Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no universal “disable all MCP servers” switch. “All” means every server in the particular surface you are using: local Codex configuration, a Codex plugin, a ChatGPT workspace app, or an OpenAI API project. Identify that surface first, then disable entries at that layer and verify access there.

Choose the scope you actually need

Where the MCP server is configured What to change What it does not change
Codex CLI or IDE extension Remove or disable each [mcp_servers.<name>] entry in user and trusted-project configuration Workspace apps, organization policy, or API projects
Codex plugin Set that server’s enabled = false policy Other plugins or workspace-installed plugins
ChatGPT workspace plugin or app Use Workspace settings administration for the plugin or app Local Codex files and API-hosted tools
OpenAI API hosted MCP Use organization hosted-tool policy, then remove project MCP permission when using selected projects Local servers and ChatGPT workspace controls

Codex CLI and its IDE extension share configuration layers. Project configuration is loaded only for trusted projects, so an untrusted repository may not be affected by a project-level change.

Disable every local Codex server

1. Inspect both configuration layers

  1. Open your personal file at ~/.codex/config.toml.
  2. From the repository you are using, inspect .codex/config.toml if the project is trusted.
  3. Find every table whose name starts with [mcp_servers.. The text after the dot is the server name.

The files can contain command-based servers, URL-based servers, or other server-specific settings. Do not assume that deleting one named entry disables the others.

2. Remove or disable the entries

To stop a server in a scope, delete its complete [mcp_servers.server_name] section (including nested settings), or comment it out while preserving a backup. If you may need it later, copy the original file first and keep a dated backup outside the repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Pearson Computer Networking, 8E
  • brand: Pearson
  • Computer Networking, 8e

There is no documented top-level key that means “disable every MCP server.” Do not add a guessed setting such as mcp_enabled = false to a local Codex file; that name belongs to a different, API hosted-tool policy.

3. Reload the client

Close and reopen the Codex CLI session or reload/restart the IDE extension. A running process can retain a server connection until it is restarted. Open a new session after editing both files.

4. Verify the same scope

  • Start Codex in the repository where you changed the settings.
  • Confirm that the MCP tools or server names no longer appear in the available-tool list.
  • Test a new session in another repository to determine whether a user-level entry remains.

If a server still appears, check for a second user or project configuration file, confirm the project is trusted, and look for a plugin that is reintroducing the server.

Disable MCP servers bundled by a Codex plugin

A plugin can provide its own server. Codex supports a server-specific policy in configuration:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
[plugins."my-plugin".mcp_servers.docs]
enabled = false

Replace my-plugin and docs with the exact plugin and server names in your configuration. Repeat the block for every bundled server you want disabled, then restart or reload Codex.

A local-marketplace plugin can be disabled for a project with enabled = false in that project’s .codex/config.toml. That turns off the plugin for that trusted project; it does not necessarily disable every server from every source, and it does not change a workspace installation managed by an administrator.

Disable workspace plugins and MCP apps in ChatGPT

Workspace plugins

  1. Open Workspace settings.
  2. Select Plugins.
  3. Open the plugin’s more-options menu.
  4. Choose Disable or Disable plugin, when that option is available.

Plugin installation, app access, and synchronization are separate controls. If the plugin depends on a shared app, review what other users or workflows will lose before disabling that app. Turning off an app does not necessarily uninstall the plugin or remove skills that operate independently.

Custom MCP apps

ChatGPT MCP app availability and action controls depend on workspace plan and role. For Enterprise and Edu workspaces, administrators can manage app or connector access and action permissions. The exact controls are not identical for every plan or user, so use the controls exposed to your administrator account rather than assuming a personal setting exists.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After changing a workspace setting, start a new chat or session and check that the app and its actions are absent. A local Codex configuration edit cannot revoke a workspace-installed app.

Disable MCP access for OpenAI API projects

API-hosted MCP is governed by organization hosted-tool policy. The organization can allow the tool for all projects, deny it for all projects, or allow selected projects.

When you need one project disabled

  1. Change the organization policy from allowing the tool for all projects to allow selected projects.
  2. Open the target project’s tool permissions.
  3. Set its MCP permission to false (the documented policy field is mcp_enabled).
  4. Run a new API request and verify that the hosted MCP tool is unavailable.

The project-level change fails while the organization still allows MCP for every project. This policy affects API-hosted tools only; it does not disable local Codex servers or ChatGPT workspace apps.

What “all” means in practice

Use this checklist before declaring success:

  • Local: every [mcp_servers.<name>] entry is removed or disabled in both the user file and any trusted project file.
  • Plugins: each bundled server has an explicit enabled = false policy, or its plugin is disabled for the relevant project.
  • Workspace: the plugin or MCP app is disabled in the workspace where it was installed, with shared-app effects reviewed.
  • API: organization policy is compatible with project-level denial, and the target project’s MCP permission is false.
  • Verification: a fresh session on the same surface shows no MCP tools and rejects a deliberate test call.

Troubleshooting

The server still appears after editing config.toml

Restart Codex or reload the extension. Then inspect both ~/.codex/config.toml and the repository’s .codex/config.toml. Check whether the repository is trusted; project settings are ignored for untrusted projects. Finally inspect plugins, which can register a separate server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A project setting did nothing

You may be testing an untrusted repository, editing the wrong project, or changing a project file while the server is configured at user scope. Test a new session in the exact repository and compare it with a clean repository.

The plugin disappeared but tools remain

Plugin installation, app access, and sync are independent. Disable the underlying shared app or connector if it is the source of the tools, and check for another plugin providing the same server.

The API project refuses the MCP permission change

The organization probably still allows the hosted tool for all projects. Select the organization-wide “allow selected projects” model first, then set the project’s MCP permission false.

I disabled a workspace app but a plugin still works

An app can be shared while a plugin retains independent skills. Review the plugin’s own status and disable it separately if your goal is to remove every action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Performance, security, and recovery considerations

Disabling unused servers reduces the tools exposed to an agent and can prevent accidental calls, but it does not revoke credentials stored in environment variables, secret managers, plugin files, or an MCP server’s own host. Remove or rotate those credentials separately when the server is no longer trusted.

Keep a backup of each edited TOML file. To restore one server, put back only its original section, restart the client, and verify that the expected tool list returns. For a workspace or API change, record the prior admin policy so another administrator can reverse it without guessing.

Or skip the browser setup

If the MCP server you are turning off was only being used to capture website screenshots, you can call ScreenshotNeo directly over HTTPS instead of maintaining a browser-connected server. It returns a PNG, JPEG, WebP, or PDF from one request and can accept the cookie or consent banner before removing more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed; response headers identify the page verdict and billing status.

See the parameter reference in the ScreenshotNeo documentation. Replace the example URL as needed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also offers an MCP server for Claude, Cursor, and other MCP clients, with take_screenshot, get_page_info, and capture_pdf tools. Every plan includes its features; 1,000 screenshots per month are free with no card, and paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can one command disable MCP everywhere?

No. Local Codex, workspace apps, plugins, and API-hosted MCP are separate control planes, so each must be changed in its own scope.

Will disabling a local Codex server remove its API credentials?

No. Remove or rotate credentials separately in environment variables, secret stores, plugin files, or the server host.

Why must I start a new session after changing settings?

A running client may retain an existing MCP connection and tool list until it is restarted or reloaded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.