Counter Scan your API

For SaaS

Three reviews, three sets of rules, two of them published

If you already have a public API you are most of the way there, and the part that is left is not engineering. It is three review processes that each reject for different reasons, and one of them does not say what its reasons are.

Claude Connectors Directory

Submissions happen inside a portal in Claude itself, and the account doing the submitting has to belong to a Team or Enterprise organisation. That is the first thing that stops most teams, because it is a plan decision rather than a code change.

Anything that touches a user's own account or private data has to use OAuth with a real consent screen. An API key pasted into a configuration field does not qualify, however well it works. The experience a reviewer expects is: paste the URL, press Connect, land on your login page, approve, done.

A missing or incomplete privacy policy is an immediate rejection, and a certificate that is not from a recognised authority fails quietly inside Claude rather than showing an error. The listing itself has hard limits: a tagline of at most 55 characters, a description of at most 2,000, categories, documentation and privacy links, a support contact, an icon and a slug. Reviewers then call your server for real and try every tool it advertises.

ChatGPT app directory

OpenAI wants your organisation verified and your domain verified before it will look at the app. The endpoint has to be a public HTTPS address; a tunnel to a laptop is fine while you develop and will not pass review.

You declare how authentication works, and you justify every single tool: what it is for and why an assistant needs it. Then you supply test cases that a reviewer can run on both ChatGPT on the web and ChatGPT on a phone, screenshots, and the countries you are available in. The test cases are where most submissions come back, because a flow that works in a browser often has not been tried on mobile.

Muse

Meta has published no requirements at all. There is a Submit a connector button, a statement that submissions are reviewed for functional, security and legal requirements, no SDK, no specification, no fee and no stated review time. Muse is also United States only, so a Canadian or European business needs a US-reachable path before the listing means anything.

There is a second door that is open today. A Muse user can point it at any hosted MCP endpoint or OpenAPI document and Muse will build a custom connector from it, with no review at all. So the OpenAPI document we generate for you is usable immediately, while the directory submission sits in a queue nobody can see into. A server on localhost is unreachable from Muse, which runs in Meta's cloud.

What we do about it

We scan you first, so you can see which of the above you already fail. Then we build one connector that satisfies all three: an MCP endpoint and an OpenAPI document generated from the same definition, OAuth where a directory demands it, the privacy and documentation pages the reviewers open, and listing text that fits inside each field limit. Before any of it is filed it goes through the pre-flight harness, because a connector that passes review and then double-books a customer has cost you more than it earned.