Scan a page for accessibility issues
scan_pageScan a web page for WCAG accessibility issues. Works on any URL — deployed sites, localhost, staging. Returns the three-tier shape: issues (high-confidence violations safe to fix), incomplete (needs human review — gradient backgrounds, marketing imagery, axe-incomplete results, framer-motion pre-animation states), and a summary. Treat incomplete as questions, never auto-fix them. On React ≤18 / Vue dev builds each issue carries source ({file, line, column, component}) read from the live component tree. Every issue carries a structured fix.op (add-attribute | set-attribute | remove-attribute | add-element | remove-element | add-text-content | suggest) with fix.attribute / fix.value when known, and a fixability tier (mechanical = apply as given; contextual = op known, value needs judgment; visual = needs rendered output, propose only). NOTE: on this HOSTED server, localhost and private addresses are refused — it runs in our cloud and cannot reach your machine. Two ways to scan a local dev server: run the MCP locally (npx -y @webability/mcp, simplest — nothing leaves the machine), or open a tunnel (webability-tunnel --port 3000) and pass its URL as url together with the printed secret as tunnel_secret.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | URL to scan (e.g. https://example.com or http://localhost:3000) | |
| wcag | No | Only these WCAG criteria. A prefix selects the whole guideline ("1.4") or principle ("2"). | |
| rules | No | Only these rule ids (WebAbility type such as "missing_alt" or axe rule id such as "image-alt"). See get_rules. | |
| format | No | "compact" prints one line per element with rule metadata once — far fewer tokens than the default JSON. Default json. | |
| context | Yes | Explain in 15-25 words, in third person, why this tool is called and how it supports the user's goal. For analytics only. You MUST describe only the abstract purpose of the tool call. NEVER include, repeat, paraphrase, or infer personal, sensitive, or identifying information from the user request or tool results, including names, emails, phone numbers, IPs, IDs, or credentials. You MUST generalize specific entities into roles such as "a user", "the customer", or "an account". Example: "Retrieving a customer's recent orders to investigate a billing issue and help support determine the appropriate resolution." | |
| viewport | No | Viewport size (default: desktop) | |
| llm_model | Yes | The exact model identifier you (the assistant) are running as, taken from your system prompt or environment (e.g. "claude-opus-4-8", "gpt-5.2"). Used for analytics only. If you do not know your model identifier with certainty, pass "unknown" — never guess. | |
| minImpact | No | Only findings at this severity or above (critical > serious > moderate > minor) | |
| sourceRoot | No | Local project root (local installs only). Issues without a framework `source` pointer get `sourceCandidates[]` — files whose contents match the selector's id/class/attribute tokens. | |
| rootSelector | No | CSS selector to limit scan scope (optional) | |
| tunnel_secret | No | Secret printed by `webability-tunnel`. Required when `url` is a tunnel URL; the URL alone will be refused by the relay. Ignored otherwise. | |
| conversation_id | No | Echo the conversation_id from the server's previous response. The server provides it on the first call — never invent one, and do not issue parallel tool calls until you have it. |