# webGCP > webGCP (Web Graph-Context-Protocol) is an open protocol for graph-aware AI agents. It is not affiliated with Google Cloud Platform. An open protocol for matching agentic capabilities (skills) to work (tasks). Agents today reach tools through flat lists; webGCP models context as a typed graph instead, so capabilities carry relationships, provenance, and evidence rather than sitting in an undifferentiated catalog. Two properties are load-bearing. **Discovery is link-driven** — a server advertises itself at a well-known path and a DNS record; there is no central registry, and aggregators are not the protocol. **Evidence outranks self-description** — a manifest is a *claim*; only real-execution outcomes are recorded as proven. The protocol and the skill corpus are open; the trained matcher is not. Read the spec, build to it, and report what breaks. New here? https://webgcp.org/start routes five ways in, each with its first step inline: install webGCP on your website (one JSON file at /.well-known/webgcp — the descriptor IS the installation), subscribe to the public data, call the doors from your app, publish your skills into the catalog, or build a conformant server. The consumer quick-start for the doors is https://webgcp.org/guides/consuming. ## What webGCP is for (positioning) The protocol serves **agentic workflows that need capabilities**: an agent working on a task queries the network for the skills, roles, and evidence that fit it. The shape is webMCP-like, the reach is not: webMCP declares a website's *own* tools to visiting agents; a website that adopts webGCP gives its agents the *network's* graph — skills and pillars with provenance, not a local tool list. The network's public projection is served self-serve at https://webgcp.org/onboarding (a per-subscriber BigQuery Analytics Hub listing — corpus text, the capability graph, and a derived evidence surface; queries billed to your own cloud project), and hosted query/answer doors are documented in the descriptor. Raw embedding vectors and raw evidence rows are not part of the open surface — semantic search and fresh evidence verdicts route through the hosted doors. A packaged site-embed ("install webGCP on your site") is stated direction with a published extension draft, not yet a shipped SDK — today adoption means publishing a descriptor, consuming the doors, or subscribing to the projection. ## Status — read this before citing anything here - **v1.0 was declared 2026-08-27** by promoting the frozen v0.1 core as-is after its use-alone soak gate passed (soak exited 2026-08-16). https://webgcp.org/spec/v1.0 permanently redirects to the byte-stable /spec/v0.1/ text — the promotion is status metadata; the bytes did not change, and the URL discipline below is unchanged. - **The v0.1 URL is permanent and its bytes do not change.** Later revisions publish at new URLs; they never overwrite it. - **Three implementations are registered** — two full-L0, one of them written outside the authoring team (2026-06-26, the second-implementer threshold), and a third in build toward L1 carrying a cryptographically signed conformance claim. Levels are fixture-backed; only L0 has passing fixtures today, and production posture is stated per surface, never implied by the version number. - **This is not from a standards body.** It is a public proposal, authored independently, intended for eventual donation to a neutral foundation after interoperability is demonstrated. No standards status is claimed. - **Licensing:** specification text under CC-BY-4.0; JSON Schemas and conformance fixtures under Apache-2.0. The services and reference implementations are **proprietary** — the format is open, the running code is not. ## Spec - https://webgcp.org/spec/v0.1/ — the frozen normative protocol (v1.0-promoted). Wire format, manifests, discovery, conformance levels. - https://webgcp.org/spec/v1.0 — the v1.0 name; a permanent redirect to the byte-stable text above. - https://webgcp.org/spec/v0.2-candidate/ — the v0.2 **candidate**. A working draft, not v0.2 final, and not normative. It is served with `X-Spec-Status: candidate-draft`. - https://webgcp.org/spec/v0.2-profile/ — **webGCP as a webMCP profile** (candidate-normative, promoted 2026-08-25 after measured gates on a live reference implementation): the typed-context extension carried on webMCP's own surfaces, with graceful degradation as the load-bearing invariant. Candidate, not normative — a second, independent implementer gates normative publication. The two candidates coexist; neither wins by default. - No machine-readable revision feed is published yet. There is no changelog endpoint to poll; watch the URLs above. (Stated so an agent does not go looking for one.) ## Conformance ladder Levels are **self-declared and externally verifiable** against the published fixtures. A server declares its level in its descriptor; over-claiming is a conformance failure, not a rounding error. - **L0 — Reader.** Single knowledge base, single bundle contract, manifest, typed responses, provenance, ACL, typed failures, plus the discovery surfaces (the well-known descriptor and the SVCB record). The smallest useful deployment. Fixtures are live and passing. - **L1 — Compiled.** Adds multiple knowledge bases, multiple retrieval primitives, versioned artifacts, refresh SLAs. Production single-org deployments. - **L2 — Governed.** Adds PII classification, audit retention, signed manifests, right-to-delete, ACL inheritance. Design target. - **L3 — Federated.** Adds cross-server trust, identity propagation, content-origin tagging. Design target. - **L4 — Composable.** Adds manifest changefeed, eval-gated publishing, deterministic conflict resolution, cross-KB transactions. Design target. Only L0 has passing fixtures today. L2 through L4 are design targets and are labelled as such in the specification. ## Conformance suite — runnable - https://webgcp.org/conformance/v0.1/ — the suite index. - https://webgcp.org/conformance/v0.1/runner.py — the runner. Point it at a host and it reports. - https://webgcp.org/conformance/v0.1/WGCP-L0-001.json — L0 fixture. - https://webgcp.org/conformance/v0.1/WGCP-L0-002.json — L0 fixture. - https://webgcp.org/conformance/v0.1/WGCP-L0-003.json — L0 SVCB discovery fixture. - https://webgcp.org/conformance/attested-context/ — the Attested Context L0 suite (see Extensions). - https://webgcp.org/conformance/site-embed/ — site-embed conformance material (draft). - https://webgcp.org/conformance/v0.2-candidate/ — v0.2-candidate conformance material (draft). ## Extensions (draft) - https://webgcp.org/extensions/attested-context/v0.1-draft/ — **Attested Context**, an MCP extension for server-vouched context (`org.webgcp/attested-context`). DRAFT v0.1: one author-operated implementation in use-alone soak; served with `X-Spec-Status: draft`. The delta: provenance per served item, absent-not-masked denial, audience-scoped tools, mediated assembly, and a signed content-addressed vouch backed by a governed receipt. - https://webgcp.org/extensions/site-embed/v0.1-draft/ — **Site-embed**: a website installs webGCP as a network participant, descriptor-first — the participant descriptor is the installation. DRAFT v0.1. - https://webgcp.org/extensions/task-answer/v0.1-draft/ — **Task Answer**: the typed ask/answer door contract (typed outcomes, provenance-carrying answers). DRAFT v0.1. - https://webgcp.org/conformance/attested-context/ — the Attested Context L0 suite: twelve assertions across three fixtures, a stdlib-only transcript runner (run `runner.py --self-test` first), golden transcripts and eleven negative controls. Passing it is a claim about a captured transcript, not a ratification signal. ## Discovery surfaces - https://webgcp.org/.well-known/webgcp — a live example descriptor, and this host's own. A conformant server MUST publish one at this path. - `_webgcp.` SVCB record (RFC 9460) — the DNS-layer half. Hosts without a controllable DNS zone declare a `restricted_domain_reason` in the descriptor instead. - The catalog's MCP server is published in the official MCP registry as `org.webgcp/catalog` (active listing) — MCP-native discovery of the same hosted doors the descriptor documents. - https://webgcp.org/discovery-checklist/ — the pre-L0 discovery checklist: runnable curl/jq assertions for the descriptor, the agent-card carrier, cross-surface agreement, and SVCB. Passing it is **not** an L0 claim; it is the discovery subset provable before a query endpoint exists. ## JSON Schemas - https://webgcp.org/schemas/ — the schema index. - https://webgcp.org/schemas/manifest/v0.1.json - https://webgcp.org/schemas/bundle/v0.1.json - https://webgcp.org/schemas/entity/v0.1.json - https://webgcp.org/schemas/receipt/v0.1.json ## How webGCP relates to adjacent protocols - https://webgcp.org/composition/ — wire-level pairing with MCP, WebMCP, MCP server cards, AP2, x402, A2A, and DNSAID. webGCP composes with these; it does not replace or compete with them. - https://webgcp.org/payments/ — payments & interoperability: how value moves; settlement composes on external standards, never embeds in the protocol. ## Skills (OKF bundle) - https://webgcp.org/skills/index.md — public skill concepts, OKF v0.1, content-addressed. Imported from public publisher repositories; the source repo is encoded in each concept's `resource` URN, and each concept is licensed by its upstream source. Most claims are self-declared (`inferred`); a `# Proven Capabilities` section appears only once real-execution evaluation edges exist. Synthetic and uncleared-flagged skills are excluded. - https://webgcp.org/skills/llms.txt — the bundle's own descriptor. ## Contact - ops@webgcp.org — spec questions and issues, five-business-day response. - https://webgcp.org/contact/ — the collaboration intake form. ## About this file `llms.txt` is a **community convention, not a ratified standard**. It has no IETF or W3C status, adoption is roughly one site in ten, and support across crawlers and model providers is inconsistent. It is published here because it is cheap and additive — not because it confers any standing. If the convention is abandoned, this content moves; the obligation it serves — an agent arriving with no prior knowledge should be able to orient in one fetch — does not depend on the filename. Last reviewed: 2026-08-27.