Always enable MCP Apps UI; remove remote_mcp_ui_apps flag gate - #3348
Open
SamMorrowDrums wants to merge 3 commits into
Open
SamMorrowDrums wants to merge 3 commits into
SamMorrowDrums wants to merge 3 commits into
Conversation
The remote_mcp_ui_apps flag is fully rolled out on the hosted server, but the OSS server still defaulted it off. Make MCP Apps unconditional: - _meta.ui is always emitted, stripped only when the client explicitly does not advertise the io.modelcontextprotocol/ui capability - ui_get is always registered - write tools defer to MCP App forms by default (still opt-out via mcp_apps_disable_form_deferral) - remove MCPAppsFeatureFlag and its AllowedFeatureFlags/InsidersFeatureFlags entries - update tests and regenerate docs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
HTTP capability detection is not connected to metadata stripping, and stripping exposes the app-only ui_get tool to models.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Makes MCP Apps UI available by default by removing the legacy feature-flag gate.
Changes:
- Enables UI metadata,
ui_get, and form deferral by default. - Retains capability-based metadata stripping and deferral opt-out.
- Updates tests and generated documentation.
| File | Description |
|---|---|
README.md |
Documents UI-enabled tools. |
pkg/inventory/registry.go |
Removes the UI feature gate. |
pkg/inventory/registry_test.go |
Updates metadata behavior tests. |
pkg/inventory/builder.go |
Removes the inventory flag constant. |
pkg/http/server_test.go |
Updates feature-checker tests. |
pkg/http/handler_test.go |
Updates HTTP UI metadata tests. |
pkg/github/ui_tools.go |
Makes ui_get unconditional. |
pkg/github/ui_tools_test.go |
Verifies ui_get is ungated. |
pkg/github/ui_capability.go |
Defaults write tools to form deferral. |
pkg/github/ui_capability_test.go |
Updates deferral defaults. |
pkg/github/tools_validation_test.go |
Removes obsolete flag validation. |
pkg/github/server.go |
Updates UI resource documentation. |
pkg/github/pullrequests_test.go |
Updates PR form-routing tests. |
pkg/github/issues_test.go |
Updates issue form-routing tests. |
pkg/github/feature_flags.go |
Removes the legacy feature flag. |
pkg/github/feature_flags_test.go |
Updates flag resolution tests. |
pkg/github/feature_flags_benchmark_test.go |
Updates benchmark flag data. |
docs/server-configuration.md |
Documents always-on MCP Apps. |
docs/insiders-features.md |
Removes MCP Apps from insiders. |
docs/feature-flags.md |
Removes the retired flag. |
cmd/github-mcp-server/generate_docs.go |
Updates generated UI documentation logic. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+190
to
+191
| if shouldStripMCPAppsMetadata(ctx) { | ||
| tools = stripMCPAppsMetadata(tools) |
Comment on lines
+229
to
232
| func shouldStripMCPAppsMetadata(ctx context.Context) bool { | ||
| supported, ok := ghcontext.HasUISupport(ctx) | ||
| return ok && !supported | ||
| } |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
When a client does not advertise io.modelcontextprotocol/ui, stripping _meta.ui from ui_get turned it into an ordinary model-visible tool, violating its app-only contract. Now that ui_get is no longer feature gated, omit tools whose ui.visibility excludes "model" instead. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
tommaso-moro
approved these changes
Sep 29, 2026
tommaso-moro
self-requested a review
September 29, 2026 21:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Why
The
remote_mcp_ui_appsfeature flag is at 100% rollout on the hosted (remote) server, so MCP Apps is always on in production. In this repo it was still off by default unless enabled through--features/X-MCP-Featuresor insiders mode. This PR removes that difference so the OSS server matches the shipped remote behavior.What changed
_meta.uiis now always emitted. It's stripped only when the client explicitly doesn't advertise theio.modelcontextprotocol/uicapability, which is the spec-conformant check. The flag branch is gone fromToolsForRegistration,shouldStripMCPAppsMetadataandRequiredFeatures, andmcpAppsFeatureFlagis deleted.ui_get: no longer feature-gated. It is app-only (_meta.ui.visibility: ["app"]), so for clients without the UI capability, app-only tools are now left out entirely. Previously, stripping_meta.uiwould have exposed it as an ordinary model-visible tool.shouldDeferToFormno longer checksremote_mcp_ui_apps. Write tools hand off to their MCP App form by default for UI-capable clients.mcp_apps_disable_form_deferralis unchanged and remains the long-lived opt-out.MCPAppsFeatureFlagand its entries inAllowedFeatureFlagsandInsidersFeatureFlags.featureEnabledRule/featureDisabledRulestay because other flags use them.ui_get) are left out for clients without UI support and kept when support is present or unknown.script/generate-docs, so the README now lists the MCP App UI URIs andui_get, and theremote_mcp_ui_appssections are gone fromfeature-flags.md/insiders-features.md. The MCP Apps section inserver-configuration.mdnow says MCP Apps is always on.Follow-up for github/github-mcp-server-remote
After this merges, github/github-mcp-server-remote should:
github-mcp-serverdependency to pick this up;githubMcp.MCPAppsFeatureFlag(internal/featureflags/flags_test.go,pkg/mcp/inventory/inventory_test.go);remote_mcp_ui_appscomment ininternal/featureflags/flags.go.