IntegrationsUse DoorOps with the OpenAI API
Use DoorOps with the OpenAI API
Connect an OpenAI Responses API application to DoorOps using remote MCP, a scoped OAuth token and explicit tool-call approval.
An application using the OpenAI Responses API can connect to DoorOps as a remote MCP server. This is a developer integration; ChatGPT setup has its own guide.
You need an OpenAI API account, an MCP-capable model, the Python openai SDK and a DoorOps company with MCP access enabled. API usage is billed by OpenAI separately.
Authorise the DoorOps user
Your application must complete DoorOps OAuth authorization-code flow with PKCE and mcp:use. Follow the server's advertised discovery and registration endpoints, using a supported callback URI. Keep access and refresh tokens on your application's trusted backend.
Pass the user's valid DoorOps OAuth access token in the MCP tool's authorization field. An OpenAI API key authenticates your application to OpenAI; it cannot authenticate to DoorOps. A REST API key or DoorOps password is not an MCP OAuth token.
See the MCP authentication guide for connection scope, callback requirements and company pinning.
First request: check identity with approval
Set OPENAI_API_KEY, OPENAI_MODEL and DOOROPS_OAUTH_TOKEN securely in your runtime. The SDK reads the OpenAI key from its environment. This example exposes only the identity tool and asks the operator before each MCP call; it does not change DoorOps records.
import os
from openai import OpenAI
client = OpenAI()
model = os.environ["OPENAI_MODEL"]
tools = [{
"type": "mcp",
"server_label": "doorops",
"server_url": "https://doorops.com/mcp/connect",
"authorization": os.environ["DOOROPS_OAUTH_TOKEN"],
"allowed_tools": ["who-am-i-tool"],
"require_approval": "always",
}]
response = client.responses.create(
model=model,
tools=tools,
input="Tell me which DoorOps company and role I am connected as.",
)
while requests := [
item for item in response.output
if item.type == "mcp_approval_request"
]:
approvals = []
for request in requests:
print(f"Requested tool: {request.name}")
print(f"Arguments: {request.arguments}")
approved = input("Approve this tool call? [y/N] ").strip().lower() == "y"
approvals.append({
"type": "mcp_approval_response",
"approval_request_id": request.id,
"approve": approved,
})
response = client.responses.create(
model=model,
tools=tools,
previous_response_id=response.id,
input=approvals,
)
print(response.output_text)
Use Python 3.10 or later with the current SDK. The example prints requested tool details and the identity result, never credentials. Supply authorization on every request, including approval follow-ups; OpenAI does not retain that token for later calls.
Add operational tasks carefully
After checking identity, select only the discovered tools your application needs. Examples include reading open jobs, reviewing asset history or preparing an authorised customer edit.
For changes, show the exact DoorOps proposal and consequences in your application's approval screen. Obtain explicit human confirmation before execution, including approval of the unchanged preview when a fixed workflow tool requests it. API tool-call approval alone must not be treated as blanket permission for later changes. Never automatically approve an mcp_approval_request.
Handle denied calls, OAuth expiry, validation errors and Retry-After without bypassing permissions. Read current records after an uncertain result before preparing a retry. Some operations return a native DoorOps link for the person to finish.
Revoke access
Remove the application's stored DoorOps tokens when disconnecting and revoke its connection under DoorOps → Settings → Connected apps. The OpenAI API key and the DoorOps OAuth grant have separate lifecycles.
Guidance checked 7 October 2026 against OpenAI's remote MCP, authentication and approval documentation and official Python SDK requirements.