Secure MCP Tunnel workspace/org association fails, and Support says there is no manual fix

I’m trying to set up Secure MCP Tunnel for a private MCP server and connect it to a ChatGPT Business workspace, but I’m blocked when editing/creating the tunnel.

In Platform tunnel settings, I select my Platform organization and enter/select my ChatGPT workspace ID. When I save, I get:

“We couldn’t automatically verify the association between these workspaces and organizations.”

Earlier in the process I also saw a 403-style error similar to:

“Tenant context missing and no allowlist is configured for the active organization”
“reason=fallback_missing_entry”

Local setup does not appear to be the issue. The tunnel-client runs locally, the MCP server is reachable, and the local health checks pass. The problem appears to be specifically the association between the Platform organization and the ChatGPT Business workspace.

I opened multiple support cases. Support first said the behavior may be tied to an internal issue they were reviewing. In a later case, Support said Secure MCP Tunnel requires the ChatGPT Business workspace and Platform organization to be automatically verified as belonging to the same entity.

They also stated that:

  • There is no customer-visible diagnostic tool for why verification failed.
  • There is no documented checklist of the exact association criteria.
  • Support cannot manually link a ChatGPT Business workspace with a Platform organization.
  • Support cannot force or repair a failed association.
  • If automatic verification fails for a workspace/org pair, Secure MCP Tunnel is currently not usable for that pair.

We also tried creating a new ChatGPT workspace using the same email/account, but the same issue occurs.

Questions:

  1. Has anyone successfully resolved this without waiting on a product/backend fix?
  2. Is there a known way to create a Platform org that is automatically tied to a ChatGPT Business workspace?
  3. Are there hidden requirements beyond being admin/owner in both ChatGPT Business and Platform?
  4. Does the workspace need to be created in a specific order relative to the Platform org?
  5. Is this effectively a current product limitation for some Business/API org combinations?

I’m not looking to expose the private MCP server over public HTTPS as a workaround. I’m specifically trying to use Secure MCP Tunnel as documented.

I would treat this as an association/entitlement problem, not a local MCP problem, given that the tunnel client and local health checks pass.

The most useful next artifact is a small evidence packet that separates the layers:

  • Platform org ID and ChatGPT workspace ID, with both admin/owner roles confirmed.
  • Whether the Business workspace and Platform org were created by the same root account, same billing entity, and same domain.
  • The exact tunnel save request timestamp and the returned error/correlation ID if visible.
  • Proof that the local MCP server is not involved: local health OK, tunnel client starts, failure happens before remote tool registration.
  • A matrix of tested pairs: existing workspace + existing org, new workspace + existing org, new workspace + new org.

If all pairs fail with the same fallback_missing_entry / tenant-context error, I would avoid building a public-HTTPS workaround and instead keep the issue framed as: automatic org/workspace association cannot be diagnosed or repaired by the customer. That is the missing product surface.

I’m owner/admin on all accounts and use the same email account for both ChatGPT Bussniess and the Platform site. I also added tunnel roles to my account had have no issues creating tunnels.
I’ve also tried created a whole new ChatGPT workspace under this same email.
No matter what I do the accounts will not associate.

This 100% seems like an issue on OpenAI’s end, but support has not been very helpful at all. I basically got “There’s nothing we can do about it” responses from them, which is quite frustrating seeing as how the issue is I can’t associate their two sites/setups to the same account.

To use private MCP’s with the Claude app it just a config file setting.
We prefer to use ChatGPT, but can’t expose our MCP servers to the public web, and this secure MCP tunnel setup that doesn’t seem to work correctly is our only other option.

Thanks for posting this. I am having the same problem and did the same steps as you before searching to see if others experienced the same thing. Glad I found this discussion.

I also double checked that my billing and address information was up to date, accurate, and matched my ChatGPT Business account. Same email, payment info, address, everything matches. I also successfully completed the Persona Business verification as well since I hadn’t done that (I haven’t used the Platform before this).

Just like you, I don’t want to expose my MCP Server to the public web just yet so using the Secure MCP Tunnel is the right choice. I hope OpenAI fixes it soon. I am looking into whether some of the Cloudflare solutions (search for Cloudflare MCP server portals) may work but I haven’t figured that out yet.

I’m having the same issue, and support is telling me the same thing. I’ll send them a link to this forum in hopes they are willing to dig a bit more on there side…

It finally started working for me. I sent a screenshot of every single page related, an .har file from the browser dev tools while trying to create a tunnel, and a screen recording of the whole process failing.
Then we had some more back and forth where they basically asked again for info I’d already provided.

Then I feel like this final paragraph is what got it going lol

"The video I attached in the last email shows the whole process and the error we’re getting. It also confirms I’m using the same account for both the ChatGPT workspace site and platform.openai.com site.
This very much appears to be a system issue on OpenAI’s side and I believe that is why their error message says “Contact Support to review the association” "

Quite happy with the secure tunnel setup now that it’s working though.

Hey everyone, Seems like the issue is now resolved. We will be closing this thread. Please let us know if there is any issue relating to this topic. Thanks!