At DevDay on September 29, 2026, OpenAI announced Plugin Extensions, which expand ChatGPT plugins into something closer to full apps. Developers can now open a plugin full-screen from the sidebar, show an interface beside the conversation, and let users view and edit files in custom formats.
With support for MCP Events, changes in external services, such as an updated document or an incoming message, can also trigger processing in ChatGPT. Plugins that once simply called external tools from a conversation are growing into something more app-like, with their own screens and event-driven automation.
However, what was announced is not a single, giant "ChatGPT app specification." It combines several distinct mechanisms: public specifications that work across multiple environments, ChatGPT-specific UI features, a system for receiving events from external services, and plugin publishing and permission management.
Looking at each role separately clarifies which parts developers can reuse outside ChatGPT, which parts they add specifically for ChatGPT, and how permissions differ for users and administrators to check.
The New Plugins, Viewed as Four Mechanisms
The plugin extensions can be broadly organized into four categories: shared UI, ChatGPT-specific UI extensions, event integration, and distribution and permission management.
| Category | Main role | What to check when developing or deploying |
|---|---|---|
| Shared UI | Uses MCP Apps to link tools with a UI, with components inside an iframe communicating with the host | Build here any UI you want to use in other environments that support MCP Apps |
| ChatGPT-specific UI extensions | Add sidebar apps, conversation-side panels, settings screens, file viewing and editing, and more | Check whether you need ChatGPT-specific features and whether the screen you'll use provides them |
| Event integration | Uses MCP Events to subscribe to changes in external services and deliver them to ChatGPT via webhooks | Requires storing subscription data, HTTPS connectivity, and handling duplicate deliveries and expirations |
| Distribution and permission management | Manages plugin review and publishing, sharing within a workspace, and authentication and operation permissions for external apps | Consider installation, connection to external services, sharing, and publishing separately |
OpenAI does not officially describe these as "four layers." This is our own organization of the published materials on UI, Extensions, MCP Events, and publishing and permission management, sorted by role.
The key point is that adding a screen and automatically starting processing when an external service changes are separate features.
Even if you build an easy-to-use interface, automatically receiving changes from an external service requires a separate mechanism such as MCP Events. Conversely, a feature that receives events and processes them automatically does not necessarily need a dedicated interface.
Developers can combine only the features they need for their use case.
Even with a ChatGPT-Specific Interface, Core Functionality Shouldn't Depend on the UI
When adding a custom UI to a plugin, OpenAI first recommends using the public specification, MCP Apps.
MCP Apps links the tools provided by an MCP server with UI resources. In ChatGPT, UI components run inside an isolated iframe and exchange tool inputs, execution results, and context to pass to the model through JSON-RPC over postMessage.
This mechanism is not exclusive to ChatGPT; it can also be used with other hosts that support MCP Apps.
OpenAI recommends a design in which Plugin Extensions are added on top of this only when ChatGPT-specific features are needed.
The newly released Plugin Extensions include mainly the following features:
- "Sidebar apps," which open a plugin full-screen from the sidebar
- "Conversation panels," which show an app beside the conversation
- "Plugin settings," which let users change plugin-specific settings within ChatGPT
- "File viewers and editors," which open and edit files in custom formats
- "Display modes," which specify how content appears within a conversation
- "Deep links," which jump directly to a specific page inside an app
- "Model-App Context," which shares context in both directions between ChatGPT and the app
- "Composer mentions," which let users search for and reference items inside a plugin from the input box
- "Rich forms," which accept input from choices that include images and other media
For example, with Sidebar apps, a plugin can be launched from ChatGPT's sidebar and used as a full-screen app. With Conversation panels, users can work in the plugin's screen beside the conversation while keeping their chat with ChatGPT.
With File viewers and editors, a plugin registers the file extensions it supports, so that opening a file in that format displays its own viewer or editing screen.
At the same time, OpenAI asks that the MCP tools themselves remain usable without a dedicated UI.
That's because not every ChatGPT screen or MCP client can display custom components. Ideally, the design lets the model complete the necessary work using only the structured data the tool returns, even in environments where the UI can't be opened.
With this structure, ChatGPT can offer a dedicated interface while the underlying MCP tools remain reusable in other supported environments.
Availability also varies.
OpenAI says it will bring the web version of Plugin Extensions to ChatGPT Free and Go soon, and that this will not affect existing plugin functionality. Composer Mentions, which lets users search for and reference files and other items inside a plugin from the input box, is limited to the ChatGPT desktop app.
In other words, not all nine announced features are immediately available to every user from the same screen.
Triggering Actions from External Changes Requires a Subscription
MCP Events is the mechanism for starting processing in ChatGPT when something happens in an external service.
Suppose a user says, "When a new comment is added to this document, review it."
First, ChatGPT checks what events the connected MCP server offers. It then subscribes to the target event and passes the MCP server a callback URL and information for signing.
When a matching event occurs, such as a comment being added to the document, the MCP server sends a signed webhook to that URL. ChatGPT receives the event in the conversation that subscribed to it and handles it in the way the user specified in advance.
So this isn't merely "sending notifications to ChatGPT"; the user specifies what to monitor, and the subscription is created and maintained between ChatGPT and the MCP server.
There are several implementation requirements.
To use MCP Events in ChatGPT, the server must support MCP 2.0 protocol version 2026-07-28. The server side must store subscription information persistently and be able to connect to external callback URLs over HTTPS.
It must also implement three methods:
events/list, which returns the available eventsevents/subscribe, which creates or updates a subscriptionevents/unsubscribe, which cancels a subscription
Webhooks must be signed so that ChatGPT can verify the sender and the content.
In actual operation, developers also have to account for cases where the same event arrives multiple times or out of order. OpenAI likewise asks that write tools be idempotent, so that repeating the same operation does not cause duplicate changes.
The supported MCP Events features are also limited.
Of the MCP Events specification, which is still at the draft stage, OpenAI currently supports webhook delivery and callback verification. It does not support polling or streaming, and the gap and terminated notifications, which signal missed events or ended subscriptions, are not available either.
So simply being "MCP Events-compatible" does not mean every notification method in the MCP Events specification can be used in ChatGPT.
In addition, which events to offer is decided by each plugin's MCP server. Not every plugin will expose document updates or incoming messages as events.
Installing a Plugin Doesn't Automatically Expand Access to External Services
Even as UI and automation features grow, access permissions for external services are managed separately.
Installing a plugin does not automatically complete the connection or authentication for the external apps it includes.
Depending on the service, separate conditions apply, such as:
- Account authentication by the user
- Connections configured by an administrator
- Which operations can read or write
- Approval for each operation
- Permitted accounts and domains
- Sync targets
A plugin can use only what falls within the permissions that the user or workspace already has.
Publishing a plugin also involves multiple stages.
Developers upload the finished plugin as a ZIP, review and fix any issues flagged by automated checks, and then submit it for review. Only one review can be in progress per plugin at a time, and even after approval, the developer decides when to actually publish it.
Once published, OpenAI scans the hosted MCP server every day.
If tools are changed on the server side, and the changes pass the automated checks, the update can take effect without submitting a new plugin ZIP. Developers can also request a rescan manually.
On the other hand, changes to the plugin's metadata, assets, or bundled skills require uploading a new ZIP and going through the necessary review.
In other words, updates to the tools running on the MCP server and updates to the distributed plugin package itself are managed through separate mechanisms.
ChatGPT Sites Adds a Way to Publish MCP Tools
ChatGPT Sites also gained a way to host an MCP server within a Site and use its tools as a plugin.
For example, you could add an MCP tool to a Site that holds an internal handbook and build a plugin that searches and retrieves information from it.
According to OpenAI's help documentation, hosting plugins on a Site is itself available on all plans. However, the features announced at DevDay are being rolled out in stages, so they may not yet appear in some accounts.
Sharing a Site or plugin within an organization on Business or Enterprise also requires permission settings from an administrator.
On Enterprise, for example, separate permissions govern:
- Whether plugins can be used
- Whether plugins can be uploaded
- Whether MCP-based plugins can be created
- Whether they can be shared with other members
- Whether they can be published to the workspace directory
The people a plugin is shared with must also have access to the necessary Site, install the plugin themselves, and complete the connections to the required external services.
Also, on individual accounts such as Pro, it is currently not possible to share a plugin created on a Site directly with other ChatGPT users through invitations or share links.
Sharing the Site itself and sharing a plugin created from it are also separate operations.
Look at What You Can Actually Use, Not Just What Was Announced
With this update, ChatGPT plugins now have the features needed to build app-like experiences: custom UI, file editing, automatic event-driven execution, and publishing and sharing.
However, features that exist in the specification are not the same as features currently available in ChatGPT.
Some Plugin Extensions are still rolling out, and MCP Events does not support the entire draft specification. Moreover, being able to install a plugin is a separate matter from having the operation permissions required on the connected service.
What matters in development is not increasing the number of full-screen views or dedicated panels.
Can the necessary work be completed with the MCP tools alone, even in environments where the UI can't be displayed? Can events be processed safely even if they arrive in duplicate or out of order? Can users understand which permissions they are handing to which external services?
If these conditions are met, ChatGPT plugins can evolve from a way of adding features to a conversation into a foundation for continuously handling work that spans multiple services.
