Connect your gateway to OpenAI MCP

Set up the gateway connection, add it to your AI workspace and read a first measurement. Configuration takes place in the gateway dashboard and your OpenAI environment.

Prepare the gateway and workspace

  1. Use gateway software that includes OpenAI MCP, with permission to change its configuration.
  2. Allow outbound HTTPS from the gateway to api.openai.com on port 443. The connection is disabled until you configure and enable it.
  3. Arrange tunnel permissions in the intended OpenAI Platform organisation and developer-mode access in the ChatGPT workspace.

The Platform organisation owns the tunnel; the ChatGPT workspace controls who can use its private app. Associate the tunnel with the workspace that needs access.

The gateway manages its connection through the dashboard. Its internal endpoint path is not a public server URL.

Create the tunnel and runtime key

  1. Open OpenAI Platform tunnel settings in the organisation that will own the connection. Create a tunnel and associate it with the intended ChatGPT workspace.
  2. Create a restricted runtime API key with Tunnels Read and Use. Creating or editing the tunnel itself requires the separate Tunnels Read and Manage permissions.
  3. Keep the tunnel ID and runtime key ready for the gateway setup. Enter the key only in the gateway’s API key field.

The tunnel ID identifies the connection. The runtime key authenticates the gateway’s outbound traffic. Keep the key out of prompts, shared reports and screenshots.

Connect from the gateway dashboard

  1. Open OpenAI MCP in the gateway dashboard and add a connection.
  2. Enter the Tunnel ID and restricted API key. Advanced settings contain the local connection name and endpoint path; keep each connection’s identity distinct.
  3. Enable the MCP bridge and select Save changes. Refresh the status until the saved connection is ready.
Tunnel ID
The connection created in OpenAI Platform.
API key
Your restricted runtime key, with Tunnels Read and Use.
Advanced settings
A distinct local connection name and endpoint path.

The gateway supports up to five independently configured connections. The API key is write-only: the dashboard never returns the saved secret. Leaving an existing key unchanged retains it; entering a new key replaces it.

If the dashboard says environment configuration is active, saving transfers ownership to its persistent configuration. The two sources are not merged; coordinate that change with the installation administrator.

Add the private workspace app

  1. Open the developer-mode app flow in the authorised ChatGPT workspace and choose Tunnel as the connection.
  2. Select the configured tunnel, or enter its ID. For the iQunet bridge, select No Auth: it does not perform a second MCP OAuth exchange. The outbound tunnel remains authenticated by its runtime key.
  3. Create and connect the private app, then start a new ChatGPT or Codex session so it discovers the current tool inventory.

Users allowed to use the same app share the same bridge-level read access. This integration does not assign separate sensor permissions to individual chat users.

OpenAI screen labels and account permissions can change. Use the current official tunnel guide alongside these gateway steps.

Check a real measurement

  1. Ask the assistant to discover the available sensors and measurements. Select a known signal and check its identity, current value, units and timestamps.
  2. Choose a defined period with an explicit time zone when retrieving history. Check result completeness and quality codes before comparing or plotting the returned values.

Calculations, aggregation and reports run in the client environment using the returned samples. The bridge retrieves raw history without server-side aggregation.

Understand what is connected

List the available sensors and measurements on this gateway. Keep their identifiers and units so I can choose the right signals.
Read tools and advanced access

inspect_nodes inspects a bounded part of the OPC UA address space and can include current variable values. Use depth 0 for exact known targets, or start with a shallow depth to discover relevant signals.

read_history retrieves raw historical samples for one to eight selected series. Supply start and end times with a time zone. Point counts, response size and processing limits bound each request; check the returned completion information before drawing conclusions.

opcua_service provides native Read, HistoryRead, Browse and BrowseNext operations. It uses the same read-only service boundary.

Tool discovery follows the negotiated MCP protocol. Newer clients receive guidance and capabilities as protocol metadata; compatible earlier clients also expose get_capabilities and get_agent_guide.

Maintain the connection

  1. If a request fails, refresh the gateway status. Check outbound HTTPS, key permissions, tunnel ownership, workspace association and the app’s selected tunnel. Start a new client session after a tool update.
  2. To rotate a key, create a replacement with the required restricted permissions, save it to the existing connection and verify readiness before revoking the old key.
  3. Disable the bridge to stop its tunnel runtime while retaining configuration. To remove access permanently, also remove the workspace app and binding and revoke the runtime key.

Deleting the workspace app alone does not revoke the runtime credential.

Ready to work with the data

Explore questions, comparisons and reporting workflows for your installation.

Questions you can ask
iQunet · Engineering enquiries

Connect your existing equipment

Tell us what you want to measure or connect. Include a device model or interface if known.

About your question

About: Connect your AI workspace

Request type: Connect a device or system
Prefer email or a call?info@iqunet.com+32 52 86 00 25

We use your details to answer this request. Privacy information (new tab)