← Browser AI From First Principles

Appendix A — Browser AI Field Guide: Setup, APIs, States, Diagnostics and Configuration

The working reference for the book: development setup, API matrix, availability and lifecycle states, configuration keys, event dictionary, diagnostics, authority states, and the Lens cheat sheet.

This appendix consolidates the contracts, states, and procedures distributed through the argument into one working reference. Prose explains; this section is for the keyboard.

Publication snapshot: September 2026. Browser flags, origin trials, API availability, and experimental configuration change. Flag values and external documentation details below reproduce the tested builds of this edition. Anything the book’s own laboratories did not observe is marked as such.


A.1 Development setup

SurfaceSetting / locationValue / actionPurposeStability
Chrome flagschrome://flags/#optimization-guide-on-device-modelEnabled (lab profile)On-device model support for local developmentExperimental, recheck per build
Chrome flagschrome://flags/#prompt-api-for-gemini-nanoEnabled where applicableFoundation-model API access for local testingExperimental, recheck per build
WebMCPchrome://flags/#enable-webmcp-testingEnabledLocal WebMCP development without relying on the origin trialExperimental, recheck per build
Extensionschrome://extensionsDeveloper mode, load unpackedLoad the Browser AI ObservatoryDurable workflow
Diagnosticschrome://on-device-internalsOpen model statusInspect on-device model state and errorsBrowser diagnostic surface
JavaScriptLanguageModel.availability(options) in DevToolsRun with intended optionsOperational preflight before creationAPI contract
ObservatoryAI Observatory panel, capability inspectionRun inspectionCapture the full lifecycle instead of guessingBook tooling

Flag values follow the laboratory run-book convention of this edition, not a permanent browser contract.


A.2 Availability and lifecycle states

One hierarchy, observed in the book’s laboratories:

LayerStateMeaningWhat to do
Interfacenot exposedGlobal such as LanguageModel absentCheck browser, channel, context, configuration
InterfaceexposedJavaScript interface existsContinue to operational preflight
CapabilityunavailableRequested configuration cannot currently be createdExplain, change route, or fall back
CapabilitydownloadableRequired assets can be acquiredRequire visible user action
CapabilitydownloadingAcquisition underwayShow progress and wait
CapabilityavailableCompatible instance can be createdCall create()
SessioncreatingBrowser is preparing the instanceMeasure creation separately
SessionreadyResource existsPermit operation
SessionrunningRequest activePermit cancellation
SessiondestroyedExplicit lifecycle endDo not reuse
RequestcompletedRuntime returned successfullyStill evaluate output
RequestabortedIntentionally stoppedDo not count as model failure
RequestfailedRuntime operation failedClassify the failure
FeatureacceptedApplication validator accepted the outputUse the result
FeaturerejectedModel completed but the feature contract failedRepair, retry, or abstain

available is not a ready session, and operational completion is not behavioral acceptance.


A.3 Built-in AI API matrix

Globals, operations, and streaming support as implemented in the book’s adapter registry:

CapabilityGlobalCreateMain operationStreamingOutput
PromptLanguageModelLanguageModel.create()prompt()promptStreaming()Text, optionally constrained
SummarizationSummarizerSummarizer.create()summarize()summarizeStreaming()Summary text
WritingWriterWriter.create()write()writeStreaming()New text
RewritingRewriterRewriter.create()rewrite()rewriteStreaming()Transformed text
ProofreadingProofreaderProofreader.create()proofread()—Corrected text with correction evidence
DetectionLanguageDetectorLanguageDetector.create()detect()—Ranked language candidates
TranslationTranslatorTranslator.create()translate()translateStreaming()Translated text

Session verbs observed in code: create, prompt, clone, destroy. The extension worker in this edition executes prompt; other operations return an explicit unsupported marker rather than failing silently.


A.4 Prompt API configuration quick reference

KeyWherePurposeImportant note
expectedInputscreate() and matching availability checkDeclares input modalities and languagesMust agree with preflight options
expectedOutputscreate() and matching availability checkDeclares expected outputTreat as capability contract
samplingModeEnrolled web experimentsSemantic sampling policyNot available on ordinary pages by default
topKExtension compatibility surfaceNumerical sampling controlLegacy extension surface; also a named compat alternative
temperatureExtension compatibility surfaceSampling variationLegacy extension surface; also a named compat alternative
monitorcreate()Observe acquisition progressProgress events do not prove fresh bytes transferred
signalcreation and request operationsCancellationPreserve abort separately from failure
responseConstraintprompt operation in laboratory surfacesConstrain output with a schemaLaboratory surface; structure still requires validation

A.5 Sampling modes

Per current Chrome Prompt API documentation (external, September 2026 — not lab-observed except as noted):

samplingModeIntent
most-predictableMaximum predictability
predictableStrongly predictable
slightly-predictableMildly predictable
balancedBalance of predictability and variation (typical default)
slightly-creativeMildly varied
creativeMore varied
most-creativeMaximum variability

Book laboratory default: most-predictable. Reason: controlled experimental comparison and compatibility with the runtime observed during the book’s experiments, including the recorded speculative-decoding rejection that named it alongside topK: 1 and temperature: 0. Not a universal recommendation: creative or writing features may legitimately choose another supported profile.


A.6 Session lifecycle

Exposure, creation, ready, usage, clone, destroy, failure — see the table in Chapter 9, Section 6. Application rules: measure creation separately from inference, snapshot usage and quota, branch experiments with clone() rather than reprompting, end with explicit destroy(), and record why destruction occurred.


A.7 Observatory event dictionary

Every trace in this book validates against one closed vocabulary. Canonical lifecycle events:

EventMeaning
capability.inspect.startedCapability inspection began
capability.inspect.finishedExposure and availability observed
capability.inspect.failedThe inspection itself failed
model.download.progressBrowser emitted acquisition progress
session.create.startedCreation attempt began
session.create.finishedSession available to the application
session.create.failedCreation failed
session.snapshotUsage, quota, and resource state observed
session.clonedBranch created from an existing session
session.destroyedResource explicitly ended
prompt.startedModel request began
prompt.chunkStreaming output observed
prompt.finishedCompleted, failed, or aborted
fixture.evaluatedMachine-checkable evaluation performed
feature.validation.finishedApplication-level acceptance or rejection

Coordination, authority, policy, and context events:

EventMeaning
coordinator.job.receivedJob accepted by the coordinator
coordinator.job.queuedJob awaiting a worker
coordinator.worker.selectedIdle worker matched capabilities
coordinator.lease.issuedWork leased, never duplicated
coordinator.job.startedExecution began (authority consumed here for bound jobs)
coordinator.job.completedResult captured
coordinator.job.failedError captured
authority.effect.normalizedExact effect canonicalized
authority.grant.boundSingle-use grant issued with digest
authority.grant.consumedGrant consumed once
authority.grant.expiredGrant lapsed unused
policy.compile.finishedPortable policy compiled or rejected
policy.decision.finishedDecision with rule and reversibility recorded
policy.run.finishedPolicy evaluation complete, external effects counted
context.manifest.loadedSite context validated
context.unit.extractedBounded unit admitted with provenance
context.unit.excludedOmission recorded with reason
structured.candidate.receivedProposal entered admission
structured.validation.finishedGate outcomes recorded

A.8 Capture and privacy modes

Metrics-only capture is the default: sizes and outcomes are recorded without retaining prompts or page text. Content capture is explicit and visible. Private units are excluded by default and cannot cross an external provider boundary; exclusions carry reasons rather than failing silently.


A.9 Structured-output validation gates

Parse, schema, domain, policy, authority, then bounded repair — see the table in Chapter 16, Section 11. A model may propose a structured action; only deterministic policy and appropriate human authority may admit it for execution.


A.10 WebMCP quick reference

The live surface is document.modelContext.registerTool(definition, { signal }), withdrawn via AbortController. Registration requires the origin trial or the testing flag, a secure top-level context, and an exposed global; the book’s probe records available or absent rather than assuming. Observed in the tested profile: WebMCP absent — the capstone never depends on it being present.


A.11 Authority states

A grant binds one normalized effect — origin, tool, arguments, policy version — under a SHA-256 digest, with a TTL and single use. Lifecycle: bound, consumed exactly once at the coordinator START boundary, or expired. Replay is denied before execution; mutation is rejected on digest mismatch. Policy requests authority; it never manufactures it.


A.12 Diagnostic decision table

SymptomFirst checkNext checkLikely layer
LanguageModel undefinedbrowser, channel, contextflags and configurationexposure
availability() returns unavailableexact options passedhardware, storage, language supportcapability
downloadablevisible user actionacquisition monitormodel acquisition
downloading never completeschrome://on-device-internalsrestart, storage pressureacquisition
available but create() failscreation optionssampling and profile compatibilitysession configuration
Session succeeds, no answerprompt traceabort and error eventsrequest
Prompt completes, result wrongfixture and evaluatortrace with captured evidencebehavior
Worked yesterday, unavailable todaymodel and browser statestorage, updates, buildbrowser-managed lifecycle
WebMCP global absentorigin trial and testing flagbrowser buildWebMCP exposure
Visible tool, wrong tool selectedselection fixturedescriptions, schemas, resultsagent behavior

A.13 Lens modes

See the comparison table in Chapter 24, Section 2. One line each: Understand interprets, Explore retrieves bounded evidence, Govern applies user policy reversibly, Act proposes and executes through admission, policy, authority, and coordinator boundaries.


A.14 What to record in every experiment

Selection and inputs, provider and data route, evidence with provenance, policy version and decision, authority state for effects, worker and execution lineage, the validated trace — enough that a stranger can replay the run and reach the same verdict about what happened.


A.15 Laminated card

UNDERSTAND interpret      EXPLORE retrieve bounded evidence
GOVERN policy, reversible ACT propose, never self-authorize

MODEL CAN: perceive, classify, generate, rank, propose
MODEL CANNOT: grant authority, change policy, bypass admission,
  consume a grant twice, invent provenance, turn uncertainty
  into certainty

AVAILABILITY: absent < exposed < downloadable < available
SESSION: create, run, clone, destroy — measure each
GRANT: exact effect, once, expiring — consumed at START
TRACE: every claim validates or it did not happen