Panduan WebMCP
WebMCP lets sebuah halaman web expose structured alat untuk sebuah AI agent di browser. Learn how ini differs dari MCP, what Chrome mendukung, security risks, dan when untuk wait.
Bahasa
1 sinyal bukti di halaman ini
- Alat aktif terkaitSchema Markup Validator
WebMCP adalah sebuah experimental browser API itu lets sebuah open halaman web offer structured alat untuk sebuah AI agent. ini adalah berguna untuk bounded halaman tindakan, not web penemuan atau rankings. sebagai dari July 17, 2026, ini adalah sebuah Community Group draft dan Chrome 149 origin trial; saat ini Chrome contoh gunakan document.modelContext, while navigator.modelContext adalah deprecated di Chrome 150.
TL;DR — WebMCP lets sebuah situs web describe -nya buttons dan functions sebagai structured alat sebuah AI agent dapat panggil while halaman adalah open. itu dapat membuat sebuah nyata halaman tindakan—searching inventory, validating code, filtering products—more reliable daripada asking sebuah agent untuk guess which control untuk click. ini melakukan not membuat halaman easier untuk peringkat, crawl, atau menemukan. sebagai dari July 17, 2026, ini adalah experimental: sebuah Community Group draft dengan sebuah Chrome 149 origin trial, not sebuah finished web standard.
What WebMCP adalah
WebMCP adalah sebuah proposed browser API itu lets sebuah halaman web expose structured alat untuk sebuah AI agent operating di itu halaman’s browsing context. sebuah alat memiliki sebuah name, sebuah deskripsi, structured inputs, dan code itu performs sebuah tindakan. Evidence for this claim WebMCP is a proposed browser API through which web applications expose JavaScript-based tools to agents in a browsing context. Scope: WebMCP Draft Community Group Report dated July 10, 2026; the report is not a W3C Standard. Confidence: high · Verified: WebMCP Draft Community Group Report
Imagine sebuah pengunjung opens sebuah schema validator dan menanyakan mereka browser agent untuk
“validate this Product JSON-LD.” (terjemahan) “validate ini Product JSON-LD.” Without WebMCP, agent dapat inspect screen,
temukan sebuah text area, paste ke ini, click right button, dan interpret hasil.
dengan WebMCP, halaman dapat offer sebuah validate_schema alat dengan sebuah explicit input
schema dan mengembalikan structured hasil—while keeping terlihat interface di sync.
itu adalah berguna mental model: WebMCP adalah sebuah explicit control surface untuk sebuah agent itu memiliki sudah reached halaman. ini adalah not sebuah baru cara untuk publish prose.
saat ini status pada July 17, 2026
WebMCP adalah moving quickly, so code dan compatibility claims perlu dates. saat ini position adalah: Evidence for this claim As of July 17, 2026, WebMCP is a Community Group draft rather than a W3C Standard, and Chrome documents an origin trial beginning in Chrome 149. Scope: Standards and Chrome experiment status checked July 17, 2026; these are time-sensitive claims. Confidence: high · Verified: WebMCP: Status of This Document Chrome: Join the WebMCP origin trial
| pertanyaan | saat ini jawaban |
|---|---|
| adalah ini sebuah W3C Standard? | No. July 10 draft adalah sebuah Community Group Report dan explicitly not pada W3C Standards Track. |
| Which JavaScript object seharusnya contoh gunakan? | document.modelContext. Chrome says navigator.modelContext adalah deprecated beginning di Chrome 150. |
| adalah ini stable di Chrome? | No. Chrome documents sebuah origin trial beginning di Chrome 149 plus sebuah local testing flag. |
| melakukan ini berfungsi sebagai sebuah headless, web-wide directory? | Not di documented Chrome experiment. sebuah client visits sebuah halaman untuk menemukan itu halaman’s alat. |
| adalah declarative form API settled? | Chrome documents ini, tetapi saat ini Community Group draft’s declarative bagian adalah masih marked TODO. |
I ditemukan no primary-source basis di ini research pass untuk claim stable WebMCP mendukung di Edge, Safari, atau Firefox. sebuah Microsoft editor contributing untuk draft adalah not yang sama thing sebagai sebuah browser shipping fitur.
WebMCP versus MCP
Model Context Protocol dan WebMCP expose alat di berbeda boundaries:
- MCP biasanya connects sebuah AI application untuk sebuah persistent server. server dapat menyediakan alat dan data whether atau not sebuah particular halaman web adalah open.
- WebMCP lets open halaman expose -nya saat ini frontend tindakan dan state. -nya alat dapat perubahan when pengunjung navigates atau when sebuah tindakan becomes unavailable.
mereka complement setiap lainnya. sebuah store mungkin gunakan remote MCP untuk sebuah product catalog dan WebMCP untuk filter, configuration, dan checkout langkah terlihat di pengunjung’s saat ini tab. Evidence for this claim WebMCP is designed for tools owned by an active page and its browser context, while remote MCP commonly connects an AI application to a persistent backend server. Scope: Architecture-selection guidance, not a rule that prevents an application from using both technologies. Confidence: high · Verified: Chrome: When to use WebMCP and MCP
melakukan WebMCP help SEO atau AI citations?
ada no documented evidence itu menambahkan WebMCP improves rankings, crawling, pengindeksan, AI citations, atau penemuan. documented fitur begins setelah sebuah agent reaches sebuah halaman dan inspects alat available there. Evidence for this claim The documented Chrome WebMCP experiment requires a browsing context and a client visit to discover page tools; no documented ranking, crawling, indexing, or citation benefit was found in this research pass. Scope: The browser-context and visit requirements are direct documentation; the SEO conclusion is a bounded absence-of-evidence statement as of July 17, 2026, not a prediction about future search systems. Confidence: high · Verified: Chrome: WebMCP overview and limitations Google Search guidance for AI experiences
ini dapat meningkatkan completion dari sebuah pada-situs task. itu dapat menjadi commercially valuable, tetapi ini adalah sebuah product dan conversion hypothesis—not sebuah peringkat factor. pertahankan doing ordinary berfungsi itu membuat sebuah halaman discoverable dan understandable: semantic HTML, accessible forms, tautan internal, dapat diindeks konten, dan appropriate data terstruktur.
Editorial halaman melakukan not perlu fake alat hanya untuk look “agent-ready.” (terjemahan) “agent-ready.” jika halaman hanya perlu untuk menjadi read, readable HTML adalah right interface.
dapat Cloudflare enable WebMCP untuk my situs?
Not oleh itself. Cloudflare browser Run currently offers experimental lab browser sessions itu dapat visit dan test halaman dengan WebMCP alat. Anda halaman masih memiliki untuk define dan register itu alat. Cloudflare’s documentation juga says -nya lab sessions adalah not untuk production workloads. Evidence for this claim Cloudflare Browser Run offers experimental lab sessions that can consume and test page-provided WebMCP tools, but the page still owns tool registration and Cloudflare says lab sessions are not for production workloads. Scope: Cloudflare product documentation last updated April 23, 2026; its example API names lag current Chrome documentation and should not be used as the API authority. Confidence: high · Verified: Cloudflare Browser Run: WebMCP
itu membuat Cloudflare sebuah mungkin test environment atau consuming browser, not sebuah switch itu converts setiap existing form dan button ke WebMCP.
seharusnya Anda implement ini now?
untuk sebagian besar production situs, wait. sebuah kecil private experiment dapat membuat sense when semua dari ini adalah benar:
- halaman sudah memiliki sebuah bounded, berguna tindakan;
- normal human interface remains complete without WebMCP;
- tindakan adalah read-hanya atau easily reversible;
- yang sama application logic menyajikan both UI dan alat;
- inputs, outputs, authorization, dan logs menerima sebuah nyata security review; dan
- success dapat menjadi diukur without pretending experiment affects search visibilitas.
jangan gunakan sebuah experimental browser API sebagai satu-satunya path untuk sebuah critical task.
Evidence for this claim Chrome documents declarative form annotations such as toolname and tooldescription, but the declarative section of the July 10, 2026 Community Group draft is still marked TODO. Scope: secure browser context Confidence: high · Verified: WebMCP Draft Community Group ReportTL;DR — WebMCP exposes halaman-owned alat dari
document.modelContextuntuk sebuah agent di active browsing context. imperative API registers sebuah name, deskripsi, JSON Schema input, annotations, dan sebuah async callback; alat dapat menjadi state-dependent dan unregistered dengan sebuahAbortSignal. Chrome documents sebuah declarative form layer too, tetapi July 10, 2026 Community Group draft masih labels -nya declarative bagian TODO. fitur adalah di sebuah Chrome 149 origin trial, not sebuah stable cross-browser baseline. Treat ini sebagai progressive enhancement, not SEO infrastructure, dan secure ini sebagai sebuah authenticated application surface.
How WebMCP berfungsi di browser
sebuah berguna WebMCP lifecycle begins dan ends dengan halaman. halaman registers hanya tindakan itu adalah valid di -nya saat ini state; sebuah agent sudah operating di itu browsing context discovers dan invokes one; halaman executes -nya normal application logic, updates human-terlihat interface, dan mengembalikan sebuah bounded hasil. When state perubahan, halaman menghapus alat itu no longer apply. Evidence for this claim The imperative API registers named, described, schema-constrained callbacks and supports state-aware cleanup with AbortSignal plus tool-set change notifications. Scope: Current draft and Chrome experiment; API details may change before stable release. Confidence: high · Verified: WebMCP ModelContext API Chrome: WebMCP Imperative API
Five numbered steps run left to right. First, the page registers a name, description, input schema, and callback. Second, an agent already in the page context discovers it. Third, the agent invokes it with validated structured arguments. Fourth, the page reuses its normal application logic and updates the visible interface. Fifth, it returns a bounded result or safe error. A branch from execution shows that state changes or navigation should unregister the tool with AbortSignal and notify observers through toolchange.
© Patrick Stox LLC · CC BY 4.0 ·
ini stateful lifecycle adalah one alasan WebMCP seharusnya not become sebuah static dump dari setiap function di sebuah JavaScript bundle. sebuah alat itu adalah impossible di terlihat UI seharusnya normally menjadi unavailable untuk agent too.
WebMCP vs MCP: two berbeda runtime boundaries
names invite confusion, tetapi operational boundary adalah berbeda. WebMCP lives di sebuah document’s event loop dan saat ini browser session. Remote MCP lives di AI application’s integration boundary dan commonly reaches sebuah persistent backend server. Evidence for this claim WebMCP is designed for tools owned by an active page and its browser context, while remote MCP commonly connects an AI application to a persistent backend server. Scope: Architecture-selection guidance, not a rule that prevents an application from using both technologies. Confidence: high · Verified: Chrome: When to use WebMCP and MCP
The left lane shows WebMCP: a browser agent interacts with an open web page, which owns a JavaScript tool and current visible session state. The page must be open for those tools to exist. The right lane shows remote MCP: an AI application connects through an MCP client to a persistent MCP server, which can remain available outside a browser tab. The two lanes are complementary rather than replacements.
© Patrick Stox LLC · CC BY 4.0 ·
| Interface | Where ini lives | When ini adalah ditemukan | halaman harus menjadi open? | Best fit |
|---|---|---|---|---|
| WebMCP | Active browser document | setelah client visits halaman | Yes | saat ini UI state dan halaman tindakan |
| Remote MCP | AI client dan sebuah MCP server | melalui client/server configuration atau penemuan | No | Persistent alat, data, dan backend workflows |
| Web/API endpoint | Application backend | melalui application-spesifik integration | No | Stable programmatic access untuk known consumers |
| data terstruktur | halaman markup | selama halaman processing | biasanya fetched sebagai konten | Describing entities dan halaman meaning, not executing tindakan |
llms.txt | Static text file | When sebuah client chooses untuk permintaan ini | No active tab diperlukan | Proposed konten guidance; not sebuah callable alat surface |
| browser automation | Agent/controller interpreting UI | setelah memuat dan inspecting halaman | Yes | Fallback where no explicit halaman alat exists |
melakukan not choose dari acronym. Choose dari owner dari tindakan. jika tindakan perlu saat ini DOM, selection, cart, atau UI state, WebMCP dapat fit. jika ini harus run di background, di seluruh banyak situs, atau without sebuah open tab, gunakan API atau remote MCP.
imperative API
imperative API registers sebuah alat melalui document.modelContext.registerTool().
alat mencakup sebuah unique name, deskripsi, JSON Schema input, sebuah execute
callback, dan optional annotations. Chrome juga documents getTools(),
executeTool() untuk testing, dan sebuah toolchange event. Evidence for this claim Current Chrome documentation uses document.modelContext and says navigator.modelContext is deprecated beginning in Chrome 150. Scope: Chrome implementation guidance checked July 17, 2026; version and API-name claims expire quickly. Confidence: high · Verified: Chrome: WebMCP Imperative API
ini illustrative candidate menampilkan intended shape untuk sebuah future Schema Validator pilot. ini adalah not running pada ini situs, dan API dapat perubahan sebelum sebuah stable release:
if (document.modelContext) {
const registration = new AbortController();
await document.modelContext.registerTool({
name: 'validate_schema',
description: 'Validate pasted JSON-LD and return bounded issues.',
inputSchema: {
type: 'object',
properties: {
markup: {
type: 'string',
description: 'JSON-LD markup to validate.',
maxLength: 50000
}
},
required: ['markup'],
additionalProperties: false
},
annotations: {
readOnlyHint: true,
untrustedContentHint: true
},
execute: async ({ markup }) => {
const result = await validateWithTheSameEngineAsTheUI(markup);
renderResultInTheVisibleUI(result);
return minimizeValidationResult(result);
}
}, { signal: registration.signal });
// When this page state no longer supports validation:
// registration.abort();
}penting architecture adalah not wrapper. ini adalah itu callback panggilan sama validator sebagai terlihat UI, server-side limits dan authorization masih apply, dan respons adalah deliberately minimized. fitur detection preserves full human workflow di unsupported browser.
gunakan document.modelContext, not stale contoh dibangun sekitar
navigator.modelContext; Chrome marks latter deprecated beginning di Chrome
150. Date itu advice because fitur remains experimental.
declarative API memiliki sebuah standards mismatch
Chrome documents sebuah declarative approach itu annotates ordinary forms dengan
attributes such sebagai toolname, tooldescription, dan
toolparamdescription. ini juga documents optional toolautosubmit; otherwise,
pengguna clicks Submit. SubmitEvent.agentInvoked identifies sebuah agent-triggered
submission. Evidence for this claim Chrome documents declarative WebMCP form annotations, but the July 10, 2026 Community Group draft says its Declarative WebMCP section is entirely TODO. Scope: A direct comparison between Chrome implementation documentation and the current draft; it does not imply Chrome's experimental implementation is unavailable. Confidence: high · Verified: Chrome: WebMCP Declarative API WebMCP: Declarative WebMCP
However, July 10 Community Group Report says -nya Declarative WebMCP bagian adalah “entirely a TODO” (terjemahan) “entirely sebuah TODO” dan leaves form-untuk-JSON-Schema algorithm undefined. itu tidak berarti Chrome’s experiment adalah imaginary. ini berarti implementation documentation adalah ahead dari normative draft. Treat declarative markup sebagai sebuah experimental Chrome surface, not settled cross-browser HTML.
Evidence for this claim Chrome documents declarative WebMCP form annotations, but the July 10, 2026 Community Group draft says its Declarative WebMCP section is entirely TODO. Scope: A direct comparison between Chrome implementation documentation and the current draft; it does not imply Chrome's experimental implementation is unavailable. Confidence: high · Verified: Chrome: WebMCP Declarative API WebMCP: Declarative WebMCPuntuk now, ordinary semantic forms remain durable base. sebuah experimental annotation layer seharusnya enhance them, tidak pernah replace labels, validation, accessibility, confirmation, atau server-side authorization.
alat penemuan, lifecycle, dan cross-origin boundaries
saat ini API memiliki several boundaries worth designing explicitly:
- Browsing context: Chrome’s experiment memerlukan sebuah browser context. client visits situs sebelum ini discovers situs’s alat.
- Dynamic availability: register alat when mereka adalah valid dan abort mereka
registration when state atau navigation invalidates them. Observers dapat listen
untuk
toolchange. - sama origin oleh default:
toolsPermissions Policy defaults untuk'self'. Cross-origin iframes perlu explicit delegation such sebagaiallow="tools". - Two-sided cross-origin consent: sebuah alat dapat gunakan
exposedTountuk list allowed secure origins, while sebuah caller permintaan alat dari named origins denganfromOrigins. One side opting di adalah not enough. - Progressive enhancement: unsupported atau disabled WebMCP harus leave ordinary halaman fully usable.
ini adalah berguna platform controls, tetapi mereka melakukan not turn sebuah risky application tindakan ke sebuah safe one.
Security: browser session raises stakes
sebuah browser agent dapat operate inside pengguna’s authenticated session. itu dapat menjadi fitur—access untuk saat ini cart, account, atau workspace—dan danger. Chrome dan draft discuss prompt injection, misleading alat metadata, contaminated alat output, di atas-broad parameters, privacy leakage, cross-origin exposure, dan misuse dari signed-di authority. Evidence for this claim WebMCP tool hints can communicate read-only and untrusted-output intent, but they do not eliminate prompt injection, misleading metadata, privacy leakage, cross-origin risk, or misuse of authenticated browser authority. Scope: Threat-model and defensive guidance; application authorization and confirmation remain implementation responsibilities. Confidence: high · Verified: WebMCP security and privacy considerations Chrome: WebMCP tool security Chrome: Agent security considerations
Treat setiap alat sebagai sebuah public application endpoint dengan sebuah unusual caller:
- pertahankan alat narrow. One job, explicit inputs, tight enums dan lengths, no hidden “do anything” (terjemahan) “melakukan anything” parameter.
- Enforce authorization di application logic. agent melakukan not gain more authority daripada signed-di pengguna, dan sebuah hint adalah not permission.
- Separate reads dari writes.
readOnlyHintdanuntrustedContentHintcommunicate risk; mereka melakukan not enforce ini. - memerlukan terlihat confirmation untuk consequences. Purchases, submissions, deletions, messages, dan account perubahan perlu sebuah human-understandable checkpoint.
- Minimize output. kembalikan hanya what task perlu; tidak pernah spill session data, raw headers, secrets, atau unrelated records.
- Treat output sebagai untrusted. sebuah string dikembalikan oleh one alat dapat become input untuk later model reasoning. melakukan not allow ini untuk smuggle instructions atau authority.
- Log boundary. Record alat, input class, authorization decision, confirmation, hasil class, error, origin, dan lifecycle without logging secrets.
safe pertanyaan adalah not “Can an agent call this?” (terjemahan) “dapat sebuah agent panggil ini?” ini adalah “Would I expose this as a reviewed endpoint to a caller that can misunderstand instructions and relay untrusted text?” (terjemahan) “akan I expose ini sebagai sebuah reviewed endpoint untuk sebuah caller itu dapat misunderstand instructions dan relay untrusted text?”
Test contracts dan agent perilaku separately
Chrome’s eval guidance separates deterministic product tests dari probabilistic agent tests. Evidence for this claim WebMCP testing should combine deterministic contract and UI-state tests with probabilistic evaluation of agent tool selection and use. Scope: Chrome's evaluation guidance; teams must define product-specific tasks, models, risks, and thresholds. Confidence: high · Verified: Chrome: Evals for WebMCP Both penting:
Deterministic tests seharusnya verify registration, schema rejection, valid dan invalid inputs, authorization, rate limits, side effects, error shape, output minimization, UI parity, unregister perilaku, dan unsupported-browser fallback.
Probabilistic evals seharusnya mengukur whether representative agents menemukan right alat, hindari irrelevant alat, choose correct parameters, tanyakan untuk clarification when diperlukan, respect confirmations, stop setelah success, dan resist adversarial deskripsi atau output.
jangan gunakan one demo prompt sebagai release gate. sebuah successful callback proves code ran; ini melakukan not prove itu models select ini reliably atau itu tindakan adalah safe.
Cloudflare browser Run: berguna lab, not enablement
Cloudflare documents WebMCP mendukung di browser Run’s experimental lab pool dan says lab sessions seharusnya not menjadi digunakan untuk production workloads. -nya April 23 halaman juga berisi older Chrome-era testing names, so gunakan itu halaman sebagai evidence dari Cloudflare’s saat ini product offering—not sebagai authority untuk latest WebMCP API shape. Evidence for this claim Cloudflare Browser Run offers experimental lab sessions that can consume and test page-provided WebMCP tools, but the page still owns tool registration and Cloudflare says lab sessions are not for production workloads. Scope: Cloudflare product documentation last updated April 23, 2026; its example API names lag current Chrome documentation and should not be used as the API authority. Confidence: high · Verified: Cloudflare Browser Run: WebMCP
Cloudflare dapat menyediakan sebuah browser session dan sebuah agent path itu consumes alat. ini cannot infer safe contract untuk Anda application atau register halaman-owned alat Anda melakukan not bangun.
Proposed patrickstox.com pilot: Schema Validator
Schema Markup Validator adalah sebuah baik future pilot
candidate, not sebuah live WebMCP implementation. ini sudah memiliki sebuah bounded pasted
input, deterministic logic, structured issues, dan sebuah terlihat hasil. sebuah future
validate_schema alat dapat reuse yang sama validation mesin sebagai UI dan
existing remote MCP alat suite.
pilot seharusnya wait until browser API reaches sebuah stable, non-experimental release dan passes sebuah fresh security review. pertama versi seharusnya menjadi read-hanya, fitur-detected, input-limited, respons-minimized, dan unavailable pada preview, admin, atau owner-hanya surfaces. ini situs melakukan not currently claim WebMCP mendukung.
Decision: bangun, experiment, wait, atau skip
| Situation | Decision |
|---|---|
| Stable browser mendukung adalah diperlukan untuk sebuah customer workflow | Wait dan pertahankan normal UI/API complete |
| Anda memiliki sebuah bounded read-hanya tindakan dan dapat run sebuah private lab | Experiment, dengan fitur detection dan no production dependency |
| task perlu background atau headless execution | gunakan API atau remote MCP |
| halaman hanya publishes konten | Skip WebMCP; meningkatkan semantic, accessible HTML |
| tindakan writes, purchases, submits, deletes, atau exposes private data | melakukan not pilot casually; memerlukan sebuah separate threat model dan confirmation design |
| sebuah stable implementation ships dan semua contract/security/parity tests pass | pertimbangkan sebuah progressive production pilot |
AI summary
- Definition: WebMCP adalah sebuah proposed browser API untuk exposing structured, halaman-owned alat untuk sebuah agent di sebuah active browsing context.
- Status pada July 17, 2026: Community Group draft, not W3C Standard; Chrome 149 origin trial/local flag, not stable cross-browser mendukung.
- saat ini Chrome API:
document.modelContext; Chrome deprecatesnavigator.modelContextbeginning di Chrome 150. - Not remote MCP: WebMCP adalah tab- dan halaman-state-bound; remote MCP commonly connects sebuah AI application untuk sebuah persistent backend server.
- Not penemuan atau peringkat: no documented benefit untuk crawling, pengindeksan, rankings, AI citations, atau reaching halaman di pertama place.
- Declarative caveat: Chrome documents form annotations, while July 10 Community Group draft masih marks itu normative bagian TODO.
- Security: authenticated browser state, prompt injection, poisoned metadata atau output, broad inputs, dan cross-origin exposure membuat least privilege, confirmation, server authorization, dan logs essential.
- Cloudflare: browser Run dapat consume/test WebMCP di experimental lab sessions; ini melakukan not buat alat pada situs.
- Recommendation: pertahankan human UI complete dan wait untuk stable mendukung; private experiments seharusnya menjadi bounded, reversible, dan measurable.
- ini situs’s candidate: sebuah future read-hanya Schema Validator pilot. ini adalah proposed, not implemented.
What primary sources establish
| Source | What ini mendukung | penting limit |
|---|---|---|
| WebMCP Draft Community Group Report | API definitions, lifecycle, permissions, risks, standards status | sebuah Community Group report adalah not sebuah W3C Standard |
| Chrome WebMCP overview | saat ini Chrome experiment, browser-context limitation, local testing | Chrome implementation guidance adalah not cross-browser mendukung |
| Chrome imperative API | document.modelContext, registration, penemuan, execution, events, cross-origin aturan | Subject untuk perubahan; navigator.modelContext adalah deprecated di Chrome 150 |
| Chrome declarative API | Experimental form annotations dan submit perilaku | saat ini Community Group draft’s corresponding bagian remains TODO |
| WebMCP alat security | alat annotations, origin exposure, defensive guidance | Hints melakukan not guarantee safety |
| WebMCP evals | Deterministic tests dan probabilistic agent evaluation | sebuah eval suite adalah product-spesifik |
| When untuk gunakan WebMCP dan MCP | halaman-context versus persistent-server decision | technologies dapat menjadi digunakan together |
| Cloudflare browser Run WebMCP | Experimental lab sessions itu consume/test halaman alat | Not production enablement; halaman contoh lag saat ini Chrome naming |
Status dan compatibility adalah diperiksa July 17, 2026. Recheck ini sources sebelum copying code atau membuat sebuah production decision.
WebMCP implementation checklist
Product fit
- halaman memiliki one bounded tindakan itu adalah materially more reliable sebagai sebuah alat.
- alat solves sebuah pengguna task; ini adalah not menjadi ditambahkan untuk speculative rankings.
- sebuah normal semantic, accessible interface remains sumber kebenaran.
- tindakan belongs untuk saat ini halaman/session alih-alih sebuah background API.
Contract dan lifecycle
- name dan deskripsi adalah pendek, unique, spesifik, dan not generated dari untrusted konten.
- JSON Schema rejects unknown fields dan limits strings, arrays, ranges, dan enums.
- callback reuses yang sama mesin dan authorization path sebagai terlihat UI.
- UI visibly reflects resulting state.
- alat adalah unregistered when navigation atau state membuat ini invalid.
- Unsupported browser retain complete workflow.
Security dan privacy
- Read/write perilaku adalah explicit; annotations adalah treated sebagai hints hanya.
- server authorization adalah enforced independently dari agent.
- Sensitive tindakan memerlukan terlihat, informed confirmation.
- Cross-origin exposure adalah denied unless sebuah named gunakan case memerlukan ini.
- alat output adalah minimized dan treated sebagai untrusted downstream input.
- Secrets, cookies, local history, raw private records, dan unrelated state adalah excluded.
- Logs mendukung incident review without storing sensitive payloads.
Release dan evaluation
- Registration, validation, errors, side effects, output, UI parity, dan cleanup memiliki deterministic tests.
- Representative agents memiliki probabilistic selection dan parameterization evals.
- Adversarial prompts, metadata, output, dan confused-deputy cases adalah tested.
- saat ini spec, Chrome milestone, flags/trial, dan vendor docs adalah rechecked.
- fitur adalah not sebuah production dependency while mendukung remains experimental.
WebMCP decision cheat sheet
| jika requirement adalah… | Prefer… |
|---|---|
| gunakan saat ini halaman’s DOM, selection, cart, atau UI state | WebMCP candidate |
| Run without sebuah tab, di background, atau di seluruh banyak clients | Remote MCP atau API |
| Describe sebuah entity atau halaman untuk mesin pencari | data terstruktur |
| Publish readable konten | Semantic HTML |
| Help sebuah client locate preferred situs konten | Ordinary navigation/sitemaps; possibly llms.txt where sebuah client chooses untuk gunakan ini |
| Automate sebuah halaman itu memiliki no explicit alat | browser automation, dengan -nya fragility dan safeguards |
| meningkatkan rankings atau AI citations | None dari ini adalah sebuah documented shortcut |
saat ini syntax dan status
Current object: document.modelContext
Deprecated in C150: navigator.modelContext
Chrome status: 149 origin trial / testing flag
Standards status: Community Group draft, not W3C Standard
Discovery moment: after the client visits the page
Cloudflare role: experimental consuming/test browser tindakan gate
gunakan tindakan sebelum exposing sebuah halaman function:
- sebuah — tindakan adalah bounded. One purpose, explicit input, predictable output.
- C — Context belongs untuk halaman. saat ini tab atau terlihat state adalah genuinely diperlukan; otherwise prefer sebuah API atau remote MCP.
- T — Trust boundary adalah reviewed. Authentication, origins, untrusted konten, confirmation, dan output minimization memiliki owners.
- I — Interface stays complete. ordinary UI adalah accessible dan fully functional without experimental browser mendukung.
- O — One implementation. UI, API/MCP, dan WebMCP panggil yang sama canonical mesin alih-alih drifting ke separate business logic.
- N — angka dapat menjadi diukur. Define task completion, error, clarification, abandonment, unsafe-attempt, dan fallback rates sebelum launch.
jika apa pun letter fails, alat adalah not ready untuk production.
WebMCP anti-patterns
- menambahkan sebuah alat untuk setiap artikel. Readable konten melakukan not become more
discoverable because sebuah halaman registers sebuah meaningless
read_articletindakan. - Treating annotations sebagai enforcement.
readOnlyHintcommunicates intent; ini melakukan not mencegah hidden writes atau guarantee safe model perilaku. - Copying
navigator.modelContextcontoh without sebuah date. Chrome documents move untukdocument.modelContextdan deprecation beginning di Chrome 150. - Giving agent sebuah generic command runner. Broad inputs erase benefit dari sebuah structured contract dan expand prompt-injection impact.
- Leaving stale alat registered. jika halaman disables sebuah tindakan, -nya alat seharusnya not remain callable.
- Returning whole application object. Minimize output; private atau untrusted fields dapat leak data atau poison later reasoning.
- Letting Cloudflare status substitute untuk halaman berfungsi. sebuah beta browser itu consumes WebMCP melakukan not author, register, secure, atau test Anda alat.
- Replacing form dengan experiment. Progressive enhancement berarti human interface survives missing browser mendukung dan API perubahan.
- Calling sebuah private demo production-ready. Contract success adalah not agent reliability, interoperability, atau sebuah completed threat model.
Related alat pada ini situs
- Schema Markup Validator: proposed pertama WebMCP pilot because -nya inputs dan findings adalah bounded dan deterministic. WebMCP adalah not enabled pada ini today.
- MCP alat Suite: situs’s live remote MCP surface dan clearest cara untuk compare sebuah persistent server integration dengan sebuah future halaman alat.
- Agent Readiness Checker: memeriksa several server-terlihat agent signals. ini intentionally seharusnya not score WebMCP because sebuah server-side fetch cannot reliably observe alat registered di sebuah live document.
- Schema Markup Generator: lainnya contoh dari sebuah deterministic human workflow itu harus remain complete regardless dari agent mendukung.
Primary sources
- WebMCP Draft Community Group Report — saat ini draft, API definitions, permissions, security, dan explicit standards status.
- Chrome: WebMCP overview — origin-trial entry poin, limitations, dan testing setup.
- Chrome: Imperative API — saat ini object name, registration, lifecycle, testing, events, dan cross-origin controls.
- Chrome: Declarative API — experimental form annotations dan submission perilaku.
- Chrome: WebMCP alat security — annotations, origin exposure, dan alat-provider safeguards.
- Chrome: Agent security considerations — malicious metadata, contaminated outputs, authenticated sessions, dan defense secara mendalam.
- Chrome: WebMCP best practices — alat scope, deskripsi, state, dan reliability.
- Chrome: WebMCP evals — deterministic testing dan probabilistic agent evaluation.
- Chrome: When untuk gunakan WebMCP dan MCP — frontend/halaman context versus persistent backend boundaries.
- Chrome: Join WebMCP origin trial — Chrome 149 experiment announcement.
- Chrome DevTools: Debug WebMCP alat — registered dan invoked alat inspection.
- Lighthouse: Registered WebMCP alat — informational registered-alat audit.
- Cloudflare browser Run: WebMCP — beta lab sessions dan production limitations; API contoh pada itu halaman lag saat ini Chrome documentation.
Related guides
- Model Context Protocol
- Agentic Search
- llms.txt
- Schema Markup untuk AI
- untuk AI agents — situs’s currently available agent-facing files dan remote MCP surface; ini melakukan not claim WebMCP mendukung.
Compatibility dan status claims adalah verified July 17, 2026. Recheck sebelum implementation because milestones, flags, API names, dan draft text dapat perubahan.
Log perubahan
Diperbarui 20 Jul 2026.
Ringkasan editorial dan detail perubahan yang tercatat.Detail perubahan
-
Catatan perubahan terperinci saat ini tersedia dalam bahasa Inggris.
Perbandingan lengkap tidak tersedia — tidak ada cuplikan sebelumnya yang diarsipkan untuk revisi ini.