ChatGPT and dots

Connect Deliverd to ChatGPT so a dot asks your organisation's policy before it acts, waits for the right person, and reports what it did.

Dots are ChatGPT agents that keep working on their own and reach other services through ChatGPT's plugins, which run over MCP. Deliverd is an MCP server, so a dot reaches it the way it reaches any plugin, and nothing here depends on an API for dots that OpenAI has not published.

Connect

  1. 1

    Add the connector

    In ChatGPT, Settings → Apps → Advanced settings → Developer mode, then add a custom connector with the address on the ChatGPT page. Custom connectors need a paid ChatGPT plan.

  2. 2

    Sign in

    ChatGPT registers itself and sends you to Deliverd to choose the organisation and approve the permissions it asks for. There is no key to paste.

  3. 3

    Say what needs asking

    Tell your dot which acts to check first — sending reports outside the company, publishing, payments. Your organisation's policy decides the rest.

The plugin package — a portable plugin.json, mcp.json and the approval skill — is published in deliverd-dev/deliverd-skills. Deliverd is not yet listed in ChatGPT's plugin directory; until it is, the custom connector above is how to connect.

What a dot does

ToolWhen
check_gateAsk policy before acting, naming the action, the destination, the data's classification and the artifact's SHA-256.
get_gateWhile a person decides, read the gate back. Act only when canExecute is true.
record_executionAfter acting, report what was done, with the same hash and destination. A mismatch is refused.
get_evidenceThe record: the policy, the approvers and their authority, and the receipt.

A permission covers the artifact and destination it was asked for, for a window and a number of uses set by policy — one unless the policy says otherwise. If the report changes, or the dot wants to send it somewhere else, it asks again. A person can send a request back for changes; the dot revises and asks again, naming the request it replaces.

Sign-in, for the security review

  • OAuth 2.1 authorization code with PKCE (S256 only), and dynamic client registration.
  • Client ID metadata documents: ChatGPT can identify itself by the URL of its own published metadata (https://chatgpt.com/oauth/client.json) instead of registering. Only documents on allow-listed hosts are fetched, and the consent screen says who published the identity.
  • private_key_jwt at the token endpoint: a client that publishes keys signs each token request. The assertion must name the token endpoint, expire within five minutes and is accepted once.
  • A profile tool, get_profile, marked openai/profile: a stable, opaque account id with the person's name and email and the organisation, so ChatGPT can keep two connected accounts apart.
  • Resource indicators (RFC 8707): a token asked for /api/mcp works there and is refused at the REST API.
  • Issuer identification (RFC 9207): every authorization response carries iss, which lets ChatGPT use its stable redirect address.
  • Every tool declares the scope it needs; a missing scope comes back with a challenge ChatGPT turns into a re-consent, not a dead end.
  • Each tool says whether it only reads, changes something, or can reach outside the organisation, so ChatGPT can decide what to confirm with its user.

Submitting the plugin needs the domain verified: OpenAI's form issues a token, which the deployment serves at /.well-known/openai-apps-challenge from the OPENAI_APPS_CHALLENGE setting.