ChatGPT MCP connector for a local browser
Connect ChatGPT to an MCP server on your own machine: why a loopback address is out of reach from OpenAI's cloud, and the two ways across.
Last updated
ChatGPT runs in OpenAI's cloud, so it can only reach an MCP server that is reachable from the internet. A daemon on 127.0.0.1 is not, and no setting changes that.
Before you start
Everything below assumes a daemon that is already running and a token to reach it with.
The app starts the daemon for you. The token is the contents of
%LOCALAPPDATA%\Scalebrowser\token, and the address it is listening on is the
native_addr field of %LOCALAPPDATA%\Scalebrowser\runtime.json. That is usually
127.0.0.1:8787, but the app moves up a port when something else already holds it.
scalebrowser-daemon --generate-token prints a token and stores it under
<data_dir>/token. The address is whatever bind_addr says, which is 127.0.0.1:8787
unless you changed it. See Install & run.
The token is a full-power credential. It reaches every profile, every stored session and the whole management API. Treat it like a password: keep it out of a repository, and prefer your client's environment-variable syntax over a literal in a config file that gets committed.
Two ways across, and one of them is ours
ChatGPT fetches a custom connector from OpenAI's own servers, so the endpoint has to be reachable from the internet. Every other client in this section runs on your machine and reaches 127.0.0.1 directly.
| Way | What it means |
|---|---|
| Remote access | Our relay. The browser stays on your machine; only the control channel goes through the cloud, and the daemon's static token deliberately does not work through it. See Remote access. |
| Tunnel your local daemon | A tunnel gives your machine a public HTTPS name. Faster to set up, and it puts a full-power token on an address the whole internet can reach. |
Developer mode does not exist on ChatGPT Plus. Measured on a real Plus account: all seventeen settings tabs checked in two languages, the settings search empty for both "MCP" and "developer". The named tab carries multi-factor, password, security keys, sessions and lockdown, and no developer mode.
Custom connectors need Business, Enterprise or Edu. A customer with one can use remote access; we have simply not seen it ourselves, and this line says so rather than implying otherwise.
Connect it
Developer mode is where custom MCP connectors live, on the web app.
With remote access, add a connector with the address the portal gave you and let the OAuth flow run: no token is typed anywhere. See Remote access for the three steps, one of which is a switch on the machine itself and is the usual reason a connection fails with a message that explains nothing.
With your own server or tunnel, the endpoint is your public address plus /v1/mcp, and the bearer token is its credential.
If you only want an agent to drive a browser on your own machine, one of the local clients is the shorter path: Claude, Cursor, Codex, GitHub Copilot or Antigravity. None of them needs an address that is reachable from outside.
What the agent can do now
Ask it to open a page and it will lease a profile, bind a tab and start reading. The tool set, the page map and the failure shapes are on MCP server; what the agent is allowed to do is decided by the daemon, not by the client, so see tool profiles.
Run it on your own machine
Seven days to try it with your own agents on your own sites. Starting the trial needs a card.