Before you start
- A paid ChatGPT plan that offers Developer mode. It is what lets ChatGPT call a server of your own. Step 3 turns it on.
- A public HTTPS address on port 443, already set up. ChatGPT connects from OpenAI’s cloud on
port 443 only. It cannot reach
localhostor your private Tailscale network. Nothing on the internet can reach Postern until you set this up, and it is off by default: Set up remote access — Tailscale plus Funnel, about 20 minutes, once. - Postern running, and the Console at http://localhost:8787. Everything on this side happens at Agents & keys.
- Your password manager open. Postern shows the key once. ChatGPT asks for it at the end of the sign-in, in another window, after step 2 has replaced it on your clipboard.
Create a key that expires, and save it
Open the Console at http://localhost:8787. Go to Agents & keys and press
Mint a key.In Name, type
chatgpt. That name is what the record prints under Who.Under Grant which sectors, tick each sector ChatGPT may reach. The six toggles read Finance,
Mail, Calendar, Contacts, Health and Home. A grant covers read and act across
every provider in the sector, and only Home has anything to act on today —
what a grant covers. A key with no sectors
ticked still connects, and Postern then denies every read.Under Expires, press 30 days, 60 days or 90 days. Do not press Never: the
sign-in in step 5 refuses a key that never expires. Once you save an address, the form starts on
90 days and prints This gate is published. A key you paste into a hosted client should expire.Press Mint the key. A screen opens headed chatgpt is ready, with the key under
Agent key — shown once. Press the Copy beside it, then paste and save it in your password
manager.Copy the address ChatGPT connects to
On that same screen, follow Connect a hosted client (claude.ai, ChatGPT) →. From anywhere else:
Agents & keys → Set up the bridge →. Both open Connect claude.ai or ChatGPT.If your address works for ChatGPT, that page prints it under Paste this into claude.ai or
ChatGPT. Press Copy there. It ends in
/mcp, which the Console adds itself —
the endpoint:No Copy button, and the pattern
https://your-mac.tailnet.ts.net/mcp in place of your address?
One sentence on that page says which of five things is true.Turn on Developer mode in ChatGPT
Open ChatGPT’s settings, then Plugins. Scroll to the bottom of that list, past Browse
plugins, and press Developer mode.ChatGPT moves you to Security and login, and the address ends
#settings/Security?section=developer-mode. The Developer mode row there carries a red
⊘ ELEVATED RISK badge and the line Allows you to add unverified connectors that could modify
or erase data permanently. Use at your own risk.That badge is correct. Developer mode is what lets ChatGPT call a server you point it at, rather
than one OpenAI reviewed. Turn Developer mode on.No menu in ChatGPT says Connectors. The settings rail says Plugins, ChatGPT’s banner says
Apps, and the addresses still say Connectors. Three names, one thing. Go by the rail.The run behind this page met that screen with Developer mode already on. Nobody wrote down
the switch’s own name, or what it reads afterwards. Go by the row’s name.
Create the plugin and point it at your address
Open
chatgpt.com/plugins. The page carries the heading Plugins — Work with ChatGPT across your
favorite tools. Press the + button, top right. The New Plugin form opens.- Name — type
Postern. Its placeholder readsCustom Tool. - Connection — leave the toggle on Server URL, not Tunnel, and paste the address you
copied in step 2. Its placeholder reads
https://example.com/sse. - Authentication — already reads
OAuth. Leave it. - Icon and Description are optional. Skip both.
Allow low-risk. That setting decides when ChatGPT asks you before it uses a plugin, not what
Postern allows. The run behind this page changed nothing there. The address still says Connectors,
as it does everywhere in ChatGPT’s settings.A second tab opens on your own address, served by your own Postern. Step 5 happens in that tab.If no tab opens, your browser blocked it. Allow pop-ups for
chatgpt.com, then press Create
again. You can also close that tab before you approve: press Create again to reopen it.If ChatGPT says instead that it could not reach your server, and nothing appears in your logs:
nothing arrived, so there was nothing to log. Fix the address in step 2, then wait five minutes
before you retry. The Console says the same thing under the address:
If claude.ai or ChatGPT says it can't connect, fix the address, wait five minutes, and try once: a hosted client remembers a failed check for a few minutes.Approve the sign-in on your own machine
Your own Postern serves this tab. It opens blank, then resolves to your own address. It is plain
and unstyled, in a system font on a white background — nothing like the Console. That is normal.It carries the heading Authorize agent access, then two lines. The first is the name ChatGPT
registered with your Postern, followed by
is asking to connect to your gateway. The second reads
Approving sends a sign-in code to, then the address that code goes to, then . If you did not start this from that app, close this page. Postern prints both from what ChatGPT registered.Paste the key from step 1 into Paste an agent key from the Console, then press Approve.The tab goes black with a spinner and returns to ChatGPT. Postern shows no page of its own to say it
worked. ChatGPT confirms instead, with a green message over your plugin’s own page. That page lists
no actions yet. That is what a new plugin shows, not a broken connection.Your browser’s password manager pops over the key field. Dismiss it. It can cover the Approve
button underneath, and the key is not a login.
The page answers
This agent key never expires. Keys used with a cloud client must have an expiry — mint or rotate a key with a 30/90/365-day expiry in the Console, then try again. The key is good;
its lifetime is not. Ignore the 365: the Console offers Never, 30 days, 60 days and
90 days, and nothing else.Rotate it. Console → Agents & keys → chatgpt → Rotate. The form opens headed
Rotate chatgpt. Press 90 days, then Rotate the key, then Copy. Save the new key and
run this step again with it. A rotation keeps the name and the sectors, so you do not tick the
sectors again.Ask ChatGPT something, then read the record
In a chat, attach the plugin you named
Postern. A [P] Postern chip lands in the message field.
Type your question after it.ChatGPT shows plain-English progress, never tool names: Describing the Current Context means
ChatGPT called describe_context. On the Allow low-risk setting from step 4 it asked no
permission per call. A Postern entry in the Sources rail is the sign that a call landed.Confirm it works
chatgpt.com/pluginslists Postern under Personal → Created by me.- Console → The ledger holds a row with
chatgptunder Who. - That row names the tool ChatGPT called under Tool.
- Leave the sector filter alone. The Console says why:
One sector at a time also leaves out every call that belonged to no sector — an agent asking what the gate holds, or a handshake the gate refused. Those are still recorded; they just cannot match a sector. - An empty answer with a row means Postern has no sources yet. No row means nothing arrived.
If something went wrong
What you have now
ChatGPT holds a temporary pass issued by your own machine, never the key itself. It sees exactly the sectors you ticked in step 1, and appears in the record under the name you gave it. Its access ends when the key expires — the OAuth bridge, for hosted agents. Revoke the key and Postern refuses ChatGPT’s next call. Rotate it and its passes die at the same moment — revoking and rotating a key. Three standing costs come with this.- The key now lives on OpenAI’s infrastructure and dies on the date you chose. Postern then refuses ChatGPT’s calls, and to replace the key you work this page again from step 1.
- Your address stays reachable from the internet until you turn it off in Settings → Remote
access. That is also what turns the sign-in off:
Stop publishing and the sign-in disappears — nothing else about this gate changes. - ChatGPT asked no permission per call on the run behind this page, so the sectors you ticked are its whole boundary for as long as the key lives.
Next
ChatGPT can only answer from sources Postern already holds. Pick the one you can finish now.Connect Google and Gmail
your own Google Cloud app and one app password · about 20 minutes · weekly re-consent until you
publish to production
Connect Apple Health
Health Auto Export on your iPhone · about 10 minutes · push, not pull