Connect a custom MCP server
Connect your Model Context Protocol (MCP) server to ChatGPT as a plugin. ChatGPT supports both read and write tools from your server.
Only connect to MCP servers you trust. An untrusted server may access or steal information shared through app use, or trick ChatGPT into using tools in unintended ways, including changing or deleting data. Review prompt injections and other risks before connecting a server.
How to use
-
Access: Use ChatGPT on the web. Workspace permissions and security restrictions, including Lockdown, apply to adding and using custom MCP servers.
-
Add an MCP server as a plugin:
- Go to ChatGPT Plugins.
- Select the plus button, then Add custom MCP server.
- Enter a name and, optionally, a description. Under Connection, enter your Server URL, or select Tunnel for a Secure MCP Tunnel.
- Configure authentication for your server.
- Review the risk warning and select I understand and want to continue.
- Select Create as a plugin.
- Supported MCP protocols: SSE and streaming HTTP.
- Authentication options include OAuth, No authentication, and OAuth or no authentication.
- For OAuth, if static credentials are provided, then they will be used. Otherwise, ChatGPT can use Client ID Metadata Documents when the authorization server advertises support and the app creator chooses CIMD. CIMD supports public-client token exchange (
none) and signed client assertion token exchange (private_key_jwt). ChatGPT can also use DCR when configured. - Mixed authentication supports OAuth and no authentication. This means the initialize and list tools APIs use no auth, and tools use OAuth or no auth based on the security schemes set on their tool metadata.
- For OAuth, if static credentials are provided, then they will be used. Otherwise, ChatGPT can use Client ID Metadata Documents when the authorization server advertises support and the app creator chooses CIMD. CIMD supports public-client token exchange (
- Find the resulting plugin in your personal plugins or the workspace where you created it. Install it before using it in a conversation.
-
Manage tools: In app settings there is a details page per app. Use that to toggle tools on or off and refresh apps to pull new tools, descriptions, and server instructions from the MCP server.
-
Use apps in conversations: In the prompt box, type
@and select your installed plugin. Custom MCP plugins can be used alongside other apps, subject to workspace permissions and security restrictions. You may need to explore different prompting techniques to call the correct tools. For example:- Be explicit:
Use the "Acme CRM" app's "update_record" tool to …. When needed, include the server label and tool name. - Disallow alternatives to avoid ambiguity: “Do not use built-in browsing or other tools; only use the Acme CRM app.”
- Disambiguate similar tools: “Prefer
Calendar.create_eventfor meetings; do not useReminders.create_taskfor scheduling.” - Specify input shape and sequencing: “First call
Repo.read_filewith{ path: "…" }. Then callRepo.write_filewith the modified content. Do not call other tools.” - If multiple apps overlap, state preferences up front (for example, “Use
CompanyDBfor authoritative data; use other sources only ifCompanyDBreturns no results”). - Custom MCP servers do not require
search/fetchtools. Any tools your app exposes (including write actions) are available, subject to confirmation settings. - See more guidance in Using tools and Prompting.
- Improve tool selection with better tool descriptions: In your MCP server, write action-oriented tool names and descriptions that include “Use this when…” guidance, note disallowed/edge cases, and add parameter descriptions (and enums) to help the model choose the right tool among similar ones and avoid built-in tools when inappropriate.
- Add server instructions for cross-tool guidance: Use the MCP
instructionsfield for server-wide guidance such as required tool sequences, shared rate limits, or relationships between tools. Keep the first 512 characters self-contained.
Examples:
Schedule a 30‑minute meeting tomorrow at 3pm PT with alice@example.com and bob@example.com using "Calendar.create_event". Do not use any other scheduling tools.Create a pull request using "GitHub.open_pull_request" from branch "feat-retry" into "main" with title "Add retry logic" and body "…". Do not push directly to main. - Be explicit:
-
Reviewing and confirming tool calls:
- Inspect JSON tool payloads to verify correctness and debug problems. For each tool call, expand the tool call details. Full JSON contents of the tool input and output are available.
- Write actions by default require confirmation. Carefully review the tool input which will be sent to a write action to ensure the behavior is as desired. Incorrect write actions can inadvertently destroy, alter, or share data!
- Read-only detection: We respect the
readOnlyHinttool annotation (see MCP tool annotations). Tools without this hint are treated as write actions. - You can choose to remember the approve or deny choice for a given tool for a conversation, which means it will apply that choice for the rest of that conversation. Because of this, you should only allow a tool to remember the approve choice if you know and trust the underlying application to make further write actions without your approval. New conversations will prompt for confirmation again. Refreshing the same conversation will also prompt for confirmation again on subsequent turns.