Local tool-registration linter

Local JSON analysis · Free browser tool

WebMCP Preflight

Paste or import a registration document and get a local, deterministic preflight. It helps authors make tool contracts legible without treating an MCP server card or a JSON document as proof of a live browser registration.

1 · Define and run

GoalContract input

Start with the included example, then replace it with one narrow customer goal and its real authority boundary.

WebMCP registration JSON

Parsed locally in this browser · maximum file size 250 KB

Example JSON loaded

Authority, assertions, and safe stop

Selecting a sandbox records a declaration in the contract; a later executor must still verify written authorization, isolation, fixture reset, and revocation. This public tool does not execute the sandbox run.

By running this tool, you confirm the submitted inputs are within your authorized scope.

2 · Inspect and export

Evidence bundle

Your structured result will appear here

Review the example GoalContract, adjust its boundaries, and run the tool. No action is taken beyond the boundary shown on this page.

Why this test exists

A practical WebMCP tool registration validator

A machine-readable tool registration can be syntactically valid while remaining unsafe or unusable. Agents need clear names, input schemas, authorization requirements, non-destructive examples, and results that agree with the human interface and underlying product behavior.

WebMCP Preflight parses a registration document locally and maps its observable properties into the same contract-and-receipt model used by the other AgentReady tools. That makes schema gaps, ambiguous authority, and missing evidence explicit before a functional call is attempted.

Repeatable workflow

From a bounded goal to an inspectable receipt

  1. 1

    Collect the public registration

    Paste or choose the JSON document you intend an agent or browser surface to consume.

  2. 2

    Bind it to a goal

    State the user outcome, expected origins, permitted operations, prohibited writes, and safe stop.

  3. 3

    Run the local preflight

    Inspect registrations, schemas, descriptions, declared authorization clarity, and declared human-interface parity.

  4. 4

    Test harmless calls later

    Use the exported gaps to design an authorized read-only or sandbox functional test with authoritative readback.

Read the evidence precisely

Four interpretation rules

Registration is discovery

Publishing a tool definition does not prove the backing operation exists, is authorized, or returns the declared result.

Schemas are contracts

Required fields, types, enums, defaults, and error behavior should be narrow enough to prevent accidental misuse.

Authority must be legible

The agent and user need to know which identity grants access and which operations require confirmation.

Human parity builds trust

Material actions should have understandable equivalents, policies, or explanations in the human-facing product.

Included in this tool

Observable checks and exports

  • Local JSON parsing with no registration payload upload
  • Checks for stable names, useful descriptions, object input schemas, and constraints
  • Consequence and authorization clarity for write-capable operations
  • Explicit declarations for harmless test calls and visible-form parity

Keep outside the claim

Known limitations

  • The linter evaluates only the supplied document, not the live page runtime.
  • Declared form parity and harmless behavior are claims until independently observed.
  • No tool is invoked and no user authority is inferred from public metadata.

Frequently asked questions

Is WebMCP the same as an MCP server?

No. Both expose structured tools, but a browser registration and a remotely hosted MCP server have different discovery, runtime, and authorization surfaces.

What is human-form parity?

It means the structured tool and the visible human workflow express the same required inputs, options, constraints, consequences, and resulting state.

Does a passing lint mean the tool is safe to call?

No. Static clarity is only a prerequisite. Live behavior, authorization, side effects, error handling, and authoritative state changes still need controlled testing.

Continue the investigation

Related tools and field research

Explore the agent-actionable web library

Public scan projection

Agent Access Matrix

Compare robots policy, simulated agent user-agent responses, server-rendered content, browser stability, CAPTCHA, and security evidence in one public-site preflight.

Open tool

Local JSON analysis

Lighthouse Agentic Importer

Import a Lighthouse JSON report locally, preserve official audit IDs and display values, and turn observed failures into an agent-journey rerun checklist.

Open tool

Planning artifact

Journey Contract Builder

Define the goal, starting state, allowed and prohibited actions, safe stop, assertions, and authoritative readback before an agent touches a site.

Open tool

Measured comparisons

Use receipts—not anecdotes—in a leaderboard

AgentReady's public leaderboard model requires owner opt-in, category fit, compatible scanner versions, observation windows, denominators, and evidence coverage. A tool export is an input to that process, not automatic publication.

View leaderboards

Need the whole public-site baseline?

Run the free AgentReady scan for discovery, semantics, browser compatibility, public forms, safety signals, and evidence-backed fixes.

Scan a public URL