ChatGPT Connectors and Apps: What They Can Reach
ChatGPT’s connectors became apps, and apps now arrive inside plugins. What they are called today, what they can read and change, how they work inside ChatGPT Projects, how to add your own MCP server, and what an admin controls.
7 min read
ChatGPT connectors are now called apps, and apps now usually arrive inside plugins. An app is a connection to another service, built on an MCP server, that lets ChatGPT search, read and sometimes change what is in that service; a plugin is the installable bundle that carries one or more apps along with skills. Whatever the name, an app reaches only what the account you signed in with can reach in that service, and a workspace admin decides which apps and which actions are allowed at all. Inside ChatGPT Projects, connectors work at two levels: connected context can sit in a project’s Sources for every chat in it, and installed plugins can be called from any project chat. For a service with no listing, developer mode lets you add a remote MCP server yourself.
Step-by-step set-ups for particular tools are elsewhere: ChatGPT connectors for Jira, Notion MCP with ChatGPT and Trello MCP with ChatGPT. The other ways OpenAI’s products speak MCP, from the API to Codex, are mapped in MCP with OpenAI. This post is the overview: what these things are, what they can reach, and who controls it. It follows OpenAI’s documentation as it reads at the end of September 2026; the names have changed more than once and may again.
The names, once
OpenAI started with connectors, moved to apps, and its newest menus say Plugins. Its admin guide to plugin controls (opens in a new tab) settles the vocabulary: app and MCP server refer to the same connected integration and are used interchangeably, while a plugin packages reusable workflows and can include skills and MCP servers. So when a vendor says it has a ChatGPT connector, a ChatGPT app or a ChatGPT plugin, it usually means the same connection, possibly wrapped with some instructions.
- Skills: reusable instructions for one kind of work, which ChatGPT loads when a request matches.
- MCP servers: the connection itself. They define tools, enforce sign-in, return structured data and perform actions in the other system, and can include their own interface inside the chat.
- Browser extensions and hooks: extras some plugins need. Hooks run in the Codex runtime, which includes ChatGPT Work, and have to be present where that runs.
What an app can reach
An app can reach exactly what the service lets the signed-in account reach, and no more. OpenAI’s admin guide is direct about it: making an app or plugin available in ChatGPT does not grant access to files, records or actions in the connected service. Your Google Drive permissions, your Jira project roles, your Slack channels set the outer limit. ChatGPT’s settings can only narrow that, or change when it stops to ask.
Within that limit, apps do three kinds of thing:
- Look things up during a chat. ChatGPT sends a request to the service and uses the answer. OpenAI calls this non-synced: data from Chat and deep research is processed transiently and not indexed.
- Search content indexed in advance. Some apps support sync, where selected content is indexed ahead of time rather than fetched on each request. Each plugin’s page says whether its connection supports sync, and changes in the source can take time to appear.
- Act. Create a Jira work item, send a message, update a record. Actions are where the approval settings matter, and where an admin can restrict an app to read-only actions or an approved set.
One sign-in shortcut is worth knowing about. OpenAI’s plugins documentation (opens in a new tab) describes Sign in with ChatGPT, rolling out in beta for some partners, and says it shares only your name, email address and profile picture with the partner. It does not grant the plugin access to your data or approve actions; you review the plugin’s requested permissions as a separate step.
Using an app in a chat
- Open Plugins in ChatGPT, search or browse, and install the plugin you want.
- Connect the underlying app when asked. Some plugins ask at install, others the first time you use them.
- Start a new chat. Bundled skills become available in new chats after installation.
- Describe the outcome, such as “summarise unread threads from today”, and let ChatGPT pick the tools, or type
@to choose the plugin or one of its skills yourself.
Uninstalling a plugin removes the bundle, but OpenAI notes that a separately connected MCP integration stays connected until you disconnect it too. If you are tidying up access, do both.
Connectors in ChatGPT Projects
A project keeps related chats, files, instructions and sources together. OpenAI’s page on projects and chats (opens in a new tab) describes each project as having a Chats section and a Sources section, for uploaded files and connected context, with project instructions applying across its chats. It also notes that a ChatGPT project on the web does not give ChatGPT access to a folder on your computer: you upload or connect the sources you want it to use.
That gives you two places to put an outside service, and they suit different jobs.
- Project Sources, for reference material every chat in the project should draw on: the spec, the contract, the brand guide, a connected folder of documents. It is there without anyone asking for it.
- Apps called from a chat, for live data and actions: today’s open bugs, this week’s calendar, a record to update. You ask for it when you need it, and the answer is as fresh as the service.
- Project instructions, to steer between them. They are text ChatGPT reads, not a switch, but a line such as “for ticket status use the Jira app, not the uploaded export” removes the guesswork.
- One chat per outcome. OpenAI suggests starting a separate chat in the project for each distinct outcome, so a research chat and a drafting chat do not mix, while the project holds the shared context.
On the web, the same project can hold chats started in Chat and in ChatGPT Work, and OpenAI’s projects page points to installing plugins in Work to bring in context and actions. In the ChatGPT desktop app, a project can also be local, attached to folders on your computer that ChatGPT can read and change there.
Your own MCP server: developer mode
When a service has an MCP server but no listing, ChatGPT’s developer mode (opens in a new tab) adds it as your own app. OpenAI lists it for Pro, Plus, Business, Enterprise and Education accounts on the web, and describes it as full MCP client support for read and write tools: powerful but dangerous, meant for people who understand prompt injection, mistaken writes and malicious servers.
- Turn it on under Settings, Security and login, Developer mode.
- In Plugins, use the plus button to create a developer-mode app with the server’s URL. It supports SSE and streaming HTTP, with OAuth, no authentication or a mix. The app appears under Drafts.
- In a chat, choose Developer mode from the plus menu and select the app for that conversation.
- Confirm writes as they come. Tools not marked read-only with the
readOnlyHintannotation are treated as writes and ask first by default; you can remember a choice for the rest of that conversation only.
Being explicit helps: OpenAI’s own advice is to name the app and the tool, and to say which other tools not to use. What readOnlyHint means for people building servers is covered in MCP with OpenAI.
What an admin controls
In a Business, Enterprise or Edu workspace, access runs through a chain of layers, and a request has to pass every one that applies. OpenAI’s plugin controls guide lists them: whether the plugin is available to a role, which skills it contributes, whether the role may use its MCP server, which actions are allowed and when ChatGPT asks, what the signed-in account may do in the service, and what the runtime may do with the result.
- Defaults differ by plan. The ChatGPT Work overview (opens in a new tab) says plugins and their apps are off by default for Enterprise and Edu workspaces and on by default for Business.
- Action control. Where an app supports it, admins can allow read-only actions or an approved custom set, and decide how newly added actions are handled.
- App permissions. These set when ChatGPT asks before using a connection or making a change. Not every action needs an individual confirmation.
- Shared and agent-owned connections. A connection can belong to a person, be shared, or belong to an agent. A shared one uses the connected account’s permissions in the source system, which can differ from the permissions of the person asking.
- Start with reads. OpenAI’s own rollout advice is to enable read actions first and to name an owner, check scopes and document a recovery path before switching on writes.
What connectors do not give you
Apps act through an account. A Jira item ChatGPT creates through your connection looks like one you created, and a shared connection acts as whoever owns it. For reading, that is fine. For a list of work that several people and assistants change, it means the service’s own history cannot tell you which changes were made by ChatGPT.
fenbs, a small task board with lanes To Do, Next Up, In Progress and Completed, takes the other approach. It is a remote MCP server at https://fenbs.ai/api/mcp, which ChatGPT can add in developer mode where your plan allows, with a browser sign-in and nothing to paste. ChatGPT then holds your role on the board narrowed by the scopes you tick, and every change it makes appears in the board’s History under its own name alongside yours.
Related
Connect ChatGPT to a board: the ChatGPT integration. How projects compare across assistants: Claude Projects vs ChatGPT Projects. What the scopes on a connection mean: assistant tokens and scopes. The risks behind the warnings: MCP security risks.