AI agent · ChatGPT

ChatGPT, with every gated call waiting for you.

ChatGPT reaches your services only through PrivacyFence, which reviews reads before release and holds changes for your approval. It works with both deployments: ChatGPT desktop with PrivacyFence on your own computer (local mode), and ChatGPT on the web with PrivacyFence run by your organization (organization mode). Both were checked with a personal ChatGPT plan; Business, Enterprise and Edu workspaces are not verified.

How it connects

The desktop app on your computer, the web app through your organization.

Local mode: ChatGPT desktop

ChatGPT desktop connects to PrivacyFence's /mcp endpoint on localhost as a Streamable HTTP server, with your own token in an Authorization: Bearer header. The token stays the same across restarts, upgrades and reboots. Checked on macOS; the Windows app is not verified, and there is no ChatGPT desktop app for Linux: use Claude Code there.

Organization mode: a Developer Mode app

ChatGPT on the web connects to MCP servers from OpenAI's servers, not from your computer, so it needs a PrivacyFence it can reach over public HTTPS. A PrivacyFence on your own computer listens on localhost only, on purpose. ChatGPT registers itself, and you sign in with your organization account. Access tokens last one hour and are refreshed silently; after 30 days you sign in again.

Set it up

Add a server, or create an app.

Local mode

  1. Install PrivacyFence from the download page.
  2. In PrivacyFence, open Settings → AI clients. Note the MCP URL, normally http://127.0.0.1:8765/mcp, and click Copy token.
  3. In ChatGPT desktop, open Settings → MCP servers → Add server. Name it PrivacyFence, choose Streamable HTTP, enter the MCP URL, and add the header Authorization with Bearer followed by your token.
  4. Save, then turn the server on in a chat.

Organization mode

  1. Your administrator gives you the deployment's URL, for example https://pf.example.com.
  2. In ChatGPT, turn on Developer mode under Settings → Security and login.
  3. Open Settings → Apps → Create. Name it PrivacyFence, enter the MCP Server URL https://pf.example.com/mcp, choose OAuth, and leave the OAuth client ID and secret empty.
  4. Sign in with your organization account when PrivacyFence's sign-in page opens.
  5. Connect your services at https://pf.example.com/connect.

A Developer Mode app is off in every new chat. Turn it on from + → Developer mode → PrivacyFence.

Set it up Local or organization mode?

Confirmations

ChatGPT may ask first. PrivacyFence's card decides.

PrivacyFence tells ChatGPT truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. ChatGPT sorts the tools into Read and Write, and whether it asks you first is decided by ChatGPT's own permission setting.

What we observed on the web, with a personal plan and the setting Allow low-risk tools: ChatGPT did not ask before creating a calendar event. It asked once before an upload and offered to always allow the tool; after that it did not ask again. ChatGPT desktop asked before tools that are not read-only, with an option to always allow them. In every case PrivacyFence's approval card was still shown.

Allowing a tool in ChatGPT only stops ChatGPT's question: a gated call still waits for PrivacyFence's approval card, and that card decides. There is no mode that advertises writes as read-only.

Files

One-time links, with no allowlist to set up.

Local mode. A large file comes back as a one-time link on 127.0.0.1, which ChatGPT desktop fetches itself; ChatGPT asks its own permission before saving to a folder such as ~/Downloads. PrivacyFence runs under its own system account and cannot read your home folder, so a file path for an upload is refused, and ChatGPT sends the file through an upload link instead.

Organization mode. A download of up to about 75 KB comes back in the tool result; a larger one becomes a short-lived, one-time link. ChatGPT's code sandbox fetches that link and sends uploads itself, over public HTTPS, so unlike claude.ai there is no domain list to fill in. Files has the sizes and lifetimes.

To read a document, no download is needed: PrivacyFence returns a PDF, Word, PowerPoint or Excel file from Drive as text.

How it's identified

A name is a claim until an administrator pins it.

Local mode. Every AI client on your computer uses the same credential, so the approval card names the requester Undetected. The audit log records the name ChatGPT desktop gives, codex-mcp-client, which OpenAI's Codex command-line tool gives too, so the two cannot be told apart.

Organization mode. ChatGPT registers with PrivacyFence as ChatGPT, so the approval card says Says it is ChatGPT, marked Not verified, because any program that can reach the deployment can register under the same name. An administrator can pin ChatGPT's registration on Settings → AI systems, for example by matching its last-used time to their own sign-in from ChatGPT, and the cards for it are then verified.

Which AI system is asking

Client settings worth knowing

A few ChatGPT settings to know.

  • Developer Mode is per chat. Turn the app on in each new chat from + → Developer mode → PrivacyFence.
  • Business, Enterprise and Edu workspaces. An administrator may have to allow Developer Mode first. These workspaces have not been verified.
  • Rotating the token. After Rotate token on Settings → AI clients, paste the new token into ChatGPT desktop.
  • Deployments that accept only known addresses. They must accept the address ranges OpenAI publishes for ChatGPT's connectors. File links are fetched from ChatGPT's code sandbox, which may use other addresses.

Next

Other clients, and what they can reach.

Compare the AI clients PrivacyFence is tested with, or see what each connector lets them read and change.