Connect ChatGPT
DropZoom can be added to ChatGPT as a custom MCP server. Once connected, ChatGPT can list your links, preview a new link and publish pages and text files that it writes. Every new link is public. You approve the connection yourself, in your browser, with a passkey, and you can remove it at any time.
Only ChatGPT can connect this way. DropZoom has not been reviewed, approved or listed by OpenAI.
Before you start
- A DropZoom account with a passkey. Sign in at publish.dropzoom.link, open Account, then Passkeys, and add one. A passkey is how you approve the connection.
- A ChatGPT plan and workspace that allow custom MCP servers. If you do not see the option below, your plan or workspace settings may not allow it.
Connect
- In ChatGPT, open chatgpt.com/plugins.
- Choose +, then Add custom MCP server.
- Enter the server URL
https://mcp.dropzoom.link/mcpand choose OAuth as the sign-in method. - ChatGPT opens a DropZoom page in your browser. Check that you started it, choose what to allow, tick I started this connection from my own ChatGPT, and choose Continue with passkey. If someone else sent you that page, close it.
- Use your passkey when your browser asks. DropZoom shows the account it found and asks you to confirm it. Choose Connect, or Not me if it is the wrong account.
- You are sent back to ChatGPT. You can connect up to 3 ChatGPT connections to one account.
What you choose on the approval page
| Choice | What it lets ChatGPT do | Default |
|---|---|---|
| See your DropZoom links, their files and their versions | List your links, read one, list its files and its versions | On |
| Publish new links from files you give ChatGPT | Preview and publish a new link. It cannot change or delete a link you already have | On |
| Read reviewer comments left on your links by visitors | List the comments visitors left on a link. Visitor text can contain instructions aimed at an AI, so ChatGPT is told to treat it as data. Adding this later means connecting again | Off |
You can allow less than ChatGPT asked for. ChatGPT cannot delete your links, change links you already have, change your password, manage keys or passkeys, or see or change your account.
The pairing code
A new connection is unconfirmed. Until you confirm it:
- it can create new links (up to 10, holding up to 50 MiB) and see only the links it created;
- it cannot choose a link's address, so DropZoom picks a random one;
- it is removed after 7 days.
To confirm it, ask ChatGPT for the DropZoom connection status. While the connection is unconfirmed it shows a six-digit pairing code. Open DropZoom, go to Account, then Connected agents and devices, find the ChatGPT connection, and type the code to choose Confirm. Only the connection that owns the code is shown it.
What the tools do
| Tool | Does | Needs |
|---|---|---|
connection_status | Says whether the connection is confirmed, what it may do and, while unconfirmed, the pairing code. Changes nothing. | Sign-in only |
list_publications | Lists your links, newest first, 50 at a time. | See links |
get_publication | Shows one link: summary, whether it has a password, file count, when published. | See links |
list_publication_files | Lists the files in a link's current version, 200 at a time. | See links |
list_versions | Lists a link's versions, newest first, up to 100. | See links |
list_feedback | Lists visitor comments on a link, 50 at a time. | Read comments |
preview_publication | Checks exactly what a new link would contain and returns a one-time plan token and a summary. Creates nothing. | Publish |
publish_files | Publishes the previewed files as a new public link. Never changes or deletes an existing link. | Publish |
Publishing
- ChatGPT calls
preview_publication. It tells you the file list and that the link will be public. - After you agree, it calls
publish_fileswith the same files, the plan token and the summary, unchanged. A plan token lasts 15 minutes. - DropZoom scans every file for secrets and for malware before the link goes live. A file that looks like it holds a key or token, or that the malware scan flags, is refused and nothing is published.
- Calling
publish_filesagain with the same plan token returns the same link and never makes a second one, so it is safe to retry.
ChatGPT publishes pages and files that it writes, as text. Attaching files from your computer is not supported yet. Inline text is limited to 256 KiB per file and 1 MiB in all, in at most 20 files.
Links are public. Anyone with the address can open it. A random address is not private. Publish only what you are happy for anyone to see.
Limits
| Limit | Value |
|---|---|
| Files in one publish | 20 |
| Inline text | 256 KiB per file, 1 MiB in all |
| Malware scans | 20 files a minute and 100 an hour for your account |
| Previews | 20 a minute for each connection |
| Publishes | 10 a minute and 60 an hour for each connection |
| Tool calls | 120 a minute for each connection, 240 a minute for the account |
| Connections | 3 ChatGPT connections for one account |
| Unconfirmed connection | 10 new links, 50 MiB, removed after 7 days |
| Active keys on one account | 10, a ChatGPT connection counting as one |
The limits for links themselves are on Limits.
Errors
A problem comes back as a tool error with a stable code, a fixed message and, where it matters, a retryable flag. Match on code. A sign-in problem is not a tool error: ChatGPT is asked to sign in again. The ones you are most likely to meet:
| Code | Retry | What to do |
|---|---|---|
connection_unconfirmed | No | Confirm the connection in Account, under Connected agents and devices, with the pairing code. |
unconfirmed_link_limit / unconfirmed_storage_limit | No | An unconfirmed connection hit its 10 links or 50 MiB. Confirm it. |
slug_requires_confirmation | No | Choosing an address needs a confirmed connection. Leave the address out. |
too_many_files / inline_content_too_large | No | Stay within 20 files and 1 MiB of text (256 KiB a file). |
secret_detected | No | A file looks as if it holds a key or token. Remove it. |
malware_detected | No | A file was refused by the malware scan. Nothing was published. |
malware_scan_unavailable | Yes | The scan could not finish. Call publish_files again with the same plan token. |
plan_expired / plan_mismatch / summary_mismatch | No | Call preview_publication again and publish exactly what it returned. |
publish_in_progress | Yes | A publish is already running. Wait, then retry with the same plan token. |
rate_limited | Yes | Wait retryAfterSeconds, then retry. |
Every code is listed on Errors.
What DropZoom keeps
See the privacy notice. In short: DropZoom keeps the connection (its name, what you allowed, the passkey that approved it, when) and hashes of its tokens, and records security events for 90 days. A preview keeps nothing. A publish plan is kept for 24 hours without any file content. The files you publish are kept as the link.
Disconnect
Open DropZoom, go to Account, then Connected agents and devices, and remove the ChatGPT connection. It stops working at once.
