Warning
Experimental. This extension is experimental and not yet ready for production use. It is built on top of WebMCP, which is itself an experimental, early-stage proposal. Both the underlying specification and this extension's API may change or break at any time without notice. Use at your own risk.
Changelog
This extension is experimental. Until a 1. release, the API described in
this documentation may change or break between versions without notice.
Note
The canonical, commit-level history lives in the Git repository. This page records notable, user-facing changes per release.
Unreleased
- (nothing yet)
0.4.0 - 2026-10-08
Aligns the runtime with the WebMCP Community Group draft of 2026-10-02. See Upgrading for what to check.
Changed
- Behavior change: the runtime no longer uses
provide, which the specification removed. Every tool is registered individually viaContext () registerwith its ownTool () Abort; tools therefore appear one after another instead of atomically. A tool whose registration fails (e.g. duplicate name) is skipped with a singleSignal console.; the others are unaffected. Tools are unregistered onwarn pagehideand registered again when the page returns from the back/forward cache. - Behavior change: tools are only registered in the top-level document, never inside iframes.
- Behavior change: the text output of a tool call is capped at 1,500
characters by default (see
output).Limit - The deprecated
navigator.fallback is isolated and can be switched off.model Context
Added
consequentialargument onManifest, emitted asannotations.(derived from the primitive: onlyconsequential Hint mailtois flagged).debuggingargument onManifest, emitted asannotations.only whendebugging true.- Data processor options
legacy(defaultNavigator Fallback 1) andoutput(defaultLimit 1500,0= unlimited). Manifest: the data processor logs warnings for tool or parameter names over 30 characters, descriptions over 500, parameter descriptions over 150 (Chrome recommendations) and names outside the specification's pattern. Tools are still emitted.Validator - Runtime tests (Node.js built-in test runner) and documentation chapters Standards and browser support, Security considerations and Upgrading.
Removed
- Use of
providein the runtime.Context ()
Migration
No action is required for tools built on the four primitives. Escape-hatch
modules that called provide themselves must switch to
register. Check tools that rely on long text output against the new
output. Details: Upgrading.
0.3.0 - 2026-07-20
- Added: each manifest now also carries the WebMCP
annotations.flag, warning the agent that a tool's output may contain untrusted third-party data. It is derived from the primitive (onlyuntrusted Content Hint searchis flagged) and overridable via the newuntrustedargument onContent Manifest. - Added:
Manifestgained an optionaltitleargument — a human-readable label for UI display, distinct from the machine-stablename. It is emitted into the manifest and forwarded to the tool descriptor only when set. - Changed: the runtime now registers its tools atomically via
provide(the WebMCP spec's primary entry point), falling back to per-toolContext ( { tools }) registeronly whereTool provideis absent. Manifest entries that reuse a name already taken are dropped, so a duplicate tool name no longer aborts registration.Context - Added: the
navigateandmailtoprimitives accept an optionalconfirmmessage that triggers a human-in-the-loop confirmation before the side effect runs, via the WebMCP client'srequest(with aUser Interaction () confirmfallback). Escape-hatch modules now receive the client as() ctx.. Without aclient confirmmessage the behaviour is unchanged. - Changed: the built-in primitives now flag genuine failure paths
(
navigatewith an unknown option,mailtowith no configured contact) with the WebMCPisresult flag, so agents can tell a failed call from a successful one. An empty but valid search result stays a success.Error - Added: each tool manifest now carries a WebMCP
annotations.flag, derived from the primitive (read Only Hint searchandstaticare read-only;navigateandmailtoare not) and overridable via the newreadargument onOnly Manifest. The generic runtime forwards it toregisterso agents can tell read-only tools from state-changing ones.Tool
0.2.0 - 2026-07-19
- Breaking: the backend module moved from the Web group to
System, and its route identifier changed from
web_towebmcp system_. The module no longer carries a page tree — its statistics are site-wide. Update any backend user/group access rights and hardcoded module links accordingly.webmcp - Changed: the backend module icon was redrawn in the three-colour TYPO3 v14 icon style.
- Added: an
ext_so the extension can be published to and installed from the TER.emconf. php - Documentation: added a Quickstart, an Architecture overview, a dedicated Analytics chapter (data model, retention, endpoint hardening), a Troubleshooting guide and this changelog.
0.1.0
Initial experimental release.
- Declarative tool framework: define agent tools as server-side PHP providers
(
Tool) collected into a per-page manifest.Provider Interface - Four behaviour primitives interpreted by a single generic runtime
(
webmcp.):js navigate,search,mailto,static. - Escape hatch: a tool may point at its own ES module for behaviour no primitive covers.
- Optional, privacy-preserving first-party analytics: anonymous per-call
logging via
/webmcp-, rate limiting, and a System > WebMCP backend module.event - Requires TYPO3 v14.3+ and PHP 8.2+.