ChatGPT Now Speaks WebMCP: Is Your Website Ready for AI Agents to Use It Directly?
Hi everyone, this is Neo.
Back in April, I wrote about Google-Agent and UCP, and I spent a good chunk of that post on a protocol called WebMCP — the idea that AI agents could “use” your website the way they use a local app, instead of guessing at buttons by looking at pixels. A lot of you asked the obvious question: when is this actually going to ship?
On August 27, OpenAI announced that WebMCP support is now live in the built-in browser of the ChatGPT desktop app. Websites can register JavaScript functions as “site tools,” and ChatGPT and Codex can call them directly while browsing your page. This is the moment WebMCP went from a concept to a real, shipped feature in a mainstream product.
Let me break down the standard itself, what OpenAI actually built, what you can do with it right now, and how independent site owners should play this.
First, a quick recap: what WebMCP actually is
WebMCP (Web Model Context Protocol) is an open draft specification being developed by the W3C Web Machine Learning Community Group — the latest Community Group Report was published on August 26, and it’s worth noting the spec is not on the W3C Standards Track yet. It’s an experimental, community-led standard.
The core idea in one sentence: a website can declare parts of its functionality as “tools” — JavaScript functions with a natural-language description and a structured input schema — and AI agents can discover and call those tools when they visit the page.
The key difference from the server-based MCP:
- MCP (server-based): Connects an AI app to a local or remote server. Tools can work independently of any open webpage — querying inventory via API, managing records — and they require a separate connection setup.
- WebMCP (page-based): The webpage you’re visiting provides the tools. The agent discovers them on arrival, no MCP connector installation needed. Tools stay bound to the live page and your signed-in session — close the page, and the tools are gone.
Think of it this way: MCP is handing the AI a back-office key; WebMCP is handing it a self-service menu at the front door.
What OpenAI actually shipped
Based on OpenAI’s docs and the August 27 announcement, here’s the rollout picture:
- Where: The built-in browser in the ChatGPT desktop app. Both ChatGPT Work and Codex can discover and use site tools.
- How you see it: When a page offers site tools, an arrow appears in the address bar showing whether a tool can read data or make changes. You can open it to inspect what the site provides.
- Binding: Tools stay linked to the page they were accessed from and disappear when you close that page.
- Model requirements: You need GPT-5.6 Sol or Terra. GPT-5.6 Luna has WebMCP disabled, and site tools aren’t available in Enterprise or Edu workspaces.
- Permissions and safety: Every tool invocation goes through a safety review, and consequential actions — sending messages, making purchases, deleting data, changing permissions — still follow the normal confirmation flow. You can turn site tools off entirely under Settings > Browser > Permissions.
- One important caveat: OpenAI explicitly warns that website-provided tool definitions and results are untrusted content — a tool calling itself “read-only” isn’t proof that it is, and site instructions don’t give the agent permission to share unrelated information or take sensitive actions.
Also worth knowing: this is a subset implementation of WebMCP. What’s not supported yet: the declarative API via HTML form attributes (JavaScript registration only) and tools registered inside iframes (same-origin or cross-origin). For the full API, the W3C draft and Chrome’s developer docs are the reference.
What developers can do right now
If you have engineering help, there’s real work you can start today:
1. Test it in Chrome
Chrome 149 has opened a WebMCP Origin Trial — a time-limited program for early access to experimental platform features. Google’s official use cases:
- Complex structured forms: Build a tool that maps data to fields correctly (e.g., telling a “full name” field apart from “first name”), instead of relying on autofill.
- Application diagnostics: Register a diagnostic tool on a developer settings page so an agent can trigger fixes hidden behind nested menus.
- Dashboard exploration: Let the agent set a date range and dig into the data behind a chart.
- Document collaboration: Let the agent find a section, suggest an edit, or leave a comment for you to review.
2. Register a minimal tool
The docs show a minimal registration right in your page’s JavaScript module:
if (typeof document.modelContext?.registerTool === "function") {
await document.modelContext.registerTool({
name: "get_page_title",
description: "Read the title of the current page.",
inputSchema: {
type: "object",
properties: {}
}
});
}
You can even have Codex do it for you: describe what an agent should be able to do, and ask Codex to reuse your app’s existing logic and permissions.
3. Follow the best practices
- Keep inputs narrow, describe side effects, and return enough information to verify the result.
- Reuse your existing authentication, authorization, and input validation.
- Keep the normal human interface intact for browsers and users that don’t support WebMCP.
What independent site owners should do
Most of you aren’t writing JavaScript, so here are four pragmatic moves:
- Don’t rush — watch first. Site tools in the ChatGPT desktop browser are an experimental feature with negligible traffic right now. The right move isn’t rebuilding your site; it’s putting WebMCP on your technical radar and telling your dev partner or agency to follow the standard.
- Pilot 1-2 high-value actions later. Once the standard settles, the tools most worth registering are: cart operations, order lookup, shipping cost calculators, and stock checks — the exact steps where AI agents get stuck when acting for a user. If you have a tool and your competitor doesn’t, agents will “use” your site first.
- Think about the security boundary now. Opening a tool means opening an interface to every AI agent on the internet. Start with read-only or low-risk operations, and keep sensitive actions behind human confirmation.
- Add “being used” to your AI strategy. We spent the last two years talking about SEO (being seen) and AEO/GEO (being cited). Now add a third layer: being directly operated by AI agents. Your website is no longer just a page for humans — it’s a service that programs can call.
Neo’s take
The real weight of this news isn’t the new ChatGPT feature. It’s this: WebMCP just got its first mainstream endorsement.
The W3C Community Group published an updated draft on August 26; OpenAI announced support on August 27. That timing tells you OpenAI is deeply involved in the spec. And the spec itself names ChatGPT, Claude, and Gemini as the AI platforms it’s designed for. When OpenAI, Anthropic, and Google are all in the room, that’s your common language for “AI agents operating websites” locked in.
My read for independent site owners, in three lines:
- This is an opportunity, not a threat. WebMCP gives small sites an open, official channel to let AI agents do real things on their site — no platform API partnership, no big budget. The standard is open.
- But don’t jump the gun. Agent traffic in the ChatGPT browser is still tiny. Rewriting your site for it today is wasted effort. The right posture is “technical reserve plus a pilot,” not an all-in rebuild.
- The real dividing line is how digitalized your data and operations are. Whether it’s WebMCP or UCP, what ultimately matters is whether your product data, order system, and inventory can be called programmatically. That foundation is the true moat for independent sites over the next five years.
One-line summary: WebMCP shipping is the starting gun for the agent era — not the sprint signal. Position yourself, then wait for the field to catch up.