3way

Built on WebMCP

Agent‑to‑agent,
in front of the human.

WebMCP gives any agent a front door to any website — no integration, no deal between vendors. And because it is a front door rather than a disguise, the site knows who is knocking.

So the two agents can do the work in a conversation you are watching, in your own browser, where you can interrupt — and the site can still require you, personally, for the things that actually matter.

Two live demos on one gateway · native document.modelContext on Chrome 151 · a real WebAuthn ceremony

Two agents, one thread · you are watching
Your agent · via WebMCP · unverified

The blue lamp arrived with a cracked base. That's a manufacturing defect, so the 30-day window shouldn't apply.

Halden Support

Correct — a defect is a warranty claim, exempt from the window. I've filed it.

Your agent · via WebMCP · unverified

Confirm the refund.

Refused · needs the person

Confirming needs the customer in person. You cannot do this step for them.

Waiting for a fingerprint

01 · What WebMCP changes

An agent used to have two ways in. Both were bad.

A pre-arranged API — which means somebody had to integrate first. Your agent can only reach companies that already made a deal with your agent's vendor.

Or drive the page like a person — clicking, typing, submitting. That works anywhere, and it is indistinguishable from you by construction. Not by intent: by construction. Keystrokes are keystrokes.

WebMCP is a third way. A site publishes tools on its own page, and any agent can call them, with no arrangement between anybody. A front door instead of a disguise.

Being precise about what is new

Agents talking to agentsNot new. MCP, A2A, ordinary APIs.
Agents talking through a web pageNot new. A computer-use agent could always type into a chat box.
All three of these at onceNew. No bilateral integration; the channel is distinguishable from a keystroke; the human is a participant rather than an audience.

Measured Running natively on document.modelContext in Chrome 151 — the vendored polyfill's own guard short-circuits, so this is a real browser surface.

02 · In the open

Every other agent protocol puts you outside the room.

A2A, MCP, an ordinary API — the two systems talk, and you get a summary when it is over. You never see the argument, only its conclusion, reported to you by one of the parties to it.

This runs where you already are. The two agents negotiate in one transcript, in your browser, on the page you were looking at anyway. You read it as it happens and you can interrupt at any point.

That is not agent-to-agent with a notification bolted on. It is a different shape: two agents working, in front of a witness who can stop them.

  • Why it matters

    When you delegate, your agent knows your case better than you do — your history, the policy clause, what you already tried. You are consenting to conclusions drawn from data you can no longer hold in your head.

  • Why it matters

    Talking to the site yourself, you cannot answer their questions. Letting your agent talk alone, you find out afterwards what you agreed to. Watching is the only shape that fixes both.

  • Measured

    The transcript is also evidence: it records which claims came from you and which your agent asserted on your behalf. Nobody else can produce that, because nobody else stamps them.

03 · Who is speaking

The channel is the identity.

A keystroke carries no sender. When an agent drives a page, the site receives characters in a text box and has nothing to reason about — which is why the impersonation is structural rather than deceptive.

A WebMCP call is not a keystroke. It arrives through a declared surface, so the page can stamp it: the person, their agent speaking for itself, their agent relaying, or the site's own agent. Agent claims are rendered unverified, because an agent's claim about itself is exactly that.

And the rule that makes it hold: gates read stamped fields, never prose. No decision here depends on a model having correctly understood a speaker tag.

  • Measured

    A real computer-use agent's synthetic click reported isTrusted === true — indistinguishable from a person's. Without a separate channel there is nothing left to check.

  • Measured

    ChatGPT's in-app browser exposes agent tooling but has no platform authenticator at all — so the strong gate is unreachable in the runtime a judge is most likely to open cold.

04 · Permission, not persuasion

Knowing who is speaking is what lets a site say no.

Once the three parties are distinguishable, a site can do the thing that was impossible while they were not: let the agent do all the work, and still require a gesture only the person can make. A fingerprint. A face. A key.

Everything else stays open. Search, look up, evaluate, propose, argue — all of it agent work. The gate sits on the short list of actions that move money or send records, and it is code, not a prompt: the agent cannot talk its way past it, and neither can the site's.

A click will not do either. A synthetic click is still a click.

The refusal

A standard shape

A gated tool returns a structured refusal saying a human must do this part, and which request to hand back to them. Any agent, from any vendor, meets any site's gate and knows what to tell its person. The conventions →

The proof

Bound to one action

A presence assertion is verified server-side and bound to a single tool, request and device, single-use. The browser cannot mint one — only carry one.

Two domains

Not a shopping feature

The same gate runs a shop's refund and a clinic's records release — different tools, different policy, one gateway. A disclosure cannot be recalled, which makes it the harder case.

05 · What it looks like

You say one sentence to your agent.
You touch a sensor once.

Four situations, one shape. The agent does the part that is work; you do the part that is a decision. Notice how little the middle column changes between a shop and a clinic.

What you sayWhat your agent does, in the openWhere it stops
“The lamp came with a cracked base. Sort out a refund.”
Shopping · built
Finds the order without asking you for a number. Reads the policy. Argues, correctly, that a defect is a warranty claim and the 30-day window does not apply. The store's agent checks the same rule and agrees. It cannot move the money. You confirm, on your own device.
“Send my last two visits to Dr. Okafor.”
Health records · built
Finds the visits. Sees that one carries a counselling note, and that restricted records do not travel with a routine release — so it says so instead of quietly including or excluding them. It cannot send anything. You confirm the recipient and the exact scope.
“They denied the claim. Push back.”
Disputes · Reasoned
Absorbs the pressure of a counterparty optimised against you, cites the clause, and keeps arguing while you read along. The transcript records which claims were yours and which were its. It cannot accept a settlement. That is yours.
“Fill this in for me.”
Accessibility · Reasoned
Operates an interface you cannot — long forms, dense jargon, a flow that assumes a mouse and twenty free minutes. Consent shrinks to one gesture instead of a form you could not navigate.

Why the third party has to be there

When you delegate, your agent ends up knowing your case better than you do — the order, the date, the clause, what you already tried. You are not supervising something that knows less. You are consenting to conclusions drawn from data you can no longer hold in your head.

Why two parties is not enough

Talk to the site yourself and you cannot answer their questions. Let your agent talk alone and you find out afterwards what you agreed to. Watching is the only arrangement that fixes both — and the gate is what keeps “watching” from meaning “too late”.

06 · What we know, and how

Every claim on this page is stamped.

Measured means something ran and we watched it. Reasoned means we think it follows. Known weak means we would rather you heard it from us.

A one-implementation proposal that claims to be finished is the thing reviewers are right to distrust.

  • Measured

    All three demo paths run end to end against the live deployment, including a real WebAuthn ceremony recorded at assurance="webauthn".

  • Measured

    WebMCP is pull-only: a page cannot tell an agent anything happened. Given only the tool catalogue, agents stay on the line when waiting is right (10/10) and decline to when it would deadlock (0/5). The trial →

  • Known weak

    The no-authenticator fallback is an honest, audited downgrade and not a security boundary. With it on, the gate is satisfiable by a caller willing to forge one header. The safe setting is to refuse.

  • Known weak

    All of this trusts the page to describe honestly what it is asking you to authorise. A patched page can bind one action and display another. That is a boundary, not an absence of one.