Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To connect an existing MCP server to ChatGPT, use a custom MCP app in Developer Mode: have an eligible workspace admin enable Developer Mode, create an app with your remote MCP endpoint and metadata, choose authentication, scan the tools, create a draft, test it in a new chat, and have an admin or owner publish it. If you are building the app’s logic and interface rather than connecting an existing server, use OpenAI’s Apps SDK instead.

Availability is changing. OpenAI currently describes full MCP, including write and modify actions, as a beta rollout for ChatGPT Business, Enterprise, and Edu. Pro users can build Apps SDK apps and use MCP with read/fetch permissions in Developer Mode. Check your workspace’s current settings before designing a deployment.

Choose the correct integration route

There are two different jobs that people call “integrating MCP with ChatGPT.” Choosing the right one first prevents a dead-end configuration.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect an existing MCP server

Use a custom MCP app in ChatGPT Developer Mode when your server already exposes tools or data. ChatGPT connects to the server’s remote endpoint, imports the available tool definitions, and lets users invoke them from a chat. The server remains the system that performs the work and enforces its own permissions.

Build a complete ChatGPT app experience

Use the Apps SDK when you are creating the app’s behavior and interface for ChatGPT, not merely wiring in an existing server. OpenAI describes the preview SDK as letting developers design “both the logic and the interface of an app that runs inside ChatGPT.” You connect the app to your backend, test it in ChatGPT, and follow the separate submission process if you want directory publication.

Question Custom MCP app Apps SDK
Starting point An existing remote MCP server A new ChatGPT app experience
What you build Tools and data integration Application logic and an interactive interface
Initial publishing path Workspace draft reviewed and published by an admin or owner Test in ChatGPT, then use the separate directory submission path if desired
Permissions Depends on workspace plan, role, server authentication, and tool actions Depends on the SDK app, backend, workspace, and submission requirements

This article focuses on connecting an existing server, then explains where the Apps SDK fits.

Check eligibility and prepare the server

Confirm workspace access

  • ChatGPT web is the supported surface described in the current Help Center; MCP apps are not documented as available on mobile.
  • Business, Enterprise, and Edu workspaces may expose Developer Mode and full MCP, with write/modify support currently described as beta.
  • On Business, an admin or owner enables Developer Mode for themselves. On Enterprise/Edu, administrators can grant access to selected people through role-based access controls (RBAC).
  • Pro support described by OpenAI is limited to building Apps SDK apps and read/fetch MCP access in Developer Mode.

Plans, regions, roles, models, and interface versions can change what you see. If the Apps option is missing, ask a workspace owner to verify the plan and your role rather than assuming the server is broken.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make the MCP endpoint reachable

ChatGPT requires a remote server endpoint and metadata. A local process on your laptop, a private LAN address, or an on-premises-only URL is not connected directly. For a private network, on-premises deployment, or developer-machine server, OpenAI points to Secure MCP Tunnel.

Before opening the ChatGPT configuration, obtain:

  • The HTTPS MCP server endpoint your administrator intends to expose.
  • The metadata ChatGPT requests for the app and server.
  • Authentication details, such as an OAuth authorization flow, if the server is protected.
  • A test account or test data set that cannot damage production records.
  • A list of expected tools, their inputs, and which actions read or modify data.

Connect the server in Developer Mode

  1. Enable Developer Mode. Ask the appropriate workspace admin or owner to enable it. Enterprise/Edu administrators can use RBAC to restrict who may create or access custom apps.
  2. Open the app creator. In ChatGPT web, go to Workspace settings → Apps → Create, or use the corresponding user-settings flow if your role is authorized.
  3. Enter server details. Supply the remote MCP endpoint and the required metadata. Select the authentication mechanism when the server requires one.
  4. Scan the tools. Choose Scan Tools. If OAuth is configured, complete the authorization prompt and wait for ChatGPT to import the tool definitions.
  5. Create a draft. Select Create. The result is a draft app, not yet a workspace-wide published integration.
  6. Test in a new chat. Open a new conversation, select the draft from the tools menu or refer to it in your prompt, and run representative read operations first. Then test every write or modify action in a safe account.
  7. Publish after review. An admin or owner publishes the app from workspace app settings. Enterprise/Edu administrators can configure who may access the app and which actions are allowed.

Use prompts that make the intended tool explicit, for example: “Use the inventory lookup tool to check item 1842, but do not change data.” This makes it easier to see whether ChatGPT selected the expected tool and whether the server returned a useful result.

Configure OAuth so sessions keep working

For OAuth or OpenID Connect, verify that the identity provider issues refresh tokens. OpenAI notes that providers commonly request refresh access with the offline_access scope and should advertise it in discovery metadata such as .well-known/openid-configuration or .well-known/oauth-authorization-server.

Without a refresh token, access can stop when the original authorization expires and each user may have to authenticate again. Test the complete lifecycle: authorize, close and reopen ChatGPT, wait past the access-token lifetime in a test environment, and confirm that the server can refresh or that the failure message tells the user exactly what to do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review tools, data, and write actions before publication

Inspect the imported tool list

Read every tool description and input schema that ChatGPT scans. Confirm that names, required arguments, defaults, and error responses match the server implementation. A published app uses a reviewed snapshot of the available tools and inputs, not a live, automatically changing catalog.

Separate read and write testing

  • Start with read-only calls against non-sensitive test data.
  • For each write or modify tool, identify the records it can affect, the user identity passed to the server, and whether ChatGPT asks for confirmation.
  • Use least-privilege OAuth scopes and server-side authorization; a chat prompt is not a security boundary.
  • Document irreversible operations and provide a recovery procedure before enabling them for a workspace.

ChatGPT may request confirmation for write or modify actions depending on permissions and context, and some especially risky actions may be blocked. Do not rely on confirmation alone: enforce authorization and validation in the MCP server.

Threat-model prompt injection

OpenAI warns that unsafe or untrusted MCP servers can increase exposure to prompt injection. Vet the server owner, code, dependencies, outbound requests, logging, data retention, and OAuth scopes. Treat instructions returned by external content as untrusted data, especially when a tool can send messages, change records, or upload files.

Publish and maintain the app

After review, an admin or owner publishes the draft from workspace app settings. Enterprise/Edu administrators can restrict access and actions with RBAC. Business apps currently cannot be edited after publishing; to change tools or metadata, recreate and republish the app.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plan a change-management process because server updates do not automatically update the published snapshot. Enterprise/Edu admins can refresh tools and review diffs, and newly added actions are disabled by default. If definitions change incompatibly, calls may fail until an administrator refreshes the actions. OpenAI says users are not automatically prompted to update an app when a call errors, so communicate version changes and provide a rollback path.

Use the integration in ChatGPT’s other features

  • Deep Research: custom apps can be used for read/fetch actions.
  • Agent mode: the current Help Center says Agent mode will not use custom apps.
  • Company Knowledge: custom apps can support search/fetch, but interactive UI apps are not currently supported there.
  • Search and fetch: they are not required for every MCP server; expose only the capabilities your use case needs.

These boundaries matter when a team expects one app to work identically in every ChatGPT mode.

Troubleshoot common failures

The Apps or Developer Mode controls are missing

Cause: the plan, workspace role, region, surface, or rollout does not provide the feature. Fix: use ChatGPT web, ask an owner to verify eligibility and RBAC, and confirm the current Help Center guidance for your workspace.

Tool scan fails immediately

Cause: an unreachable endpoint, incorrect metadata, TLS problem, or authentication configuration. Fix: verify the exact remote URL from an external network, inspect the server’s TLS certificate and logs, then repeat OAuth authorization. A local-only address will not work without a tunnel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OAuth works once, then calls are unauthorized

Cause: the provider did not issue a refresh token or did not advertise refresh capability. Fix: request offline_access where appropriate, publish the provider’s discovery metadata, and reauthorize a test account.

A tool appears in the draft but calls fail after publication

Cause: the published snapshot is stale or the server changed its schema incompatibly. Fix: have an Enterprise/Edu administrator refresh and review the tool diff, or recreate and republish the app in Business.

ChatGPT selects an unsafe action

Cause: ambiguous prompts, overly broad tool descriptions, or insufficient server-side authorization. Fix: narrow tool scopes, improve descriptions and required inputs, separate read and write tools, and enforce authorization in the server. Test adversarial prompts before publication.

A private server cannot be reached

Cause: ChatGPT does not connect directly to localhost or an inaccessible private network. Fix: expose a properly secured remote endpoint or use the Secure MCP Tunnel route OpenAI recommends for private, on-premises, or developer-machine servers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup: ScreenshotNeo’s MCP server

If your immediate goal is to give ChatGPT or another MCP client a reliable website-screenshot tool, ScreenshotNeo provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools. You can connect that remote MCP service through the same custom-app workflow above, subject to your workspace’s current MCP eligibility.

For a direct API call instead, see the ScreenshotNeo documentation. The following examples use the supplied endpoint and parameter names.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie-consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the result in X-Page-Verdict and X-Billed headers. Its options include full-page captures with lazy images, CSS-selector element capture, dark mode, device presets or custom viewports, retina scale, PDF controls, custom CSS and JavaScript, click-before-capture, selector or network-idle waits, request and resource blocking, headers, cookies, user agents, Authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. An MCP server lets AI agents use the screenshot tools directly.

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is on every plan, and yearly billing gives two months free. Create a free ScreenshotNeo account to get started.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical deployment checklist

  • Confirm the target workspace, plan, role, web access, and current MCP rollout.
  • Expose a secured remote endpoint or configure Secure MCP Tunnel for a private server.
  • Document tools, inputs, data classifications, OAuth scopes, and write effects.
  • Test discovery, OAuth refresh, read calls, write confirmations, failures, and rollback.
  • Review the draft with an administrator before publication.
  • Record the published tool snapshot and schedule refresh reviews for server changes.
  • Tell users which ChatGPT modes support the app and which do not.

Frequently Asked Questions

Can ChatGPT connect directly to an MCP server running on localhost?

No. The documented workflow requires a remote endpoint. For a developer-machine, private-network, or on-premises server, OpenAI points to Secure MCP Tunnel.

Do all MCP servers need search and fetch tools?

No. Those tools are optional; expose the capabilities your server actually implements.

Will a newly added MCP tool automatically appear for users?

No. Published apps use a reviewed snapshot. An administrator must refresh and review changes, and newly added actions are disabled by default in Enterprise/Edu.

Can I use a custom MCP app in ChatGPT Agent mode?

The current Help Center says Agent mode will not use custom apps, even though custom apps can be used by Deep Research for read/fetch actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should I do if my OAuth access expires?

Check that the provider issues refresh tokens and advertises refresh support; OpenAI commonly references the offline_access scope and standard discovery metadata.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.