Skip to main content
The MCP Apps Conformance SDK lets you validate the server-side MCP Apps surface your server exposes through tools and ui:// resources. Use it when you want the same checks as the CLI’s apps conformance command, but inside your own test runner or CI pipeline.
This currently validates the server-side MCP Apps surface only. It does not prove full host-side SEP-1865 behavior such as ui/initialize, sandbox-proxy forwarding, or host notification ordering.

Import

Basic usage

For a stdio server:

Suite usage

MCPAppsConformanceSuiteConfig is shaped for CI matrices:

MCPAppsConformanceConfig

MCPAppsConformanceConfig extends the standard MCPServerConfig, so it accepts the same HTTP and stdio connection settings as MCPClientManager. Additional property: Example with custom headers and a focused check set:

Check ids

Available checks:
  • ui-tools-present
  • ui-tool-metadata-valid
  • ui-tool-input-schema-valid
  • ui-listed-resources-valid
  • ui-resources-readable
  • ui-resource-contents-valid
  • ui-resource-meta-valid

Result shape

run() returns an MCPAppsConformanceResult. Each MCPAppsCheckResult includes:
  • id
  • category
  • title
  • description
  • status
  • durationMs
  • optional details
  • optional warnings
  • optional error
MCPAppsConformanceSuite.run() returns an MCPAppsConformanceSuiteResult:

CI reporting

All three conformance domains use the same shared reporting helpers:
  • toConformanceReport(result) normalizes protocol, OAuth, and apps runs into a single report shape.
  • renderConformanceReportJUnitXml(report) emits redacted JUnit XML for CI dashboards.
  • renderConformanceReportJson(report) returns the redacted JSON-ready object for artifact uploads.
That makes the SDK and CLI JUnit output byte-identical for the same result.

What the runner validates

The current runner checks:
  1. At least one tool advertises MCP Apps UI metadata.
  2. Tool metadata uses a valid ui:// resource URI and valid visibility values.
  3. Tool inputSchema is a non-null JSON Schema object.
  4. Listed UI resources use ui:// and text/html;profile=mcp-app.
  5. Referenced UI resources are readable via resources/read.
  6. Resource payloads provide exactly one HTML document through text or blob.
  7. _meta.ui.csp, permissions, domain, and prefersBorder use valid shapes.

Notes

  • The runner always advertises the MCP Apps UI extension capability so servers do not hide their MCP Apps surface when custom clientCapabilities are supplied.
  • Deprecated _meta["ui/resourceUri"] is accepted but surfaced as a warning.
  • Tool name SHOULD validations (length, character set, uniqueness) surface as warnings, not failures.
  • HTML validation is intentionally lightweight. It verifies the expected MIME type and document-style HTML payload, not the full browser lifecycle.
  • For a runnable project that writes JUnit XML from Vitest, see examples/conformance/basic/.