Apps SDK Examples GallerySAFE
Example apps for the Apps SDK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE)
This repository showcases example UI components to be used with the Apps SDK, as well as example MCP servers that expose a collection of components as tools. It is meant to be used as a starting point and source of inspiration to build your own apps for ChatGPT.
Note: If you are on Chrome and have recently updated to version 142, you will need to disable the `local-network-access` flag to see the widget UI.
How to disable it:
- Go to chrome://flags/
- Find #local-network-access-check
- Set it to Disabled
⚠️ Note 🚨 Make sure to restart Chrome after changing this flag for the update to take effect.
MCP + Apps SDK overview
The Model Context Protocol (MCP) is an open specification for connecting large language model clients to external tools, data, and user interfaces. An MCP server exposes tools that a model can call during a conversation and returns results according to the tool contracts. Those results can include extra metadata—such as inline HTML—that the Apps SDK uses to render rich UI components (widgets) alongside assistant messages.
Within the Apps SDK, MCP keeps the server, model, and UI in sync. By standardizing the wire format, authentication, and metadata, it lets ChatGPT reason about your connector the same way it reasons about built-in tools. A minimal MCP integration for Apps SDK implements three capabilities:
- List tools – Your server advertises the tools it supports, including their JSON Schema input/output contracts and optional annotations (for example,
readOnlyHint). - Call tools – When a model selects a tool, it issues a
call_toolrequest with arguments that match the user intent. Your server executes the action and returns structured content the model can parse. - Return widgets –
73c52aca9e6cOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pizzaz-mcp-node --env AUTHORIZATION_SERVER_URL=${AUTHORIZATION_SERVER_URL} -- npx -y [email protected]{
"mcpServers": {
"pizzaz-mcp-node": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AUTHORIZATION_SERVER_URL": "${AUTHORIZATION_SERVER_URL}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Avocados | read | Perfectly ripe |
Bread | read | Fresh and toasty |
Eggs | read | Breakfast basics |
Tomatoes | read | Juicy and bright |
kitchen-sink-refresh | read | Lightweight echo tool called from the widget via callTool. |
kitchen-sink-show | read | Returns the widget template with the provided message. |
kitchen_sink_refresh | read | # Simple echo tool used by the widget via window.openai.callTool. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
.pre-commit-config.yaml
} from "../../src/cards-against-ai/types.js";
The server listens on `http://127.0.0.1:8000` and exposes the standard MCP endpoint at `GET /mcp`.
This boots a FastAPI app with uvicorn on `http://127.0.0.1:8000` (equivalently `uvicorn pizzaz_server_python.main:app --port 8000`). The endpoints mirror the Node demo:
This boots a FastAPI app with uvicorn on `http://127.0.0.1:8000` (equivalently
fastmcp, mcp, pydantic, python-dotenv, uvicorn
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, cors, dotenv, express, zod, @types/cors, @types/express
@modelcontextprotocol/sdk, zod, tsx, typescript
fastapi, mcp, uvicorn
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, cors, express, zod, @types/cors, @types/express, tsx
This example shows how to thread state across conversation turns by pairing `_meta["widgetSessionId"]` with `window.openai.widgetState`. The Python server ships a simple `add_to_cart` tool as an examp
ngrok-v3-stable-linux-amd64.tgz
src/cards-against-ai/assets/card-back-pattern.png
Gates applied: no_behavioural_pass.
73c52aca9e6cfull audit observations/trust-audit/mcp-server/openai__apps-sdk-examples-gallery.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 73c52aca9e6c | SAFE | B | 89 | source changed, verdict held |
Questions
What is the Apps SDK Examples Gallery MCP server?
Example apps for the Apps SDK
What tools does Apps SDK Examples Gallery expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Apps SDK Examples Gallery safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Apps SDK Examples Gallery need?
It reads AUTHORIZATION_SERVER_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Apps SDK Examples Gallery run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as pizzaz-mcp-node at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (73c52aca9e6c), read on 2026-09-23. The repository is watched and re-audited when it changes.