Swagger UI WebMCP
OpenAI WebMCP Challenge entry: a Swagger UI plugin that turns any OpenAPI docs page into agent tools, with access the page and the person can only tighten.

If you can Try it out, your agent can too.
This is one of four entries Allison submitted to OpenAI's WebMCP Challenge on the morning of 3 September 2026. JupyterLite WebMCP was the one that won. The other two were Careers WebMCP and Strudel WebMCP, and a fifth build, Storybook WebMCP, never got submitted. All five went from first commit to the last Devpost submission in under 48 hours, each starting as a long written build contract handed to Claude Code or Codex agents.
Swagger UI WebMCP is a plugin. Add plugins: [SwaggerUIWebMCP] to an existing Swagger UI config and every OpenAPI docs page becomes a set of WebMCP tools a browser agent can call. It gets five core tools for finding, reading and running operations, plus one tool per exposed operation. The agent uses the environment, login and request pipeline the developer already has open in that tab.

Four parties, and the agent isn't one of them
The interesting part is who decides what the agent may do. Four parties each get one instrument:
- The API publisher annotates the OpenAPI document with
x-webmcp. - The page owner sets exposure in the plugin config.
- The person at the page gets an "Agent access" dropdown next to every Try-it-out, which locks that operation for the session.
- The client gets standard MCP annotations and structured errors.
Every source reduces to a level on hidden < read < write, and the tightest one wins. Hidden always wins, so hiding something can never escalate anything. By default it's tighten-only; a page has to opt in before document annotations can relax its exposure. No tool schema has a field for the lock, so the agent gets no vote.

Tools can't name a URL
The agent never builds a request. Execution writes arguments into Swagger UI's own store and runs its normal execute action, so every call goes through the server you selected, the page's interceptors and your credentials, and the response shows up in the usual response panel. Every path, whether a direct tool, the generic executor or a batch, goes through one authorisation gate checked at call time. Tool names carry a hash of the document, so they change when the spec does, and parameters with credential-shaped names are dropped before they reach a schema.
A few things landed after the submission, during the deadline extension: a cost hint for metered operations, re-checking authorisation on every step of a batch, and closing gaps in the credential-name filter.
Try it
The live demo opens on a fictional "Waypoint" task-tracker API. One click on the Open-Meteo chip loads a real public weather API instead, and Petstore is there too.

The live demo with Open-Meteo selected, captured September 2026.
Without a WebMCP-capable browser it still works as normal Swagger UI. The agent side needs ChatGPT's in-app browser or Chrome with experimental web platform features turned on. The plugin isn't published to npm yet, so for now it's the repo and the demo.
There's a demo video and the Devpost entry. Apache-2.0.