CodeMCP
Provides workspace-bound Git operations on explicitly registered local projects, applying the runtime's path and workspace scope before Git work is performed.
Integrates with OpenAI Secure MCP Tunnel to connect ChatGPT to a local runtime without inbound public MCP exposure. Supports tunnel configuration with restricted runtime API keys, runtime status checks, and exposing workspace-scoped tools for ChatGPT custom apps.
chatgpt-mcp
A secure, workspace-bound bridge between ChatGPT and your machine.
Single Go binary · OpenAI Secure MCP Tunnel · Linux, macOS, and Windows
Get started · Connect ChatGPT · Command Center · Security · Documentation
chatgpt-mcp lets ChatGPT work with local projects through explicitly registered workspaces. The default setup uses OpenAI Secure MCP Tunnel, so the runtime can stay private without exposing an inbound MCP port to the public internet.
Overview
The main path is intentionally small: ChatGPT reaches the local runtime through the Secure MCP Tunnel, then chatgpt-mcp applies workspace scope before filesystem, shell, Git, process, or upstream MCP work happens.
Why chatgpt-mcp
Private by default for ChatGPT — the Secure MCP Tunnel is outbound-only from your machine; public MCP ingress is not required.
Workspace-bound access — filesystem, shell, Git, process, context, memory, rules, skills, and checkpoints operate against explicit
ws_*workspace targets.Local control stays local — use the CLI, full-screen TUI, or embedded Admin UI to inspect and operate the runtime.
MCP aggregation — optionally expose tools from upstream MCP servers through the same runtime.
One cross-platform binary — native releases for Linux, macOS, and Windows on amd64 and arm64, with managed background-service support.
Related MCP server: mcacp
Install
Linux / macOS
curl -fsSL get.mewis.me/chatgpt-mcp.sh | shWindows PowerShell
irm https://get.mewis.me/chatgpt-mcp.ps1 | iexHomebrew
brew tap mewisme/mew
brew install --cask chatgpt-mcpScoop
scoop bucket add mew https://github.com/mewisme/scoop-mew
scoop install mew/chatgpt-mcpBoth chatgpt-mcp and the shorter cgm command are installed. The examples below use cgm.
5-minute setup
1. Initialize
cgm init2. Register the project ChatGPT may work with
cgm workspace register ~/projects/my-projectThe command returns a stable ws_* workspace ID. Register only roots you intentionally want the runtime to reach.
3. Configure the Secure MCP Tunnel
Create a tunnel and a restricted runtime API key in OpenAI Platform, then configure them locally:
cgm tunnel configure \
--enabled \
--id tunnel_... \
--api-key 'sk-...'The runtime key should have Tunnels Read + Use. It is not an OpenAI Admin API key and is not used to call a language model.
4. Start the managed runtime
cgm upVerify locally:
cgm status
cgm tunnel status5. Connect ChatGPT
Enable Developer Mode in ChatGPT, create a custom app using Tunnel, select the same tunnel, and Scan Tools.
The complete Platform permissions and ChatGPT setup flow is in Connect ChatGPT with OpenAI Secure MCP Tunnel.
Operate it
For interactive administration:
cgm tuiFor scripts and automation, use the normal CLI:
cgm status
cgm workspace list
cgm logs -f
cgm config verifyUse cgm <command> --help for the live command surface. The exhaustive command inventory lives in the CLI reference, not in this README.
Other MCP clients
The tunnel-first flow above is the default ChatGPT setup. Generic local MCP clients can instead use dedicated stdio or local Streamable HTTP transports:
cgm mcp stdio --workspace ~/projects/my-project
cgm mcp http --workspace ws_...See MCP clients and upstream servers.
Security model
chatgpt-mcp provides an application-level workspace and control-plane boundary, not a kernel sandbox. Paths are canonicalized, symlink escapes are rejected, trusted control-plane mutations are separated from ordinary workspace operations, and sensitive managed credentials are not stored as plaintext structured config.
If you need isolation from deliberately hostile native code running as the same OS user, use an OS sandbox, container/VM, or separate operating-system identity.
Read Security before widening network exposure or filesystem access.
Documentation
Goal | Read |
Install and connect ChatGPT | |
Configure OpenAI Secure MCP Tunnel and the ChatGPT app | |
Understand workspace scope and containers | |
Run, stop, inspect, update, and read logs | |
Use the full-screen terminal UI | |
Configure auth, exposure, storage, and runtime settings | |
Connect generic clients or upstream MCP servers | |
Look up commands and flags | |
Understand trust boundaries | |
Diagnose common failures | |
Build and contribute |
See the documentation index for the recommended reading paths.
Development
Source builds require Go 1.27+, Node.js 24+, and pnpm 11+.
./scripts/check.shSee Development for the complete verification, CI, and release workflow, and CONTRIBUTING.md for contribution expectations.
License
MIT License. Copyright (c) 2026 Mew.
This server cannot be deployed
Maintenance
Related MCP Connectors
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Real-time chat for AI agents. Claude Code, Cursor, Cline and Codex join channels over MCP.
Real-time chat hub for AI agents — Claude Code, Cursor, Cline, Codex over MCP or REST.
Related MCP Servers
- AlicenseAqualityAmaintenanceOne local gateway for all your MCP servers — shared by every AI coding tool (Claude, Cursor, VS Code, Codex). Set up each server once; keys stay in the OS keychain; lazy discovery keeps agent context small. Local-first, open source.43 npm222MIT
- AlicenseAqualityDmaintenanceBridges any MCP client (like Claude Code, Zed, VS Code) to any ACP coding agent, enabling multi-agent orchestration from a single chat interface.24103 npm9Apache 2.0
- AlicenseNot gradedqualityBmaintenanceRemote MCP coding bridge that gives ChatGPT/Codex secure local workspace access, including file retrieval, semantic code intelligence, Git, diagnostics, and guarded shell execution.56 npmMIT
- AlicenseNot gradedqualityBmaintenanceA bridge that enables the ChatGPT web interface to use local file and shell tools through the official MCP protocol, turning the workspace into an agentic coding environment.9MIT