Chrome shipped a hidden WebMCP flag in 146 (spotted by Maximiliano Firtman, source:
tweet). When enabled, sites can
expose tools declaratively or via the imperative navigator.modelContext API. Agents can then
call those tools directly, skipping the DOM gymnastics that CDP/Playwright workflows rely on.
Here's what it looks like in practice. Say you run an e-commerce site and want to let agents check a user's cart and add items without navigating to the cart page or clicking "Add to Cart" buttons:
// Let agents read cart state directly, no page navigation needed
navigator.modelContext.registerTool({
name: "get_cart_items",
description: "Returns all items currently in the user's shopping cart",
input_schema: { type: "object", properties: {} },
async execute() {
const cart = await cartStore.getItems();
return {
items: cart.map(item => ({
name: item.name,
price: item.price,
quantity: item.quantity
})),
total: cart.reduce((sum, i) => sum + i.price * i.quantity, 0)
};
}
});
// Let agents add items, no "Add to Cart" button clicks
navigator.modelContext.registerTool({
name: "add_to_cart",
description: "Adds a product to the cart by SKU",
input_schema: {
type: "object",
properties: {
sku: { type: "string" },
quantity: { type: "integer", default: 1 }
},
required: ["sku"]
},
async execute({ sku, quantity }) {
const result = await cartStore.addItem(sku, quantity);
return { added: result.name, newTotal: result.cartTotal };
}
});
The agent never opens the cart page. It calls get_cart_items, gets structured JSON back
with every item, price, and quantity, then calls add_to_cart with a SKU. No screenshots,
no CSS selectors, no retries when the layout changes.
The real shift isn't speed. It's that agents get the page's actual state handed to them directly.
Today's browser agents screenshot, OCR, navigate menus, and click through a dozen elements to discover
what's on screen. With WebMCP, a tool call returns the cart contents, the form values, the dashboard
metrics. The agent never touches the UI. It reads state and executes actions through the same
structured interface. That get_cart_items call above? A screen-scraping agent would need
to navigate to the cart page, wait for render, screenshot, parse the image, and hope the layout hasn't
changed. WebMCP returns the same data in one call as typed JSON.
A tool contract is an API surface. That means API-grade guardrails, not just CSRF tokens. Treat every exposed action like a public endpoint with user intent gating.
The flag is new and likely to shift. Watch for: Chrome surfacing UI for user consent; other browsers aligning on the API; and SaaS apps publishing first-class manifests. When "agents are users" becomes a browser primitive, your API hygiene becomes your UX. Ship the tool contracts before the UI glue dries.
WebMCP gives agents direct tool access in the browser. We already saw what happens when agentic tool ecosystems skip security. 230+ malicious skills hit ClawHub in two weeks.
Read the supply chain post →