Documentation

ChatGPT connector

Connect BlackOps Center to ChatGPT through a dedicated, curated tool surface: no generic executor, explicit safety hints on every tool, drafts-only writes.

OpenAI's plugin guidelines rule out exposing BlackOps' usual tool-surface gateway (describe_tools / use_tool) to a ChatGPT connector: a generic "look up and call anything" tool isn't allowed, and every tool needs its safety hints stated outright rather than implied by its name. So ChatGPT gets its own connector URL, with its own small, individually reviewed tool list — not the default or full surface described in Tool surfaces.

Connector URL

https://mcp.blackopscenter.com/chatgpt

This path always serves the ChatGPT surface — there's no ?surface= parameter to set, because a published ChatGPT connector URL can't easily be edited later. Add it as a custom connector the same way you'd add the main /mcp URL; authentication is the same OAuth flow.

What's on this surface

About 27 tools, covering four jobs:

  • Ask or search the brain — search, fetch, list_brains, get_brain, get_note, list_notes, get_recent_notes, get_daily_feed
  • Capture — post_notes, update_brain, drop_comms, queue_daily_item, ingest_capture, get_capture_session
  • Draft and review content — get_brand_voice, get_ai_context, post_posts, get_posts, get_post, patch_posts_by_id, post_tweets, create_review_session, get_review_feedback
  • Sorties (the escape hatch) — list_sorties, fire_sortie
  • Account and context — get_me, get_account_context

Nothing else is reachable from this connection — not through a gateway, not by name. If a tool you need isn't listed here, use the main connector or the app instead.

Server-side guardrails

These are enforced in BlackOps itself, not left to the model to self-police:

  • post_posts always creates a draft. Any status you pass is ignored and forced to "draft".
  • patch_posts_by_id refuses to edit a published post, and can't publish one either. Editing a post that's already live is refused outright; on any other post, status and published_at are silently dropped from the patch before it's sent, so a patch_posts_by_id call can never be the thing that makes a post public — not by editing a live post, and not by flipping a draft's status in the same call.
  • fire_sortie only fires a Sortie explicitly marked for it. Mark a Sortie with available_in_chatgpt: true (via create_sortie / patch_sortie on the main connector) to allow it; anything else is refused before the webhook is called.
  • Responses drop internal bookkeeping fields — workspace_id, idempotency_key, source_item_id — that a ChatGPT connector has no use for and OpenAI's guidelines ask not to return.

Nothing on this connection publishes, schedules, or sends anything public. Every write is a draft or a private note; publishing stays a decision you make in the app.

Never a dead end

Every guardrail above answers, it doesn't just refuse. When a request can't go through on this connection, the response says what didn't happen and why, and gives you a working link to finish it:

  • Asking to publish a post returns the draft plus a link to review and publish it in the BlackOps app.
  • Editing a post that's already live returns a link to make the change in the app instead.
  • Firing a Sortie that isn't marked available in ChatGPT returns a link to Settings → Sorties, where you can flip that flag.

Each of these also points at the full BlackOps connector (for Claude Code, Cursor, and other MCP clients), which has the complete toolset with none of this surface's restrictions — see Tool surfaces. For anything heavier that isn't on this surface at all — rendering a video, pulling a GA4 report, long research — list_sorties and fire_sortie are the escape hatch: fire a Sortie you've already wired up, or set one up in Settings → Sorties.

Related

Want this page as machine-readable markdown? GET /docs/mcp/chatgpt.md