AigentablyAigentably
What is WebMCP?PricingBlogChangelogDocsLog inGet Started

Getting Started

  • Introduction
  • Quick Start
  • Create Your First Tool

How-to Guides

  • Generate Tools with AI
  • Build from Templates
  • Write Tools by Hand
  • Test a Tool on Your Site
  • When Tools Don't Register
  • Understand Path Patterns
  • Read Your Analytics
  • Lighthouse Agentic Browsing Score

WebMCP Technology

  • What is WebMCP?
  • Browser Compatibility
  • Connect an LLM Client

Developer Reference

  • executeJs Reference
  • Input Schema Format
  • Path Pattern Syntax
  • Config API

Config API

The public endpoint that serves tool definitions to the snippet.

Endpoint

GET /api/sites/:publicId/config

:publicId is the public identifier from your site's snippet block. It's safe to expose in HTML and doesn't grant write access.

Query parameters

ParameterTypeDescription
pathstringCurrent page path, e.g. /products/shoes. Used for path pattern filtering.

Response

{
  "siteId": "uuid",
  "tools": [
    {
      "id": "uuid",
      "name": "addToCart",
      "description": "Add a product to the shopping cart",
      "inputSchema": { "type": "object", "properties": {} },
      "executeJs": "return window.__aigentablyDemo.addToCartUI(args.productId, args.quantity)",
      "exposedTo": [],
      "title": "Add to cart",
      "annotations": {}
    }
  ],
  "formTools": [
    {
      "id": "uuid",
      "name": "subscribeNewsletter",
      "description": "Subscribe an email address to this website's newsletter.",
      "selector": "form#newsletter",
      "autosubmit": false
    }
  ],
  "pollInterval": 300
}
  • tools: only enabled tools matching the ?path= pattern are returned
  • exposedTo: origins in the page's frame tree this tool is visible to, passed straight through to registerTool()'s options. It scopes which documents can see the tool, not which agent is allowed to call it; an empty array means every document in the frame tree.
  • title: a human-readable name derived from name, passed to registerTool() as the tool's title
  • annotations: the WebMCP ToolAnnotations for the tool, with only the hints that are true: readOnlyHint (changes nothing), consequentialHint (has an effect that can't be undone, so agents should confirm with the user first) and untrustedContentHint (output includes content written by others, such as reviews). A hint set in the tool editor is served as set; one left on Auto is inferred from the tool's name, so searchProducts is read-only, placeOrder is consequential, and addToCart gets neither.
  • formTools: enabled form tools whose page path matches ?path=. For each one, the snippet finds the form with selector and sets toolname, tooldescription and, when autosubmit is true, toolautosubmit on it, which makes the browser register the form as a WebMCP tool with an input schema taken from the form's own fields. A form that already has a toolname of its own is left alone. Without autosubmit, the agent fills the form in and the visitor presses submit.
  • pollInterval: seconds between re-fetches (default: 300)

Caching

The endpoint uses ETag-based caching. The snippet sends If-None-Match on subsequent requests. If nothing has changed, the server returns 304 Not Modified and the snippet skips re-registration.

Cache-Control is set to public, max-age=60. Tool changes appear within 60 seconds.

Rate limiting

Requests are rate-limited per site. The snippet's polling interval keeps well within the limit under normal usage. Exceeded: 429 Too Many Requests.

CORS

The endpoint is open to all origins (Access-Control-Allow-Origin: *). This is intentional, as the snippet runs on third-party sites.

Error responses

StatusCodeMeaning
404NOT_FOUNDInvalid or deleted publicId
429RATE_LIMITEDToo many requests
500INTERNAL_ERRORServer error