chatgpt-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@chatgpt-mcpList the files in my home directory"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
chatgpt-mcp
A stateless MCP server that exposes explicitly configured capabilities on a Linux computer to ChatGPT or any compatible MCP client.
ChatGPT / MCP client
|
| MCP 2026-07-28
v
chatgpt-mcp
|
| typed ComputerAdapter seam
v
local operating systemChatGPT chooses which tool to call. chatgpt-mcp validates the call against the local capability configuration and performs the operation. It is a thin protocol adapter, not a second planner, and it does not add its own interactive approval loop.
Architecture: SPEC.md. Delivery history: PLAN.md. Detailed ChatGPT/tunnel guide: docs/CHATGPT.md.
Capabilities
Every family except system.info is opt-in. Disabled capability families are omitted from MCP tool discovery where practical.
Tool | Purpose |
| Host/runtime information and granted capability summary |
| List an allowed directory |
| Read an allowed UTF-8 text file |
| Create, overwrite, or append an allowed text file |
| Create an allowed directory |
| Move/rename inside allowed roots |
| Delete inside allowed roots |
| Spawn an allowed executable with an argument array |
| List visible processes |
| Send a signal to a PID |
| Read an allowed system service state |
| Start, stop, or restart an allowed service |
| Launch a configured named application |
| Close an application previously launched through its handle |
| Open an allowed URL scheme |
| Capture the desktop as a PNG MCP image |
| Move the desktop pointer |
| Click the desktop pointer |
| Type literal text into the focused application |
| Send a key sequence to the focused application |
Requirements
Core server:
Linux
Node.js 22+
pnpm 11.20.0 (the installer obtains the pinned version through Corepack or
npx)systemd user services for the persistent tunnel installed by
./install.sh
Optional host commands depend on what you enable:
services:
systemctlbrowser opening:
xdg-opendesktop input:
xdotoolscreenshots: one of
grim,gnome-screenshot,scrot, or ImageMagickimport
The quick installer can install the current official OpenAI tunnel-client and common Debian/Ubuntu desktop helpers when they are missing.
Quick install: ChatGPT + your Linux computer
For one computer, the recommended route is:
ChatGPT Developer Mode
|
OpenAI Secure MCP Tunnel
|
| outbound HTTPS
v
tunnel-client on your computer
|
| stdio
v
chatgpt-mcpNo public inbound listener is required.
The quick installer intentionally uses config.full.example.json, which grants broad owner-controlled access: filesystem read/write from /, wildcard executable access, process/service control, browser opening, screenshots, and desktop input where supported. If you want narrower authority, use config.example.json and the manual setup instead.
1. Create an OpenAI MCP tunnel
Open:
https://platform.openai.com/settings/organization/tunnels
Create a tunnel and copy its ID. It looks like:
tunnel_0123456789abcdef0123456789abcdefFor ChatGPT use, associate the tunnel with the ChatGPT workspace/account that should be able to see it.
Current permission split:
create/edit/delete tunnel: Tunnels Read + Manage
run
tunnel-clientor select the tunnel in ChatGPT: Tunnels Read + Use
2. Create a runtime API key
Open:
https://platform.openai.com/settings/organization/api-keys
Create a normal runtime API key. Do not use an Admin API key for the long-lived tunnel daemon.
The installer asks for the resulting sk-... value with hidden terminal input and stores it locally in .secrets/runtime-api-key with restrictive permissions.
Why does the tunnel need an API key?
The key authenticates tunnel-client to OpenAI's tunnel control plane. It proves that the local daemon is allowed to use the selected tunnel.
It is not used by chatgpt-mcp to call an OpenAI model API. In this setup ChatGPT is already the model/client; Secure MCP Tunnel is only the private transport that lets that ChatGPT conversation reach the local MCP server.
tunnel_... = which tunnel this computer belongs to
sk-... = permission for tunnel-client to use that tunnelchatgpt-mcp does not make /v1/responses or other model-inference requests with this runtime key. OpenAI API model billing is separate from ChatGPT subscription usage. The current Secure MCP Tunnel documentation does not publish a separate tunnel-pricing schedule; check current OpenAI documentation if that changes.
3. Clone and run the installer
git clone https://github.com/alexcodeplace/chatgpt-mcp.git
cd chatgpt-mcp
./install.shThe installer:
asks for the tunnel ID and runtime API key if they are not already supplied;
protects both values under
.secrets/;obtains the project-pinned pnpm 11.20.0 without requiring a writable
/usr/binCorepack shim;installs dependencies and runs the full project gate;
creates
config.local.jsonfrom the broad-control template;installs the official OpenAI
tunnel-clientif missing on supported Linux architectures;installs common desktop helpers on Debian/Ubuntu when needed;
initializes the
chatgpt-computertunnel profile;uses an ephemeral loopback health port so an existing service on port 8080 does not block installation;
runs
tunnel-client doctor --explain;installs and starts
~/.config/systemd/user/chatgpt-mcp-tunnel.service;verifies the service and tunnel diagnostics.
Non-interactive setup is also supported:
export CONTROL_PLANE_TUNNEL_ID='tunnel_0123456789abcdef0123456789abcdef'
export CONTROL_PLANE_API_KEY='sk-...'
./install.sh --yesDo not put the API key directly on the ./install.sh ... command line or commit it to Git.
To skip optional desktop-package installation:
./install.sh --no-desktop4. Add it to ChatGPT
While the tunnel service is running:
In ChatGPT web, open Settings → Security and login → Developer mode and enable it.
Select the plus button and create a developer-mode app.
Under Connection, choose Tunnel.
Select the tunnel you created, or paste its
tunnel_idwhen offered.Enable the new app in a conversation.
First test:
Use my computer MCP's system.info tool and report the hostname and enabled capabilities.
If the tunnel is not listed, verify its ChatGPT workspace association and Tunnels Read + Use permission.
Status and uninstall
./scripts/tunnel-status.shThe status command loads the saved runtime key itself and uses an ephemeral health listener, so you do not need to export CONTROL_PLANE_API_KEY manually just to run diagnostics.
Remove the persistent user service while leaving local config/secrets intact:
./scripts/tunnel-uninstall.shManual install / development
The repository pins pnpm 11.20.0. Corepack can force that exact version without corepack enable:
git clone https://github.com/alexcodeplace/chatgpt-mcp.git
cd chatgpt-mcp
corepack pnpm@11.20.0 install
corepack pnpm@11.20.0 gatepnpm gate runs type checking, behavioral tests, and the TypeScript build.
If Corepack is unavailable, use npx -y pnpm@11.20.0 instead.
Configure manually
cp config.example.json config.local.json
export CHATGPT_MCP_CONFIG="$PWD/config.local.json"The default configuration exposes only system.info. See config.example.json for every capability family. config.local.json and .secrets/ are gitignored.
For intentionally broad authority, copy config.full.example.json instead.
Start over stdio
corepack pnpm@11.20.0 build
CHATGPT_MCP_CONFIG="$PWD/config.local.json" node dist/src/stdio.jsstdout is reserved for MCP protocol traffic. Diagnostics go to stderr.
Start over HTTP
corepack pnpm@11.20.0 build
CHATGPT_MCP_CONFIG="$PWD/config.local.json" corepack pnpm@11.20.0 start:httpDefault endpoint:
http://127.0.0.1:3210/mcpHealth check:
curl http://127.0.0.1:3210/healthzHTTP remains stateless. A non-loopback bind is rejected unless allowed hosts are explicitly configured.
Trust boundary
Filesystem operations pass through central path authorization that rejects traversal, sibling-prefix tricks, and symlink escapes.
shell.execuses direct executable + argument-array spawning with no implicitsh -c.Services and applications are checked against configured authority before invocation.
Browser schemes are validated before opening.
Desktop input and screenshots are separate opt-in capabilities with bounded inputs/outputs.
See SPEC.md for the full contracts.
Development
corepack pnpm@11.20.0 typecheck
corepack pnpm@11.20.0 test
corepack pnpm@11.20.0 build
corepack pnpm@11.20.0 gateGitHub Actions runs the same gate on pushes and pull requests and syntax-checks the installer scripts.
Platform limitations
The concrete adapter is Linux-oriented.
process.listusesps.service.*defaults to systemd'ssystemctl.input.*usesxdotool; native Wayland may need XWayland or a future compositor-specific adapter.screen.capturesupports common Linux screenshot commands; desktop/session permissions still apply.The automatic installer targets Linux amd64/arm64 and systemd user services.
External ChatGPT/tunnel smoke requires the operator's own OpenAI tunnel identity/runtime credentials; repository CI cannot impersonate them.
Upstream references
MCP TypeScript SDK: https://github.com/modelcontextprotocol/typescript-sdk
MCP specification: https://modelcontextprotocol.io/specification/2026-07-28
OpenAI Secure MCP Tunnel: https://developers.openai.com/api/docs/guides/secure-mcp-tunnels
OpenAI tunnel-client: https://github.com/openai/tunnel-client
OpenAI tunnel management: https://platform.openai.com/settings/organization/tunnels
OpenAI runtime API keys: https://platform.openai.com/settings/organization/api-keys
ChatGPT Developer Mode: https://developers.openai.com/api/docs/guides/developer-mode
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
A paid remote MCP for AI agent browser approval MCP, built to return verdicts, receipts, usage logs,
Reasoning, code, anti-deception, memory harness MCP tools. Stdio or HTTPS api.ejentum.com/mcp
MCP server for Wan AI video generation
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/alexcodeplace/chatgpt-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server