Keyhole — local files for ChatGPT
Let ChatGPT read, and carefully edit, only the local folders you choose. No shell, no public port.
Keyhole connects your Mac, Linux or Windows computer to your private ChatGPT app through OpenAI's official Secure MCP Tunnel. Folders start read-only. Explicit local write grants allow hash-checked text edits with a private recovery history. ChatGPT cannot open other folders, run commands or widen its own access.
Install
uv tool install keyhole-mcp
keyhole setup
On Windows, use PowerShell and request x64 Python, on both x64 and ARM PCs, then follow the Windows guide:
uv tool install --python cpython-3.12-windows-x86_64-none --no-build keyhole-mcp
The package is keyhole-mcp; its command is keyhole. Do not install the unrelated package named
keyhole. uv supplies Python and isolates dependencies; setup can download and verify the official
tunnel client after confirmation.
You need ChatGPT Developer mode and OpenAI Platform tunnel permissions. Installing this package alone does not create those permissions or a private ChatGPT app. Follow the complete first-use guide, including the read-only example, account setup and PATH checks. Release wheels remain available on GitHub Releases.
Verified scope: Apple-silicon macOS, Ubuntu x86_64 and Windows 11 with x64 Python; Python 3.11–3.14 in CI. Real ChatGPT acceptance was completed on macOS 15.7.7, Ubuntu 24.04 and a hosted Windows 11 ARM machine. Ubuntu 22.04 and Windows Server 2025 have automated coverage; no physical Windows consumer PC has been tested. See platform evidence.
See the step-by-step demonstration or read the tool and safety reference. Document parsers retain the user's OS permissions; process separation is not an OS sandbox.
Unofficial project; not affiliated with OpenAI. Source and issues. Licensed under MIT.
Release files for keyhole-mcp 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keyhole_mcp-0.5.0.tar.gz | 343.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keyhole_mcp-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 421.0 kB
Release files / keyhole_mcp-0.5.0.tar.gz
| Download URL | keyhole_mcp-0.5.0.tar.gz |
|---|---|
| Size | 343.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
75379bfd0a53a9b1526c8a4a3d4ec077be018e80f32bdb3f6301eb0e4a63cfa0
|
|
BLAKE2b-256 checksum How to use checksums |
68ab083e93743b94e7a0c2a3fcdf28825c66bba3aec46ab0d89ebb5fc76d213d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / keyhole_mcp-0.5.0-py3-none-any.whl
| Download URL | keyhole_mcp-0.5.0-py3-none-any.whl |
|---|---|
| Size | 77.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0adf181cdea53a2eee311ccfbb17bbba20a3ad98b946377aa809e6cb6368e7ee
|
|
BLAKE2b-256 checksum How to use checksums |
aa01a4826590f6b93b91834e5bc5bc24b5cba3e10d5357f41e065aa74f142e3c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log