ChatGPT app (custom MCP)
Measured 2026-09-29, ChatGPT Plus, in the EU. A personal MCP app connected to https://app.coderifts.com/mcp with no authentication. One analyze call came back. No receipt was issued.
analyze and verify need no key; authorize needs a key and the ChatGPT app supports no-auth or OAuth 2.1 only — so a personal app reports, it does not issue receipts.
The four clicks
The account UI was Hungarian. These are the labels that were clicked, in order. The session connected.
- Bővítmények
- Hozzáadás
- MCP-alkalmazás létrehozása
- A name, a description, the URL
https://app.coderifts.com/mcp, authentication left at no auth, then Létrehozás
OpenAI's plugin quickstart, fetched the same day, describes a different path: open Settings, then Security and login, and turn on Developer mode, then go to ChatGPT Plugins and enter the MCP server URL. That Settings path was not the path that connected. The four labels above were.
https://developers.openai.com/plugins/quickstart
The card
After it connected, the app card showed these lines. The words are the card's, including the Hungarian labels.
- Webhely: Nem elérhető
- Verzió 1.0.0
- Kategória Other
- Fejlesztő App developer
The same evening, POST https://app.coderifts.com/mcp method initialize returned serverInfo.name CodeRifts API Governance, serverInfo.version 1.0.3, and no website field. The card's version 1.0.0 is not that initialize version. The card's website line is not a read of a websiteUrl the server did not send. The MCP schema names the field websiteUrl on Implementation (schema 2025-11-25 and 2026-07-28). It does not name website. OpenAI's plugin submission object names interface.websiteURL, which is a listing field, not the initialize result. This page does not claim the card reads either one. The card was read before any local change to serverInfo.
Three tools
The session recognized three tools. The hosted server's default tools/list is preflight_change_set, verify_receipt, and get_decision_details. This page does not have a copy of the three names as the ChatGPT UI printed them. The count is the session. The names are the server's list.
The trial
The prompt asked for an analyze of a change that deletes name on GET /pets. The result was BREAKS_DETECTED, may_execute false, authorization_effect NONE, receipt_kind NONE.
Who can see it
a personal app is visible only to you; a workspace admin can publish it to the organisation; public listing needs OAuth 2.1 and OpenAI review — not done.
The app from this session lives on the Personal tab (Személyes). It was not published to a workspace. It was not submitted to OpenAI.
Dots, the custom rule, and the required check on a pull request are a different page: dots and the gate.
What this page does not prove
The analyze result does not prove a receipt. receipt_kind was NONE and may_execute was false. Authorize was not called. A personal app on no-auth cannot call it: the form offers no-auth or OAuth 2.1, and authorize needs a key.
The Personal tab does not prove a workspace can see the app, and it does not prove a public listing. Neither publication was done.
The card does not prove what initialize returns. Live initialize the same evening returned version 1.0.3 and no website field. The card showed version 1.0.0 and website unavailable.
The quickstart's Settings path does not prove where Developer mode sits in ChatGPT Plus in the EU. The session used the four labels above.
Recognizing three tools does not prove those tools were authorized, and it does not prove a dot called them. Dots was not run. That limit is on dots and the gate.
The generated platform truth table does not list this path. The row would have to be added in the app generator that writes that table. It was not added. The classification on this page is the sentence in the box at the top: a personal app reports, it does not issue receipts.