AI AI Toolkit
AI Newsai-products

ChatGPT 现可直接构建并部署 MCP 服务器

X:Tibo (@thsottiaux)2026-10-01T04:44:34.000Z

Key Highlights

ChatGPT Sites can now host MCP servers. Users can build and deploy an MCP server directly inside ChatGPT, turn it into a plugin, and install it on web, mobile, and desktop. The author added that access can be restricted to specific people or shared publicly with the world. In effect, this lowers the barrier to "making a tool" from writing code to having a conversation, which is a meaningful expansion of who can extend an AI with their own capabilities.

What Happened

MCP, the Model Context Protocol, is the standard interface that lets AI connect to external tools and data sources. Building an MCP server used to mean writing code, standing up a service, and configuring auth yourself. Now ChatGPT turns it into a visual flow: you describe the capability you want, it generates and hosts the server for you, and with one click it becomes an installable plugin. For people without a backend background, this makes "my AI can call my data" an actual reality rather than a roadmap bullet.

Technical Details

Hosting means the server runs on OpenAI's infrastructure, so you do not manage deployment or scaling. Once turned into a plugin and installed across the apps, the AI can invoke your defined tools inside a conversation. Access control comes in two tiers: specific people, suited to internal systems, and public, suited to community sharing. Behind this is OpenAI's step of expanding ChatGPT from a chat box into an application platform, with MCP as the standard part that links internal and external capabilities together cleanly.

Comparison with Competitors

Against Claude's MCP support, ChatGPT's difference here is that it can build and host the server directly rather than only connecting to someone else's. Against no-code automation like Zapier or Make, MCP is more AI-native—tools are discovered and invoked dynamically by the model instead of a fixed pipeline. Against rolling your own API, it removes all the ops. For teams that want to quickly give an AI access to private capability, this is the lowest-friction path on the market today.

Industry Impact and Use Cases

For enterprises, this means internal databases, SaaS tools, and scripts can be quickly wrapped as AI-callable tools without exposing the underlying details to everyone. For individuals, a private MCP server that "checks my calendar" or "reads my notes" no longer requires backend skill. Competition among assistants is shifting from "how strong is the model" to "how much of your world it can connect to," and ChatGPT hosting MCP is a key move to lock the ecosystem onto its own platform before rivals standardize the experience.

Further Analysis

The platform risk in ChatGPT-hosted MCP is real and worth naming: every private tool you expose becomes reachable through OpenAI's runtime, so governance, data residency, and audit trails move from your infrastructure to theirs. Enterprises should treat public MCP servers with the same caution as any third-party integration and keep sensitive systems behind the "specific people" access tier with logging. The upside is speed: a department can ship a useful internal tool in an afternoon without a backlog ticket. The net effect is a faster, more democratic tooling layer riding on top of ChatGPT, with the usual trade of control for convenience that every platform shift demands.

A clean adoption pattern is to start every MCP server in "specific people" mode, log every invocation, and only promote to public after a review confirms no sensitive data can leak through the tool's outputs. Keep the server's granted permissions minimal—read-only where possible, scoped credentials never broad admin—so a compromised plugin has a small blast radius. Treat each MCP server like an internal microservice with an owner and a changelog, because from the model's perspective it is just another callable endpoint and will be used exactly as described. That discipline preserves the speed benefit while keeping the platform-risk side of ChatGPT-hosted MCP from becoming an incident.

Adopt MCP servers in "specific people" mode first, log every invocation, and promote to public only after a review confirms no sensitive data can leak through outputs. Grant minimal permissions—read-only where possible, scoped credentials never broad admin—so a compromised plugin has a small blast radius. Treat each server like an internal microservice with an owner and changelog, because the model will use it exactly as described. That discipline preserves the speed benefit while keeping ChatGPT-hosted MCP from becoming an incident rather than a feature.