Skip to main content
HUMΛN
Developer
Developer

WebMCP vs org MCP — two products, one trust story

HUMΛN Team··10 min·Technical (Developers)

If you remember one diagram from HUMΛN’s MCP story, make it this:

Org MCP WebMCP trust layer
Where https://{org}.mcp.haio.run Browser window.webmcp + HUMΛN bridge
Who calls Cursor, Claude Desktop, IDE agents Pages and extensions on the open web
What you expose Your workflows, agents, catalog Site tools inbound/outbound under HumanOS
Threat focus Delegation abuse inside the org mesh Origin, approval, data minimization on arbitrary sites

Same company. Same taste for receipts. Different products.

The hook: the wrong README

A team reads “MCP” once, wires the org endpoint into a browser experiment, and wonders why origin scoping and external adapters feel bolted on. Or they expect {org}.mcp.haio.run to wrap every website tool on earth. Both mistakes come from collapsing two nouns into one acronym.

Org MCP in one sentence

Your org as an MCP server — governed colleague to the platform you already run. See Your org is an MCP server.

WebMCP in one sentence

A browser trust layer for WebMCP tools: facade (expose HUMΛN capabilities) and adapter (discover/govern external site tools), both through identity, delegation, approval, capability routing, minimization, and provenance.

Transport essays (Streamable HTTP) explain how bytes move. This essay explains which product you meant.

So that buyers and builders pick deliberately

Say “org MCP” when you mean AI clients calling your mesh. Say “WebMCP” when you mean browser tool governance. If a deck mixes them, send them this table before the pilot starts.

Scroll-stopper: One word — MCP — two threat models. Pick the noun before you pick the URL.

Go deeper