Host and contribution support

Choose the host and contribution before building a package. A target or optional SDK interface describes a contract; it does not prove that a host installs the capability. Feature-detect optional APIs and preserve the distinction between permission denial and unavailable authority.

Read the status

  • Implemented means the host has a concrete execution or projection path. It does not mean a particular installed release passed live acceptance.
  • Declared means the descriptor accepts the shape, but a complete consumer path has not been established. Do not advertise it as executable support.
  • Rejected means activation rejects this package profile.
  • Host-dependent means the capability must be detected and tested in the selected host. A compiled target does not supply the capability itself.

Choose a host and contribution

This matrix describes implementation at the October 3, 2026 source baseline. Installation still requires compatible SDK and host ranges, an exact verified release, and the relevant grants.

Contribution or capabilityDesktopMobileOther execution or assistant hostsContract and verification boundary
ui.surface and lifecycleImplementedImplemented for declared mobile placementsHost-dependentSurfaces and lifecycle; verify the exact placement with Test Lab
chat.block, inline renderers and link unfurlsImplemented host projectionsHost-dependentNo generic external-host promiseChat rendering, inline rendering, link unfurls
Package toolImplemented under declared runtime and effectsHost-dependentTarget-specific executionHeadless targets; reviewed host actions are distinct from package MCP tools
agent.skillVerified skill projectionHost-dependentNo automatic external-host installationManifest and targets; package assets and human grants remain authoritative
Specialist and workflow contributionsHost-managed projectionHost-dependentOwning runtime decides admissionPlatform API; a package declaration does not grant invocation authority
Package-runtime mcp.server and mcp.toolImplemented fresh QuickJS executionRejected by the non-desktop MCP projectionNo generic package consumer pathPackaged MCP servers; exact selected-specialist grants and bounded read-only storage
Streamable HTTP package MCPImplemented public HTTPS, no auth, header credentials or OAuthRejected by the non-desktop MCP projectionNo generic package consumer pathPackaged MCP servers; verified endpoint, protocol, credential and consumer identity
Packaged stdio MCPRejectedRejectedRejected as a package contributionNo reviewed package-process or credential-injection lane; user-configured MCP is a separate feature
mcp.prompt, mcp.resource, mcp.resource-template, mcp.appDeclaredNo executable package pathNo executable package pathGeneric MCP prompts/resources do not establish package-owned app rendering
Package events and activity sourcesImplemented host-local contractsHost-dependentNo external webhook or agent-wake promiseSurface events, activity; these are separate from external MCP Events
JSON storageImplemented scoped storageHost-dependentHost-dependentStorage; verify revisions and scope in the selected profile
Private files, SQLite and vector storageOptional native capabilityUnavailable native profileUnavailable native profilePrivate storage; browser storage does not emulate these APIs
Selected files, Git, snapshots, terminal and local servicesOptional native capabilityNo desktop capability promiseNo desktop capability promisePlatform API, local services; explicit handles, grants and operation fences apply
HTTP, credentials and secure sessionsOptional governed host capabilityHost-dependentHost-dependentPlatform API; HTTP credentials and session JSON have different guest visibility
plots, home, integrationsReserved interfaces, not installedReserved interfaces, not installedReserved interfaces, not installedSDK reference; an optional type is not an implementation
worker, node, workflow-host, quickjs target buildsTarget graphs can be authoredTarget graphs can be authoredRuntime-specificBuild and Module Federation; independent compilation is not live runtime acceptance

An unsupported host must not ignore a declared capability and report success. For optional APIs, test the capability before offering an action. For protected operations, the owning service or host must enforce authority even when the UI has already checked it.

Pin a published toolchain

On October 3, 2026, npm's stable SDK and initializer were both 0.20.0. The source baseline was 0.21.0; source changes are not proof of publication. Use the same exact version for the initializer and SDK. Check current versions before upgrading:

pnpm view @theaiplatform/miniapp-sdk dist-tags --json
pnpm view create-tap-miniapp dist-tags --json

The 0.20.0 SDK and initializer passed clean-room import, declaration, deterministic scaffolding, test-tooling and federated-build verification using the public npm registry on Node 26.4.0. This verifies the published development toolchain. It does not establish a native application and SDK release pair or acceptance in ChatGPT, Codex or Claude.

See Testing miniapps for the pinned runner dependencies. A Test Lab receipt must identify the native host version, installed package/release, profile, artifact and completed cases. Keep fixture-backed and live service results separate. Do not label an untested host/version cell as passed.

Select an acceptance profile

For every advertised host and contribution, verify a successful operation, permission denial, unavailable authority, revocation and release replacement. For stateful apps, also verify remounts, conflicting revisions and actor scope. For remote MCP, verify the exact transport and authentication mode.

External-host use requires a separate supported integration profile. An MCP tool result or resource alone does not install the native SDK, create a TAP workspace authority, or make every miniapp portable.