thcThought Control

MCP Apps (SEP-1865)

MCP extension: tools ship sandboxed HTML UIs into chat hosts.

apps.extensions.modelcontextprotocol.io ↗repo ↗docs ↗MCP-UI (predecessor, community) ↗MCP Apps announcement (2025-11-21) ↗fka.dev: MCP Apps Should Work in the Terminal Too (2026-09-09) ↗Claude Code issue #93973: plugin API for interactive TUI elements ↗Anthropic: donating MCP to the Agentic AI Foundation ↗

license
Apache-2.0 · Repo LICENSE: MCP is transitioning MIT -> Apache-2.0; new code/spec contributions Apache-2.0, docs CC-BY-4.0, un-relicensed older contributions stay MIT (GitHub reports NOASSERTION; npm package still declares MIT). MCP-UI is Apache-2.0.
language
Spec + TypeScript SDK (@modelcontextprotocol/ext-apps); Views are HTML/JS
backing
Model Context Protocol project, governed under the Agentic AI Foundation (Linux Foundation directed fund co-founded by Anthropic, Block and OpenAI, Dec 2025). SEP authors from MCP-UI (Ido Salomon, Liad Yosef), Anthropic and OpenAI among others.
stars
2,927 (as of 2026-10-09)
downloads
@modelcontextprotocol/ext-apps 4,575,295/week; @mcp-ui/client 321,504/week; @mcp-ui/server 126,135/week (npm, week ending 2026-10-07)
latest release
@modelcontextprotocol/ext-apps v2.0.3 (spec 2026-01-26, Stable), 2026-09-25
first release
2025-11
complement

MCP Apps owns UI in web chat hosts; scene can fill the terminal gap and speak MCP as its control transport.

Complement it: it does a neighbouring job; interoperate.

the steelman: the best honest case for it

MCP Apps is where the users already are. It turned MCP-UI's community experiment and OpenAI's Apps SDK into one stable, foundation-governed standard, and Claude, ChatGPT, VS Code and Goose render it today, so one server reaches hundreds of millions of chat users with a real interactive app, not a widget catalog. It refuses to invent a UI language: a View is just HTML, so anything the web can draw (maps, 3D, sheet music, Excalidraw) works, and safety comes from proven browser isolation (sandboxed iframes, CSP, predeclared resources, auditable JSON-RPC over MCP's own messages). With 4.6M weekly SDK downloads and agent skills that scaffold an app in one prompt, it is the default answer to 'my tool needs a UI'.

scores
datadriveseeedittimeratetermpxteachmatureopen
UI as data1 scene 5The resource is a declared, reviewable HTML document, but the UI itself is code.
Agent can drive it3 scene 5Model triggers Views via tool calls and gets tool calls back; it cannot directly manipulate a live View.
Agent can see it2 scene 5Structured but voluntary: whatever the View sends via update-model-context.
Small, targeted edits1 scene 5
Time travel0 scene 0
Live data rate3 scene 5A View can open its own connections so data bypasses the model; no published numbers.
Terminal native0 scene 5HTML-only; terminal views exist only as a 2026-09 blog proposal.
Pixel graphics5 scene 4Full web platform (canvas, WebGL; Three.js and ShaderToy examples).
Teaching0 scene 3
Maturity4 scene 1Stable spec shipped in Claude, ChatGPT, VS Code, Goose; not yet ubiquitous across MCP clients.
Openness5 scene 4Linux Foundation (AAIF) governed, Apache-2.0/MIT.

MCP Apps (SEP-1865) scene now scene planned

how agents use it

How

Indirect: the model calls an MCP tool and the host shows that tool's View. The View, not the model, drives the UI; it can call tools and push context to the model (ui/update-model-context).

Wiring it in

Write an MCP server that registers tools with UI resources (SDK + agent skills such as create-mcp-app); works in any compliant host without host changes.

Seeing the result

Only what the View chooses to report via ui/update-model-context or tool calls; the model cannot query the DOM or see the render.

Small edits

No addressing: the host delivers tool inputs/results; the View app decides what to change.

History

None.

In short

Gives agents a way to ship arbitrary rich UI into the chat, but the UI is an opaque app the model neither inspects nor edits.

architecture

A tool declares a ui:// resource (text/html;profile=mcp-app) in _meta.ui.resourceUri; when the model calls the tool, the host fetches the HTML and renders it in a sandboxed iframe (often via a sandbox proxy). The View talks to the host over JSON-RPC on postMessage using MCP's own message shapes: ui/initialize, ui/notifications/tool-input(-partial), tool-result, tool-cancelled, size-changed, host-context-changed; the View can call server tools through the host, send ui/message, ui/open-link, ui/request-display-mode and ui/update-model-context. Hosts theme Views through standardized CSS variables and enforce CSP declared by the server.

performance

No published performance numbers; a View is an ordinary web page so its rendering/update rate is whatever the browser and the app code achieve.

adoption and upkeep

Adoption

The de facto standard for UI inside chat hosts: Claude and ChatGPT both render it, and it unifies MCP-UI and OpenAI's Apps SDK. Star count understates adoption; the spec repo is small but the SDK has 4.6M weekly downloads.

Used by: Claude, ChatGPT, VS Code, Goose, Postman, MCPJam, mcp-use inspector, Alpic playground, CopilotKit (MCP Apps renderer), json-render (@json-render/mcp)

Maintainability

Stable spec, active SDK, neutral governance; MCP-UI (the community predecessor) has gone quiet as the official extension took over.

Releases: SDK: v1.7.5 2026-07-23, v2.0.0 2026-09-08, v2.0.1 2026-09-24, v2.0.2/v2.0.3 2026-09-25; spec dated 2026-01-26 · Contributors: ~48 (ext-apps); MCP-UI ~20 · Recent: 56 commits on ext-apps main since 2026-07-11; MCP-UI shows no main-branch commits in that window (last client release 7.1.1, 2026-05-09) · Bus factor: high: foundation-governed, multiple vendors depend on it

weaknesses
and thc-scene

Overlap

Both put an interactive UI in front of a user on an agent's behalf and let the UI call back into the agent's tools.

What scene would be reinventing

Nothing in the UI model; scene's tooling should reuse MCP itself as the transport rather than a private socket protocol for remote agents.

The gap it leaves

A terminal renderer for MCP tool UIs. scene could be the host-side terminal view the fka.dev proposal and Claude Code #93973 are asking for, with readback and patching MCP Apps doesn't offer.

What to borrow

  • Expose scene as an MCP server (push/patch/keys/screen/state tools) so any MCP agent can drive it
  • Use the fka.dev extension shape: advertise a terminal-view resource next to HTML, negotiate catalogs in initialize capabilities
  • ui/update-model-context pattern: let the UI push a compact state summary to the model
  • CSP/predeclared-resource idea as a template for scene's command allowlist policy
sources
  1. modelcontextprotocol/ext-apps README github.com
  2. SEP-1865 MCP Apps spec (2026-01-26) github.com
  3. ext-apps LICENSE (MIT -> Apache-2.0 transition) github.com
  4. MCP-UI github.com
  5. fka.dev: MCP Apps Should Work in the Terminal Too blog.fka.dev
  6. Claude Code issue #93973 github.com
  7. Anthropic: Donating MCP to the AAIF (2025-12-09) anthropic.com
  8. npm downloads API api.npmjs.org