MCP and WebMCP solve the same problem from two sides. The Model Context Protocol (MCP) is the standard an AI agent uses to connect to external tools and data: a database, a CRM, a WordPress site. WebMCP brings the same idea into the browser: a web page declares which actions an agent can take, and with which parameters, instead of leaving the agent to guess by clicking around.
For a business website the consequence is practical. Today an agent that needs to request a quote looks for the form, reads the labels and tries to fill it in. With WebMCP the site tells it directly: "there's a request_quote action, and it needs name, email, product and quantity".
MCP in brief
MCP came out of Anthropic, which published it in November 2024. Within a few months OpenAI (March 2025) and Google DeepMind (April 2025) had adopted it. On 9 December 2025 Anthropic donated it to the Agentic AI Foundation, a Linux Foundation fund co-founded with Block and OpenAI and backed by Google, Microsoft, AWS and Cloudflare.
The donation announcement quoted more than 97 million monthly SDK downloads and around 10,000 active servers. ChatGPT, Claude, Gemini, Copilot, Cursor and VS Code all support MCP as clients.
How it works is easy to describe. An MCP server exposes tools, each with a name, a description and a parameter schema. An MCP client, meaning the agent's application, reads them and uses them when it needs to. The agent doesn't have to know how the system on the other side is built: the description is enough.
In the UK "mcp server" gets 9,900 Google searches a month (12-month average, Google Ads data via DataForSEO, checked in October 2026), almost always with developer intent.
WebMCP: the site declares its actions
WebMCP is a browser API that lets a web page register tools for agents. The specification is being incubated in the W3C Web Machine Learning Community Group and, according to the trade press, its authors are engineers from Google and Microsoft.
It has two modes:
- imperative: the site registers a tool in JavaScript with
registerTool(), giving a name, a description, a JSON schema for the parameters and the function to run; - declarative: the site adds annotations to its existing HTML forms, and the browser exposes them as tools.
Here's what a tool declared in JavaScript looks like:
navigator.modelContext.registerTool({
name: "request_quote",
description: "Send a quote request for a product",
inputSchema: {
type: "object",
properties: {
product: { type: "string" },
quantity: { type: "number" },
email: { type: "string" }
},
required: ["product", "email"]
},
execute: async (input) => sendQuoteRequest(input)
});
The exact name of the object (navigator.modelContext or document.modelContext) changes between trial versions. Check the latest specification before writing any production code.
One point in the specification matters: "headless" or fully autonomous use is out of scope. WebMCP assumes a user is present, with an agent helping them inside the browser.
Where it stands
The milestones, from the documentation and the technical press:
| Date | Milestone |
|---|---|
| 12 February 2026 | Preview in Chrome 146 Canary, behind a flag (VentureBeat) |
| 15 May 2026 | Origin trial requested from version 149 to 156, with a stable release planned for 157 (blink-dev) |
| May 2026 | The only agent using WebMCP tools is Gemini in Chrome |
So in September 2026 WebMCP is an experiment, not a standard. In the UK, searches for "webmcp" went from 20-50 a month at the end of 2025 to 2,900 in February 2026, the month of the Chrome preview, and stood at 1,300 in August (Google Ads data via DataForSEO, October 2026). People are talking about it far more than they're using it.
NLWeb
NLWeb is a Microsoft project presented at Build on 19 May 2025. It was conceived by R.V. Guha, the person behind RSS, RDF and Schema.org.
The idea is different from WebMCP. NLWeb turns a site's content, starting from the Schema.org data and RSS feeds many sites already have, into an interface that answers questions in natural language. It exposes an /ask endpoint for people and an /mcp endpoint for agents: every NLWeb instance is also an MCP server. The code is open source under the MIT licence on GitHub.
The first partners included Tripadvisor, Shopify, Eventbrite and O'Reilly. There's no official count of the sites using it in 2026.
How the three differ
| MCP | WebMCP | NLWeb | |
|---|---|---|---|
| Where it runs | On a server, outside the browser | Inside the page, in the browser | On the site's server |
| Who uses it | Any agent with an MCP client | Agents built into the browser | People and agents |
| What it exposes | Tools and data | Actions on the page | Search across the site's content |
| Status in September 2026 | Mature standard, Linux Foundation | Experimental in Chrome | Open source, adoption not measured |
The WordPress case: MCP is already here
On WordPress, MCP isn't a future project. Since version 6.9 the core has included the Abilities API, which lets you register functions with typed inputs and outputs and permission checks. The official WordPress/mcp-adapter plugin, released in February 2026, turns those functions into MCP tools.
Visilay.com is connected this way. We use an MCP server on WordPress that exposes dozens of functions: reading and writing Gutenberg content, managing forms, reading Yoast scores, running WP-CLI commands. An AI agent connected with OAuth authentication can, for example, read an article, add an internal link and publish it without going through the admin dashboard.
What we've learnt:
- permissions matter more than the technology. An MCP server with admin access gives the agent the same power as an administrator. Expose only the functions you need;
- you need an action log. When an agent changes a piece of content, you have to be able to see what it changed and when;
- tool descriptions are instructions. An agent uses a tool according to its description: if the description is vague, it uses the tool badly.
This is the "internal" side of MCP: an agent working on the site. WebMCP is about the "external" side: an agent visiting the site on behalf of a customer.
Use cases for business websites and online shops
Where WebMCP will make sense, once it's stable:
- quote requests with precise parameters (product, quantity, deadline) instead of a generic form;
- catalogue search with filters the agent can pass directly;
- checking stock and delivery times, which is useful for agentic commerce;
- bookings for appointments, demos and site visits.
Where it isn't needed: brochure sites with no actions, blogs, information pages. There it's enough for the HTML to be readable, as explained in our guide to SEO for AI agents.
What to do now
- Don't put WebMCP into production. It's in origin trial and the API may change.
- Make your forms accessible: labels, roles, error messages as text. WebMCP's declarative mode starts from existing HTML forms, and a form that's well built today will be easy to expose tomorrow.
- If you're on WordPress 6.9 or later, look at the Abilities API. It's the quickest way to let an agent work on the site with controlled permissions.
- Keep your structured data clean. NLWeb starts from Schema.org, and so do many agents. The guide is in schema markup.
Further reading: Agentic SEO: what it is and what changes for businesses.
FAQs
It's a browser API, being trialled in Chrome, that lets a web page declare to AI agents which actions are available, with a name, a description and parameters. It's being incubated in the W3C Web Machine Learning Community Group.
MCP connects an agent to tools and data through a server, outside the browser. WebMCP brings the same model into the web page, so an agent browsing the site can use its actions without clicking around by trial and error.
Only as an experiment. It arrived as a preview in Chrome 146 Canary in February 2026, and in May 2026 an origin trial was requested from version 149 to 156, with a stable release planned for 157.
Yes. Since WordPress 6.9 there's the Abilities API, and the official mcp-adapter plugin exposes it as an MCP server. It's best to expose only the functions you need and to use accounts with limited permissions.