ChatGPT Custom MCP App
ChatGPT supports remote MCP connectors via Developer Mode / Custom Plugins using Managed OAuth.
1. Cloudflare Zero Trust Configuration
Before connecting ChatGPT Web, configure the OAuth callback endpoints in your Cloudflare Zero Trust dashboard:
- Log into Cloudflare Zero Trust → Access controls → Applications.
- Click Edit on the application protecting
harness.zuey.me. - Navigate to Advanced settings → Managed OAuth.
- Under Allowed redirect URIs, add:
https://chatgpt.com/connector/oauth/*https://chatgpt.com/connector_platform_oauth_redirecthttps://chatgpt.com/api/aip/p/oauth/callback
- Click Save application.
Least-Privilege Scoping
Always scope ChatGPT redirect URIs to https://chatgpt.com/connector/oauth/* rather than a broad wildcard https://chatgpt.com/* to avoid leaking authorization codes on arbitrary endpoints.
2. Setup Instructions in ChatGPT
Step-by-Step Connector Setup
- In ChatGPT Web, click your avatar → Settings (or Workspace Settings) → Connected apps / Create new plugin / connector.
- Name the connector (e.g.
CloudHarness). - Set the Server URL to:text
https://harness.zuey.me/mcp - Select OAuth as the Authentication method.
- Click Create (or Connect & Authorize).
- A browser popup will open the Cloudflare Access login page (GitHub or Google SSO). Complete authentication to link the connector.
- Once authorized, ChatGPT scans and registers the Cloud Harness MCP tool definitions.
Developer Mode (Draft) vs. Published Custom Connector
ChatGPT provides two distinct execution modes for custom MCP apps:
- Developer Mode (Draft / Dev Connector):
- When first created, the connector is in Draft (Dev) state, visible under Settings → Apps → Enabled Apps with a Dev label.
- Prerequisites: Developer Mode must be actively enabled for your user account (Settings → Apps → Advanced Settings → Developer mode).
- Supported Surfaces: Testing is supported in standard 1-on-1 ChatGPT Web conversations with the draft app selected.
- Workspace Published (Custom Connector):
- To make CloudHarness accessible across your workspace without requiring each member to manage Developer Mode, a Workspace Admin/Owner must publish the connector.
- Navigate to Workspace Settings → Apps → Drafts, select the connector, configure allowed actions and group access via RBAC, and click Publish.
- Once published, the connector displays the custom label and is available to all authorized workspace members according to workspace action controls.
Plan & Feature Availability
Full MCP execution (including write/execute operations such as workspace_open and exec_run) is provided in beta for ChatGPT Business, Enterprise, and Edu plans. Feature availability, UI paths, and permissions follow OpenAI's Developer mode and MCP apps in ChatGPT guide.
3. Troubleshooting
FORBIDDEN: This conversation does not support developer MCPs
Cause: ChatGPT discovered the MCP tool schemas, but the active conversation context or account configuration prohibits executing draft/developer-mode MCP tools. This occurs in any of the following conditions:
- Unsupported Conversation Context: Developer MCPs (draft apps) cannot be invoked in Custom GPTs, Project chats (unless permitted by project settings), Canvas mode, temporary chats, or ChatGPT mobile apps.
- Developer Mode Disabled: The connector is in draft state, but Developer Mode is toggled off in the current user account settings.
- Draft State in Workspace Conversations: The connector has not yet been published by a Workspace Admin/Owner and is being accessed in a standard team conversation.
- Plan Tier Gating: The ChatGPT plan tier does not support full MCP write actions in developer mode.
- Stale Thread Cache: An existing chat thread started prior to connector authorization retained an earlier tool configuration.
Fix:
- Use Standard 1-on-1 Web Chats: Open a fresh conversation on ChatGPT Web, mention
@CloudHarnessor select the connector from the tools menu, and initiate the task. - Enable Developer Mode: Go to Settings → Apps → Advanced Settings (or Workspace Settings → Permissions & Roles) and ensure Developer mode is toggled ON.
- Publish to Workspace (Admins): In Workspace Settings → Apps → Drafts, review the tool actions and click Publish to convert the draft into an approved workspace Custom Connector.
- Verify Plan Support: Confirm your workspace has access to full MCP support (Business, Enterprise, or Edu plan).
- Start a Fresh Thread: If the connector was just created or re-authorized, open a new chat session to refresh conversation capabilities.
Dynamic client registration failed (invalid_client_metadata: redirect_uri is not allowed)
Cause: Cloudflare Access rejected ChatGPT's callback URL during Dynamic Client Registration. Fix:
- In ChatGPT's connector modal, expand Advanced OAuth settings to view the exact redirect URI assigned to your connector.
- Verify that
https://chatgpt.com/connector/oauth/*(or the exact URI shown in the modal) is listed in Allowed redirect URIs in your Cloudflare Zero Trust dashboard. - Save the Cloudflare application and retry creating the connector.