Review times
← Cursor Marketplace
Rejection library

Why Cursor plugins get rejected

What Cursor has said when it turned Cursor plugins down, what causes each reason, and how to fix it before you submit.

6 reasons
0 rejections reported, 0 with a reason

How rejections arriveEvery plugin is reviewed by hand. Cursor staff have said the publish form sends no confirmation and has no status page, so silence is normal.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Couldn’t connect to the serverChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI
Reviewer couldn’t sign inChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI
Privacy policyChatGPT Plugins, Claude Connectors, Claude Plugins, Muse Connectors, Cursor Marketplace, Microsoft 365 Agent Store–Server check
Plugin repository problemClaude Plugins, Cursor Marketplace, Grok Plugins, Gemini CLI Extensions, Docker MCP Catalog–mcplane CLI
Not accepting submissionsDocker MCP Catalog, Cursor Marketplace–By hand
No reason givenChatGPT Plugins, Claude Plugins, Grok Plugins, Docker MCP Catalog, Gemini CLI Extensions, Cursor Marketplace–By hand

Reaching your server

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“Unable to connect to your MCP server to conduct further testing.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We’re unable to connect to your MCP server using the MCP URL and/or test credentials we were given.”
ChatGPT Plugins · OpenAI’s help centre, quoted on the developer forum
“ERR_CONNECTION_RESET before connection established”
ChatGPT Plugins · First-hand: one of our own submissions; OpenAI’s answer to an appeal

The server works for you but not from the reviewer’s network. Review traffic goes through TLS-inspecting proxies and automated clients, which fail on things a browser at home never hits: Encrypted ClientHello advertised in DNS (the proxy resets the handshake, so nothing reaches your logs), a firewall or bot rule that answers scripts with 403, a 403 instead of a 401 for calls without a token, or a URL pasted with a trailing slash that 404s. ECH alone cost one developer three ChatGPT rejections. OpenAI uses the same wording when the test credentials don’t work, so check sign-in too.

How to fix it

  • Turn off Encrypted ClientHello for the MCP host. On Cloudflare it’s a zone setting, and only reachable through the API on the free plan.
  • Let automated clients through on the MCP path: no bot challenge, no user-agent or country rules.
  • Answer calls without a token with 401 and a WWW-Authenticate header, never 403.
  • Serve /mcp/ as well as /mcp.
  • Test from outside your own network, with a TLS 1.2 client as well as a browser.
  • Appeal by replying to the rejection email with your case ID, and ask what error the reviewer saw.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers advertise Encrypted ClientHello in DNS (505 of 3,185), and 39% of servers stop working when the URL has a trailing slash (221 of 562).

Caught by

Signing in

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“We’re unable to complete your sign-in or OAuth flow. Please ensure valid, working credentials are included and that they require no additional setup or verification to access your service.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We were unable to proceed through the OAuth flow. The authorization URL loaded a blank page with no login or consent interface available to enter the submitted test credentials.”
ChatGPT Plugins · First-hand: one of our own submissions; a ChatGPT rejection email
“Plugins that require additional login steps, such as a new account sign-up or 2FA through an inaccessible account, will be rejected.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“Test credentials: required, and they must be for a fully populated account”
Claude Connectors · Anthropic’s connector checklist

Reviewers sign in as strangers, on a network you don’t control, with the account you gave them. It breaks when the account needs an emailed code, a magic link, MFA or a Google login, when the sign-in page waits on JavaScript from another domain that is slow or blocked (they see a blank page), when that domain sits behind a bot challenge, or when OAuth discovery or client registration fails.

How to fix it

  • Give reviewers a dedicated account with a login and password that works immediately: no MFA, no email or SMS codes, no magic links, not your Google or SSO login, and seeded with data for every test case.
  • Sign in once as a brand-new user, in a fresh browser, from outside your network. Make the page show something before any JavaScript loads.
  • Keep bot challenges off your sign-in and auth domains, not just the MCP path.
  • Serve protected-resource metadata on the MCP host, authorisation-server metadata and PKCE (S256), and Dynamic Client Registration that accepts the store’s redirect URIs.
  • Accept private-use redirect schemes such as cursor:// in client registration, or desktop clients can’t sign in at all.

Caught by

  • auth.prm Protected-resource metadata resolves on the MCP hostServer check
  • auth.as-metadata Authorization-server metadata resolvesServer check
  • auth.pkce PKCE (S256) is supportedServer check
  • auth.dcr Dynamic Client Registration is offeredServer check
  • auth.dcr-native Registration accepts native redirect URIs (with --register)mcplane CLI
  • A reviewer account a stranger can use, and a sign-in page that renders without third-party scriptsBy hand

Policy

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Muse Connectors · Cursor Marketplace · Microsoft 365 Agent Store

What reviewers and the rules say

“Missing or incomplete privacy policies result in immediate rejection.”
Claude Connectors · Anthropic’s submission guide
privacy policy gaps and undisclosed returned data
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

Every store asks for a privacy policy, and reviewers read it. Anthropic wants it to cover data collection, usage and storage, third-party sharing, retention and contact information. OpenAI asks for the categories of personal data you collect, why you use them, who receives them, how long you keep them and what users can do about it. Data your tools return that the policy doesn’t mention counts as a gap.

How to fix it

  • Link a page that loads without signing in.
  • Cover collection, use, sharing, retention, user controls such as deletion, and how to contact you.
  • Mention the data your tools return and any free-form content users send, not only what they type into forms.

How common it is: in our scan of Claude’s connector directory on 29 September, 4% of servers link a privacy policy that doesn’t load (145 of 3,283).

Caught by

Plugin package

Applies to Claude Plugins · Cursor Marketplace · Grok Plugins · Gemini CLI Extensions · Docker MCP Catalog

What reviewers and the rules say

“Put a README of at least 40 words in the plugin folder”
Claude Plugins · Anthropic’s plugin checklist (blocks if missing)
“main, v1.2.3, and abbreviated SHAs are rejected by the validator.”
Grok Plugins · xAI’s contributing guide
“looks like there’s a failure in the CI job that ran, you’ll need to fix that first”
Docker MCP Catalog · A Docker maintainer on a pull request
“(MIT or Apache 2 are great, GPL is not).”
Docker MCP Catalog · Docker’s contributing guide

Stores that take plugins read them from a public GitHub repository at a pinned commit, and validate it before anyone reviews it. A private repository, a missing manifest, README or licence, a branch instead of a commit, or a failing CI run leaves nothing to review. Gemini CLI’s gallery skips a repository that fails validation without saying so.

How to fix it

  • Host the plugin in its own public GitHub repository. A private monorepo can’t be pinned.
  • Claude: add .claude-plugin/plugin.json, a README of at least 40 words and a LICENSE, then run claude plugin validate --strict.
  • Don’t leave a SKILL.md at the root beside a skills/ folder. Claude loads it as a single-skill plugin and hides the rest.
  • Grok: pin a full 40-character commit SHA, not main or a tag.
  • Docker: use a licence that lets people run the server, such as MIT or Apache 2.0, and get CI green before asking for review.
  • Gemini CLI: put gemini-extension.json at the root and add the gemini-cli-extension topic.

Caught by

The store itself

Applies to Docker MCP Catalog · Cursor Marketplace

What reviewers and the rules say

“We keep the marketplace curated. We work directly with plugin authors we trust, and every submission goes through our internal review process.”
Cursor Marketplace · Cursor’s marketplace security page
“We’re actually no longer accepting new mcp server entries”
Docker MCP Catalog · A Docker maintainer on a pull request, 8 August 2026

Some stores stop taking new entries without closing the door. A Docker maintainer said so on 8 August, quoted above; since then 639 more pull requests adding a server have been opened, and none has been merged (counted on 1 October). Cursor curates its marketplace and works directly with plugin authors it trusts.

How to fix it

  • Read the latest maintainer comments in the queue before you open a pull request.
  • Ask on your pull request whether it will be reviewed at all.
  • List the server where intake is open, such as the official MCP Registry, which takes entries through its own CLI.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to ChatGPT Plugins · Claude Plugins · Grok Plugins · Docker MCP Catalog · Gemini CLI Extensions · Cursor Marketplace

What reviewers and the rules say

The rejection email said “Please see the details below:”, followed by nothing.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)
The submission portal only shows “Rejected” with no notes.
Claude Plugins · A developer in Anthropic’s plugin issue tracker (paraphrased)

Some reviews end without an explanation. ChatGPT rejection emails have arrived with an empty details section, Claude’s old plugin portal showed “Rejected” with no notes, Grok and Docker maintainers often close pull requests without a comment, Gemini CLI’s crawler skips repositories silently, and Cursor’s publish form sends no confirmation.

How to fix it

  • ChatGPT: reply to the rejection email with your case ID and ask for the specific finding.
  • On a pull request, ask what would make it acceptable.
  • Rule out the mechanical causes with a server check before you resubmit.

Of the 6 pull requests maintainers closed in the Grok and Docker queues we track, none had a comment saying why (checked 1 October).

Caught by

No script can see this one. A server check rules out the mechanical causes first.

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.