Agent Ready Report / Documentation
Agent Ready Report documentation
The technical reference for the Agent Ready Report MCP connector: how to connect, what its two tools take and return, how the 35 checks are scored, the limits, and exactly what the scanner sends to a website. For what the report is and how to add it to an assistant, see the product page.
Last updated:
1. Connect
| Setting | Value |
|---|---|
| Endpoint | https://scan.agenticplug.ai/mcp |
| Transport | MCP over Streamable HTTP, stateless: no session to open or keep. Send JSON-RPC requests with POST, accepting both application/json and text/event-stream, as the MCP specification requires. |
| Authentication | None. No account, sign-in or API key. Both tools are read-only. |
| Server | agent-ready-report (title “Agent Ready Report by agenticplug.ai”) |
| Health | GET https://scan.agenticplug.ai/health returns the server and methodology versions. |
Setup steps for Claude, ChatGPT and other clients are on the product page. From a terminal, with Claude Code:
claude mcp add --transport http agent-ready-report https://scan.agenticplug.ai/mcp2. Tools
scan_website · Scan a website for agent readiness
Scans a public website and reports every check: which pass, which are missing, and what each one is, in plain English and technically. The site root is always scanned, whatever page is given.
| Parameter | Type | Required | Description |
|---|---|---|---|
url | string (3 to 2,048 characters) | Yes | The website, e.g. "example.com" or "https://www.example.com". Any path, query or fragment is ignored. |
sells_online | "auto" | "yes" | "no" | No (default "auto") | "auto" detects online selling from the homepage. Use "yes" or "no" when the owner has said; it decides whether agentic commerce is scored. |
detail | "standard" | "full" | No (default "standard") | "standard" gives each finding with its plain-English and technical explanation. "full" adds pass criteria, request-by-request evidence and source links. |
Returns: A Markdown report in the text content, and the same report as structuredContent (fields below). Invalid input, refused addresses and rate limits come back as a tool error (isError: true) with a plain-English message.
explain_check · Explain an agent-readiness check
Explains one check in depth: what it is, why it matters for AI agents and AI search, how the scanner tests it, what counts as a pass, and the official sources.
| Parameter | Type | Required | Description |
|---|---|---|---|
check_id | string (a check id, below) | No | The check to explain. Omit it to list every check, grouped. |
Returns: Markdown text, plus structuredContent: the check's full explanation, or the grouped list of all checks.
Both tools are annotated read-only, non-destructive and idempotent. scan_website is also marked open-world, because it reads a third-party website.
3. The report
scan_website returns the report twice: as Markdown in the text content, for the assistant to read and quote, and as structuredContent for software. An excerpt of the Markdown for example.com:
# Agent Ready Report: https://example.com
Scanned 2026-09-30 05:10:29 UTC · doesn't appear to sell online
## Summary
- **Agent readiness:** 0 of 16 passing
- **AI search foundations:** 4 of 11 passing
- **Agentic commerce:** not scored, because the site doesn't appear to sell online. …
## Agent readiness: 0 of 16 passing
…
### ❌ robots.txt: Missing or not working
**Finding:** No robots.txt found (HTTP 404).
**What it is:** A small text file at the root of your website that tells automated visitors …
**Why it matters:** It's the first file every crawler reads. …
**Technical:** GET /robots.txt and parse it per RFC 9309.
…
---
Agent Ready Report by agenticplug.ai · https://agenticplug.ai/agent-ready-report
This is an automated, point-in-time diagnostic of publicly available signals. …The same scan as structured data (trimmed):
{
"requestedUrl": "https://example.com/",
"scannedOrigin": "https://example.com",
"reachable": true,
"platform": null,
"commerce": { "detected": false, "signals": [] },
"botProtection": { "detected": false },
"tallies": {
"agentReadiness": { "passed": 0, "scored": 16, "couldntCheck": 0 },
"commerce": { "passed": 0, "scored": 0, "couldntCheck": 0 },
"foundations": { "passed": 4, "scored": 11, "couldntCheck": 0 }
},
"checks": [
{
"id": "robotsTxt",
"group": "agentReadiness",
"status": "fail",
"statusLabel": "Missing or not working",
"summary": "No robots.txt found (HTTP 404).",
"explanation": { "title": "robots.txt", "plainEnglish": "…", "whyItMatters": "…", "technical": { … } }
}
],
"methodologyVersion": "1.4.0"
}| Field | Contents |
|---|---|
requestedUrl | The address that was scanned: the site root of the input. |
scannedOrigin | The origin the homepage ended on, after redirects. |
scannedAt, durationMs | When the scan ran (ISO 8601) and how long it took. |
reachable, unreachableReason | Whether the site let the scanner in; if not, why. Most checks are then "couldn't check". |
platform | The website platform, when recognized (for example Shopify or WordPress), with the signals seen. |
commerce | Whether the site appears to sell online, and the signals behind that decision. |
botProtection | Whether bot protection challenged the scanner, and whose. |
tallies | Per group: passed, scored (passes plus fails) and couldntCheck. |
checks[] | Per check: id, group, status, statusLabel, summary (the finding), optional caveat and details, evidence (full detail only) and explanation. |
groups | Each group's title, description and tally. |
methodologyVersion | The version of the check logic and copy that produced the report. |
attribution, disclaimer | The attribution line and the diagnostic disclaimer, which should be kept when the report is shown. |
4. How results are scored
Every check gets one status:
| Status | Shown as | Meaning |
|---|---|---|
pass | Pass | The site meets the check's pass criteria. |
fail | Missing or not working | The site answered, and what the check looks for is missing or invalid. |
couldnt_check | Couldn't check | No usable answer: the site blocked, challenged or timed out the scanner, or returned a server error. Never counted as a fail. |
not_applicable | Not scored | Agentic commerce on a site that doesn't sell online. |
informational | For information | Reported, never scored. |
- Each group is reported as a tally, such as “4 of 11 passing”: passes out of passes plus fails. “Couldn’t check”, not-scored and informational results are left out of both numbers. There is no overall grade or level.
- Agent-readiness checks are scored for every business, including emerging standards, which are labeled “emerging standard” because missing them is still common.
- Agentic commerce is scored only for sites that sell online. That is detected from storefront markup on the homepage, or from a site already passing a commerce protocol check, and
sells_onlineoverrides the detection either way. - The report is a diagnostic: it explains each finding and never prescribes fixes. The
methodologyVersionchanges whenever the check logic or wording does.
5. The 35 checks
The id is what reports use and what explain_check accepts. Ask explain_check for any id to get its full explanation, pass criteria and sources.
Agent readiness (16 scored, 1 informational)
Whether AI agents can find, read and work with the website. Scored for every business, because this is where AI search is heading.
| Id | Check | What it looks at |
|---|---|---|
robotsTxt | robots.txt | The file that tells crawlers, including AI crawlers, which parts of the site they may visit. |
sitemap | XML sitemap | A machine-readable list of the site's pages. |
linkHeaders | Link headers for agents | Signposts on the homepage pointing machines to the site's APIs and documentation. |
dnsAid | DNS-AIDemerging standard | DNS records that announce the business's agent services, signed with DNSSEC. |
markdownNegotiation | Markdown for agents | A clean text version of pages for AI tools that ask for one. |
robotsTxtAiRules | AI crawler rules | robots.txt rules that apply to AI crawlers such as GPTBot or ClaudeBot, by name or through rules for all crawlers. |
contentSignals | Content Signalsemerging standard | A robots.txt declaration of whether AI may use the content for search, answers or training. |
apiCatalog | API catalog | One standard file listing the ways software can connect to the business. |
oauthDiscovery | OAuth discovery | Where and how software signs in to the site's services. |
oauthProtectedResource | OAuth protected resource metadata | Which sign-in service protects the site's tools and data. |
authMd | auth.mdemerging standard | A guide for AI agents on registering with the service. |
mcpServerCard | MCP server cardemerging standard | A description of the business's MCP server, so AI assistants can find its tools. |
a2aAgentCard | A2A agent card | A profile of the business's own AI agent, for agent-to-agent conversations. |
agentSkills | Agent skills indexemerging standard | Step-by-step skills the business publishes to teach agents its service. |
webMcp | WebMCPemerging standard | Actions a page offers to AI assistants built into the browser, checked in a real browser. |
ard | ARD capability manifestemerging standard | One catalogue of everything the business offers to AI agents. |
webBotAuth | Web Bot Authemerging standardinformational, not scored | Signing keys for the business's own bots. Only relevant if it runs bots. |
AI search foundations (11 scored, 2 informational)
The technical basics that decide whether AI search engines can read, understand and cite the website today.
| Id | Check | What it looks at |
|---|---|---|
https | HTTPS | A secure connection, with plain HTTP redirected to it. |
aiCrawlerAccess | AI search crawler access | Whether ChatGPT, Claude and Perplexity's search crawlers can actually reach the site. |
indexable | Indexable homepage | No 'noindex' instruction keeping the page out of search indexes. |
contentWithoutJs | Content readable without JavaScript | Whether the text is in the page itself, for crawlers that don't run code. |
headingStructure | Heading structure (H1–H6) | A clear outline: a main heading, section headings and no skipped levels. |
titleAndDescription | Page title and description | The headline and summary machines read first. |
canonical | Canonical URL | The page's single official address. |
structuredData | Structured data | Machine-readable facts about the business and its content. |
entitySchema | Business identity markup | Who the business is, linked to its official profiles elsewhere. |
language | Page language | The language the page declares it's written in. |
responseTime | Response time | How quickly the site starts responding. |
pageTypeSchema | Content-type markupinformational, not scored | FAQ, product, service or event markup, where it fits. |
llmsTxt | llms.txtinformational, not scored | A proposed AI summary file. No major AI platform has said it reads one. |
Agentic commerce (5 scored)
Whether AI shopping agents can buy from the business. Scored only for sites that sell online.
| Id | Check | What it looks at |
|---|---|---|
x402 | x402emerging standard | Instant payments by AI agents inside the web request, typically in stablecoins. |
mpp | MPP (Machine Payments Protocol)emerging standard | Machine-to-machine payments by Stripe and Tempo, as one-time charges or pay-as-you-go sessions. |
ucp | UCP (Universal Commerce Protocol) | A store profile that lets shopping agents search, build a cart and check out. |
acp | ACP (Agentic Commerce Protocol)emerging standard | OpenAI and Stripe's standard for agents buying on a customer's behalf. |
ap2 | AP2 (Agent Payments Protocol)emerging standard | A protocol, started by Google and now run by the FIDO Alliance, giving businesses proof of what a customer authorized an agent to buy. |
6. Limits and errors
| Limit | Value |
|---|---|
| Scans of the same domain | At most 4 a minute (www. and the bare domain count as one). |
| Scans from one client | At most 60 a minute. |
| Repeat requests | The same domain and sells_online value within 10 minutes is answered from a cache and does not count toward the limits. |
| Scan time | Usually 5 to 30 seconds; a scan stops at 45 seconds and reports anything unfinished as "couldn't check". |
| Addresses | Public http and https websites on ports 80 and 443, by domain name. IP addresses, credentials in the URL, private and internal hosts are refused. |
Problems come back as a tool result with isError: true and a message written for the person asking, never as a protocol error. For example: an address that isn’t a public website, a domain that doesn’t exist, an email address given instead of a website, a site redirecting to a private address, or a rate limit (“please try again in a minute”). A site that blocks or times out the scanner is not an error: the scan completes and those checks read “Couldn’t check”.
7. What the scanner sends
For each scan, the website being scanned receives:
- About two to three dozen requests for public pages and files (the homepage, robots.txt, sitemaps and standard discovery files), identified by the user agent agenticplug-agent-ready-report/1.0 and signed with Web Bot Auth (HTTP Message Signatures), so a website can verify they come from agenticplug.ai. The public key is at https://scan.agenticplug.ai/.well-known/http-message-signatures-directory.
- Four homepage requests using the published user agents of OAI-SearchBot, ChatGPT-User, PerplexityBot and Perplexity-User, to test how the site treats AI crawlers. These are not signed, since they use those crawlers' names, not ours.
- One homepage load in a headless browser run by Cloudflare, to detect WebMCP tools. Cloudflare marks those requests as coming from its browser service.
- Public DNS lookups over DNS-over-HTTPS (Cloudflare, with Google Public DNS as a fallback).
- Never a sign-in, a form submission or a purchase. At most five requests are in flight at once, and fewer once bot protection shows up.
8. Privacy, terms and support
The connector keeps no IP addresses, request headers or identifiers that AI assistants send. Reports are cached for 10 minutes, and anonymous usage statistics (the site scanned, which assistant asked, and the results) are kept for three months. The details are in the privacy policy and the conditions of use in the terms of service. Please keep each report’s attribution line and disclaimer when you show it.
Questions, bugs or a site that you think is scored wrongly: info@agenticplug.ai.
