Specification feature · interfaces

WebMCP security annotationsWebMCP draft 2026-08-26

Communicate read-only and untrusted-content hints across the site-to-agent boundary.

Terminology basis: WebMCP draft 2026-08-26. WebMCP draft 2026-08-26

WebMCP security annotations: 1 supported, 0 partial, 0 unsupported, 30 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in WebMCP6 capabilities

Current evidence by product

Can my agent use WebMCP security annotations?

Read across for the answer. 1 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported1
  • Partial0
  • Unsupported0
  • Unknown30
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

Communicate read-only and untrusted-content hints across the site-to-agent boundary.

WebMCP is a draft Community Group Report, not a W3C Standard. Positive implementation cells must retain origin-trial, version, permissions, and agent-integration qualifiers.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Chrome WebMCP origin trialdesktop · current
Supported
Target
Chrome 153 WebMCP origin-trial documentation · dated-documentation
Environment
preview-enabled
Observed
2026-08-28
  • origin-trialWebMCP is an experimental origin trial and local testing requires the enable-webmcp-testing flag
  • policyannotations are advisory hints to the consuming agent; they do not by themselves enforce read-only behavior or sanitize untrusted output
Evidence
  1. 1. Evidence checked 2026-08-28: Chrome's origin-trial documentation exposes `readOnlyHint` and `untrustedContentHint` in registered and discovered WebMCP tools and publishes handling guidance for both hints.