Skip to content

Always enable MCP Apps UI; remove remote_mcp_ui_apps flag gate - #3348

Open
SamMorrowDrums wants to merge 3 commits into
mainfrom
sammorrowdrums-remove-ui-apps-flag-gate
Open

SamMorrowDrums wants to merge 3 commits into
mainfrom
sammorrowdrums-remove-ui-apps-flag-gate

Conversation

@SamMorrowDrums

@SamMorrowDrums SamMorrowDrums commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Why

The remote_mcp_ui_apps feature flag is at 100% rollout on the hosted (remote) server, so MCP Apps is always on in production. In this repo it was still off by default unless enabled through --features/X-MCP-Features or insiders mode. This PR removes that difference so the OSS server matches the shipped remote behavior.

What changed

  • Inventory: _meta.ui is now always emitted. It's stripped only when the client explicitly doesn't advertise the io.modelcontextprotocol/ui capability, which is the spec-conformant check. The flag branch is gone from ToolsForRegistration, shouldStripMCPAppsMetadata and RequiredFeatures, and mcpAppsFeatureFlag is deleted.
  • ui_get: no longer feature-gated. It is app-only (_meta.ui.visibility: ["app"]), so for clients without the UI capability, app-only tools are now left out entirely. Previously, stripping _meta.ui would have exposed it as an ordinary model-visible tool.
  • Form deferral: shouldDeferToForm no longer checks remote_mcp_ui_apps. Write tools hand off to their MCP App form by default for UI-capable clients. mcp_apps_disable_form_deferral is unchanged and remains the long-lived opt-out.
  • Feature flags: removed MCPAppsFeatureFlag and its entries in AllowedFeatureFlags and InsidersFeatureFlags. featureEnabledRule/featureDisabledRule stay because other flags use them.
  • Tests: updated for the new defaults, plus new tests showing app-only tools (including the real ui_get) are left out for clients without UI support and kept when support is present or unknown.
  • Docs: regenerated with script/generate-docs, so the README now lists the MCP App UI URIs and ui_get, and the remote_mcp_ui_apps sections are gone from feature-flags.md/insiders-features.md. The MCP Apps section in server-configuration.md now says MCP Apps is always on.

Follow-up for github/github-mcp-server-remote

After this merges, github/github-mcp-server-remote should:

  • bump its github-mcp-server dependency to pick this up;
  • update the tests that reference the now-deleted githubMcp.MCPAppsFeatureFlag (internal/featureflags/flags_test.go, pkg/mcp/inventory/inventory_test.go);
  • drop the stale remote_mcp_ui_apps comment in internal/featureflags/flags.go.

The remote_mcp_ui_apps flag is fully rolled out on the hosted server, but
the OSS server still defaulted it off. Make MCP Apps unconditional:

- _meta.ui is always emitted, stripped only when the client explicitly
  does not advertise the io.modelcontextprotocol/ui capability
- ui_get is always registered
- write tools defer to MCP App forms by default (still opt-out via
  mcp_apps_disable_form_deferral)
- remove MCPAppsFeatureFlag and its AllowedFeatureFlags/InsidersFeatureFlags
  entries
- update tests and regenerate docs

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner September 29, 2026 14:05
Copilot AI balanced review requested due to automatic review settings September 29, 2026 14:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

HTTP capability detection is not connected to metadata stripping, and stripping exposes the app-only ui_get tool to models.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Makes MCP Apps UI available by default by removing the legacy feature-flag gate.

Changes:

  • Enables UI metadata, ui_get, and form deferral by default.
  • Retains capability-based metadata stripping and deferral opt-out.
  • Updates tests and generated documentation.
File Description
README.md Documents UI-enabled tools.
pkg/​inventory/​registry.go Removes the UI feature gate.
pkg/​inventory/​registry_test.go Updates metadata behavior tests.
pkg/​inventory/​builder.go Removes the inventory flag constant.
pkg/​http/​server_test.go Updates feature-checker tests.
pkg/​http/​handler_test.go Updates HTTP UI metadata tests.
pkg/​github/​ui_tools.go Makes ui_get unconditional.
pkg/​github/​ui_tools_test.go Verifies ui_get is ungated.
pkg/​github/​ui_capability.go Defaults write tools to form deferral.
pkg/​github/​ui_capability_test.go Updates deferral defaults.
pkg/​github/​tools_validation_test.go Removes obsolete flag validation.
pkg/​github/​server.go Updates UI resource documentation.
pkg/​github/​pullrequests_test.go Updates PR form-routing tests.
pkg/​github/​issues_test.go Updates issue form-routing tests.
pkg/​github/​feature_flags.go Removes the legacy feature flag.
pkg/​github/​feature_flags_test.go Updates flag resolution tests.
pkg/​github/​feature_flags_benchmark_test.go Updates benchmark flag data.
docs/​server-configuration.md Documents always-on MCP Apps.
docs/​insiders-features.md Removes MCP Apps from insiders.
docs/​feature-flags.md Removes the retired flag.
cmd/​github-mcp-server/​generate_docs.go Updates generated UI documentation logic.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/inventory/registry.go
Comment on lines +190 to +191
if shouldStripMCPAppsMetadata(ctx) {
tools = stripMCPAppsMetadata(tools)
Comment thread pkg/inventory/registry.go
Comment on lines +229 to 232
func shouldStripMCPAppsMetadata(ctx context.Context) bool {
supported, ok := ghcontext.HasUISupport(ctx)
return ok && !supported
}
SamMorrowDrums and others added 2 commits September 29, 2026 16:15
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
When a client does not advertise io.modelcontextprotocol/ui, stripping
_meta.ui from ui_get turned it into an ordinary model-visible tool,
violating its app-only contract. Now that ui_get is no longer feature
gated, omit tools whose ui.visibility excludes "model" instead.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@tommaso-moro
tommaso-moro self-requested a review September 29, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants