ChatGPT Desktop
Add Draxis as an MCP server inside the ChatGPT desktop app for macOS and Windows, so you can ask about your risk register, KRIs, controls, and CSF posture without opening a browser.
Desktop is not the same as the browser.
If you followed our ChatGPT Connectors page and Draxis never showed up in the desktop app, that is expected. That page covers the account-level connector you create in a browser at chatgpt.com, and developer mode (the toggle that lets you register a custom MCP server) is a web-only setting. The desktop app has its own, separate MCP servers list, and that is the path this page documents.
Which path do you want?
| Path | Use it when |
|---|---|
| A. Desktop MCP server Settings → MCP servers |
You want Draxis in the desktop app itself. The app connects to /api/mcp from your machine, so it also works for private deployments that are only reachable on your VPN. This is the recommended path and the rest of this page assumes it. |
| B. Account connector chatgpt.com → Plugins |
You want Draxis available to your ChatGPT account everywhere (web, mobile, and, where OpenAI has enabled it, the desktop chat surface). Requires a paid plan, developer mode enabled in a desktop browser, and a Draxis deployment reachable from OpenAI’s servers. See Path B below. |
What you’ll need
| ChatGPT desktop app | Current release for macOS or Windows, with the MCP servers section under Settings. The desktop app, the Codex CLI, and the IDE extension share one config file, so a server added in any of them shows up in the others. |
|---|---|
| Draxis account | An active user on at least one Draxis tenant, with read access (analyst role or higher). |
| Draxis MCP URL | https://app.draxis.ai/api/mcp, or the same path on your private deployment. |
Path A, option 1: OAuth (recommended)
Nothing secret is stored on disk, the grant is bound to one tenant, and you revoke it from Draxis rather than from your laptop.
- In the ChatGPT desktop app, open Settings → MCP servers and click Add server.
- Name it
draxis, choose the Streamable HTTP transport, and enter the URLhttps://app.draxis.ai/api/mcp. - Save, then click Restart. The server list will show Draxis as needing authentication.
- Click Authenticate. Draxis’s discovery documents (
/.well-known/oauth-protected-resourceand/.well-known/oauth-authorization-server) are fetched automatically and the client registers itself via Dynamic Client Registration (RFC 7591), so there is no client ID or secret to paste. - Your browser opens the Draxis sign-in page. Sign in, complete MFA if your tenant requires it, then pick the tenant on the consent screen and review the scopes:
mcp:readis enough for questions; addmcp:writeonly if you want ChatGPT to submit evidence to the AI Drop Zone or trigger integration runs. - Back in the app, type
/mcpin the composer to confirm Draxis is connected and see its tools.
If you prefer the terminal, the same flow runs as codex mcp login draxis.
Path A, option 2: Personal Access Token
Use this when you want a token you can scope and expire yourself, or when the OAuth browser hand-off is blocked on a managed device.
- In Draxis, open Settings → API Tokens and click New token. Name it “ChatGPT Desktop”, pick a 90-day expiry, and pick a scope: read for question-answering, read + write only if you want Drop Zone submission and integration runs. Copy the plaintext, you will see it once.
- Add the server in Settings → MCP servers exactly as in option 1, or edit the shared config file directly at
~/.codex/config.toml(macOS) or%USERPROFILE%\.codex\config.toml(Windows):# Reads the token from an environment variable at connect time, # so the secret never lands in the config file. [mcp_servers.draxis] url = "https://app.draxis.ai/api/mcp" bearer_token_env_var = "DRAXIS_MCP_TOKEN" tool_timeout_sec = 240 - Set the variable where the desktop app can see it. A GUI app launched from the Dock or Start menu does not inherit your shell profile, so an
exportin.zshrcis not enough:# macOS, then fully quit and reopen the app launchctl setenv DRAXIS_MCP_TOKEN "drx_pat_<your-tenant>.<your-token>" # Windows PowerShell, then sign out and back in setx DRAXIS_MCP_TOKEN "drx_pat_<your-tenant>.<your-token>" - Save and Restart the server from the MCP servers screen, then type
/mcpin the composer.
If the environment-variable route is impractical, you can put the header in the config file instead. It works, but the token is then stored in plaintext, so restrict the file (chmod 600 ~/.codex/config.toml) and prefer a short expiry:
[mcp_servers.draxis]
url = "https://app.draxis.ai/api/mcp"
tool_timeout_sec = 240
[mcp_servers.draxis.http_headers]
Authorization = "Bearer drx_pat_<your-tenant>.<your-token>"
The _env_var suffix means “the name of the variable”, not the token itself. Pasting the token into bearer_token_env_var is the single most common setup mistake.
Trim the tool list before you start
Draxis exposes 42 MCP tools. Every one of them is sent to the model on each turn, and a long list makes tool selection worse, not better. Give the server an allowlist covering what you actually ask about:
[mcp_servers.draxis]
url = "https://app.draxis.ai/api/mcp"
tool_timeout_sec = 240
enabled_tools = [
"list_kris", "get_kri", "list_controls", "list_risks",
"get_risk_controls", "get_csf_posture", "get_top_risks_for_audience",
"get_financial_exposure_summary", "list_simulations",
]
Pair that with a read-scoped PAT (or mcp:read alone on OAuth) and the connection can only answer questions. Add write tools and the matching scope later, deliberately, if you decide you want them.
What the tools cover
Thirty-two read tools and ten write tools, the same surface every Draxis MCP client sees:
| Area | Scope | Representative tools |
|---|---|---|
| Risk chain | read | list_risks, list_controls, get_risk_controls, get_control_risks, list_outcomes |
| KRIs | read | list_kris, get_kri, list_composite_kris, get_kri_trend_summary, list_kri_pipelines |
| Posture & reporting | read | get_csf_posture, get_top_risks_for_audience, summarize_program_maturity, get_board_narrative, get_adopted_frameworks |
| Exposure & events | read | get_financial_exposure_summary, list_simulations, list_events, list_signatures, get_warnings |
| Inventory & vendors | read | get_asset_inventory, list_vendors, list_integrations |
| Evidence in | read + write | submit_dropzone_artifact, run_integration, push_kri_value, ingest_event |
Write tools stop at ingestion on purpose. Accepting AI proposals, rewriting risk scores, and other analyst-owned decisions stay inside Draxis so the human-review signal is captured.
Good first questions
- “Using Draxis, what are my top 5 risks by current score, and which controls cover each?”
- “Which KRIs are red right now, and which of them have not been measured since last week?”
- “Summarize my CSF 2.0 posture by function, and call out where confidence is low.”
- “Draft the risk section of a board update from the latest simulation run.”
Path B: the account-level connector
This is the connector you create once for your ChatGPT account. It is created in a desktop browser, not in the app:
- Open chatgpt.com in a browser on a computer. Mobile and the desktop app cannot create one.
- Turn on developer mode. Since the July 2026 rename it lives under Settings → Apps → Advanced settings (older builds: Settings → Connectors → Advanced, and it also appears under Settings → Security and login). On Business, Enterprise, and Edu workspaces an admin must first allow custom MCP connectors under Workspace Settings → Permissions & Roles → Connected data.
- Go to Settings → Plugins (formerly Connectors), click +, and register
https://app.draxis.ai/api/mcpwith authentication set to OAuth. ChatGPT self-registers via Dynamic Client Registration, so there is nothing to paste. - Approve the Draxis consent screen, pick your tenant, and choose scopes as above.
- Your app lands in Drafts, then appears in the composer’s developer-mode tool picker, where you choose which conversations can use it.
Caveats worth knowing before you pick this path. Custom connectors need a paid plan (Plus, Pro, Business, Enterprise, or Edu), and write-capable tool use is restricted to Business/Enterprise/Edu on some plans. Developer mode itself is a web setting, so a connector can be listed on a desktop or mobile device and still not be usable there. And because OpenAI’s servers run the OAuth and tool calls, /api/mcp must be reachable from the public internet, which rules out VPN-only private deployments. Path A has none of those constraints.
Managing access
OAuth connections appear in Draxis under Settings → Connected Apps, with the client name, the bound tenant, last-used timestamp, and a Revoke button. PATs are managed separately under Settings → API Tokens. Every tool call, whichever path you used, writes an MCP_TOOL_CALLED row to the tenant audit log with the calling client recorded, so desktop traffic is separable from browser and script traffic.
Security notes
- One tenant per connection. A token issued for tenant acme cannot read tenant contoso, even if you have access to both. To reach a second tenant, add a second server entry and authorize it separately.
- Start read-only. A read PAT (or
mcp:readon its own) cannot submit evidence or run connectors. Widen the scope when you have a reason to. - Approve write tools explicitly. Keep the app’s tool-approval prompts on for anything write-capable, at least until you trust the workflow.
- Refresh tokens last 30 days. The app rotates them automatically; after a month of not using the connection you will be asked to reauthorize.
Troubleshooting
- Draxis is missing from the desktop app after setting it up in the browser. That is Path B behaviour, not a fault. Add it under Settings → MCP servers instead.
- The server is listed but shows no tools. Click Restart on the MCP servers screen, then run
/mcpin the composer. The app reads server config at start-up. - 401 Unauthorized. Check the token is complete, including both halves of
drx_pat_<tenant-slug>.<hex>, and that it has not expired or been revoked in Settings → API Tokens. - Authenticated, but the token never gets sent. Almost always the environment variable is invisible to the GUI app. Use
launchctl setenv(macOS) orsetx(Windows) and fully restart the app, or move the token intohttp_headers. - Tool call times out on a narrative or advisory question. Synthesis tools such as
get_board_narrativeandask_vcisocall a model server-side and can run for a couple of minutes. Settool_timeout_sec = 240on the server entry. - “You do not have access to that tenant” on the consent screen. Your account exists in your home tenant but not in the one you selected. Ask that tenant’s admin to grant access.
- Connection fails only on a private deployment. Confirm the URL ends in
/api/mcp, and that the host resolves from the machine running the app (VPN up, split-tunnel routing correct). - Still stuck? Open a ticket with the server name and, for OAuth, the client ID shown in Connected Apps.
Other LLM clients
See ChatGPT Connectors (browser), Claude Desktop, Claude Code, Cursor, VSCode + Copilot.