modelcontextprotocol/ext-apps: Escaping the Chatbox Prison

How the Model Context Protocol standardized interactive, sandboxed UIs to turn AI clients into fully-fledged operating systems.

8 min read • View on GitHub • More from modelcontextprotocol

A classic mechanical teletype machine bursting open to reveal complex, glowing clockwork mechanisms and interactive control panels. This represents the transition from a rigid text-only interface to rich, dynamic applications.
For years, the universal interface for AI has been a linear stream of text. MCP Apps shatters that limitation.

Today we’re introducing the proposal for the MCP Apps Extension(SEP-1865) to standardize support for interactive user interfaces in the Model Context Protocol.

Anton Pidkuiko (Maintainer), Olivier Chafik (Maintainer), et al., SEP Authors / Maintainers · Model Context Protocol Blog
Key Takeaways

Escaping the Text-Only Straightjacket

The chatbox is a straightjacket. If you ask an AI agent to analyze a dataset, it prints a markdown table. If you ask it to build a dashboard, it writes a block of code and tells you to run it yourself. The primary interface for state-of-the-art intelligence is functionally identical to a 1970s teletype terminal.

The modelcontextprotocol/ext-apps repository provides the escape hatch. It standardizes how AI models can stream fully functional, interactive applications directly into the client. By introducing the ui:// URI scheme, tools can return rich HTML and JavaScript payloads instead of just JSON. This simple metadata shift transforms the AI client from a text renderer into a complete operating system.

FeatureStandard MCP ToolMCP App Tool
ProtocolJSON over Standard Outui:// URI scheme over JSON-RPC
RenderingHost parses JSONHost embeds sandboxed iframe
InteractivityOne-shot request/responsePersistent, bidirectional event loop
SecurityModel trustStrict CSP & window.top isolation

The Double-Iframe Sandbox

Injecting untrusted HTML from a third-party server directly into a secure host application like Claude or VS Code is a terrifying prospect for any security engineer. The MCP Apps specification solves this with a rigid double-iframe proxy architecture.

The Proxy architecture ensures that the host application never directly executes untrusted UI code.

The host embeds an outer sandbox on a completely separate origin. This outer sandbox is responsible for creating an inner iframe that houses the untrusted application code. Communication is restricted entirely to JSON-RPC over postMessage. To guarantee these boundaries hold, the SDK performs a self-test during initialization.

// examples/basic-host/src/sandbox.ts
try {
  // Security self-test: ensure we cannot access the host
  if (window.top && window.top !== window.self) {
    const test = window.top.location.href;
    throw new Error("Sandbox escape detected: able to access window.top");
  }
} catch (e) {
  if (e instanceof DOMException) {
    // Expected outcome: CORS blocks access to window.top
    console.log("Security boundary verified.");
  }
}

The Agentic Trojan Horse

The most surprising directory in the repository is plugins/mcp-apps/skills/. The maintainers did not just build an SDK for human developers. They built a meta-layer of agent skills so models can autonomously write, test, and migrate proprietary applications to this new open standard.

A close-up of a human hand holding a drafting compass over a blueprint, connected by a taut thread to a mechanical robot hand assembling a miniature UI dashboard out of physical gears and glass.
The repository provides the tools for AI agents to construct the very interfaces humans use to interact with them.

This is a strategic move. By providing a skill like migrate-oai-app, the protocol actively encourages AI coding assistants to port existing closed-ecosystem apps into the open MCP format. It lowers the barrier to adoption to a single prompt.

Forging the Open Standard

Before this specification, ecosystem fragmentation was inevitable. Individual client developers were building custom ad-hoc logic to render specific JSON data returned by specialized tools. The collaboration between Anthropic engineers, OpenAI, and the creators of the original MCP-UI project merged these disparate efforts into SEP-1865.

A stippled ink hedcut portrait of Olivier Chafik.

By defining exactly how an AI client should handle a ui:// resource, the maintainers have ensured that developers only need to write their interactive tools once. The era of the text-only chatbox is officially coming to a close.