Tools

chatgpt-mcp

Connects an AI assistant to explicitly permitted files, commands and desktop actions on a Linux machine.

The problem it solves

Your assistant cannot inspect local files or run your project’s commands unless you give it a connection to that machine. chatgpt-mcp provides that connection through explicitly configured tools, replacing repeated copy-pasting of file contents, terminal output and screenshots.

Ways to use it

  • Inspect and test a local project

    Grant one project directory and its required test executable. Ask the assistant to inspect the project’s documented commands, run a bounded test, and return its exit code and relevant failures instead of a huge log.

  • Review a UI in a disposable desktop

    With approved desktop grants, open a test browser on a selected X11 display and inspect a screenshot before sending input. A screenshot is an observation, not permission to type into an unrelated active session.

Before you start

  • A Linux machine or disposable VM, Node.js 22+, Git and the project-pinned pnpm 11.20.0.
  • An MCP client; for ChatGPT’s private tunnel path, your own tunnel identity and locally entered runtime key, plus systemd user services for the installer.
  • Only the filesystem roots, commands and optional desktop capabilities you intend to grant. X11 desktop operations require an explicit display.

Install and set up

  1. Check existing service ownership

    Identify any existing MCP or Overdeck-managed installation first. Do not overwrite its config or install a competing service. The standalone quick installer uses a broad-control template; choose manual setup for a minimal first connection.

  2. Build the public server

    Clone a fresh directory, install the pinned dependencies and run the repository gate. This builds the server without installing a tunnel or granting computer-control capabilities.

    git clone https://github.com/alexcodeplace/chatgpt-mcp.git
    cd chatgpt-mcp
    corepack pnpm@11.20.0 install
    corepack pnpm@11.20.0 gate
  3. Start with system.info only

    For a fresh standalone clone, copy the minimal template and start stdio. Preserve an existing config rather than overwriting it. Configure the client with these environment/path values; stdout is MCP traffic, not a human chat.

    cp config.example.json config.local.json
    CHATGPT_MCP_CONFIG="$PWD/config.local.json" node dist/src/stdio.js
  4. Add ChatGPT transport only when needed

    Follow the linked README’s Secure MCP Tunnel walkthrough and current official OpenAI instructions. Enter runtime credentials locally, keep the backend on loopback, and review broad grants before using ./install.sh. Do not paste a key into an agent prompt.

Use it in your project

  1. Confirm identity before granting access

    In the connected client, ask for system.info and check the host and enabled capabilities. A successful build alone does not establish a working client connection.

    Use system.info to report the connected host and enabled capabilities.
  2. Try an allowed read, then a bounded command

    After approving narrow filesystem/command grants, list one non-sensitive directory and run a small command with an explicit cwd and timeout. The server does not add a second approval dialogue of its own.

  3. Check the transport without exposing secrets

    For an installation created by the tunnel installer, use its saved-profile status command. For manual HTTP, check /healthz on the chosen loopback port. Use the owning deployment workflow for updates.

    ./scripts/tunnel-status.sh

What success looks like

The client discovers only your enabled tools and system.info identifies the intended Linux host. An authorized directory read works without expanding grants; blocked operations remain blocked.

Ask your agent to set it up

Copy this into a coding agent that can access your environment. The prompt asks it to check the current instructions and verify the setup before calling it done.

You can also select and copy the text directly.

What to know first

Computer access is powerful. Use a disposable VM and grant only the capabilities you intend to expose.

Current project README