webmcp: one of 35 homepages lets AI agents call it, and it is Cloudflare's own
webmcp is a new browser standard that lets a site hand a set of tools to the AI agent visiting it. On 35 homepages read 2026-09-30, exactly one runs it, and it is Cloudflare's own site.

RULE CHANGE · 2026-08-06 · Cloudflare WebMCP
webmcp is a browser standard that lets a page hand a set of tools to the AI agent visiting it, instead of forcing that agent to guess its way through a page built for a human. On 35 homepages we could read on 2026-09-30, exactly one exposes it, and that one is Cloudflare's own. The change is real and the adoption is not, which is the most useful thing we can say about it today.
What the change actually is
Cloudflare launched a developer preview of WebMCP on 6 August 2026. In its own words, "WebMCP is a new browser standard, shipping experimentally in Chrome 146, that shows up in the page as document.modelContext." A site can then register tools the visiting agent can call, and the announcement frames the point plainly: the previous path, crawlers copying content back to a server, "too often, give the original site none of the traffic and little of the credit."
The Cloudflare preview does not ask you to write that code. Flip one setting in the dashboard, under Agent Readiness, and the edge injects a single line into each HTML response:
<script type="module"
src="/.webmcp/bridge.js"
data-packs="c2pa,mcp-server-client"
data-mcp-url="/mcp"></script>
The tag and the script it loads are served from the edge, on the same origin, so nothing about the page changes for a visitor whose browser has no such surface. The bridge then composes the named packs into one tool list and registers each with registerTool. Two packs ship in the preview: one reads Content Credentials out of images, the other proxies to your own Model Context Protocol server. Cloudflare is explicit that this is a developer preview and that every tool in it runs in the visitor's browser, not on a server of theirs.
How we checked, and what one crawl can see
We fetched 35 homepages once each on 2026-09-30 with curl, a desktop Chrome user agent, redirects followed and no JavaScript, and looked for the three tell-tale strings: the word webmcp, the bridge path /.webmcp/bridge, and modelContext. Four of 39 sites (nytimes.com, medium.com, stackoverflow.com, canva.com) answered 403 and were dropped. We did the same to the six sites we run.
One page matched, and the match is worth reading carefully. Cloudflare's homepage carries inline script that reads document.modelContext, returns early if it is absent, and calls registerTool for a list of tools, with a console warning that reads "WebMCP tool registration failed." We found no /.webmcp/bridge.js tag on the page, so its own site appears to wire the standard by hand rather than through the dashboard injection it is selling.
| Signal | Homepages | Our six sites |
|---|---|---|
| Sites fetched and usable | 35 of 39 | 6 of 6 |
| Exposes WebMCP | 1 | 0 |
| Uses the Cloudflare bridge tag | 0 | 0 |
Mentions modelContext at all | 1 | 0 |
The single match also marks the limit of the method. Reading HTML only tells you whether the code is present in the response. It cannot tell you whether an agent can reach the tools, whether the tools work, or whether any agent has ever tried.
webmcp: what it means for a content site
If you publish articles, the honest answer is that this changes nothing for you yet, and here is why that is still worth knowing. The standard is aimed at tasks, not reading: booking, filtering, configuring, the things a person does with clicks. A content page has almost nothing of that shape. What it does change is the direction of travel. An agent that can call a site gets clean, structured answers instead of reconstructing them from HTML, and that is the same goal as the reader-facing work the rest of this blog is about.
The five things a reader can actually do today:
- Check your own page. One request and one grep tells you whether anything is there:
curl -s https://your-site.example | grep -i webmcp. - Do nothing else unless you sell a task. If your site is mostly read-only content, there is no tool to expose yet.
- Watch the standard, not the vendor. Chrome 146 is experimental; the surface can move before it is stable.
- Keep the fallback. Serving clean HTML and markdown to non-rendering clients is the part that works today, and this does not replace it.
- Do not treat exposure as a ranking tactic. There is no documentation that any search or answer engine ranks a page by whether it speaks it.
A standard nobody has adopted is not a best practice. It is a checkpoint.
What we cannot tell you is what happens on the other side of the call. We have no agent that speaks it, so we did not run a single tool, and we do not know whether Cloudflare's tools return anything an agent would find useful. That is the whole reason we report the string we found rather than a working example.
Common questions
What is webmcp?
It is a browser standard, experimental in Chrome 146, that exposes a page's tools to an AI agent through document.modelContext. It is unrelated to how crawlers copy your content; it is about an agent doing something on the page rather than reading it.
Should I turn on the Cloudflare preview?
Only if your site has a task an agent could perform. For a blog or a brochure site, the answer is no, and the preview being a preview makes that an easy call to defer.
Does it help SEO or AI citations?
No engine documents it as an input, and we would not present it as one. The connection to this blog is direction of travel, not measured effect.
How did you measure this?
One request per homepage on 2026-09-30, desktop Chrome user agent, redirects followed, no JavaScript, searching the returned HTML for three strings. Four sites returned 403 and were dropped, leaving 35. We did not call any tool and did not open a browser.
The pattern here is the same one that runs through the rest of this site: a platform ships a capability, the marketing says "any site", and a count over real homepages says one. The quieter half of the same story is how sites already serve non-rendering clients, in serving markdown to AI crawlers. The Cloudflare control that most sites actually trip over is in which AI crawlers got in, and the setting that decides whether your content trains a model at all is in block AI training without blocking search. Getting any of that onto a page you control is the part QueryWin works on.


