Connect ChatGPT through the hosted OAuth flow and approve the memory:read and memory:write scopes.
Prerequisite
Use an OpenAI app configuration that supports a remote MCP server and the hosted Streamable HTTP endpoint. The reviewed client profile is ChatGPT / OpenAI Apps SDK with OAuth.
- Endpoint: https://xmemo.dev/mcp.
- Transport: streamable-http.
- Auth mode: OAuth with memory:read and memory:write.
Professional memory workflows in ChatGPT
Five professional workflows turn important conversations into durable decisions, plans, TODOs, and progress checkpoints:
- Discovery & Planning: Recall constraints and prior decisions, explore distinct options, challenge assumptions, and convert approved direction into project plans.
- Evidence Review: Compare proposals and progress reports against saved decisions and repository evidence.
- Session Memory: Preserve decisions, rationale, TODOs, and verified results without raw conversation archiving.
- Continuity: Reconcile latest checkpoints and prepare handoffs for compatible agents.
- Interactive Workspaces: Open TODO Board, Ledger, and Project Workspace directly inside ChatGPT.
Install / setup
In the OpenAI Platform app management dashboard, add the hosted MCP URL and the OAuth metadata for the remote connection. Keep the endpoint exactly as shown in the reviewed client configuration.
- Configure the hosted MCP URL in the app dashboard.
- Request memory:read and memory:write at consent.
- Do not add a bearer token to the app listing.
Permissions and user workspace isolation
XMemo uses browser OAuth and server-enforced scopes (memory:read and memory:write) to keep reads and writes strictly bounded within the signed-in user's workspace. Durable memory remains under complete user control throughout its lifecycle (search, update, export, soft-delete, and restore).
Set the credential
No key — complete browser OAuth. ChatGPT receives the credential through the OAuth grant; do not set XMEMO_KEY or add an Authorization header.
No XMEMO_KEY
Complete browser OAuth in ChatGPT
Generate / confirm XMEMO_AGENT_INSTANCE_ID
The reviewed ChatGPT OAuth listing has no client-side identity header. Do not invent or paste XMEMO_AGENT_INSTANCE_ID into the app configuration; confirm that attribution is managed by the OAuth grant for this client path.
Preserve the existing config block
Use the existing ChatGPT XMemo configuration block rendered on this page. Preserve its hosted URL, OAuth mode, and requested scopes; change only local dashboard values that the client requires.
Restart the client
Save the app configuration, close any stale MCP connection, and reopen the ChatGPT app or conversation so it loads the current OAuth metadata.
Test with a real recall call
Make the first MCP call read-only. This is an actual recall invocation, not a health-check placeholder, and it does not write memory.
recall({ query: "connection check", limit: 1 })
Expected response (literal shape)
A successful call returns the public ranked text shape below; the reference and content are real values from the authorized memory space.
### XMemo Memory Results:
1. Reference: <opaque-memory-id> | Location: <location>
> <memory content>
Common Errors
ChatGPT-specific OAuth failures map to the real token endpoint responses.
- invalid_grant — Authorization code is invalid or expired, or was already used: reconnect ChatGPT and authorize again.
- invalid_target — the OAuth resource does not match this MCP server: restart the connection using https://xmemo.dev/mcp as the resource.
- 403 insufficient_scope — the grant does not include memory:read or memory:write: approve the requested scope and reconnect.