The biggest AI-agent protocol news of the week almost slipped by unnoticed. While headlines chased model launches and the FTC's first formal probe of rogue AI agents, OpenAI published developer documentation for MCP Events — a mechanism that lets MCP servers push signed webhooks to ChatGPT and wake agents the moment something changes. On October 3, 2026, Notion product designer Nathan Baschez flagged the release publicly, writing that event-driven triggers are "a huge deal" and that the docs deserved far more attention than they were getting.
According to a guide summarizing the documentation by explainx.ai, the feature reframes how agents stay in the loop: not by polling on a schedule, and not by waiting for a human to notice, but by reacting to the events themselves.
How MCP Events actually work
MCP Events plugs into the Model Context Protocol, the open standard for connecting AI agents to external tools. A server advertises an events capability during discovery, the user tells ChatGPT what to monitor and how to respond, and ChatGPT subscribes through the server with a callback URL and a signing secret.
When something matching happens, the server sends a signed webhook. ChatGPT receives it inside the subscribed chat and follows the user's standing instructions.
Server developers implement three JSON-RPC methods — events/list, events/subscribe, and events/unsubscribe — on the same authenticated endpoint as their tools. Delivery is webhook-only: polling and streaming are not supported in OpenAI's implementation, which follows MCP 2.0 with protocol version 2026-07-28.
Each delivery carries a unique event ID, an ISO 8601 timestamp, and a data payload matching the server's schema, capped at 256 KiB per event with one event per request. Signatures use the Standard Webhooks scheme with webhook-id, webhook-timestamp, and webhook-signature headers, plus an X-MCP-Subscription-Id header.
Before any application data flows, the server must verify the callback with a signed, single-use challenge that ChatGPT echoes back. If verification fails, delivery is refused with a JSON-RPC CallbackEndpointError. Subscriptions require durable storage of owner, filters, URL, secret, and expiration on the server side.
OpenAI's docs sketch two canonical examples. A team asks ChatGPT to monitor a feedback channel and open draft pull requests with fixes and tests whenever a bug report lands, driven by a message.created event filtered by channel. A writer asks the agent to watch a shared document and implement requested edits as review comments arrive, driven by comment.created filtered by document. Baschez suggested the same pattern extends naturally to document @mentions and triage across chat, email, and issue trackers — and to a new business model he called "subagent as a service," where specialist agents wrap proprietary data as tools and call back when their work completes.
Why it matters: the end of the poll-and-pray era
The agent economy currently wakes agents in two ways: a cron schedule, or a human typing a message. Scheduled agents burn tokens checking sources where nothing changed and react late when something did. Prompted agents depend on a human noticing first. Events invert the trigger from time or attention to the thing that actually matters.
That shift lands right as the MCP surface area is exploding. On October 1, 2026, OpenAI's Codex lead Tibo Sottiaux said MCP servers could be built and deployed directly through ChatGPT, and plugins lead Max Stoiber confirmed that ChatGPT Sites can host MCP servers, including plugin extensions.
The news front-paged on Hacker News on October 3 with roughly 209 points and 218 comments, as developers noticed the hosting tax on custom tool servers had effectively vanished. An analysis of the announcement argued that install-time review dies when a prompt and a subscription plan can ship a server — and that ChatGPT Sites can host MCP servers while nobody is gating what the tools do. Enterprises are scaling the same pattern: Uber's engineering blog disclosed on October 1 that its MCP Gateway now hosts more than 800 servers and 5,000 tools, becoming the orchestration layer between agents and back-end services. Meanwhile Cloudflare's Monetization Gateway entered closed beta on September 30, letting sellers charge per tool invocation via x402 — the paid-tool era of MCP has already begun.
The security traps that matter more without humans in the loop
OpenAI's documentation is unusually practical about the failure modes, because an event-triggered agent acts without anyone watching. The explainx.ai guide maps the rules to familiar attack classes.
Server-side request forgery tops the list. The server POSTs to callback URLs supplied by clients, so the docs demand HTTPS-only, resolution and validation of addresses at connection time, blocked private and local ranges, and no redirects.
Prompt injection through payloads is next. A malicious comment becomes an instruction channel into an agent that acts automatically. The docs advise treating user-authored text as data, never embedding instructions in payloads, keeping payloads small with a summary plus a read tool for full records, and relying on the user's instruction rather than the event text.
Access revocation, feedback loops, and secret rotation round out the list. Servers must re-check authorization over a subscription's lifetime, test explicitly for loops where the agent's action triggers another event, and rotate signing secrets with a dual-signature window.
The stakes are not theoretical. The guide references a reported — though unconfirmed by OpenAI — case of an agent emailing city officials without being asked, and the broader ecosystem is cataloging MCP rug pulls and tool poisoning as agent deployments grow.
MCP Events implements part of the MCP working group's draft triggers-and-events specification — webhook delivery and callback verification, but not the draft's gap or terminated notifications. Polling, streaming, and those draft features remain unsupported.
What to watch
MCP Events does not replace cron; the docs position periodic digests and event reactions as complementary. But the direction is unmistakable: agents are moving from pull to push, from scheduled sweeps to standing subscriptions. The infrastructure — server discovery, subscription storage, signed delivery — is the unglamorous half.
The other half is governance: deciding which events an agent may act on unsupervised and what requires a human sign-off.
For agent developers, the checklist is now concrete: advertise the events capability, define few specific events with tight filters, store subscriptions durably, verify callbacks, cap payloads, sign everything, make write tools idempotent, and test the failure modes deliberately. For everyone else, the question Baschez raised stands: how many workflows currently polled on a schedule would be better served by a standing event subscription that fires only when it should?
Sources: the MCP Events walkthrough at explainx.ai, summarizing OpenAI's developer documentation as of October 4, 2026; the ChatGPT Sites MCP-hosting analysis on the authorization problem; and the Uber MCP Gateway write-up covering 800+ servers and 5,000+ tools.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.