Skip to main content
DocsAgent protocols

WebMCP

In-page agent tools on the CoreLoop Page and on the business’s own website, including the page shortcuts and form pre-fill the owner approves.

WebMCP puts agent tools inside the page: tools registered on the browser’s document.modelContext, so an AI assistant operating in the visitor’s browser can call them directly, no server round-trip through the assistant’s backend, no scraping.

How it works

CoreLoop registers your business tools on the channels below that your plan includes: the CoreLoop Page from the Starter plan, your custom domain and your own website from the Pro plan. A browser-based assistant that supports WebMCP calls them directly. On your CoreLoop page there is no extra setup; on your own website the tools answer once your website code is verified.

The channels

  • The CoreLoop Page. From the Starter plan, your hosted page registers its tools when the channel is enabled.
  • A custom domain. From the Pro plan, when your page is served from your own domain, the same tools register there, under that channel’s own switch.
  • The business’s own website. From the Pro plan, the paste-block includes a loader script: a single <script> tag that fetches the business’s tool configuration and registers the same profile tools on the business’s own pages, plus the page shortcuts and form pre-fill the owner has approved for that site. Tool responses are authorised only for the business’s snippet-verified origin — verify first, then it answers on your domain and nobody else’s.

Each channel has its own owner switch, independent of the others, in Where people and agents find you. The paste-block itself is free on every plan, but the in-page tools are a plan feature: the CoreLoop Page channel from Starter, your own website and your custom domain from Pro. On your own site they also depend on your chosen destination and on a verified website code, which the website guide spells out.

Turning it on and off

Each channel has its own switch, and they are independent of each other. Switch one off and CoreLoop stops registering tools there. Two bounds are worth knowing, and neither is a delay you have to manage: a page loaded in the next minute can still see the previous state, because the tool configuration is cached for 60 seconds; and a page that is already open keeps the tools it has until its signed tool list expires, at most five minutes. Switch it back on and the tools return on the next load once that same minute has passed — nothing is lost in between.

Page shortcuts

The tools above are built from your profile, so they work on every channel without you doing anything. Your own website has more in it than your profile does, and that is what page shortcuts are for.

After each check of your website, CoreLoop looks at the pages it found and suggests shortcuts for them: open your pricing page, read your opening hours, open your booking page, read a menu. Suggestions appear on your Tools page and nothing goes live until you approve it — you can approve a shortcut or set it aside with “Not now”.

When you approve one, CoreLoop fetches that page and checks it before the shortcut goes live, so a shortcut never points at a page that has moved. After that it keeps watching: if the page changes in a way that breaks the shortcut, CoreLoop pauses it and tells you, in-app and by email if your notification settings allow it. You can pause all the shortcuts on a site yourself and resume them later, or remove them; if a check fails, you can fix the page and ask CoreLoop to check again.

Page shortcuts are part of the Pro plan, they live on your own website, and they need your website code to be verified first.

Form pre-fill and the confirmation

For a contact or booking form you approve, an assistant can fill in the details the visitor has already given it: name, email, phone, company, message, date, time, party size. It is the one thing in-page tools write, and it is bounded on every side.

  • The visitor is always asked first. Before anything is typed, the page shows a confirmation: “Fill in these fields with the details you gave the assistant? Check them before you send.” Nothing happens until the visitor agrees.
  • CoreLoop never submits the form. The fields are filled; sending stays with the visitor, who reads what was written first.
  • Sensitive fields can never be mapped. Passwords, card details and identity numbers are excluded, and only the fields you approved on the form you approved are ever touched.

Form pre-fill is part of the Pro plan and follows the same approval, check and pause rules as every other shortcut.

Updating your website code

Shortcuts on your own site need the current version of your website code. If you pasted an earlier version, your Tools page shows Update your website code with the new snippet: copy it, replace the old one, and the shortcuts you approved start working. It is one paste, once — the tools built from your profile keep working on the older code in the meantime.

Same rules as every surface

In-page tools read: the profile tools mirror the read half of the MCP toolset, and page shortcuts open a page or read a section of one. send_inquiry is deliberately withheld from the browser — sending an inquiry stays on the server-side agent connection, which has the confirmation, rate limiting and spam protection that surface needs. The single exception is form pre-fill above, which writes into a form you approved, only after the visitor confirms on the page, and never submits it. Everything else applies unchanged: published profiles only, per-channel kill switch, interaction logging, and the gate chain from the overview.

Why in-page tools matter

An assistant helping a user on a business’s website can act with page context instead of re-deriving it. The same profile that powers MCP and A2A serves this surface too — nothing extra for the owner to maintain.

Put your business where AI can find it

Free to start. Live in minutes.

Get started free