WebMCP lets a website hand capabilities to an agent. Loadout explores the inverse: you bring capabilities you already own. Discover them over MCP, grant only the ones you choose, watch every call, and revoke instantly — without the page ever receiving the credentials behind them.
Paste any MCP server that speaks Streamable HTTP. Its tools become capabilities here, and anything you grant becomes a live tool for your agent. The URL and token go to the bridge once and come back as an expiring handle, so this page never holds your credential.
Invokes a granted capability's WebMCP execute() directly, so you can
verify the path without an agent. This is a test harness, not an agent.