> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcp-b.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and human-in-the-loop

> Why WebMCP security starts with browser mediation but still depends on application authorization.

WebMCP tools can reuse a site's authenticated browser session. The session
identifies the user; it does not make the agent trusted. Tool calls still pass
through the application's validation and authorization rules.

Tool metadata, page content, and tool output can contain prompt injection.
Annotations provide information to browsers and agents, but they do not enforce
authorization or guarantee a confirmation prompt. Human review should follow
consequence: financial, destructive, external-communication, and
privacy-sensitive actions need stronger confirmation than read-only lookup.

<Columns cols={2}>
  <Card title="Context and signals" icon="circle-info">
    Browser mediation, session identity, schemas, and annotations provide context. They do not
    authorize a call or guarantee confirmation.
  </Card>

  <Card title="Enforced controls" icon="shield-halved">
    The application validates input, authorizes the current user, and requires human review when the
    consequence warrants it.
  </Card>
</Columns>

The Community Group draft's [security and privacy
considerations](https://webmachinelearning.github.io/webmcp/#security-and-privacy-considerations)
cover the proposal's threat model. Chrome publishes separate guidance for
[sites that expose tools](https://developer.chrome.com/docs/ai/webmcp/secure-tools)
and [agents that consume them](https://developer.chrome.com/docs/agents/security).
Those sources own browser and agent mitigation details.

## MCP-B bridges add another boundary

Iframe, tab, extension, and localhost bridges carry tools beyond their original
page surface. Each bridge must validate its own origin, connection identity,
permissions, and exposure controls. Browser mediation does not configure an
MCP-B transport, and transport access does not grant application permission.

[Transports and bridges](/explanation/architecture/transports-and-bridges)
describes these trust boundaries. The relevant package references define their
specific controls.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.