Guide
How to connect an existing MCP server to a ChatGPT app
Inspect an HTTPS MCP server, explicitly test selected tools and create a reviewed app draft while keeping upstream credentials in DraftYourApp.
Reuse the tools you already maintain
Model Context Protocol (MCP) servers describe tools and their input/output contracts. If your service already exposes MCP, rebuilding those tools in a second format adds another contract to maintain. DraftYourApp can inspect an existing server and preserve selected descriptors in a reviewed draft.
A useful first task might be finding an order and showing its status. Choose the smallest set of tools needed to complete that task. The review flow supports one to three tested tools, rather than importing an entire server indiscriminately.
Prepare the supported connection
- Use a public HTTPS Streamable HTTP endpoint. HTTP URLs, embedded credentials, query strings and fragments are rejected.
- Provide an optional bearer token if the server requires it. Upstream OAuth and individual visitor authorization are separate capabilities; do not assume bearer support provides them.
- Choose tools you are authorized to expose to app visitors and prepare synthetic or otherwise authorized test arguments.
Inspection negotiates with the server and lists tools. It does not call tools or read resources. Negotiation may create a temporary remote session, so discovery still involves contacting the server.
Inspect, explicitly test, then review
- Inspect the endpoint and read the original server identity, tool descriptions, schemas and annotations.
- Select a tool and supply JSON arguments. Explicitly confirm the remote test; it may modify real data.
- Review successful tests, describe the task and select one to three tested tools.
- Name the project and confirm that app visitors may execute those tools through the connection before creating the draft.
For bearer-protected servers, the flow requests the credential again at the required steps. Successful test receipts are short-lived. If descriptors change or a receipt expires, inspect and test again rather than treating an earlier screenshot as proof.
What happens to credentials after deployment?
Persisted connection credentials are encrypted in DraftYourApp. New reviewed-MCP deployments delegate through the builder using a private app-bound grant; the upstream bearer is not copied into generated source files. The executor checks the current connection and reviewed contract before calling the server.
Deleting or deactivating the connection blocks subsequent calls through that executor. It cannot undo an operation already admitted or in flight. Older deployments that copied credentials require rebuilding or retirement; the newer boundary does not retrofit old bundles.
Troubleshoot contract drift before changing the UI
If a server changes a tool schema or descriptor after inspection, the review or execution can reject the stale contract. Reinspect the server, check the changed inputs and repeat explicit tests. Do not solve a contract mismatch by changing only the label on a button.
After drafting, add an interface only where it helps the task, then preview it locally and test the deployed endpoint in the intended host. A reviewed draft is a starting point for that verification.