MCP Apps Kit - v0.5.0
    Preparing search index...

    Interface CSPConfig

    Content Security Policy configuration

    Unified CSP interface that maps to protocol-specific formats:

    • MCP Apps: _meta.ui.csp.{connectDomains, resourceDomains}
    • ChatGPT: _meta["openai/widgetCSP"].{connect_domains, resource_domains, ...}
    interface CSPConfig {
        connectDomains?: string[];
        frameDomains?: string[];
        redirectDomains?: string[];
        resourceDomains?: string[];
    }
    Index

    Properties

    connectDomains?: string[]

    Domains allowed for fetch/XHR/WebSocket connections. Maps to connect-src directive.

    ["https://api.example.com", "wss://realtime.example.com"]
    
    frameDomains?: string[]

    Allowed iframe origins. ChatGPT only - discouraged for security reasons.

    ["https://embed.example.com"]
    
    redirectDomains?: string[]

    Domains for openExternal without confirmation modal. ChatGPT only - ignored on MCP Apps.

    ["https://docs.example.com"]
    
    resourceDomains?: string[]

    Domains allowed for images, scripts, stylesheets, fonts. Maps to img-src, script-src, style-src, font-src directives.

    ["https://cdn.example.com", "https://fonts.googleapis.com"]