Actions
Parameters
invoke fetches the item again and rejects an operation that isn’t currently advertised. Read the operation’s description and get explicit user approval before invoking it.
wait observes readiness. It doesn’t detect edits to an item that’s already ready; compare version from get without wait instead. A ready credential means its required values exist, not that a login succeeded. A ready card doesn’t mean a payment succeeded.
Wait for a credential
collect.
Fill a form
Fill writes values into the browser without submitting the form. Pass the attached browser’s session ID, the exact current page URL, and selectors verified on that page:status of completed, failed, or unknown, and an ordered per-field outcome. completed means the fields were written, not that the form was submitted or accepted. failed and unknown are returned as tool errors and fields may already be written.
Because fill never submits the form, it’s safe to retry after a failed or unknown outcome, a lost response, or an API error. When a field failed, fix its cause, such as a selector that matched nothing, before retrying. A retry right after unknown can wait up to 15 seconds for the earlier attempt’s browser lock to expire. See Fill Browser Fields for selector and timeout rules.
Call a WebMCP tool with vault values
When the item advertiseswebmcp_invoke, list the browser’s tools with webmcp, then bind vault fields to null slots in the tool’s input:
The result carries
status (completed, awaiting_submission, canceled, error, or unknown), invocation_id, output, and error_text. Unlike fill, the tool may submit the form or cause other side effects, so get user approval first.
1Password operations
1Password credentials advertise these operations:
Give the approval link, unmodified, only to the account owner outside the agent-controlled browser. Never open or approve it yourself.
fill_submitted means the extension submitted the form, not that the login succeeded. Never retry fill_unknown in the same browser. If a request is uncertain, the item has no advertised operations; don’t delete or recreate it to retry.
Observe events
events, next_after, and observation hints. Pass next_after as after on the next call to read only newer events.
Delete an item
delete invalidates the item’s credential; confirm with the user first. Unresolved payments can block deleting a card or wallet. Deletion doesn’t prove a payment didn’t happen. recovery_required isn’t a decline or expiry: stop payment attempts and reconcile with the provider or support.