Hướng dẫn về WebMCP
WebMCP lets một web trang expose structured tools để an AI agent trong đó trình duyệt. Learn cách điều này differs từ MCP, điều gì Chrome hỗ trợ, security risks, và khi nào nên chờ.
Ngôn ngữ
1 tín hiệu bằng chứng trên trang này
- Công cụ trực tuyến liên quanSchema Markup Validator
WebMCP là an experimental trình duyệt API đó lets an open web trang offer structured tools để an AI agent. Điều này là hữu ích cho bounded trang actions, không web phát hiện hoặc thứ hạng. As of July 17, 2026, điều này là một Community Group draft và Chrome 149 origin trial; hiện tại Chrome các ví dụ dùng document.modelContext, trong khi navigator.modelContext là deprecated trong Chrome 150.
Tóm tắt — WebMCP lets trang web mô tả của nó buttons và functions as structured tools AI agent có thể call trong khi trang là open. đó có thể làm thực trang hành động—searching inventory, validating code, filtering các sản phẩm—nhiều hơn reliable hơn asking agent để guess mà control để nhấp. nó làm không làm trang easier để xếp hạng, crawl, hoặc discover. As của July 17, 2026, nó là experimental: Community Group draft với Chrome 149 origin trial, không finished web tiêu chuẩn.
Điều gì WebMCP là
WebMCP là proposed trình duyệt API đó lets trang web expose structured tools để AI agent operating trong đó trang browsing context. tool có name, mô tả, structured inputs, và code đó thực hiện hành động. Evidence for this claim WebMCP is a proposed browser API through which web applications expose JavaScript-based tools to agents in a browsing context. Scope: WebMCP Draft Community Group Report dated July 10, 2026; the report is not a W3C Standard. Confidence: high · Verified: WebMCP Draft Community Group Report
Imagine một khách truy cập opens một schema validator và asks của họ trình duyệt agent để
“validate this Product JSON-LD.” (bản dịch) «validate này Sản phẩm JSON-LD.» Không có WebMCP, đó agent có thể inspect đó screen,
tìm một text area, paste vào điều này, nhấp đó right button, và interpret đó kết quả.
Với WebMCP, đó trang có thể offer một validate_schema tool với an rõ ràng input
schema và trả về một structured kết quả—trong khi giữ đó visible interface trong sync.
Đó là hữu ích mental model: WebMCP là rõ ràng control surface cho agent đó có đã reached trang. nó không phải new way để publish prose.
hiện tại status on July 17, 2026
WebMCP là moving quickly, so code và compatibility claims cần dates. hiện tại position là: Evidence for this claim As of July 17, 2026, WebMCP is a Community Group draft rather than a W3C Standard, and Chrome documents an origin trial beginning in Chrome 149. Scope: Standards and Chrome experiment status checked July 17, 2026; these are time-sensitive claims. Confidence: high · Verified: WebMCP: Status of This Document Chrome: Join the WebMCP origin trial
| Câu hỏi | hiện tại câu trả lời |
|---|---|
| là nó W3C tiêu chuẩn? | Không. July 10 draft là Community Group Báo cáo và explicitly không on W3C Các tiêu chuẩn Track. |
| Mà JavaScript object nên các ví dụ sử dụng? | document.modelContext. Chrome nói navigator.modelContext là deprecated beginning trong Chrome 150. |
| là nó ổn định trong Chrome? | Không. Chrome documents origin trial beginning trong Chrome 149 plus local kiểm thử flag. |
| Làm nó hoạt động as headless, web-wide directory? | không trong được ghi lại Chrome thử nghiệm. client visits trang để discover đó trang tools. |
| là declarative form API settled? | Chrome documents nó, nhưng hiện tại Community Group draft declarative section là vẫn marked TODO. |
I tìm thấy không chính-nguồn basis trong điều này research truyền để claim ổn định WebMCP hỗ trợ trong Edge, Safari, hoặc Firefox. Microsoft editor contributing để draft không phải giống nhau điều as trình duyệt shipping feature.
WebMCP versus MCP
Model Context Giao thức và WebMCP expose tools tại khác boundaries:
- MCP thường connects AI application để persistent máy chủ. máy chủ có thể cung cấp tools và dữ liệu hoặc không particular trang web là open.
- WebMCP lets open trang expose của nó hiện tại frontend actions và state. Của nó tools có thể thay đổi Khi khách truy cập navigates hoặc Khi hành động becomes không khả dụng.
họ complement mỗi khác. store có thể sử dụng remote MCP cho sản phẩm catalog và WebMCP cho filter, configuration, và checkout steps visible trong khách truy cập hiện tại tab. Evidence for this claim WebMCP is designed for tools owned by an active page and its browser context, while remote MCP commonly connects an AI application to a persistent backend server. Scope: Architecture-selection guidance, not a rule that prevents an application from using both technologies. Confidence: high · Verified: Chrome: When to use WebMCP and MCP
Làm WebMCP help SEO hoặc AI citations?
có không được ghi lại evidence đó thêm WebMCP improves thứ hạng, crawling, lập chỉ mục, AI citations, hoặc phát hiện. được ghi lại feature begins sau khi agent reaches trang và inspects tools khả dụng ở đó. Evidence for this claim The documented Chrome WebMCP experiment requires a browsing context and a client visit to discover page tools; no documented ranking, crawling, indexing, or citation benefit was found in this research pass. Scope: The browser-context and visit requirements are direct documentation; the SEO conclusion is a bounded absence-of-evidence statement as of July 17, 2026, not a prediction about future search systems. Confidence: high · Verified: Chrome: WebMCP overview and limitations Google Search guidance for AI experiences
nó có thể improve completion của on-trang web task. đó có thể là commercially valuable, nhưng nó là sản phẩm và conversion hypothesis—không xếp hạng factor. giữ đang làm ordinary hoạt động đó làm trang discoverable và understandable: semantic HTML, accessible forms, liên kết nội bộ, indexable nội dung, và appropriate dữ liệu có cấu trúc.
Editorial các trang không cần fake tools chỉ để look “agent-ready.” (bản dịch) «agent-ready.» Nếu đó trang chỉ cần để là đọc, readable HTML là đó right interface.
có thể Cloudflare enable WebMCP cho my trang web?
không by itself. Cloudflare trình duyệt Chạy hiện tại offers experimental lab trình duyệt sessions đó có thể visit và kiểm thử các trang với WebMCP tools. của bạn trang vẫn có để define và register những điều đó tools. Cloudflare’s tài liệu cũng nói của nó lab sessions không phải cho production workloads. Evidence for this claim Cloudflare Browser Run offers experimental lab sessions that can consume and test page-provided WebMCP tools, but the page still owns tool registration and Cloudflare says lab sessions are not for production workloads. Scope: Cloudflare product documentation last updated April 23, 2026; its example API names lag current Chrome documentation and should not be used as the API authority. Confidence: high · Verified: Cloudflare Browser Run: WebMCP
đó làm Cloudflare có thể kiểm thử environment hoặc consuming trình duyệt, không chuyển đó converts mỗi existing form và button vào WebMCP.
nên bạn implement nó hiện tại?
cho phần lớn production các trang, chờ. nhỏ riêng tư thử nghiệm có thể làm hợp lý Khi tất cả những điều này là đúng:
- trang đã có bounded, hữu ích hành động;
- thông thường human interface vẫn hoàn tất không có WebMCP;
- hành động là đọc-chỉ hoặc easily reversible;
- giống nhau application logic phục vụ cả hai UI và tool;
- inputs, outputs, authorization, và nhật ký nhận thực security review; và
- thành công có thể là measured không có pretending thử nghiệm ảnh hưởng khả năng hiển thị trên tìm kiếm.
không sử dụng experimental trình duyệt API as chỉ path để cốt yếu task.
Evidence for this claim Chrome documents declarative form annotations such as toolname and tooldescription, but the declarative section of the July 10, 2026 Community Group draft is still marked TODO. Scope: secure browser context Confidence: high · Verified: WebMCP Draft Community Group ReportTóm tắt — WebMCP exposes trang-owned tools từ
document.modelContextđể agent trong active browsing context. imperative API registers name, mô tả, JSON Schema input, các chú thích, và async callback; tools có thể là state-phụ thuộc và unregistered vớiAbortSignal. Chrome documents declarative form layer cũng, nhưng July 10, 2026 Community Group draft vẫn labels của nó declarative section TODO. feature là trong Chrome 149 origin trial, không ổn định cross-trình duyệt baseline. Treat nó as progressive enhancement, không SEO infrastructure, và secure nó as authenticated application surface.
Cách WebMCP hoạt động trong trình duyệt
hữu ích WebMCP lifecycle begins và ends với trang. trang registers chỉ actions đó là hợp lệ trong của nó hiện tại state; agent đã operating trong đó browsing context discovers và invokes một; trang executes của nó thông thường application logic, cập nhật human-visible interface, và trả về bounded kết quả. Khi state thay đổi, trang xóa tools đó không lâu hơn apply. Evidence for this claim The imperative API registers named, described, schema-constrained callbacks and supports state-aware cleanup with AbortSignal plus tool-set change notifications. Scope: Current draft and Chrome experiment; API details may change before stable release. Confidence: high · Verified: WebMCP ModelContext API Chrome: WebMCP Imperative API
Five numbered steps run left to right. First, the page registers a name, description, input schema, and callback. Second, an agent already in the page context discovers it. Third, the agent invokes it with validated structured arguments. Fourth, the page reuses its normal application logic and updates the visible interface. Fifth, it returns a bounded result or safe error. A branch from execution shows that state changes or navigation should unregister the tool with AbortSignal and notify observers through toolchange.
© Patrick Stox LLC · CC BY 4.0 ·
điều này stateful lifecycle là một reason WebMCP nên không become static dump của mỗi function trong JavaScript bundle. tool Đó là không thể trong visible UI nên thông thường là không khả dụng để agent cũng.
WebMCP so với MCP: hai khác runtime boundaries
names invite confusion, nhưng operational boundary là khác. WebMCP lives trong document event loop và hiện tại trình duyệt session. Remote MCP lives tại AI application integration boundary và commonly reaches persistent backend máy chủ. Evidence for this claim WebMCP is designed for tools owned by an active page and its browser context, while remote MCP commonly connects an AI application to a persistent backend server. Scope: Architecture-selection guidance, not a rule that prevents an application from using both technologies. Confidence: high · Verified: Chrome: When to use WebMCP and MCP
The left lane shows WebMCP: a browser agent interacts with an open web page, which owns a JavaScript tool and current visible session state. The page must be open for those tools to exist. The right lane shows remote MCP: an AI application connects through an MCP client to a persistent MCP server, which can remain available outside a browser tab. The two lanes are complementary rather than replacements.
© Patrick Stox LLC · CC BY 4.0 ·
| Interface | nơi nó lives | Khi nó là discovered | trang phải là open? | Best fit |
|---|---|---|---|---|
| WebMCP | Active trình duyệt document | sau khi client visits trang | Có | hiện tại UI state và trang actions |
| Remote MCP | AI client và MCP máy chủ | qua client/máy chủ configuration hoặc phát hiện | Không | Persistent tools, dữ liệu, và backend workflows |
| Web/điểm cuối API | Application backend | qua application-cụ thể integration | Không | Ổn định programmatic access cho known consumers |
| Dữ liệu có cấu trúc | trang markup | During trang processing | thường fetched as nội dung | Describing entities và trang meaning, không executing actions |
llms.txt | Static text file | Khi client chọn để yêu cầu nó | Không active tab bắt buộc | Proposed nội dung hướng dẫn; không callable tool surface |
| trình duyệt automation | Agent/controller interpreting UI | sau khi loading và inspecting trang | Có | Fallback nơi không rõ ràng trang tool tồn tại |
không chọn từ acronym. chọn từ owner của hành động. nếu hành động cần hiện tại DOM, selection, cart, hoặc UI state, WebMCP có thể fit. nếu nó phải chạy trong background, trên nhiều các trang, hoặc không có open tab, sử dụng API hoặc remote MCP.
imperative API
imperative API registers tool qua document.modelContext.registerTool().
tool bao gồm unique name, mô tả, JSON Schema input, execute
callback, và tùy chọn các chú thích. Chrome cũng documents getTools(),
executeTool() cho kiểm thử, và toolchange event. Evidence for this claim Current Chrome documentation uses document.modelContext and says navigator.modelContext is deprecated beginning in Chrome 150. Scope: Chrome implementation guidance checked July 17, 2026; version and API-name claims expire quickly. Confidence: high · Verified: Chrome: WebMCP Imperative API
điều này illustrative candidate hiển thị dự kiến shape cho tương lai Schema Validator pilot. nó không phải đang chạy on điều này trang web, và API có thể thay đổi trước khi ổn định phát hành:
if (document.modelContext) {
const registration = new AbortController();
await document.modelContext.registerTool({
name: 'validate_schema',
description: 'Validate pasted JSON-LD and return bounded issues.',
inputSchema: {
type: 'object',
properties: {
markup: {
type: 'string',
description: 'JSON-LD markup to validate.',
maxLength: 50000
}
},
required: ['markup'],
additionalProperties: false
},
annotations: {
readOnlyHint: true,
untrustedContentHint: true
},
execute: async ({ markup }) => {
const result = await validateWithTheSameEngineAsTheUI(markup);
renderResultInTheVisibleUI(result);
return minimizeValidationResult(result);
}
}, { signal: registration.signal });
// When this page state no longer supports validation:
// registration.abort();
}quan trọng architecture không phải wrapper. nó là đó callback calls giống nhau validator as visible UI, máy chủ-side limits và authorization vẫn apply, và phản hồi là có chủ ý minimized. Feature detection preserves đầy đủ human workflow trong unsupported các trình duyệt.
sử dụng document.modelContext, không stale các ví dụ được xây dựng khoảng
navigator.modelContext; Chrome marks latter deprecated beginning trong Chrome
150. Date đó advice vì feature vẫn experimental.
declarative API có các tiêu chuẩn mismatch
Chrome documents declarative approach đó annotates ordinary forms với
các thuộc tính chẳng hạn như toolname, tooldescription, và
toolparamdescription. nó cũng documents tùy chọn toolautosubmit; nếu không,
người dùng clicks Submit. SubmitEvent.agentInvoked identifies agent-triggered
submission. Evidence for this claim Chrome documents declarative WebMCP form annotations, but the July 10, 2026 Community Group draft says its Declarative WebMCP section is entirely TODO. Scope: A direct comparison between Chrome implementation documentation and the current draft; it does not imply Chrome's experimental implementation is unavailable. Confidence: high · Verified: Chrome: WebMCP Declarative API WebMCP: Declarative WebMCP
Tuy nhiên, đó July 10 Community Group Báo cáo says của nó Declarative WebMCP section là “entirely a TODO” (bản dịch) «hoàn toàn một TODO» và leaves đó form-để-JSON-Schema algorithm chưa xác định. Đó không có nghĩa là Chrome thử nghiệm là imaginary. Điều này có nghĩa là đó implementation tài liệu là ahead of đó normative draft. Treat declarative markup as an experimental Chrome surface, không settled cross-trình duyệt HTML.
Evidence for this claim Chrome documents declarative WebMCP form annotations, but the July 10, 2026 Community Group draft says its Declarative WebMCP section is entirely TODO. Scope: A direct comparison between Chrome implementation documentation and the current draft; it does not imply Chrome's experimental implementation is unavailable. Confidence: high · Verified: Chrome: WebMCP Declarative API WebMCP: Declarative WebMCPcho hiện tại, ordinary semantic forms vẫn durable base. experimental chú thích layer nên enhance them, không bao giờ replace labels, validation, accessibility, xác nhận, hoặc máy chủ-side authorization.
Tool phát hiện, lifecycle, và cross-origin boundaries
hiện tại API có several boundaries worth designing explicitly:
- Browsing context: Chrome thử nghiệm requires trình duyệt context. client visits trang web trước khi nó discovers trang web tools.
- Dynamic availability: register tools Khi họ là hợp lệ và abort của họ
registration Khi state hoặc navigation invalidates them. Observers có thể listen
cho
toolchange. - giống nhau origin theo mặc định:
toolsPermissions Policy defaults để'self'. Cross-origin iframes cần rõ ràng delegation chẳng hạn nhưallow="tools". - Hai-sided cross-origin consent: tool có thể sử dụng
exposedTođể list được phép secure origins, trong khi caller các yêu cầu tools từ named origins vớifromOrigins. Một side opting trong không phải đủ. - Progressive enhancement: unsupported hoặc disabled WebMCP phải leave ordinary trang fully usable.
những điều này là hữu ích nền tảng controls, nhưng họ không turn risky application hành động vào safe một.
Security: trình duyệt session raises stakes
trình duyệt agent có thể operate bên trong người dùng authenticated session. đó có thể là feature—access để hiện tại cart, account, hoặc workspace—và danger. Chrome và draft discuss prompt injection, misleading tool metadata, contaminated tool output, over-rộng parameters, quyền riêng tư leakage, cross-origin exposure, và misuse của signed-trong authority. Evidence for this claim WebMCP tool hints can communicate read-only and untrusted-output intent, but they do not eliminate prompt injection, misleading metadata, privacy leakage, cross-origin risk, or misuse of authenticated browser authority. Scope: Threat-model and defensive guidance; application authorization and confirmation remain implementation responsibilities. Confidence: high · Verified: WebMCP security and privacy considerations Chrome: WebMCP tool security Chrome: Agent security considerations
Treat mỗi tool as công khai application điểm cuối với unusual caller:
- giữ tool hẹp. Một job, rõ ràng inputs, tight enums và lengths, không hidden “làm bất cứ điều gì” parameter.
- Enforce authorization trong application logic. agent không gain nhiều hơn authority hơn signed-trong người dùng, và hint không phải permission.
- Tách biệt đọc từ ghi.
readOnlyHintvàuntrustedContentHintcommunicate risk; họ không enforce nó. - Require visible xác nhận cho consequences. Purchases, submissions, deletions, messages, và account thay đổi cần human-understandable checkpoint.
- Minimize output. trả về chỉ Điều gì task cần; không bao giờ spill session dữ liệu, thô các header, secrets, hoặc unrelated records.
- Treat output as untrusted. string được trả về by một tool có thể become input để sau đó model reasoning. không cho phép nó để smuggle instructions hoặc authority.
- Log boundary. Record tool, input class, authorization decision, xác nhận, kết quả class, lỗi, origin, và lifecycle không có logging secrets.
Đó safe câu hỏi không phải “Can an agent call this?” (bản dịch) «Có thể an agent call này?» Điều này là “Would I expose this as a reviewed endpoint to a caller that can misunderstand instructions and relay untrusted text?” (bản dịch) «Sẽ I expose này as một reviewed endpoint để một caller đó có thể misunderstand instructions và relay untrusted text?»
Kiểm thử contracts và agent behavior riêng
Chrome eval hướng dẫn separates deterministic sản phẩm các kiểm thử từ probabilistic agent các kiểm thử. Evidence for this claim WebMCP testing should combine deterministic contract and UI-state tests with probabilistic evaluation of agent tool selection and use. Scope: Chrome's evaluation guidance; teams must define product-specific tasks, models, risks, and thresholds. Confidence: high · Verified: Chrome: Evals for WebMCP Cả hai quan trọng:
Deterministic các kiểm thử nên verify registration, schema rejection, hợp lệ và không hợp lệ inputs, authorization, rate limits, side effects, lỗi shape, output minimization, UI parity, unregister behavior, và unsupported-trình duyệt fallback.
Probabilistic evals nên đo lường liệu representative agents discover right tool, tránh irrelevant tools, chọn đúng parameters, ask cho clarification Khi bắt buộc, respect confirmations, dừng sau khi thành công, và resist adversarial các mô tả hoặc output.
không sử dụng một demo prompt as phát hành gate. thành công callback proves code ran; nó không prove đó models select nó reliably hoặc đó hành động là safe.
Cloudflare trình duyệt Chạy: hữu ích lab, không enablement
Cloudflare documents WebMCP hỗ trợ trong trình duyệt Chạy experimental lab pool và nói lab sessions nên không là được sử dụng cho production workloads. Của nó April 23 trang cũng contains older Chrome-era kiểm thử names, so sử dụng đó trang as evidence của Cloudflare’s hiện tại sản phẩm offering—không as authority cho mới nhất WebMCP API shape. Evidence for this claim Cloudflare Browser Run offers experimental lab sessions that can consume and test page-provided WebMCP tools, but the page still owns tool registration and Cloudflare says lab sessions are not for production workloads. Scope: Cloudflare product documentation last updated April 23, 2026; its example API names lag current Chrome documentation and should not be used as the API authority. Confidence: high · Verified: Cloudflare Browser Run: WebMCP
Cloudflare có thể cung cấp trình duyệt session và agent path đó consumes tools. nó không thể infer safe contract cho của bạn application hoặc register trang-owned tools bạn đã làm không xây dựng.
Proposed patrickstox.com pilot: Schema Validator
Schema Markup Validator là good tương lai pilot
candidate, không trực tiếp WebMCP implementation. nó đã có bounded pasted
input, deterministic logic, structured các vấn đề, và visible kết quả. tương lai
validate_schema tool có thể reuse giống nhau validation engine as UI và
existing remote MCP tool suite.
pilot nên chờ cho đến khi trình duyệt API reaches ổn định, non-experimental phát hành và truyền fresh security review. đầu tiên version nên là đọc-chỉ, feature-detected, input-limited, phản hồi-minimized, và không khả dụng on preview, admin, hoặc owner-chỉ surfaces. điều này trang web làm không hiện tại claim WebMCP hỗ trợ.
Decision: xây dựng, thử nghiệm, chờ, hoặc skip
| Situation | Decision |
|---|---|
| Ổn định trình duyệt hỗ trợ là bắt buộc cho customer workflow | Chờ và giữ thông thường UI/API hoàn tất |
| bạn có bounded đọc-chỉ hành động và có thể chạy riêng tư lab | Thử nghiệm, với feature detection và không production dependency |
| task cần background hoặc headless execution | sử dụng API hoặc remote MCP |
| trang chỉ publishes nội dung | Skip WebMCP; improve semantic, accessible HTML |
| hành động ghi, purchases, submits, deletes, hoặc exposes riêng tư dữ liệu | không pilot casually; require tách biệt threat model và xác nhận design |
| ổn định implementation ships và all contract/security/parity các kiểm thử truyền | cân nhắc progressive production pilot |
AI summary
- Definition: WebMCP là proposed trình duyệt API cho exposing structured, trang-owned tools để agent trong active browsing context.
- Status on July 17, 2026: Community Group draft, không W3C tiêu chuẩn; Chrome 149 origin trial/local flag, không ổn định cross-trình duyệt hỗ trợ.
- hiện tại Chrome API:
document.modelContext; Chrome deprecatesnavigator.modelContextbeginning trong Chrome 150. - không remote MCP: WebMCP là tab- và trang-state-bound; remote MCP commonly connects AI application để persistent backend máy chủ.
- không phát hiện hoặc xếp hạng: không được ghi lại benefit cho crawling, lập chỉ mục, thứ hạng, AI citations, hoặc reaching trang trong đầu tiên place.
- Declarative caveat: Chrome documents form các chú thích, trong khi July 10 Community Group draft vẫn marks đó normative section TODO.
- Security: authenticated trình duyệt state, prompt injection, poisoned metadata hoặc output, rộng inputs, và cross-origin exposure làm least privilege, xác nhận, máy chủ authorization, và nhật ký essential.
- Cloudflare: trình duyệt Chạy có thể consume/kiểm thử WebMCP trong experimental lab sessions; nó không tạo tools on trang web.
- Khuyến nghị: giữ human UI hoàn tất và chờ cho ổn định hỗ trợ; riêng tư các thử nghiệm nên là bounded, reversible, và measurable.
- điều này trang web candidate: tương lai đọc-chỉ Schema Validator pilot. nó là proposed, không implemented.
Điều gì chính sources establish
| Nguồn | Điều gì nó hỗ trợ | quan trọng limit |
|---|---|---|
| WebMCP Draft Community Group Báo cáo | API definitions, lifecycle, permissions, risks, các tiêu chuẩn status | Community Group báo cáo không phải W3C tiêu chuẩn |
| Chrome WebMCP overview | hiện tại Chrome thử nghiệm, trình duyệt-context limitation, local kiểm thử | Chrome implementation hướng dẫn không phải cross-trình duyệt hỗ trợ |
| Chrome imperative API | document.modelContext, registration, phát hiện, execution, events, cross-origin rules | Subject để thay đổi; navigator.modelContext là deprecated trong Chrome 150 |
| Chrome declarative API | Experimental form các chú thích và submit behavior | hiện tại Community Group draft corresponding section vẫn TODO |
| WebMCP tool security | Tool các chú thích, origin exposure, defensive hướng dẫn | Hints không bảo đảm safety |
| WebMCP evals | Deterministic các kiểm thử và probabilistic agent evaluation | eval suite là sản phẩm-cụ thể |
| Khi nào nên dùng WebMCP và MCP | trang-context versus persistent-máy chủ decision | technologies có thể là được sử dụng together |
| Cloudflare trình duyệt Chạy WebMCP | Experimental lab sessions đó consume/kiểm thử trang tools | không production enablement; trang các ví dụ lag hiện tại Chrome naming |
Status và compatibility là checked July 17, 2026. Recheck những điều này sources trước khi copying code hoặc đang làm production decision.
WebMCP implementation checklist
Sản phẩm fit
- trang có một bounded hành động Đó là materially nhiều hơn reliable as tool.
- tool solves người dùng task; nó không phải là đã thêm cho speculative thứ hạng.
- thông thường semantic, accessible interface vẫn nguồn của truth.
- hành động belongs để hiện tại trang/session thay vì background API.
Contract và lifecycle
- name và mô tả là ngắn, unique, cụ thể, và không generated từ untrusted nội dung.
- JSON Schema rejects unknown các trường và limits strings, arrays, ranges, và enums.
- callback reuses giống nhau engine và authorization path as visible UI.
- UI visibly reflects resulting state.
- tool là unregistered Khi navigation hoặc state làm nó không hợp lệ.
- Unsupported các trình duyệt retain hoàn tất workflow.
Security và quyền riêng tư
- đọc/ghi behavior là rõ ràng; các chú thích là được xem như hints chỉ.
- máy chủ authorization là enforced independently của agent.
- Sensitive actions require visible, informed xác nhận.
- Cross-origin exposure là denied trừ khi named sử dụng case requires nó.
- Tool output là minimized và được xem như untrusted downstream input.
- Secrets, cookies, local history, thô riêng tư records, và unrelated state là excluded.
- nhật ký hỗ trợ incident review không có storing sensitive payloads.
Phát hành và evaluation
- Registration, validation, các lỗi, side effects, output, UI parity, và cleanup có deterministic các kiểm thử.
- Representative agents có probabilistic selection và parameterization evals.
- Adversarial prompts, metadata, output, và confused-deputy cases là tested.
- hiện tại spec, Chrome milestone, flags/trial, và vendor tài liệu là rechecked.
- feature không phải production dependency trong khi hỗ trợ vẫn experimental.
WebMCP decision bảng tra nhanh
| nếu requirement là… | Ưu tiên… |
|---|---|
| sử dụng hiện tại trang DOM, selection, cart, hoặc UI state | WebMCP candidate |
| Chạy không có tab, trong background, hoặc trên nhiều clients | Remote MCP hoặc API |
| Mô tả entity hoặc trang Đối với tìm kiếm engines | Dữ liệu có cấu trúc |
| Publish readable nội dung | Semantic HTML |
| Help client locate được ưu tiên trang web nội dung | Ordinary navigation/sitemaps; possibly llms.txt nơi client chọn để sử dụng nó |
| Automate trang đó có không rõ ràng tool | trình duyệt automation, với của nó fragility và safeguards |
| Improve thứ hạng hoặc AI citations | None của những điều này là được ghi lại shortcut |
hiện tại syntax và status
Current object: document.modelContext
Deprecated in C150: navigator.modelContext
Chrome status: 149 origin trial / testing flag
Standards status: Community Group draft, not W3C Standard
Discovery moment: after the client visits the page
Cloudflare role: experimental consuming/test browser HÀNH ĐỘNG gate
sử dụng HÀNH ĐỘNG trước khi exposing trang function:
- ** — Hành động là bounded.** Một purpose, rõ ràng input, dễ dự đoán output.
- C — Context belongs để trang. hiện tại tab hoặc visible state là genuinely bắt buộc; nếu không ưu tiên API hoặc remote MCP.
- T — Trust boundary là reviewed. Authentication, origins, untrusted nội dung, xác nhận, và output minimization có owners.
- I — Interface vẫn giữ hoàn tất. ordinary UI là accessible và fully functional không có experimental trình duyệt hỗ trợ.
- O — Một implementation. UI, API/MCP, và WebMCP call giống nhau canonical engine thay vì drifting vào tách biệt business logic.
- N — Numbers có thể là measured. Define task completion, lỗi, clarification, abandonment, unsafe-attempt, và fallback rates trước khi launch.
nếu bất kỳ letter fails, tool không phải ready cho production.
WebMCP anti-patterns
- Thêm tool để mỗi bài viết. Readable nội dung không become nhiều hơn
discoverable vì trang registers meaningless
read_articlehành động. - Treating các chú thích as enforcement.
readOnlyHintcommunicates intent; nó không ngăn hidden ghi hoặc bảo đảm safe model behavior. - Copying
navigator.modelContextcác ví dụ không có date. Chrome documents move đểdocument.modelContextvà deprecation beginning trong Chrome 150. - Giving agent generic command runner. Rộng inputs erase benefit của structured contract và expand prompt-injection impact.
- Leaving stale tools registered. nếu trang disables hành động, của nó tool nên không vẫn callable.
- Returning toàn bộ application object. Minimize output; riêng tư hoặc untrusted các trường có thể leak dữ liệu hoặc poison sau đó reasoning.
- Letting Cloudflare status substitute cho trang hoạt động. beta trình duyệt đó consumes WebMCP không tác giả, register, secure, hoặc kiểm thử của bạn tools.
- Thay thế form với thử nghiệm. Progressive enhancement có nghĩ là human interface survives bị thiếu trình duyệt hỗ trợ và API thay đổi.
- Calling riêng tư demo production-ready. Contract thành công không phải agent reliability, interoperability, hoặc đã hoàn tất threat model.
Related tools on điều này trang web
- Schema Markup Validator: proposed đầu tiên WebMCP pilot vì của nó inputs và findings là bounded và deterministic. WebMCP không phải enabled on nó hôm nay.
- MCP Tool Suite: trang web trực tiếp remote MCP surface và clearest way để so sánh persistent máy chủ integration với tương lai trang tool.
- Agent Readiness Checker: kiểm tra several máy chủ-visible agent các tín hiệu. nó intentionally nên không score WebMCP vì máy chủ-side fetch không thể reliably observe tools registered trong trực tiếp document.
- Schema Markup Generator: một ví dụ của deterministic human workflow đó phải vẫn hoàn tất regardless của agent hỗ trợ.
Chính sources
- WebMCP Draft Community Group Báo cáo — hiện tại draft, API definitions, permissions, security, và rõ ràng các tiêu chuẩn status.
- Chrome: WebMCP overview — origin-trial entry point, limitations, và kiểm thử setup.
- Chrome: Imperative API — hiện tại object name, registration, lifecycle, kiểm thử, events, và cross-origin controls.
- Chrome: Declarative API — experimental form các chú thích và submission behavior.
- Chrome: WebMCP tool security — các chú thích, origin exposure, và tool-provider safeguards.
- Chrome: Agent security considerations — malicious metadata, contaminated outputs, authenticated sessions, và defense trong depth.
- Chrome: WebMCP thực hành tốt nhất — tool phạm vi, các mô tả, state, và reliability.
- Chrome: WebMCP evals — deterministic kiểm thử và probabilistic agent evaluation.
- Chrome: Khi nào nên dùng WebMCP và MCP — frontend/trang context versus persistent backend boundaries.
- Chrome: Join WebMCP origin trial — Chrome 149 thử nghiệm announcement.
- Chrome DevTools: Debug WebMCP tools — registered và invoked tool inspection.
- Lighthouse: Registered WebMCP tools — informational registered-tool audit.
- Cloudflare trình duyệt Chạy: WebMCP — beta lab sessions và production limitations; API các ví dụ on đó trang lag hiện tại Chrome tài liệu.
Related các hướng dẫn
- Model Context Giao thức
- Agentic Tìm kiếm
- llms.txt
- Schema Markup cho AI
- cho AI agents — trang web hiện tại khả dụng agent-facing files và remote MCP surface; nó không claim WebMCP hỗ trợ.
Compatibility và status claims là verified July 17, 2026. Recheck trước khi implementation vì milestones, flags, API names, và draft text có thể thay đổi.
Nhật ký thay đổi
Đã cập nhật 8 thg 8, 2026.
Tóm tắt biên tập và chi tiết thay đổi đã ghi nhận.Chi tiết thay đổi
-
Ghi chú thay đổi chi tiết hiện chỉ có bằng tiếng Anh.
Không thể so sánh đầy đủ — không có bản lưu trước đó cho lần sửa đổi này.
Đã cập nhật 20 thg 7, 2026.
Tóm tắt biên tập và chi tiết thay đổi đã ghi nhận.Chi tiết thay đổi
-
Ghi chú thay đổi chi tiết hiện chỉ có bằng tiếng Anh.
Không thể so sánh đầy đủ — không có bản lưu trước đó cho lần sửa đổi này.