Keyhole — local files for ChatGPT
Let ChatGPT read, and carefully edit, only the local folders you choose. No shell, no public port.
Keyhole connects your Mac or Linux computer to your private ChatGPT app through OpenAI's official Secure MCP Tunnel. Folders start read-only. Explicit local write grants allow hash-checked text edits with a private recovery history. ChatGPT cannot open other folders, run commands or widen its own access.
Install
uv tool install keyhole-mcp
keyhole setup
The package is keyhole-mcp; its command is keyhole. Do not install the unrelated package named
keyhole. uv supplies Python and isolates dependencies; setup can download and verify the official
tunnel client after confirmation.
You need ChatGPT Developer mode and OpenAI Platform tunnel permissions. Installing this package alone does not create those permissions or a private ChatGPT app. Follow the complete first-use guide, including the read-only example, account setup and PATH checks. Release wheels remain available on GitHub Releases.
Verified scope: Apple-silicon macOS and Ubuntu x86_64; Python 3.11–3.14 in CI. Real ChatGPT acceptance was completed on macOS 15.7.7 and Ubuntu 24.04. Ubuntu 22.04 has automated coverage. Windows is not supported by this release. See platform evidence.
Watch the real demonstration or read the tool and safety reference. Document parsers retain the user's OS permissions; process separation is not an OS sandbox.
Unofficial project; not affiliated with OpenAI. Source and issues. Licensed under MIT.
Release files for keyhole-mcp 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keyhole_mcp-0.4.0.tar.gz | 1.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keyhole_mcp-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.2 MB
Release files / keyhole_mcp-0.4.0.tar.gz
| Download URL | keyhole_mcp-0.4.0.tar.gz |
|---|---|
| Size | 1.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ed945a2ad88452e4293dafc4616ffd3899ccde632493410bd9204a64820f0bf1
|
|
BLAKE2b-256 checksum How to use checksums |
d931a4e9267ec8cdb57ba385725d0189f20a95b2cee93377ad82f8ff77120e62
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / keyhole_mcp-0.4.0-py3-none-any.whl
| Download URL | keyhole_mcp-0.4.0-py3-none-any.whl |
|---|---|
| Size | 60.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b40ee97d40c25c4a08876bb273565e06de74a118e5f363319b7ccd7ce87c5492
|
|
BLAKE2b-256 checksum How to use checksums |
ea3090bf9792433e16a8c15bb213bc8ac8ee9c3833faa0a09cd47d18673e3694
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log