Yes, ChatGPT supports MCP. But "ChatGPT" now means three different products, and each one handles Model Context Protocol servers differently. ChatGPT on the web connects to remote MCP servers through Developer mode and the Plugins page. The ChatGPT desktop app, which absorbed the Codex app in July, has its own MCP servers screen that can launch local stdio servers as well. The OpenAI API has a built-in mcp tool that lets your own code hand a remote server to the model.
Plenty of guides still say ChatGPT "cannot use local servers". That is true for the web app and no longer true for the desktop app. This guide covers all three, checked against OpenAI's docs and Help Center on October 1, 2026. Where two OpenAI pages disagree, we say so.
Where ChatGPT supports MCP
| ChatGPT web | ChatGPT desktop app | OpenAI API (Responses) | |
|---|---|---|---|
| Where you add it | Settings → Security and login → Developer mode, then the plus button on ChatGPT Plugins | Settings → MCP servers → Add server | A {"type": "mcp"} entry in the request's tools array |
| Transports | Streamable HTTP and SSE | Streamable HTTP and stdio | Streamable HTTP and HTTP/SSE |
| Local servers | No. Use Secure MCP Tunnel. | Yes, as stdio commands | Through Secure MCP Tunnel (tunnel_id) |
| Auth | OAuth, no auth, or mixed | OAuth, bearer token from an env var, static headers | You pass an OAuth token in authorization on every request |
| Write tools | Depends on plan (see below) | Yes, with per-tool approval modes | Yes, approval required by default |
| Config is shared with | Your account or workspace | Codex CLI and IDE extension (config.toml) | Nothing. You send it on every request. |
Sources: OpenAI's Developer mode guide, the ChatGPT Learn MCP page and the API MCP guide.
Connectors, apps, plugins: same thing, new names
A custom remote MCP server was first a "connector", then an "app", and the current docs call it a "plugin" or a "developer-mode app". All of these still appear in ChatGPT's screens, and they all mean the same thing: a remote MCP endpoint that ChatGPT calls as a client.
Two related terms are not the same thing:
- The Apps SDK is for MCP servers that also ship an interactive UI shown inside the chat. ChatGPT now implements the open MCP Apps standard for those embedded UIs. A tools-only server does not need any of it.
- ChatGPT Work, launched on July 9, 2026, is an agent in ChatGPT that runs longer tasks across your apps. It gets its tools from installed plugins. OpenAI's docs do not say whether a developer-mode app reaches Work, and the Help Center says agent mode will not use custom apps, so test it before you rely on it.
The same announcement merged the Codex app into the ChatGPT desktop app, which is why the desktop app reads Codex's MCP configuration.
Which plans get MCP in ChatGPT
This is the part most likely to waste your afternoon, because OpenAI's own pages do not agree.
- The Developer mode guide on the developer site says Developer mode gives "full Model Context Protocol (MCP) client support for all tools, both read and write" and is "available to Pro, Plus, Business, Enterprise, and Education accounts on the web."
- The Help Center article says full MCP, including write actions, is "rolling out in beta to ChatGPT Business, Enterprise, and Edu plans." Its FAQ adds that "Pro users can connect MCPs with read/fetch permissions in developer mode."
The practical test: add the server and see whether write tools run. If only read tools work, the plan is the reason, not your server.
On Enterprise and Edu, admins can grant it to specific members through role-based access control. The Help Center says custom MCP apps are web-only, not mobile, and there are no geographic restrictions.
The desktop app is a separate case. OpenAI says the desktop app with Chat, Work and Codex is "available on every plan, including Free." Its MCP servers page does not name a plan restriction. A managed workspace can still lock it down, so check with your admin if the screen is missing.
How to add a remote MCP server in ChatGPT on the web
- Turn on Developer mode. Settings → Security and login → Developer mode. On workspace plans the toggle may instead sit under Settings → Apps → Advanced settings. On Enterprise and Edu, an admin first grants access in Workspace settings → Permissions & Roles → Connected Data. On Business, only admins and owners can turn it on, each for themselves.
- Open ChatGPT Plugins and click the plus button. OpenAI notes that the plus button "will only create developer-mode apps after you turn on Developer mode." Searching the plugin directory for your server is not the same thing.
- Fill in the connection. A name, a one-line description, and the server URL including its path (usually
/mcp). Pick the authentication method the server expects. - Scan, then create. Click Scan Tools. If the server uses OAuth, a sign-in window opens. Finish it, wait for the tool scan, then click Create. The new app lands under Drafts.
- Use it in a chat. Choose Developer mode from the plus menu in the composer and select the app. On workspace plans, the Help Center notes the selection applies to the message, not the whole conversation, so @mention the app again when a follow-up needs it.
Two details matter for server authors. First, after you change tool names, descriptions or schemas, open the app and click Refresh, then start a new conversation. Until you refresh, ChatGPT keeps using the metadata it fetched earlier. Second, on Business plans a published workspace app is a frozen snapshot. The Help Center says it "cannot be updated after publishing at launch", so a breaking schema change means recreating and republishing it.
ChatGPT desktop app: local servers and config.toml
The desktop app is where ChatGPT finally behaves like Claude Desktop or Cursor. OpenAI's MCP page lists stdio servers, Streamable HTTP servers, bearer-token auth, OAuth with CIMD and DCR, and server instructions. To add one:
- Open Settings, then MCP servers.
- Select Add server, enter a name, choose STDIO or Streamable HTTP, and give the command or URL.
- Save, then select Restart. If the server needs OAuth, select Authenticate. Type
/mcpin the composer to see what is connected.
The useful part is that the desktop app, the Codex CLI and the Codex IDE extension share one file: ~/.codex/config.toml, or a project-scoped .codex/config.toml in trusted projects. Configure a server once and all three see it. We registered DialMCP with Codex CLI 0.159.3 to see exactly what gets written:
$ codex mcp add dialmcp --url https://mcp.dialmcp.com/mcp
Added global MCP server 'dialmcp'.
Detected OAuth support. Starting OAuth flow…
Authorize `dialmcp` by opening this URL in your browser:
https://mcp.dialmcp.com/authorize?response_type=code&client_id=…
&code_challenge_method=S256
&redirect_uri=http%3A%2F%2F127.0.0.1%3A36261%2Fcallback%2FSnTi2XH0tVcp
&resource=https%3A%2F%2Fmcp.dialmcp.com%2Fmcp
The config entry itself is two lines:
[mcp_servers.dialmcp]
url = "https://mcp.dialmcp.com/mcp"
Codex found OAuth on its own, registered a client through Dynamic Client Registration (our authorization server does not advertise CIMD, so Codex fell back as documented) and used PKCE with S256. Before sign-in, codex mcp list shows the server as enabled and Not logged in. We stopped at the sign-in page and did not authorize or call any tools.
A local stdio server looks like this, adapted from OpenAI's own Context7 example:
[mcp_servers.context7]
command = "npx"
args = ["-y", "@upstash/context7-mcp"]
Worth knowing in the same file: enabled_tools and disabled_tools for allow and deny lists, tool_timeout_sec (default 60), and default_tools_approval_mode, whose writes value prompts only for tools not marked read-only. One limit: the web app "doesn't read local Codex configuration files", so a server added here does not appear in ChatGPT in the browser.
Local and private servers: Secure MCP Tunnel
If your server runs on a laptop or inside a private network and you want ChatGPT on the web, or the API, to reach it, OpenAI's answer is Secure MCP Tunnel. You run tunnel-client somewhere that can reach the server. It opens an outbound HTTPS connection to OpenAI, pulls queued MCP requests, forwards them locally and posts the responses back. Nothing listens on a public port. In the plugin form you choose Tunnel instead of a URL, then pick the tunnel or paste its tunnel_id.
OpenAI also says other HTTPS forwarding services work for testing, but "do not replace the public HTTPS endpoint required for plugin submission." Our remote MCP servers explainer covers why hosted endpoints won.
Authentication: what ChatGPT accepts
On the web, the Developer mode guide lists three options: OAuth, no authentication, and mixed. Mixed means listing tools needs no auth, while each tool can require OAuth according to its own security scheme. For OAuth, ChatGPT uses static client credentials if you enter them. Otherwise it can use a Client ID Metadata Document when the authorization server advertises one, or Dynamic Client Registration.
There is no field for a raw API key in that list. If a server only accepts a bearer token, the web app is the wrong client for it. The desktop app and Codex can send one from an environment variable with bearer_token_env_var.
The Help Center adds a refresh-token warning that explains a lot of "it worked yesterday" reports. If your OAuth provider does not issue refresh tokens (for OpenID Connect, usually the offline_access scope), "ChatGPT may lose access after the original authorization expires," and users have to sign in again. Fix it at the provider, then recreate the app so ChatGPT re-reads the metadata.
Our OAuth docs walk through the same flow from the server's end.
Write actions, approvals and what to watch
OpenAI calls Developer mode "powerful but dangerous" and lists three risks up front: prompt injection, "model mistakes on write actions that could destroy data", and "malicious MCPs that attempt to steal information." The guardrails it provides:
- Writes ask first. ChatGPT respects the
readOnlyHinttool annotation. Any tool without it is treated as a write and needs confirmation by default. - Remembered approvals are per conversation. You can tell ChatGPT to remember approve or deny for a tool for the rest of a conversation. A new conversation, or a refresh, asks again.
- You can read the payload. Each tool call expands to show the full JSON input and output. Read it before approving a write.
- Some modes are read-only. Per the Help Center, deep research can use custom apps "for read/fetch actions only," and "agent mode will not use custom apps."
OpenAI's prompting advice is blunt and it works: name the app and the tool, and rule out alternatives. Their example is "Do not use built-in browsing or other tools; only use the Acme CRM app." Without that, ChatGPT will sometimes search the web for an answer your server was supposed to supply.
For developers: the MCP tool in the OpenAI API
If you are building your own app on OpenAI models, you do not need ChatGPT at all. The Responses API accepts a remote MCP server as a tool:
from openai import OpenAI
client = OpenAI()
resp = client.responses.create(
model="gpt-6-astra",
tools=[{
"type": "mcp",
"server_label": "dmcp",
"server_description": "A Dungeons and Dragons MCP server to assist with dice rolling.",
"server_url": "https://dmcp-server.deno.dev/mcp",
"require_approval": "never",
}],
input="Roll 2d4+1",
)
print(resp.output_text)
That is OpenAI's own quickstart example. How it behaves:
- The API calls the server's
tools/listfirst and writes anmcp_list_toolsitem into the output. Keep that item in context and it will not re-fetch the list each turn. allowed_toolslimits what the model sees, which saves tokens on servers with dozens of tools.- Approval is on by default. The model emits an
mcp_approval_request, and you reply with anmcp_approval_response. Setrequire_approvalto"never"only for servers you trust. - The API does not store the
authorizationvalue, so you send your token on every call. - OpenAI says you pay for the tokens used to import tool definitions and make calls, with "no additional fees" per tool call.
OpenAI's warning applies here too: "A malicious server can exfiltrate sensitive data from anything that enters the model's context."
Building an MCP server that works well in ChatGPT
- You don't need
searchandfetchfor chat. Early connectors required them. Developer mode does not, and the Help Center says "they are no longer required." They do still matter for company knowledge, which only includes apps with search and fetch. Deep research can use custom apps, but only for read and fetch actions. - Mark read-only tools. Set
readOnlyHinton tools that only read, or every call will ask for approval. - Write tool descriptions for selection. OpenAI suggests action-oriented names, "Use this when…" guidance, and enums on parameters.
- Use server instructions for rules that span tools, such as call order and shared rate limits. ChatGPT and Codex read the MCP
instructionsfield, and OpenAI says to keep the first 512 characters self-contained. - Test outside ChatGPT first. OpenAI's own checklist starts with MCP Inspector, then Developer mode, then the API Playground (Tools → Add → MCP Server) for raw request logs.
If you are starting from zero, our guide to building an MCP server walks through a remote server end to end.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| No plus button, or it doesn't create an app | Developer mode is off, or your workspace hasn't granted it | Turn it on in Settings → Security and login, or ask an admin |
| Scan finds no tools | Wrong path (missing /mcp), OAuth not finished, or server error | Check the URL in MCP Inspector, finish sign-in, rescan |
| Only read tools show or run | Plan limits writes (see the plan section) | Use a plan with full MCP, or the desktop app or API |
| New tools or descriptions don't appear | ChatGPT cached the old metadata | Refresh the app, then start a new conversation |
| Asked to sign in again after a while | No refresh token issued | Enable offline_access or equivalent, recreate the app |
| Tool calls error after a server update (Business) | Published app is a frozen snapshot | Admin recreates and republishes the app (Enterprise/Edu admins can refresh actions instead) |
| Local server not visible on the web | Web doesn't read config.toml or run stdio | Use the desktop app, or Secure MCP Tunnel |
| ChatGPT browses instead of using your tool | Ambiguous prompt | Name the app and tool; say not to use other tools |
An example: phone calls from ChatGPT
A concrete case makes the write-tool rules clearer. DialMCP is a remote MCP server whose tools place real phone calls from your own verified mobile number. place_call and end_call change something in the real world, because a phone rings somewhere. get_call and list_calls only read, but DialMCP does not yet mark them with readOnlyHint, so ChatGPT treats all four as writes and asks before each one.
In ChatGPT on the web, that means DialMCP is only useful on an account where write tools run. If your plan limits you to read and fetch, expect none of DialMCP's tools to run, and deep research will never place a call. In the desktop app, it is the two-line config.toml entry above plus a one-time OAuth and SMS sign-in. The full web recipe, with the exact form values, is on our ChatGPT connector docs page. Other clients are covered in client setup.
The confirmation step is a good thing here. Every call ChatGPT proposes shows the destination and objective as JSON before anything dials, and the server's own safety rules (AI disclosure, calling hours, opt-outs) apply no matter which client sent the request.
Further reading
- Remote MCP servers explained
- MCP Inspector: debug a local or remote MCP server
- Zapier MCP: what it is and what it costs
- MCP configuration examples for each client
- OpenAI: ChatGPT Developer mode
- OpenAI Help Center: Developer mode and MCP apps
- ChatGPT Learn: Model Context Protocol
Want ChatGPT to make the phone call, not just draft the script? Add https://mcp.dialmcp.com/mcp, verify your own mobile number, and approve the call. You get back a transcript and a structured outcome. Free during launch.
FAQ
Does ChatGPT support MCP?
Yes. ChatGPT on the web connects to remote MCP servers through Developer mode. The desktop app connects to remote and local stdio servers from Settings → MCP servers. The OpenAI API accepts remote MCP servers as a built-in tool.
Can ChatGPT use a local MCP server?
The desktop app can, as a stdio command. ChatGPT on the web cannot launch local servers. To reach a local or private server from the web or the API, use OpenAI's Secure MCP Tunnel.
Which ChatGPT plans support MCP?
OpenAI's pages disagree. The Developer mode guide lists Plus, Pro, Business, Enterprise and Education with read and write. The Help Center says full MCP with writes is for Business, Enterprise and Edu, and Pro gets read and fetch only.
How do I enable ChatGPT Developer mode?
Go to Settings → Security and login and turn on Developer mode. On workspace plans an admin may have to grant it first, and the toggle can sit under Settings → Apps → Advanced settings.
Does ChatGPT MCP work on mobile?
No. OpenAI's Help Center says custom MCP apps are web-only. You can use them in ChatGPT on the web, and the desktop app has its own MCP servers settings.
Do MCP servers for ChatGPT need search and fetch tools?
Not for chat. Developer mode works with any tools, including writes. Search and fetch still matter for company knowledge, which only uses apps that implement them. Deep research is limited to read and fetch actions.