Making private MCP servers reachable without making them public
Blog post from OpenAI
Secure MCP Tunnel offers a solution for connecting private MCP servers to OpenAI products without exposing them to public internet traffic, thereby maintaining privacy and security. This approach is particularly beneficial for enterprise environments where creating public endpoints, deploying additional proxies, or introducing new network operators is undesirable. The system uses a small, open-source client run by customers within their own private networks to establish outbound HTTPS connections to OpenAI, enabling normal MCP request and response flows without compromising the server's network boundary. Secure MCP Tunnel is designed around principles like outbound-only connectivity and explicit destination configuration, ensuring compatibility with MCP streaming and notifications while allowing teams to inspect and operate the client independently. This setup not only preserves the privacy and security of the servers but also simplifies integration with OpenAI products by treating the client as a developer tool rather than a network project. Additionally, the tunnel supports enterprise authentication mechanisms and extends its model to approved REST targets through a feature called Harpoon, allowing controlled access to customer-private APIs without opening them to public networks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 46 | 7,755 | 862 | 214 | 0% |
| Kubernetes | 2 | 2,083 | 321 | 111 | +3% |
| Real-time | 2 | 6,055 | 1,444 | 270 | -11% |
| Developer Experience | 1 | 430 | 253 | 101 | -17% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.