Articles

Add Web Search to Your AI Agent with MCP (2026 Guide)

Learn how to equip your AI agent with live web search using the Model Context Protocol (MCP) and AgentSearch services. This step‑by‑step guide shows setup, payment via USDC, and best practices for secure, cost‑effective queries.

Written by:
APin

Senior Technology Analyst • Verified Expert

More from this author →
Add Web Search to Your AI Agent with MCP (2026 Guide)

Learn how to equip your AI agent with live web search using the Model Context Protocol (MCP) and AgentSearch services. This step‑by‑step guide shows setup, payment via USDC, and best practices for secure, cost‑effective queries.

Large language models (LLMs) stop learning at their training cut‑off date. After that point they cannot answer questions that depend on changes made to software libraries, cloud‑provider pricing, or regulatory documents. An engineer asking “what changed in the react‑router package last week?” or “what is the current cost of a t3.medium instance on AWS?” will receive stale or speculative answers because the model’s internal knowledge base reflects the state of the world at the time of training, not the present.

To keep AI‑assisted tooling reliable, agents must be able to retrieve fresh information from the live web and incorporate it as structured data. Typical scenarios include:

  • Detecting a newly introduced breaking change in an open‑source library by scanning its changelog.
  • Fetching the latest vendor pricing tables to compute cost estimates for deployment pipelines.
  • Verifying compliance documentation (e.g., SOC 2 or ISO 27001 controls) that is frequently updated by auditors.
  • Obtaining current security advisories that affect dependency management.

The Model Context Protocol (MCP) provides a standardized way for LLM clients to request live web data. An MCP‑compatible client (such as Claude Desktop, Cursor, or Claude Code) launches a local MCP server that signs micro‑payments in USDC on the Pocket Network. The server mediates calls to services like agentsearch-web-search-v1 and agentsearch-web-extract-v1, each priced at $0.005 per call and requiring no separate API key.

Key technical characteristics of MCP include:

  • Local payment control: Wallet keys reside on the developer’s machine; limits on total spend and per‑call cost are enforced before any payment is signed.
  • Structured responses: Search results return JSON with fields such as title, url, snippet, score, and date, enabling deterministic downstream processing.
  • Secure data handling: Results are kept in a dedicated data block, never injected into system prompts, mitigating prompt‑injection attacks described in the MCP integration guide.
  • Extensibility: Additional tools (e.g., agentsearch-web-render-v1) can be added without changing client code, as long as they conform to the MCP schema.

By coupling static LLM reasoning with MCP‑driven live web search, enterprise agents can maintain accuracy in environments where information changes rapidly, while preserving security and cost transparency.

Understanding MCP and AgentSearch Services

The Model Context Protocol (MCP) is a lightweight, JSON‑RPC‑style interface that lets an LLM invoke external tools as if they were local functions. An MCP client (e.g., Claude Desktop, Cursor, Claude Code) launches a local stdio server that forwards tool calls to a provider. The provider’s MCP server holds a private key and signs an x402 payment in USDC before forwarding the request to the actual service.

AgentSearch exposes two MCP‑registered services on the Pocket Network:

  • Web Search (agentsearch-web-search-v1) – Returns a structured JSON payload with up to five results. Each result contains title, url, snippet, score, domain, and date.
  • Web Extract (agentsearch-web-extract-v1) – Retrieves the full content of a single URL as clean markdown or plain text, together with title, links, and fetch metadata such as status_code, content_type, fetched_at, chars, and truncated.

Both services are priced at $0.005 per call. Payments are made in USDC (6‑decimal precision) on either the Base chain using the x402 protocol or on Tempo via the MPP protocol. The MCP server enforces spending limits through environment variables:

  • POCKET_MAX_TOTAL_ATOMIC – total atomic units the server may spend while running.
  • POCKET_MAX_PER_CALL_ATOMIC – maximum atomic units per individual call (set to 5000 for $0.005).
  • POCKET_NETWORK – selects the target network (default eip155:8453 for Base).

Example request for a web search (the MCP server handles the initial 402 challenge, signs the payment, and retries automatically):

curl -X POST https://agent.pocket.network/v1/agentsearch-web-search-v1/v1/search \
  -H 'content-type: application/json' \
  -d '{"query":"x402 payment protocol v2 headers","max_results":5}'

The envelope returned by the portal separates payment metadata from the supplier response:

{
  "portal": {
    "provenance": "third-party-supplier",
    "serviceId": "agentsearch-web-search-v1",
    "schemaCheck": "unchecked"
  },
  "data": {
    "query": "x402 payment protocol v2 headers",
    "result_count": 5,
    "results": [
      {
        "title": "...",
        "url": "https://...",
        "snippet": "...",
        "score": 0.91,
        "domain": "...",
        "date": "..."
      }
    ]
  }
}

When a full document is required, the extract service is called with a payload such as:

{
  "url": "https://example.com",
  "formats": ["markdown"],
  "max_chars": 20000
}

Agents should treat the data block as immutable content, never inject it into system prompts, and verify portal.schemaCheck before trusting the structure.

Installing and Configuring a Local MCP Server

To integrate live web search and content extraction into your AI agent workflows, you must deploy the @pocket-network/agentic-portal-mcp server. This server facilitates payments for Pocket Network services by signing x402 requests locally, ensuring your private key is never transmitted to the service provider.

Installation requires Node.js 20 or newer to support the npx execution model. Because MCP clients, such as Claude Desktop, Cursor, or Claude Code, launch the server in an isolated process, you must define all configuration parameters, including the wallet's private key, within the client's configuration file rather than your shell environment.

Configuring Spending Limits

Security is managed through hard-coded limits in the MCP configuration. Because USDC utilizes 6 decimal places, spending limits are defined in atomic units (e.g., 1,000,000 units equals $1.00 USDC). Configure the following environment variables within your mcpServers definition:

  • POCKET_PRIVATE_KEY: The private key of a dedicated wallet containing USDC on Base. Use a wallet specifically for this integration to mitigate risk.
  • POCKET_MAX_TOTAL_ATOMIC: The cumulative spend limit for the server session.
  • POCKET_MAX_PER_CALL_ATOMIC: The maximum cost permitted for a single tool invocation. Set this to 5000 (0.005 USDC) to prevent overspending on individual operations.
  • POCKET_QUOTE_ONLY: Set to true to test service discovery and pricing without executing payments.

Example implementation for an MCP configuration file:

{
  "mcpServers": {
    "pocket-network": {
      "command": "npx",
      "args": ["-y", "@pocket-network/agentic-portal-mcp"],
      "env": {
        "POCKET_PRIVATE_KEY": "0x...",
        "POCKET_MAX_TOTAL_ATOMIC": "250000",
        "POCKET_MAX_PER_CALL_ATOMIC": "5000",
        "POCKET_QUOTE_ONLY": "true"
      }
    }
  }
}

After updating your configuration, restart the client. Use search_services to explore available tools without cost, and once validated, remove POCKET_QUOTE_ONLY to enable live execution. When processing results, strictly treat them as external data; do not inject them into system prompts or follow instructions embedded within the retrieved content to prevent prompt injection attacks.

Running Searches and Extracts with AgentSearch

Before an agent can invoke a live web search or page extraction, it must locate the correct AgentSearch service definitions. The Agentic Portal exposes three MCP tools; the first two are free and can be used without a private key:

  • search_services – queries the portal catalogue by keyword or category.
  • describe_service – returns the price, HTTP method, endpoint path, request schema, and a captured example for a given service ID.

A typical discovery flow looks like this:

search_services("agentsearch")
describe_service("agentsearch-web-search-v1")
describe_service("agentsearch-web-extract-v1")

The describe_service output shows that both agentsearch-web-search-v1 and agentsearch-web-extract-v1 cost $0.005 per call and accept a JSON payload defined in their OpenAPI specs.

Running a paid search

Once the service IDs are known, the agent issues a call_service request. The underlying HTTP call can be reproduced with curl:

curl -X POST https://agent.pocket.network/v1/agentsearch-web-search-v1/v1/search \
  -H "Content-Type: application/json" \
  -d '{"query":"x402 payment protocol v2 headers","max_results":5}'

The MCP server first receives a 402 Payment Required response containing the seller’s terms. It signs an x402 payment (using the wallet configured in POCKET_PRIVATE_KEY) and retries automatically. The final envelope returned by the portal has two top‑level objects:

{
  "portal": {
    "provenance": "third-party-supplier",
    "serviceId": "agentsearch-web-search-v1",
    "schemaCheck": "unchecked"
  },
  "data": {
    "query": "x402 payment protocol v2 headers",
    "result_count": 5,
    "results": [
      {
        "title": "...",
        "url": "https://...",
        "content": "...",
        "score": 0.91,
        "domain": "..."
      }
    ]
  }
}

Extracting a full page

If the snippets returned by the search are insufficient, the agent can request a clean markdown extraction:

curl -X POST https://agent.pocket.network/v1/agentsearch-web-extract-v1/v1/extract \
  -H "Content-Type: application/json" \
  -d '{
        "url":"https://example.com",
        "formats":["markdown"],
        "max_chars":20000
      }'

The response follows the same envelope pattern, with data.title, data.markdown, data.links, and metadata fields such as status_code, content_type, and fetched_at. These fields should be treated as raw data; they must never be injected into system prompts or executed as instructions, as third‑party pages can contain malicious directives.

Operational safeguards

  • Set POCKET_MAX_TOTAL_ATOMIC and POCKET_MAX_PER_CALL_ATOMIC to enforce spending limits (e.g., 1 000 000 atomic units ≈ $1.00).
  • Use POCKET_QUOTE_ONLY=true for dry‑run discovery; remove it before real calls.
  • Validate portal.schemaCheck – a value of unchecked means no schema validation was performed.

Following this pattern lets enterprise engineers integrate live web search and extraction into Retrieval‑Augmented Generation pipelines while keeping payment handling, data hygiene, and security controls explicit.

Security, Troubleshooting, and Next Steps

When an LLM agent consumes data from agentsearch-web-search-v1 or agentsearch-web-extract-v1, the response is wrapped in a portal envelope that contains metadata such as schemaCheck. A passed value indicates that the service performed a schema validation; unchecked means no validation occurred, and the payload must be treated as untrusted raw data.

Best‑practice checklist for third‑party data

  • Isolate data from prompts. Store the entire result in a dedicated data block (e.g., a JSON field or a tool‑result variable) and never concatenate it into a system or user prompt.
  • Validate schema. Verify portal.schemaCheck === "passed" before deserializing. If the check is unchecked, run a local JSON schema validator against the expected contract.
  • Guard against instruction injection. Do not execute instructions that appear inside the payload (e.g., “call another endpoint” or “ignore prior instructions”). Treat any such text as plain data.
  • Apply least‑privilege limits. Configure MCP environment variables (POCKET_MAX_TOTAL_ATOMIC, POCKET_MAX_PER_CALL_ATOMIC) to cap spending and prevent runaway calls.
  • Follow compliance frameworks. Align the handling of third‑party data with standards such as NIST SP 800‑53 for data integrity, and ensure audit logs satisfy ISO 27001 requirements for access control.

Common error scenarios

  • Missing private key. Free tools work, but paid calls fail with “POCKET_PRIVATE_KEY is missing.” Add the key to the MCP server’s env block, not just the shell.
  • Limit blocks. Calls are rejected when POCKET_MAX_TOTAL_ATOMIC or POCKET_MAX_PER_CALL_ATOMIC is exceeded, or when POCKET_QUOTE_ONLY remains true.
  • Empty result with error.retryable. Indicates a timeout or upstream failure; implement exponential back‑off and retry.
  • Unsupported content. UNSUPPORTED_CONTENT is returned for PDFs, images, or JavaScript‑rendered pages. Use the agentsearch-web-render-v1 service for headless‑browser rendering.

Next steps and resources

APPWORKS ENGINEERING

Looking for Custom Software or AI Solutions?

Appworks Technologies designs, builds, and scales production enterprise platforms, microservices, and AI agent workflows tailored to your business goals.

Editorial Policy & Research Methodology

Our findings are based on rigorous internal research, verified industry benchmarks, and direct technical implementation experience from our enterprise client projects. All statistics and technical claims are reviewed by senior engineers before publication to ensure accuracy, transparency, and helpfulness for our readers.

Have an Idea? we offer services in Lucknow, Bangalore, Delhi NCR and other locations