WebMCP & browser agents
Authenticate agents that operate your page — WebMCP clients and browser agents — with the browser SDK.
WebMCP & browser agents
Some agents don't just fetch your pages — they operate them: WebMCP clients calling
navigator.modelContext, and browser agents clicking and typing through your UI. The browser
SDK detects them in the page and upgrades them to a verified identity when they present a
credential.
Install
Passing a secret key (agtx_sk_…) throws at init(), so a leak fails loudly. React? Use
<AgentronicsProvider> from @agentronics/react — see Next.js.
From detected to verified
| Step | Call | Trust |
|---|---|---|
| Agent is present | automatic on init() (autoDetect) | detected |
| Agent says who it is | client.presentIdentity({ class, vendor, token }) | declared |
| Credential verified | client.authenticate({ … }) + a verifyToken hook | verified |
| Linked to a user | client.authenticate({ sessionLinkToken, linkedUserId }) | linked |
client.detect() always returns the highest-trust identity available.
Verifying credentials
A browser can't safely verify a credential by itself, so authenticate() hands tokens to a
verifyToken hook that calls your server (which can use the Agentronics gateway or your own
logic):
Supported inputs: bearerToken, extensionToken, oauth2AccessToken, ssoIdToken,
spiffeJwt, xfccHeader, sessionLinkToken (+ linkedUserId), xAgentHeader and a
declaration. SSO, SPIFFE and mTLS are verified by the gateway — see SSO,
SPIFFE and mTLS.
Handing back to a human
When an agent returns control to a person, call client.clearIdentity().
What detection can and can't see
- WebMCP — exact when an agent uses
navigator.modelContext. - DOM drivers (Playwright-style automation) — heuristic, with a confidence score.
- Screenshot agents (pixel-level control) — not reliably detectable; they should authenticate if they need more than anonymous access.
Pair the browser SDK with the server middleware: the server sees every request, the browser sees what happens on the page.