Zscaler WebMCP Security Controls: Bringing Zero Trust to the Agentic Web
Zscaler, Thursday, August 27th, 2026
Zscaler extends zero trust to AI agent tool calls in the browser via the emerging WebMCP standard.
Zscaler has announced WebMCP Security Controls in its Zero Trust Browser, extending the zero-trust framework traditionally applied to human web activity to cover automated tool calls made by AI agents.
WebMCP is a proposed web standard currently available in Chrome Origin Trials that lets websites expose structured, typed JavaScript functions and annotated HTML forms as callable tools for AI agents.
An in-page agent can list those tools and invoke them directly. That creates a new execution path inside the browser that existing controls do not inspect, which is the gap Zscaler's controls are designed to close.