Optional Secure MCP Tunnel
Understand RepoTunnel’s optional OpenAI Secure MCP Tunnel transport, local setup requirements, key handling and readiness checks.
Guides follow the current project source. Check the release notes for your installed version.
When this transport applies
RepoTunnel retains an optional integration with OpenAI’s tunnel-client for environments that already use Secure MCP Tunnel. It is a separate connection path from the managed public ngrok, Cloudflare and Direct HTTPS providers.
Choose the transport supported by your AI environment. The ordinary public-provider setup does not require this optional tunnel client.
Prepare the local connection
Run RepoTunnel’s local gateway and make the supported tunnel-client available on the machine. Supply the tunnel ID and Runtime API key through the local connection controls.
RepoTunnel validates the tunnel ID before starting its managed client. Enter credentials only in the relevant local UI; do not place them in a project, chat transcript or copied example.
Understand key handling
The Runtime API key is passed only to the tunnel-client child environment and is not stored by RepoTunnel. It is separate from the provider configuration used by ngrok or Cloudflare.
A reconnect may require entering it again. Missing availability of this optional client should not be interpreted as failure of every supported connection provider.
Verify and stop cleanly
Use the client’s health state and then make a real authenticated MCP request against an approved workspace. A launched process alone does not prove that the client can reach the project.
Stopping the local gateway also stops the managed tunnel process. Connection troubleshooting should follow the gateway, transport, authentication and workspace layers in order.