ChatGPT App review notes

WhatSync for ChatGPT

Connect your WhatsApp conversations to ChatGPT. Search messages, summarize chats, and find shared links, photos, and files using your actual synced history. Save useful answers as documents and create share links when you choose.

Capabilities

Browse WhatsApp chats

List WhatsApp chats and groups captured by your WhatSync workspace.

Ask about WhatsApp messages

Search messages by chat (projectId), text, date range, sender, and media attachments.

Save summaries

Create summaries and notes from source WhatsApp messages.

Save and share

Save generated documents back to WhatSync and create share links only when the user asks.

Architecture

The ChatGPT app uses a dedicated MCP endpoint separate from the generic MCP endpoint used by Claude, Codex, Cursor, and other developer tools.

ChatGPT MCP endpoint:
https://construction.whasupcrm.com/api/chatgpt/mcp

Generic MCP endpoint:
https://construction.whasupcrm.com/api/mcp

The ChatGPT endpoint exposes the same WhatsApp tools, plus ChatGPT-specific metadata, output schemas, OAuth discovery, and a compact widget resource for chat/message/document results.

OAuth flow

ChatGPT discovers authentication by calling the MCP endpoint and receiving a bearer challenge that points to protected resource metadata.

Protected resource metadata:
https://construction.whasupcrm.com/.well-known/oauth-protected-resource

Authorization server metadata:
https://construction.whasupcrm.com/.well-known/oauth-authorization-server

The implemented flow supports:

  • OAuth protected resource metadata discovery
  • OAuth authorization server metadata discovery
  • Dynamic client registration
  • Authorization code with PKCE
  • Bearer token access to the ChatGPT MCP endpoint

Reviewer flow

  1. Create a new ChatGPT app connector.
  2. Use OAuth authentication.
  3. Use https://construction.whasupcrm.com/api/chatgpt/mcp as the MCP server URL.
  4. Continue the OAuth connection flow.
  5. Sign in to the WhatSync dashboard when prompted.
  6. Connect WhatsApp and return to finish authorization.
Suggested test prompts
  • Show me my latest WhatsApp chats and messages.
  • Give me a quick summary of what has been happening across my WhatsApp.
  • Show me the links, photos, and files shared on WhatsApp this week.
  • Summarize this WhatsApp chat and save it.
  • Create a share link for the saved report.

Safety posture

No outbound messaging

The ChatGPT app does not send WhatsApp messages. It reads captured workspace data and writes saved reports only.

Controlled sharing

Share links are created only through an explicit tool call when the user asks for something shareable.

For public review, the value proposition should be framed as searching and understanding WhatsApp conversations using connected workspace data.

Submission checklist

  • OpenAI Platform organization is verified.
  • Production MCP endpoint is reachable over HTTPS.
  • OAuth discovery, registration, authorization, and token exchange work.
  • Privacy policy URL and company website URL are ready.
  • App icon, screenshots, test prompts, and reviewer notes are ready.