Connect your own MCP server to ChatGPT
Already have an MCP server? Eligible users can connect it from Plugins in ChatGPT web, create a plugin, install it and invoke it with @. Choose a server endpoint or Secure MCP Tunnel, configure authentication, and check the returned tool result. The direct flow has no separate Developer Mode step; workspace policy and security restrictions still apply.
Check access and connect your server ↓1. Check access and choose the direct route
Use ChatGPT on the web for this setup. Eligible users need the relevant account, plan, role, surface and rollout access. In a managed workspace, check the effective plugin permissions, including Create plugins with MCPs. A missing control can be an access restriction rather than a server fault. Lockdown and other security restrictions still apply. Plugin controls.
The direct guide starts in Plugins. It does not tell you to enable Developer Mode first. By contrast, the Developer mode and MCP apps Help article describes workspace/private app development and full-MCP access for Business, Enterprise and Edu. Preserve that distinction: it is not evidence that every ChatGPT user can create every kind of MCP connection.
This page assumes you already operate or trust a server. If you want a Site to provide the backend instead, use ChatGPT Sites hosted plugins. Optional UI belongs in Plugin Extensions.
2. Prepare the endpoint or private tunnel
The current custom-MCP guide lists SSE and streaming HTTP. For a public service, check its actual HTTPS MCP endpoint, commonly ending in /mcp. An ordinary website URL is not enough. Supported transports; connection checks.
Do not paste a stdio launch command into Server URL. For a private or local service, Secure MCP Tunnel forwards requests from a host that can already reach the server over stdio or HTTP. The server can remain inside its network. This is a supported private connection route, not an instruction to expose your machine publicly.
Tunnel setup has separate prerequisites: a Platform tunnel ID, a runtime API key for the tunnel client, and the correct organization/workspace association. Tunnel creation needs Tunnels Read + Manage; using it needs Tunnels Read + Use. These Platform roles do not grant ChatGPT workspace permission. Check both with the appropriate administrators. Official tunnel documentation.
Before connecting, inspect transport initialization, schemas and authentication with your server's existing test setup. A reachable URL or healthy tunnel does not prove a tool succeeded. This review did not start a tunnel or connect a server.
3. Add the server, create the plugin, then install it
Follow the current connection instructions:
- Open ChatGPT web → Plugins.
- Choose the plus button, then Add custom MCP server.
- Enter a recognizable name and an optional description.
- Under Connection, supply Server URL, or select Tunnel and choose an available Secure MCP Tunnel or its
tunnel_id. - Configure authentication for the server.
- Read the elevated-risk warning and acknowledge it only if you trust the server.
- Select Create as a plugin.
- Find the resulting plugin in your personal plugins or the workspace where you created it. Inspect its tools, then Install.
- Open a conversation, type @, select the plugin, and request one narrow operation.
- Inspect the actual tool result before relying on the answer.
Editorial first test — not executed: ask your plugin to read one known sample record and return its identifier and status. Compare both with the source system. If no tool ran, the plugin card and the assistant's prose are not a completed integration test.
4. Choose authentication and the correct account
Select OAuth for tools that need access to a user's protected provider data. Use No authentication only where the server deliberately exposes a suitable unauthenticated capability. OAuth or no authentication is the mixed option: initialization and tool discovery are unauthenticated, while individual tools follow their declared security schemes. Custom-MCP options; authentication design.
The documented OAuth registration choices include supplied static credentials, CIMD when advertised by the authorization server and selected by the creator, or configured DCR. CIMD supports a public client using none and signed client assertions using private_key_jwt. Choose the method your authorization server actually implements; a label in the form cannot supply missing server support. OAuth details.
Install is not provider authorization. Complete the requested provider sign-in when connecting or when a protected tool needs it. Verify the intended account/workspace and requested scopes before consenting. Shared plugin access does not let recipients borrow your provider identity. Review and disconnect unwanted connections through the account controls. Connection management.
5. Inspect tools and refresh changed metadata
Open the app's details/settings to inspect its advertised tools and toggle tools on or off. After the server adds or changes tools, descriptions or instructions, refresh the connection rather than assuming real-time discovery. Tool management.
For a direct custom connection: deploy or restart the server, open it under Plugins, select Refresh, verify the metadata changed, then start a new conversation for affected tests. Include changed schemas, annotations, authentication and UI resources in that check. Refresh procedure.
This is different from the owner publishing an updated Site-hosted plugin. Do not substitute Refresh for a Site publication or assume a local code edit updated a remote server.
6. Verify reads, writes and approval memory
Custom MCP supports read and write tools. search/fetch are not required. For write actions, confirmation is the default. Inspect the expanded JSON input and output, including the target record and account. ChatGPT uses readOnlyHint for read-only detection; a tool without that hint is treated as a write action. An annotation describes behavior—it is not an authorization grant. Custom-MCP action rules.
A remembered approve/deny choice applies to a particular tool in the current conversation. New conversations prompt again. Refreshing the same conversation also restores confirmation on subsequent turns. This is not permanent global approval. Do not remember approval for writes you do not trust. Confirmation scope.
App action permissions and organization rules are additional controls. A provider may limit the account or scopes available; a workspace can restrict access. A successful sign-in does not override those restrictions. App permissions.
Editorial verification example — not run: first read a sample inventory item. For an authorized write, review its exact ID and proposed inspection date, approve only that intended change, then check the item in the inventory system. A successful HTTP response, a plugin install and a real changed record are different observations.
7. Review trust before giving the server access
Only connect trusted MCP servers. External results and tool descriptions can contain prompt injection; a malicious server can steer tool use or try to exfiltrate information. Writes can alter, delete or unexpectedly share data. Wrong-account authorization can expose the wrong workspace even when the endpoint is legitimate. Keep credentials out of prompts and use the narrowest useful data access. OpenAI security guidance.
AgentSkillsHub editorial checklist:
- Verify the server operator and its current ownership.
- Inspect the exact endpoint or tunnel target.
- Read the discovered tool names, descriptions and inputs.
- Mark which tools read data and which change it.
- Test a read before considering a write.
- Use sample data that you are allowed to expose.
- Inspect JSON input/output, including account and record identifiers.
- Verify an authorized write in the external system.
- Avoid remembered approval for untrusted writes.
- Revoke authorization if ownership or behavior changes unexpectedly.
These are editorial checks, not a security certification. For a broader review, see the MCP server security checklist.
8. Direct MCP, Sites, workspace apps or local plugins?
Choose by where the tools run and who should use them. These routes can overlap: a workspace-created app can point to an externally hosted server. They are not four interchangeable permission tiers.
The comparison combines Plugins, Sites hosting, workspace MCP development and the direct connection guide. A Site owner publishing creates or updates the associated plugin; directly connecting your own endpoint does not move it into a Site.
| Route | Host and creation | Surface and sharing | Site access and admin controls |
|---|---|---|---|
| Direct custom MCP | Host and creationYou or your provider hosts the endpoint. Add it in Plugins to create a plugin. | Surface and sharingStart on ChatGPT web. Personal or workspace placement depends on where it was created; workspace sharing needs the relevant permissions. | Site access and admin controlsNo ChatGPT Site is required. Account, workspace, authentication and security restrictions apply. |
| Sites-hosted MCP | Host and creationThe ChatGPT Site hosts tools. Its owner publishes to create or update the associated plugin. | Surface and sharingUse supported plugin surfaces. The hosting article documents Business/Enterprise workspace sharing; personal/Pro direct sharing is unavailable. | Site access and admin controlsRecipients need Site access AND plugin access, plus their own connection. Sites and plugin permissions are separate. |
| Workspace-created MCP app | Host and creationAn authorized developer or admin connects a server for the workspace through its app-development flow. | Surface and sharingThe developer-mode Help article describes web development, testing and workspace publication; its plan and role scope applies. | Site access and admin controlsA Site is not inherently required. Admin review, app controls and workspace publication govern wider access. |
| Local MCP plugin | Host and creationA local MCP process runs on your computer as part of a supported plugin. | Surface and sharingChatGPT Desktop can run local MCP apps. Saving the plugin to an account does not make its local tools run on web or mobile. | Site access and admin controlsNo Site is required. Local process access, plugin policy and provider authorization still need review. |
9. Find the failed step before changing access
No Add custom MCP server control: verify the web surface, account eligibility, workspace role and security restrictions. Do not work around a managed restriction with another account.
Connection fails: distinguish an incorrect endpoint, incompatible transport, unreachable tunnel target and failed authentication. For a tunnel, check workspace association and client readiness. For a public endpoint, check MCP initialization and discovery. Connection diagnostics.
Plugin exists but cannot read protected data: check installation and the intended provider connection separately. Tool missing after an update: check the deployed server, Refresh and the advertised tool list. Unexpected approval: inspect the read-only annotation, operation and applicable app policy.
Tool ran but the answer is wrong: compare JSON inputs and outputs with a known record. Fix the underlying tool or metadata and rerun a small evaluation set. Do not treat a polished answer as evidence of a successful external operation.
FAQ
Must I turn on Developer Mode first?
The current direct Add custom MCP server instructions do not include a separate Developer Mode toggle. The workspace developer/app-development Help article describes a different setup path. Your account and workspace must still permit the direct route.
Can I paste a local stdio command into Server URL?
No. A command is not a web endpoint. Use a supported remote endpoint or the official Secure MCP Tunnel route that reaches your private stdio or HTTP server.
Are custom MCP tools limited to search and fetch?
No. Custom MCP supports read and write tools; search/fetch are not required. Authentication, permissions and confirmation settings still govern execution.
Does installing a plugin authorize my provider account?
No. Complete any required connection to the intended provider account and review requested access. Installation and provider authorization are separate.
Will a remembered write approval apply forever?
No. The choice is scoped to the tool and current conversation. New conversations prompt again, and refreshing the same conversation restores confirmation on subsequent turns.
Do tool changes appear immediately?
Do not assume so. Update the server, open the direct connection, use Refresh, inspect the advertised metadata and retest in a new conversation.
Was this connection tested end to end by AgentSkillsHub?
No. This guide is SOURCE_CHECKED_ONLY. We validated the guide page locally, not a real MCP connection, tunnel, provider authorization or write operation.
Primary sources
Source-checked 2026-10-06. Published documentation, account availability and a hands-on workflow are separate evidence. Examples and checklists here are editorial material.