Skip to content

April 28, 2026: ChatGPT app foundation

  • Added Apps SDK widget metadata to the Eclipse MCP tools.
  • Added standard read-only search and fetch tools so ChatGPT company knowledge can cite Eclipse documents, invoices, and contacts.
  • Registered a same-origin in-chat accounting widget for dashboard snapshots, reports, receivables, invoice previews, payment previews, and journals.
  • Kept writes draft-first or explicitly confirmed so ChatGPT can help without silently changing the books.
  • Bound invoice creation, payment recording, and journal posting to short-lived confirmation claims for the exact reviewed card, active user, and workspace. Changed, expired, or direct write attempts are rejected before accounting work.
  • Expanded use-case research with persona, constraints, prioritization, inline requirements, write boundaries, and prompt coverage for every launch scenario.
  • Expanded the tool catalog into a full implementation handoff with schemas, structured outputs, components, auth requirements, error expectations, and prompt rehearsal notes.
  • Added a submission review packet with tool annotation justifications, privacy posture, auth scope notes, and remaining reviewer assets.
  • Added a UX review and compact follow-up actions so the widget supports conversational next steps without mirroring the full web app.
  • Added a UI review and aligned the inline card with ChatGPT display-mode rules: no repeated app logo, no nested table scrolling, and no more than two actions per card.
  • Optimized tool metadata with explicit routing boundaries and parameter descriptions to improve ChatGPT tool selection precision.
  • Added a security/privacy review, widget sandbox checks, prompt-injection probes, and safer MCP transport error logging.
  • Bound OAuth scopes to both the registered ChatGPT client and the user’s live permissions in the selected Eclipse organization. Offboarding or permission reductions now invalidate affected tokens, authorization codes are protected from invalid PKCE burn attempts, and refresh tokens rotate once to block replay.
  • Bounded and distributed-rate-limited dynamic client registration, restricted callback metadata, and reused exact reconnect registrations so the public OAuth edge fails closed without growing unbounded client rows.
  • Added a troubleshooting runbook and layer-level smoke diagnostics for health, MCP connection, tools, resources, and widget checks.
  • Added a smoke check and golden prompt set for the public MCP contract so the app can be verified before connecting it in ChatGPT Developer Mode.

This gives Eclipse the same kind of conversational accounting surface users expect from modern finance apps in ChatGPT: live context, clear financial cards, and guarded actions that keep the company connection locked to the workspace the user approved.