ChampCity GPT MCP Launcher
ChatGPT-compatible MCP server and Electron launcher for controlled local project-file access, providing read-only and approval-gated write tools over STDIO or HTTP with optional OAuth and HTTPS tunneling.
README
ChampCity GPT MCP Launcher
ChampCity GPT MCP Launcher is a pre-release ChatGPT-compatible MCP server and Electron launcher for controlled local project-file access. It can expose read-only and approval-gated write tools over local STDIO or local HTTP, with optional OAuth and HTTPS tunneling for ChatGPT.com-compatible MCP connectors.
Current maturity: v0.1.0, pre-release/private-tooling quality. Review the code and security model before using it with sensitive repositories.
License: not yet selected. See docs/LICENSE_DECISION_NEEDED.md.
What It Does
- Lists, reads, and searches files inside configured allowed roots.
- Reports git status and git diffs for allowed git worktrees.
- Supports write modes:
off,docs,patch, andelevated. - Provides an Electron launcher for local setup, status checks, OAuth administration, and client config generation.
- Supports local STDIO MCP for trusted local clients.
- Supports local Streamable HTTP MCP on
127.0.0.1. - Supports OAuth metadata, Dynamic Client Registration, PKCE, access tokens, refresh token rotation, and scopes for ChatGPT.com-compatible public HTTPS endpoints.
- Includes optional Cloudflare Tunnel docs and examples.
What It Does Not Do
- It does not make hosted ChatGPT local-only; file contents returned by tools can enter the model/tool context.
- It does not safely expose arbitrary folders. You must configure narrow allowed roots.
- It does not require Cloudflare or any specific domain.
https://mcp.example.com/mcpis only a placeholder. - It does not enable writes by default.
- It does not replace human review. Review generated patches and git diffs before committing.
Security Model
Filesystem access is limited to configured allowed roots. Use project-level roots such as:
C:\Users\<you>\Projects\<project>
Avoid broad roots such as C:\, C:\Users\<you>, home directories, cloud sync roots, browser profile folders, SSH folders, and credential stores.
HTTP mode should bind to 127.0.0.1 by default. ChatGPT.com compatibility requires an HTTPS-reachable endpoint with OAuth and Dynamic Client Registration. For public use, set:
CHAMPCITY_GPT_PUBLIC_BASE_URL=https://mcp.example.com
OAuth scopes:
files.read: list/read/search files, git status/diff, write-access status, and tool discovery.files.write: propose patches, write Markdown artifacts, apply approved patches, and run allowlisted scripts, still gated by local write mode.
Never expose unauthenticated HTTP mode through a tunnel.
Write Modes
off: default. Blocks write tools.docs: allows Markdown artifact writes for planning or notes.patch: allows proposed patch workflows and approved patch application.elevated: allows rare allowlisted script/elevated operations with a local approval token.
Set the mode with:
$env:CHAMPCITY_GPT_WRITE_MODE='off'
Local Configuration
On first launch, the Electron app opens a setup wizard where each user chooses allowed roots, local-only or public endpoint mode, OAuth admin password, optional Cloudflare guidance, and write mode. Write mode defaults to off, and the OAuth admin password is stored only as a local hash.
For source development, you can still copy example config files and create repo-local versions as needed:
Copy-Item config\allowed-roots.example.json config\allowed-roots.local.json
Copy-Item config\write-access.example.json config\write-access.local.json
Local files matching config/*.local.json are ignored by git. Do not commit OAuth stores, auth tokens, local paths, tunnel credentials, logs, generated configs, release outputs, or .env files.
Useful examples:
- config/allowed-roots.example.json
- config/write-access.example.json
- config/http-auth.example.json
- config/oauth.example.json
- examples/cloudflared-config.example.yml
- examples/mcp-client-config.example.json
Development
Requirements:
- Node.js
>=20.10.0 - npm
Install, build, and test:
npm install
npm run build
npm test
npm run typecheck
npm run lint
Public clone/build flow:
git clone https://github.com/<owner>/<repo>.git
cd <repo>
npm install
npm run build
npm test
npm run app:dist
Run the local MCP server after building:
node dist\src\index.js
Run the Electron app:
npm run app:dev
Package the Electron app:
npm run app:dist
Release binaries belong in GitHub Releases, not in the repository.
Runtime Paths
Development mode uses the source checkout and can use repo-local config/*.local.json for development.
Installed mode stores runtime-local files under Electron userData:
configlogsgenerated
Portable mode activates when a data folder exists next to the executable:
<exeDir>\data\config<exeDir>\data\logs<exeDir>\data\generated
The app status panel shows runtime mode, config directory, logs directory, generated directory, and bundled server resource path.
ChatGPT-Compatible HTTPS Endpoint
For ChatGPT.com-compatible MCP registration, use an HTTPS endpoint like:
https://mcp.example.com/mcp
The server exposes OAuth metadata under:
https://mcp.example.com/.well-known/oauth-protected-resource
https://mcp.example.com/.well-known/oauth-authorization-server
https://mcp.example.com/oauth/register
https://mcp.example.com/oauth/authorize
https://mcp.example.com/oauth/token
Cloudflare Tunnel is optional. Any equivalent HTTPS reverse tunnel can work if OAuth remains enabled and the local service is still bound narrowly.
Publication Safety
Before publishing, run the release and publication checklists:
Do not publish until the license, GitHub owner/repo, and release-binary policy are decided.
Final local checks:
npm run check:public
npm run app:dist
npm run check:release
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.