Glossary · term

MCP Apps

MCP Apps is an optional Model Context Protocol extension that lets an MCP server associate a tool with an interactive user interface. The server declares an HTML UI resource using a `ui://` URI, and a compatible host renders it in a sandboxed iframe. The view and host exchange structured messages over MCP's JSON-RPC base protocol. MCP Apps extends MCP; it is not a separate agent protocol or a guarantee that every MCP host can render interfaces.

Agents2025-11-21Wave 3 · 2025–26Maturity: 3/5

Origin and context

SEP-1865 was created on 21 November 2025 and became the stable 2026-01-26 MCP Apps specification on 26 January 2026. The specification says its design incorporates lessons from the community MCP-UI project and OpenAI's Apps SDK while defining one optional extension identifier and capability-negotiation path. The official announcement framed it as the first official MCP extension. By June 2026, Vercel documented an independent host implementation in its AI SDK, providing evidence of use outside the specification team.

Sources: s1, s2, s3

Why it matters

A normal tool result is often text or structured data that the host must present itself. MCP Apps lets a tool point to a reusable interface such as a chart, form or dashboard while preserving a protocol-level relationship between the tool, its data and the view. That can reduce host-specific adapters and make one app portable across supporting hosts. The separation also gives hosts a place to inspect resources, negotiate capability, restrict content security policy and decide which app-initiated actions require approval.

Sources: s1, s2, s3

Example

A weather server can expose a forecast tool whose metadata references `ui://weather/dashboard`. A supporting host reads the HTML resource, places it in a sandboxed iframe and passes the tool result to the view; the user can then change a city or refresh the chart. A host without MCP Apps support can fall back to the tool's ordinary content. By contrast, arbitrary HTML appended to a chat response is not automatically an MCP App: the resource declaration, negotiated extension capability and host-view messaging contract are defining parts.

Sources: s1, s3

Maturity and evidence

Maturity is rated 3. MCP Apps has a stable official specification, a reference SDK and documented support in an independent application framework. The extension is nevertheless young and optional, host coverage is still uneven, and the stable specification leaves several content types and advanced features for future work. Broader interoperable deployment could justify a later increase.

Sources: s1, s2, s3

Limits and open questions

Sandboxing and content security policy reduce risk but do not make a third-party view trustworthy. Hosts still need origin separation, capability checks, validation, user consent and controls on tool calls and external links. Apps may degrade to text when a host lacks the extension, and implementation differences can appear across hosts as the extension evolves. MCP Apps should also remain distinct from A2UI, AG-UI and WebMCP, which define different UI or browser interaction boundaries.

Sources: s1, s3

Related terms

References

Last updated: 2026-09-04

In the Skills Atlas

This term is also covered in the Skills Atlas as model context protocol skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as llm function calling skill.