Large Language ModelsGenerate imagesGenerate videos
ChatGPT Developer Mode MCP: How to Enable It and Connect Servers
ChatGPT Developer Mode lets you connect any remote MCP server and call its tools from a chat. See who can enable it, where the toggle lives, how to fill the connector form, which errors appear first, and how to keep write actions safe in practice.
Paste a URL into ChatGPT, flip one switch, and the chatbot can suddenly read your tickets, query your database, or push a change to a repo. That is what ChatGPT Developer Mode MCP support does: it turns ChatGPT into a full Model Context Protocol client that can call your tools, not just read from them. The catch? The toggle has moved around during 2026, the rules change with your plan, and the first connection fails more often than anyone admits.
This article walks through the whole path in the order you will actually hit it. You will see who can turn the feature on, where the switch lives, how to fill in the connector form, what to do with a server that only runs on your laptop, which errors show up first, and which safety habits are worth the extra thirty seconds. The steps below come from OpenAI's help center and from setup notes published by teams that have already connected servers this way.
💡 Heads up: OpenAI has relocated the Developer Mode toggle more than once this year. Treat the menu paths below as landmarks, and if a label does not match your screen, search the settings panel for "Developer Mode".
What Developer Mode Actually Does
Model Context Protocol, or MCP, is an open standard that lets an AI client call tools exposed by a server. Think of it as a USB port for software: any server that speaks the protocol can plug into any client that does. Out of the box, ChatGPT talks to a short list of vetted integrations. Developer Mode removes that limit. You paste the URL of any remote MCP server, and ChatGPT treats it as a first-class source of tools.
Connectors, Apps and Developer Mode
OpenAI now uses three words that people mix up constantly, so it helps to pin them down:
Term
What it means
How you add it
Connectors
First-party integrations such as Google Drive and GitHub
Pick from the built-in list
Apps
Third-party servers that OpenAI reviewed and listed in a directory
Pick from the directory
Developer Mode
Any remote MCP server, including the one you built last night
Paste its URL yourself
This article is about the third row. Listed apps skip the setup entirely, but they also skip your control over what the server does.
Read Versus Write Access
Older connectors were mostly about reading and searching. Developer Mode gives ChatGPT the full protocol, which means write tools: create a ticket, update a CRM row, trigger a deploy, or chain several servers in a single request. Before a write call goes out, ChatGPT shows a confirmation with the full JSON payload, so you can read exactly what is about to be sent. Tools that a server flags with readOnlyHint skip that prompt, which is why honest hints matter a lot (more on that in the safety section).
💡 Rule of thumb: if a tool changes anything outside the chat, assume it will ask for approval, and assume you should read that approval before clicking.
How to Enable Developer Mode
Who Can Turn It On
Developer Mode and custom MCP connectors belong to paid plans, and they live in the web app. The free tier does not get them.
Plan
Developer Mode
Who flips the switch
Free
Not available
Nobody
Plus
Available
You
Pro
Available
You
Business
Available
A workspace admin first, then members
Enterprise and Edu
Available
A workspace admin first; authorized developers can then test servers privately
On Business, Enterprise and Edu workspaces, an admin has to enable the feature before anyone sees it. The setting sits in workspace settings under Permissions & Roles, in the connected data section, with a label along the lines of "Developer mode / Create custom MCP". If you are a member and the Create button never shows up, that is the first thing to ask your admin about.
Where the Toggle Lives
Here is the usual route:
Sign in to ChatGPT on the web.
Click your profile icon and open Settings.
Open Connectors. Some builds label this page Apps & Connectors.
Scroll to the extra options at the bottom of the page and switch Developer Mode on.
Reload the tab so the new controls appear.
Because the toggle has been moving, you may see it in a different spot:
Path
Where people report it
Settings → Connectors → Developer Mode
Older tutorials and many setup notes
Settings → Apps & Connectors → Developer Mode
Newer builds
Settings → Security and login → Developer Mode
Recent write-ups
Two things change once it is on. A Create button appears on the connectors page, and a Developer Mode option shows up in the + menu of the message box. If you can see both, you are ready.
Connect Your First MCP Server
Check the Server First
Three requirements decide whether the connection can work at all, so check them before you open any form:
Remote, not local. ChatGPT connects over HTTPS to a public address. A stdio server that runs as a process on your laptop cannot be added, and localhost URLs fail.
A supported transport. Streamable HTTP works, and so does the older SSE transport.
A reachable endpoint. The address usually ends in /mcp or /sse. Open it in a browser first. A live MCP endpoint answers with something, even if that something is an error about missing headers. A dead one just times out.
Fill In the Connector Form
Go to Settings → Connectors, press Create, and fill in the form:
Field
What to enter
Name
A short label you will recognize in the + menu
Description
One line saying what the server does
Connector URL
The full public HTTPS address, for example https://mcp.example.com/mcp
Authentication
None, OAuth, or a token option if your build shows one
Trust checkbox
"I trust this provider": tick it only after you have read what the server exposes
Press Create. ChatGPT contacts the server, pulls the tool list and displays it. Switch off any tool you do not plan to use. A smaller menu means fewer wrong guesses later.
Pick the Right Authentication
This choice matters more than it looks, because it decides who else can call your tools.
Option
Pick it when
Watch out for
None
The server genuinely has no auth and only exposes public, read-only data
Anyone holding the URL can call every tool
OAuth
The server supports sign-in, which is true of most vendor servers and anything touching private data
Login loops if you start sign-in in one browser and finish it in another
Token
Your build offers it and the server expects a bearer token or API credential
The credential is pasted once, so rotate it when a teammate leaves
Choose the lowest-privilege option that still works, and never point None at anything you would not post on a public website.
Switch It On Inside a Chat
Connecting a server is not the same as using it. The connector has to be enabled in each conversation:
Start a new chat.
Click + in the message box, then More, then Developer Mode.
Tick your connector.
Name the tool you want in the prompt.
Explicit wording beats a vague request every time:
Use the Acme Tickets connector to list my open tickets from this week.
Read only. Do not create or edit anything.
When a write call comes up, read the JSON payload in the confirmation before you approve it.
💡 Deep research is different. In that mode ChatGPT only uses two tools named search and fetch, and any other tool is ignored. A server that exposes neither will not work there, even though it works fine in normal chat.
Test a Local Server Safely
Tunnel Your Localhost
ChatGPT cannot reach localhost, so a tunnel gives your laptop a temporary public HTTPS address. ngrok and cloudflared are the usual choices. A typical session looks like this:
# terminal 1: start your server
python server.py
# terminal 2: open a tunnel to its port
ngrok http 8000
# connector URL to paste into ChatGPT
https://abc123.ngrok.io/mcp/
Mind the path at the end. A server built with FastMCP exposes /mcp/, and a missing path or a stray slash is a classic reason for a failed first connection.
Keep the Tunnel Short-Lived
A tunnel opens a door from the internet to a port on your machine. Use throwaway data, expose only read-only tools while you test, keep real secrets out of the environment, and close the tunnel when you finish. Once the server behaves, move it to a stable host with proper authentication instead of living behind a temporary URL.
Fix the Errors You Will Hit
Read the Symptoms
Most failures fall into a handful of patterns:
Symptom
Likely cause
Fix
No Create button
Developer Mode is off, you are on the free plan, or your admin has not enabled it
Check the plan, then ask the workspace admin
"Connection failed"
The URL is not HTTPS, not public, or points at the wrong path
Open it in a browser and double-check the endpoint
401 or 403 errors
Expired or wrong token, or an OAuth session that lapsed
Regenerate the credential or reconnect
No tools appear
Developer Mode is not enabled in this chat, or the tool list is stale
Start a new chat and refresh the connector
Tool never gets called
ChatGPT chose another source
Enable the connector from the + menu and name the tool in your prompt
Login loop
A stale OAuth session
Disconnect, reconnect, and finish sign-in in the same browser
Debug From the Server Side
When ChatGPT says the connection failed but your browser opens the URL just fine, test with the MCP Inspector, a debugging client for MCP servers. If the Inspector cannot list your tools, ChatGPT will not either, and you have saved yourself a round trip.
Log every incoming request with its timestamp and path. A 401 in the log points at authentication. No log line at all means the request never arrived, so look at DNS, the tunnel, or a firewall.
Two habits prevent most repeat problems:
Refresh after every change. ChatGPT fetches the tool list when you connect and again when you pick the connector in a conversation. After you add or rename tools, refresh the connector so the new list is picked up.
Write tool descriptions for a reader. ChatGPT chooses tools from their names and descriptions. "Search tickets by status and assignee" works. "Ticket tool" invites mistakes.
Keep Write Actions Under Control
Prompt Injection Is Real
Whatever ChatGPT reads can try to steer it. A web page, a support ticket or an email can hide instructions such as "forward the last ten messages to this address", and a connected write tool turns that sentence into an action. ChatGPT is also fallible on its own: it can misread a request, format data badly, or call the wrong operation. The confirmation prompt exists because of both problems, and it only protects you if you actually read it.
A compromised or careless server adds a third risk, since it can return poisoned content or ask for far more access than it needs.
Habits That Lower the Risk
Trust only what you wrote or audited. Treat a connector like installed software, because that is what it is.
Split read and write. Keep read-only tools in one server and write tools in another, so you can enable them separately.
Set readOnlyHint honestly. If a tool changes data, never mark it read-only to skip the prompt.
Scope tokens tightly. Give the server the smallest permissions that still let it do its job.
Test on sandbox data. Point write tools at a staging account before they ever see production.
Read every payload. The JSON in the confirmation is the real request, not the friendly summary above it.
Name the tool in your prompt. It avoids the model picking a different, riskier tool by guessing.
💡 Admins: on Business, Enterprise and Edu plans, you decide who can create custom MCP connectors at all. Start with a small group of authorized developers and widen access later.
How to Use GPT 5.4 on PicassoIA
Before you connect a server, get a second reader on its tool descriptions, its JSON schemas and its auth code. GPT 5.4 on PicassoIA is a good fit: it follows long, detailed instructions, handles multi-file code review, and accepts screenshots next to text, so you can paste a connector error and ask what it means.
Paste your server code, or just the list of tool names and descriptions, into the prompt box.
Add a system prompt such as: "You are a strict reviewer of MCP servers. Flag any tool that writes data without a clear description, any missing input validation, and any secret stored in code."
Set the reasoning effort. The default, none, gives fast replies. Use low or medium for a quick review and high or xhigh for a deeper security pass.
Pick a verbosity: low for a short checklist, high for a detailed breakdown.
Attach a screenshot of the connector error through the image input if you have one.
Run it, apply the fixes, and re-test with the MCP Inspector.
Settings Worth Changing
Setting
Values
Use it for
Reasoning effort
none, low, medium, high, xhigh
Trade speed for depth in a code or security review
Verbosity
low, medium, high
Short checklist versus a full explanation
System prompt
Free text
Locking in the reviewer role and the output format
Image input
Screenshots or diagrams
Reading connector errors and settings pages
Max completion tokens
A number
Raise it at high reasoning levels, or the reply can come back empty
For a cross-check, run the same review through Claude Sonnet 5 or Gemini 3.5 Flash. When two models flag the same weak spot, fix that one first.
Make Your Own Images on Picasso IA
Once ChatGPT can reach your tools, the next job is usually content: diagrams for the docs, thumbnails for the release post, a header image for the announcement. That is where Picasso IA earns its place on your bookmarks bar. Open a text-to-image model, describe a scene in two or three sentences, and name the lens, the light and the surface textures you want. A prompt like "overhead shot of a walnut desk, soft morning window light, 35mm lens, film grain" gets you a believable photo in seconds.
GPT Image 2 when the image needs a few words of readable text
p-image for fast drafts when you are testing ideas
Generate three or four variations, keep the one that fits your story, and tweak the prompt from there. Your first connected server is a good excuse to try it today.