What it is
VT is a browser coding workspace for safe human-and-agent collaboration. A visitor can explore a small in-memory project without credentials, open files in CodeMirror, edit a draft, inspect a unified diff, and use the browser's native WebMCP surface to ask an agent to perform the same structured actions. An optional authenticated VT Code bridge connects the editor to a running VT Code session and a real workspace.
Why WebMCP is a strong fit
Browser agents often have to infer editor state from pixels, DOM labels, and keyboard shortcuts. VT exposes the editor's meaningful operations as typed, discoverable tools through document.modelContext.registerTool. An agent can receive a bounded file listing, search result, file digest, or diff, then use that structured result as the next tool input. The person remains in the editor and reviews the exact proposed change before anything can reach the terminal.
This makes a previously awkward workflow—find the right file, make a precise change, inspect the diff, and hand it to a coding session—legible to both the human and the agent without granting the browser direct filesystem write access.
What people and agents do together
A person opens the public editor and can use it normally even when WebMCP is unavailable. An agent lists project files, searches for a symbol or phrase, and opens the relevant file using returned paths. An agent reads the current file and its sha256: digest, then stages one exact replacement only when the draft is clean and the digest still matches. The person reviews the generated diff in the CHANGES panel and decides whether to approve it. In an active VT Code session, the person can attach the reviewed diff to a prompt and let VT Code apply its normal terminal/full-auto policy.
The browser tool surface cannot approve, apply, or revert a filesystem change. Browser draft edits remain in page memory; VT Code and its terminal approval policy remain authoritative for connected changes.
WebMCP implementation
The browser registers eight bounded tools for file listing, search, reading, editor state, file opening, exact draft edits, diff review, and panel navigation. Each tool has a concise description, JSON Schema validation, a display title, abort-aware execution, annotations for read-only and untrusted content, and a 1,500-character result budget. File, diff, and collection responses include truncation metadata. The app listens for WebMCP toolchange events and unregisters tools through an AbortSignal.
The stage_text_edit tool is intentionally narrow: it requires a current digest, rejects stale or dirty drafts, requires exactly one matching text span, and returns the base and draft digests. It never approves a patch, writes a local file, or bypasses the authenticated VT Code bridge.
The Rust vtcode-webmcp bridge adds authenticated loopback WebSocket pairing, exact origin checks, bounded workspace operations, digest validation, event replay, reconnect support, and fail-closed handling for unsafe paths and stale changes. It is shipped as a first-class VT Code integration, and the maintained Vite WebMCP app lives in apps/webmcp/.
Why the workflow is safe
The browser never writes directly to the filesystem. Workspace access is rooted, bounded, digest-checked, and protected against traversal, symlink/hard-link escapes, sensitive paths, and unsafe check execution. Real mutations remain subject to terminal approval or the existing explicit full-auto policy. The public page includes a deterministic in-memory fallback so judges can evaluate the product without credentials or a local backend.
Built With
- bun
- codemirror
- rust
- typescript
- vite
- vt-code
- webmcp
Log in or sign up for Devpost to join the conversation.