Skip to main content
Glama

chatgpt-mcp

A secure, workspace-bound bridge between ChatGPT and your machine.

Single Go binary · OpenAI Secure MCP Tunnel · Linux, macOS, and Windows

Latest Release CI Go License

Get started · Connect ChatGPT · Command Center · Security · Documentation

chatgpt-mcp lets ChatGPT work with local projects through explicitly registered workspaces. The default setup uses OpenAI Secure MCP Tunnel, so the runtime can stay private without exposing an inbound MCP port to the public internet.

Overview

The main path is intentionally small: ChatGPT reaches the local runtime through the Secure MCP Tunnel, then chatgpt-mcp applies workspace scope before filesystem, shell, Git, process, or upstream MCP work happens.

Why chatgpt-mcp

  • Private by default for ChatGPT — the Secure MCP Tunnel is outbound-only from your machine; public MCP ingress is not required.

  • Workspace-bound access — filesystem, shell, Git, process, context, memory, rules, skills, and checkpoints operate against explicit ws_* workspace targets.

  • Local control stays local — use the CLI, full-screen TUI, or embedded Admin UI to inspect and operate the runtime.

  • MCP aggregation — optionally expose tools from upstream MCP servers through the same runtime.

  • One cross-platform binary — native releases for Linux, macOS, and Windows on amd64 and arm64, with managed background-service support.

Related MCP server: mcacp

Install

Linux / macOS

curl -fsSL get.mewis.me/chatgpt-mcp.sh | sh

Windows PowerShell

irm https://get.mewis.me/chatgpt-mcp.ps1 | iex

Homebrew

brew tap mewisme/mew
brew install --cask chatgpt-mcp

Scoop

scoop bucket add mew https://github.com/mewisme/scoop-mew
scoop install mew/chatgpt-mcp

Both chatgpt-mcp and the shorter cgm command are installed. The examples below use cgm.

5-minute setup

1. Initialize

cgm init

2. Register the project ChatGPT may work with

cgm workspace register ~/projects/my-project

The command returns a stable ws_* workspace ID. Register only roots you intentionally want the runtime to reach.

3. Configure the Secure MCP Tunnel

Create a tunnel and a restricted runtime API key in OpenAI Platform, then configure them locally:

cgm tunnel configure \
  --enabled \
  --id tunnel_... \
  --api-key 'sk-...'

The runtime key should have Tunnels Read + Use. It is not an OpenAI Admin API key and is not used to call a language model.

4. Start the managed runtime

cgm up

Verify locally:

cgm status
cgm tunnel status

5. Connect ChatGPT

Enable Developer Mode in ChatGPT, create a custom app using Tunnel, select the same tunnel, and Scan Tools.

The complete Platform permissions and ChatGPT setup flow is in Connect ChatGPT with OpenAI Secure MCP Tunnel.

Operate it

For interactive administration:

cgm tui

For scripts and automation, use the normal CLI:

cgm status
cgm workspace list
cgm logs -f
cgm config verify

Use cgm <command> --help for the live command surface. The exhaustive command inventory lives in the CLI reference, not in this README.

Other MCP clients

The tunnel-first flow above is the default ChatGPT setup. Generic local MCP clients can instead use dedicated stdio or local Streamable HTTP transports:

cgm mcp stdio --workspace ~/projects/my-project
cgm mcp http --workspace ws_...

See MCP clients and upstream servers.

Security model

chatgpt-mcp provides an application-level workspace and control-plane boundary, not a kernel sandbox. Paths are canonicalized, symlink escapes are rejected, trusted control-plane mutations are separated from ordinary workspace operations, and sensitive managed credentials are not stored as plaintext structured config.

If you need isolation from deliberately hostile native code running as the same OS user, use an OS sandbox, container/VM, or separate operating-system identity.

Read Security before widening network exposure or filesystem access.

Documentation

Goal

Read

Install and connect ChatGPT

Getting started

Configure OpenAI Secure MCP Tunnel and the ChatGPT app

OpenAI + ChatGPT

Understand workspace scope and containers

Workspaces

Run, stop, inspect, update, and read logs

Runtime and operations

Use the full-screen terminal UI

TUI Command Center

Configure auth, exposure, storage, and runtime settings

Configuration

Connect generic clients or upstream MCP servers

MCP and upstreams

Look up commands and flags

CLI reference

Understand trust boundaries

Security

Diagnose common failures

Troubleshooting

Build and contribute

Development

See the documentation index for the recommended reading paths.

Development

Source builds require Go 1.27+, Node.js 24+, and pnpm 11+.

./scripts/check.sh

See Development for the complete verification, CI, and release workflow, and CONTRIBUTING.md for contribution expectations.

License

MIT License. Copyright (c) 2026 Mew.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    One local gateway for all your MCP servers — shared by every AI coding tool (Claude, Cursor, VS Code, Codex). Set up each server once; keys stay in the OS keychain; lazy discovery keeps agent context small. Local-first, open source.
    4
    3 npm
    222
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Remote MCP coding bridge that gives ChatGPT/Codex secure local workspace access, including file retrieval, semantic code intelligence, Git, diagnostics, and guarded shell execution.
    56 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A bridge that enables the ChatGPT web interface to use local file and shell tools through the official MCP protocol, turning the workspace into an agentic coding environment.
    9
    MIT