Published:
MCP Events in ChatGPT: your AI assistant now reacts on its own to what happens in your systems
In short: MCP Events is a draft extension to the Model Context Protocol that lets an MCP server actively notify an AI client when something happens, instead of waiting to be asked. Since DevDay (29 September 2026), OpenAI supports part of it in ChatGPT through signed webhooks. The specification is not yet an official MCP standard and may still change.
Until now, MCP was request and response at its core: a user asks, the AI assistant calls a tool, the server answers. If you wanted an assistant to react to a new ticket or a comment on a document, the client had to keep asking or hold a connection open. MCP Events reverses that: the server speaks up when something happens. With ChatGPT, a major client vendor is now putting it into production, as part of the plugin automations it announced at DevDay 2026.
What exactly is MCP Events?
The design comes from the MCP project's Triggers and Events Working Group, led by Clare Liguori (Amazon Web Services) and Peter Alexander (Anthropic). The group's charter dates from 24 March 2026; its mission is to define how MCP servers proactively notify clients of state changes. The MCP roadmap of 22 August lists server-initiated events — webhooks and channels, so clients are not left polling — under one of its five priority areas.
In the design sketch, a server uses events/list to describe the events it offers, each with filters and a payload schema. The draft defines three delivery modes, none of them mandatory:
- Poll (
events/poll) — the client periodically asks for new events. - Push (
events/stream) — events arrive over a long-lived request. - Webhook (
events/subscribe) — the client registers an https address and the server posts each event there, signed according to Standard Webhooks.
The status matters: the working group's repository explicitly calls itself experimental and states that its contents do not represent official MCP specifications or recommendations. The design sketch is marked “Draft proposal” and the working group charter still lists the corresponding proposal as “Ideating”.
What has OpenAI actually shipped?
According to OpenAI's developer documentation, ChatGPT supports only the webhook mode plus callback verification. Polling, streaming and the draft's gap and terminated control notifications are not supported. The user tells ChatGPT what to monitor and what to do when an update arrives; ChatGPT then subscribes through the MCP server, supplying a callback URL and a signing secret.
The server-side requirements are specific:
- MCP 2.0, protocol version
2026-07-28— the stateless specification we covered earlier. - Three methods:
events/list,events/subscribeandevents/unsubscribe, on the same authenticated endpoint as your tools. - Persistent subscription storage and outbound HTTPS to callback URLs; block private and local addresses and do not follow redirects.
- One event per request, at most 256 KiB, signed using Standard Webhooks. Events can arrive out of order.
The feature is available in Work chats on ChatGPT web, in the desktop app with Cloud selected, and with dots, the always-on agents OpenAI presented the same day. Workspace controls for plugins and event-triggered tasks apply.
What is the risk of an AI that acts on its own?
Two things deserve attention. The first is revocation. The design sketch requires a server to check permissions when a subscription is created and to re-verify them periodically afterwards — without a fixed interval — and to end a subscription with a signed terminated message when access is lost. That is exactly the message ChatGPT does not support. In an analysis published on 1 October, identity vendor WorkOS points out that a subscription therefore behaves like a long-lived credential: a server that only checks at creation time keeps sending data on behalf of an employee who should no longer have access, until the subscription expires. The sketch itself says lifetimes from a few minutes up to about a day cover most deployments, but it also allows subscriptions with no expiry.
The second is prompt injection. An event often carries text written by an outsider: an email subject, a ticket, a chat message. The design sketch explicitly calls event payloads untrusted data, with the same injection considerations as tool results. The difference from an ordinary tool call is that nobody is watching at the moment the assistant acts.
Our advice
If you use off-the-shelf plugins: treat event-triggered tasks as a risk category of their own. Have your admin decide which plugins may start tasks unattended, and begin with automations that only read or prepare a draft — not ones that write, send or pay on their own. If you build your own MCP server: go ahead, but build against what ChatGPT supports today and expect changes while the specification is a draft. Check permissions on every delivery rather than only at subscription time, grant short lifetimes, and make sure you can revoke all of one user's subscriptions at once when they leave. Keep payloads minimal: a reference to the record is safer than its full contents. More background in security & watchouts and building an MCP server.
The bigger picture
Our reading: this is the step from an assistant that answers to an agent that keeps watch. A major client vendor shipping a draft specification speeds up adoption, but it also means practice is running ahead of the standard — and the working group will have to reckon with what is already deployed.
Sources
- MCP Events — OpenAI developer documentation
- DevDay 2026 Recap — OpenAI
- OpenAI makes 20+ announcements at DevDay — 9to5Mac
- Triggers and Events Charter — modelcontextprotocol.io
- experimental-ext-triggers-events (MCP Events design sketch) — GitHub
- The New MCP Roadmap — official MCP blog
- MCP Events in ChatGPT: why an event subscription is a credential — WorkOS
Frequently asked questions
Is MCP Events an official part of the MCP specification?
No, not yet. It is a design sketch from the Triggers and Events Working Group, in a repository explicitly marked experimental. ChatGPT supports part of that draft; details may still change before it becomes an accepted extension.
What do I need to use MCP Events in ChatGPT?
An MCP server on protocol version 2026-07-28 that implements events/list, events/subscribe and events/unsubscribe, stores subscriptions persistently and can send signed webhooks. On the user side it works in Work chats on ChatGPT web, in the desktop app with Cloud selected, and with dots.
What is the main security risk of MCP Events?
A subscription that keeps running after someone's access has been revoked. ChatGPT does not support the draft's termination message, so the server itself must check permissions on every delivery and grant short lifetimes. In addition, event payloads are untrusted data that may contain prompt injection.
Last updated: