When custom GPTs retire on 11 December 2026, OpenAI’s migration moves instructions and knowledge into a plugin. Custom Actions do not move: each one has to be rebuilt as a Model Context Protocol (MCP) server that the plugin connects to. ChatGPT, Codex and Claude all use the same server.
One operation, one tool
- Each OpenAPI operation becomes a tool. Its
operationIdbecomes the tool name, 64 characters or fewer. - The summary becomes the title; the description says what the tool does, never what the model should do.
- Path, query and body fields become the tool’s input schema. Credentials are never tool inputs.
- Every tool states
readOnlyHint,destructiveHintandopenWorldHint. OpenAI requires all three; hosts ask the user before running anything that is not read-only.
Sign-in changes
An Action could hold one shared API key. A public plugin usually signs each user in with OAuth 2.1, using PKCE and client registration (Client ID Metadata Documents or Dynamic Client Registration). The MCP server publishes where to sign in at /.well-known/oauth-protected-resource and answers 401 until the user connects.
What reviewers check
- Five positive and three negative test cases, run on a test account without multi-factor sign-in.
- A short demo recording, a privacy policy, terms, and a support URL.
- Tool copy that does not steer the model toward your plugin over others.
The migration checker does the mapping for you and generates the server, the manifest and draft test cases.