Web search and fetch
A conversation can search the web and read pages, either through the search built into its model's provider or through a search service you set up in Mework. You turn web access on per conversation, choose who searches and fetches, and can filter and trim what comes back.
Turn on web access
Web access is one switch per conversation: Conversation settings → Advanced tools → Enable web search. Open conversation settings from More options → Conversation settings in the top bar, or press ⌘⇧, (CtrlShift, on Windows).
With the switch off, the model gets no web tools. With it on, it gets up to two:
- web_search whenever Search provider is not Off.
- web_fetch whenever Fetch provider is not Off; with Native, only on Anthropic Messages and AWS Bedrock models.
If the chosen provider is switched off in Settings, unavailable or missing its API key, the tool is still offered, and each call fails with a message naming the setting to change. Changing providers in Settings → Providers → Search providers never adds a tool to a conversation or removes one.
The built-in mework preset starts with the switch on, both providers on Native, Result count 5, Result compression 2,000 and Domain filter off.
A preset's settings window and each agent role have the same Advanced tools page. A role reaches the web only when the conversation that starts it does, but it can choose its own providers and domain filter, or Follow the conversation.
Search providers
Advanced tools → Search provider chooses who runs a search:
| Choice | What happens |
|---|---|
| Native | The model's own provider searches, in a separate request that contains only the query, and returns a written report with the sites it consulted. The provider bills the tokens, and they appear in your usage. |
| A provider | Mework calls that search service, and the model gets a list of results, each with a title, URL and text. Only providers switched on in Settings are listed. |
| Off | No web_search. web_fetch may still be offered. |
If a provider you picked is later switched off in Settings, becomes unavailable or lacks its API key, the menu reads Repair search provider, and searches fail until you fix it or choose again.
Native search by provider type
Whether Native works depends on the type of the model's provider, as shown in Settings → Providers → Model providers (see providers):
| Provider type | Native search | Native fetch |
|---|---|---|
| Anthropic Messages, AWS Bedrock | Yes | Yes |
| OpenAI Responses, OpenAI Codex (ChatGPT), Azure OpenAI, xAI | Yes | No |
| Google Gemini, Google Vertex AI | Yes (Google Search grounding) | No |
| OpenAI Chat Completions, OpenAI Compatible, Claude Agent (Claude Code) | No | No |
On Anthropic Messages and AWS Bedrock, the Native row opens a submenu with the tool version: web_search_20250305 (the default) or web_search_20260209, which adds dynamic filtering; for fetch, web_fetch_20250910 (the default) or web_fetch_20260209.
On a model whose type has no native search, Native cannot search, so choose a provider; ExaMCP is on out of the box and needs no API key.
Native search becomes fixed for a conversation once a search has run with it on a model that supports it, and Native fetch once a request has offered it. A fixed selector is gray, and you start a new conversation to choose again. Nothing else is ever fixed, so on a model without native search you can switch to a provider at any time. While the model's prompt cache is warm the selector is orange, because after a change the next request cannot reuse that cache.
Set up a provider
Open Settings → Providers → Search providers (⌘, opens Settings, Ctrl, on Windows). Choose a provider in the list and turn on the switch in its header.
| Field | What it does |
|---|---|
| API Key | Saved when you leave the field; clear it to delete it. Kept in the system credential store, never in conversations. |
| Search endpoint, Fetch endpoint | Leave empty to use the default below. A path is kept: https://gateway.example/tavily sends searches to https://gateway.example/tavily/search. Must be https, except that addresses on your own machine or local network (localhost, *.local, 192.168.x.x and similar) may use plain http. |
| Search engines (Searxng) | Comma-separated engine names. Empty uses the engines the instance enables in both its general and web categories. |
| Basic auth username, Basic auth password (Searxng) | For an instance behind basic authentication. |
| Provider | Searches | Fetches | API key | Default endpoint | Good to know |
|---|---|---|---|---|---|
| Zhipu | Yes | — | Required | https://open.bigmodel.cn/api/paas/v4/web_search |
The endpoint is used as the full address. |
| Tavily | Yes | — | Required | https://api.tavily.com |
|
| Searxng | Yes | — | None | http://localhost:8080 |
Your own instance, with the json output format enabled. Mework downloads each result page itself, which is slower. |
| Exa | Yes | — | Required | https://api.exa.ai |
|
| ExaMCP | Yes | — | Optional | https://mcp.exa.ai/mcp |
On out of the box. |
| Bocha | Yes | — | Required | https://api.bochaai.com |
|
| Querit | Yes | Yes | Required | https://api.querit.ai |
|
| fetch | — | Yes | None | Runs on your computer | See below. |
| Jina | Yes | Yes | Required for search; optional for fetch | https://s.jina.ai, https://r.jina.ai |
On out of the box. Fetching works without a key; a key raises the quota. |
| Firecrawl | Yes | Yes | Optional | https://api.firecrawl.dev |
Fetching pages
Advanced tools → Fetch provider works like the search provider, and the two are independent.
- Native: on Anthropic Messages and AWS Bedrock models, the provider fetches the page. Other provider types get no
web_fetchwith Native; OpenAI-style providers read pages as part of their search. - A provider that can fetch and is switched on: fetch, Jina, Firecrawl or Querit.
- Off: no
web_fetch.
A fetch provider that is later switched off, unavailable or missing its API key shows Repair fetch provider: web_fetch is still offered, and fetches fail until you fix it or choose again.
The fetch provider
The provider named fetch needs no account: Mework downloads the page itself and extracts its readable text.
- It does not run JavaScript, so a page that builds its content in the browser can come back empty.
- It reads up to 4 MiB, keeps up to 200,000 characters of text, and gives up after 30 seconds.
- It refuses pages on private or loopback addresses, except that at Full access the model may fetch a local address it names directly, such as your dev server. Redirects into your local network and links found in search results are always refused.
Domain rules
Advanced tools → Domain filter offers Use blocklist, Use allowlist and Off. Edit lists opens Domain lists, with a Blocklist and an Allowlist page: one rule per line, up to 512 rules per list.
- Only one list is in effect at a time; turning the filter off keeps both lists.
- The blocklist drops results that match a rule. The allowlist keeps only results that match, so an empty allowlist keeps nothing.
- Rules apply to search and fetch results from a provider, and fetching a blocked URL returns nothing. They do not apply to Native.
| Rule | Matches |
|---|---|
<all_urls> |
Every http and https URL. |
https://example.com/* |
Any page on example.com over https, but not its subdomains. |
*://*.example.com/* |
example.com and all its subdomains, over http or https. |
https://example.com/blog/*/draft |
Paths that match the pattern; * matches any text. The pattern must match the whole path and query. |
/example\.com\/login/ |
A regular expression, without regard to case, over the URL's origin, path and query. |
Anything else is not a rule and is ignored. A bare example.com or *.example.com is ignored, so write *://*.example.com/* to cover a domain and all its subdomains. A pattern needs a path: https://example.com is ignored, and https://example.com/ matches only the home page.
An agent role on Follow the conversation uses the conversation's filter and lists; a role with its own mode uses only its own lists.
Shaping results
Two numbers on Advanced tools limit how much of a provider's results goes into the context. Neither applies to Native, and an agent role always sets both itself.
| Field | What it does | Default | Range |
|---|---|---|---|
| Result count | How many results a search asks for. 0 leaves it to the provider. |
5 | 0–50 |
| Result compression | A token budget for the whole call, split evenly across the results; longer text is cut and ends in .... Applies to searches and fetches. 0 keeps everything, and one fetch can then fill the context window. |
2,000 | 0–200,000 |
Approvals
At Manual and Accept edits, web_search and web_fetch ask before they run; at Full access they do not (see security levels). One card covers the whole call, the query or every URL in it, and Always allow is offered. Results reach the model marked as untrusted web content.