Connect ChatGPT to a gateway
Add an MCP gateway as a ChatGPT app with a sign-in through your identity provider.
ChatGPT reaches an MCP gateway through an app, created once in the settings of a Business, Enterprise or Edu workspace with developer mode on, after which the gateway's tools are available in chats that have the app enabled. The app form has no field for a header, so the gateway it connects to has OAuth on.
The app form
- Open Settings > Apps and Connectors, turn Developer mode on under Advanced settings, and choose Create.
- Enter a name, e.g.
Billing, and the gateway's URL as the MCP Server URL, e.g.https://api.example.com/mcp/billing. - Choose OAuth as the authentication method. The form shows the Callback URL ChatGPT uses for this app - the person managing your identity provider needs it, as described below.
- With a provider that allows dynamic registration, Keycloak among them, leave the client fields empty - ChatGPT registers itself with the provider on the first sign-in. With a provider that does not, Entra ID among them, enter the Client ID and the Client Secret of the registration made for ChatGPT.
- Create the app.
What the identity provider needs
ChatGPT's callback URL is shown in the app form and it is one of two addresses:
https://chatgpt.com/connector/oauth/<callback-id>- an address of this app's own, which is the usual casehttps://chatgpt.com/connector_platform_oauth_redirect- the shared address, used with providers that meet the issuer identification requirements of the MCP authorization specification
With Keycloak and dynamic registration on, ChatGPT registers a client with that callback URL itself and nothing is registered by hand. With Entra ID, the registration for ChatGPT is a confidential client - a Web platform with the callback URL, a client secret under Certificates and secrets, and the API's scope among its permissions, as described on the OAuth page.
The sign-in
- The new app appears in the list with a Connect button.
- Clicking it opens your identity provider's sign-in page in a new browser tab.
- After the sign-in, the tab returns to ChatGPT, the app shows as connected and its tools are available in a chat once the app is selected from the tools menu.
ChatGPT keeps the token and refreshes it on its own until the provider's session ends. The app's menu has Disconnect, which drops it.
When access is refused
A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists, or signed in to the wrong tenant - sees the app fail to connect, with a message that the server rejected the authentication, and Connect stays available. The reason is in the gateway's audit log, in the Reason column of the auth-failed event, next to the person's name.
See also
| Feature | What it does |
|---|---|
| OAuth | How the sign-in works and how to set up Entra ID or Keycloak |
| Sharing with clients | The export with the gateway's address and the other clients' snippets |
| MCP gateways | Configuration and the governance controls |