According to Beating, OpenAI has announced Secure MCP Tunnels, addressing compliance challenges for enterprises integrating private network data with large language models. The solution enables companies to connect internal tools and databases to ChatGPT, Codex, and the Responses API without exposing IP addresses or opening inbound firewall ports.
The tunnel operates through a one-way outbound HTTPS connection via an open-source client tool (tunnel-client) running on the local network. Enterprises retain full control through granular interface whitelisting, preventing models from accessing resources beyond predefined scopes. Permissions integrate with OpenAI's workspace role system and support enterprise-grade outbound proxies, custom CA certificates, and mTLS authentication.