ChatGPT
ChatGPT connects over OAuth in developer mode, from OpenAI's cloud, so the server must be public over HTTPS.
Add the app
- In ChatGPT open Settings, Apps and connectors, Advanced, and turn on Developer mode.
- Create a connector. Name
Nexara, MCP server URLhttps://dev.nexara.ac/mcp, authentication OAuth. - ChatGPT registers itself (
POST /oauth/register) with the callbackhttps://chatgpt.com/connector_platform_oauth_redirectand opens the Nexara consent page. Pick Spaces and a ceiling (up toconfidential) and approve.
To pin the connector to one workspace, use https://dev.nexara.ac/w/<workspace>/mcp as the URL; the token is then bound to that URL only.
Status in 0.1.0
- Works through dynamic client registration and PKCE. The authorization response carries
iss(RFC 9207), andclient_id_metadata_document_supportedis advertised. - Deep Research and company knowledge work through the
searchandfetchtools, which follow OpenAI's compatibility schema.searchtakes onequerystring and returns{results: [{id, title, url}]}, one result per Page.fetchtakes oneidfrom those results and returns{id, title, text, url, metadata}. Both are read-only, declare anoutputSchema, and obey the same grants, ceiling, redaction and audit ascontext_searchandcontext_get. - Every
urlis the absolute web link to the Page (https://dev.nexara.ac/n/<id>), so ChatGPT can cite it and you can open it in the Nexara app. - In developer-mode chat ChatGPT can also call every
context_*tool directly. Per-toolsecuritySchemesare not shipped yet. - OAuth access tokens work on MCP only;
/api/v1refuses them. Use an agent key for REST. - Tool names are underscore-only (
context_bundle), which is what OpenAI function names require.
Verify
- Ask ChatGPT to "call context_whoami on Nexara". The connector shows up on the Agents page with its grants.
- Deep Research: start a Deep Research run with the Nexara connector selected and ask about something you know is in the vault. ChatGPT calls
search, thenfetchon the hits. The answer cites Nexara Pages, and each citation opens the Page at/n/<id>. The reads appear on the Audit page assearchandnode.readevents for the connector. - Redaction check: ask about a Page that has a block above the connector's ceiling. The fetched text shows
[REDACTED: <level>, ask owner]in its place.