ChatGPT no longer has to be asked before it looks at your data. OpenAI’s developer documentation describes a new feature called MCP Events, which lets ChatGPT sign up for alerts from a connected app and act on them when they land.
MCP, Anthropic’s protocol for connecting models to outside tools, has so far worked on a request-and-response basis. The user asks, the model calls a tool, the answer comes back. MCP Events adds a second direction. An app announces that something changed, and ChatGPT picks it up inside the chat where the user set up the watch.
OpenAI’s own examples show the idea. One example has a user telling ChatGPT to keep an eye on a team’s product-feedback channel and, whenever a bug report shows up, prepare a draft code change that includes a fix and tests. Another user could ask it to watch a shared document and apply the edits reviewers request. In both cases the user names what to watch and what to do, and the trigger is a specific event type, such as a new message or a new comment, narrowed by a filter like a channel or document ID.
The mechanics are more demanding for developers than for users. According to OpenAI’s docs, a server must speak MCP 2.0 (protocol version 2026-07-28), keep subscriptions in persistent storage, and be able to reach callback addresses over HTTPS. ChatGPT hands the server a callback URL and a signing secret when it subscribes. The server first proves the address is live by answering a one-time challenge, then sends each event as a signed webhook. The docs tell developers to block private and local network addresses and refuse redirects, a sign that OpenAI expects attackers to try pointing callbacks at internal systems.
Subscriptions expire. The server grants a lifetime, and ChatGPT renews before it runs out. Each event must carry a unique ID that stays the same across retries, and OpenAI warns that delivery order is not guaranteed, so any tool the model calls in response should be safe to run twice. Payloads are capped at 256 KiB, and the docs advise sending a summary with a separate read tool for large records.
The limits are worth noting. ChatGPT supports only webhook delivery. It does not support polling, streaming, or two of the control notifications in the draft MCP Events specification, which is still a draft. Replay is optional too: for event types without it, the server returns no cursor, and OpenAI states that anything missed during an outage is gone, because the protocol offers no way to fetch it later.
The security guidance carries its own warning. OpenAI tells developers to treat comments and other user-written text in an event as data and not to embed instructions to the model in the payload. That matters because the feature’s headline use case is a model reading a stranger’s comment and then editing code. It also tells developers to test for feedback loops, where an action the model takes creates a new event that triggers the action again.
The page carries no publication date, no launch pricing, and no customer names. OpenAI does not say which plans get the feature or when it reaches everyone, so this reads as a developer specification rather than a finished consumer rollout.
For teams that ship an MCP server, the cost of entry is now concrete: event definitions, signed delivery, subscription storage, and idempotent write tools. Those who already run webhooks for Slack or GitHub integrations have most of the plumbing, and they are the ones best placed to appear on ChatGPT’s plugin page first.
Reported from OpenAI’s developer documentation, which carries no publication date.