Add MCP App Support to a Web App
Add MCP App support to an existing web application so it works both as a standalone web app and as an MCP App that renders inline in MCP-enabled hosts like Claude Desktop — from a single codebase.
How It Works
The existing web app stays intact. A thin initialization layer detects whether the app is running inside an MCP host or as a regular web page, and fetches parameters from the appropriate source. A new MCP server wraps the app's bundled HTML as a resource and registers a tool to display it.
The app's rendering logic is shared — only the data source changes.
Getting Reference Code
Clone the SDK repository for working examples and API documentation:
API Reference (Source Files)
Read JSDoc documentation directly from /tmp/mcp-ext-apps/src/:
Framework Templates
Learn and adapt from /tmp/mcp-ext-apps/examples/basic-server-{framework}/:
Reference Examples
Step 1: Analyze the Existing Web App
Before writing any code, examine the existing web app to plan what needs to change.
What to Investigate
- Data sources — How does the app get its data? (URL params, API calls, props, hardcoded, localStorage)
- External dependencies — CDN scripts, fonts, API endpoints, iframe embeds, WebSocket connections
- Build system — Current bundler (Webpack, Vite, Rollup, none), framework (React, Vue, vanilla), entry points
- User interactions — Does the app have inputs/forms that should map to tool parameters?
- Runtime detection — How to tell if the app is running inside an MCP host (e.g., check the current origin, a query param, or whether
window.parent !== window)
Present findings to the user and confirm the approach.
Data Source Mapping
In hybrid mode, the app keeps its existing data sources for standalone use and adds MCP equivalents:
Step 2: Investigate CSP Requirements
MCP Apps HTML runs in a sandboxed iframe with no same-origin server. Every external origin must be declared in CSP — missing origins fail silently.
Before writing any code, build the app and investigate all origins it references:
- Build the app using the existing build command
- Search the resulting HTML, CSS, and JS for every origin (not just "external" origins — every network request will need CSP approval)
- For each origin found, trace back to source:
- If it comes from a constant → universal (same in dev and prod)
- If it comes from an env var or conditional → note the mechanism and identify both dev and prod values
- Check for third-party libraries that may make their own requests (analytics, error tracking, etc.)
Document your findings as three lists, and note for each origin whether it's universal, dev-only, or prod-only:
- resourceDomains: origins serving images, fonts, styles, scripts
- connectDomains: origins for API/fetch requests
- frameDomains: origins for nested iframes
If no origins are found, the app may not need custom CSP domains.
Step 3: Set Up the MCP Server
Create a new MCP server with tool and resource registration. This wraps the existing web app for MCP hosts.
Dependencies
Use npm install so the package manager resolves versions; ext-apps 2.x needs
the split base MCP SDK packages at ^2.0.0 (@modelcontextprotocol/core comes
in transitively). Do not add the legacy @modelcontextprotocol/sdk v1 package
or substitute unpublished local packages.
Server Code
Create server.ts:
Package Scripts
Add to package.json:
Step 4: Adapt the Build Pipeline
The MCP App build must produce a single HTML file using vite-plugin-singlefile. The standalone web app build stays unchanged.
Vite Configuration
Create or update vite.config.ts. If the app already uses Vite, add vite-plugin-singlefile and a separate entry point for the MCP App build. If it uses another bundler, add a Vite config alongside for the MCP App build only.
Add framework-specific Vite plugins as needed (e.g., @vitejs/plugin-react for React, @vitejs/plugin-vue for Vue).
HTML Entry Point
Create mcp-app.html as a separate entry point for the MCP App build. This can point to the same app code — the runtime detection handles the rest:
Two-Phase Build
- Vite bundles the UI →
dist/mcp-app.html(single file with all assets inlined) - Server is compiled separately (TypeScript → JavaScript)
The standalone web app continues to build and deploy as before.
Step 5: Add MCP App Initialization Alongside Existing Logic
This is the core step. Instead of replacing the app's data sources, add an alternative initialization path for MCP mode. The app detects its environment at startup and reads parameters from the right source.
The Hybrid Pattern
URL Parameters (Hybrid)
API Calls (Hybrid)
Or keep direct API calls in both modes with CSP connectDomains:
localStorage / sessionStorage (Hybrid)
Complete Hybrid Example
Step 6: Add Host Styling Integration (MCP Mode Only)
When running as an MCP App, integrate with host styling for theme consistency. Use CSS variable fallbacks so the app looks correct in both modes.
Vanilla JS — use helper functions:
React — use hooks:
Using variables in CSS — use var() with fallbacks so standalone mode still looks right:
Key variable groups: --color-background-*, --color-text-*, --color-border-*, --font-sans, --font-mono, --font-text-*-size, --font-heading-*-size, --border-radius-*. See src/spec.types.ts for the full list.
Optional Enhancements
App-Only Helper Tools
For data the UI needs to poll or fetch that the model doesn't need to call directly:
The UI calls these via
app.callServerTool({ name: "refresh-data", arguments: {} }).
Streaming Partial Input
For large tool inputs, use ontoolinputpartial to show progress during LLM generation:
Fullscreen Mode
Text Fallback
Always provide a content array for non-UI hosts:
Common Mistakes to Avoid
- Forgetting CSP declarations for external origins — fails silently in the sandboxed iframe
- Using
localStorage/sessionStoragein MCP mode — not available in sandboxed iframe; use fallbacks or pass viastructuredContent - Missing
vite-plugin-singlefile— external assets won't load in the iframe - Registering handlers after
connect()— register ALL handlers BEFORE callingapp.connect() - Hardcoding styles without fallbacks — use host CSS variables with
var(..., fallback)so both modes look correct - Not handling safe area insets — always apply
ctx.safeAreaInsetsinonhostcontextchanged - Forgetting text
contentfallback — always providecontentarray for non-UI hosts - Forgetting resource registration — the tool references a
resourceUrithat must have a matching resource - Replacing standalone logic instead of branching — keep the original data sources intact; add the MCP path alongside them
Testing
Using basic-host
Test the MCP App mode with the basic-host example:
Configure SERVERS with a JSON array of your server URLs (default: http://localhost:3001/mcp).
Verify
- MCP mode: App loads in basic-host without console errors
ontoolinputhandler fires with tool argumentsontoolresulthandler fires with tool result- Host styling (theme, fonts, colors) applies correctly
- External resources load (if CSP domains are configured)
- Standalone mode: App still works when opened directly in a browser


