MartechARTICLE

OpenAI documents official path for third-party apps inside ChatGPT

The question for AI startup founders is who ends up owning the customer at the end of the conversation.

OpenAI's developer documentation has formalized how third-party apps live inside ChatGPT, with review, checkout, and even paid ads. The question for AI startup founders is who ends up owning the customer at the end of the conversation.

From conversation to storefront

OpenAI Platform's official documentation (platform.openai.com/docs/changelog and the neighboring sections of the same portal) has stopped treating ChatGPT as just a consumer product and now describes, in detail, an entire distribution architecture for third-party apps. It isn't a single announcement: it's a mature documentation structure, with sections dedicated to identity, review, commerce, and advertising inside the conversation. This changes the calculus for anyone deciding today where to build an AI product.

The technical core is the Apps SDK, built on MCP (Model Context Protocol) servers. A third-party app is no longer just a function the model calls: it's a complete service, with its own interface inside the chat (Widgets, Actions), events, user authentication via Sign in with ChatGPT, and a publishing flow with defined steps: brainstorming use cases, defining tools, building the MCP server, adding UI, packaging the plugin, testing, and only then submitting for review.

The entry filter: review as barrier and as seal

The existence of a Submission error reference and MCP server review requirements in the documentation points to something relevant: publishing inside ChatGPT goes through an approval process, not free self-service. This echoes the review model of traditional app stores, with the same two sides.

For founders, the barrier has two opposite effects. On one hand, it filters out noise and reduces competition from poorly made apps fighting for the same storefront, which favors those who already have a mature product. On the other, it creates a single point of failure: OpenAI decides what gets in, what stays out, and can change UI/UX rules without the developer having a vote.

Commerce inside the chat already has a spec

The most revealing part of the documentation is the conversion specs: Restaurant reservation spec, Get Quote spec, and Product checkout spec, plus a dedicated Checkout API reference. This means OpenAI isn't just letting third parties respond inside the chat: it's standardizing how a restaurant reservation, a service quote, or a product purchase gets completed without leaving the conversation.

In practical terms, this removes the need for the third-party app to build its own checkout, but it also removes its control over the most valuable step in the funnel: the transaction. Anyone currently running an e-commerce store, a travel agency, or a quoting service via their own API needs to decide whether it's worth giving up that step in exchange for distribution inside ChatGPT.

Ads: visibility becomes a budget line item

The Ads section of the documentation details a complete programmatic advertising stack: Advertiser API, Campaign Management, Bidding & Budgets, Targeting, Product Feeds, and even Hotel Feeds in limited beta, along with Conversion Tracking and Reporting. This brings ChatGPT's structure closer to that of a Google Ads or Meta Ads, only applied to the responses of a conversational assistant.

In practice, this means that appearing inside a ChatGPT response for a competitive category no longer depends only on product quality, but also on media budget. It's the same move marketplaces and social networks made before: organic visibility drops, paid visibility becomes the norm.

The choice left to founders

The table below summarizes the central trade-off for anyone deciding where to invest the next quarter of engineering:

CriterionBuild inside ChatGPT (Apps SDK/MCP)Keep your own channel
User acquisitionInherited from the ChatGPT user base, but contested through Ads and reviewBuilt from scratch, own CAC cost
Transaction controlGoes through OpenAI's Checkout API and specsTotal, including over data and margin
Policy dependencyHigh: UI rules, review, and bans dictated by the platformLow: depends only on the API's terms of use
Launch speedFaster, reusing distribution infrastructureSlower, requires its own funnel and stack
Data and customer relationshipMediated by OpenAIDirect with the end user

For those at an early stage who need quick validation, the storefront inside ChatGPT reduces the cost of product discovery. For those who already have traction and margin to defend, keeping your own channel preserves the most expensive part of any business: the direct relationship with the paying customer.

The counterpoint: free distribution is also dependency

One possible reading of this scenario is that whoever controls end-user demand ends up capturing value from whoever supplies the offering, even when the platform charges nothing at first. It's a strong argument against betting everything on the ChatGPT storefront: review can get stricter, Ads can effectively become mandatory for anyone who wants visibility, and the Checkout API could, in the future, come with a fee.

But the counter-argument is also real. For most AI founders today, the problem isn't excessive bargaining power held by the platform: it's lack of distribution. An app inside ChatGPT that uses Sign in with ChatGPT and the ready-made conversion specs reaches the market without rebuilding authentication, checkout, or conversation UI, which at the pre-traction stage outweighs the risk of future dependency.

What changes for decision-makers in Brazil

A technical detail in the same documentation matters specifically for anyone operating in Brazil: the Ultrafast mode of gpt-6.1-sol, released on October 8, 2026, is available with global processing and data residency in the US and EU, with no mention of residency in Latin America. This means any app built on this model, whether inside or outside ChatGPT, still runs with data governance designed for the US and Europe.

For Brazilian founders weighing whether to build inside OpenAI's storefront, this adds another layer of dependency beyond the commercial one: the jurisdiction over end-user data remains explicitly outside the radar of the LGPD (Brazil's data protection law). Before packaging a plugin with the Checkout API and conversion specs, it's worth mapping whether your product's data flow can live with that gap, or whether your own channel, slower but with infrastructure of your own choosing, is still the safer bet right now.

Translated from the Brazilian Portuguese original · Read the original