modelcontextprotocol/ext-apps: Escaping the Chatbox Prison
How the Model Context Protocol standardized interactive, sandboxed UIs to turn AI clients into fully-fledged operating systems.

Today we’re introducing the proposal for the MCP Apps Extension(SEP-1865) to standardize support for interactive user interfaces in the Model Context Protocol.
- MCP Apps replaces static markdown responses with interactive, stateful user interfaces rendered directly inside the chat stream.
- A strict double-iframe proxy architecture isolates untrusted server code from the host application to maintain rigorous security boundaries.
- The repository ships with built-in agent skills that allow language models to autonomously write, test, and migrate interactive applications to this open standard.
Escaping the Text-Only Straightjacket
The chatbox is a straightjacket. If you ask an AI agent to analyze a dataset, it prints a markdown table. If you ask it to build a dashboard, it writes a block of code and tells you to run it yourself. The primary interface for state-of-the-art intelligence is functionally identical to a 1970s teletype terminal.
The modelcontextprotocol/ext-apps repository provides the escape hatch. It standardizes how AI models can stream fully functional, interactive applications directly into the client. By introducing the ui:// URI scheme, tools can return rich HTML and JavaScript payloads instead of just JSON. This simple metadata shift transforms the AI client from a text renderer into a complete operating system.
| Feature | Standard MCP Tool | MCP App Tool |
|---|---|---|
| Protocol | JSON over Standard Out | ui:// URI scheme over JSON-RPC |
| Rendering | Host parses JSON | Host embeds sandboxed iframe |
| Interactivity | One-shot request/response | Persistent, bidirectional event loop |
| Security | Model trust | Strict CSP & window.top isolation |
The Double-Iframe Sandbox
Injecting untrusted HTML from a third-party server directly into a secure host application like Claude or VS Code is a terrifying prospect for any security engineer. The MCP Apps specification solves this with a rigid double-iframe proxy architecture.
The host embeds an outer sandbox on a completely separate origin. This outer sandbox is responsible for creating an inner iframe that houses the untrusted application code. Communication is restricted entirely to JSON-RPC over postMessage. To guarantee these boundaries hold, the SDK performs a self-test during initialization.
// examples/basic-host/src/sandbox.ts
try {
// Security self-test: ensure we cannot access the host
if (window.top && window.top !== window.self) {
const test = window.top.location.href;
throw new Error("Sandbox escape detected: able to access window.top");
}
} catch (e) {
if (e instanceof DOMException) {
// Expected outcome: CORS blocks access to window.top
console.log("Security boundary verified.");
}
}
The Agentic Trojan Horse
The most surprising directory in the repository is plugins/mcp-apps/skills/. The maintainers did not just build an SDK for human developers. They built a meta-layer of agent skills so models can autonomously write, test, and migrate proprietary applications to this new open standard.
This is a strategic move. By providing a skill like migrate-oai-app, the protocol actively encourages AI coding assistants to port existing closed-ecosystem apps into the open MCP format. It lowers the barrier to adoption to a single prompt.
Forging the Open Standard
Before this specification, ecosystem fragmentation was inevitable. Individual client developers were building custom ad-hoc logic to render specific JSON data returned by specialized tools. The collaboration between Anthropic engineers, OpenAI, and the creators of the original MCP-UI project merged these disparate efforts into SEP-1865.
By defining exactly how an AI client should handle a ui:// resource, the maintainers have ensured that developers only need to write their interactive tools once. The era of the text-only chatbox is officially coming to a close.