ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do
ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do On October 1, 2026, OpenAI's Codex lead Tibo Sottiaux said you can build and deploy MCP servers right through ChatGPT — then restrict access or
ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do
On October 1, 2026, OpenAI's Codex lead Tibo Sottiaux said you can build and deploy MCP servers right through ChatGPT — then restrict access or share them. Plugins lead Max Stoiber confirmed: ChatGPT Sites can host MCP servers, including plugin extensions. By October 3, "Sites in ChatGPT" was front-paged on Hacker News (~209 points, 218 comments).
The hosting how-to is well covered. The missing question: every MCP tool call an agent makes is a small authorization decision — and Sites just removed the hosting tax that kept the callable-tool count low.
Prompt-built servers × paid MCP tools (Cloudflare's Monetization Gateway went closed beta Sept 30 — sellers can charge for MCP tools via x402) × write tools = an authorization problem, not a hosting problem.
The tool-call gate
Install-time review dies when a prompt and a Plus plan ships a server. The authorization has to live at the call:
| Call | Gate band |
|---|---|
| Free read-only tool on a private owner-only Site | ≥0.80 → auto-call |
| Paid tool (0.10 USDC/invocation) inside a 5 USDC task budget, unreviewed server | 0.50–0.79 → human confirm |
| Write tool on a shared/unreviewed server | <0.50 → block, log, escalate |
The hosting tax was never the real tax. The judgment tax is.
Two live gate receipts (Oct 3, 2026)
Scored against the live endpoint POST https://scriptmasterlabs.com/api/harness/decide (local-heuristic-v1, bands 0.80/0.50):
- Unreviewed paid Sites-hosted tool, 0.10 USDC/invocation, 5 USDC task budget → 0.4045, escalate, block + log
- Free read-only
list_todos, owner-approved task, private owner-only Site → 0.4132, escalate, block + log
Honest finding: the uncalibrated heuristic can't discriminate the free read from the unreviewed paid call — the fail-closed ceiling is the protection. Eighth consecutive run with this finding. "Block everything" is a seatbelt, not judgment; production needs a calibrated decider.
5 steps: gate the tools, not just the install
- Keep every new Site private until the tool list is boring — 3 or fewer least-privilege tools, save first, deploy only when boring.
- Score the call, not just the server — bands ≥0.80 / 0.50–0.79 / <0.50 at the tool-call boundary.
- Per-task budget envelopes for paid tools — 0.10 USDC × 100 calls = 10 USDC. Price is a fact; the envelope is the judgment.
- Log instruction, authority, intent, outcome for every paid/write call (the FTC's Sept 30 rogue-agent probe demands exactly this).
- Don't outsource judgment to ChatGPT's permission settings — they're UX, not an authorization layer.
Full receipts, the gate table, Claim Receipts and FAQ schema: https://scriptmasterlabs.com/chatgpt-sites-hosted-mcp-servers
Built by ScriptMasterLabs — the x402/MCP/AI pedia. SDVOSB.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.