IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. OXU Workspace
  3. Applications
  4. OXU Developer
  5. User guides
  6. 6. Publish your app

Prepare before publishing your app

Previous6. Publish your appNext7. Manage your app

Last updated 7 months ago

  • Submission phases at a glance
  • What to prepare before you submit
  • Submit and publish
  • Review process
  • Phase 4 — After approval
  • FAQ

The Store is where customers discover, install, and manage all Oten and third‑party apps. Any developer can build an app and submit it for review. This page explains the end‑to‑end submission flow, what reviewers look for, and how to avoid common pitfalls.

All apps go through four phases: Prepare → Submit → Review → After approval. Expect an initial response within a few business days. Duration depends on the app’s scope, complexity, and how quickly feedback is addressed.

Submission phases at a glance

  1. Prepare for submission: verify requirements, quality, security, and assets

  2. Submit your app: complete the form in the Developer portal and send for review

  3. Review process: address feedback (if any) until approval

  4. After approval: monitor analytics, manage reviews, and ship updates via versions

What to prepare before you submit

Before you click Submit, make sure the essentials below are complete. This avoids back‑and‑forth during review.

Minimum setup:

  • Application Info: name, short/long descriptions, category/tags, logo, screenshots, website, support email/URL

  • Policies: Website, public privacy policy URL and terms of service URL

  • API access (if your app exposes APIs to others): define your resource server with permissions, features, and scopes. See how to declare resource server

  • Review materials: demo credentials or seed data (if needed) and brief reviewer instructions

Pre‑submit checklist (quick view):

Submit from the Developer portal once preparation is complete:

You will see an on‑screen confirmation; the app status changes Pending approval.

What reviewers evaluate:

  • Product: core value, UX, stability, accessibility basics

  • Engineering: correctness of OAuth, scopes, APIs, and webhooks

  • Security: transport/security controls, dependency risk, secrets handling

  • Privacy: data minimization, policy clarity, user controls and data rights

  • Content and assets: accurate listing, compliant branding

  • Support and docs: supportability, troubleshooting, and completeness

  • Legal: terms acceptance, licensing/trademarks

If issues are found, you’ll receive feedback via email or a review board. Address the items and resubmit; the team will re‑evaluate. Initial responses typically arrive within 2–3 business days; total time depends on app complexity and iteration speed.

Once approved, your app published onto Oten Store. Keep track on our Developer portal to:

  • Monitor analytics and adoption trends

  • Manage user reviews and respond to feedback

  • Track overall states

Ongoing maintenance is required to remain compliant and ensure a great user experience.

How long does the review take?

Most apps receive an initial response within a few business days. Complex apps or apps requesting sensitive scopes can take longer.

Why was my app rejected?

Common reasons include missing essential information, over‑broad scopes, unstable auth/config flows, unclear privacy policy, or duplicating existing marketplace functionality without added value.

Do I need a privacy policy and terms?

Yes. End users are required to consent on these to complete Subscribe app request. Public URLs are required if your app collects or processes user data.

Can I submit a private or beta app?

This features will be supported.

What happens if I change scopes after approval?

Requesting new or more sensitive scopes typically requires a new version and trigger re‑review.

How should I handle user data deletion requests?

Document your deletion/export processes and provide a support contact. Implement automated deletion where feasible.

Apps that do not provide clear, unique value or that heavily duplicate existing marketplace functionality may be declined.

Submit and publish

  1. Open Developer portal → App management → App listing.

  2. In application Info, confirm listing details and policies are complete (name, icon, descriptions, screenshots, category/tags, website, support, Privacy Policy URL, Terms of Service URL).

  3. Open resources & security and verify:

  4. Click Submit/Publish app to open the submission screen.

  5. Provide review inputted information and consent the terms and conditions.

  6. Submit.

Review process

Phase 4 — After approval

FAQ

Area
Must have
Where
  • If your app exposes APIs for others: resource server has permissions, features, and scopes defined.

  • If your app uses roles: roles link the right features.

App listing

Name, logo, short/long descriptions, category/tags, website, support

Application Info

Policies

Privacy Policy URL, Terms of service URL

Application Info

Auth

OAuth client with valid redirect URIs; flows tested (PKCE where applicable)

Configure resources & security → OAuth

Scopes/

Permissions

Least‑privilege scopes; if exposing APIs, permissions/features/scopes defined

Configure resources & security → resource server

Pricing

At least one plan or Free listing

Pricing & plans

Docs

Quick start, configuration, troubleshooting

Project docs/README

Review materials

Demo account/seed data and short test steps

Submission form