MCP Apps vs MCP TypeScript SDK
MCP TypeScript SDK leads on trust: 94.6/100 (Grade A) against 89.1/100 (Grade A), a 5.5-point gap. MCP TypeScript SDK leads on supply-chain integrity and adoption.
Official repo for spec & SDK of MCP Apps protocol - standard for UIs embedded AI chatbots, served by MCP servers
MCP Apps doesn't lead on any scored dimension in this pair.
The official TypeScript SDK for Model Context Protocol servers and clients
Choose MCP TypeScript SDK if supply-chain integrity and adoption matter most.
- +2.7Adoption: 76.2M weekly downloads against 5.3M
- +2.6Safety / Integrity: 100% of recent commits signed, against 68%
- +1.4Maintenance: last push today, against 13d ago
- +0.7Transparency: OSSF Scorecard 6.9 against 6.1
Where they differ
1 dimension identical: Identity 18.0 · Full evidence table
An independent, evidence-based trust comparison of MCP Apps and MCP TypeScript SDK, two Protocols & Tool Integration projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.
Full evidence
| Signal | MCP Appsmodelcontextprotocol/ext-apps | MCP TypeScript SDKmodelcontextprotocol/typescript-sdk |
|---|---|---|
| HVTrust score | 89.1 | 94.6 |
| Evidence grade | A | A |
| Coverage grade | B | B |
| Overall rank | #32 | #3 |
| Rank in Protocols & Tool Integration | #5 | #1 |
| GitHub stars | 2.9k | 13.5k |
| Last updated | 13d ago | today |
| Build provenance | Yes | Yes |
| OSSF Scorecard | 6.1 / 10 | 6.9 / 10 |
| License | NOASSERTION | NOASSERTION |
| Downloads | 5.3M/wk | 76.2M/wk |
| Trust dimensions (points earned) | ||
| Safety / integrity / 25 | 18.5 | 21.1 |
| Identity & provenance / 18 | 18.0 | 18.0 |
| Transparency / 17 | 13.7 | 14.4 |
| Maintenance / 20 | 17.4 | 18.8 |
| Adoption / 20 | 17.3 | 20.0 |
| Runtime capability surface (full matrix) | ||
| MCP server | Implemented | Implemented |
| External providers | 1 — Anthropic | — |
| Requires API keys | No | No |
| Plugin surface | plugins | — |
| Provenance drift | Match | Match |
How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.4 →