Agent Readiness Index
Per-check agent-readiness results for 17 organizations building agentic commerce infrastructure, measured against the 21 scored checks, and refreshed weekly.
- Organizations scanned
- 17
- Checks per organization
- 21
- Median score
- 3 / 21
Rankings
Ranked by the number of scored checks passing. We publish the check tally rather than the scanner's level, because a site can be labelled “Agent-Native” with real gaps still open.
1agenticplug.aiIndex operatoragenticplug.ai · Our own site16 / 2116 core · 0 commerce
Passing · 16
- robots.txt
- Sitemap
- Link headers (RFC 8288)
- DNS-AID + DNSSEC
- Markdown negotiation
- Named AI bot rules
- Content-Signal
- API catalog (RFC 9727)
- OAuth discovery (RFC 8414)
- Protected resource metadata (RFC 9728)
- auth.md
- MCP server card (SEP-2127)
- A2A agent card
- Agent Skills index
- WebMCP
- ARD / ai-catalog
Missing · 5
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents, and the scanner detected commerce signals here (platform:shopify, schema:Offer, meta:shopify, prices:multiple).
Scanned 2026-08-21 · scanner reported Level 5
2Model Context Protocolmodelcontextprotocol.io · Standards body10 / 2110 core · 0 commerce
Passing · 10
- robots.txt
- Sitemap
- Link headers (RFC 8288)
- Markdown negotiation
- Named AI bot rules
- Content-Signal
- MCP server card (SEP-2127)
- A2A agent card
- Agent Skills index
- WebMCP
Missing · 11
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 4
3Cloudflarecloudflare.com · Infrastructure6 / 216 core · 0 commerce
Passing · 6
- robots.txt
- Sitemap
- Link headers (RFC 8288)
- Markdown negotiation
- Named AI bot rules
- Content-Signal
Missing · 15
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 3
4PayPalpaypal.com · Payments4 / 214 core · 0 commerce
Passing · 4
- robots.txt
- Sitemap
- Named AI bot rules
- OAuth discovery (RFC 8414)
Missing · 17
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents, and the scanner detected commerce signals here (payment:paypal, url:/checkout, url:/buy).
Scanned 2026-08-21 · scanner reported Level 1
5Stripestripe.com · Payments4 / 214 core · 0 commerce
Passing · 4
- robots.txt
- Sitemap
- Named AI bot rules
- Agent Skills index
Missing · 17
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents, and the scanner detected commerce signals here (platform:shopify, platform:woocommerce, payment:stripe, meta:shopify, url:/shop).
Scanned 2026-08-21 · scanner reported Level 1
6Anthropicanthropic.com · AI platform3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
7Block (Square)squareup.com · Payments3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
8Coinbasecoinbase.com · Payments3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
9Klarnaklarna.com · Payments3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
10Linux Foundationlinuxfoundation.org · Standards body3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
11Microsoftmicrosoft.com · AI platform3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
12Salesforcesalesforce.com · Commerce platform3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
13Shopifyshopify.com · Commerce platform3 / 213 core · 0 commerce
Passing · 3
- robots.txt
- Sitemap
- Named AI bot rules
Missing · 18
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents, and the scanner detected commerce signals here (platform:shopify, payment:apple-pay, meta:shopify, url:/shop).
Scanned 2026-08-21 · scanner reported Level 1
14Adyenadyen.com · Payments2 / 212 core · 0 commerce
Passing · 2
- robots.txt
- Sitemap
Missing · 19
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Named AI bot rulesNames specific AI crawlers and states what each one may do.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
15Googlegoogle.com · AI platform2 / 212 core · 0 commerce
Passing · 2
- robots.txt
- Sitemap
Missing · 19
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Named AI bot rulesNames specific AI crawlers and states what each one may do.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21 · scanner reported Level 1
16Amazonamazon.com · Commerce platform2 / 212 core · 0 commerce
Passing · 2
- robots.txt
- Named AI bot rules
Missing · 18
- SitemapLists every URL worth crawling, so nothing depends on link discovery.
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
Not evaluated: WebMCP. The scanner could not run this check, so it is excluded from the score rather than counted as a failure.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21
17Visavisa.com · Payments0 / 210 core · 0 commerce
Passing · 0
Nothing passing.
Missing · 21
- robots.txtTells crawlers what they may fetch, and points them at the sitemap.
- SitemapLists every URL worth crawling, so nothing depends on link discovery.
- Link headers (RFC 8288)Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
- DNS-AID + DNSSECPublishes agent endpoints in DNS, signed, so they can be found without fetching the site.
- Markdown negotiationServes clean Markdown to agents that ask for it, instead of making them parse HTML.
- Named AI bot rulesNames specific AI crawlers and states what each one may do.
- Content-SignalDeclares how content may be used: search, ai-input and ai-train, each set separately.
- API catalog (RFC 9727)A single document listing every API the site offers.
- OAuth discovery (RFC 8414)Tells an agent where and how to authenticate.
- Protected resource metadata (RFC 9728)Says which authorization server guards a given resource.
- auth.mdPlain-language instructions for an agent on obtaining credentials.
- MCP server card (SEP-2127)Declares an MCP server that agents can actually call.
- A2A agent cardDeclares an agent that other agents can talk to.
- Agent Skills indexPublishes executable skills an agent can load and run.
- WebMCPExposes in-page tools to agents through navigator.modelContext.
- ARD / ai-catalogA capability manifest listing the servers, agents and tools on offer.
- ACPAgentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
- UCPUniversal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
- AP2Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
- x402Prices a resource over HTTP 402 so an agent can pay per request.
- MPPMachine Payments Protocol. Lets agents settle payments programmatically.
No agentic commerce protocol is implemented. These apply to sites that transact through agents.
Scanned 2026-08-21
Want to know where you'd rank?
We'll scan your site against all 21 checks and send you the scorecard, free, including which fixes move you the most.
What we measure
Every organization in this index is scored against the same 21 checks, in five groups: discoverability, content accessibility, bot access control, API and agent interfaces, and agentic commerce. Each one asks whether a single specific artifact is published in the form its standard defines: a sitemap, a Link response header, an MCP server card, a signed DNS record, a priced HTTP 402 response. A check passes or it does not: there is no partial credit, no weighting, and no judgement about the company behind the site.
Discoverability
4 scoredCan an agent find the site, and the endpoints it offers, without guessing at URLs?
- robots.txtRFC 9309
A valid /robots.txt that resolves and carries at least one Sitemap: directive.
Tells crawlers what they may fetch, and points them at the sitemap.
16 of 17 scanned organizations pass this check.
- Sitemapsitemaps.org
A valid XML sitemap at /sitemap.xml listing the URLs worth crawling.
Lists every URL worth crawling, so nothing depends on link discovery.
15 of 17 scanned organizations pass this check.
- Link headersRFC 8288 · RFC 9727
A Link: response header on the homepage using registered relations: api-catalog, service-desc, service-doc, describedby.
Advertises the API catalog and docs in the HTTP response itself, before the page is parsed.
3 of 17 scanned organizations pass this check.
- DNS-AID + DNSSECRFC 9460 · DNS-AID draft
ServiceMode SVCB/HTTPS records under _*._agents.<domain> (_index, _mcp, _a2a), resolving with DNSSEC validation.
Publishes agent endpoints in DNS, signed, so they can be found without fetching the site.
1 of 17 scanned organizations pass this check.
Content accessibility
1 scoredCan an agent read the content without rendering and parsing a page built for human eyes?
- Markdown negotiationHTTP content negotiation
Clean Markdown of the page, served in response to Accept: text/markdown, from a /md twin, or at /llms.txt.
Serves clean Markdown to agents that ask for it, instead of making them parse HTML.
3 of 17 scanned organizations pass this check.
Bot access control
2 scored · 1 informationalHas the site stated, in machine-readable form, which agents may do what with its content?
- Named AI bot rulesRFC 9309
Named AI-crawler rules in robots.txt (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and the rest) rather than one blanket User-agent: *.
Names specific AI crawlers and states what each one may do.
14 of 17 scanned organizations pass this check.
- Content-SignalCloudflare Content Signals
A Content-Signal: directive in robots.txt setting search, ai-input and ai-train independently.
Declares how content may be used: search, ai-input and ai-train, each set separately.
3 of 17 scanned organizations pass this check.
- Web Bot AuthHTTP Message Signatures
A signed bot-identity directory, so an agent's requests carry an HTTP Message Signature the origin can verify.
Lets a site tell a real agent from something wearing its user agent string.
Reported by the scanner but never scored, so it is excluded from every tally on this page.
API, auth and agent interfaces
9 scoredCan an agent call the site rather than only read it, and authenticate when it has to?
- API catalogRFC 9727 · RFC 9264
/.well-known/api-catalog served as application/linkset+json, each entry naming an anchor with its service-desc and service-doc.
A single document listing every API the site offers.
1 of 17 scanned organizations pass this check.
- OAuth discoveryRFC 8414 · OIDC Discovery
/.well-known/oauth-authorization-server declaring issuer, authorization and token endpoints, jwks_uri, and the supported grant and response types.
Tells an agent where and how to authenticate.
2 of 17 scanned organizations pass this check.
- Protected resource metadataRFC 9728 §3.1
An /.well-known/oauth-protected-resource document whose resource, authorization_servers and bearer_methods_supported match the resource it actually guards.
Says which authorization server guards a given resource.
1 of 17 scanned organizations pass this check.
- auth.mdworkos.com/auth.md
/auth.md in Markdown, with an H1 naming auth.md, describing how an agent registers and obtains credentials.
Plain-language instructions for an agent on obtaining credentials.
1 of 17 scanned organizations pass this check.
- MCP server cardSEP-2127 (draft)
/.well-known/mcp/server-card.json carrying serverInfo, a transport endpoint and the declared capabilities.
Declares an MCP server that agents can actually call.
2 of 17 scanned organizations pass this check.
- A2A agent cardA2A protocol 0.3.0
/.well-known/agent-card.json with protocolVersion, url, preferredTransport, capabilities and skills[], pointing at a JSON-RPC endpoint that answers.
Declares an agent that other agents can talk to.
2 of 17 scanned organizations pass this check.
- Agent Skills indexAgent Skills Discovery v0.2.0
/.well-known/agent-skills/index.json listing real SKILL.md artifacts, each with a sha256 digest matching the bytes served.
Publishes executable skills an agent can load and run.
3 of 17 scanned organizations pass this check.
- WebMCPW3C CG draft
Tools registered on navigator.modelContext in the page itself, advertised in /.well-known/webmcp.json.
Exposes in-page tools to agents through navigator.modelContext.
2 of 17 scanned organizations pass this check.
- ARD / ai-catalogARD v0.9 · ai-catalog
/.well-known/ai-catalog.json served as application/json with Access-Control-Allow-Origin: *, listing entries under urn:air: identifiers with representative queries.
A capability manifest listing the servers, agents and tools on offer.
1 of 17 scanned organizations pass this check.
Agentic commerce
5 scoredCan an agent transact and pay without a person completing the checkout?
These apply to sites that sell through agents. On a documentation or marketing domain their absence is expected rather than a deficiency. Read the five together, not as five separate failures.
- ACPAgentic Commerce Protocol
An ACP surface (/.well-known/acp.json and its checkout endpoints) that an agent can drive end to end.
Agentic Commerce Protocol. Lets an agent complete a purchase through the merchant's existing checkout.
0 of 17 scanned organizations pass this check.
- UCPUniversal Commerce Protocol
/.well-known/ucp publishing catalog and checkout in the shape UCP defines.
Universal Commerce Protocol. Publishes catalog and checkout in a form agents can transact against.
0 of 17 scanned organizations pass this check.
- AP2Agent Payments Protocol
AP2 mandate support, carried on the A2A agent card, so a purchase arrives with cryptographic proof the buyer authorized it.
Agent Payments Protocol. Carries a verifiable mandate proving the buyer authorized the purchase.
0 of 17 scanned organizations pass this check.
- x402x402
An HTTP 402 response that prices a resource, so an agent can pay for a single request without holding an account.
Prices a resource over HTTP 402 so an agent can pay per request.
0 of 17 scanned organizations pass this check.
- MPPMachine Payments Protocol
MPP payment metadata in the OpenAPI document: an x-payment-info block describing how an agent settles.
Machine Payments Protocol. Lets agents settle payments programmatically.
0 of 17 scanned organizations pass this check.
One point per passing check, 21 available. A check the scanner could not run is recorded as not evaluated and left out of the score rather than counted against the site, and a site that refuses the scanner outright is reported as blocked, never as a zero. We publish the check tally, never the scanner's level: Level 5 “Agent-Native” is returned with real gaps still open.
Scores come from the agent-readiness scanner Cloudflare publishes at isitagentready.com, using its public scan API. Anyone can re-run any row of the table above and check it, and we do not score ourselves: the same third-party tool scores every row, including our own. Seeing an error? Request a correction.
Adoption by check
How many of the 17 scanned organizations pass each check. Adoption concentrates in the long-established ones: robots.txt and sitemaps are near-universal, and 14 of 17 publish named AI-crawler rules. The newer discovery standards (MCP server cards, agent skills indexes, ai-catalog manifests) remain in low single digits.
- robots.txt16 / 17
- Sitemap15 / 17
- Named AI bot rules14 / 17
- Link headers (RFC 8288)3 / 17
- Markdown negotiation3 / 17
- Content-Signal3 / 17
- Agent Skills index3 / 17
- OAuth discovery (RFC 8414)2 / 17
- MCP server card (SEP-2127)2 / 17
- A2A agent card2 / 17
- WebMCP2 / 17
- DNS-AID + DNSSEC1 / 17
- API catalog (RFC 9727)1 / 17
- Protected resource metadata (RFC 9728)1 / 17
- auth.md1 / 17
- ARD / ai-catalog1 / 17
- ACP0 / 17
- UCP0 / 17
- AP20 / 17
- x4020 / 17
- MPP0 / 17
Where this is heading
What is agent readiness?
Agent readiness is how easily an AI agent can discover, understand and use a website without a person involved. It is measured as a set of published files, HTTP response headers and DNS records: a machine-readable API catalog, an MCP server card, clean Markdown, signed agent endpoints. Together these let software find what a site offers and act on it. A site can rank well in search and still be unreadable to an agent.
Why does agent readiness matter?
Agent readiness matters because the exchange that funded the web is changing. For most of the web's history a crawler indexed your pages, a search engine sent you a visitor, and the visit was what you monetized. An AI assistant reads the page, answers the question, and the visit may never happen. The content still creates value, but the site does not necessarily capture it. Readiness determines whether a site can still be found, used and paid when the visitor is software rather than a person.
What does agent readiness let a website do?
Agent readiness lets a website do three things it otherwise cannot:
- Be found without a search engine
- Discovery files, DNS records and catalogs let an agent locate what a site offers directly, instead of inferring it from rendered HTML.
- Be used, not only read
- An MCP server card or an A2A agent card turns a site from a document into something another piece of software can call and act on.
- Be paid, not only crawled
- Metered access over HTTP 402 makes it possible to charge for a resource an agent consumes, rather than serving it free by default.
Can a website charge AI agents for access?
Yes. A website can now charge AI agents per request, and the infrastructure shipped in 2026. Cloudflare's monetization gateway lets any asset behind its network carry a price, settled in stablecoins over x402, enforced at the edge and requiring no prior account from the buyer. The x402 protocol moved to a vendor-neutral foundation under the Linux Foundation in July 2026. AWS ships agent payments with per-session spending limits in Bedrock AgentCore, and Coinbase Business accepts agent-initiated payments at existing merchant checkouts.
None of this depends on predicting how quickly agents arrive. Each check is independently useful today and most take hours rather than weeks. This index only records who has done them.
Don't see your company?
Request a scan and we'll add you to the index. Listing is free and never paid for. We scan companies whether they ask or not, which is what makes the index worth reading.
Fixed something? Get re-scanned.
Shipped changes since your last result? We'll re-scan and update your row, and send you the before-and-after.
Agent-Native Certification
A verifiable attestation of which checks a site passes, re-verified monthly and expiring if it lapses. Published criteria, automated verification, no opinion about the business. It is a measurement, not an endorsement.
