“frame_domain_explanation_required”
A view declares origins it embeds in iframes, and the submission has no explanation of why the UI needs each one and what it shows. The three common causes: (1) _meta.ui.csp.frameDomains lists an origin; each one needs its own explanation in the submission. To tell: The doctor's resource-frames line lists the frame domains the scan will report. (2) The legacy _meta["openai/widgetCSP"].frame_domains lists one, which ChatGPT still reads. To tell: Read the view's _meta in the doctor's --json output (checks with id resource-legacy-csp). (3) The view embeds a third-party page (a video, a map, a document viewer); OpenAI limits those to cases where the embedded experience is essential and may review them further. To tell: The frame domain is not on your server's registrable domain. One command shows which: npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory.
Check your server now
npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory
Discovery only: no credential, no tool called. It prints the first broken step, whose it is, and the fix with its source, and shows the view in a sandboxed preview.
Who prints it
OpenAI's plugin submission portal, for each external frame domain the tool scan reports.
The three causes, and how to tell them apart
- Cause 1. _meta.ui.csp.frameDomains lists an origin; each one needs its own explanation in the submission.
The check flags it atresource-frames. The doctor's resource-frames line lists the frame domains the scan will report. - Cause 2. The legacy _meta["openai/widgetCSP"].frame_domains lists one, which ChatGPT still reads.
The check cannot see this one from outside: it happens inside the host or the portal. Read the view's _meta in the doctor's --json output (checks with id resource-legacy-csp). - Cause 3. The view embeds a third-party page (a video, a map, a document viewer); OpenAI limits those to cases where the embedded experience is essential and may review them further.
The check flags it atresource-frames. The frame domain is not on your server's registrable domain.
Sources and public reports
- frame_domain_explanation_required [source: OpenAI plugin submission errors, read 8 October 2026]
- iframes and embedded pages: your registrable domain is allowed with a justification; third parties only when essential [source: OpenAI plugin guidelines, MCP requirements, read 8 October 2026]
Keep checking
Other messages
- “MCP App renders blank”
- “Resource not found: ui://”
- “Tool has no UI”
- “Invalid ui.domain format”
- “ui.domain mismatch”
- “Refused to load the script”
- “annotations_required”
- “domain_verification_required”
- “screenshots_not_allowed”
- “Failed to fetch template”
Written 8 October 2026 from the sources above. The MCP Apps check · MCP Liveness · Terms · Privacy