# OpenAI app review domain token

Source: https://immiscible.fly.dev/docs/api/get-well-known-openai-apps-challenge

`GET /.well-known/openai-apps-challenge`

The token OpenAI's app submission asks the host to serve, to prove the MCP server's domain: the value of the `OPENAI_APPS_CHALLENGE` setting, as plain text. Without the setting it is `404`.

## Authentication

Public. No credential. Public routes are rate limited per address.

## Request

curl:

```bash
curl "https://immiscible.fly.dev/.well-known/openai-apps-challenge"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/.well-known/openai-apps-challenge', {
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

res = requests.get(
    "https://immiscible.fly.dev/.well-known/openai-apps-challenge",
)
print(res.status_code, res.json())
```
