Discoverable is not authorized
WebMCP gives agents a structured way to discover and call tools exposed by a website. BOSAI explores the next problem: tool discovery should not automatically grant execution authority.
BOSAI — Governed WebMCP is a public WebMCP demo that lets an agent inspect a synthetic duplicate-charge case, propose a refund, request authorization, execute only after an explicit Human GO, independently verify the result, retrieve an evidence receipt, and deny replay of the same single-use permit.
The core idea is simple:
Agents can discover and propose. Humans retain authority. BOSAI verifies what actually happened.
Why this is a strong fit for WebMCP
Without structured tools, agents often have to infer actions from UI state. WebMCP makes the capability surface explicit. BOSAI uses that explicit surface to add a second layer: an authority boundary around consequential actions.
The live app registers eight native WebMCP tools:
inspect_case inspect_transaction propose_refund request_authorization authorization_status execute_refund verify_refund get_evidence_receipt
The agent has no Human GO tool. It can reach HUMAN_GO_REQUIRED, but it cannot grant itself approval.
The demo flow
The challenge uses a fully synthetic EUR 49 duplicate-charge refund scenario.
The agent inspects the case and transaction. It creates a bounded proposal. BOSAI stops at HUMAN_GO_REQUIRED. Before approval, the mutation count is 0. A human explicitly approves that exact proposal. BOSAI issues a single-use permit. The synthetic refund commits exactly once. Independent readback returns VERIFIED and an evidence receipt. The same execution is attempted again. The replay is denied, and the replay mutation count remains 0.
No real payment is made and no customer data is used.
Better human + agent interaction
The user experience is not "AI asks for permission" as a loose convention. The approval state is explicit, inspectable, and bound to one exact proposal.
Agent: inspect, reason, propose, request authorization, execute within the granted permit, verify. Human: retain the authority to approve or deny the exact consequential action. BOSAI: enforce the execution boundary, record the result, and deny permit replay.
This makes WebMCP more useful for workflows where agents should be capable without becoming self-authorizing.
Implementation
The challenge surface is a standalone browser app implemented with HTML, CSS, and JavaScript. It registers tools through WebMCP and maintains deterministic synthetic challenge state for proposals, authorization, execution, verification, evidence receipts, and replay denial.
The public challenge surface is served as static assets on OVHcloud through a scoped Caddy route. The live browser proof was run in Google Chrome 152 with WebMCP testing enabled.
What was added during the challenge
BOSAI existed before the WebMCP Challenge. During the challenge submission period, it was meaningfully extended with a dedicated WebMCP implementation and public challenge surface, including the eight WebMCP tools above, a synthetic duplicate-charge workflow, explicit HUMAN_GO_REQUIRED behavior, zero-mutation pre-approval enforcement, exact Human GO binding, a single-use execution permit, independent verified readback, an evidence receipt, replay denial with zero replay mutations, and a public live browser proof surface.
The WebMCP challenge implementation is isolated from proprietary BOSAI internals and is being published as a standalone public-safe repository for judging.
Live proof
The validated live flow demonstrated 8 registered WebMCP tools, HUMAN_GO_REQUIRED before authorization, 0 pre-GO mutations, 1 authorized synthetic mutation after Human GO, VERIFIED independent readback, an evidence receipt, REPLAY_DENIED on the duplicate execution attempt, 0 replay mutations, and no blocking browser/runtime errors.
Live app: https://bosai.syncguard.fr/webmcp-challenge/index.html
Operating principle
Intelligence is not authority.
WebMCP makes agent capabilities discoverable. BOSAI demonstrates how those capabilities can remain human-governed, bounded, verifiable, and auditable.
Built With
- caddy
- chrome
- css
- html
- javascript
- ovhcloud
- webmcp
Log in or sign up for Devpost to join the conversation.