/wp-json/beeclear-webmcp/v1/manifest./agent-manifest.txt, /agents-manifest.txt, /agents.txt and /.well-known/api-catalog endpoints, detects whether /llms.txt and /llms-full.txt are already available, and can optionally provide WebMCP fallback output for each llms file independently.Accept: text/markdown./wp-json/beeclear-webmcp/v1/openapi.debugging tool annotation so end-user agents filter them out.Origin-Trial header and HTML meta tag for Chrome 149+ production testing.document.modelContext, keeps a compatibility fallback for older navigator.modelContext builds, runs registered tools through executeTool() with the Chrome 155 object input arguments (and a stringified fallback for older Chrome), and can expose tools to configured secure cross-origin iframe hosts.allow="tools"./llms.txt and /llms-full.txt files from another plugin or static file./llms.txt or /llms-full.txt fallback output.agent-manifest.txt, agents-manifest.txt and agents.txt policy files.x- capability tokens.beeclear-webmcp-ai-visibility folder to your /wp-content/plugins/ directory, or upload the ZIP from Plugins > Add New > Upload Plugin./wp-json/beeclear-webmcp/v1/manifest.No. The plugin adds REST endpoints, discovery files, optional Markdown responses and discovery links. It does not replace your theme or normal frontend templates.
They can be public if enabled in the plugin settings. State-changing tools still require the normal logged-in WordPress REST nonce/current-user context.
For local development, Chrome can use the chrome://flags/#enable-webmcp-testing flag. For production testing in Chrome 149 and newer while WebMCP is in Origin Trial, register your site origin in Chrome Origin Trials and paste the WebMCP token into the plugin settings. The plugin will publish it as an Origin-Trial HTTP header and an HTML meta tag on uncached pages. If a page cache, CDN or server cache serves HTML before WordPress runs, add the same header at the cache/server layer.
Yes, but only when the embedding page delegates permission with allow="tools" on the iframe and the embedded site lists that secure HTTPS origin in the plugin's Cross-origin WebMCP setting. Leave the setting empty for same-origin tools only.
Yes. You can enable or disable content, navigation, media, Contact Form 7, custom form and custom function tools from the admin screen.
No. The content tools are intended for public content. Review the exposed post-type settings before enabling public read access. Password-protected posts and pages are not exposed through public content tools or Markdown output.
No. Markdown is served only for compatible requests that explicitly ask for it, or through the dedicated REST Markdown endpoint.
Yes. WebMCP detects existing /llms.txt and /llms-full.txt files and links to them from discovery metadata. Keep Let WebMCP generate /llms.txt disabled when another plugin or static file should own /llms.txt. /llms-full.txt has a separate fallback toggle.
It means the public URL exists, but the response does not look like WebMCP-generated output. This is expected when another plugin or a static file serves the llms document.
No. Contact Form 7 integration is optional. If Contact Form 7 is not active, the rest of the plugin can still expose content, discovery files, OpenAPI metadata, custom forms and custom functions.
Custom functions are limited to same-site endpoints or relative paths. The target endpoint should handle validation, permissions and business logic.
A page cache such as WP Rocket can serve cached HTML before WordPress runs, so headers added by the plugin through WordPress hooks are not emitted. On NGINX, add the WebMCP discovery headers at the server/cache layer.
For multilingual installs where WordPress lives under /pl and /en, define $bcwm_wp_prefix with a map in the http {} context; otherwise set it to an empty string inside server {}. Then add the directives in the server {} block or in each location that serves cached HTML. Note that if a lower-level location already has any add_header directive, NGINX does not inherit add_header from the parent context, so repeat the directives in that same location.
set $bcwm_manifest "$scheme://$host$bcwm_wp_prefix/wp-json/beeclear-webmcp/v1/manifest";
set $bcwm_openapi "$scheme://$host$bcwm_wp_prefix/wp-json/beeclear-webmcp/v1/openapi";
set $bcwm_catalog "$scheme://$host$bcwm_wp_prefix/.well-known/api-catalog";
set $bcwm_llms "$scheme://$host$bcwm_wp_prefix/llms.txt";
set $bcwm_agents "$scheme://$host$bcwm_wp_prefix/agents.txt";
add_header Permissions-Policy "tools=(self)" always;
For Chrome Origin Trial production testing, add the token registered for this exact origin:
add_header Origin-Trial "PASTE_WEBMCP_ORIGIN_TRIAL_TOKEN_HERE" always;
add_header Vary "Accept" always;
add_header Content-Signal "ai-train=no, search=yes, ai-input=yes" always;
add_header Link "<$bcwm_manifest>; rel=\"webmcp-manifest\", <$bcwm_manifest>; rel=\"service-doc\", <$bcwm_openapi>; rel=\"service-desc\"; type=\"application/vnd.oai.openapi+json\", <$bcwm_catalog>; rel=\"api-catalog\", <$bcwm_llms>; rel=\"describedby\", <$bcwm_agents>; rel=\"agent-policy\"" always;
After editing, run nginx -t and reload NGINX, then purge WP Rocket and any CDN/edge cache. Verify with curl -sI https://example.com/ | grep -Ei 'permissions-policy|link:|content-signal|vary'.
Use the Tests screen under BeeClear WebMCP in wp-admin. It includes quick checks for the manifest, discovery files and common read tools.
toolactivated and toolcancel events, which moved from window to document.modelContext (webmcp PR #245). With console logging enabled, the start and cancellation of a declarative form tool are logged with the tool name; the listener is attached to document.modelContext when it exposes the ontoolactivated/ontoolcancel handlers and to window on older builds.checkbox_device-Internet-connection), so the field purpose no longer matched the field and was lost on the next save. Field names now keep their case and the characters CF7 allows; descriptions stored under the old lowercased key are still read. submit_cf7_form also passes field names with their original case.\" or \\d was unslashed twice and saved as {}. It is now unslashed once and saved as entered.debugging: true tool annotation (Chrome 156+, webmcp PR #253) and published with it in the manifest, so general-purpose and end-user agents can filter out tools meant for testing frameworks and developer tooling such as Chrome DevTools AI assistance.debugging: false for every built-in tool. None of the built-in tools are developer tools, so the browser leaves them unflagged and end-user agents keep seeing them.window.BeeClearWebMCPTools.executeNativeTool( name, input ) runs a browser-registered tool through the native WebMCP API and resolves to its result. It is the execution companion to getNativeTools() and accepts either a tool name or a tool object.executeTool() takes an optional JavaScript object instead of a stringified JSON DOMString. The input object is passed directly; on pre-155 Chrome Stable — which still expects stringified arguments and rejects with "Failed to parse input" — the call is retried with JSON.stringify(), so it keeps working across Chrome builds.scripts/update-translations.sh build helper from the distributed plugin (it tripped Plugin Check's application_detected). The release-time translation steps are now documented directly in the Translations section using standard WP-CLI commands.execute() promise instead of resolving with the error text as a string, so agents can tell a failed tool call apart from a successful one.toolparamtitle attribute from declarative form annotation. The WebMCP declarative API only defines toolname, tooldescription, toolparamdescription and toolautosubmit; browsers ignored toolparamtitle and the code path never actually set it.RegisteredTool.inputSchema (webmcp PR #241) is now a JavaScript object instead of a stringified JSON schema. The frontend normalizes both shapes, so it keeps working on pre-154 Chrome (string) and Chrome 154+ (object).window.BeeClearWebMCPTools.getNativeTools() returns the tools the browser actually registered with inputSchema normalized to an object across Chrome builds.execute(input, { signal }). The cancellation signal is forwarded to every REST request the tools make, so cancelling a tool call from the browser or the agent aborts the request instead of leaving it running.window.BeeClearWebMCPTools.unregister() cancels executions that are still running. Chrome 153 no longer does this automatically when a tool is unregistered.execute() is contracted to return.window.BeeClearWebMCPTools.call( name, args, { signal } ) accepts an optional signal for manual tool invocations.update_option() from a front-end read path.window.BeeClearWebMCPTools.initMs reports the synchronous initialization cost without turning on console logging.get_menu tool now understands menus built outside the WordPress menu system. A menu-builder plugin registers its navigation on the new beeclear_webmcp_external_menus filter (slug, name, nested title/url items); the tool resolves them by menu name or slug, prefers them over the flat page-list fallback when no WordPress menu exists, and every response lists all discoverable menus in available_menus. Location-assigned WordPress menus keep taking precedence and unassigned menus stay hidden.navigator.modelContext was deprecated in Chrome 150 and removed in Chrome 152, so it now only serves as a fallback for pre-150 builds. The document.modelContext || navigator.modelContext feature detection already handled all these cases; no functional change.document.modelContext.registerTool() returns a Promise that resolves when the tool is available across the frame tree.document.modelContext API, JSON-string tool execution arguments and optional exposedTo cross-origin iframe support./agent-manifest.txt, /agents-manifest.txt and /agents.txt./llms.txt and /llms-full.txt files served by another plugin or static file./llms.txt and /llms-full.txt toggles.assets/admin.css and aligned the UI with the BeeClear Marketing Source Tracking admin style./agent-manifest.txt, /agents-manifest.txt, /agents.txt and /.well-known/api-catalog discovery documents, plus optional /llms.txt and /llms-full.txt compatibility output.