# Dossier requirements

The dossier is markdown prose accompanying your manifest. Cover:

- **Contacts** — technical contact (email) for integration questions;
  the verified submitter is used for review notifications.
- **Official docs** — links to your API reference, webhook guide, auth
  guide, and rate-limit documentation. Public URLs only.
- **Rate limits** — global and per-endpoint, plus burst behavior.
- **Setup AO must perform** — e.g. "create an OAuth app at
  Settings → Developer → New App with callback <url>", marketplace
  listing steps, allowlisting. Be exact; this becomes our runbook.
- **Sandbox offer** — whether you can provide a test account/org, and
  the handoff contact. Do NOT put credentials in the dossier; if you
  have sandbox credentials to share, the portal provides a sealed
  channel for them after approval.
- **Anything weird** — versioned APIs, regional endpoints, IP
  allowlists, webhook quirks. Surprises cost review cycles.
