Review times
← Vercel Connect
Rejection library

Why Vercel Connect services get rejected

The reasons that apply to Vercel Connect services, what causes each one, and how to fix it before you submit.

2 reasons
0 rejections reported, 0 with a reason

How rejections arriveThe Submit a Service form won’t send until each OAuth method has returned a real token through a test connector, so discovery and sign-in problems show up in the form first. Vercel then reviews every submission before publishing it to the directory. No Vercel Connect rejections have been reported yet, so these are the reasons that apply to any store that connects to your server.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Couldn’t connect to the serverChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI
Reviewer couldn’t sign inChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect–Server check + CLI

Reaching your server

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“Unable to connect to your MCP server to conduct further testing.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We’re unable to connect to your MCP server using the MCP URL and/or test credentials we were given.”
ChatGPT Plugins · OpenAI’s help centre, quoted on the developer forum
“ERR_CONNECTION_RESET before connection established”
ChatGPT Plugins · First-hand: one of our own submissions; OpenAI’s answer to an appeal

The server works for you but not from the reviewer’s network. Review traffic goes through TLS-inspecting proxies and automated clients, which fail on things a browser at home never hits: Encrypted ClientHello advertised in DNS (the proxy resets the handshake, so nothing reaches your logs), a firewall or bot rule that answers scripts with 403, a 403 instead of a 401 for calls without a token, or a URL pasted with a trailing slash that 404s. ECH alone cost one developer three ChatGPT rejections. OpenAI uses the same wording when the test credentials don’t work, so check sign-in too.

How to fix it

  • Turn off Encrypted ClientHello for the MCP host. On Cloudflare it’s a zone setting, and only reachable through the API on the free plan.
  • Let automated clients through on the MCP path: no bot challenge, no user-agent or country rules.
  • Answer calls without a token with 401 and a WWW-Authenticate header, never 403.
  • Serve /mcp/ as well as /mcp.
  • Test from outside your own network, with a TLS 1.2 client as well as a browser.
  • Appeal by replying to the rejection email with your case ID, and ask what error the reviewer saw.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers advertise Encrypted ClientHello in DNS (505 of 3,185), and 39% of servers stop working when the URL has a trailing slash (221 of 562).

Caught by

Signing in

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“We’re unable to complete your sign-in or OAuth flow. Please ensure valid, working credentials are included and that they require no additional setup or verification to access your service.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We were unable to proceed through the OAuth flow. The authorization URL loaded a blank page with no login or consent interface available to enter the submitted test credentials.”
ChatGPT Plugins · First-hand: one of our own submissions; a ChatGPT rejection email
“Plugins that require additional login steps, such as a new account sign-up or 2FA through an inaccessible account, will be rejected.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“Test credentials: required, and they must be for a fully populated account”
Claude Connectors · Anthropic’s connector checklist

Reviewers sign in as strangers, on a network you don’t control, with the account you gave them. It breaks when the account needs an emailed code, a magic link, MFA or a Google login, when the sign-in page waits on JavaScript from another domain that is slow or blocked (they see a blank page), when that domain sits behind a bot challenge, or when OAuth discovery or client registration fails.

How to fix it

  • Give reviewers a dedicated account with a login and password that works immediately: no MFA, no email or SMS codes, no magic links, not your Google or SSO login, and seeded with data for every test case.
  • Sign in once as a brand-new user, in a fresh browser, from outside your network. Make the page show something before any JavaScript loads.
  • Keep bot challenges off your sign-in and auth domains, not just the MCP path.
  • Serve protected-resource metadata on the MCP host, authorisation-server metadata and PKCE (S256), and Dynamic Client Registration that accepts the store’s redirect URIs.
  • Accept private-use redirect schemes such as cursor:// in client registration, or desktop clients can’t sign in at all.

Caught by

  • auth.prm Protected-resource metadata resolves on the MCP hostServer check
  • auth.as-metadata Authorization-server metadata resolvesServer check
  • auth.pkce PKCE (S256) is supportedServer check
  • auth.dcr Dynamic Client Registration is offeredServer check
  • auth.dcr-native Registration accepts native redirect URIs (with --register)mcplane CLI
  • A reviewer account a stranger can use, and a sign-in page that renders without third-party scriptsBy hand

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.