Turn ChatGPT Web into a Local Coding Agent via OpenAI Secure MCP Tunnel

This guide explains how to use OpenAI's Secure MCP Tunnel with WebCodex to run local code operations through ChatGPT's Chat mode without consuming subscription quotas, comparing four MCP integration tools and providing step-by-step setup instructions.

Sohu Tech Products
Sohu Tech Products
Sohu Tech Products
Turn ChatGPT Web into a Local Coding Agent via OpenAI Secure MCP Tunnel

The article addresses a common problem for ChatGPT Plus users: after exhausting Astra (Codex) quota, how to continue working without hitting limits. The author discovers that ChatGPT's Chat mode does not consume subscription quota (no official limit stated), while Work and Codex modes consume local Codex quota. The core idea is to shift tasks normally requiring Work or Codex into Chat mode, then use MCP (Model Context Protocol) to call local tools — achieving top-model capability without quota consumption.

ChatGPT Modes and MCP Architecture

ChatGPT Web has two modes: Chat (quota-free, cannot manipulate local files) and Work (consumes Codex quota, can operate local files). The Codex client adds a third Codex mode designed for coding. Both Work and Codex can operate local files as agents; Chat currently cannot. OpenAI's official Developers handbook documents a Secure MCP Tunnel that solves the connectivity problem: a local tunnel-client initiates an outbound HTTPS connection to OpenAI's hosted tunnel endpoint, polling for MCP requests and forwarding them to the local MCP server. This avoids exposing local ports or 127.0.0.1 publicly. The tunnel works for ChatGPT, Codex, and Responses API.

Four MCP Integration Tools Compared

The author evaluates four existing solutions:

WebCodex : Most complete architecture. ChatGPT connects via MCP to a server; a local Runner handles file I/O, Git, tests, shell, and long tasks. Supports multi-project, multi-device, task state, run logs, human guidance, file transfer, and Computer Use. Desktop app manages tunnel-client via OpenAI Secure Tunnel. Trade-off: complexity (server, runner, project registration, tunnel, tokens, scopes).

DevSpace : Also lets ChatGPT directly operate local projects but with a smaller default toolset ( open_workspace, read, apply_patch, exec_command, write_stdin, show_changes). Naming resembles Codex, easing model understanding. Supports Git worktree, AGENTS.md/CLAUDE.md, local Skills, optional sub-agents. Simpler for single-machine, few-repo Node workflows. Main drawback: no built-in tunnel — users must provision Cloudflare Tunnel, ngrok, Tailscale Funnel, or other HTTPS reverse proxy and handle fixed addresses with OAuth Owner password.

codex-with-chatgpt : Dual-agent pattern. ChatGPT plans (read-only: 9 tools — search, read, git diff, test logs); Codex executes. After Codex finishes, ChatGPT verifies via MCP. Clearest security boundary: each token binds one workspace, sensitive files denied by default, path-escape checks, no write/shell tools in ChatGPT's hands. However, Codex execution quota is still consumed for coding, testing, Git ops.

Mac Developer Bridge : Broadest access — arbitrary shell, file R/W, real PTY, background tasks, historical Codex sessions, logged-in Chrome control via AppleScript/Accessibility. No model calls; ChatGPT reasons. Exceeds coding agent, becoming a full Mac remote-operation layer. Highest risk: no path/command allowlists, sandbox, or per-command approval; MCP client runs with macOS user privileges.

The author chooses WebCodex for long-term coding agent use, noting DevSpace is also viable and may be covered later.

Step-by-Step WebCodex + Secure Tunnel Setup

On platform.openai.com, create a Tunnel (Organization/Workspace defaults).

Create a Runtime API Key for tunnel-client authentication (not for API billing; ChatGPT web conversations remain under ChatGPT plan rules).

Download WebCodex Desktop (macOS: darwin-arm64.dmg or darwin-x64.dmg).

In WebCodex OpenAI Tunnel config, enter Tunnel ID and Runtime API Key, then start. WebCodex Desktop hosts tunnel-client in background on channel=main; no manual tunnel-client run needed.

In ChatGPT Web: Settings → Security and Login → enable Developer mode → Plugins → Create app. Fill: Name WebCodex, Description 访问本机 WebCodex 中已配置的项目, Connection Tunnel, Available tunnels select running nativetunnel (or use Tunnel ID), Authentication No Auth (second-layer auth not needed because tunnel already bound). Confirm risk notice and Create.

Two distinct authentications: (1) API Key in WebCodex/ tunnel-client for local client → OpenAI Secure Tunnel; (2) Authentication field in ChatGPT plugin for ChatGPT → MCP App (set to No Auth).

Full chain:

ChatGPT Web → OpenAI Secure Tunnel → tunnel-client → WebCodex → Local Files / Commands

. ChatGPT never gets direct file permissions; WebCodex executes locally. Desktop must keep

tunnel-client
ready

.

Usage and Model Differences

After config, invoke via @WebCodex or plugin picker. Example: @WebCodex 列一下 Downloads 目录下面有哪些文件. ChatGPT understands natural language; WebCodex calls local tools; actual file access runs on the user's Mac.

Free tier: Chat mode uses GPT-5.6 Luna (free). Plus tier: Chat mode uses GPT-5.6 Sol. Author recommends Plus for Sol access.

Long-Running Project Suitability

In principle, yes — Tunnel ID, channel=main, and local project persist. Code, Git history, test results stay local; ChatGPT can resume next day. However, Chat mode works turn-by-turn with context limits, affected by model availability, plan rules, sleep, network. WebCodex keeps local tasks running, but ChatGPT does not gain Work/Codex /goal long-task mechanism just by adding MCP. OpenAI now offers Long-running work and /goal for multi-hour migrations, refactors, test loops — requires Mac to stay awake. For true multi-hour continuous runs, author still prefers Work or Codex; daily coding, file queries, test runs, iterations go to Chat + WebCodex. This setup makes ChatGPT a recurring local agent, not a free, always-on, unlimited server.

References

OpenAI Secure MCP Tunnel:

https://developers.openai.com/api/docs/guides/secure-mcp-tunnels

Long-running work: https://learn.chatgpt.com/docs/long-running-work?surface=cli WebCodex, DevSpace, codex-with-chatgpt, Mac Developer Bridge (links omitted in source)

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

MCPChatGPTAI coding agentlocal developmentGPT-5.6OpenAI Secure TunnelWebCodex
Sohu Tech Products
Written by

Sohu Tech Products

A knowledge-sharing platform for Sohu's technology products. As a leading Chinese internet brand with media, video, search, and gaming services and over 700 million users, Sohu continuously drives tech innovation and practice. We’ll share practical insights and tech news here.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.