Markdown

WebMCP

WebMCP is the Acronym for Web Model Context Protocol

A proposed in-page browser interface that lets a live web application expose typed JavaScript tools to AI agents sharing the same tab. Pages that implement it can be thought of as Model Context Protocol (MCP) servers whose tools run in client-side script instead of on a backend. The visitor still sees the existing User Interface (UI). The agent calls named functions instead of scraping the Document Object Model (DOM) or driving clicks from screenshots. The draft is incubated in the World Wide Web Consortium (W3C) Web Machine Learning Community Group. Editors are Brandon Walderman of Microsoft and Khushal Sagar and Dominic Farolino of Google. The Draft Community Group Report was updated 26 August 2026. It is not a W3C Standard and is not on the W3C Standards Track.

await document.modelContext.registerTool({
  name: "search_catalog",
  description: "Search products by query and category.",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string" },
      category: { type: "string" }
    },
    required: ["query"]
  },
  execute: async function (input) {
    return await runCatalogSearch(input.query, input.category);
  }
});

How In-Page Tools Work

Each Document carries a modelContext object. A page registers tools with a unique name, a natural-language description, a JavaScript Object Notation (JSON) Schema for inputs, and an execute callback. A browser agent, or an in-page agent written in JavaScript, discovers that list and invokes a tool with structured arguments. Execution stays inside the page’s origin, cookies, and live state, so a checkout tool can use the shopper who is already signed in. Tools are ephemeral. They disappear when the user leaves the page or closes the tab. The JavaScript Application Programming Interface (API) is document.modelContext. Early Chrome experiments also exposed navigator.modelContext. Current drafts use the Document accessor. The browser’s own agent reads tools through an internal path. getTools() and executeTool() exist so JavaScript running in the page, including an iframe agent, can do the same.

  • registerTool: Adds one tool. Names are 1 to 128 characters of ASCII alphanumerics plus _, -, and .. Duplicate names reject. Passing an AbortSignal unregisters the tool when that signal aborts.
  • getTools: Returns the tools this document may see, including same-origin descendants. Cross-origin tools require a fromOrigins list plus the owner’s exposedTo list.
  • executeTool: Runs a previously discovered tool and resolves with a JSON string result (or null when the call navigates).

Declarative HTML

Form attributes toolname and tooldescription turn a standard form into a tool. toolparamdescription annotates fields. toolautosubmit lets the agent submit without a human click. Without it, the browser focuses the submit control so a person can check the values first.

Security gates

The API requires a secure, origin-isolated document. The tools Permissions Policy defaults to self, so a cross-origin iframe needs allow="tools".

“`javascript await document.modelContext.registerTool({ name: "search_catalog", description: "Search products by query and category.", inputSchema: { type: "object", properties: { query: { type: "string" }, category: { type: "string" } }, required: ["query"] }, execute: async function (input) { return await runCatalogSearch(input.query, input.category); } }); “`

Trying It in Chrome and at the Edge

Chrome has offered a public origin trial since version 149, so a site can register a trial token and ship tools on real visitors. For local development, enable chrome://flags/#enable-webmcp-testing and relaunch. Google’s Model Context Tool Inspector extension lists registered tools, checks schemas, and lets you invoke them with natural-language prompts. On 6 August 2026 Cloudflare launched a developer preview that does not require origin code changes. In the dashboard, open Agent Readiness, then WebMCP, and toggle it on for the zone. Cloudflare’s HTMLRewriter injects a same-origin module at /.webmcp/bridge.js. That script registers tool packs in the page. The preview ships two packs: Content Credentials, which reads Coalition for Content Provenance and Authenticity (C2PA) metadata from images, and a Site MCP Server pack (mcp-server-client) that proxies tools from an existing same-origin MCP endpoint, defaulting to /mcp. If the browser has no modelContext, the bridge exits and the page behaves as before. The injection works for static sites and Single Page Application (SPA) responses because the script is added on the way out.

WebMCP Versus MCP and Markdown for Agents

Chrome’s guidance is that this API does not replace MCP. MCP is a backend protocol, typically JSON-RPC, that exposes persistent tools and resources to agents anywhere. This API is MCP-inspired and purpose-built for a browser agent sitting on a live page. It omits server-side concepts such as resources. MCP remains the remote service. This interface is only available while the visitor has the site open. Cloudflare Markdown for Agents is a different product. When a client sends Accept: text/markdown, the edge converts HTML to markdown so a model can read the page with fewer tokens. That path is for retrieval. It does not register callable tools and it does not keep the agent inside the interactive UI. Screenshot actuation remains the fallback when a site exposes nothing. Those agents guess from pixels and selectors, which is slower and breaks when the layout changes.

Table: Approach

ApproachWhere it runsWhat the agent getsJob it is good at
WebMCPThe visitor’s live tabTyped tools registered in page script or annotated formsSearch, booking, checkout, and inspect actions while the UI updates
MCPA backend serverPersistent tools, resources, and workflows over JSON-RPCCatalog lookups, CRM writes, and jobs that must run when no tab is open
Markdown for AgentsCloudflare’s edgeAn HTML-to-markdown rendering via content negotiationReading and indexing copy, not driving the interface
Screenshot or DOM actuationA computer-use agentPixels, accessibility trees, and guessed selectorsLast-resort clicking when the site exposes no tools

Articles Tagged WebMCP

View Additional Articles Tagged WebMCP