Could we add a standard way for a page to send messages to the visiting agent, without waiting for another tool call?
Example
A concrete example is PostHog's ask_max tool. Currently, sending a question opens the assistant UI on the page, but the assistant's answer isn't sent back to the visiting agent through the tool. The conversation continues in the page UI.
This could be a smoother experience if the visiting agent could talk directly to the site's assistant through WebMCP, receive answers and follow-up questions, and continue the conversation without having to operate the assistant's UI.
@Kulikowski explored a similar interaction in The three homes of the Agentic Web and When agents talk, with a working demo comparing WebMCP tool calls with A2A. We also discussed the missing feedback channel in Bring your own agent, coauthored with @Kulikowski and @andreban.
Strawman
- The visiting agent opts into messages for a specific task.
- The browser gives the page a channel scoped to that task.
- The page can send structured messages through the channel:
{
"taskId": "analysis-123",
"type": "question",
"message": "Should I look at the last 7 or 30 days?"
}
The visiting agent decides whether to respond through the tool, ask the user or ignore the message. Either side can close the channel. Many websites have an in-page assistant whose logic runs on the backend. In this setup, the page relays messages between the visiting agent and the site's assistant.
Displaying messages
If the visiting agent displays a message directly, without processing it through its own LLM, the UI should clearly identify it as an unchanged message from the site's assistant. The user should be able to distinguish a relayed message from the visiting agent's own response.
Security
- Treat messages as untrusted site content, with the same trust level as tool results.
- Receiving a message should not grant new permissions or automatically trigger an action.
- Replies should not expose unrelated private context.
- The browser should enforce origin and task boundaries, rate and size limits, and close the channel when the task ends or the user leaves the page.
Relationship to A2A
A2A's task and messaging concepts could inform this without requiring sites to implement the full protocol.
Is this something the existing proposals could cover? @Kulikowski @andreban, curious how you see this fitting with those experiments.
Prior discussions
Could we add a standard way for a page to send messages to the visiting agent, without waiting for another tool call?
Example
A concrete example is PostHog's
ask_maxtool. Currently, sending a question opens the assistant UI on the page, but the assistant's answer isn't sent back to the visiting agent through the tool. The conversation continues in the page UI.This could be a smoother experience if the visiting agent could talk directly to the site's assistant through WebMCP, receive answers and follow-up questions, and continue the conversation without having to operate the assistant's UI.
@Kulikowski explored a similar interaction in The three homes of the Agentic Web and When agents talk, with a working demo comparing WebMCP tool calls with A2A. We also discussed the missing feedback channel in Bring your own agent, coauthored with @Kulikowski and @andreban.
Strawman
{ "taskId": "analysis-123", "type": "question", "message": "Should I look at the last 7 or 30 days?" }The visiting agent decides whether to respond through the tool, ask the user or ignore the message. Either side can close the channel. Many websites have an in-page assistant whose logic runs on the backend. In this setup, the page relays messages between the visiting agent and the site's assistant.
Displaying messages
If the visiting agent displays a message directly, without processing it through its own LLM, the UI should clearly identify it as an unchanged message from the site's assistant. The user should be able to distinguish a relayed message from the visiting agent's own response.
Security
Relationship to A2A
A2A's task and messaging concepts could inform this without requiring sites to implement the full protocol.
Is this something the existing proposals could cover? @Kulikowski @andreban, curious how you see this fitting with those experiments.
Prior discussions