MCP BRIDGE · CLOUDFLARE TUNNEL · CAPABILITY-URL AUTH

网页版 ChatGPT 隔空指挥你电脑上的 Codex 和 Claude CodeWeb ChatGPT remote-controls local Codex & Claude Code

ChatGPT 负责想,你的电脑负责动手。以前你得人肉中转:ChatGPT 里问完方案、复制、粘到终端。这座桥把中转自动化——派活、执行、审查、回传,全程只在 ChatGPT 里打字。 ChatGPT plans, your machine executes. No more copy-pasting between tabs — dispatch, execution, review and results flow back automatically over one encrypted tunnel.

3 角色协作roles 5 个 MCP 工具MCP tools FastMCP Cloudflare Tunnel MIT
01 · DATA FLOW

数据怎么流:一个小团队The data flow — a tiny team

ChatGPT = 项目经理(想方案、派活)|Claude Code = 干活的工程师|Codex = 审查的同事。蓝色向下游派活,绿色原路回传结果。 ChatGPT = PM (plans, dispatches) · Claude Code = engineer (executes) · Codex = reviewer. Blue flows downstream, green flows back.

你 只打一行字 ChatGPT(云端) 负责「想」:规划 · 拆需求 · 派活 开发者模式 → MCP connector Cloudflare Tunnel HTTPS · http2 /mcp/<hex密钥> MCP 桥(你的电脑) app/bridge_server.py · FastMCP 分派任务 · 一套代码 stdio/--http 两用 Claude Code 真改文件 · 真跑命令 Codex 执行 · 代码审查 结果原路返回 · 显示在 ChatGPT 对话里
02 · ROLES & TOOLS

三个角色,五个工具Three roles, five tools

AI强项Strength短板Limitation
ChatGPT(网页版)规划、调研、拆需求Planning, research, task decomposition在云端,碰不到你的电脑Cloud-only — can't touch your machine
Claude Code(本地)真改文件、真跑命令、执行落地Real file edits, real commands规划不如 ChatGPTWeaker at planning
Codex(本地)真改文件、真跑命令、代码审查Real edits, commands, code review规划不如 ChatGPTWeaker at planning
MCP 工具tool作用Purpose
run_codex把任务交给本地 Codex 跑(执行 / 审查)Dispatch a task to local Codex (execute / review)
run_claude_code把任务交给本地 Claude Code 跑(执行落地)Dispatch a task to local Claude Code
read_file / write_file读写 BRIDGE_WORK_ROOT 内的文件Read/write files inside BRIDGE_WORK_ROOT
list_dir列目录,供规划端探索结构List a directory for the planning side
03 · SECURITY

安全警告——务必读完再用Security warning — read before use

⚠ DANGEROUS FLAGS INSIDE

两个执行工具运行时带 --dangerously-bypass-approvals-and-sandbox(Codex)与 --dangerously-skip-permissions(Claude Code)。含义很直接: Both executors run with --dangerously-bypass-approvals-and-sandbox (Codex) and --dangerously-skip-permissions (Claude Code). Meaning: 谁能连到端点,谁就能在你的电脑上跑任意命令、改任意文件。whoever reaches the endpoint can run any command and touch any file on your machine.

  • 🔒 绝不裸奔公网Never expose it raw:至少用 BRIDGE_PATH_SECRET(不可猜密钥 URL),有条件再叠 BRIDGE_TOKEN。: at minimum BRIDGE_PATH_SECRET (an unguessable capability URL), ideally plus BRIDGE_TOKEN.
  • 🚫 绝不分享你的端点地址Never share your endpoint——那等于把你电脑的钥匙发出去。分享请让对方自建。— that's handing over your keys. Share the repo, not the URL.
  • 📁 BRIDGE_WORK_ROOT 把可读写范围锁在一个目录里,别放任整个 $HOME。 confines read/write to one directory — never all of $HOME.
  • 🔐 .env 有密钥,已被 .gitignore 排除——永远不要提交它。 holds secrets and is gitignored — never commit it.

这是个人效率工具,不是多人生产服务。请自担风险。A personal productivity tool, not a multi-user service. Use at your own risk.

04 · QUICK START

五步跑通Five steps to live

STEP 1

克隆 + 装依赖(Python 3.10+,mcp[cli] + uvicorn)Clone + install (Python 3.10+, mcp[cli] + uvicorn)

STEP 2

配置 .env:生成纯 hex 的 BRIDGE_PATH_SECRET;CODEX_BIN/CLAUDE_BIN 指向真身二进制(shell 里的 codex/claude 常是函数包装,用 which 找真身)Configure .env: pure-hex BRIDGE_PATH_SECRET; point CODEX_BIN/CLAUDE_BIN at the real binaries (shell wrappers won't work)

STEP 3

起 server:python -m app.bridge_server --http(监听 127.0.0.1:8000)Start the server: python -m app.bridge_server --http (127.0.0.1:8000)

STEP 4

起隧道:cloudflared tunnel --protocol http2 --url http://localhost:8000(http2 是必须的,默认 QUIC 过夜会失活)Start the tunnel with --protocol http2 (QUIC default dies overnight)

STEP 5

ChatGPT → Settings → Connectors → 开发者模式 → 添加 https://xxx.trycloudflare.com/mcp/<密钥>ChatGPT → Settings → Connectors → Developer mode → add the secret URL

05 · PITFALLS

踩坑速查——都是真踩过的Pitfalls — all really hit

现象Symptom原因 / 解法Cause / fix
run_codex 报fails with exit=-6 + dyld libllhttp.x.dylib not loadedHomebrew 升级拽断了 node 的 llhttp 依赖 →upgrade broke node's llhttp → brew reinstall node
ChatGPT 声称「被安全检查拦截」但其实没真调claims it was "blocked" without calling anything没真发工具调用,自己脑补借口 → 措辞强制点名工具 + 要求原样回贴返回It never sent the call → force name the tool + demand verbatim output echo
隧道过夜失活,报Tunnel dies overnight with quic: timeoutquick tunnel 默认 QUIC/UDP → 必须加defaults to QUIC → must add --protocol http2
ChatGPT 访问端点gets 404密钥路径含secret path contains _/- 被 URL 规范化吞掉 →normalized away → 必须纯 hex(pure hex via secrets.token_hex)
调本地 codex/claude 没反应Local codex/claude doesn't respondshell 里是带审批音效的函数包装 → .env 指向真身二进制shell wrappers with approval hooks → point .env at real binaries
trycloudflare 地址重启就变address changes on restartquick tunnel 是临时的 → 配命名隧道绑自己域名is ephemeral → use a named tunnel with your domain
06 · FAQ

常见问题 · 四问速览FAQ · The four questions

Q.1解决什么问题?What problem does it solve?+
三个 AI 各关在各的盒子里:ChatGPT 会想但碰不到你的电脑;本地 AI 能动手但规划弱。以前靠人肉中转(复制粘贴),这座桥把中转自动化——ChatGPT 直接派活,结果自动回传。Each AI is boxed: ChatGPT plans but can't touch your machine; local AIs execute but plan worse. The bridge automates the human relay between them.
Q.2什么场景用?得到什么结果?Scenario and outcome?+
在 ChatGPT 里说「写个三步计划,再让 Codex 审一遍」:Claude Code 真在你硬盘上生成文件,Codex 真读了文件写下审查意见,结果回到对话里。全程只在 ChatGPT 打字。Say "draft a 3-step plan, have Codex review it": files really appear on disk, Codex really reads and reviews, results land back in the chat. You only ever type in ChatGPT.
Q.3内部是什么结构?How is it structured?+
四个关键招数:① ChatGPT 开发者模式(MCP 入口);② 本地 FastMCP 桥(一套代码 stdio/--http 两用);③ Cloudflare Tunnel(不裸奔公网);④ 密钥路径认证(capability URL——开发者模式发不了自定义请求头,Bearer Token 用不了,改用 /mcp/<hex密钥>)。Four moves: ChatGPT developer mode (MCP entry); a local FastMCP bridge (stdio/--http dual mode); Cloudflare Tunnel; capability-URL auth (developer mode can't send custom headers, so Bearer is out).
Q.4能复用什么?What can you reuse?+
① FastMCP 桥模式(stdio/--http 一套代码两用)可直接抄;② capability-URL 认证适用于一切「云端只能发 GET 式 connector」的场景;③ 六条踩坑速查能帮任何走 Cloudflare Tunnel + MCP 路线的人省一晚上。MIT。The FastMCP dual-mode bridge, capability-URL auth for header-less connectors, and six hard-won tunnel/MCP pitfalls. MIT.