Agent Readiness Rules

What We Check

147 rules across 25 categories. Each rule ensures your site is discoverable, understandable, and usable by AI agents.

Quick fix Moderate Complex CRITICAL MEDIUM LOW Severity
Gap types: Documentation Semantic Capability Evidence

Learn about agent readiness

New to agent readiness? Start with these guides:

Discovery

Can an agent find you?

Weight: 20
πŸ”
Discovery
Can AI agents find your site and understand what it offers?
15 rules
πŸ”
Robots.txt File
Your site has a robots.txt file that tells crawlers and AI agents what they can access.
low Quick fix Documentation
πŸ—ΊοΈ
Sitemap File
Your site has a sitemap listing all important pages for agents to discover.
low Quick fix Documentation
🧭
Agent Guide
Your site has a dedicated guide that tells AI agents what you offer and how to interact.
high Moderate Documentation
πŸ“„
LLMs.txt File
Your site has an llms.txt file that provides a plain-text overview for large language models.
medium Quick fix Documentation
πŸ”—
Link Relationships
Your homepage includes link headers that connect related resources together.
medium Moderate Documentation
πŸ“š
API Catalog
Your site publishes a catalog of all available APIs in a standard location.
medium Moderate Documentation
🏷️
Content Signals
Your robots.txt declares preferences about how AI can use your content.
low Quick fix Documentation
🌐
DNS Agent Discovery
Your domain has DNS records that help agents discover your services automatically.
low Moderate Documentation
map
Blog articles in AI sitemap
AI sitemap includes blog/article URLs, not just static pages.
medium Moderate Documentation
clock
Crawl-delay directive in robots.txt
robots.txt includes a Crawl-delay directive to control crawl rate.
low Quick fix Documentation
policy
LLM policy file
LLM usage policy published at /.well-known/llm-policy.json.
low Moderate Documentation
coverage
AI sitemap content type coverage
AI sitemap covers at least 50% of the URLs in the regular sitemap.
medium Moderate Documentation
🧭
Capability list declared
A capabilities list is present in agent-guide.
medium Quick fix Documentation
πŸ€–
AI-Agent Discovery meta tags
Your HTML head declares ai-agent-discovery and ai-agent-onboarding meta tags pointing to machine-readable entry points.
high Quick fix Documentation
πŸ“‘
Agent feeds (JSON Feed 1.1 / RSS 2.0)
Your site serves structured JSON Feed 1.1 or RSS 2.0 feeds at common paths like /agents.json, /jobs.rss, or /feed.json.
low Moderate Documentation
πŸ€–
Machine-Readable
Is your site's data structured for AI consumption?
9 rules
πŸ“‹
OpenAPI
Is your API specification complete and reachable?
9 rules
🎯
Skills
Can agents discover and use your specialized skills?
3 rules
πŸ“œ
Agents.txt
Do you have instructions specifically for AI agents?
1 rule
🌐
WebMCP
Can browsers interact with your agent via MCP?
7 rules
πŸ”„
Content Negotiation
Does your site serve the right format to AI agents?
7 rules
πŸ”Ž
SEO / AEO
Is your content optimized for search engines and AI answer engines?
12 rules
πŸ”Ž
Blog Article OpenGraph Type
Blog and article pages declare og:type=article in their OpenGraph meta tags.
medium Quick fix Documentation
πŸ”Ž
Article Author and Date Meta Tags
Article pages include article:author, article:published_time, and article:modified_time meta tags.
medium Quick fix Documentation
πŸ”Ž
AEO Short-Answer Summary Block
Article pages include a short-answer summary block (2-3 sentences) at the top for AI answer engines.
low Moderate Documentation
πŸ”Ž
Semantic Definition Lists in Guides
Guide pages use <dl> definition lists for term/definition pairs instead of plain paragraphs.
low Moderate Documentation
πŸ”Ž
OG Image Alt Text Brand Consistency
og:image:alt text is present and includes the site's brand name for consistent social sharing.
low Quick fix Documentation
πŸ“
Service page content depth
Service pages have at least 300 words of meaningful content.
low Moderate Documentation
πŸ“
Breadcrumb navigation on service pages
Service pages have breadcrumb navigation (JSON-LD BreadcrumbList or HTML .breadcrumb class).
low Quick fix Documentation
❓
Answer-first extractability
Question-shaped headings are followed by self-contained answer blocks AI systems can quote.
low Moderate Documentation
πŸ“Š
Evidence density for citability
Pages contain citable evidence: sourced numbers, dated claims, fact tables, attributed quotations.
low Moderate Documentation
🏷️
Entity clarity and canonical naming
The page states what the entity is in one canonical line, names it consistently, and links About/schema signals.
low Quick fix Documentation
πŸ–₯️
Server-rendered primary content
Primary content is present in the initial HTML without executing JavaScript.
low Documentation
🚫
Anti-citation disqualifiers
Content is free of overlays covering it, funnel-grade CTA density, and missing author/date on articles.
medium Moderate Documentation

Understandability

Can an agent understand you?

Weight: 25
πŸ“–
Documentation
Is your API documented in formats that AI agents can read?
16 rules
πŸ“‹
API Specification
Your site has a machine-readable API specification that agents can parse.
high Complex Documentation
πŸ§ͺ
Agent Guide Schema Validation
Your agent guide follows the expected format with all required fields.
high Moderate Documentation
πŸ”Œ
MCP Server Descriptor
Your site advertises its MCP server so agents can discover and connect to it.
medium Moderate Documentation
πŸ“‘
Detailed LLMs File
Your site has an extended llms-full.txt with comprehensive information for AI models.
medium Moderate Documentation
πŸ“Œ
LLMs File Linked from HTML
Your homepage links to your llms.txt file so AI models can find it.
low Quick fix Documentation
πŸ“‘
RSS or Atom Feed
Your site has an RSS or Atom feed for agents to subscribe to updates.
low Moderate Documentation
πŸ–ΌοΈ
Social Preview Image
Your site has a social preview image that appears when shared on social media or in AI responses.
low Quick fix Documentation
⭐
SVG Favicon
Your site has a scalable SVG favicon that looks crisp at any size.
low Quick fix Documentation
πŸ”—
Canonical URL
Your pages have canonical URLs that tell agents which version is the official one.
low Quick fix Documentation
πŸ“°
RSS Feed Linked from HTML
Your homepage links to your RSS feed so agents can discover it.
low Quick fix Documentation
πŸ“
Agent Registration Instructions
Your site has instructions telling agents how to register and authenticate.
low Moderate Documentation
πŸ“–
Auth.md documents agent auth flow
Your auth.md file documents agent authentication with session-scoped tokens.
low Quick fix Documentation
πŸ“–
Auth.md documents credential vault pattern
Your auth.md mentions credential vault, scoped tokens, or session rotation (optional).
low Quick fix Documentation
πŸ“‹
Parameter semantics
Parameters have descriptions with constraints (min, max, required).
medium Quick fix Documentation
πŸ’‘
Request/response examples
OpenAPI operations include example requests and responses.
medium Quick fix Documentation
πŸ†˜
Support path declared
A support contact or help URL is declared in agent-guide.
low Quick fix Documentation
⚑
Actionability
Can agents actually call your API with the right authentication?
11 rules
πŸ”„
Guide and API Consistency
Your agent guide and your API specification describe the same endpoints.
high Moderate Semantic
πŸ”‘
Authentication Declared
Your site declares its authentication method in a machine-readable way.
medium Moderate Semantic
🧩
Capability Coverage
Your agent guide covers all the capabilities your service offers.
medium Moderate Semantic
🀝
A2A Agent Card Published
Your agent publishes a /.well-known/agent-card.json file so other agents can discover its capabilities via the A2A protocol.
medium Quick fix Semantic
βœ…
A2A Agent Card Verified
Your agent-card.json includes all required fields: name, description, url, and capabilities.
medium Quick fix Semantic
πŸ”Œ
MCP Server Name Present
Your MCP server's initialize response includes serverInfo.name, allowing agents to identify the server.
medium Quick fix Semantic
πŸ”
MCP Auth Discovery Resolves
If your MCP descriptor declares authentication, the auth URL is reachable and returns valid metadata.
medium Moderate Semantic
πŸ“
Operation descriptions
Every OpenAPI operation has a description or summary.
medium Quick fix Semantic
βš–οΈ
Business constraints documented
Business rules (refund windows, cancellation policies) are documented.
low Quick fix Semantic
πŸ’“
Heartbeat.md availability
Your site serves /heartbeat.md with YAML frontmatter, providing a periodic check-in routine for AI agents.
low Quick fix Semantic
➑️
next_call pattern in API responses
Your OpenAPI spec includes a next_call field in response schemas with method, path, and why to guide agents to the next request.
low Moderate Semantic
β™Ώ
Accessibility
Is your site accessible to all users, including those using assistive technology?
2 rules
πŸ’²
Pricing
Is pricing information available in machine-readable formats for automated clients?
1 rule
⏱️
Rate Limits
Are rate limits and over-limit behavior declared machine-readably?
1 rule

Executability

Can an agent act on your API?

Weight: 30
πŸ”
Bot Authentication
Can you prove which AI bot is making the request?
23 rules
πŸ”
MCP Auth Discovery
Your MCP server's authentication info is discoverable by agents.
medium Moderate Capability
✍️
Bot Signatures Directory
Your site has a directory of bot signatures for verifying AI agent identities.
medium Complex Capability
πŸ‘₯
Bot Directory Members
Your bot signatures directory has valid, recognized members.
medium Moderate Capability
πŸ”‘
Bot Public Keys
Public keys for verified bots are reachable and valid.
medium Moderate Capability
πŸ›‘οΈ
Protected Resource Metadata
Your site publishes metadata about what resources are protected and how.
medium Moderate Capability
πŸ“œ
Web Bot Auth Directory
Your site has a directory for web-based bot authentication using HTTP message signatures.
medium Complex Capability
πŸ”
OAuth2 preferred over static API keys
Your API uses OAuth2 security schemes instead of static API keys.
high Moderate Capability
πŸ”
Credentials via headers not query params
API keys and tokens are passed in headers, not query parameters.
high Quick fix Capability
πŸ”
OAuth scopes defined
Your OAuth metadata declares scopes_supported.
medium Quick fix Capability
πŸ”
Token revocation endpoint available
Your OAuth metadata publishes a revocation_endpoint.
medium Moderate Capability
πŸ”
Token introspection supported
Your OAuth metadata publishes an introspection_endpoint (optional).
low Moderate Capability
πŸ”
Private key JWT authentication
Your token endpoint supports private_key_jwt auth method (optional).
low Complex Capability
πŸ”
Token Exchange (RFC 8693) supported
Your OAuth metadata supports token-exchange grant type (optional).
medium Complex Capability
πŸ”
AAuth metadata endpoint available
Your API publishes /.well-known/aauth.json with agent authorization metadata.
medium Moderate Capability
πŸ”
Agent Authorization Grant supported
Your OAuth metadata includes the agent_authorization grant type.
medium Complex Capability
πŸ”
AAuth scope descriptions published
Your aauth.json publishes scope_descriptions (optional).
low Quick fix Capability
πŸ”
DPoP token binding supported
Your OAuth metadata supports DPoP (RFC 9449) for token binding (optional).
medium Complex Capability
πŸ”
mTLS-bound access tokens
Your OAuth metadata supports mTLS certificate-bound tokens (optional).
medium Complex Capability
πŸ”
Short-lived access tokens
Your token endpoint returns expires_in with access tokens.
medium Quick fix Capability
πŸ”
Refresh token rotation supported
Your OAuth metadata includes refresh_token in grant_types_supported (optional).
medium Moderate Capability
πŸ”
Token revocation endpoint reachable
Your credential security analysis confirms revocation endpoint is supported.
medium Moderate Capability
πŸ”
No static API keys in OpenAPI security
Your OpenAPI spec does not use apiKey security schemes.
high Moderate Capability
πŸ”
Authentication clarity
Security schemes are declared in the OpenAPI spec.
critical Moderate Capability
πŸͺͺ
Identity
Can agents verify your on-chain identity?
3 rules
πŸ’°
Payments
Can agents pay for your services programmatically?
11 rules
πŸ’°
Paid Endpoint Response
When an agent tries to access a paid feature, your site responds with a clear payment request.
high Complex Capability
πŸ”“
Payment Challenge Decodable
The payment request your site sends is properly formatted and can be decoded by agents.
high Complex Capability
πŸ“‹
Payment Required Header
Your payment responses include a header that tells agents payment is needed.
high Moderate Capability
πŸ‘€
Payment Recipient
Your payment requests specify who should receive the payment.
high Moderate Capability
πŸ’΅
Payment Amount
Your payment requests specify how much the agent needs to pay.
medium Moderate Capability
πŸ“„
Payment Discovery File
Your site publishes a file that describes all payment options in one place.
medium Moderate Capability
🏦
Payment Facilitator
Your payment requests specify a facilitator that can process the payment.
medium Complex Capability
⚑
Lightning Payment Support
Your site supports Lightning Network payments for instant, low-cost transactions.
high Complex Capability
🎫
Lightning Payment Details
Your Lightning payment responses include all required details for agents to pay.
high Complex Capability
πŸ’³
MPP (Machine Payments Protocol) Support
Checks for /.well-known/mpp.json declaring Machine Payments Protocol support.
medium Quick fix Capability
πŸ’³
SPT (Stripe Payment Terms) Support
Checks for /.well-known/spt.json declaring Stripe Payment Terms support.
low Quick fix Capability
πŸͺ
Bazaar
Is your agent listed in the decentralized marketplace?
3 rules
🚫
Error Semantics
Are 4xx error responses declared with schemas and descriptions in the spec?
1 rule
πŸ”
Retry Semantics
Are idempotency and retry guidance (Retry-After) declared for agents?
1 rule
πŸ§ͺ
Sandbox
Is a test/sandbox environment advertised for agent experimentation?
1 rule
πŸ“Œ
Versioning
Is the API version declared with a deprecation/sunset policy?
1 rule

Verifiability

Can an agent verify what it observed?

Weight: 25

How does AgentBadge compare?

Wondering if you need AgentBadge alongside your existing tools?

Want to check your site against all 147 rules?

Scan Your Site

Explore More

  • FAQ

    Common questions about agent readiness rules

  • Agent Guide

    Step-by-step guide to becoming agent-ready

  • Blog

    Deep dives into agent readiness concepts