The API allows a webpage to ask for access to a device in response to a user action only. At this point the user has to give the page permission to access Bluetooth devices. The browser then prompts the user to choose a device from a list of available devices, and the webpage is granted access to whichever device the user picks. That's all. There's no "list every Bluetooth device in the area" API (at least not yet), unless I'm missing something.
More reading: https://medium.com/@jyasskin/the-web-bluetooth-security-mode...
And also: https://medium.com/@urish/is-now-a-good-time-to-start-using-...
And also also: https://developers.google.com/web/updates/2015/07/interact-w...