What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no universal “disable all MCP” switch that covers every OpenAI surface. To stop MCP access completely, first identify where the server is configured—local Codex, a Codex plugin, a ChatGPT workspace app, or an OpenAI API project—then disable every entry in that specific scope. Changing ~/.codex/config.toml, for example, does not turn off workspace apps or API-hosted tools.

What “all MCP servers” can mean

Model Context Protocol (MCP) servers can be enabled at several independent layers. Treat “all” as “all servers managed by the layer you are changing,” not as a single global state.

Surface Where access is controlled What the change affects
Codex CLI or IDE extension User and trusted-project configuration Locally configured servers for that user or project
Plugin-bundled MCP Per-plugin, per-server policy The selected server inside that plugin
ChatGPT workspace plugin or app Workspace Plugins or Apps administration Workspace availability and user access, subject to role and plan
OpenAI API hosted MCP Organization hosted-tool policy and project permissions API access for the selected organization and projects

These controls are separate. A local change cannot disable an administrator-managed workspace app, and a project permission cannot remove a server from a developer’s local Codex installation.

Disable locally configured MCP servers in Codex

1. Check both configuration layers

Codex uses personal defaults in ~/.codex/config.toml. A repository can also contain .codex/config.toml for project-specific overrides. Codex CLI and the IDE extension share these configuration layers. Project configuration is loaded only for trusted projects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Open ~/.codex/config.toml in a text editor.
  2. If you are working in a repository, open that repository’s .codex/config.toml as well.
  3. Search for sections whose names begin with [mcp_servers.. The text after the dot is the configured server name.
  4. Record each server name and decide whether you want to remove it or disable it for the relevant scope.

Do not assume that deleting one project entry removes the user-level definition. Inspect both files when you need local access gone everywhere you control.

2. Remove or neutralize each server entry

Remove the complete configuration block for each unwanted server, including its command, URL, environment, and arguments. If you need to preserve the settings for later, copy the block to a secure backup and then remove it from the active file. The documented configuration does not define a universal top-level key that means “disable every MCP server,” so do not invent one.

After saving, restart Codex or reload the IDE extension. A running process may retain the previous server list until it is restarted.

3. Verify on the same client

Open the MCP or tools view in the Codex client you actually use and confirm that the removed servers no longer appear or respond. Test both the CLI and IDE extension if you use both; they share configuration files, but a trusted-project file can still add a server for one repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable MCP servers bundled by a Codex plugin

A plugin can ship its own MCP server. For that case, use a server-scoped policy in configuration:

[plugins."my-plugin".mcp_servers.docs]
enabled = false

Replace my-plugin and docs with the exact plugin and server names in your configuration. Repeat the block for every bundled server you want disabled. This is more precise than disabling the entire plugin when you still need its other features.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Disable a local plugin for one project

A repository’s local-marketplace plugin can be switched off with enabled = false in that project’s .codex/config.toml. This affects that project only and requires the project to be trusted before project configuration is loaded. It does not change workspace installation policy for plugins imported through an administrator’s Plugins settings.

Disable workspace plugins and MCP apps in ChatGPT

Workspace plugins

  1. Open Workspace settings.
  2. Choose Plugins.
  3. Open the plugin’s more-options menu.
  4. Choose Disable or Disable plugin, when that option is available.

Plugin installation, app access, and synchronization are separate controls. If the plugin depends on a shared app, review what other workflows use that app before disabling it. Turning off an app does not necessarily uninstall the plugin or remove skills that operate independently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Custom MCP apps

ChatGPT custom MCP app controls depend on the workspace plan, administrator role, developer-mode requirements, user access settings, and action controls. Enterprise and Edu administrators can manage app or connector access and actions, but the exact controls are not identical for every plan or user. If you cannot see an Apps or action-control setting, an administrator may need to make the change.

Disable MCP for OpenAI API projects

API-hosted MCP is governed by organization policy first. The organization can allow hosted tools for all projects, deny them for all projects, or allow selected projects.

  1. Review the organization’s hosted-tool policy.
  2. If the organization currently allows MCP for all projects, change the policy to allow selected projects.
  3. Open the target project’s tool permissions.
  4. Set that project’s MCP permission to false or remove its MCP permission.
  5. Make a test API request using the same project credentials and confirm the hosted MCP tool is unavailable.

The project-level change fails while the organization still allows the tool for every project. This setting controls API project access only; it does not affect local Codex servers or ChatGPT workspace apps.

Decision checklist for a complete shutdown

  • Local Codex: inspect both ~/.codex/config.toml and the trusted project’s .codex/config.toml.
  • Plugin servers: set enabled = false for each actual plugin/server pair, or disable the local plugin for that project.
  • Workspace controls: use Workspace settings → Plugins or Apps with an administrator account where required.
  • API projects: change organization policy before removing project MCP permission.
  • Verification: test from the same surface where the server was available; “all” applies only to the scope you changed.

Troubleshooting

The server still appears after editing the file

Restart Codex or reload the IDE extension. Then check for a second definition in the other configuration layer. A trusted project can add a server even when the user file is clean.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A project configuration seems ignored

Confirm that the repository is trusted. Codex loads project configuration only for trusted projects; an untrusted repository will not contribute its MCP entries.

Disabling a plugin did not remove app access

Plugin installation, app access, and sync are separate. Review the workspace’s Apps controls and any shared app dependency instead of assuming one switch controls all three.

The API project permission cannot be set to false

Check the organization policy. Project-level denial is not available while the organization allows MCP for all projects; select the allow-listed-projects mode first.

A user can still use a workspace MCP app

Check plan and role-specific controls, developer mode, user assignment, and action permissions. Workspace settings may be visible only to administrators, and controls vary by Enterprise, Edu, and other plans.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security and operational considerations

Disabling a server removes its availability; it does not erase credentials stored in shell environments, secret managers, plugin files, or workspace records. Remove or rotate credentials separately when a server is no longer trusted. Keep a dated backup of configuration before deleting entries, and document which scope was changed so another administrator does not re-enable the server unintentionally.

For incident response, start with the narrowest layer that blocks the unwanted access, then audit the other layers. A local shutdown is fast for one developer; an organization policy change is appropriate when API access must stop across projects; workspace administration is required when users access an app through ChatGPT.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Or skip the browser setup: ScreenshotNeo for automated captures

If you are disabling MCP because browser automation or screenshot tooling is creating unwanted setup, ScreenshotNeo offers a direct HTTP alternative at ScreenshotNeo. One request returns a PNG, JPEG, WebP, or PDF. It accepts cookie and consent banners like a visitor, then removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. An MCP server is also available when you want an AI agent to call take_screenshot, get_page_info, or capture_pdf rather than configuring browser drivers.

See the ScreenshotNeo documentation for all options. A minimal call is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account to try it.

Frequently Asked Questions

Does disabling MCP in Codex disable MCP in ChatGPT?

No. Codex local configuration, ChatGPT workspace controls, and API project permissions are independent scopes.

Should I delete MCP credentials when I disable a server?

Disablement blocks use in that scope, but credentials remain wherever you stored them. Remove or rotate them separately when required.

Why can’t I disable an API project’s MCP permission?

The organization must first switch from allowing MCP for all projects to allowing selected projects; only then can a project be denied.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

There is no documented global off switch. Identify the surface, disable every server configured in that scope, restart or reload the client, and verify access from the same product where it was available.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.