By NHI Mgmt Group Editorial TeamBased on WorkOS: “MCP-UI: Breaking the Text Wall in AI Interactions” (August 27, 2025)

TL;DR: MCP-UI extends the Model Context Protocol by letting MCP servers return interactive UI components that clients can render in sandboxed iframes or remote DOM, reducing text-only friction for complex tasks and supporting adoption across commerce and workflow tooling, according to WorkOS. The security question is no longer whether agents can talk to tools, but how their interfaces preserve control, trust, and user safety at runtime.


At a glance

What this is: MCP-UI is a protocol pattern for returning interactive UI components from MCP servers so AI agent conversations can support richer, task-specific workflows without collapsing into plain text.

Why it matters: It matters because IAM, NHI, and agentic governance teams now have to review not just what an agent can call, but how interactive interfaces preserve intent, isolation, and control at execution time.


Context

MCP-UI addresses a governance and usability gap in AI agent workflows: text-only interactions are often too limited for complex tasks that depend on structured choices, visual context, and user confirmation. In practice, that gap sits inside the control plane for MCP-based agent interactions, not just the presentation layer.

The article frames MCP-UI as an emerging pattern for interactive agent interfaces rather than a finished control standard. That matters to identity teams because the interface becomes part of the trust boundary, especially when an agent mediates access to tools, commerce flows, or business actions.

WorkOS presents the topic through demos and ecosystem adoption, but the operational question is broader: how do organisations let an agent render richer workflows without letting interface complexity weaken approval, isolation, or accountability?


Key questions

Q: How should security teams govern interactive UI inside AI agent workflows?

A: Security teams should govern interactive UI as part of the agent’s execution path, not as a separate front end. That means approving which components can render, validating which intents they may emit, and logging the downstream action chain. If the UI can change state, it needs the same policy discipline as the underlying tool call.

Q: Why do rich agent interfaces increase trust and safety risk?

A: Rich interfaces compress the path from prompt to action, which can hide where authority actually changes hands. A component can influence user choices, shape the options presented, or frame an action in a way that creates implicit trust. That is why isolated rendering, explicit intent capture, and per-action authorisation matter more when the UI is interactive.

Q: What breaks when agent UIs can trigger actions directly?

A: When UI events can trigger actions directly, the agent loses its role as a policy gate and the interface becomes an uncontrolled execution path. That increases the risk of hidden privilege escalation, untraceable state changes, and confusing accountability. The control failure is not visual complexity, but bypass of the mediated decision point.

Q: How do sandboxed iframes compare with remote DOM rendering for agent UI?

A: Both are containment patterns, but they differ in how much control the client retains over rendering and interaction. Sandboxed iframes prioritise isolation, while remote DOM can offer tighter integration with the host experience. The practical choice depends on whether your primary concern is user experience consistency or minimizing the risk of privilege leakage.


Technical breakdown

How MCP-UI packages interaction as MCP resources

MCP-UI shifts presentation from a static assistant response to a structured resource returned by the server and rendered by the client. The server publishes interactive components, while the client decides whether to render them inline, in a sandboxed iframe, or through remote DOM. That separation matters because the tool result is no longer just data for the model to read. It is a controlled UI object that can carry actions, state changes, and visual affordances into the session. The design tries to preserve interoperability across clients while keeping the server responsible for the component contract, not the browser runtime.

Practical implication: treat MCP UI rendering as part of the governed agent surface, not a cosmetic add-on.

Why sandboxed rendering changes the trust model

The security model described in the article relies on sandboxed iframes and controlled rendering paths so remote code does not run directly in the host context. That reduces the chance that a rich interface can inherit the full privileges of the agent host, the browser session, or adjacent application state. This is an important boundary because interactive components can request input, surface intent, and trigger follow-on actions. If those components are not isolated, the interface itself becomes an attack surface for prompt injection, click confusion, or untrusted state manipulation. The core design principle is that presentation should be expressive without becoming authoritative.

Practical implication: verify where UI code executes and whether the rendering boundary is actually isolated from host privileges.

Intent-based events keep the agent in control

The Shopify example in the article shows an intent-based pattern: a click inside the embedded component does not directly change state. Instead, the action bubbles up as an intent that the agent interprets before anything is committed. That keeps the agent as the policy and orchestration layer while the UI handles interaction. For identity governance, this distinction is important because it prevents the interface from becoming an uncontrolled executor. It also creates a clearer audit model for what the user selected, what the component proposed, and what the agent decided to do next. Without that separation, rich UI can quietly become privileged automation.

Practical implication: require intent mediation for agent-triggered actions instead of allowing embedded components to execute directly.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

MCP-UI turns the interface into a governance boundary, not just a usability layer. Once an agent can render interactive components, the control problem shifts from message content to interaction design, rendering isolation, and intent handling. That is a meaningful change for MCP governance because the user now acts through a mediated interface rather than a simple text exchange. Teams should treat the UI path as part of the identity control surface, not as a separate product feature.

Sandboxing is necessary, but it does not by itself solve trust. Sandboxed iframes reduce host compromise risk, yet they do not automatically prevent misleading prompts, unsafe user choices, or ambiguous intent capture. The governance question is whether the component can influence decisions without acquiring implicit authority. Practitioners need to distinguish visual containment from decision containment.

Intent-based UI creates an audit opportunity that text chat never had. When user actions bubble up as explicit intents, organisations can log a richer decision trail than free-form conversation alone. That trail is only useful if the agent preserves the distinction between a presented option, a user selection, and a committed action. This is a stronger foundation for accountability in agent-mediated workflows than plain chat approvals.

Interface richness will pressure existing approval models to move closer to runtime. Text-only agent workflows often leave too much interpretation to the model, while interactive components can compress the distance between request and action. That does not make the process safer by default; it makes the need for runtime authorisation clearer. Practitioners should expect more agent workflows to demand policy decisions at the point of interaction rather than after the fact.

Interactive agent UX is becoming a control plane for non-human and human collaboration. As MCP-UI patterns spread across commerce and workflow tooling, the same interface may mediate human approval, agent execution, and downstream API calls. That convergence raises the value of standardised rendering, explicit intent capture, and least-authority execution paths. Organisations should prepare for agent interfaces to be governed like privileged workflows.

From our research library:

What this signals

Interactive agent UI will push governance closer to runtime. Text-only agent workflows allow too much ambiguity between suggestion and execution. As richer interfaces spread, organisations will need to review where user intent is captured, where approval happens, and how an agent proves that a displayed action was the one actually committed.

MCP-UI changes the security problem from message safety to interface authority. The main question is no longer whether an agent can speak to a tool, but whether the UI path preserves least authority when the agent is acting through a rendered component. Teams that treat the interface as trusted by default will miss the place where control actually shifts.

Ephemeral interface trust debt: every extra interaction path expands the set of places where a user can be misled or a component can overreach. That matters even more in agentic workflows because the control boundary can move from the model response to the rendered UI in a single step.


For practitioners

  • Define the trust boundary for interactive agent UI Map which UI elements are informational, which can request input, and which can trigger downstream actions. Require each class of component to have an explicit rendering boundary and an approval path before it can affect state.
  • Mediate every action through explicit intent handling Ensure clicks, selections, and form submissions from embedded components become agent-readable intents rather than direct state changes. Log the originating component, the user choice, and the agent decision separately.
  • Review sandboxing assumptions for remote UI components Test whether sandboxed iframes and remote DOM rendering actually prevent privilege inheritance, token exposure, and host-page manipulation in your client runtime. Validate the rendering path under adversarial content and untrusted component behavior.
  • Align approval workflows to runtime interaction points Move human review closer to the moment a user or agent commits to an action inside the interface. Do not rely on upstream conversation context alone when the UI can shape the decision path.

Key takeaways

  • MCP-UI moves interactive agent workflows beyond plain text and makes the rendered interface part of the control boundary.
  • Sandboxing and intent mediation reduce risk, but they do not eliminate the need to govern where authority changes hands.
  • Identity teams should review interactive agent paths as privileged workflows, with explicit approval and audit at the point of action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseInteractive agent UI can shift authority if rendered components gain unintended execution scope.
ASI02 — Tool MisuseMCP-UI components can steer agents into unsafe or unintended tool actions if intent is not mediated.
Recommendation — Bind interactive agent components to explicit identity and privilege boundaries before allowing state-changing actions. Mediate every component-triggered action through policy before the agent invokes downstream tools.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIHumans and agents share the same interactive path, so user-mediated NHI actions need clear authority boundaries.
Recommendation — Separate human selection from NHI execution so user interaction never bypasses governed authorization.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAgent UI actions still require governed permissions and explicit authorization decisions.
Recommendation — Apply authorization controls at the point where an interactive action becomes a committed system change.

Key terms

  • MCP-UI: MCP-UI is the user interface layer through which a person or agent interacts with Model Context Protocol tools and data. It presents available actions, prompts, results, and permissions in a controlled workspace. In practice, it mediates how an AI agent discovers, requests, and uses external capabilities while preserving visibility and governance.
  • Intent-based interaction: Intent-based interaction is a design pattern where a user action becomes a declared intent that must be interpreted before any state change occurs. For agent workflows, that separation helps preserve auditability and prevents a component from silently turning a click into an unreviewed privileged action.
  • Sandboxed iframe: A sandboxed iframe is an isolated browser container that restricts what embedded UI can access or load. It reduces exposure of cookies, scripts, and network destinations, but it does not grant or replace authorization to perform privileged backend actions.
  • Remote DOM: Remote DOM is a rendering approach where JavaScript updates are sent through a controlled layer rather than directly manipulating the host page. In MCP-UI, it enables richer interactions while keeping the component sandboxed, but it also increases dependence on message integrity and host-side validation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org