ChatGPT is adding draft MCP Events support. WorkOS's argument: the subscription row — principal, callback URL, signing secret, TTL up to no expiry — outlives the access token that created it. Treat events/subscribe as credential issuance, not as a session.
What WorkOS Published
On October 1, 2026, WorkOS published MCP Events in ChatGPT: Why an event subscription is a credential. MCP Events is a draft extension: the client calls events/subscribe, the server stores the subscription, and matching events go to a webhook until the subscription expires or is ended.
OpenAI said at DevDay on September 29 that it is adding support for the proposed MCP Events specification. WorkOS notes the working-group charter still lists the Events SEP as ideating, and that ChatGPT implements a slice of an unfinished design sketch.
What The Row Stores
Before accepting a subscribe, OpenAI's guide (as restated by WorkOS) tells the server to check authorization, validate arguments and the whsec_ secret, verify the callback URL, then store owner, filters, callback URL, signing secret, and expiration. That storage step is the argument: you now hold a persistent row that names a user, a public-internet destination, and a secret.
Under the 2026-07-28 authorization spec, access tokens are short-lived, audience-bound, and re-checked on every request. The subscription inherits none of that. The design sketch keys a webhook on (principal, delivery.url, name, arguments) — not the token, its scopes, or its expiry. ttlMs: null requests a subscription with no expiry.
Revocation Visibility
At subscribe time, the principal must be authenticated and authorized. At delivery time the draft says the server SHOULD periodically re-verify permissions. WorkOS's point: SHOULD / "periodically" with no interval and no conformance test. The path of least effort is authorize-once and never look again.
ChatGPT supports webhook delivery and callback verification. It does not support the draft's terminated envelope. After you stop delivering, ChatGPT learns only when the next refresh fails. Grant no expiry and there is no next refresh. The TTL you grant is therefore the revocation visibility window.
What Operators Should Change
- Refuse
ttlMs: null. Grant short, finite TTLs. - Re-verify access on a stated cadence — a number you can put in a sentence — not "periodically."
- Index subscriptions by user so SCIM / directory offboarding can delete every row a departing principal created.
- Authorize again at delivery time, not only at subscribe time.
What The Post Does Not Prove
- MCP Events is still a draft. WorkOS says the working group chartered subscription lifecycle and has not shipped a SEP for it yet.
- ChatGPT's omitted
terminatedenvelope is a current integration fact from the WorkOS post, not a claim about every MCP client. - This extends MCP governance and management-surface auth and DPoP / scope challenges. It does not replace them.
Related: See our notes on MCP gateways compared and SCIM for agentic identity.