An agent can reach one of this estate's calculators three ways. The page registers a tool with the browser. A link carries the inputs. A call goes over the network to the worker. This page walks each door in turn, then runs one published input sample through all three paths so the receipts can be compared line by line. Everything described as running today was read or run against the public site on 5 October 2026.
What a registration publishes, the two ways its arguments can travel, the link that carries inputs, and the worker that runs the same module one network hop away.
A page that wants an agent's call publishes one registration: a name, a description, an input schema derived from the kernel's declared inputs, and an execute function. The page makes the registration in its own JavaScript when the browser exposes the model context, so the browser learns what the page can do and nothing leaves the machine.
In stock Chrome 149 through 156 the surface is on behind an origin trial, and a first-party token in a meta tag turns it on for visitors without a flag. Off-site discovery has its own artifact: .well-known/webmcp.json lists each registered tool with its page, its name, a SHA-256 of its input schema and its read-only annotation. On 5 October 2026 that file listed 107 tools.
Read https://ainumbers.co/.well-known/webmcp.json and report the name, description and read-only annotation recorded for the x402 signer recovery page.
One registration carries two ways for the arguments to travel. In wrapper mode the arguments fill the page's own form and press the page's own run, so what the agent receives is byte for byte what a person pressing Run receives. In direct mode the arguments are checked against the registration's schema and handed straight to the page's kernel function, and an echo panel shows the exact inputs the agent used.
Direct mode is rare, and the reason is the point: handing arguments straight to the kernel function only means something when the page carries a byte-exact copy of that kernel, so the page stamps a digest of the exact kernel bytes it shipped and the site checks that stamp against the kernel file. Most registrations choose wrapper mode for exactly this reason. On 5 October 2026 the site's own check of every registered page ran clean, with 54 pages settling on a documented baseline that is designed only to shrink.
On the currency basket index page, call the registered tool with a two-component basket, then read back the echo panel: list the exact inputs the agent used.
A node page accepts a link that carries its inputs. The fragment after #p=v1 holds the parameters, gzipped and base64url-encoded, and adding &run=1 computes on load. A URL fragment is never sent to a server, so the inputs never reach this site's server, and the page's own run function produces the artifact.
The link is a handoff and the page is still the computer, so the form state decides the bytes. The manifest's worked sample carries five fields and its receipt reads 38071028…9e4b. Let the page's form supply the three remaining declared fields as empty strings and the same sample produces f2f31693…a853. Both receipts say SIGNER_RECOVERED. The different hash is expected: it commits to the exact bytes, and the two form states are different bytes.
Give me a link that opens the x402 signer recovery page with this digest, r, s, yParity and claimed address filled in, and runs it on load.
The same kernel module runs one network hop away. The page carries a shard of the kernel inline, the worker carries its own copy of the same module, and a tools/call request in a JSON-RPC envelope reaches the worker at mcp.ainumbers.co/mcp. The response is a full artifact: verdict, output payload, execution hash, and the digest of the kernel that ran.
POST https://mcp.ainumbers.co/mcp
{"jsonrpc":"2.0","id":2,"method":"tools/call",
"params":{"name":"verify_x402_signer_recovery",
"arguments":{"policy_parameters":{ "the manifest sample" }}}}Whether an agent arrives through the registration, a link or the network, the kernel identity and the hash travel with the answer, so a third party can check the work without trusting the messenger. The server lists one tool per node, and utilities such as verify_execution_hash recompute any artifact's hash from its inputs.
The same input through all three doors, and the origin trial that carries the registration door while the browser decides.
The payoff is convergence. One input sample, the worked example published in the x402 signer recovery manifest, went through the page's kernel shard, the deep-link path and one live worker call on 5 October 2026. All three returned the same verdict and the same execution hash.
| Door | What ran on 5 October 2026 | execution_hash |
|---|---|---|
| Page compute | the page's inline kernel shard, wrapper fill then run | sha256:f2f3169335e70d55f770b7fff200403885be8672878973c53dbe3f8b185fa853 |
| Deep link | the #p=v1 fragment decoded by the page, computed on load | sha256:f2f3169335e70d55f770b7fff200403885be8672878973c53dbe3f8b185fa853 |
| Worker | one tools/call to mcp.ainumbers.co/mcp | sha256:f2f3169335e70d55f770b7fff200403885be8672878973c53dbe3f8b185fa853 |
| Verdict | SIGNER_RECOVERED; recovered signer 0x7e5f4552…5bdf matches the claimed address | identical preimage: digest, r, s, yParity, claimedFrom, plus the form's three empty declared fields |
The registration door's own published beat comes from the Agent Staircase: the page's registered function produced sha256:1bc5c975…7a64 with zero network requests during the call. That beat ran a different input sample, and the difference is the design working: the hash commits to the bytes it received, and identical bytes converge on every door.
Call verify_x402_signer_recovery on https://mcp.ainumbers.co/mcp with the sample from this page's step five table, and compare its execution_hash with the page's, character by character.
The registration door rides a browser surface that is in public testing. Chrome runs the WebMCP origin trial for versions 149 through 156, and a first-party token in a meta tag turns the surface on for this estate's registered pages without a flag. The current token expires on 17 November 2026. The trial itself ends 16 November 2026, and Chrome 157 is the pencilled-in ship-by-default milestone.
Staged progress is the posture: register tools, let agents exercise them in the open, and let the surface earn its default. The pages are built so the outcome does not change them: a browser with the surface gets the registered tools, and a browser without it gets the same page, form and hashes, with the registration code idle.
Read the origin-trial meta tag on the x402 signer recovery page and report the feature it declares and the expiry it carries.