OpenAI has released a plugin that lets the macOS ChatGPT desktop app work with Apple's Messages app. It can read and search iMessage, SMS and RCS conversations, draft replies, and send them on your behalf. The rollout is narrow: it runs only on Apple silicon Macs, and only inside Codex and ChatGPT Work chats.
Not Just Reading, but Sending as You
Once the plugin is enabled, ChatGPT can read the conversations stored in the Messages app on your Mac. That covers iMessage as well as SMS and RCS, so you can search past exchanges or review what was said. If it stopped there, this would be a read-only convenience feature. The integration goes further, adding draft composition and sending messages as the user.
Examples OpenAI shared on its official account include checking your calendar and replying with a good time for dinner next week, surfacing items from the previous day's messages that still need a response, spotting a birthday mentioned in a thread and adding it to your calendar, and looking for messages that may be spam. The intent is less about one-off questions and more about agentic work that spans messages and calendar.
Limited to Codex and ChatGPT Work on Apple Silicon
The requirements are restrictive at this stage. The feature is available on every plan of the macOS desktop app, but the plugin ships only in the Apple silicon (arm64) build, so Intel-based Macs are excluded.
Where you can invoke it is limited as well. Only Codex and ChatGPT Work chats support it; ordinary ChatGPT chats do not. The web app, the mobile apps, Codex CLI and the IDE extensions are all out of scope. There is also no path in the other direction, meaning you cannot drive ChatGPT from inside the Messages app.
Setup involves installing the Apple Messages plugin from the Public section under Plugins in the app, then starting a new chat in Codex or ChatGPT Work. Letting ChatGPT actually read your conversations requires granting access permission on the macOS side. Multiple reports say Full Disk Access is required along with permissions for contact names and automation, so the scope of what you hand over is not small. Enabling this means entrusting your entire message history to one application, which is worth weighing before you start.
How Far to Skip the Approval Step
Sending is governed by an approval flow. By default, ChatGPT sends a message only after the user has reviewed and approved both the body and the recipients. The approval prompt offers Allow once, which permits that single send, and Always allow sending to this chat, which lets later messages go out to that conversation without approval.
OpenAI is cautious about the second option. For conversations that may contain untrusted or misleading instructions, the company recommends keeping the per-send approval setting. Granting permanent permission removes the final check before ChatGPT sends a message as you.
That warning is not a formality. The text of an incoming message can itself be read as an instruction to the AI. If a conversation ChatGPT has read contains a line such as forward this to someone, there is no obvious mechanism separating that from what the user actually asked for. Whether to leave sending permission wide open is a decision worth making per contact.
To return to per-send approval, open the Computer use settings, choose Manage for Messages, and remove the conversations listed under Always allowed to send using the trash icon.
Admin Controls and a Known Issue
In managed workspaces, administrators can disable Apple Messages from the existing Computer Use admin controls. That gives organizations a single place to block access to message history on work Macs.
There is a known issue: when approval prompts are disabled, such as when a task is set to Full access, the confirmation screen required for sending cannot appear and the message fails to send. Switching to Ask for approval or Approve for me resolves it.
Users who sign in to Codex with an OpenAI API key can also browse, install and manage OpenAI-provided plugins in Codex CLI and the Codex desktop app. Plugins that require OAuth features are not usable with API key authentication.
Summary
The Apple Messages plugin for ChatGPT on macOS covers searching conversations, drafting replies and sending them as the user. It targets Apple silicon Macs and works only in Codex and ChatGPT Work chats. By default every send requires approval, and OpenAI itself urges caution about granting permanent permission. Given how sensitive a message archive is, deciding how much access to grant on a per-contact and per-task basis is the practical approach.
