MCP Apps are not WebMCP
SEP-1865 widgets live in a sandboxed iframe inside the agent. WebMCP lives on the page. Do not allowlist them as one surface.
Source: Model Context Protocol
MCP Apps are not WebMCP. SEP-1865 lets a server ship HTML (ui://, _meta.ui.resourceUri) that Claude and ChatGPT render in a sandboxed iframe. That is a widget inside the agent. WebMCP / ChatGPT site tools are the opposite shape: named actions on the live origin, human still looking at your URL bar. Classic MCP is still tools/list with no UI.
OpenAI documents MCP Apps as the portable layer and window.openai as ChatGPT extras. Chrome’s WebMCP vs MCP note is the other half: the agent is a guest on the page. Influzer keeps the catalogs separate — ~12,850 MCP servers (~383 with indexed tools) and ~1,330 WebMCP sites / ~7,750 page tools. An App is a label on a connector, not a third website class.
Why it matters: if money or session must stay on your origin, do not hide checkout in Claude’s iframe. If the human never opens your site, do not call it WebMCP. Full take: MCP Apps Are Not WebMCP. Pair with your website is not an MCP server and the Toronto packing list.