Skip to main content
Connect AgentWeb to the AI agent you already use, find a mapped action, and call execute. Executing mapped actions through execute (MCP) or POST /api/execute (REST) is the core capability. Four steps.
Every live tool, including read_page and discover, requires an AgentWeb aw_ API key. Only the signup tools and agentweb_auth_status work anonymously.

1. Add the MCP server

AgentWeb exposes a Streamable HTTP MCP server at https://mcp.agentweb.us/mcp.
Codex CLI (~/.codex/config.toml):
Cursor and Windsurf: add https://mcp.agentweb.us/mcp as a remote MCP server by URL (Streamable HTTP; no catalog entry needed). Any other MCP client takes the same URL. Per-client steps: install.md.

2. Sign in

Show the human the Terms and Privacy Policy, then call agentweb_start_claim_link_signup. A real response (trimmed):
Show only verification_uri_complete to the human, then poll agentweb_poll_claim_link_signup with the device_code every interval seconds (pending polls return authorization_pending; the link expires after expires_in seconds). The completed poll returns the API key once. Reconnect with:
Fallbacks (email-code, raw HTTP, A2A) are on Auth & connections.

3. Find your action

Call list_actions with no arguments for the catalogue of mapped sites (over 1,100 and growing):
Call it again with an exact domain for that site’s full action definitions, including every parameter, defaults, and whether the action needs a connected account:
If an action lists an auth_provider, connect the target-site account first: check agentweb_connection_status, and if it is not connected call agentweb_start_connection, show the human the returned URL, then poll agentweb_poll_connection. Details on Auth & connections. If a site is not mapped yet, call request_map to queue a build and poll agentweb_map_status.

4. Execute and verify

Call execute (or POST /api/execute over REST) with the domain, action, and declared params. Over REST, an optional Idempotency-Key header (or idempotency_key field) maps retries to the same billing task so a retried call is never charged twice:
A real response:
Treat the returned fields as the source of truth, never an accepted request:
  • success answers “did the mapped call work”. For actions where step success can diverge from job completion (checkouts, payments), an outcome object states the job-level truth: status of complete (with proof such as an order ref), partial (with the exact missing_step and safe_to_retry), or unavailable.
  • On failure, success is false with a typed error.code (AUTH_REQUIRED, INSUFFICIENT_CREDITS, UPSTREAM_APP_ERROR, …), a trace_id you can quote in a bug report, and the credit reservation is refunded.
  • billing.receipt_id is the support receipt for the action.

Safety rules

  • Never place passwords, raw card numbers, unrestricted credentials, or unrelated private conversation content in a tool request.
  • Stop when the action is unsupported, unsafe, expired, over a limit, or missing approval.
  • Before any paid, irreversible, or externally visible action, summarize the exact inputs and obtain approval.
  • Use a first-party API when it already provides the full required workflow and access model.

Going further