Allowed web domains¶
By default the agent's fetch_page tool is disabled: it refuses every URL. To let that tool read
specific sites for context:
- Exact hosts match themselves;
*.example.commatches subdomains only;**.example.commatches the apex and its subdomains. Matching is case-insensitive and ignores ports. Loopback and private addresses are only allowed when listed literally (for example127.0.0.1). fetch_pagechecks the host before any network I/O and on every redirect, converts HTML to readable text, caps the size, and returns the text to the model. A refused URL tells the agent which domains are allowed so it can ask you to extend the list.
Text fetched from an allowed site becomes a tool result and is sent to the model endpoint like any other
result. /context, /status and the startup panel show the active allowlist. The allowlist governs the
agent's own web tool, not what notebook code can do: with the default docker kernel, code the agent runs
in the notebook has no network at all unless [kernel] network = true; with unsafe-local it is ordinary
Python on your machine with your network access (see Security).