The new package is real.
OpenAI published @openai/mcp-extensions and openai-mcp-extensions at version 0.1.0. The repository defines TypeScript support for MCP servers and apps, plus Python support for servers.[1] This pass fetched the npm package, inspected its archive, and found the advertised server, app, form, mention, resource, settings, and UI modules.
The extensions can add global and thread entrypoints, desktop file handlers, structured settings, custom display modes, composer mentions, model-context attachments, local file opening, and richer elicitation forms.[2] That is a serious jump from a tool that exists only when the model decides to call it.
The host can give an MCP app a front door. The front door still belongs to that host.
Host fit is part of the interface contract.
The published support table is uneven by design. Global and thread entrypoints work across desktop, web, iOS, and Android. File entrypoints, local file opening, file resources, and composer mentions are desktop-only at launch. OpenAI form elicitation works on desktop and web, but not on either mobile platform.[2]
A plugin that depends on a desktop file viewer is not broken on mobile. It needs a fallback. Return a normal resource link. Offer a read-only summary. Ask the user to continue on desktop only when the job truly requires desktop file access.
Capability negotiation is the socket test.
The MCP lifecycle already requires clients and servers to exchange protocol versions and capabilities before normal operation. Both sides must use only the capabilities they negotiated.[3] Host extensions should follow the same discipline. Check the advertised extension before sending its method or metadata.
Do not infer support from a product name, a recent version, or a successful server connection. Record the protocol version, host, platform, requested extension, advertised capability, and fallback used. That turns a vague compatibility report into a reproducible one.
File editing needs a version brake.
File entrypoints receive an opaque resource URI instead of a raw path. Reads and subscriptions go through MCP resource methods. The OpenAI write extension accepts an optional ifMatch value and can return saved, conflict, or too-large.[2]
Use the ETag. A file viewer that writes without a version check can overwrite a newer edit. Keep the opaque URI in the app. Let the server handle any work that truly needs the filesystem path. Then log the pre-write version, result, and returned version without exposing the path.
Portability needs a deliberate floor.
- Define the job with standard MCP tools, resources, prompts, or elicitation when they can carry it.
- Add the host extension for a better entrypoint, viewer, picker, or display mode.
- Check support at runtime and choose one named fallback.
- Test every platform you claim to support.
- Save the negotiated capability and result in the release receipt.
The extension can make the experience feel native. The baseline keeps the job reachable when the custom socket is absent.