RCE
RCE exposes the current project to ChatGPT through an OAuth-protected MCP server.
RCE exposes fast local coding tools backed by Pi, persistent process controls through Herdr, direct batched reads, and Codex-format patching shortcuts.
What RCE exposes
| Area | RCE tools | Purpose |
|---|---|---|
| Pi coding tools | ls, find, grep, write, bash | Fast direct filesystem, search, write, and shell operations. |
| Pi skills | list_skills, load_skill | Discover and load local Agent Skills without routing through Codex. |
| Direct files | read_many, apply_patch | Read files in batches and apply structured Codex-format patches. |
| Persistent processes | process_start, process_read, process_wait, process_send, process_info, process_stop | Run and control persistent or interactive commands through Herdr. |
Requirements
- Node.js
>=24.0.0 - A public HTTPS origin that forwards to the local RCE port
- A ChatGPT plan and workspace that support the MCP actions you need
- Herdr for persistent process tools, recommended
[!IMPORTANT] ChatGPT cannot connect directly to a local MCP server. Give RCE a stable public HTTPS origin before you create the ChatGPT app.
Install
Install RCE globally with npm:
npm install -g rce-mcp
cd ~/code/my-project
rce
Or run it with npx:
cd ~/code/my-project
npx rce-mcp
RCE fixes the current directory as the workspace root for that process.
The default local MCP endpoint is:
http://127.0.0.1:6767/mcp
RCE binds only to loopback.
Add Herdr process control
Install Herdr if you want persistent interactive process control:
brew install herdr
Other install methods are in the Herdr install guide.
RCE detects the herdr CLI at startup. When Herdr is available, RCE registers the process_* tools.
These tools use dedicated Herdr panes for long-running or interactive commands. They can read terminal output, send input, and wait for output. They can also inspect foreground process state and close the process pane.
Without Herdr, the Pi-backed tools, read_many, and apply_patch still work.
Create a stable HTTPS endpoint
A stable hostname keeps the ChatGPT app configuration unchanged between RCE sessions.
Cloudflare Tunnel
Cloudflare recommends remotely managed tunnels for most use cases. They support stable public hostnames and keep tunnel configuration in Cloudflare.
-
Open the Cloudflare Tunnels dashboard and create a tunnel.
-
Name the tunnel, for example
rce. -
Select your operating system and run the generated
cloudflaredinstall command. -
Wait until Cloudflare shows the connector as healthy.
-
Add a Published application route.
-
Set a public hostname, for example
rce.example.com. -
Set the service URL to
http://localhost:6767. -
Save the route.
See the Cloudflare Tunnel setup guide for the current dashboard flow.
Save the public origin in RCE:
rce config set port 6767
rce config set origin https://rce.example.com
The public MCP endpoint is then:
https://rce.example.com/mcp
[!TIP] Run
cloudflaredas a system service if you want the tunnel to survive terminal restarts.
Tailscale Funnel
Tailscale Funnel is a quick alternative when you already use Tailscale.
Expose the RCE port:
tailscale funnel --bg 6767
Tailscale prints a public HTTPS URL similar to:
https://my-machine.example.ts.net
Save that origin in RCE:
rce config set port 6767
rce config set origin https://my-machine.example.ts.net
Reset Funnel when you no longer want the public route:
tailscale funnel reset
Both tunnel options publish an HTTPS endpoint to the Internet. RCE still requires OAuth before MCP tools can run.
Configure RCE
Run setup from the project that ChatGPT should control:
cd ~/code/my-project
rce init
RCE asks for two values:
Local port: 6767
Public origin: https://rce.example.com
RCE stores these values in the OS-native user config directory. It does not load project .env files.
Start RCE after setup:
rce
Each launch prints an approval code. Keep that terminal visible while you connect ChatGPT.
Use local defaults without interactive setup:
rce --yes
Override saved configuration for one run:
rce --origin https://rce.example.com
rce --port 7000
RCE_ORIGIN and PORT also override saved values for one run.
Configuration precedence is:
CLI flags > RCE_ORIGIN/PORT > saved config > defaults
Manage saved configuration with:
rce config get
rce config set origin https://rce.example.com
rce config set port 6767
rce config unset origin
rce config reset
Connect ChatGPT
ChatGPT calls custom MCP integrations apps.
[!NOTE] MCP write and modify actions depend on current ChatGPT plan and workspace support. Check the OpenAI developer mode guide before setup.
-
Open ChatGPT on the web.
-
Enable Developer mode for your account or workspace.
-
Open Settings → Apps → Create.
-
Enter a name such as
RCE. -
Set the MCP endpoint to
https://rce.example.com/mcp. -
Select OAuth authentication.
-
Select Scan Tools.
-
Complete the OAuth flow in the browser.
-
Compare the browser approval code with the code printed by RCE.
-
Approve only when both codes match.
-
Wait for the tool scan to finish, then select Create.
Open a new chat and select RCE from the tools menu. You can also mention RCE when a message needs project access.
If your ChatGPT client exposes tool permissions, you can allow RCE actions there. Grant only the access level you want RCE to have.
Workspace and authorization model
RCE resolves the current working directory at startup and uses its canonical path as the initial workspace root. The model can change the active workspace at runtime with the set_root tool; relative paths passed to that tool resolve from the current root.
RCE stores its OAuth database and signing secret in the OS-native user config directory, alongside config.json. Access and refresh tokens survive process restarts; refresh tokens expire after 30 days. The database and secret are restricted to the current OS user. Keep this directory private; removing the auth files requires connecting again. Each launch still creates a new approval code for new connections.
A stable public hostname keeps the ChatGPT app endpoint unchanged between RCE sessions.
The two configuration values have separate roles:
originis the public HTTPS origin used by OAuth and MCP clients.portis the local loopback port where RCE listens.
RCE supports MCP 2026-07-28, CIMD, S256 PKCE, the mcp:tools scope, and offline_access refresh tokens.
Development
Install dependencies and check the project:
bun install
bun run check-types
bun run --filter '*' test
bun run build
The publishable npm workspace is apps/server. Its executable builds to apps/server/dist/index.mjs.
Inspect the package before release:
cd apps/server
npm pack --dry-run