chatgpt-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@chatgpt-mcpList the files in my home directory"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
chatgpt-mcp
A stateless MCP server that exposes explicitly configured capabilities on a Linux computer to ChatGPT or any compatible MCP client.
ChatGPT / MCP client
|
| MCP 2026-07-28
v
chatgpt-mcp
|
| typed ComputerAdapter seam
v
local operating systemChatGPT chooses which tool to call. chatgpt-mcp validates the call against the local capability configuration and performs the operation. It is a thin protocol adapter, not a second planner, and it does not add its own interactive approval loop.
Architecture: SPEC.md. Detailed ChatGPT/tunnel guide: docs/CHATGPT.md.
Capabilities
Every family except system.info is opt-in. Disabled capability families are omitted from MCP tool discovery where practical.
Tool | Purpose |
| Host/runtime information and granted capability summary |
| List an allowed directory |
| Read an allowed UTF-8 text file |
| Create, overwrite, or append an allowed text file |
| Create an allowed directory |
| Move/rename inside allowed roots |
| Delete inside allowed roots |
| Spawn an allowed executable with an argument array |
| List visible processes |
| Send a signal to a PID |
| Read an allowed system service state |
| Start, stop, or restart an allowed service |
| Launch a configured named application |
| Close an application previously launched through its handle |
| Open an allowed URL scheme |
| Capture the desktop as a PNG MCP image |
| Move the desktop pointer |
| Click the desktop pointer |
| Type literal text into the focused application |
| Send a key sequence to the focused application |
Related MCP server: AX Local Operations MCP Server
Requirements
Core server:
Linux
Node.js 22+
pnpm 11.20.0 (the installer obtains the pinned version through Corepack or
npx)systemd user services for the persistent tunnel installed by
./install.sh
Optional host commands depend on what you enable:
services:
systemctlbrowser opening:
xdg-opendesktop input:
xdotoolscreenshots: one of
grim,gnome-screenshot,scrot, or ImageMagickimport
The quick installer can install the current official OpenAI tunnel-client and common Debian/Ubuntu desktop helpers when they are missing.
Quick install: ChatGPT + your Linux computer
For one computer, the recommended route is:
ChatGPT Developer Mode
|
OpenAI Secure MCP Tunnel
|
| outbound HTTPS
v
tunnel-client on your computer
|
| stdio
v
chatgpt-mcpNo public inbound listener is required.
The quick installer intentionally uses config.full.example.json, which grants broad owner-controlled access: filesystem read/write from /, wildcard executable access, process/service control, browser opening, screenshots, and desktop input where supported. If you want narrower authority, use config.example.json and the manual setup instead.
1. Create an OpenAI MCP tunnel
Open:
https://platform.openai.com/settings/organization/tunnels
Create a tunnel and copy its ID. It looks like:
tunnel_0123456789abcdef0123456789abcdefFor ChatGPT use, associate the tunnel with the ChatGPT workspace/account that should be able to see it.
Current permission split:
create/edit/delete tunnel: Tunnels Read + Manage
run
tunnel-clientor select the tunnel in ChatGPT: Tunnels Read + Use
2. Create a runtime API key
Open:
https://platform.openai.com/settings/organization/api-keys
Create a normal runtime API key. Do not use an Admin API key for the long-lived tunnel daemon.
The installer asks for the resulting sk-... value with hidden terminal input and stores it locally in .secrets/runtime-api-key with restrictive permissions.
Why does the tunnel need an API key?
The key authenticates tunnel-client to OpenAI's tunnel control plane. It proves that the local daemon is allowed to use the selected tunnel.
It is not used by chatgpt-mcp to call an OpenAI model API. In this setup ChatGPT is already the model/client; Secure MCP Tunnel is only the private transport that lets that ChatGPT conversation reach the local MCP server.
tunnel_... = which tunnel this computer belongs to
sk-... = permission for tunnel-client to use that tunnelchatgpt-mcp does not make /v1/responses or other model-inference requests with this runtime key. OpenAI API model billing is separate from ChatGPT subscription usage. The current Secure MCP Tunnel documentation does not publish a separate tunnel-pricing schedule; check current OpenAI documentation if that changes.
3. Clone and run the installer
git clone https://github.com/alexcodeplace/chatgpt-mcp.git
cd chatgpt-mcp
./install.shThe installer:
asks for the tunnel ID and runtime API key if they are not already supplied;
protects both values under
.secrets/;obtains the project-pinned pnpm 11.20.0 without requiring a writable
/usr/binCorepack shim;installs dependencies and runs the full project gate;
creates
config.local.jsonfrom the broad-control template;installs the official OpenAI
tunnel-clientif missing on supported Linux architectures;installs common desktop helpers on Debian/Ubuntu when needed;
initializes the
chatgpt-computertunnel profile;uses an ephemeral loopback health port so an existing service on port 8080 does not block installation;
runs
tunnel-client doctor --explain;installs and starts
~/.config/systemd/user/chatgpt-mcp-tunnel.service;verifies the service and tunnel diagnostics.
Non-interactive setup is also supported:
export CONTROL_PLANE_TUNNEL_ID='tunnel_0123456789abcdef0123456789abcdef'
export CONTROL_PLANE_API_KEY='sk-...'
./install.sh --yesDo not put the API key directly on the ./install.sh ... command line or commit it to Git.
To skip optional desktop-package installation:
./install.sh --no-desktop4. Add it to ChatGPT
While the tunnel service is running:
In ChatGPT web, open Settings → Security and login → Developer mode and enable it.
Select the plus button and create a developer-mode app.
Under Connection, choose Tunnel.
Select the tunnel you created, or paste its
tunnel_idwhen offered.Enable the new app in a conversation.
First test:
Use my computer MCP's system.info tool and report the hostname and enabled capabilities.
If the tunnel is not listed, verify its ChatGPT workspace association and Tunnels Read + Use permission.
Status and uninstall
./scripts/tunnel-status.shThe status command loads the saved runtime key itself and uses an ephemeral health listener, so you do not need to export CONTROL_PLANE_API_KEY manually just to run diagnostics.
Remove the persistent user service while leaving local config/secrets intact:
./scripts/tunnel-uninstall.shManual install / development
The repository pins pnpm 11.20.0. Corepack can force that exact version without corepack enable:
git clone https://github.com/alexcodeplace/chatgpt-mcp.git
cd chatgpt-mcp
corepack pnpm@11.20.0 install
corepack pnpm@11.20.0 gatepnpm gate runs type checking, behavioral tests, and the TypeScript build.
If Corepack is unavailable, use npx -y pnpm@11.20.0 instead.
Configure manually
cp config.example.json config.local.json
export CHATGPT_MCP_CONFIG="$PWD/config.local.json"The default configuration exposes only system.info. See config.example.json for every capability family. config.local.json and .secrets/ are gitignored.
For intentionally broad authority, copy config.full.example.json instead.
Start over stdio
corepack pnpm@11.20.0 build
CHATGPT_MCP_CONFIG="$PWD/config.local.json" node dist/src/stdio.jsstdout is reserved for MCP protocol traffic. Diagnostics go to stderr.
Start over HTTP
corepack pnpm@11.20.0 build
CHATGPT_MCP_CONFIG="$PWD/config.local.json" corepack pnpm@11.20.0 start:httpDefault endpoint:
http://127.0.0.1:3210/mcpHealth check:
curl http://127.0.0.1:3210/healthzHTTP remains stateless. A non-loopback bind is rejected unless allowed hosts are explicitly configured.
Trust boundary
Filesystem operations pass through central path authorization that rejects traversal, sibling-prefix tricks, and symlink escapes.
shell.execuses direct executable + argument-array spawning with no implicitsh -c.Services and applications are checked against configured authority before invocation.
Browser schemes are validated before opening.
Desktop input and screenshots are separate opt-in capabilities with bounded inputs/outputs.
See SPEC.md for the full contracts.
Development
corepack pnpm@11.20.0 typecheck
corepack pnpm@11.20.0 test
corepack pnpm@11.20.0 build
corepack pnpm@11.20.0 gateGitHub Actions runs the same gate on pushes and pull requests and syntax-checks the installer scripts.
Platform limitations
The concrete adapter is Linux-oriented.
process.listusesps.service.*defaults to systemd'ssystemctl.input.*usesxdotool; native Wayland may need XWayland or a future compositor-specific adapter.screen.capturesupports common Linux screenshot commands; desktop/session permissions still apply.The automatic installer targets Linux amd64/arm64 and systemd user services.
External ChatGPT/tunnel smoke requires the operator's own OpenAI tunnel identity/runtime credentials; repository CI cannot impersonate them.
Upstream references
MCP TypeScript SDK: https://github.com/modelcontextprotocol/typescript-sdk
MCP specification: https://modelcontextprotocol.io/specification/2026-07-28
OpenAI Secure MCP Tunnel: https://developers.openai.com/api/docs/guides/secure-mcp-tunnels
OpenAI tunnel-client: https://github.com/openai/tunnel-client
OpenAI tunnel management: https://platform.openai.com/settings/organization/tunnels
OpenAI runtime API keys: https://platform.openai.com/settings/organization/api-keys
ChatGPT Developer Mode: https://developers.openai.com/api/docs/guides/developer-mode
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for Qwen Image 3 AI image generation
MCP server giving AI agents one-connection access to China A-share market intelligence: financials,
MCP server unifying ERPs, CRMs, APIs and knowledge base for Claude, ChatGPT and Gemini.
A paid remote MCP for AI agent browser approval MCP, built to return verdicts, receipts, usage logs,
Related MCP Servers
- AlicenseBqualityDmaintenanceA powerful MCP server that provides interactive user feedback and command execution capabilities for AI-assisted development, featuring a graphical interface with text and image support.144MIT
- AlicenseAqualityDmaintenanceA comprehensive MCP server that enables AI models to perform local file operations, command execution, and task management across multiple platforms. It features advanced capabilities like row-level file editing, directory searching, and system monitoring with built-in security filters.1325Mulan Permissive Software , Version 2
- AlicenseBqualityAmaintenanceA secure MCP server for shell operations, terminal management, and process control, enabling AI assistants to safely execute commands and manage interactive sessions.137046MIT
- AlicenseNot gradedqualityAmaintenanceMCP server enabling AI assistants to securely operate remote servers via persistent SSH sessions, with tools for command execution, file transfer, directory listing, and system monitoring.4MIT