MCP for ChatGPT Plugins: The Architecture Behind Every Plugin
TL;DR: Every ChatGPT plugin that touches live data runs on an MCP server. This guide explains how that server sits in front of your API, what the 2026-07-28 revision of the protocol changed, how OAuth 2.1 and tool annotations fit, and when MCP Events and interface extensions are worth adding.
How does MCP fit into a ChatGPT plugin?
A ChatGPT plugin that reads live data or takes actions does so through an MCP server. The server sits in front of your existing API and exposes a small set of tools, each with a description, an input schema, a structured result and three safety annotations. ChatGPT chooses a tool from its description, your server verifies the user's OAuth 2.1 token, calls your API and returns the result. OpenAI requires a public HTTPS endpoint using Streamable HTTP. HouseofMVPs builds this layer for existing products from $4,999. Book a 30 minute scoping call.
If your plugin does anything with live data, it does it through an MCP server. Skills can carry instructions and interface extensions can draw a panel, but the server is the only part that reaches your product.
This guide is for the engineer or technical founder who has an API and wants to know what has to be built in front of it. If MCP itself is new to you, start with our MCP guide.
The shape of it
Person in ChatGPT
|
ChatGPT picks a tool from its description
|
Your MCP server (public HTTPS, Streamable HTTP)
| verifies the OAuth token, validates input
Your existing API
|
Your database and systems
Three properties matter.
The server is thin. It does not hold business logic. It maps a user goal to one or more API calls and shapes the answer.
The server is the trust boundary. OpenAI's security guidance says to assume prompt injection and malicious input will reach your server, and to validate everything on the server side even when the model supplied it.
The server is public. A submitted plugin needs a stable HTTPS endpoint on your own domain. During development you can use OpenAI's Secure MCP Tunnel or a forwarding service, but neither replaces the public endpoint for submission.
Designing tools
A tool has a name, a description, an input schema and a result. ChatGPT reads the name and description to decide whether to call it, so those two fields are your interface to the model.
What works:
- One goal per tool.
list_overdue_invoicesbeats a genericquerytool. OpenAI's guidelines reject a generic executor that hides operations. - Descriptions that say when not to use the tool. OpenAI's metadata guide recommends opening with when to use it and stating disallowed cases.
- Structured results. Declare an output schema. OpenAI's own submission helper warns on tools without one.
- Minimal data. Return what the request needs. Leave out internal IDs, logs, timestamps and personal data the user did not ask for. Reviewers check this.
What does not work is mirroring your REST API endpoint by endpoint. Twenty tools with overlapping descriptions are hard for a model to choose between and slow to test.
Want this ChatGPT plugin built for you in 14 days to submission?
HouseofMVPs delivers from $4,999 fixed. 50+ shipped. Same team scopes, builds, and supports.
Annotations
Every tool declares three booleans: readOnlyHint, destructiveHint and openWorldHint. OpenAI scans them and compares them with what the tool does. Our submission guide has the table and the usual mistakes.
Annotations tell ChatGPT how carefully to treat a call, including when to ask the person to confirm. They are descriptions, not defences. Your server still has to check permissions on every call.
Authentication
A plugin that works for anyone needs none. Declare those tools as noauth.
A plugin that reads a customer's own data must link their account with OAuth 2.1. OpenAI's requirements, in short:
- Authorization code flow with PKCE using
S256 - Protected resource metadata published at
/.well-known/oauth-protected-resource - Authorization server metadata that advertises PKCE support
- Client registration through Client ID Metadata Documents, which ChatGPT prefers, or Dynamic Client Registration, or a predefined client
- Your server verifies every token itself: signature, issuer, audience, expiry and scopes
ChatGPT does not support client credentials, service accounts or JWT bearer grants for this. If your product only has passwords and API keys, an authorization server has to be added. Auth0, Stytch and similar providers are listed in OpenAI's documentation as options.
You can mix the two. A tool can declare both noauth and oauth2, so people get something useful before they link an account and more after. That lowers the friction that loses people at the first step.
What the 2026-07-28 revision changed
OpenAI's documentation calls this revision MCP 2.0. The MCP project's changelog does not use that name, so cite the date when you need to be exact.
If you built a server against an earlier revision, these are the changes that touch you:
| Change | What to do |
|---|---|
Protocol level sessions and the Mcp-Session-Id header are removed | Stop relying on per connection state. Pass any handle you need as a tool argument |
The initialize handshake is removed. Each request carries its protocol version | Read version and capabilities from request metadata |
server/discover is required | Implement it to advertise versions, capabilities and identity |
| Multi Round Trip Requests replace server initiated requests | Return an input required result and handle the retry |
| The older HTTP+SSE transport is classed as Deprecated | Use Streamable HTTP |
| Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents | Support CIMD. Keep DCR only for older authorization servers |
| Roots, Sampling and Logging are deprecated | Do not add them to new servers |
Stateless requests are good news for hosting. A server with no session state scales horizontally and runs well on serverless platforms.
MCP Events
MCP Events let ChatGPT subscribe to changes in your product and act when they happen: a new ticket, a changed document, a reply in a thread. Your server lists the events it supports, ChatGPT subscribes with a callback URL and a signing secret, and your server posts matching events to that URL.
Before you plan around it, note four things from OpenAI's documentation:
- It follows a draft specification. OpenAI supports webhook delivery and callback verification from that draft, and does not support polling, streaming or two of the draft's control notifications.
- It is available in Work chats on ChatGPT web, in Work chats on desktop with Cloud selected, and with dots.
- Your server needs persistent subscription storage and outbound HTTPS.
- Events can arrive out of order and more than once, so every write tool they trigger must be idempotent.
Add events when a real workflow starts with "when this happens". Do not add them to a first release because they are new.
Interface extensions
Extensions give a plugin its own views inside ChatGPT: a sidebar entry, a panel beside the conversation, file viewers, forms, settings. They are declared in a tool's metadata with an entry point type.
OpenAI's architecture guidance is to use interface elements only when people need to inspect, compare, edit, confirm or navigate structured information, and to keep tools useful without them so the model can finish a task headlessly. We follow the same order: tools first, a view when text is the wrong shape for the result.
Hosting and operations
- Pick the hostname once. Changing scheme, hostname or port means a new plugin.
- Expect daily scans. OpenAI rescans the server and holds changes that fail checks. Keep approved tool schemas working until an update is live.
- Log tool calls, not prompts. OpenAI's guidance is to redact personal data, store correlation IDs and avoid keeping raw prompt text unless you must.
- Return clean errors. OpenAI's authentication guide says to answer an expired or malformed token with a 401 and a
WWW-Authenticatechallenge, so the person can be asked to sign in again. A vague 500 just looks like a broken plugin.
Where to go next
- Decide whether you should build at all: the readiness checker
- Compare a plugin with embedding a model in your own product: ChatGPT plugin vs API integration
- Have it built: ChatGPT plugin development, from $4,999 fixed, submitted for OpenAI review in 14 days
HouseofMVPs is independent of OpenAI. We build to its published documentation, and OpenAI decides what is approved.
Sources and verification
Each claim below was read from the linked page on the date shown. Vendors change their documentation without notice, so check the source before relying on a detail.
| Claim | Source | Source date | Verified |
|---|---|---|---|
| Public HTTPS endpoint, typically /mcp, Streamable HTTP; Secure MCP Tunnel for private testing | OpenAI developer docs, Connect and test your pluginFirst party | Undated | 9 Oct 2026 |
| OAuth 2.1, PKCE S256, CIMD preferred, DCR supported, protected resource metadata, token verification, per tool security schemes, unsupported grant types | OpenAI developer docs, AuthenticationFirst party | Undated | 9 Oct 2026 |
| Stateless protocol, server/discover, MRTR, deprecation of DCR and of HTTP+SSE, removal of sessions | Model Context Protocol, Key Changes for revision 2026-07-28First party | Revision 2026-07-28 | 9 Oct 2026 |
| MCP Events: draft specification, webhook delivery, signing, limits, where it is available, the MCP 2.0 label | OpenAI developer docs, MCP EventsFirst party | Undated | 9 Oct 2026 |
| Annotation rules and data handling rules for tools | OpenAI developer docs, Plugin guidelinesFirst party | Undated | 9 Oct 2026 |
| Ten extension surfaces and how entry points are declared | OpenAI developer docs, Plugin ExtensionsFirst party | Undated | 9 Oct 2026 |
| Choosing use cases and the smallest implementation; prompt injection and confirmation guidance | OpenAI developer docs, Brainstorm plugin use cases; Security and PrivacyFirst party | Undated | 9 Oct 2026 |
HouseofMVPs is an independent development studio. We are not affiliated with, endorsed by or partnered with OpenAI. ChatGPT is a trademark of OpenAI. We build the plugin and prepare the submission. OpenAI controls review, approval, ranking and publication.
Frequently Asked Questions
Frequently Asked Questions
Turn your product into a ChatGPT plugin
Fixed price from $4,999. Built, tested and submitted for OpenAI review in 14 days. OpenAI controls approval.