Three tested invocation invariants

Hostile direct calls must preserve site-defined boundaries.

Privileged fields reject, nonexistent items do nothing, and replay commits once. Trusted state comes from a source-fixed server replay.

Scope: three frozen synthetic checkout cases on the exact tested build. Thurstone is a testing/audit system—not runtime enforcement, certification, guaranteed security, or arbitrary-site verification.

Open this route in the official ChatGPT in-app browser. In Chrome 149+, open chrome://flags/#enable-webmcp-testing, choose Enabled, and relaunch Chrome.

If Thurstone reports consumer-mismatch, close other same-origin Thurstone tabs, then reload this tab.

WebMCP unavailable? Inspect sealed Results
Separate 3/3 · no model calls
Declared boundary

Zero model calls. Zero server durable-store writes.

Checking native APIs

The browser supplies only native receipts and traces from the source-fixed calls. The verifier accepts no caller-selected tool, payload, schema, expected value, target URL, or trusted state and replays the frozen sequence in a fresh server-only store.

The one-run guard uses an exclusive browser LockManager claim keyed to this exact build in same-origin localStorage for this browser profile. Clearing site storage or using another browser or profile can bypass it; no in-app reset is provided, and the guard is not a security boundary.

  • This is a deterministic native WebMCP plumbing check, not a model-behavior measurement.
  • It is outside the Meaning Matrix denominator and does not establish generality or safety.
  • It does not validate, replace, or imply human approval of any semantic or revision artifact.
  • The compatibility cart_get and verified reset are disclosed but excluded from II-01–II-03.
  • One browser observation is compared with one source-fixed server replay; it is not a stability estimate.
Secure same-origin preflight

Provider registration and consumer execution

9d1bf2e5c4a0

Provider API

Checking…

Consumer APIs

Checking…

Initial catalog

Discovering…

Compatibility: pending · one read-only cart_get completed; the measured reset runs atomically at one-shot admission.

Frozen sequence · no arbitrary inputs

II-01 → II-02 → II-03

0 / 4 native calls

II-01 · Privileged-field injection

checkout_request · rejection-no-op

Awaiting the one-shot run

II-02 · Nonexistent item

cart_update · rejection-no-op

Awaiting the one-shot run

II-03 · Replay

checkout_request · one-transition-then-replay-no-op

Awaiting the one-shot run