Content
# ChatGPT Local Terminal Plugin
An unofficial, self-hosted MCP server that lets ChatGPT run commands on your computer through an OpenAI Secure MCP Tunnel.
It works similarly to Codex: ChatGPT can run commands, read output, manage long-running processes, send input, and work inside a chosen project directory.
**Codex and ChatGPT Work** have **limited shared quotas**, while the **regular Chat** interface pulls from a **seperate quota pool**. This lets you **use high end models like Sol without cutting into your limited Work and Codex usage limits**. Usage limits and model availability depend on your OpenAI account and may change; this tool does not guarantee extra or unlimited quota.
## How it works
```text
ChatGPT
→ OpenAI Secure MCP Tunnel
→ tunnel-client
→ local MCP server
→ commands on your computer
```
The folder where you run `start.sh` becomes the workspace.
## Installation
Currently supported on Mac, untested on Linux.
### 1. Clone the repository
```bash
git clone https://github.com/Angad-D/ChatGPT-Local-Terminal-Plugin-Unofficial.git
cd ChatGPT-Local-Terminal-Plugin-Unofficial
```
### 2. Run the installer
```bash
./install.sh
```
The installer creates a local Python environment, installs the MCP server, and downloads the latest official OpenAI `tunnel-client`.
### 3. Create a Secure MCP Tunnel
Create your own tunnel and runtime API key in OpenAI Platform.
Tunnel settings:
```text
https://platform.openai.com/settings/organization/tunnels
```
Runtime API keys:
```text
https://platform.openai.com/settings/organization/api-keys
```
### 4. Configure `.env`
Edit:
```bash
nano .env
```
Add:
```dotenv
CONTROL_PLANE_TUNNEL_ID=tunnel_your_id
CONTROL_PLANE_API_KEY=sk-your-runtime-api-key
MCP_SERVER_URL=http://127.0.0.1:8000/mcp
```
Do not commit `.env`.
### 5. Choose an access mode
Edit:
```bash
nano config.toml
```
Recommended:
```toml
sandbox_mode = "workspace-write"
network_access = true
fail_if_sandbox_unavailable = true
```
Available modes:
```toml
sandbox_mode = "read-only"
sandbox_mode = "workspace-write"
sandbox_mode = "full-access"
```
`full-access` disables filesystem sandboxing and should only be used when necessary.
Linux users need Bubblewrap for sandboxed modes:
```bash
sudo apt install bubblewrap
```
## Connect to ChatGPT
Start the tool from the project directory you want ChatGPT to access:
```bash
cd ~/Documents/projects/my-project
/path/to/ChatGPT-Local-Terminal-Plugin-Unofficial/start.sh
```
Then in ChatGPT:
1. Enable developer mode.
2. Create a custom app/plugin.
3. Choose **Tunnel** as the connection type.
4. Paste in the tunnel id.
5. Choose "No Auth"
6. Save and enable.
7. Change the plugin settings to "Always Ask"
If it doesn't let you type in the tunnel id, and asks you to create a new one after you have already made one (previous step), click "Create" in the bottom right corner of the popup (for creating the plugin), and the create option for the tunnel will switch to a text box in which you can type in your tunnel id.
The exact ChatGPT interface may change over time.
## Usage
Example prompts:
```text
List the files in this workspace.
```
```text
Run the project's tests and fix any failures.
```
```text
Start the development server and keep it running.
```
```text
Read the latest output from the development server.
```
```text
Stop the running development server.
```
Commands run in separate processes rather than one permanently shared shell. ChatGPT should specify the correct working directory for each command.
## Stopping the tool
Normally, press:
```text
Ctrl+C
```
If processes remain:
```bash
/path/to/chatgpt-terminal-mcp/stop.sh
```
## Security warning
This tool gives ChatGPT the ability to execute commands on your computer.
Commands may:
* modify or delete files;
* install or execute software;
* make network requests;
* expose sensitive information through command output;
* consume system resources.
Recommended precautions:
* Use `workspace-write`.
* Run it only from a project directory you are comfortable exposing.
* Do not run it from your home directory or filesystem root.
* Keep important projects under version control.
* Do not send passwords, API keys, recovery codes, or MFA codes through ChatGPT.
* Read all commands before allowing ChatGPT to run them (set permissions to "Always Ask")
* Stop the server when it is not being used.
No sandbox is a complete security guarantee. `full-access` gives commands the same filesystem access as your user account.
## Unofficial project
This is an independent, unofficial open-source project.
It is not affiliated with, endorsed by, approved by, or maintained by OpenAI.
Each user must create and secure their own:
* Secure MCP Tunnel;
* runtime API key;
* custom ChatGPT developer app/plugin.
ChatGPT plans, models, usage limits, developer mode, and MCP availability vary and may change.
Connection Info
You Might Also Like
Train-in-Silence
The first Task-Aware MCP server and automated VRAM calculator for LLM...
stacklit
108,000 lines of code. 4,000 tokens of index. One command makes any repo...
AppClaw
AI-powered mobile automation agent — describe what you want in plain...
pdf-mcp
Production-ready MCP server for PDF processing with intelligent caching....
kotadb
Local-only code intelligence API for AI developer workflows (Bun +...
gemini-api-docs-mcp
A remote HTTP MCP server for searching Google Gemini API documentation.