Inspiration
Supply-chain exceptions are rarely owned by one company. A delayed shipment may require a buyer to change an order, a supplier to reserve replacement inventory, and a carrier to select a new route. Today, operations coordinators manage these multi-party recoveries through email chains, spreadsheets, phone calls, and manual copy-pasting between incompatible portals. This process is slow, error-prone, and lacks audit trails. We built RelayRoom to demonstrate how WebMCP can enable secure, coordinated cross-organizational workflows without requiring every company to integrate with a central backend or surrender control of their systems.
What it does
RelayRoom is a neutral coordination room that orchestrates supply-chain recovery across three simulated partner portals (buyer, supplier, carrier) using browser-native WebMCP. Each partner exposes a minimal, explicitly allowlisted set of tools that the coordination room can discover and execute. The system:
- Discovers tools from three distinct origins with exact trust boundaries
- Queries constraints from all partners (deadlines, inventory, routes, costs)
- Simulates feasible recovery candidates using a deterministic solver
- Presents a coordinated plan with cost deltas, timing, and rollback options
- Requires explicit user approval before any partner actions execute
- Stages all partner actions first, then commits in a deterministic order
- Automatically runs compensating rollbacks if any step fails
- Generates signed audit receipts showing tool, origin, inputs, results, and timestamps
The hero scenario resolves CASE-1047: 480 sensor modules needed by Friday, with original supplier short 170 units, backup supplier requiring minimum reservations, and carrier route running 36 hours late—all while keeping added logistics cost under 10%.
How we built it
Architecture: Monorepo with separate apps for the coordination room and three partner portals, plus shared packages for contracts, operations logic, simulator, and UI components.
Tech Stack:
- TypeScript, React, Vite for all surfaces
- Express.js for backend APIs
- SQLite for operational databases (buyer, supplier, carrier, workspace)
- WebMCP draft implementation for cross-origin tool discovery and execution
- Zod for schema validation
- Zustand for state management
- Vitest for unit tests, Playwright for E2E tests
- Docker Compose for containerized deployment
Key Implementation Details:
- Each partner portal runs on a distinct origin with its own branding and state
- WebMCP tools are registered with exact
exposedToallowlists containing only the RelayRoom origin - The room discovers tools using
getTools({ fromOrigins: [...] })and executes them with origin-scoped permissions - SQLite transactions prevent overlapping reservations from overbooking resources
- Idempotency keys are tied to transaction, partner, and phase for safe retries
- Approval is written before any partner action; changed plans are rejected before execution
- Compensation restores previous order contents with new revisions and releases staged/committed allocations
Challenges we ran into
- Cross-origin WebMCP implementation: The WebMCP draft is still evolving. We had to implement the protocol correctly while providing a compatibility bridge fallback for browsers that don't support native WebMCP yet.
- Transaction safety across distributed systems: Designing a staged commit pattern with proper compensating rollback that works even when network timeouts or partial failures occur.
- Origin isolation vs. coordination: Keeping each partner's state truly isolated while still enabling the coordination room to discover and call their tools without importing their stores directly.
- Deterministic simulation: Building a solver that produces feasible candidates from normalized partner evidence without relying on AI hallucinations.
- Permission granularity: Designing tool schemas that expose exactly the capabilities needed for coordination without giving away unnecessary access to partner systems.
Accomplishments that we're proud of
- Real cross-origin WebMCP implementation: The deployed demo makes the cross-origin architecture obvious with three distinct origins and proper
allow="tools"permissions. - Complete transaction safety: Staged commit with automatic compensating rollback, idempotency keys, and SQLite transaction guarantees.
- Deterministic solver: The system computes feasible candidates without requiring AI, though it can optionally use OpenAI/Gemini for selection and explanation.
- Full audit trail: Every tool execution is logged with origin, inputs, results, and timestamp—providing clear attribution for every action.
- Comprehensive testing: Unit tests cover expiry, duplicate import rollback, idempotency, changed approval rejection, exact allocation, and failed compensation. E2E tests verify the hero flow and failure-plus-rollback scenarios.
- Production-ready deployment: Docker Compose support, environment variable configuration, and proper security headers for HTTPS deployment.
What we learned
- WebMCP's potential: Browser-native tool sharing is a powerful primitive for cross-organizational interoperability that doesn't require every company to build to the same central API.
- The importance of staged commits: In distributed systems, staging all actions first and validating feasibility before commit is essential for safety.
- Origin boundaries matter: Keeping each partner's state isolated while enabling coordination is not just a security concern—it's fundamental to the interoperability story.
- Deterministic > AI for core logic: AI is valuable for selection and explanation, but the core solver should be deterministic to ensure reliability.
- Audit trails build trust: When coordinating across company boundaries, being able to show exactly who authorized which action is critical.
What's next for it
- Multi-leg route optimization: Extend the solver to support multi-leg and split-shipment networks beyond the current single-route constraint.
- Real provider integrations: Complete certification and live-testing with actual ERPNext, Shippo, and other provider adapters.
- SSO and account management: Add single sign-on, password reset, and account revocation UI for production deployment.
- Tenant isolation: Transform from single-organization deployment to multi-tenant SaaS with proper data isolation.
- Additional exception scenarios: Support more than one polished exception scenario beyond the CASE-1047 hero case.
- Native WebMCP browser support: Full validation in a supporting browser build once native WebMCP is widely available.
Built With
- webmcp
Log in or sign up for Devpost to join the conversation.