OpenAI Plugins, Sign in with ChatGPT, and the Marketplace: A New Distribution Layer

Rohit Ramachandran avatarRohit Ramachandran
OpenAI developer distribution stack linking plugin discovery, ChatGPT identity, interactive extensions, events, and enterprise procurement

OpenAI Plugins, Sign in with ChatGPT, and the Marketplace: A New Distribution Layer

DevDay gave startups a new OpenAI distribution stack: richer ChatGPT plugins, Sign in with ChatGPT, portable plan usage, Sites, MCP Events, shareable profiles, and an enterprise Marketplace. Each piece sounds modest on its own. Together they provide most of the machinery OpenAI needs to mediate discovery, identity, interaction, paid inference, and enterprise procurement.

That is a different business from selling tokens.

A developer can now imagine a product that appears inside ChatGPT as an interactive application, responds when an external event happens, lets a user arrive with an existing OpenAI identity, and—in selected partner integrations—lets that user spend part of an existing Plus or Pro allowance instead of forcing the developer to subsidize every inference call. At the enterprise end, an approved vendor may eventually be purchased against a customer's existing OpenAI commitment.

The pieces are early and uneven. MCP Events is a draft specification. Marketplace is not a public self-serve app store. Some extension surfaces vary by client or plan. Portable plan usage is available only through selected partners. Those constraints matter.

But the direction is clear: OpenAI wants to own the route from discovery to identity, intelligence, interaction, and procurement. Builders should treat this as a new channel with attractive economics—and real platform dependency.

This analysis is part of RohitAI's complete OpenAI DevDay 2026 guide. It focuses on the distribution layer. For shared work and collaboration, read the companion analysis of ChatGPT Space, Pages, and team tasks.

Seven announcements, one platform thesis

OpenAI's official DevDay recap separates this story into multiple launches:

  1. plugin extensions;
  2. improved plugin creation, submission, and discovery;
  3. the ability for eligible Sites to host plugins;
  4. the proposed MCP Events specification;
  5. shareable ChatGPT profiles;
  6. Sign in with ChatGPT, including plan usage at selected partners;
  7. the OpenAI Marketplace for enterprise software.

There is also Pro 500, which supplies the premium compute tier that makes the distribution strategy easier to see. OpenAI is not merely putting third-party logos in a directory. It is connecting software supply to users who already have identity, context, trust, and paid compute inside its products.

The seven pieces line up as one distribution path:

The DevDay distribution stackDiscoverydirectory, rankings,profiles and SitesIdentitySign in plus optionalplan entitlementExperienceplugin extensionsand interactive UIActivationMCP Events andagent automationsProcurementMarketplace andcommitted spendShared foundation: ChatGPT and Codex surfaces, OpenAI models, plan limits, policy and trustA shorter route from finding an app to running work—and a larger dependency on one platform's rulesRohitAI analysis · September 29, 2026

The diagram is not a claim that every component is generally available today. It shows how the announced pieces fit. Availability ranges from live product surfaces to limited partnerships and a draft event protocol.

Plugins are no longer just invisible tools

The word “plugin” used to suggest a narrow connector: give the model a function, let it call an API, return some text. OpenAI's plugin extension documentation describes something closer to an embedded application platform.

Extensions can provide sidebar homes, panels inside conversations, settings views, rich forms, file viewers and editors, display modes, deep links, and bidirectional context between the model and the application. A user can discover a capability in chat, open a persistent interface, inspect structured output, change settings, and pass the result back to the model.

That matters because chat alone is a weak interface for many serious jobs. A sales pipeline needs filters and rows. A design review needs a canvas and comments. A security finding needs evidence, severity, ownership, and status. A deployment tool needs an explicit diff and confirmation step.

The winning plugin will not hide all of that in prose. It will use chat for intent and explanation, then switch to a purpose-built interface for inspection and control.

OpenAI also announced easier creation and submission, plus revised rankings and recommendations. The plugin hub positions the directory as shared across ChatGPT and Codex, while Plugin Creator can help eligible users build a plugin conversationally. Exact availability can depend on plan, client, and workspace permissions. For example, the documentation says some web extension availability for Free and Go users is still coming, and composer mentions are desktop-only at the launch cutoff.

That is why a launch-day article should not reduce “all plans” to “every surface works identically for every account.” Rollouts and clients still matter.

LayerWhat DevDay addedBuilder valueMain dependency
ApplicationExtension panels, homes, forms, settings and file viewsComplex workflows no longer have to fit in chat bubblesClient support and review rules
DiscoveryNew submission flow, rankings, recommendations and profilesPotential access to users already in ChatGPT or CodexPlatform ranking and category competition
ActivationMCP Events draft and Sites-hosted pluginsEvent-driven work and distribution outside a chat threadProtocol maturity, permissions and reliable delivery
Identity and computeSign in with ChatGPT and selected plan-usage integrationsLess onboarding and potentially less vendor-subsidized inferencePer-app caps, allowance rules and partner access
ProcurementOpenAI Marketplace for approved enterprise partnersA path into committed AI budgetsApproval, contracts and opaque launch economics

MCP Events turns a plugin from a tool into a participant

Traditional tool use is pull-based:

user asks -> model decides -> plugin runs -> answer returns

The proposed MCP Events specification adds a push path. A server can advertise event types; a client can subscribe; the server can call a verified webhook when an event happens. That makes workflows such as these possible:

  • a support escalation arrives and triggers a triage task;
  • a deployment fails and starts an investigation;
  • a contract changes and asks an agent to summarize the delta;
  • a CRM opportunity reaches a stage and prepares a briefing;
  • a security scanner produces a finding and opens a review workflow.

This is strategically important because useful agents cannot wait inside an open chat window. They need triggers.

It is also easy to overstate. At the September 29 cutoff, MCP Events is a draft, tied to the 2026-07-28 MCP protocol version. OpenAI says the ChatGPT integration is available to all plans, but the protocol remains draft. The documented transport is webhook-based. Builders need persistent subscription state, callback verification, outbound HTTPS, deduplication, retry discipline, and a record of what happened after an event fired.

A trigger is not authorization. An event saying “invoice overdue” may justify preparing a reminder; it should not automatically justify sending one, changing account status, or charging a card. The event payload, the plugin's data permissions, and the agent's action permissions are separate control planes.

Sign in with ChatGPT is really two products

The name makes this sound like another social-login button. The official Sign in with ChatGPT documentation shows a more interesting split. Identity is available globally in participating tools. In supported apps, eligible Plus and Pro users can separately allow plan usage, which consumes Codex or ChatGPT Work usage included in the plan. The permissions remain distinct:

  1. Identity: with consent, an app can receive basic profile information such as name, email, and photo.
  2. Use my plan: selected apps can let eligible Plus and Pro users consume OpenAI plan allowance inside the third-party product.

Signing in does not grant a plugin access to a user's conversations, memories, connected apps, or action permissions. Users can disconnect a partner under ChatGPT Settings > Security and login; builders should separately document what disconnecting deletes or retains in their own service.

At the cutoff, OpenAI's detailed partner page listed 11 commercial plan-usage apps live: Amp Code, Conductor, Dactyl, Devin, Hermes Agent, Hyperagent, Kilo Code, Notion, Vercel, Vorflux, and Warp. Lovable was marked coming soon. Airtable, Canva, GitLab, HubSpot, and Supabase were sign-in-only, while OpenClaw, OpenCode, Pi, and T3 were listed as open-source integrations.

The commercial insight is portable compute. AI startups often face an awkward choice: charge enough to cover unpredictable model usage, impose tight internal credits, or subsidize early users. If a user can bring an existing OpenAI allowance, the app can potentially spend less on inference while offering a more capable first session.

But it is not free, reserved capacity. The associated plan-usage guidance says partner apps can have weekly caps. An app's cap is a ceiling, not a dedicated pool carved out for that app. Usage still interacts with the user's overall plan. If users opt into credits, additional usage may draw from those credits after the relevant limit is reached.

That creates a product-design obligation: show users which allowance is being consumed, what happens at the cap, and whether paid credits may be used. “Continue” is not sufficient cost disclosure.

Identity only
Use sign-in, bill your own AI

Best when the product needs predictable cross-model economics, owns its inference stack, or cannot tolerate changing plan limits. The login can reduce onboarding without coupling the core service to a user's OpenAI allowance.

Portable allowance
Let eligible users bring compute

Attractive for coding and agent products where launch friction and model cost are high. Design a clear fallback for ineligible users, exhausted caps, model changes, and optional credit use.

Hybrid
Use the plan first, preserve a paid fallback

Often the most resilient option: consume portable allowance when available, then offer an explicit vendor-funded or customer-funded tier instead of letting the workflow fail silently.

Profiles and Sites turn work into a storefront

Shareable profiles add a social discovery surface. They are rolling out gradually on web and desktop and are private by default; viewers must sign in. A profile can show a name, photo, bio, activity, top plugins, and up to 12 Sites. Personal and Business profiles share core identity fields but keep activity, showcase, and sharing settings separate. The recap lists Enterprise, while the detailed Help article says Enterprise is coming soon.

This is more than cosmetic if recommendations and public work reinforce each other. A developer can publish a Site, attach a plugin, demonstrate useful outputs, and let visitors move from a human's reputation to an executable product.

OpenAI also says eligible Business, Enterprise, Healthcare, and Education Sites can host plugins. That makes a Site more than a generated page. It can be a distribution endpoint for an interactive capability inside a governed workspace.

There is a familiar platform loop here:

useful work -> shareable artifact -> creator profile -> plugin discovery -> more useful work

The upside is organic distribution. The risk is that identity, audience, and execution become entangled. Teams should keep an exportable source of truth for content, customer relationships, and authorization records. A ranking change should hurt acquisition, not erase the business.

Marketplace is procurement, not an app-store clone

OpenAI announced an enterprise Marketplace with 32 initial partners across creative software, customer support, legal, security, data, and infrastructure. The important mechanic is not a consumer “Install” button. Eligible enterprises can express interest in approved partner products and may apply part of an existing OpenAI commitment toward them.

That turns committed spend into a channel.

Large companies routinely sign platform agreements before individual teams know every workload they will fund. A marketplace can redirect some of that budget toward partner software without starting procurement from zero. For a startup, access to that budget may be more valuable than top placement in a consumer directory.

The launch leaves major questions unanswered: there is no public self-serve catalog with uniform pricing, no standard revenue share disclosed, and no guarantee that every vendor can apply. Contract mechanics, support boundaries, data processing terms, and renewal incentives may vary.

So “OpenAI launched an App Store” is the wrong headline. The more accurate description is: OpenAI opened a curated enterprise sales and committed-spend channel.

Where Pro 500 fits

The updated ChatGPT Pro tiers put a visible price on the heaviest individual use: Pro 100 at $100 per month, Pro 200 at $200, and Pro 500 at $500. OpenAI says Pro 500 carries 25 times the Plus allowance and, among Pro tiers, is the only one that includes Astra Ultrafast at launch.

Pro 500 deserves its own buyer analysis, but it also completes the platform picture. Once third-party apps can consume plan usage, a higher-priced plan is not only a better ChatGPT subscription. It can become a compute wallet used across an ecosystem.

That does not make $500 economical for everyone. Teams should compare the allowance and latency benefit with direct API spend, the vendor's own subscription, and the value of work completed. The unit is not “messages.” It is accepted tasks, saved time, and avoided integration cost.

The platform risks are ordinary—and serious

The new channel can be genuinely valuable without being neutral. Builders should model at least five dependencies:

  • Discovery risk: rankings and recommendations can change acquisition overnight.
  • Entitlement risk: plan allowances, per-app caps, model access, and credit rules can change unit economics.
  • Surface risk: desktop, web, mobile, ChatGPT, and Codex may not support the same extension features at the same time.
  • Policy risk: review rules or sensitive-action requirements may block a previously acceptable workflow.
  • Procurement risk: marketplace access can shorten sales cycles while making the platform a gatekeeper to contracted demand.

The answer is not to reject the channel. It is to separate what should be portable from what can be optimized for OpenAI.

The procedure layer should remain explicit. RohitAI previously argued that skills are becoming a cross-product workflow standard, while the retirement of Custom GPTs showed why prompts alone are not a durable product boundary. GitHub's Agent Plugins 1.0 offers another portability reference point.

A sensible architecture keeps business rules, customer data, consent records, evaluations, and core services outside a client-specific extension. Then the plugin becomes a first-class distribution surface, not the only place the product exists.

Before shipping a ChatGPT plugin business
01Map every capability to its actual plan, client, region, and rollout status instead of relying on the broad launch label.
02Separate sign-in identity, plugin data access, action permissions, and plan usage in both code and user-facing consent.
03Make allowance consumption, app caps, fallback billing, and optional credit use visible before expensive work begins.
04Design MCP Events for verification, idempotency, retry, replay protection, narrow scopes, and human approval where actions carry risk.
05Keep customer records, policy logic, evaluation data, and an exportable workflow definition outside the extension surface.
06Measure discovery conversion and completed-task economics, but maintain an acquisition path that does not depend on one directory ranking.

Three strategies for builders

Channel
Add ChatGPT as a distribution surface

Keep the existing product and economics. Use a plugin to make a high-value workflow discoverable where users already ask for help. This is the lowest-dependency starting point.

Native
Build around OpenAI identity and allowance

Appropriate when OpenAI models are central, partner access is available, and faster onboarding materially improves the product. Budget for entitlement and fallback complexity from day one.

Infrastructure
Stay portable beneath several hosts

Expose the same underlying service through ChatGPT, Codex, web, and other agent hosts. More engineering work, but less exposure to any single ranking, interface, or subscription policy.

My default recommendation is the third strategy with a strong version of the first: make ChatGPT feel native, but keep the product's durable state and permission model portable.

What to watch next

The next six months will tell us whether this is a real ecosystem or a polished launch bundle. The useful signals are concrete:

DevDay distribution watch list
01Public terms for Marketplace eligibility, economics, commitments, support, and renewal.
02Broader access and published limits for plan usage in third-party apps.
03MCP Events moving from draft to a stable protocol with clear retry and lifecycle semantics.
04Extension feature parity across web, desktop, mobile, ChatGPT, and Codex.
05Evidence that directory recommendations reward completed user value rather than engagement alone.
06Practical disconnect, export, deletion, and audit controls across identity, plugins, Sites, and shared workspaces.

The strongest sign will not be the number of plugins submitted. It will be whether independent products can acquire a user, complete meaningful work, earn revenue, and preserve trust without hiding the cost or surrendering their entire business boundary.

FAQ

Is the OpenAI Marketplace a consumer app store?

Not at launch. OpenAI describes a curated enterprise channel with 32 initial partners. Eligible customers can express interest and may apply existing OpenAI commitments to approved partner software. Public self-serve listing rules and standard economics were not available at the September 29 cutoff.

Does Sign in with ChatGPT share my conversations or memory?

The identity flow is documented as sharing basic profile information with consent, such as name, email, and photo. It does not by itself grant access to conversations, memory, connected apps, or plugin actions. Those capabilities require separate permission paths.

Can every Plus or Pro user spend plan allowance in any app?

No. “Use my plan” is available through selected integrations, is subject to per-app and overall plan limits, and may not support every model or mode. Apps need a fallback for users who are ineligible or have exhausted the relevant allowance.

Are MCP Events production-ready?

The specification was explicitly a draft at DevDay. It is promising for event-driven automation, but production builders should expect protocol changes and implement durable subscription state, webhook verification, idempotency, audit logs, and conservative permissions.

What is the difference between a skill and a plugin?

A skill packages instructions and procedure for an agent. A plugin exposes application capabilities, data connections, actions, and now potentially interactive UI. They can work together: a skill explains how to perform a workflow; a plugin gives the agent and user a governed place to perform it.

Conclusion: use the channel without surrendering the business

OpenAI's developer platform is no longer just an API plus a chat product.

After DevDay, the company has credible pieces for discovery, identity, application UI, event triggers, plan-funded intelligence, public proof of work, and enterprise procurement. The bundle could give small teams distribution and economics that previously required several vendors and a much larger go-to-market operation.

It also concentrates leverage. A founder who treats rankings, entitlements, UI surfaces, and Marketplace access as permanent infrastructure will eventually be surprised. A founder who treats them as a high-value channel—while keeping policy, data, billing, and workflow logic portable—can use the platform without letting it become the whole company.

That is the DevDay bargain: a shorter road to users, with OpenAI collecting more of the tollbooths along the way.