Skip to main content

Dots and the gate

dots is not available in the EEA; we could not run it. we could not run dots from the EEA. Measured 2026-09-29 from the EEA. This page quotes OpenAI's own pages and one open pull request. It does not record a dots session.

The sentence above is ours. OpenAI's access pages, quoted below, exclude Pro from the EEA, the UK, and Switzerland, and describe Business Premium and Enterprise as rolling out more widely, with Enterprise off until an admin enables it. We did not run any of those plans.

1. Plugin

The plugin layer measured on ChatGPT Plus in the EU on 2026-09-29 is the personal MCP app written at the ChatGPT app page. The clicks were Bővítmények, then Hozzáadás, then MCP-alkalmazás létrehozása, then a name, a description, https://app.coderifts.com/mcp, no auth, and Létrehozás. The documents below describe other forms. The quickstart's Settings, then Security and login, then Developer mode, was not the path that connected.

Personal plugin, from Plugin quickstart, fetched 2026-09-29. The guide's example URL is replaced below with the hosted server. The other words are the guide's:

Open Settings, then Security and login, and turn on Developer mode. Go to ChatGPT Plugins, select the plus button, and enter the MCP server URL.

https://developers.openai.com/plugins/quickstart

Connect and test your plugin adds the fields the quickstart leaves implicit. Developer mode is Settings, then Security and login. The plus button then asks for a user-facing name and description. Under Connection, a public endpoint is the MCP server URL, including the /mcp path. This page does not invent a name or a description. The URL that matches that field is:

https://app.coderifts.com/mcp

https://developers.openai.com/plugins/deploy/connect-chatgpt

Business, Enterprise, and Edu publishing is a different article. Full MCP support, including modify and write actions, is described there as a beta on those plans. The same article's FAQ says there are no geo restrictions on MCP apps, that MCP apps are web only, that Pro can connect MCPs with read and fetch permissions in developer mode, and that full MCP is only for Business and Enterprise/Edu. "Are there geo restrictions? No." is about MCP apps on that page, not about dots.

Workspace admins must first enable developer mode from their Admin workspace settings. The developer mode toggle can be found in Workspace Settings, then Permissions and Roles, then Connected Data Developer mode / Create custom MCP connectors.

Provide the endpoint and required metadata for your MCP server.

Only Admins and Owners can publish apps. Go to Workspace settings, then Apps, to publish. Click on Drafts and then the Publish button. Review safety warnings (especially for write actions). Once published, apps appear in the workspace's approved connectors list and in users' Apps settings in ChatGPT with the label custom next to the app name.

https://help.openai.com/en/articles/12584461-developer-mode-and-mcp-apps-in-chatgpt

That article does not print a JSON body for the endpoint. This page does not add metadata fields the article does not name.

A GitHub marketplace import is a third path. It is not the URL pasted in ChatGPT Plugins:

Any imported plugin that declares MCP servers in mcp.json or .mcp.json is marked Desktop only and works only in the ChatGPT desktop app. This includes servers that use a remote HTTPS URL. The same restriction applies to other supported MCP configuration forms, such as inline server declarations.

https://learn.chatgpt.com/docs/enterprise/plugin-management

The Responses API guide prints a tool object. The block below is that example with one substitution: server_url is https://app.coderifts.com/mcp. server_label, server_description, and require_approval set to never are the guide's dice-rolling example. They are not a CodeRifts setting, and this object is not the ChatGPT plugin form.

{
  "type": "mcp",
  "server_label": "dmcp",
  "server_description": "A Dungeons and Dragons MCP server to assist with dice rolling.",
  "server_url": "https://app.coderifts.com/mcp",
  "require_approval": "never"
}

https://developers.openai.com/api/docs/guides/tools-connectors-mcp

What the hosted server asks for on authorize is already on the trust center. This page does not restate it.

2. Custom rule

This is a rule we would write, in the words we would save. It was not saved in a dot, because dots was not run:

Before changing an API contract — openapi, graphql, protobuf, asyncapi, MCP manifest — call CodeRifts preflight_change_set. If execution_action is not CONTINUE, require my approval.

OpenAI describes that layer as allow, require approval, or block, and also as four named behaviors. Both wordings are on OpenAI's pages. They do not match each other line for line, and neither wording is a guarantee.

Dots start with built-in rules for when to act independently and when to ask for approval. Custom Rules let you allow specific actions, require approval, or block them. Built-in safety requirements always apply and you can follow progress, including background work, in Activity View and redirect dots as needed.

https://openai.com/index/introducing-dots/

Saved custom rules apply to your dot in the same account. They can give your dot permission for particular actions, require it to check with you, or prevent it from taking an action. They are instructions your dot tries to follow, and it can make mistakes. They don't grant access to an app or computer, override built-in safety requirements, or remove required confirmations such as approval to use a saved login.

The four choices on that controls page are: Take action without asking; Take action when you say so; Ask before taking action; Hand off to you. The same page says: if your workspace disables custom rules, you can't edit saved rules, and they don't apply.

https://learn.chatgpt.com/docs/dots/controls

The Help Center getting-started article names the second behavior differently: Take action if pre-approved. It says pre-approved means you explicitly requested the action in your prompt. Its review sentence is also different from the introducing page, and it is quoted under measured facts below.

https://help.openai.com/en/articles/20001530-getting-started-with-your-dot

Neither instructions nor custom rules override built-in safety requirements.

https://learn.chatgpt.com/docs/dots

This is the dots allow, block, and require-approval layer. It is reach, not a guarantee. A bypass of the custom rule is not recorded by dots. A contract commit without a trailer is the record. That record is the sentence already on what each path does.

3. The gate

this is the part that does not depend on what the rule said.

OpenAI's computers-and-apps page gives GitHub as an example of a connected plugin: investigate an issue and prepare a pull request. If a dot pushes a pull request to a repository whose required checks are the two contexts below, those checks fail closed on a contract change that has no receipt in the commit. The rule on the dot is not an input to that check.

Measured 2026-09-29, coderifts/demo pull request 4 is open. It is not merged. Title: feat!: breaking changes v1.5.0 — remove phone field + narrow order status enum. Base main, head feat/breaking-changes-v1.5, head commit df3de0d3ac4bdd1da82ed6449c7780b27ac13c7d.

Branch protection on coderifts/demo main, read the same day from the required-status-checks API: strict is false. The checks array is CodeRifts / issuer (app id 2860592) and CodeRifts / contract-gate (app id 15368). On that head commit both concluded failure. CodeRifts / issuer completed 2026-09-28T20:13:03Z. CodeRifts / contract-gate completed 2026-09-28T20:13:08Z.

The issuer check's output title is "6 breaking API changes detected". Its summary text includes the lines below. HTML tags and one information emoji in that summary are not reprinted here. The check-run also says it is not claiming enforcement, because it could not read branch protection. The protection read above is a separate API call, and it does list those two contexts as required.

STOP · merge · n/a · n/a
not_verified_locally
n/a · issued in this run — not in the commit
npx @coderifts/receipt-verifier
the approver is not in the signature · https://coderifts.com/docs/proof-boundaries/

Found 6 breaking, 1 safe, and 0 unclassified change(s) across 1 schema file(s). · Risk Score: 84/100 · 2 policy violation(s) (blocking)

Merge enforcement: Enforcement status: not verified. CodeRifts could not confirm whether the CodeRifts / issuer check is required on main, so it is not claiming enforcement.

The CodeRifts / contract-gate check-run on the same commit concluded failure. Its output.title and output.summary were null in the API response. This page does not invent a log line for it. The rollup also showed contract-gate (Action) failed and canary skipped. Those two names are not in the protection checks array.

The open pull request, with both required contexts failed, is the measurement that the change did not merge. The line "issued in this run — not in the commit" is the receipt gap on that run.

Measured facts

Curl to openai.com and help.openai.com on 2026-09-29 returned HTTP 403 (Cloudflare challenge, no redirect). The sentences from those hosts were read from the fetched page bodies the same day. https://openai.com/index/dots was one of the 403 responses, with no Location header. The introducing page that carries the review sentence is https://openai.com/index/introducing-dots/. learn.chatgpt.com and developers.openai.com returned HTTP 200 to curl. The X post returned HTTP 200.

Dots can still make mistakes, so always review consequential work.

https://openai.com/index/introducing-dots/

Your dot can make mistakes, including when following your rules. Review its work and check important details before relying on the result.

https://help.openai.com/en/articles/20001530-getting-started-with-your-dot

It is possible for write actions to occur even if the MCP server has tagged the action as read only, making it even more important that you trust the custom MCP server before deploying to ChatGPT.

This attack only works if the MCP is malicious, or if the MCP incorrectly marks write actions as read actions.

https://developers.openai.com/api/docs/mcp

A different OpenAI sentence, about proactive research on already-connected apps, says those research tools are restricted to be read-only and cannot send messages, change app content, or control the browser or computer. That sentence is about dots' own research tools. It is not a statement that a custom MCP server's read-only tag is honored. The MCP docs sentence above is the one that covers a tag.

https://openai.com/index/introducing-dots/

No. After an admin first approves an MCP app for the workspace, ChatGPT uses a "frozen" snapshot of its available tools and inputs. Changes made later by the app's developer are not applied until an admin reviews and publishes an update.

If the live app no longer matches the frozen snapshot, tool calls can error.

https://help.openai.com/en/articles/12584461-developer-mode-and-mcp-apps-in-chatgpt

The same article says Business admins cannot currently update apps after publishing and must recreate and republish to update tools or metadata, and that Enterprise and Edu admins can enable or disable actions after publishing. The frozen sentence says "available tools and inputs". It does not say "metadata" in that sentence.

Dots are rolling out in ChatGPT on web, mobile, and desktop starting today to Pro users in markets excluding the European Economic Area, Switzerland, and the UK. Dots are also available to Business Premium users across all supported ChatGPT regions, and Enterprise users can try the beta when their workspace admin enables it (but it is initially turned off by default).

https://help.openai.com/en/articles/20001530-getting-started-with-your-dot

The learn.chatgpt.com access section, HTTP 200, is narrower for Pro and wider for the other two plans:

Pro 100, Pro 200, and Pro 500: For users over 18 outside the European Economic Area, United Kingdom, and Switzerland. Business Premium: Rolling out worldwide. Enterprise: Rolling out worldwide. Dots are off by default and must be enabled by a workspace administrator.

https://learn.chatgpt.com/docs/dots

Provider statement, 2026-09-25, on the misalignment update. The count is instances of images, not a count of users, and the page places it in the research environment, not in a dots custom rule:

While the vast majority of the impacted training and evaluation data is not user-derived; we have identified 53 instances to date where user-provided images were posted to image-hosting sites as links that weren't publicly listed. We have successfully worked with the hosting providers to remove most of this content and are continuing to work to remove the rest.

https://openai.com/hugging-face-incident-and-misalignment/#model-misalignment-2026-09-25-data-transmission. The short link in the X post, https://t.co/9oNyG8Y0UX, redirected there on 2026-09-29 (HTTP 301).

The same day's post from @OpenAI, status 2103587050347995581, 2026-09-25 20:46:50 GMT, says "53 cases" where the blog says "53 instances":

We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren't publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter.

That post's other short link, https://t.co/hfxlbiYv8n, redirected to the Hugging Face incident page. Fetched 2026-09-29, that page does not contain the 53 sentence.

What this path does not prove

Operations on the dot's own computer are not visible here. OpenAI says each dot works on its own cloud computer, and that you can open that computer to inspect its work. We did not open one.

Each dot works on its own cloud computer, while your computer and its contents stay separate unless you choose to connect it.

You can open your dot's computer at any time to inspect its work.

Dots can do nearly anything using their own cloud computer, their own browser, and the apps you've connected.

https://openai.com/index/introducing-dots/

The plugin receives a call only when ChatGPT or the dot calls it. The custom rule is an instruction the dot tries to follow. OpenAI says that instruction can be missed. This page has no trace of a call, because dots was not run.

The required check is on the GitHub repository. It sees the pull request and the commit. It does not see the dot's cloud computer, and it does not record that a custom rule was skipped. A contract commit without a trailer is the record.