# Connect ChatGPT to a gateway

Add an MCP gateway as a ChatGPT app with a sign-in through your identity provider.

ChatGPT reaches an [MCP gateway](https://zato.io/docs/ai/mcp/index.html) through an app, created once in the settings of a Business, Enterprise or Edu workspace with developer mode on, after which the gateway's tools are available in chats that have the app enabled. The app form has no field for a header, so the gateway it connects to has [OAuth](https://zato.io/docs/ai/mcp/oauth.html) on.

## The app form {#the-app-form}

1. Open **Settings** > **Apps and Connectors**, turn **Developer mode** on under **Advanced settings**, and choose **Create**.
2. Enter a name, e.g. `Billing`, and the gateway's URL as the **MCP Server URL**, e.g. `https://api.example.com/mcp/billing`.
3. Choose **OAuth** as the authentication method. The form shows the **Callback URL** ChatGPT uses for this app - the person managing your identity provider needs it, as described below.
4. With a provider that allows dynamic registration, Keycloak among them, leave the client fields empty - ChatGPT registers itself with the provider on the first sign-in. With a provider that does not, Entra ID among them, enter the **Client ID** and the **Client Secret** of the registration made for ChatGPT.
5. Create the app.

## What the identity provider needs {#what-the-identity-provider-needs}

ChatGPT's callback URL is shown in the app form and it is one of two addresses:

- `https://chatgpt.com/connector/oauth/<callback-id>` - an address of this app's own, which is the usual case
- `https://chatgpt.com/connector_platform_oauth_redirect` - the shared address, used with providers that meet the issuer identification requirements of the MCP authorization specification

With Keycloak and dynamic registration on, ChatGPT registers a client with that callback URL itself and nothing is registered by hand. With Entra ID, the registration for ChatGPT is a confidential client - a **Web** platform with the callback URL, a client secret under **Certificates and secrets**, and the API's scope among its permissions, as described on the [OAuth](https://zato.io/docs/ai/mcp/oauth.html#microsoft-entra-id) page.

## The sign-in {#the-sign-in}

1. The new app appears in the list with a **Connect** button.
2. Clicking it opens your identity provider's sign-in page in a new browser tab.
3. After the sign-in, the tab returns to ChatGPT, the app shows as connected and its tools are available in a chat once the app is selected from the tools menu.

ChatGPT keeps the token and refreshes it on its own until the provider's session ends. The app's menu has **Disconnect**, which drops it.

## When access is refused {#when-access-is-refused}

A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists, or signed in to the wrong tenant - sees the app fail to connect, with a message that the server rejected the authentication, and **Connect** stays available. The reason is in the gateway's [audit log](https://zato.io/docs/ai/mcp/audit-log.html), in the **Reason** column of the `auth-failed` event, next to the person's name.

## See also {#see-also}

- [OAuth](https://zato.io/docs/ai/mcp/oauth.html) - How the sign-in works and how to set up Entra ID or Keycloak
- [Sharing with clients](https://zato.io/docs/ai/mcp/sharing-with-clients.html) - The export with the gateway's address and the other clients' snippets
- [MCP gateways](https://zato.io/docs/ai/mcp/index.html) - Configuration and the governance controls

## Learn more {#learn-more}

- [MCP tutorial](https://zato.io/tutorials/mcp/01.html) - Expose Python services as AI tools and connect Claude Code in minutes
- [AI Integrations overview](https://zato.io/docs/ai/) - Both directions of AI traffic in one platform, and where to start
- [MCP gateway reference](https://zato.io/docs/ai/mcp/) - Configuration, endpoint behavior and the governance controls
- [Tool schemas](https://zato.io/docs/ai/mcp/tool-schemas.html) - How a service's docstring and declared I/O become its tool definition
- [MCP gateway security](https://zato.io/docs/ai/mcp/security.html) - API keys, Basic Auth and bearer tokens for AI agents
- [MCP response controls](https://zato.io/docs/ai/mcp/response-controls.html) - PII removal, prompt-injection safeguards and token-denominated size caps
- [MCP audit log](https://zato.io/docs/ai/mcp/audit-log.html) - What each agent did, when and with what outcome - payloads never recorded
- [MCP alerts](https://zato.io/docs/ai/mcp/alerts.html) - Failing backends, agents stuck in a loop and gateways with too many tools
- [Cost and limits](https://zato.io/docs/ai/cost-and-limits.html) - Every knob that caps AI cost and traffic, with worked examples
- [GitOps for AI integrations](https://zato.io/docs/ai/enmasse.html) - LLM connections and MCP gateways as YAML in version control
- [AI examples](https://zato.io/docs/ai/examples/) - Complete, runnable scenarios - one real-world need per file
