Skip to main content

Connect Selfmade Ninja Labs MCP to ChatGPT & Claude

SELFMADE NINJA LABS · REMOTE MCP

One Labs environment. Two AI clients. One controlled interface.

Connect ChatGPT or Claude to the same authorized Labs MCP service and turn your cloud lab into an AI-assisted engineering workspace.

Application EngineeringCybersecurityAI AgentsInfrastructure
Connect Selfmade Ninja Labs MCP to ChatGPT and Claude

What you need

Everything required to establish the connection safely.

01Labs accountAn active Selfmade Ninja Labs account with the resources you want to access.
02AI clientChatGPT or Claude on a surface that supports custom remote MCP connections.
03Supported accessA plan or workspace configuration that permits custom MCP apps or connectors.
04Network accessAn internet connection that can reach the remote Labs MCP service.

1. What is MCP?

Model Context Protocol (MCP) is an open standard that lets AI applications such as ChatGPT and Claude connect to external tools and data through a structured, permission-controlled interface.

Think of MCP as a bridge between an AI client and Selfmade Ninja Labs. ChatGPT and Claude are different MCP clients, but both can connect to the same remote Labs MCP service:

One protocol · two AI clients · one Labs environment

The MCP connection at a glance

REMOTE MCP
01YouNatural-language request
02ChatGPT / ClaudeAI client + reasoning
03Model Context ProtocolStructured tool interface
04Selfmade Ninja LabsAuthorized labs, domains, devices & services

Without MCP, ChatGPT or Claude can explain how to use a lab, but they cannot directly access the information exposed by Labs. With MCP, the connected AI client can discover the tools provided by the Labs MCP server and use the appropriate tool when your request requires it.

The important point is that MCP is not a ChatGPT-only or Claude-only technology. It is an open protocol. Selfmade Ninja Labs exposes one remote MCP endpoint, and compatible clients such as ChatGPT and Claude can connect to it using their own connection and authorization flows.

The important idea

MCP does not give ChatGPT or Claude unrestricted access to your account. The MCP server defines the tools and capabilities that are exposed, while the Labs authorization and the AI client's permissions determine what can actually be used.

2. Why connect Labs MCP to ChatGPT or Claude?

Connecting Labs MCP is useful when you want ChatGPT or Claude to work with the real state of your lab environment instead of relying on information you manually copy into the conversation.

01Observe

Inspect labs, domains, devices, services, files, processes and current state.

02Diagnose

Correlate live evidence and explain failures instead of guessing from symptoms.

03Build

Develop applications, scripts, security tooling and AI-agent workflows inside a real lab.

04Operate

Execute approved changes, deployments and repeatable engineering workflows.

The productivity gain: natural-language intent meets structured, permission-controlled tools.

What Can You Build With Labs MCP?

Labs MCP is not limited to checking whether a lab is running. The bigger idea is to give an AI assistant a practical, authorized interface to a real development environment. That makes Selfmade Ninja Labs useful for application development, cybersecurity, AI-agent engineering, infrastructure work, automation, and hands-on learning.

01 · BUILD

Build & ship applications

Use ChatGPT or Claude with a real lab to inspect architecture, edit permitted files, run tests, debug failures and iterate toward a working system.

  • Web apps, APIs, CLIs and backend services
  • Codebase inspection and architecture analysis
  • Build, dependency and runtime debugging
  • Tests, Git workflows and verification
02 · SECURITY

Cybersecurity & ethical hacking

Make an authorized security lab interactive: prepare methodology, inspect evidence, troubleshoot tooling, build utilities and document findings.

  • Reconnaissance and enumeration workflows
  • Scanners, parsers and CTF tooling
  • Network, service and log analysis
  • Controlled vulnerability reproduction and validation
AUTHORIZED TARGETS ONLY
03 · AGENTS

Develop AI agents

Prototype and test tool-using agents against realistic files, APIs, databases and services inside a controlled environment.

  • Agent backends and API services
  • Tool calling and orchestration
  • RAG and automation pipelines
  • Runtime debugging and evaluation
04 · OPERATE

Infrastructure & DevOps

Work with the actual operational state of your environment rather than copying fragments into a chat.

  • Services, ports, processes and domains
  • Deployment and configuration diagnosis
  • Repeatable operational tasks
  • Post-deployment verification
Security boundary

Use these capabilities only against systems and targets you are authorized to assess. MCP provides a connection to your lab; it does not make an unauthorized target permissible.

Learn by doing

Hands-on learning loop

Ask. Experiment. Understand.

01 · Ask02 · Inspect03 · Experiment04 · Observe05 · Explain06 · Repeat

Use a real lab as the feedback loop instead of learning from isolated examples. ChatGPT or Claude can ground explanations in the state and evidence available through Labs MCP.

The key advantage

The important distinction is that your AI assistant is not merely generating instructions for you to copy. When the required permissions are available, it can work with the actual state of your lab. That means explanations can be grounded in real files, processes, services, configurations, and tool results rather than assumptions.

01ChatGPT / ClaudeReasoning and natural-language interaction
02Labs MCPStructured, permission-controlled tool interface
03Your isolated development environmentLabs, projects, services, devices and permitted resources
=AI-assisted engineering workspace

3. Connect Labs MCP to ChatGPT

MCP apps are currently available through the ChatGPT web experience. Open ChatGPT in your browser and sign in to the account or workspace where you want to connect Labs.

Availability can vary

OpenAI's MCP capabilities and interface are evolving. OpenAI currently documents full MCP support, including write/modify actions, as a beta capability for Business, Enterprise and Edu plans. Availability, permissions, supported actions, and interface labels can vary by plan and workspace. Custom MCP apps are web-only.

Enable Developer Mode

If your account or workspace provides Developer Mode, enable it before creating the custom MCP app.

In the current ChatGPT interface, the setting may be available under:

Settings → Security and login → Developer mode

Some workspace configurations expose Developer Mode through workspace or app administration instead. Older interfaces may show it under Settings → Apps → Advanced Settings. If you cannot see Developer Mode, the Labs endpoint is not necessarily the problem; your plan, role, workspace policy, or rollout may determine whether the feature is available.

Create the Selfmade Ninja Labs MCP app

  1. Open the ChatGPT web interface and go to the area where your account exposes Apps or Plugins.
  2. Use the option to create/add a custom app or MCP connection.
  3. Enter a clear name, for example Selfmade Ninja Labs.
  4. For the MCP server URL, enter:
https://labs.selfmade.ninja/mcp
  1. Provide the requested metadata or description.
  2. Choose the authentication mechanism supported by the Labs endpoint. If OAuth is offered, use OAuth rather than sharing your Labs password in a prompt.
  3. If ChatGPT offers Scan tools or an equivalent tool-discovery step, run it and complete the OAuth authorization when prompted.
  4. Review the trust and permission warnings, then select Create or the equivalent confirmation.

The exact labels can change as OpenAI updates the MCP/app experience.

Verify ChatGPT

Open a new conversation and enable Selfmade Ninja Labs from the available app/tool menu. Start with a read-only request:

List my Selfmade Ninja Labs and tell me which ones are currently deployed.

Then try:

Show me the connection information for my Essentials lab. Do not change anything.

If ChatGPT retrieves current information from Labs, the connection is working.

4. Connect Labs MCP to Claude

Claude supports remote MCP servers through custom connectors. Anthropic's current documentation places custom connector management under Customize → Connectors for individual accounts. Custom remote MCP connectors are available on Claude, Cowork, and Claude Desktop for Free, Pro, Max, Team, and Enterprise plans; Free users are limited to one custom connector.

The same Labs MCP endpoint works for both

You do not need a second Selfmade Ninja Labs server for Claude. Use the same remote MCP endpoint:

https://labs.selfmade.ninja/mcp

ChatGPT and Claude are simply two different MCP clients connecting to the same authorized Labs MCP service.

Add the connector on Claude Pro or Max

  1. Open Claude on the web.
  2. Go to Customize → Connectors.
  3. Click the + button next to Connectors.
  4. Select Add custom connector.
  5. Enter a name such as Selfmade Ninja Labs.
  6. Enter:
https://labs.selfmade.ninja/mcp
  1. If needed, open Advanced settings and provide an OAuth Client ID and OAuth Client Secret for the server.
  2. Click Add and complete the authentication flow.

After connecting, enable the connector for a conversation from the + menu → Connectors.

Team and Enterprise workspaces

For Claude Team and Enterprise, an Owner or Primary Owner must add the custom connector for the organization first:

  1. Go to Organization settings → Connectors.
  2. Click Add.
  3. Choose Custom → Web.
  4. Enter the Selfmade Ninja Labs MCP URL.
  5. If required, use Advanced settings to provide the OAuth Client ID and Client Secret.
  6. Click Add.

Members can then go to Customize → Connectors, find Selfmade Ninja Labs, and click Connect to authenticate their own account.

Enable Claude's Labs tools in a conversation

Once connected:

  1. Click the + button in the lower-left of the Claude chat composer.
  2. Open Connectors.
  3. Enable Selfmade Ninja Labs for the conversation.
  4. Ask Claude for a read-only task first.

For example:

List my deployed Selfmade Ninja Labs and tell me which ones are currently available.

Then try:

Inspect my Essentials lab and explain the current service state. Do not change anything.

Claude network requirement

Anthropic's current remote MCP connector architecture connects to your MCP server from Anthropic's cloud infrastructure, not directly from your laptop. Your server therefore needs to be reachable over the public internet from Anthropic's infrastructure. A server available only on localhost, a private LAN, or a VPN will not work as a normal custom remote connector unless the required network access is provided.

This is important for Labs because the public endpoint https://labs.selfmade.ninja/mcp is already designed as a remotely reachable MCP service.

Claude security

Anthropic warns that custom connectors can access and potentially modify data through the tools they expose. Review OAuth scopes, connector permissions, and tool approvals carefully. Remote MCP servers can also carry prompt-injection risks. Connect only to MCP servers you trust.

5. Authorize and verify the connection

Both clients follow the same security principle: authenticate the Labs connection through the provider's supported flow, then start with read-only requests.

AUTHENTICATEUse OAuth or delegated authorizationDo not expose long-lived credentials in prompts.
REVIEWInspect requested scopes and toolsKnow what the connector can read or change.
VERIFYStart with a read-only requestConfirm live Labs state before making changes.
Protect your credentials

Do not paste your Selfmade Ninja Labs password, SSH private key, WireGuard private key, API tokens, or recovery codes into ChatGPT or Claude merely to connect MCP.

ChatGPT verification

Use a read-only prompt such as:

List my Selfmade Ninja Labs and tell me which ones are currently deployed.

Claude verification

Use a read-only prompt such as:

List my deployed Selfmade Ninja Labs and tell me which ones are currently available.

If the assistant retrieves current state from Labs instead of giving a generic explanation, the MCP connection is functioning.

6. Use MCP effectively: ask for outcomes, not tool names

You do not normally need to tell ChatGPT or Claude which internal MCP function to call.

Instead of writing:

Call list_labs.

Prefer:

Check my Selfmade Ninja Labs and tell me which machine labs are currently deployed.

The connected assistant can determine which available tool is appropriate for the request.

This makes your prompts easier to read and keeps them independent from internal tool names that may change over time.

7. Give Your AI Assistant Enough Context

Good MCP prompts contain three things:

  1. The goal — what you want to achieve.
  2. The scope — which lab, project, domain, or resource is relevant.
  3. The safety boundary — whether ChatGPT or Claude should only inspect, propose a change, or actually perform an action if permitted.

For example:

Inspect my Essentials lab. Find the project that is currently serving on port 80, explain its structure, and do not modify any files.

Or:

Check why my lab is unavailable. Inspect the lab status and logs first. Do not redeploy it unless I explicitly approve the fix.

This is much safer and more useful than a vague prompt such as:

Fix my lab.

8. A practical workflow: Inspect → Explain → Propose → Execute

For important changes, use a staged workflow. Whether you are using ChatGPT or Claude, the assistant should move from observation to evidence, then from a reviewed proposal to an approved action.

Labs MCP · Operating model

A safer path from request to result

Use the same evidence-first workflow with ChatGPT or Claude. Changes happen only after the scope and action are clear.

  1. 01

    Start

    User request

    State the outcome you want and include the relevant lab, project, service, domain, or other scope.

  2. 02

    Discover

    Identify the relevant resource

    Let ChatGPT or Claude determine which connected Labs resource is actually relevant to the request.

  3. 03

    Observe

    Read current state

    Inspect the live state before forming a diagnosis: status, configuration, files, processes, ports, domains, or other relevant data.

  4. 04

    Evidence

    Collect supporting evidence

    Gather the additional logs, command output, metadata, or configuration details needed to distinguish symptoms from the root cause.

  5. 05

    Reason

    Reason over the evidence

    Compare the evidence, explain the likely cause, and separate verified facts from assumptions or uncertainty.

  6. 06

    Plan

    Propose the next action

    Present the smallest sensible fix or next step, including what will change, why it is needed, and any expected side effects.

  7. 07

    Control point

    Request approval when a change is needed

    Pause before write, deploy, delete, routing, or other consequential actions. The user reviews and approves the proposed change.

    Approval gate · No approval, no consequential change.
  8. 08

    Finish

    Perform the approved action

    Execute only the approved scope, make the smallest necessary change, and avoid unrelated modifications.

  9. 09

    Verify

    Verify the result

    Re-check the resulting state and confirm that the intended outcome was achieved without introducing a new problem.

Step 1 — Inspect

Ask ChatGPT or Claude to gather the current state.

Inspect my lab and identify the current problem. Do not make changes.

Step 2 — Explain

Ask for a concise diagnosis.

Explain the likely cause, the evidence you found, and what would need to change.

Step 3 — Propose

Ask for the exact action plan.

Give me the safest fix, the files or settings that would change, and any possible side effects.

Step 4 — Execute

Only after reviewing and approving the plan:

Apply the proposed fix. Before changing anything, re-check that the target is the same lab and that no unrelated configuration will be overwritten.

Step 5 — Verify

After the action, ask the assistant to confirm the outcome:

Verify the change you just made. Check the resulting state and tell me whether the original problem is resolved. Do not make any additional changes.

This evidence-first workflow is especially valuable for production-connected resources because it creates a clear separation between observation, diagnosis, approval, execution, and verification.

9. Useful prompts for Labs MCP

LAB MANAGEMENTList my labs and summarize their current status.
TROUBLESHOOTINGMy lab is not responding. Inspect its status, logs, listening ports, and recent process state. Give me a diagnosis without changing anything.
DOMAINS & HTTPSList my domains and show which lab each active domain is attached to. Flag any certificate or routing problem you find.
PROJECT INSPECTIONInspect my lab workspace and identify all project directories. For each project, tell me its language/framework and Git status.
SAFE CODE CHANGESInspect the project first. Explain the required change, then wait for my approval before editing any files.
MULTI-STEP INVESTIGATIONInvestigate this issue end to end. Start with read-only inspection, identify the root cause, propose a fix, and only execute the fix after I approve it.

10. Make your prompts more precise

A strong MCP prompt is usually short but explicit. Instead of a vague command, state the outcome, scope and safety boundary.

LESS PRECISE

Fix my lab

Check my server

Update the app

Deploy it

Delete the old domain

BETTER

Inspect my Essentials lab, identify the failure, and propose a fix without changing anything.

Inspect the lab status, processes, listening ports, and recent logs.

Inspect the repository and tell me exactly which files need to change. Wait for approval before editing.

Confirm the target lab, current configuration, and expected impact before deploying.

Identify the domain and the lab using it. Do not delete anything until I confirm.

Rule of thumb: make the requested intent and boundary unambiguous.

11. Let ChatGPT or Claude use multiple Labs tools

MCP becomes significantly more useful when a task requires several pieces of information.

For example:

Check why my website is returning an error. First identify the lab serving it, then inspect the lab status, listening ports, and relevant logs. Compare the evidence and give me the most likely root cause. Do not modify anything.

The workflow above is the operating model to follow when a task spans multiple Labs tools. The assistant should identify → inspect → gather evidence → reason → propose → obtain approval → act → verify, rather than forcing a complex task through one tool call.

This separation makes multi-tool investigations easier to audit and reduces the chance of an unnecessary or unrelated change.

12. Read-only versus write actions

Not every MCP operation has the same risk. Treat capability as a spectrum, not a single permission switch.

READ · LOW RISK

Observe the environment

Retrieve lab status, files, domains, logs, processes and other state without changing the environment.

  • Diagnosis
  • Exploration
  • Evidence gathering
WRITE · CONSEQUENT

Change the environment

Edit files, deploy labs, change routing, delete resources or modify configuration.

  • Review the proposed action
  • Approve the intended scope
  • Verify the result afterwards
Production rule

Treat an MCP-connected production environment exactly like any other production system: inspect first, make the smallest necessary change, and verify the result afterwards.

13. MCP does not replace authorization

Connecting Labs MCP does not mean ChatGPT or Claude can bypass Selfmade Ninja Labs permissions.

The Labs platform still determines which account is authenticated and which resources that account can access. ChatGPT or Claude can only work with the capabilities exposed through the MCP connection and permitted by the current app/workspace configuration.

This separation is important:

Permission model

Effective access is layered

No single layer grants unrestricted control. Access is the intersection of the AI client, MCP app, and Labs authorization.

01AI client permissionsWhat ChatGPT or Claude is allowed to use
02MCP app permissionsWhich tools and actions the connection exposes
03Labs authorizationWhich resources the authenticated account can access
=Effective accessThe actual capability available to the assistant

14. Security best practices

Follow these practices when using Labs MCP:

  • Connect only to the official Labs MCP endpoint.
  • Use OAuth or the supported authorization flow instead of placing passwords in prompts.
  • Review the tools exposed by a custom MCP app before enabling it.
  • Prefer read-only inspection before write operations.
  • Ask ChatGPT or Claude to identify the target resource before destructive actions.
  • Never paste SSH private keys or WireGuard private keys into a chat.
  • Do not give a prompt more access than the task requires.
  • Review changes before applying them to production resources.
  • After a write operation, verify the resulting state.
  • If an MCP server or app is unfamiliar, do not connect it merely because it claims to be compatible with Labs.

OpenAI also warns that connecting to unsafe or untrusted MCP servers can introduce security risks, including prompt injection. Treat a custom MCP connector as software with privileges, not as a harmless browser extension.

15. Troubleshooting

01

The MCP app does not appear

Check that you are using a supported web surface, the required developer/connector feature is enabled, your plan supports the capability, and your workspace administrator has not blocked custom apps.

03

Authorization keeps expiring

If OAuth is used, verify that the identity provider supports the token lifecycle required by ChatGPT or Claude. Reauthorization may be necessary.

04

A tool is unavailable

The capability may not be exposed to your account or enabled in your workspace. Review the connector's available actions and permissions.

05

A tool fails after an update

Managed workspaces may review or freeze a connector's available tools. If definitions changed, refresh and review the updated actions.

16. The best way to think about Labs MCP

The most effective mental model is not:

“ChatGPT or Claude can control my lab.”

Instead, think:

“ChatGPT or Claude can reason about my lab using a controlled set of tools that I authorize.”

That distinction leads to better prompts, safer workflows, and fewer accidental changes.

Selfmade Ninja Labs gives you the environment. MCP gives ChatGPT or Claude a structured interface to that environment. Your job is to define the goal clearly, constrain the scope, review important changes, and verify the result.

Official provider references

READY TO CONNECT?

Give your AI assistant a real engineering environment.

Connect the Labs MCP endpoint, verify it with a read-only request, then graduate to deeper development, security, AI-agent and infrastructure workflows.

START WITH
“Inspect my Selfmade Ninja Labs and give me a concise overview of everything I currently have running. Do not make any changes.”