send_url
Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first w...
This record as markdown: /tools/de-agentview-agentview-mcp/send-url.md
What send_url does on agentView
AI agents use send_url to create or update resources in agentView, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your agentView environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
url | string | Yes | Absolute HTTP or HTTPS URL to load, e.g. 'https://example.com/dashboard'. |
slot | string | — | 'live' (default) or 'idle' for default/fallback content (admin scope). |
duration | integer | — | Seconds the content stays; 0 = indefinite (default). Live slot only. |
display_id | string | Yes | 8-character display profile ID, e.g. 'ABCD1234'. |
access_token | string | — | Optional bearer token; prefer session_request_id. |
session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
content_description | string | — | Short summary of what the page shows (recommended). |
Parameters from the server's own tool schema.
Why send_url is rated Medium
An AI agent can call send_url faster than any human can review: one bad instruction and it creates or modifies resources in agentView by the hundred, each call as confident as the last.
Risk signalsAccepts URL/endpoint input (url) · Handles credentials or secrets (access_token) · Admin/system-level operation
Attacks that exploit this kind of access
The rule that runs send_url safely
PolicyLayer is an MCP gateway: it sits between your AI agents and agentView, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For send_url, this is the rule to start with:
send_url stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect agentView, apply this rule, and every send_url call is checked against it from then on.
Questions about send_url
Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first when unsure about connectivity or embedding limits. If the page design is not display-ready, prefer send_html with generated content. Requires content scope. It is categorised as a Write tool in the agentView MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
send_url accepts 7 parameters: url, slot, duration, display_id, access_token, session_request_id, content_description. Required: url, display_id. The full parameter table on this page comes from the server's own tool schema.
Register the agentView MCP server in PolicyLayer and add a rule for send_url: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches agentView. Nothing to install.
send_url is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the send_url rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for send_url. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
send_url is provided by the agentView MCP server (https://agentview.de/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on agentView, and thousands of servers like it.
This server
Across the catalogue