BusinessMCP

Getting started

WebMCP: Let Agents Use Your Website (2026 Guide)

WebMCP lets a page hand an AI agent real tools instead of making it guess at your DOM. It is a W3C draft from Google and Microsoft, it ships behind a Chrome origin trial that ends in November, and — the part most write-ups skip — almost nothing consumes it yet. Here is the mechanism, the exact code, and where it actually stands.

By the BusinessMCP team9 min readSeptember 17, 2026
WebMCP: Let Agents Use Your Website (2026 Guide) — illustrated overview

Key takeaways

  • WebMCP is a browser API: a page calls document.modelContext.registerTool() to expose named, described, schema-typed actions to an agent in the browser — the same shape as an MCP tool, without a server.
  • It moved from navigator.modelContext to document.modelContext on 21 July 2026. Register on both during the transition; Chrome 150 deprecated the old location while still shipping it.
  • Without an origin-trial token served by the page, document.modelContext is undefined and every registerTool() call is a silent no-op. This is the single most common reason a WebMCP integration "does nothing".
  • The Chrome origin trial runs from Chrome 149 to 156 and ends 16 November 2026. Plan for the token expiring, because an expired one fails silently.
  • Adoption is close to zero: no mainstream agent client calls these tools yet, and checker tools currently outnumber known implementations. Build for the agents arriving, not for traffic today.
  • Third-party origin trials let an external script deliver the token, which is how a tag you already embed can make a site WebMCP-capable without a code change.

What WebMCP actually is

A browser agent trying to do something on your site today has one option: read the rendered page and drive it like a person — find the button, click it, hope the markup has not moved. WebMCP replaces the guessing with a declaration. The page says "here are the things you can do here, here is what each one needs, here is what it returns", and the agent calls them.

It is a W3C Web Machine Learning Community Group draft, authored jointly by Google and Microsoft. The shape is deliberately the same as an MCP tool — a name, a description, a JSON schema and a handler — which is why the two are named alike. The difference is where the tool lives: an MCP server runs on a machine you operate, a WebMCP tool runs in the page.

Page calls registerTool()
Agent reads the tool list
Agent calls a tool with typed arguments
Your JavaScript runs and returns a result

No scraping, no synthetic clicks, and no server round trip — the handler is your own page code.

That difference matters for anything behind a login. The agent inherits the session the browser already has, so a tool can act as the signed-in user without you issuing an API credential to a third party.

The code

A tool is a name, a description, an input schema and a function. The description is doing the real work here — it is what an agent matches against a user request, so write it the way someone would ask.

const mc = document.modelContext ?? navigator.modelContext

if (mc) {
  mc.registerTool({
    name: 'search_products',
    description: 'Search this store's catalogue by keyword and return matching products with prices.',
    inputSchema: {
      type: 'object',
      properties: { query: { type: 'string', description: 'What to search for' } },
      required: ['query'],
    },
    async execute({ query }) {
      const res = await fetch('/api/search?q=' + encodeURIComponent(query))
      const products = await res.json()
      return { content: [{ type: 'text', text: JSON.stringify(products) }] }
    },
  })
}

Guard the whole block on the object existing. Outside the origin trial it is `undefined`, and an unguarded `registerTool()` throws on every page load for every visitor — including the ~100% of them who are not agents.

The origin trial, and why your tools do nothing

WebMCP is not generally available. It ships behind a Chrome origin trial, which means the page must serve a token for your origin or the API is simply not there.

Chrome origin trial at a glance
DetailValue
Chrome versions149 to 156
Ends16 November 2026
Without a tokendocument.modelContext is undefined
Token deliveryA meta tag, an HTTP header, or a third-party script
On expiryFails silently — no console error, no exception

Register at Chrome Origin Trials, then put the token in the page head:

<meta http-equiv="origin-trial" content="YOUR_TOKEN_HERE">

There is one mechanism worth knowing about: third-party origin trials. The token can be delivered by an external script loaded from the origin that registered it, which then injects the meta tag into the host page. That is what lets a tag you already embed switch WebMCP on for a site whose own team never touched the code.

Where adoption actually stands

This is the part most write-ups leave out, so here it is plainly: almost nothing consumes WebMCP tools today.

  • No mainstream agent client calls registered tools in production. Gemini in Chrome is announced as the first consumer.
  • Adoption outside demos is close to zero — one survey of the space noted that checker tools now outnumber known implementations.
  • The spec is a Community Group draft, not a standard. The API has already moved once, in July 2026.

None of which makes it a waste of time. Registering a handful of tools is an afternoon, the failure mode is inert rather than harmful, and the cost of being early is close to nothing. But be honest with yourself about the return: you are preparing for agents that are arriving, not serving traffic that exists.

Which tools to expose

The useful ones are the actions a visitor actually came to perform, not a mirror of your REST API. Three rules:

  1. 1Describe in user language. The description is the matching surface. "Book a meeting with the sales team" beats "createCalendarEvent".
  2. 2Keep them idempotent and safe. An agent may retry. Searching, checking availability and looking things up are ideal; irreversible or money-moving actions want a human confirmation step in your own UI.
  3. 3Return structured text. The agent reads the result, so return the fields it needs to answer — not an opaque id.

Good candidates on a typical business site: search the catalogue or docs, check availability, get a quote, look up an order, start a booking. Bad candidates: anything that spends money, deletes data, or sends a message on the visitor's behalf without them seeing it.

Measuring it

Because the handler is your own JavaScript, a tool call is a normal event you can record — which makes WebMCP the first agent interaction most sites can actually count. Fire your analytics event inside the handler and you get the tool name, the arguments and the outcome.

That is worth setting up before the traffic arrives rather than after, because the interesting question is not "how many agent calls did we get this quarter" but "when did the first one land, and what did it ask for". Our own tracker fires a goal on every registered tool call for exactly this reason — see the AI crawler identifier for the adjacent problem of naming the agents that fetch your pages rather than call your tools.

Frequently asked questions

Is WebMCP the same as MCP?

They share a tool shape and a name, and that is where it ends. MCP tools live on a server you operate and are reached over a transport; WebMCP tools live in a web page and run in the visitor's browser, inheriting whatever session that browser already has. A site can sensibly do both.

Do I need a server to use WebMCP?

No. The handler is page JavaScript. It may call your own API, but the tool itself is registered and executed entirely in the browser.

What happens when the origin trial ends?

Unless Chrome ships the API by default or extends the trial, document.modelContext becomes undefined again and registered tools stop being visible. The failure is silent, which is the thing to guard against: code your integration so an absent API is a no-op, and track the end date.

Is it a security risk to expose tools this way?

It is the same risk surface as the page itself — the handler runs with the visitor's session, so a tool can only do what that visitor could already do. The care is in choosing which actions to expose: keep them idempotent, keep irreversible actions behind your own confirmation UI, and validate arguments exactly as you would from a form.

Does any browser besides Chrome support it?

Not today. It is a Chrome origin trial. Microsoft co-authors the spec, so Edge is the obvious second implementer, but nothing is shipping.

BM

BusinessMCP Team

Every guide is written from running BusinessMCP on its own platform — the match rates, reply rates, and deliverability lessons are from our own data, not recycled blog folklore. About BusinessMCP

Turn your business into one AI-ready MCP server

Connect your tools, install one tracking script, and expose your unified data to any AI agent through a single secure endpoint.

Get started free