Experimental · Chrome 150+ · Off by default
WebMCP browser bridge: tools, setup and approvals
With the experimental WebMCP bridge, AX Code can read pages, call tools a website exposes and interact with its interface. It starts disabled and opens an isolated Chrome window when you enable it.
Why WebMCP matters
A website can tell an agent which actions it offers, what each action does and which inputs it accepts. This gives the agent an explicit tool interface alongside page reading and browser controls, reducing the need to infer every action from the visible interface. You still review permissions and results.
Build websites that agents can use
For developers, WebMCP offers a way to expose existing application features as named browser tools. AX Code can discover and call registered tools in its isolated Chrome window, so you can explore how an agent uses your website while reviewing approval prompts.
What can AX Code do with WebMCP?
WebMCP is a proposed web standard for websites to expose structured tools to agents. AX Code can discover and call those tools, read page snapshots and screenshots, inspect console messages and request metadata, and interact with page controls.
Start with an isolated browser
Install Chrome 150 or newer, start ax-code, then click the WebMCP chip in the sidebar or Home prompt footer. The bridge starts disabled; enabling it opens a fresh browser profile. Sign in manually in that window if needed. The default includes reading and interaction; saved configurations and administrator policy can restrict them. Click the chip again to disconnect and revoke grants.
Try a browser review
Open my local website preview. Read the page and inspect console messages. List any WebMCP tools it exposes and explain what they do before calling them. Do not submit anything or change account settings.
Review what you allow
Page navigation and page-tool calls ask for approval each time. Reading needs one grant per origin per session. Ordinary clicks and hovering use an interaction grant that renews after 20 actions. Typing, key presses, dialogs, links, double clicks and clicks with consequential-looking names ask each time. These name checks are heuristics: read the prompt before approving.
Browser access and limits
Page content is untrusted. The bridge excludes arbitrary script execution, uploads, downloads, cookie access and network request bodies. Administrators can restrict origins or disable either tier or the bridge.
Read the WebMCP browser bridge guideWebMCP questions
Does WebMCP use my existing browser login?
By default, AX Code opens its own isolated Chrome profile. It does not reuse logins from your usual browser. Sign in manually in the bridge window when a task needs an account.
Does every website need to support WebMCP?
A website must register WebMCP tools for AX Code to discover and call them. Page reading and the supported browser interactions can also work on ordinary websites, subject to your grants and configured restrictions.