agenticplug.ai - Agentic Commerce Optimization company

Agent Ready Report / Documentation

Agent Ready Report documentation

The technical reference for the Agent Ready Report MCP connector: how to connect, what its two tools take and return, how the 35 checks are scored, the limits, and exactly what the scanner sends to a website. For what the report is and how to add it to an assistant, see the product page.

Last updated:

1. Connect

SettingValue
Endpointhttps://scan.agenticplug.ai/mcp
TransportMCP over Streamable HTTP, stateless: no session to open or keep. Send JSON-RPC requests with POST, accepting both application/json and text/event-stream, as the MCP specification requires.
AuthenticationNone. No account, sign-in or API key. Both tools are read-only.
Serveragent-ready-report (title “Agent Ready Report by agenticplug.ai”)
HealthGET https://scan.agenticplug.ai/health returns the server and methodology versions.

Setup steps for Claude, ChatGPT and other clients are on the product page. From a terminal, with Claude Code:

claude mcp add --transport http agent-ready-report https://scan.agenticplug.ai/mcp

2. Tools

scan_website · Scan a website for agent readiness

Scans a public website and reports every check: which pass, which are missing, and what each one is, in plain English and technically. The site root is always scanned, whatever page is given.

ParameterTypeRequiredDescription
urlstring (3 to 2,048 characters)YesThe website, e.g. "example.com" or "https://www.example.com". Any path, query or fragment is ignored.
sells_online"auto" | "yes" | "no"No (default "auto")"auto" detects online selling from the homepage. Use "yes" or "no" when the owner has said; it decides whether agentic commerce is scored.
detail"standard" | "full"No (default "standard")"standard" gives each finding with its plain-English and technical explanation. "full" adds pass criteria, request-by-request evidence and source links.

Returns: A Markdown report in the text content, and the same report as structuredContent (fields below). Invalid input, refused addresses and rate limits come back as a tool error (isError: true) with a plain-English message.

explain_check · Explain an agent-readiness check

Explains one check in depth: what it is, why it matters for AI agents and AI search, how the scanner tests it, what counts as a pass, and the official sources.

ParameterTypeRequiredDescription
check_idstring (a check id, below)NoThe check to explain. Omit it to list every check, grouped.

Returns: Markdown text, plus structuredContent: the check's full explanation, or the grouped list of all checks.

Both tools are annotated read-only, non-destructive and idempotent. scan_website is also marked open-world, because it reads a third-party website.

3. The report

scan_website returns the report twice: as Markdown in the text content, for the assistant to read and quote, and as structuredContent for software. An excerpt of the Markdown for example.com:

# Agent Ready Report: https://example.com
Scanned 2026-09-30 05:10:29 UTC · doesn't appear to sell online

## Summary
- **Agent readiness:** 0 of 16 passing
- **AI search foundations:** 4 of 11 passing
- **Agentic commerce:** not scored, because the site doesn't appear to sell online. …

## Agent readiness: 0 of 16 passing
…
### ❌ robots.txt: Missing or not working
**Finding:** No robots.txt found (HTTP 404).
**What it is:** A small text file at the root of your website that tells automated visitors …
**Why it matters:** It's the first file every crawler reads. …
**Technical:** GET /robots.txt and parse it per RFC 9309.
…
---
Agent Ready Report by agenticplug.ai · https://agenticplug.ai/agent-ready-report
This is an automated, point-in-time diagnostic of publicly available signals. …

The same scan as structured data (trimmed):

{
  "requestedUrl": "https://example.com/",
  "scannedOrigin": "https://example.com",
  "reachable": true,
  "platform": null,
  "commerce": { "detected": false, "signals": [] },
  "botProtection": { "detected": false },
  "tallies": {
    "agentReadiness": { "passed": 0, "scored": 16, "couldntCheck": 0 },
    "commerce": { "passed": 0, "scored": 0, "couldntCheck": 0 },
    "foundations": { "passed": 4, "scored": 11, "couldntCheck": 0 }
  },
  "checks": [
    {
      "id": "robotsTxt",
      "group": "agentReadiness",
      "status": "fail",
      "statusLabel": "Missing or not working",
      "summary": "No robots.txt found (HTTP 404).",
      "explanation": { "title": "robots.txt", "plainEnglish": "…", "whyItMatters": "…", "technical": { … } }
    }
  ],
  "methodologyVersion": "1.4.0"
}
FieldContents
requestedUrlThe address that was scanned: the site root of the input.
scannedOriginThe origin the homepage ended on, after redirects.
scannedAt, durationMsWhen the scan ran (ISO 8601) and how long it took.
reachable, unreachableReasonWhether the site let the scanner in; if not, why. Most checks are then "couldn't check".
platformThe website platform, when recognized (for example Shopify or WordPress), with the signals seen.
commerceWhether the site appears to sell online, and the signals behind that decision.
botProtectionWhether bot protection challenged the scanner, and whose.
talliesPer group: passed, scored (passes plus fails) and couldntCheck.
checks[]Per check: id, group, status, statusLabel, summary (the finding), optional caveat and details, evidence (full detail only) and explanation.
groupsEach group's title, description and tally.
methodologyVersionThe version of the check logic and copy that produced the report.
attribution, disclaimerThe attribution line and the diagnostic disclaimer, which should be kept when the report is shown.

4. How results are scored

Every check gets one status:

StatusShown asMeaning
passPassThe site meets the check's pass criteria.
failMissing or not workingThe site answered, and what the check looks for is missing or invalid.
couldnt_checkCouldn't checkNo usable answer: the site blocked, challenged or timed out the scanner, or returned a server error. Never counted as a fail.
not_applicableNot scoredAgentic commerce on a site that doesn't sell online.
informationalFor informationReported, never scored.
  • Each group is reported as a tally, such as “4 of 11 passing”: passes out of passes plus fails. “Couldn’t check”, not-scored and informational results are left out of both numbers. There is no overall grade or level.
  • Agent-readiness checks are scored for every business, including emerging standards, which are labeled “emerging standard” because missing them is still common.
  • Agentic commerce is scored only for sites that sell online. That is detected from storefront markup on the homepage, or from a site already passing a commerce protocol check, and sells_online overrides the detection either way.
  • The report is a diagnostic: it explains each finding and never prescribes fixes. The methodologyVersion changes whenever the check logic or wording does.

5. The 35 checks

The id is what reports use and what explain_check accepts. Ask explain_check for any id to get its full explanation, pass criteria and sources.

Agent readiness (16 scored, 1 informational)

Whether AI agents can find, read and work with the website. Scored for every business, because this is where AI search is heading.

IdCheckWhat it looks at
robotsTxtrobots.txtThe file that tells crawlers, including AI crawlers, which parts of the site they may visit.
sitemapXML sitemapA machine-readable list of the site's pages.
linkHeadersLink headers for agentsSignposts on the homepage pointing machines to the site's APIs and documentation.
dnsAidDNS-AIDemerging standardDNS records that announce the business's agent services, signed with DNSSEC.
markdownNegotiationMarkdown for agentsA clean text version of pages for AI tools that ask for one.
robotsTxtAiRulesAI crawler rulesrobots.txt rules that apply to AI crawlers such as GPTBot or ClaudeBot, by name or through rules for all crawlers.
contentSignalsContent Signalsemerging standardA robots.txt declaration of whether AI may use the content for search, answers or training.
apiCatalogAPI catalogOne standard file listing the ways software can connect to the business.
oauthDiscoveryOAuth discoveryWhere and how software signs in to the site's services.
oauthProtectedResourceOAuth protected resource metadataWhich sign-in service protects the site's tools and data.
authMdauth.mdemerging standardA guide for AI agents on registering with the service.
mcpServerCardMCP server cardemerging standardA description of the business's MCP server, so AI assistants can find its tools.
a2aAgentCardA2A agent cardA profile of the business's own AI agent, for agent-to-agent conversations.
agentSkillsAgent skills indexemerging standardStep-by-step skills the business publishes to teach agents its service.
webMcpWebMCPemerging standardActions a page offers to AI assistants built into the browser, checked in a real browser.
ardARD capability manifestemerging standardOne catalogue of everything the business offers to AI agents.
webBotAuthWeb Bot Authemerging standardinformational, not scoredSigning keys for the business's own bots. Only relevant if it runs bots.

AI search foundations (11 scored, 2 informational)

The technical basics that decide whether AI search engines can read, understand and cite the website today.

IdCheckWhat it looks at
httpsHTTPSA secure connection, with plain HTTP redirected to it.
aiCrawlerAccessAI search crawler accessWhether ChatGPT, Claude and Perplexity's search crawlers can actually reach the site.
indexableIndexable homepageNo 'noindex' instruction keeping the page out of search indexes.
contentWithoutJsContent readable without JavaScriptWhether the text is in the page itself, for crawlers that don't run code.
headingStructureHeading structure (H1–H6)A clear outline: a main heading, section headings and no skipped levels.
titleAndDescriptionPage title and descriptionThe headline and summary machines read first.
canonicalCanonical URLThe page's single official address.
structuredDataStructured dataMachine-readable facts about the business and its content.
entitySchemaBusiness identity markupWho the business is, linked to its official profiles elsewhere.
languagePage languageThe language the page declares it's written in.
responseTimeResponse timeHow quickly the site starts responding.
pageTypeSchemaContent-type markupinformational, not scoredFAQ, product, service or event markup, where it fits.
llmsTxtllms.txtinformational, not scoredA proposed AI summary file. No major AI platform has said it reads one.

Agentic commerce (5 scored)

Whether AI shopping agents can buy from the business. Scored only for sites that sell online.

IdCheckWhat it looks at
x402x402emerging standardInstant payments by AI agents inside the web request, typically in stablecoins.
mppMPP (Machine Payments Protocol)emerging standardMachine-to-machine payments by Stripe and Tempo, as one-time charges or pay-as-you-go sessions.
ucpUCP (Universal Commerce Protocol)A store profile that lets shopping agents search, build a cart and check out.
acpACP (Agentic Commerce Protocol)emerging standardOpenAI and Stripe's standard for agents buying on a customer's behalf.
ap2AP2 (Agent Payments Protocol)emerging standardA protocol, started by Google and now run by the FIDO Alliance, giving businesses proof of what a customer authorized an agent to buy.

6. Limits and errors

LimitValue
Scans of the same domainAt most 4 a minute (www. and the bare domain count as one).
Scans from one clientAt most 60 a minute.
Repeat requestsThe same domain and sells_online value within 10 minutes is answered from a cache and does not count toward the limits.
Scan timeUsually 5 to 30 seconds; a scan stops at 45 seconds and reports anything unfinished as "couldn't check".
AddressesPublic http and https websites on ports 80 and 443, by domain name. IP addresses, credentials in the URL, private and internal hosts are refused.

Problems come back as a tool result with isError: true and a message written for the person asking, never as a protocol error. For example: an address that isn’t a public website, a domain that doesn’t exist, an email address given instead of a website, a site redirecting to a private address, or a rate limit (“please try again in a minute”). A site that blocks or times out the scanner is not an error: the scan completes and those checks read “Couldn’t check”.

7. What the scanner sends

For each scan, the website being scanned receives:

  • About two to three dozen requests for public pages and files (the homepage, robots.txt, sitemaps and standard discovery files), identified by the user agent agenticplug-agent-ready-report/1.0 and signed with Web Bot Auth (HTTP Message Signatures), so a website can verify they come from agenticplug.ai. The public key is at https://scan.agenticplug.ai/.well-known/http-message-signatures-directory.
  • Four homepage requests using the published user agents of OAI-SearchBot, ChatGPT-User, PerplexityBot and Perplexity-User, to test how the site treats AI crawlers. These are not signed, since they use those crawlers' names, not ours.
  • One homepage load in a headless browser run by Cloudflare, to detect WebMCP tools. Cloudflare marks those requests as coming from its browser service.
  • Public DNS lookups over DNS-over-HTTPS (Cloudflare, with Google Public DNS as a fallback).
  • Never a sign-in, a form submission or a purchase. At most five requests are in flight at once, and fewer once bot protection shows up.

8. Privacy, terms and support

The connector keeps no IP addresses, request headers or identifiers that AI assistants send. Reports are cached for 10 minutes, and anonymous usage statistics (the site scanned, which assistant asked, and the results) are kept for three months. The details are in the privacy policy and the conditions of use in the terms of service. Please keep each report’s attribution line and disclaimer when you show it.

Questions, bugs or a site that you think is scored wrongly: info@agenticplug.ai.