true for public or open-ended destinations, and false for a tool limited to the user’s own account, workspace or catalogue.
  • OpenAI no longer asks for a justification per hint. If its automated review flags a hint you believe is right, appeal with an explanation.

How common it is: in our scan of Claude’s connector directory on 29 September, 18% of servers leave at least one tool without explicit safety hints (102 of 564).

Caught by

Applies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub

What reviewers and the rules say

“Describe what the tool does, and don’t tell Claude how to behave.”
Claude Connectors · Anthropic’s connector checklist
manipulative ranking language in tool descriptions
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)
“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)
“authority too broad / could change agent behavior without clear guardrails”
ClawHub · ClawHub’s security scan, quoted in an issue

Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.

How to fix it

  • Describe what the tool does and returns, as facts.
  • Move usage guidance into the server’s instructions or your docs.
  • If a line has to stay, explain it in the submission’s notes for reviewers.

How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).

Caught by

Applies to ChatGPT Plugins · Claude Connectors · Grok Plugins

What reviewers and the rules say

“The description must match the tool’s actual behavior.”
Claude Connectors · Anthropic’s connector checklist
Second rejection: feedback on how our tools are described.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)
A skill file still described the old API-key sign-in after the plugin had moved to browser OAuth.
Grok Plugins · An xAI reviewer on a pull request (paraphrased)

Reviewers compare what your listing, tool descriptions and skill files promise with what the tools do. They drift: a renamed tool, a removed feature or an old sign-in method still described in a skill file reads as misleading.

How to fix it

  • Describe each tool precisely: what it does, what it returns and when to use it.
  • Re-read the listing, tool descriptions and skill files after every change to the server.
  • Before resubmitting, compare what the store is reviewing with what the server does now.

Caught by

  • listing.test-tools Test cases use tools the server hasmcplane CLI
  • mcplane drift: what each store is reviewing against what the server does nowmcplane CLI

Applies to Claude Connectors · Claude Plugins

What reviewers and the rules say

“MCP servers must provide all applicable annotations for their tools, in particular readOnlyHint, destructiveHint, and title.”
Claude Connectors · Anthropic’s directory policy

Claude shows a tool’s title in permission prompts and in the directory, and its submission portal flags tools without one. Without a title, people see the raw name, such as search_docs_v2.

How to fix it

  • Add title to each tool, or annotations.title.
  • Keep titles short and plain: “Search documents”, not the function name.

How common it is: in our scan of Claude’s connector directory on 29 September, 9% of servers have tools without a human-readable title (52 of 564).

Caught by

  • tools.title Every tool has a human-readable titleServer check

Applies to Claude Connectors · ChatGPT Plugins · Grok Plugins

What reviewers and the rules say

“Don’t ship a catch-all api_request tool with a method parameter.”
Claude Connectors · Anthropic’s connector checklist
“Do not use discovery, operation selection, or schema fetching with a generic executor to enable operations not individually exposed for review.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“a shell-exec MCP server when a scoped tool would do.”
Grok Plugins · xAI’s contributing guide, on over-broad scope

A tool such as api_request with a method and a path does reads and writes through one door, so its hints can’t be honest and nobody can review what it will do. Anthropic rejects a tool that accepts both safe and unsafe HTTP methods, OpenAI wants every operation the model can call exposed as its own tool, and xAI questions broad shell access where a narrow tool would do.

How to fix it

  • Split it into read tools and write tools, each with honest hints.
  • Expose each operation as its own tool, with its own description and input schema.
  • If a tool has to accept free-form paths or queries, name or link the API it calls in the description.

Caught by

Applies to Claude Connectors · ChatGPT Plugins

What reviewers and the rules say

“anyone who obtains or guesses a token can rewrite”
Claude Connectors · First-hand: one of our own submissions; Anthropic’s review of the Review Times connector
“Remote MCP servers that connect to a remote service and require authentication must use secure OAuth 2.0 with certificates from recognized authorities.”
Claude Connectors · Anthropic’s directory policy

A write tool that takes a secret as a parameter puts the secret in the conversation, where it can leak into logs, other tools or a shared chat. Anthropic treats that as a write nobody owns and requires OAuth for authenticated services. OpenAI counts access credentials and passwords as restricted data a plugin may not solicit.

How to fix it

  • Put writes behind OAuth, so each one is tied to a signed-in account.
  • Or move the write to your site and email the owner a private link. That is what Review Times did.
  • Never return edit tokens in tool results.

Caught by

Policy

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Muse Connectors · Cursor Marketplace · Microsoft 365 Agent Store

What reviewers and the rules say

“Missing or incomplete privacy policies result in immediate rejection.”
Claude Connectors · Anthropic’s submission guide
privacy policy gaps and undisclosed returned data
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

Every store asks for a privacy policy, and reviewers read it. Anthropic wants it to cover data collection, usage and storage, third-party sharing, retention and contact information. OpenAI asks for the categories of personal data you collect, why you use them, who receives them, how long you keep them and what users can do about it. Data your tools return that the policy doesn’t mention counts as a gap.

How to fix it

  • Link a page that loads without signing in.
  • Cover collection, use, sharing, retention, user controls such as deletion, and how to contact you.
  • Mention the data your tools return and any free-form content users send, not only what they type into forms.

How common it is: in our scan of Claude’s connector directory on 29 September, 4% of servers link a privacy policy that doesn’t load (145 of 3,283).

Caught by

Listing details

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“server name up to 100 characters, one-liner up to 200 characters, description up to 2,000 characters”
Claude Connectors · Anthropic’s submission guide
“Tool names must be 64 characters or fewer.”
Claude Connectors · Anthropic’s connector checklist
“Up to three starter prompts, at most 128 characters each. Make them unique and omit app @mentions.”
ChatGPT Plugins · OpenAI’s submission docs
“Each prompt mustn’t exceed 128 characters.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Each store enforces its own limits, some without telling you until review. ChatGPT’s display name and subtitle stop at 30 characters each, and it takes up to three starter prompts. Claude caps names at 100 characters, one-liners at 200, descriptions at 2,000 and tool names at 64. Microsoft wants three to five prompts per command, none over 128 characters.

How to fix it

  • Keep a shorter name for ChatGPT if yours runs past 30 characters.
  • Write up to three distinct starter prompts for ChatGPT, without @mentions.
  • Rename any tool over 64 characters.

How common it is: in our scan of Claude’s connector directory on 29 September, 3% of servers have a name longer than ChatGPT’s 30 characters (92 of 3,283).

Caught by

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“the fallback favicon is not resolving”
Claude Connectors · First-hand: one of our own submissions; Anthropic’s review of the Review Times connector
“Icons and logos must be square and at least 48 by 48 pixels.”
ChatGPT Plugins · OpenAI’s submission docs

With no icon set, Claude’s directory falls back to /favicon.ico on your server’s domain, and reviewers flag it when that 404s. ChatGPT wants square icons of at least 48 by 48 pixels, and its developer-mode upload stops at 10 KB.

How to fix it

  • Serve /favicon.ico on the MCP server’s domain.
  • Keep a square 512×512 PNG behind a direct link ending in .png. It covers every store.
  • Export an 8-bit PNG under 10 KB for ChatGPT’s developer-mode dialog.

Caught by

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.