# Hosted web reading

Read a public web page or research a topic from a Block, paid with StillMade credits; no network permissions or keys.

Two operations let a Block use the web without network permissions, cookies or
keys. StillMade does the reading; the person running the Block pays with
StillMade credits at the app's research prices, shown in the quote first.

**`web.fetch`** reads one public page and answers the Block's instruction from
it with StillMade's fast model. Declare one `text` input holding the URL, one
`text` output and `permissions.capabilities: ["web.fetch"]`:

```json
{"schemaVersion":1,"operation":"web.fetch","url":{"$input":"url"},"instruction":"Summarize the page in five bullet points.","output":"summary"}
```

The URL must be a public `http` or `https` address of at most 2,048
characters. StillMade refuses private, local and credentialed addresses,
follows at most three redirects, reads HTML or plain text up to 5 MB, removes
scripts and markup, and treats the page as untrusted data, never as
instructions. A page that cannot be read is refunded. The instruction is 1 to
4,000 characters.

**`web.research`** searches the web for a topic and returns a cited summary.
Declare one `text` or `brief` topic input (1 to 500 characters) and one `text`
or `json` output with `permissions.capabilities: ["web.research"]`:

```json
{"schemaVersion":1,"operation":"web.research","topic":{"$input":"topic"},"output":"findings"}
```

A `json` output receives `{"schemaVersion":1,"summary":"...","sources":[{"url":"https://...","title":"..."}]}`
(up to 12 sources); a `text` output receives the summary followed by a
numbered source list. Fixture expectations are the usual text bounds, or
`{"kind":"json"}` with optional `includes`.

The offline SDK includes `packages/block-sdk/web-example.js`, exporting
`webFetch` and `webResearch`. Pair either with `text.generate` (as a `context`
input) to write from what was read.
