Cloudflare has launched a developer preview that lets websites expose WebMCP interfaces through a single dashboard setting, extending Google Chrome’s emerging proposal for structured AI-agent access to web features. WebMCP is designed to let browser-based agents discover and invoke site-defined tools with JSON Schema inputs and outputs and shared page state, avoiding brittle HTML scraping and simulated clicks. Google has been testing the proposed standard in a Chrome origin trial beginning with Chrome 149, while Cloudflare said its preview currently works in Chrome 145 and later.
Cloudflare’s implementation injects a bridge.js module into pages it serves, where tools can be registered statically or discovered dynamically and execution is proxied back to the site on the same origin. The preview includes two initial tool packs: Content Credentials for reading C2PA image provenance metadata and a Site MCP Server pack that exposes a site’s existing MCP server tools to in-browser agents. The rollout comes with security constraints already outlined in Chrome’s proposal, including requirements for origin-isolated documents, a tools Permissions Policy, and allow="tools" for cross-origin iframe use, while both the standard and Cloudflare’s implementation remain subject to change.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Cloudflare announced a developer preview that lets websites on its platform expose a WebMCP interface through a dashboard switch. The preview initially included Content Credentials and Site MCP Server tool packs, with support described as limited to Chrome 145 and later.
Chrome made the proposed WebMCP standard available through an origin trial starting with Chrome 149, while also allowing local testing via a Chrome flag for development. The announcement described WebMCP as a browser-mediated way for websites to expose structured tools to AI agents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourceblog.cloudflare.com
Open sourcedeveloper.chrome.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.