Agents that T3 Code did not start can work with an environment through its MCP server. They can read projects and threads, start and message threads, and check which providers and models are available. This covers Claude Code or Codex in your own terminal, ChatGPT, and bots that support MCP. Each agent signs in once, and you choose what it may do.
In Settings → Connections, open a saved environment's menu and choose
Copy MCP URL. The URL is the environment's address followed by /mcp, for
example:
| 1 | https://<environment-address>/mcp |
The address must use HTTPS, or localhost when the agent runs on the host
itself. Agents refuse to sign in over a plain http:// LAN or tailnet address.
localhost on the host. See remote access.The first time an agent connects, it opens a sign-in page on the environment. The page names the agent and where its access goes:
localhost address on
the computer that opened the page.chatgpt.com.
Anyone who runs that service gets the access.Only approve a sign-in you just started. To approve, enter a pairing code from
Settings → Connections or from t3 auth pairing create on the host. A
browser already signed in to the environment as an administrator can approve
without a code.
Then choose what the agent may do:
| 1 | claude mcp add --transport http t3 https://<environment-address>/mcp |
| 2 | claude mcp login t3 |
claude mcp login opens the sign-in page in your browser. On a machine
without a browser, add --no-browser, open the printed URL elsewhere, and
paste the final URL back when asked. claude mcp list shows t3 as connected
once you approve.
| 1 | codex mcp add t3 --url https://<environment-address>/mcp |
| 2 | codex mcp login t3 |
codex mcp login --no-browser prints the sign-in URL instead of opening it.
codex mcp list shows t3 with OAuth once you approve.
Add the environment as a custom MCP app in ChatGPT's apps settings:
https://<environment-address>/mcp, using the T3
Connect address.Any agent that supports remote MCP servers over HTTP with OAuth can connect. Give it the MCP URL and choose OAuth, and the agent finds the sign-in settings itself. Agents without OAuth support cannot connect.
Approved agents appear under Settings → Connections like other clients. Revoke one there to cut off its access immediately. A sign-in lasts 30 days; after that the agent asks you to approve it again.