Swagger UI WebMCP

Any OpenAPI page becomes an agent interface. If you can Try it out, your agent can too.

Loading
Demo session: signed out
Document
How this works · install · demo tokens

Three lines in your existing Swagger UI

import SwaggerUIWebMCP from "swagger-ui-webmcp";

SwaggerUI({
  dom_id: "#swagger-ui",
  url: "/openapi.yaml",
  plugins: [SwaggerUIWebMCP],          // ← the whole integration
  webMcp: { exposure: "write" }
});

No AI SDK. No MCP server to install. No bearer token leaves the page. The agent inherits whichever server you pick in the dropdown below and whatever session you are already signed into.

What this page proves

Pick Open-Meteo above. It is a real public weather API with no key, no annotations, and no idea this plugin exists. The agent still gets tools for it and makes real calls to api.open-meteo.com straight from your browser — no curl, no MCP server, nothing installed. Any OpenAPI URL you paste behaves the same way.

Public and private, in one document

On the Demo API, most operations are open — read and write them right now, signed out. Three declare x-webmcp.requiresAuth, so Swagger draws its padlock on exactly those, and an agent calling one early gets a structured AUTH_REQUIRED. Authorize below and the same call succeeds. That is the escalation from public to privileged, live.

  • bearerAuth — usage report: waypoint-demo-bearer
  • waypointKey — header X-Waypoint-Key, create export: waypoint-demo-key
  • waypointQueryKey — query key, export status: waypoint-demo-query-key

Sign in is optional and gates nothing. It only shows the agent sharing your browser session, and tags writes in the audit log.