“frame_domain_explanation_required”

A view declares origins it embeds in iframes, and the submission has no explanation of why the UI needs each one and what it shows. The three common causes: (1) _meta.ui.csp.frameDomains lists an origin; each one needs its own explanation in the submission. To tell: The doctor's resource-frames line lists the frame domains the scan will report. (2) The legacy _meta["openai/widgetCSP"].frame_domains lists one, which ChatGPT still reads. To tell: Read the view's _meta in the doctor's --json output (checks with id resource-legacy-csp). (3) The view embeds a third-party page (a video, a map, a document viewer); OpenAI limits those to cases where the embedded experience is essential and may review them further. To tell: The frame domain is not on your server's registrable domain. One command shows which: npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory.

Check your server now

npx --allow-git=root github:agentwares/mcp-apps-doctor https://your-server.example/mcp --host chatgpt-directory

Discovery only: no credential, no tool called. It prints the first broken step, whose it is, and the fix with its source, and shows the view in a sandboxed preview.

Who prints it

OpenAI's plugin submission portal, for each external frame domain the tool scan reports.

The three causes, and how to tell them apart

  1. Cause 1. _meta.ui.csp.frameDomains lists an origin; each one needs its own explanation in the submission.
    The check flags it at resource-frames. The doctor's resource-frames line lists the frame domains the scan will report.
  2. Cause 2. The legacy _meta["openai/widgetCSP"].frame_domains lists one, which ChatGPT still reads.
    The check cannot see this one from outside: it happens inside the host or the portal. Read the view's _meta in the doctor's --json output (checks with id resource-legacy-csp).
  3. Cause 3. The view embeds a third-party page (a video, a map, a document viewer); OpenAI limits those to cases where the embedded experience is essential and may review them further.
    The check flags it at resource-frames. The frame domain is not on your server's registrable domain.

Sources and public reports

Keep checking

agentcheck's free watch checks this server every hour and emails when it stops answering or its tool list changes; no account. It does not re-read the ui:// views.

mcpcheck Server Pro diffs the server's tool catalog every night — removed tools, tightened schemas, changed descriptions — with the client-compat matrix, OAuth conformance and 90 days of history; $49 a server a month, first run free. It does not re-run these MCP Apps checks.

Other messages

Written 8 October 2026 from the sources above. The MCP Apps check · MCP Liveness · Terms · Privacy