Local
Setup
Provision the OpenAI Secure MCP Tunnel, create a least-privilege runtime key, run zodex local setup, and add the tunnel to ChatGPT.
Local connects ChatGPT through the OpenAI Secure MCP Tunnel. You do not need a Sprite proxy, Cloudflare Worker, public inbound port, or separate proxy URL for Local.
This guide takes a new Apple Silicon Mac from “Zodex is installed” to “ChatGPT can call the three Zodex tools through an OpenAI Secure MCP Tunnel.”
For the shorter path, start with Local.
OpenAI references: Secure MCP Tunnel and developer mode / MCP apps in ChatGPT.
Before you start
You need:
- an Apple Silicon Mac;
- the Zodex operator CLI;
- an OpenAI Platform account/organization that can create or access Secure MCP Tunnels;
- a ChatGPT workspace/account with developer-mode custom MCP access;
- permission to associate the tunnel with the ChatGPT workspace that will use it.
OpenAI Platform tunnel permissions and ChatGPT developer-mode permissions are separate. Being able to create a tunnel does not automatically give you permission to add it as a ChatGPT app, and vice versa.
Install the operator CLI
curl -fsSL https://zodex.ashray.xyz/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"
Verify:
zodex --help
zodex local --help
The normal non-root install uses ~/.local/bin; add the PATH line above to your shell profile to keep it available in new terminals. An explicitly root-run install uses /usr/local/bin instead.
The Local runtime is part of the zodex operator binary. You do not install a separate zodexd service on the Mac.
Create the tunnel in OpenAI Platform
Go to:
https://platform.openai.com/settings/organization/tunnels
Sign in with the same OpenAI account/email you use for ChatGPT. For a personal account, use its personal Platform organization. For a workspace account, make sure the tunnel is associated with the ChatGPT workspace that should use Zodex.
In Platform tunnel settings:
- select the intended Platform organization;
- create a new tunnel;
- associate the tunnel with the target ChatGPT workspace where applicable;
- copy the generated
tunnel_id.
The ID looks like:
tunnel_0123456789abcdef0123456789abcdef
Permissions while creating the tunnel
OpenAI’s current permission model distinguishes administration from runtime use:
- Tunnels Read + Manage — create, edit, or delete a tunnel;
- Tunnels Read + Use — run a tunnel client or select the tunnel when creating an app.
Tunnel permissions are organization-level Platform permissions rather than ordinary project-level model/API permissions.
You may need Read + Manage while provisioning the tunnel. The runtime key you give to Zodex should use the narrower Read + Use permission.
Create a least-privilege runtime API key
Create a scoped Platform API key for the runtime and grant only:
Tunnels: Read
Tunnels: Use
The runtime key does not need Tunnels Manage and does not need an OpenAI admin key.
Copy the key when OpenAI shows it. You will enter it into zodex local setup once; Zodex stores it in macOS Keychain.
Run zodex local setup
Interactive setup is recommended for a person at the terminal:
zodex local setup
You will be prompted for:
- tunnel ID;
- tunnel runtime API key.
On success, Zodex:
- validates that the runtime key can read the selected tunnel;
- stores the runtime key in macOS Keychain;
- downloads and checksum-verifies the supported OpenAI tunnel client bundle;
- saves the non-secret tunnel configuration;
- creates the automatically managed Local observability credential;
- enables and opens the lightweight Zodex menu bar app so it returns at future logins;
- exits without leaving the Local runtime or tunnel running.
Setup is idempotent, so running it again is also the repair/update path.
The menu app is only a control surface. Enabling it at login does not start Zodex Local, the tunnel, or any Agent process. If you do not want the menu app, opt out during setup:
zodex local setup --no-menu-bar
If you enable it initially and change your mind later, turn off Launch at Login from the Zodex menu. Choosing Quit exits it for the current login session without changing the Zodex Local runtime.
Scripted setup without putting the key on argv
Read the key from stdin
printf '%s\n' "$OPENAI_TUNNEL_RUNTIME_KEY" \
| zodex local setup \
--tunnel-id tunnel_<id> \
--runtime-key-stdin
Read the key from an environment variable
zodex local setup \
--tunnel-id tunnel_<id> \
--runtime-key-env OPENAI_TUNNEL_RUNTIME_KEY
Read the key from an open file descriptor
zodex local setup \
--tunnel-id tunnel_<id> \
--runtime-key-fd <FD>
The secret itself is deliberately not a CLI argument.
Rotate the Local observer credential
This is rarely needed:
zodex local setup --rotate-observability-bearer
Zodex manages that credential automatically; normal users never need to copy it into ChatGPT.
Start Local
From the repository you want ChatGPT to begin with:
cd ~/code/my-project
zodex local start
Or:
zodex local start ~/code/my-project --ttl 4h
Success means Zodex has started the Mac runtime and the managed OpenAI tunnel and reached its readiness checks.
Check it with:
zodex local status
Enable developer mode in ChatGPT
OpenAI’s UI can change, so use the path shown in your current ChatGPT settings.
Current OpenAI guidance uses Settings → Apps and developer mode / custom apps. Most OpenAI paid plans support custom MCP servers.
Create the Zodex app in ChatGPT
With Local running:
- open ChatGPT on the web;
- go to Settings → Apps → Create or the developer-mode Plugins page;
- create a new developer-mode app;
- choose Tunnel under Connection;
- select the tunnel from the list, or paste the
tunnel_...ID; - scan the tools;
- create/save the app.
The tool scan should show exactly:
exec_command
write_stdin
apply_patch
If you see a lifecycle, history, GitHub, tunnel, or configuration tool, you are not looking at the intended Zodex MCP surface.
Test the connection
Open a fresh chat, select the Zodex app, and try a harmless inspection prompt such as:
Inspect the repository Zodex Local started from and tell me the current branch and worktree status.
The Local runtime tells ChatGPT the start directory as suggested workdir guidance. The actual command tool call still supplies an explicit absolute workdir.
Then inspect the activity locally:
zodex local watch
or:
zodex local history --last 20
If the tunnel is not listed in ChatGPT
Check these separately:
- Platform organization — you created the tunnel in the expected organization.
- Tunnel association — the target ChatGPT workspace is associated with the tunnel.
- Tunnel permissions — the app creator/runtime identity has Tunnels Read + Use.
- ChatGPT developer mode — the target account has permission to create/use custom apps.
- Local runtime —
zodex local statussays the tunnel is ready.
If the tunnel belongs to a different Platform organization or ChatGPT workspace than the one you are using, it may not appear in ChatGPT. Check the tunnel’s organization/workspace association first.
macOS privacy is separate from tunnel setup
Tunnel setup does not grant filesystem privacy permissions. Local commands run as your user, but macOS can still protect Desktop, Documents, Downloads, iCloud Drive, other-app data, removable volumes, and similar resources.
If a command receives a macOS permission error, use normal System Settings → Privacy & Security controls. Do not disable or bypass TCC.