Connect ChatGPT to a gateway

Add an MCP gateway as a ChatGPT app with a sign-in through your identity provider.

ChatGPT reaches an MCP gateway through an app, created once in the settings of a Business, Enterprise or Edu workspace with developer mode on, after which the gateway's tools are available in chats that have the app enabled. The app form has no field for a header, so the gateway it connects to has OAuth on.

The app form

  1. Open Settings > Apps and Connectors, turn Developer mode on under Advanced settings, and choose Create.
  2. Enter a name, e.g. Billing, and the gateway's URL as the MCP Server URL, e.g. https://api.example.com/mcp/billing.
  3. Choose OAuth as the authentication method. The form shows the Callback URL ChatGPT uses for this app - the person managing your identity provider needs it, as described below.
  4. With a provider that allows dynamic registration, Keycloak among them, leave the client fields empty - ChatGPT registers itself with the provider on the first sign-in. With a provider that does not, Entra ID among them, enter the Client ID and the Client Secret of the registration made for ChatGPT.
  5. Create the app.

What the identity provider needs

ChatGPT's callback URL is shown in the app form and it is one of two addresses:

  • https://chatgpt.com/connector/oauth/<callback-id> - an address of this app's own, which is the usual case
  • https://chatgpt.com/connector_platform_oauth_redirect - the shared address, used with providers that meet the issuer identification requirements of the MCP authorization specification

With Keycloak and dynamic registration on, ChatGPT registers a client with that callback URL itself and nothing is registered by hand. With Entra ID, the registration for ChatGPT is a confidential client - a Web platform with the callback URL, a client secret under Certificates and secrets, and the API's scope among its permissions, as described on the OAuth page.

The sign-in

  1. The new app appears in the list with a Connect button.
  2. Clicking it opens your identity provider's sign-in page in a new browser tab.
  3. After the sign-in, the tab returns to ChatGPT, the app shows as connected and its tools are available in a chat once the app is selected from the tools menu.

ChatGPT keeps the token and refreshes it on its own until the provider's session ends. The app's menu has Disconnect, which drops it.

When access is refused

A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists, or signed in to the wrong tenant - sees the app fail to connect, with a message that the server rejected the authentication, and Connect stays available. The reason is in the gateway's audit log, in the Reason column of the auth-failed event, next to the person's name.

See also

FeatureWhat it does
OAuthHow the sign-in works and how to set up Entra ID or Keycloak
Sharing with clientsThe export with the gateway's address and the other clients' snippets
MCP gatewaysConfiguration and the governance controls

Learn more