About this project

tunnel-client is the customer-run agent behind OpenAI's Secure MCP Tunnel. It connects a private or localhost MCP (Model Context Protocol) server to ChatGPT, Codex, the Responses API, and AgentKit through an OpenAI-hosted tunnel endpoint, keeping the MCP server off the public internet. It is designed for scenarios where an OpenAI-hosted product needs to reach an MCP server on a laptop, VM, Kubernetes cluster, or private network, but security policies prevent inbound firewall rules or public endpoints. The daemon exposes operator-visible /healthz, /readyz, /metrics, and /ui endpoints. The tool can be installed via Homebrew (brew install openai/tools/tunnel-client) or built from source using Go. It offers a CLI for onboarding, admin, and profile management (tunnel-client help quickstart), alongside runtime-only flavors (tunnel-client-runtime and tunnel-client-runtime-cloudflared) that expose only the run command for long-lived daemons. The Cloudflare flavor supervises a pinned cloudflared companion for managed provisioning. Developers can embed the client directly in a Go process using the Go SDK and the MCP SDK's in-memory transport, avoiding the need for the MCP server to bind a port or use stdio. The repository includes an embedded demo mode with stateless and stateful MCP handling options. The project emphasizes supply-chain security. Releases include SPDX 2.3 sidecars, SHA256 checksums, Sigstore provenance bundles, vulnerability reports, and enterprise evidence documents. the repository provides scripts to verify release archives, SBOM baselines, and provenance offline. It supports deployment via Docker/Kubernetes images published to ghcr.io/openai/tunnel-client for Linux amd64 and arm64.