Give ChatGPT local coding tools for repos you explicitly allow.
CodexPro is a local MCP server. It connects your ChatGPT session to your machine and repos you allow.
ChatGPT can read, search, edit, review, verify, import attachments, and write handoff plans. It stays inside those roots.
It is not a hosted SaaS product, model proxy, quota bypass, account pool, or remote shell service.
Needs:
- Node.js 20+
- A ChatGPT account that can create custom MCP plugins
- An HTTPS URL to your machine for ChatGPT web (tunnel or Tailscale Funnel)
npm install -g codexpro
cd /path/to/your/repo
codexpro setupSettings -> Security and login→ turn Developer mode on (keep CSP enforcement on).Settings -> Plugins→ Plugins tab → + beside Search plugins.- Create a plugin named
CodexPro. - Connection: Server URL → paste the URL CodexPro copied.
- Authentication: No Authentication / None (change this if the form defaults to OAuth).
CodexPro auth is the token already in that URL. Do not share the URL.
Open Plugins and click + |
Complete the New Plugin form |
|---|---|
![]() |
![]() |
Daily use from the same repo:
codexpro startIf plugin creation fails, run codexpro connection-test and check whether ChatGPT requests reach the local server.
With workspace write mode (the normal agent setup):
- read, search, and inspect the repo
- edit with
write,edit, or guardedapply_patch - import ChatGPT attachments with
import_file - run allowlisted checks with
bash - review diffs with
show_changes - write plans under
.ai-bridge - export a context bundle for chats that cannot call tools
One CodexPro process can allow more than one repo:
codexpro settings set --project ~/code/web --project ~/code/api
codexpro settings show
codexpro startAsk ChatGPT to open_workspace on an allowed project. open_current_workspace returns to the launch repo.
For two ChatGPT accounts or hard isolation, run two CodexPro processes on different ports and Server URLs.
codexpro setup
codexpro start
codexpro start --root /path/to/repo
codexpro doctor
codexpro connection-test
codexpro settings
codexpro inspect
codexpro reviewUseful modes:
codexpro start --no-bash
codexpro start --tool-mode minimal
codexpro start --tool-mode full
codexpro start --mode handoff
codexpro start --mode pro
codexpro start --headlessOpt-in tool cards:
CODEXPRO_TOOL_CARDS=1 codexpro startChatGPT web needs HTTPS:
codexpro start --tunnel cloudflare # quick demo URL (changes)
codexpro ngrok --hostname your.ngrok-free.dev
codexpro stable --hostname codexpro.example.com --tunnel-name codexpro
codexpro tailscale --hostname your-device.your-tailnet.ts.net
codexpro start --tunnel none # local onlyKeep a stable token for stable hostnames:
mkdir -p ~/.codexpro
openssl rand -hex 32 > ~/.codexpro/http-token
chmod 600 ~/.codexpro/http-tokenPrefer Authorization: Bearer <token> when the client supports headers. The ?codexpro_token= query form is a personal compatibility fallback.
- Public tunnels require a CodexPro HTTP token (min 24 bytes)
- Writes stay hidden unless write mode is
workspace - Safe bash is the default
- Blocked paths cover
.env, keys,.git, build caches, and similar - Attachment import only accepts ChatGPT Apps SDK file objects from approved HTTPS hosts
Read SECURITY.md before exposing a tunnel.
npm install -g codexpro@latest
codexpro --versionRestart codexpro start after updating. Saved profiles under ~/.codexpro stay in place.
npm install
npm run build
npm run smoke
npm run stress
npm run release:checkPublish only from the CodexPro root:
cd /path/to/codexpro
npm run release:publish
