DevSpace
Allows ChatGPT to securely connect to local projects, enabling file read/write, code search, shell command execution, and Git worktree management on the user's machine.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@DevSpaceInspect my project at ~/dev/myproject and run the test suite"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.

Give ChatGPT a secure connection to your own machine and Turn ChatGPT into Codex
DevSpace is a self-hosted MCP server that lets ChatGPT read, edit, search, and run code in your real local projects — your files, your tools, your terminal — without uploading anything to a third party. You run it on your machine, expose it through a tunnel you control, and approve the connection with a password only you have.
Sponsors and Special Thanks
Related MCP server: ChatGPT Codex Bridge
Installation
DevSpace requires Node >=22.19 <27.
Install the DevSpace CLI:
npm install -g @waishnav/devspaceThen initialize and start the server:
devspace init
devspace serveOr run it without a global install:
npx @waishnav/devspace init
npx @waishnav/devspace serveDuring setup, DevSpace asks for:
the local project folders ChatGPT is allowed to open through DevSpace
the local port, usually
7676your public HTTPS base URL from Cloudflare Tunnel, ngrok, Pinggy, Tailscale Funnel, or another reverse proxy
Use the public origin without /mcp during setup:
https://your-tunnel-host.example.comYou will configure your MCP client with the public /mcp URL after setup.
When the client connects, DevSpace opens an Owner password approval page. Enter
the Owner password printed by devspace init. It is also stored in:
~/.devspace/auth.jsonKeep that password private.
Connect Your MCP Client
The default local endpoint is:
http://127.0.0.1:7676/mcpMost users should connect through a public HTTPS tunnel:
https://your-tunnel-host.example.com/mcpUsing DevSpace as an MCP connector isn't against OpenAI's Usage Policies — it's a standard custom App/connector setup, and writing or running code isn't a restricted use case. But your account is governed by your usage, not by DevSpace. Don't point it at anything that would violate your provider's terms. Used normally, you're fine. (Based on OpenAI's Usage Policies and Service Terms as of June 2026.)
What ChatGPT Can Do
Once connected, ChatGPT can open one of your approved project folders as a workspace. From there, it can inspect the repo, make scoped edits, run commands, and show you what changed.
DevSpace gives ChatGPT tools to:
read, write, and edit files inside the opened workspace
search code and inspect directories
run shell commands for tests, builds, git, and package scripts
use isolated Git worktrees for parallel coding sessions
follow project instructions from
AGENTS.mdandCLAUDE.mddiscover local agent skills from your skill folders
show tool cards and optional change summaries in ChatGPT Apps-compatible hosts
Mental Model
DevSpace is remote access to selected local folders.
You decide which roots are allowed. The MCP client still has powerful local capabilities inside an opened workspace, including shell execution. Treat a connected client like a trusted coding partner with access to your machine.
For a normal ChatGPT coding session:
Start your tunnel.
Run
devspace serve.Connect the MCP client to your public
/mcpURL.Approve the connection with the Owner password.
Ask ChatGPT to open a project inside one of your allowed roots.
Architecture
DevSpace is a local execution layer for MCP hosts. The host remains the orchestrator: it chooses tools, asks for user confirmation, and presents results. DevSpace provides the workspace-scoped capabilities and enforces the local boundaries around them.
ChatGPT / Claude / another MCP host
|
Streamable HTTP MCP server
|
+-------------+------------------+
| |
Workspace and policy layer Tool adapters
| |
| files, search, shell,
| Git, artifacts, agents
|
SQLite-backed local state
|
approved roots, workspaces, worktrees,
process sessions, review checkpointsRequest flow
The host connects to the
/mcpendpoint and completes Owner-password authentication.open_workspaceresolves a checkout or isolated Git worktree under an approved root. It loadsAGENTS.md,CLAUDE.md, and applicable skills so the host receives project-specific instructions.Read-only operations use workspace-aware file, search, and directory tools. Mutating operations go through explicit patch, write, shell, Git, process, or artifact tools and return inspectable results.
Long-running commands and bounded subagents are tracked as process or agent sessions. Their lifecycle, failures, and ownership remain visible to the host instead of being hidden inside an autonomous loop.
Change review uses persisted checkpoints so the host can show a coherent diff relative to the last review point.
Core boundaries
Allowed roots: every workspace path is resolved and checked against a configured filesystem root; a workspace is not the same thing as an allowed root.
Workspace lifecycle: checkout mode works in an existing directory; worktree mode creates an isolated Git worktree for parallel work.
Local authority: shell commands run with the user's local authority, so authentication, credentials, tunnels, and destructive actions stay explicit.
Provider adapters: Codex, Claude, OpenCode, Pi, ACP, and other runtimes are translated at the edges. Provider-specific behavior does not define the core workspace model.
Artifacts and review: generated or incoming files and change summaries use dedicated paths rather than being smuggled through ordinary text or shell arguments.
Repository map
Area | Responsibility |
| MCP server setup, tool registration, instructions, and responses |
| Workspace lifecycle, instruction loading, and path containment |
| Long-running process lifecycle and I/O |
| Git inspection and isolated worktrees |
| Bounded local-agent providers, runtimes, and lifecycle |
| Artifact exchange and downloads |
| Persisted change-review state |
| SQLite schema and migrations for local state |
| MCP host widgets and change-review presentation |
| Native desktop process adapters and packaging assets |
The design goal is a small set of composable, inspectable primitives. A host can combine them into a coding workflow without giving DevSpace hidden control over provider permissions, tunnel ownership, or user approval decisions.
Platform Support
DevSpace supports Linux, macOS, and Windows environments with a Bash-compatible shell.
Platform | Status | Notes |
Linux | Supported | Requires Node, npm, Git, and Bash. |
macOS | Supported | Requires Node, npm, Git, and Bash. |
Windows with Git Bash, WSL, MSYS2, or Cygwin Bash | Supported | Git Bash is the simplest native Windows setup. |
Windows PowerShell or | Not supported yet | Install Git Bash or use WSL. |
Run this to inspect your local setup:
devspace doctorDocumentation
Philosophy
Every piece of software is becoming conversational. Natural language is redefining how we interact with tools, workflows, and systems.
My bet is that ChatGPT becomes the operating system for everything. Once we reach AGI, we will simply talk to ChatGPT, and it will prompt, coordinate, and orchestrate sub-agents that set up the right loops for us.
We are not there yet.
DevSpace is one attempt to fast-forward that future: a way for MCP-capable hosts like ChatGPT and Claude to work directly with local project files through explicit, inspectable tools.
Built by Waishnav
I'm Waishnav. I like building opinionated products and tools, and Artifacts is one example.
This year, I began my journey to build a one-person, multi-agent company capable of generating millions in revenue. If you want to follow the failures, wins, lessons, and everything in between, come hang out with me on X.
More from me
Local Development
For working on DevSpace itself:
npm install --include=dev
npm run dev
npm run typecheck
npm test
npm run build
npm run startThis server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityBmaintenanceSelf-hosted MCP server that enables ChatGPT to access and operate on local project files after OAuth authorization, without uploading the workspace elsewhere.38107MIT
- AlicenseNot gradedqualityAmaintenanceSelf-hosted MCP server that lets ChatGPT work with your local codebase through explicit tools.MIT
- AlicenseNot gradedqualityBmaintenanceA self-hosted MCP server that gives ChatGPT a secure connection to your local machine, enabling it to read, edit, search, and run code in your projects.1,337MIT
- AlicenseNot gradedqualityCmaintenanceA self-hosted MCP server that brings a Codex-style coding workflow to ChatGPT, allowing it to read, edit, search, and run code in your local projects.MIT
Related MCP Connectors
An MCP server that gives your AI access to the source code and docs of all public github repos
Hosted MCP server connecting claude.ai, ChatGPT and other AI apps to your own computer
Search your AI chat history (ChatGPT, Claude, Codex) from any MCP client. Remote, private, read-only
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/CYZice/devs-codex'
If you have feedback or need assistance with the MCP directory API, please join our Discord server