explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR
  • What you are actually building
  • Before you type the prompt
  • How to create the Site-hosted MCP
  • What to put in the first server (and what not to)
  • Limits the film will skip
  • How this compares to hosting it yourself
  • Checklist you can run today
  • Related reading
← Back to blog

explainx / blog

How to Host an MCP Server on ChatGPT Sites

ChatGPT Sites, MCP, OpenAI Plugins, How-to, Agent Tools

ChatGPT Sites can now host MCP servers and plugin extensions. Here is the prompt, the save-then-deploy path, who can see it, and what is still not documented.

Oct 1, 2026·9 min read·Yash Thakker
add explainx.ai
go deep
How to Host an MCP Server on ChatGPT Sites

MCP's tax was never the spec. It was the host: a box that stays up, speaks Streamable HTTP, and is not your laptop.

On October 1, 2026, OpenAI staff said that tax now has a ChatGPT-native answer. Codex lead Tibo Sottiaux wrote that you can build and deploy MCP servers right through ChatGPT, then restrict access or share them. Plugins lead Max Stoiber said ChatGPT Sites can host MCP servers, including plugin extensions — answering a builder who asked whether OpenAI-hosted infrastructure would ever cover plugin backends.

This post is a how-to from that claim plus the Sites and plugin MCP docs. It is not a second copy of the MCP architecture guide. If the Sites page still talks about websites and D1 while the staff posts talk about MCP, believe the staff for what shipped and the docs for how Sites already save, deploy, and share.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

TL;DR

table · 2 cols
QuestionAnswer
What changed?Sites can host an MCP server and wrap it as a plugin
Starter promptCreate a todo list I can use in ChatGPT (mention Sites)
What that doesMCP + extensions → deploy on Sites → plugin
Share how?Sites audience: you, invited people, workspace, or public
Directory listing?Separate. Sharing a Site ≠ passing plugin review
Need a VPS?Not for a Sites-runtime demo. Yes for unsupported backends
PlansSites beta: Plus, Pro, Business, Enterprise, Edu
Save vs deploySave a version first. Every deploy URL is production

What you are actually building

Three objects get conflated in the replies. Keep them apart.

table · 2 cols
ObjectJob
SiteOpenAI-hosted runtime. Save, deploy, analytics, sharing. Docs: learn.chatgpt.com/docs/sites
MCP serverTools ChatGPT can call. ChatGPT wants remote Streamable HTTP, usually at /mcp, not local stdio
PluginPackage ChatGPT/Codex install: skills, MCP, optional extensions (sidebar, panels, file viewers)

Stoiber's sequence is those three in one prompt:

  1. Create an MCP server with extensions
  2. Deploy that server to Sites
  3. Turn the server into a plugin

That is the opposite of the old path: write a server, find HTTPS, paste /mcp into developer mode, then file a directory submission. Plugin architecture still says you can run the server on infrastructure you operate. Sites is the new default when you do not want to.

Connected-data Sites (a workspace-private Site that reads each visitor's plugins) were already in the Sites guide. Hosting the MCP itself is the October 1 piece. Do not collapse them.

Before you type the prompt

  1. Confirm Sites. Plus / Pro / Business / Enterprise / Edu. Open chatgpt.com/sites or More → Sites. If the list is missing, you are on the wrong plan or the wrong workspace.
  2. Start private. A new Site is limited to the owner and workspace admins until you change access. Leave it there while you review tools.
  3. Decide the data plane. A todo list can live in Sites D1. A tool that hits your ERP still needs a reachable API and secrets in Site settings, not in the prompt.
  4. Decide the audience. Owner-only, invited emails, workspace, or anyone on the internet. Public publishing can be off in Enterprise. That setting is visitor access, not editor access.
  5. Do not promise directory fame. Replies already include a two-week plugin rejection. Sites hosting does not erase review.

How to create the Site-hosted MCP

1. Start the Sites workflow

Official Sites docs: include the word website or mention Sites so ChatGPT enters the hosting flow. Stoiber's example is the product-shaped version of that:

text
@Sites create a todo list that I can use in ChatGPT

If @Sites does not trigger it, be boring and explicit:

text
Use ChatGPT Sites. Create a todo list I can use as an MCP server inside ChatGPT.
Add plugin extensions so I can open the list beside a conversation.
Save a version first. Do not deploy until I say so.
Keep access limited to me. Use durable storage so tasks survive reloads.

Akshay Saini's teaching example is the better second prompt once the first one works:

text
@Sites create a shared project tracker for three students.
Each student uses a separate ChatGPT chat.
One set of tasks. When one student marks an item done, the others see it.
Keep the Site private to invited emails. Turn it into a plugin I can install.

That is the moment MCP stops being abstract: someone else's write shows up in your chat.

2. Review the plan the way you would review Compose

Ask for a readable inventory before deploy:

text
List the MCP tools, who can call writes, where tasks are stored,
whether the server is Streamable HTTP, and the URL path.
Do not deploy yet.

You want:

  • A short tool list (list_todos, add_todo, complete_todo) — not a god-mode run_sql
  • Writes that need a confirmation or an explicit user action
  • Storage you asked for (D1), not a mystery
  • A path that looks like /mcp if this will ever leave ChatGPT

Sites still has two stages. Save a version builds a candidate. Deploy publishes a production URL. Ask to save first. Every Sites deploy URL is live for the current audience.

3. Deploy when the tool list is boring

text
Deploy the saved version. Give me the production URL and how to
install or enable the plugin in a new ChatGPT chat.

Then open a new chat. Plugins and skills often only appear after a fresh session. Ask: "Add milk to the todo list" and "What is still open?" If it cannot write, the plugin is UI without a server.

4. Restrict or share

Tibo's line maps onto the Sites sharing model already documented:

table · 2 cols
AudienceUse when
Owner + adminsDefault. Keep it here until tools are least-privilege
Invited emailsNamed classmates or teammates; they sign in as that account
WorkspaceInternal tracker; not the internet
Anyone on the internetOnly if public publishing is on and you reviewed the tools

Invite path (docs): Share → Only those invited → email → Viewer. Viewers are not editors. Editors are a workspace feature: they can save and publish after the owner's first publish, and they can read live database data. Do not make a stranger an editor of an MCP that can write.

text
Change this Site's access to only people I invite.
Show me the current URL and the tool list again before you send invites.

A public Site is not the same as a listed plugin. Public means the URL is reachable. The directory is plugin submission: stable HTTPS, Streamable HTTP, auth story. Secure MCP Tunnel is for developer-mode private servers and does not satisfy public submission.

5. Use it as a plugin, not only as a webpage

After deploy, you should have:

  • A Site URL (web UI for humans)
  • An MCP the model can call in ChatGPT
  • Optional extensions (sidebar / conversation panel) if you asked for them

Plugin extensions hook sidebar, composer, file viewers, settings, deep links, rich forms. Web extensions were still rolling to Free/Go at DevDay. Composer mentions are desktop-only. If the panel never appears, you still have tools.

Keep tools useful without the component. That is OpenAI's own rule: headless first.

What to put in the first server (and what not to)

Start with one read and one write. The todo list is the right size.

table · 2 cols
DoDon't
list, add, completeexecute_arbitrary
D1 for tasksSecrets in the prompt
Invite-only until you like the toolsPublic + write tools on day one
Sign in with ChatGPT if records are per-personTrust the browser for auth
Redeploy after changing Site secretsCommit .env into the Site

Identity: public Sites can add Sign in with ChatGPT. Sites forwards oai-authenticated-user-email (and optional full name). Authorize on the server. Workspace-restricted Sites already use ChatGPT identity for sharing.

Writes to connected apps (the older Sites+plugins path) need visitor consent and an explicit click. Your own todo writes still need the same instinct: no silent deletes.

If you outgrow Sites, move to a host you control and keep the same MCP tools. The stateless 2026-07-28 transport is what other clients expect. Pi's MCP + Codemode is a different host, not a Sites feature.

Limits the film will skip

  • Runtime. Sites hosts supported web shapes. Some frameworks, private networks, and background services are unsupported. HTTP, HTTPS, WebSockets yes. Raw TCP no.
  • Storage. D1 cap is 10 GB. R2 has no fixed size in the Sites table. Don't request D1 for a theme toggle.
  • Residency. Sites does not support data or inference residency at launch — including D1, R2, code, artifacts, logs.
  • Policy. No PHI, card data, kids under 13 (or local digital-consent age), financial transactions, malware, phishing.
  • Usage limits. Plan-specific. Hitting a limit can block new Sites, storage, or keeping a hot Site public. You can still edit.
  • Review. Hosting is not approval. Directory rejections still happen.
  • China / geo. Public "share with the world" follows OpenAI availability, not a promise of every country.
  • Docs lag. If chatgpt.com/sites and learn.chatgpt.com/docs/sites omit "MCP server" the week you try this, use the staff prompt anyway and keep a save-only version until the URL and tools look right.

How this compares to hosting it yourself

table · 3 cols
PathYou operateBest for
Sites-hosted MCPPrompt, share settings, Site secretsDemos, class trackers, internal toys
Your /mcp + ChatGPT developer modeProcess, TLS, logsIteration before directory
Directory pluginPublic HTTPS, OAuth, reviewDistribution inside ChatGPT
Claude / Cursor / Pi MCPstdio or your HTTPBuilder hosts that are not ChatGPT

Browse existing servers on explainx.ai at /mcp-servers when you want a known connector instead of a generated todo backend. Skills stay a different layer: what a skill is versus what MCP is. Skill security still applies if the generated plugin pulls in extra packages.

Checklist you can run today

  1. Open Sites. Confirm you can create one.
  2. Paste the long "save first, access limited to me" prompt.
  3. Demand the tool list and storage location.
  4. Save a version. Deploy only after the list is three tools or fewer.
  5. New chat: add one item, list items, complete one.
  6. Invite one person. Confirm they see the write. Confirm a stranger cannot.
  7. Only then consider workspace or public.
  8. If you need the directory, follow Build an MCP server as a second project with a stable /mcp.

Related reading

  • What is MCP? Architecture guide
  • ChatGPT Sites team editing
  • OpenAI DevDay 2026: plugin extensions
  • Sign in with ChatGPT
  • What are agent skills?
  • Pi adds MCP and Codemode
  • MCP 2026-07-28 stateless spec
  • Agent Plugins standard
  • Official: ChatGPT Sites
  • Official: Build an MCP server for plugins
  • Official: Plugin extensions

The October 1, 2026 hosting claim is from OpenAI staff posts (Sottiaux, Stoiber). Save/deploy, sharing, D1/R2, and plan availability follow the public Sites guide as of that day. Plugin transport and directory rules follow developers.openai.com. If the Sites UI and the staff posts disagree on a button name, trust what you see in chatgpt.com/sites and keep the first version private.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Aug 31, 2026

Sodium WebMCP: Turn Website Features Into Agent Tools

Savio Martin's Sodium project (sodium.result.dev) auto-exposes website features as WebMCP tools so browser agents invoke real product actions instead of scraping the DOM. explainx.ai explains the stack, limits, and how it relates to OpenAI's WebMCP Challenge.

Oct 1, 2026

Pi Adds MCP — Earendil Reverses "No MCP" With Codemode

Pi.dev used to advertise that it did not support MCP. On September 29, 2026 Earendil shipped MCP in core, wired through Codemode, so agents can compose MCP tools in a harness-side JavaScript sandbox instead of dumping every tool into context. Here is what changed and what to do if you picked Pi for the old "skills + CLI" rule.

Sep 30, 2026

Hugging Face: MCP Agents Must Verify the Source, Not Just the Fact

On September 29, 2026, Hugging Face published Multiverse Computing’s ProvenanceGuard write-up: source-aware verification for Model Context Protocol agents. The failure is not a made-up fact. It is a true fact assigned to the wrong tool output. This post is the practitioner checklist for traces, pooling, and release gates.