Overview of 1037: WebMCP is here (and you should care)
This episode of Syntax explores WebMCP—a browser-side standard for exposing web app capabilities to AI agents so they can interact with sites more reliably than by scraping the DOM or clicking around via screenshots. The conversation frames WebMCP as a major step toward a future where humans and agents can co-browse the same UI, with agents handling repetitive or complex tasks while humans stay in the loop when it matters.
What WebMCP Is
WebMCP vs. traditional MCP
- Traditional MCP is server-side and focuses on giving agents tools in chat or within model workflows.
- WebMCP is client-side, designed for the browser and the web platform.
- It’s intended to help agents use the actual application UI and client logic instead of inferring actions from screenshots, the DOM, or accessibility tree.
The core idea
- WebMCP lets developers expose high-level, task-oriented capabilities to agents.
- Instead of “click button A, then menu B, then checkbox C,” the agent can say:
- “Add conditional formatting to this column”
- “Mark these expenses as Canadian taxes”
- “Export this project”
- The point is to translate the agent’s atomic intent into real app actions.
Why It Matters
Better than DOM scraping
The guests repeatedly contrast WebMCP with the current agent approach:
- DOM/screenshot-based navigation is slow
- It causes inference thrashing
- It’s expensive because the model has to re-evaluate at every click
- It’s brittle when UI changes
WebMCP is meant to give the agent a clean capability layer instead of forcing it to reverse-engineer the UI.
Fits real-world usage
The episode emphasizes that not all web use should be fully agentic:
- Sometimes users want the agent to do the work
- Sometimes they want to stay involved and visually verify outcomes
- The future is multimodal and mixed, not “everything becomes headless”
This is where the hosts’ phrase “clicks and clankers” comes in:
- Clicks = humans using the UI
- Clankers = agents doing parts of the work
- The ideal experience blends both
How Developers Can Implement It
Two main approaches
WebMCP can be exposed in multiple ways:
Imperative API
- JavaScript-based
- Lets developers provide a callback as the tool implementation
- Best for modern app code and framework-based apps
Declarative API
- Uses annotations/attributes on existing UI or forms
- Easier for older or simpler sites to adopt
- Useful for legacy systems that want to become more agent-friendly with minimal changes
Recommended implementation strategy
The guests advise developers to:
- Think in terms of task-level milestones, not micro-interactions
- Expose stateful or effectful actions
- Reuse existing app logic like:
- REST endpoints
- GraphQL mutations
- existing action/dispatch systems
- Add useful metadata/hints to tools so agents understand what they can safely do
Good fit for frameworks
They mention that frameworks may eventually infer tools from existing app code, and that hooks/plugins could become common patterns for exposing WebMCP capabilities.
Best Use Cases Discussed
Strongest candidates
The most obvious wins are in applications with:
- Deep, multi-step workflows
- Complex UIs
- Configuration-heavy interactions
- Repetitive batch operations
Examples mentioned:
- Google Sheets
- YouTube
- Shopify
- Instacart
- Bookkeeping software
- Video editors
- 3D modeling/CAD tools
Examples of useful agent tasks
- Batch-edit expenses
- Apply conditional formatting in a spreadsheet
- Surface hidden YouTube settings
- Move through complicated video or 3D editing workflows
- Extract ingredients from a recipe site and add them to a shopping list
- Handle shopping where the user is comfortable delegating routine parts
Security and Trust
Security is a major theme
The guests spend a lot of time on the fact that WebMCP changes the trust model of the web.
Key concerns:
- Prompt injection
- Agent traps
- Untrusted user-generated content
- Cross-origin confusion
- Whether an agent should be allowed to act like the user everywhere
Suggested safeguards
They discuss a layered security strategy:
- Read-only hints
- User-generated content markers
- Origin restrictions
- Prompt injection classifiers
- Critique/validation LLMs
- A potential agent containment layer that gives the agent a more limited identity than the user
The “safe origin policy” idea
Instead of only thinking about the traditional same-origin policy, they talk about designing a safe origin policy for agents:
- The agent should only access the sites and data needed for the task
- It should not freely read cookies, bank info, or unrelated personal data
- Browsers may need an explicit agent harness to enforce this
Measuring Agent Performance
New metrics are needed
The episode argues that we need something like Core Web Vitals for agents.
Ideas discussed:
- Time to first token
- Time per tool call
- Success rates for agent journeys
- How many model turns a task takes
- Whether a tool helps or hurts completion
Why this is hard
A lot of the useful information is hidden inside the agent’s workflow:
- The browser can measure some things
- But success/failure often lives in the model loop
- Developers need visibility into whether their tools are actually improving outcomes
Community tools
They mention tools and frameworks emerging to benchmark agentic UX and WebMCP utility so developers can make data-driven changes.
Ecosystem Status
It’s an open standard effort
This is not just a Google project:
- WebMCP is being developed as a W3C open web standard
- Google is working with other companies and browser/model vendors
- Microsoft, OpenAI, Mozilla, and others are part of the conversation
- There’s active interest from browsers and model providers
Origin trial and hackathon
- Chrome is running an origin trial
- There’s also a WebMCP challenge/hackathon
- The goal is to collect real developer feedback and pressure-test the spec
Broad industry interest
The guests say many companies want a clearer capability layer because it:
- Reduces inference cost
- Makes agents more reliable
- Improves UX
- Allows better security controls
Business, Monetization, and the Future of the Web
Agents change web economics
The episode touches on how agentic browsing affects:
- Ads
- Affiliate/referral flows
- Commerce
- Subscription models
- Upsells and monetization strategies
The guests acknowledge there’s no settled answer yet for:
- Whether agents should click ads
- Whether agents should be blocked from certain revenue-sensitive flows
- How commerce protocols and payment systems will fit in
The broader vision
They see the browser evolving into an agent platform:
- Browsers may eventually provide configurable agent tools and security policies
- Agents may plug into sites through constrained, safe access layers
- The web won’t become “headless only”; it will support multiple interaction modes
Notable Takeaways
- WebMCP is about exposing app capabilities to agents, not replacing the UI.
- The best UI is often the existing app itself, not a sidecar chatbot.
- Human-in-the-loop interaction remains important for many experiences.
- Security and measurement are as important as functionality.
- The web is moving toward a world with both human and agent users, and developers should start designing for that now.
Sick Picks
Dominic Ferrellino
- The Sense of Style by Steven Pinker
Sarah Drasner
- Vintage Story — a harder, survival-focused Minecraft-like game
Plugs
- Dominic: @DomFarolino on X
- Sarah: @SarahEdo on X and other platforms
- Both are speaking at AgentCon in San Jose in October
- Discount code: Community25
