Agent Readiness Rules
What We Check
147 rules across 25 categories. Each rule ensures your site is discoverable, understandable, and usable by AI agents.
Quick fix
Moderate
Complex
CRITICAL
MEDIUM
LOW
Severity
Gap types:
Documentation Semantic Capability Evidence
Learn about agent readiness
New to agent readiness? Start with these guides:
Discovery
Can an agent find you?
Weight: 20
π
Discovery
Can AI agents find your site and understand what it offers?
15 rules
Discovery
Can AI agents find your site and understand what it offers?
π
Robots.txt File
Your site has a robots.txt file that tells crawlers and AI agents what they can access.
low
Quick fix
Documentation
πΊοΈ
Sitemap File
Your site has a sitemap listing all important pages for agents to discover.
low
Quick fix
Documentation
π§
Agent Guide
Your site has a dedicated guide that tells AI agents what you offer and how to interact.
high
Moderate
Documentation
π
LLMs.txt File
Your site has an llms.txt file that provides a plain-text overview for large language models.
medium
Quick fix
Documentation
π
Link Relationships
Your homepage includes link headers that connect related resources together.
medium
Moderate
Documentation
π
API Catalog
Your site publishes a catalog of all available APIs in a standard location.
medium
Moderate
Documentation
π·οΈ
Content Signals
Your robots.txt declares preferences about how AI can use your content.
low
Quick fix
Documentation
π
DNS Agent Discovery
Your domain has DNS records that help agents discover your services automatically.
low
Moderate
Documentation
map
Blog articles in AI sitemap
AI sitemap includes blog/article URLs, not just static pages.
medium
Moderate
Documentation
clock
Crawl-delay directive in robots.txt
robots.txt includes a Crawl-delay directive to control crawl rate.
low
Quick fix
Documentation
policy
LLM policy file
LLM usage policy published at /.well-known/llm-policy.json.
low
Moderate
Documentation
coverage
AI sitemap content type coverage
AI sitemap covers at least 50% of the URLs in the regular sitemap.
medium
Moderate
Documentation
π§
Capability list declared
A capabilities list is present in agent-guide.
medium
Quick fix
Documentation
π€
AI-Agent Discovery meta tags
Your HTML head declares ai-agent-discovery and ai-agent-onboarding meta tags pointing to machine-readable entry points.
high
Quick fix
Documentation
π‘
Agent feeds (JSON Feed 1.1 / RSS 2.0)
Your site serves structured JSON Feed 1.1 or RSS 2.0 feeds at common paths like /agents.json, /jobs.rss, or /feed.json.
low
Moderate
Documentation
π€
Machine-Readable
Is your site's data structured for AI consumption?
9 rules
Machine-Readable
Is your site's data structured for AI consumption?
π²
Machine-Readable Pricing
Your pricing information is available in a format agents can parse automatically.
medium
Moderate
Documentation
β±οΈ
Rate Limits Declared
Your site declares its rate limits in a machine-readable format.
low
Moderate
Documentation
β οΈ
Structured Error Responses
Your API returns errors in a consistent, machine-readable format.
low
Moderate
Documentation
π οΈ
MCP Tools List
Your MCP server responds to tool listing requests.
high
Moderate
Documentation
π
MCP Tool Calls
Your MCP server responds when agents try to call a tool.
high
Moderate
Documentation
π‘
MCP Streaming Support
Your MCP server supports streaming connections for real-time communication.
medium
Complex
Documentation
card
Agent Card version 1.0.0+
Agent Card JSON includes a version field >= 1.0.0.
medium
Quick fix
Documentation
π
Skill.json (JSON-LD) availability
Your site serves /skill.json as JSON-LD with @context, @type, name, and url/endpoints for machine-readable agent onboarding.
low
Moderate
Documentation
β
Error catalog endpoint
Your site serves a JSON error catalog at /api/meta/errors or /errors.json with error codes and descriptions.
low
Moderate
Documentation
π
OpenAPI
Is your API specification complete and reachable?
9 rules
OpenAPI
Is your API specification complete and reachable?
π
API Spec at Standard Location
Your API specification is published at the standard location agents expect.
high
Quick fix
Documentation
π€οΈ
API Paths Defined
Your API specification lists all available paths and endpoints.
medium
Complex
Documentation
π
API Paths Reachable
All endpoints defined in your API spec actually work when agents call them.
medium
Moderate
Documentation
π
Response Matches Spec
Your API responses match what your specification promises.
low
Moderate
Documentation
π’
API Version Identified
Your API specification clearly states which version it is.
low
Quick fix
Documentation
π·οΈ
API Title
Your API specification has a clear title that describes your service.
low
Quick fix
Documentation
π€οΈ
OpenAPI Paths Reachable
At least half the paths declared in your OpenAPI spec return valid responses when probed.
medium
Moderate
Documentation
π
OpenAPI Response Matches Spec
Your API responses match the structure declared in your OpenAPI specification.
medium
Moderate
Documentation
π³
Payment Info in OpenAPI
Your OpenAPI spec declares payment information for paid operations so agents know which endpoints cost money.
medium
Moderate
Documentation
π―
Skills
Can agents discover and use your specialized skills?
3 rules
Skills
Can agents discover and use your specialized skills?
π―
Skill File Present
Your site has a skill file that describes specialized capabilities agents can use.
medium
Moderate
Documentation
β
Skill File Format Valid
Your skill file follows the expected format with proper metadata.
low
Quick fix
Documentation
π
Skills Index
Your site has an index listing all available skills in one place.
medium
Moderate
Documentation
π
Agents.txt
Do you have instructions specifically for AI agents?
1 rule
Agents.txt
Do you have instructions specifically for AI agents?
π
WebMCP
Can browsers interact with your agent via MCP?
7 rules
WebMCP
Can browsers interact with your agent via MCP?
π
WebMCP Manifest
Your site has a WebMCP manifest that enables browser-based agent interactions.
medium
Complex
Documentation
π
WebMCP Form Annotations
Your forms are annotated so WebMCP agents can fill them automatically.
low
Moderate
Documentation
π₯οΈ
WebMCP Browser Tools
Your site exposes browser-side tools that agents can call through WebMCP.
medium
Complex
Documentation
π
MCP namespace-based tool isolation
Your MCP server exposes tools with namespace prefixes for multi-registry support.
medium
Moderate
Documentation
π
Well-known MCP descriptor
Your site publishes an MCP server descriptor at /.well-known/mcp.json.
medium
Quick fix
Documentation
π
MCP tools and REST endpoints parity
At least 50% of your REST API endpoints have corresponding MCP tools.
medium
Complex
Documentation
π
check_compliance MCP tool available
Your MCP server exposes a 'check_compliance' tool for self-assessment.
low
Moderate
Documentation
π
Content Negotiation
Does your site serve the right format to AI agents?
7 rules
Content Negotiation
Does your site serve the right format to AI agents?
π€
Agent User-Agent Format
Your site serves appropriate content when an AI agent visits.
medium
Moderate
Documentation
π
JSON Format Support
Your site returns JSON when an agent requests it.
medium
Moderate
Documentation
π
Plain Text Format Support
Your site returns plain text when an agent requests it.
medium
Quick fix
Documentation
β¬οΈ
Markdown Format Support
Your site returns Markdown when an agent requests it.
medium
Quick fix
Documentation
π―
Preferred Format Selection
Your site respects format preferences when agents specify what they want.
low
Moderate
Documentation
π
Vary Header
Your site tells caches that content varies based on the requested format.
low
Quick fix
Documentation
π
No Redirect on Negotiation
Your site serves the requested format directly without redirecting.
low
Quick fix
Documentation
π
SEO / AEO
Is your content optimized for search engines and AI answer engines?
12 rules
SEO / AEO
Is your content optimized for search engines and AI answer engines?
π
Blog Article OpenGraph Type
Blog and article pages declare og:type=article in their OpenGraph meta tags.
medium
Quick fix
Documentation
π
Article Author and Date Meta Tags
Article pages include article:author, article:published_time, and article:modified_time meta tags.
medium
Quick fix
Documentation
π
AEO Short-Answer Summary Block
Article pages include a short-answer summary block (2-3 sentences) at the top for AI answer engines.
low
Moderate
Documentation
π
Semantic Definition Lists in Guides
Guide pages use <dl> definition lists for term/definition pairs instead of plain paragraphs.
low
Moderate
Documentation
π
OG Image Alt Text Brand Consistency
og:image:alt text is present and includes the site's brand name for consistent social sharing.
low
Quick fix
Documentation
π
Service page content depth
Service pages have at least 300 words of meaningful content.
low
Moderate
Documentation
π
Breadcrumb navigation on service pages
Service pages have breadcrumb navigation (JSON-LD BreadcrumbList or HTML .breadcrumb class).
low
Quick fix
Documentation
β
Answer-first extractability
Question-shaped headings are followed by self-contained answer blocks AI systems can quote.
low
Moderate
Documentation
π
Evidence density for citability
Pages contain citable evidence: sourced numbers, dated claims, fact tables, attributed quotations.
low
Moderate
Documentation
π·οΈ
Entity clarity and canonical naming
The page states what the entity is in one canonical line, names it consistently, and links About/schema signals.
low
Quick fix
Documentation
π₯οΈ
Server-rendered primary content
Primary content is present in the initial HTML without executing JavaScript.
low
Documentation
π«
Anti-citation disqualifiers
Content is free of overlays covering it, funnel-grade CTA density, and missing author/date on articles.
medium
Moderate
Documentation
Understandability
Can an agent understand you?
Weight: 25
π
Documentation
Is your API documented in formats that AI agents can read?
16 rules
Documentation
Is your API documented in formats that AI agents can read?
π
API Specification
Your site has a machine-readable API specification that agents can parse.
high
Complex
Documentation
π§ͺ
Agent Guide Schema Validation
Your agent guide follows the expected format with all required fields.
high
Moderate
Documentation
π
MCP Server Descriptor
Your site advertises its MCP server so agents can discover and connect to it.
medium
Moderate
Documentation
π
Detailed LLMs File
Your site has an extended llms-full.txt with comprehensive information for AI models.
medium
Moderate
Documentation
π
LLMs File Linked from HTML
Your homepage links to your llms.txt file so AI models can find it.
low
Quick fix
Documentation
π‘
RSS or Atom Feed
Your site has an RSS or Atom feed for agents to subscribe to updates.
low
Moderate
Documentation
πΌοΈ
Social Preview Image
Your site has a social preview image that appears when shared on social media or in AI responses.
low
Quick fix
Documentation
β
SVG Favicon
Your site has a scalable SVG favicon that looks crisp at any size.
low
Quick fix
Documentation
π
Canonical URL
Your pages have canonical URLs that tell agents which version is the official one.
low
Quick fix
Documentation
π°
RSS Feed Linked from HTML
Your homepage links to your RSS feed so agents can discover it.
low
Quick fix
Documentation
π
Agent Registration Instructions
Your site has instructions telling agents how to register and authenticate.
low
Moderate
Documentation
π
Auth.md documents agent auth flow
Your auth.md file documents agent authentication with session-scoped tokens.
low
Quick fix
Documentation
π
Auth.md documents credential vault pattern
Your auth.md mentions credential vault, scoped tokens, or session rotation (optional).
low
Quick fix
Documentation
π
Parameter semantics
Parameters have descriptions with constraints (min, max, required).
medium
Quick fix
Documentation
π‘
Request/response examples
OpenAPI operations include example requests and responses.
medium
Quick fix
Documentation
π
Support path declared
A support contact or help URL is declared in agent-guide.
low
Quick fix
Documentation
β‘
Actionability
Can agents actually call your API with the right authentication?
11 rules
Actionability
Can agents actually call your API with the right authentication?
π
Guide and API Consistency
Your agent guide and your API specification describe the same endpoints.
high
Moderate
Semantic
π
Authentication Declared
Your site declares its authentication method in a machine-readable way.
medium
Moderate
Semantic
π§©
Capability Coverage
Your agent guide covers all the capabilities your service offers.
medium
Moderate
Semantic
π€
A2A Agent Card Published
Your agent publishes a /.well-known/agent-card.json file so other agents can discover its capabilities via the A2A protocol.
medium
Quick fix
Semantic
β
A2A Agent Card Verified
Your agent-card.json includes all required fields: name, description, url, and capabilities.
medium
Quick fix
Semantic
π
MCP Server Name Present
Your MCP server's initialize response includes serverInfo.name, allowing agents to identify the server.
medium
Quick fix
Semantic
π
MCP Auth Discovery Resolves
If your MCP descriptor declares authentication, the auth URL is reachable and returns valid metadata.
medium
Moderate
Semantic
π
Operation descriptions
Every OpenAPI operation has a description or summary.
medium
Quick fix
Semantic
βοΈ
Business constraints documented
Business rules (refund windows, cancellation policies) are documented.
low
Quick fix
Semantic
π
Heartbeat.md availability
Your site serves /heartbeat.md with YAML frontmatter, providing a periodic check-in routine for AI agents.
low
Quick fix
Semantic
β‘οΈ
next_call pattern in API responses
Your OpenAPI spec includes a next_call field in response schemas with method, path, and why to guide agents to the next request.
low
Moderate
Semantic
βΏ
Accessibility
Is your site accessible to all users, including those using assistive technology?
2 rules
Accessibility
Is your site accessible to all users, including those using assistive technology?
π²
Pricing
Is pricing information available in machine-readable formats for automated clients?
1 rule
Pricing
Is pricing information available in machine-readable formats for automated clients?
β±οΈ
Rate Limits
Are rate limits and over-limit behavior declared machine-readably?
1 rule
Rate Limits
Are rate limits and over-limit behavior declared machine-readably?
Executability
Can an agent act on your API?
Weight: 30
π
Bot Authentication
Can you prove which AI bot is making the request?
23 rules
Bot Authentication
Can you prove which AI bot is making the request?
π
MCP Auth Discovery
Your MCP server's authentication info is discoverable by agents.
medium
Moderate
Capability
βοΈ
Bot Signatures Directory
Your site has a directory of bot signatures for verifying AI agent identities.
medium
Complex
Capability
π₯
Bot Directory Members
Your bot signatures directory has valid, recognized members.
medium
Moderate
Capability
π
Bot Public Keys
Public keys for verified bots are reachable and valid.
medium
Moderate
Capability
π‘οΈ
Protected Resource Metadata
Your site publishes metadata about what resources are protected and how.
medium
Moderate
Capability
π
Web Bot Auth Directory
Your site has a directory for web-based bot authentication using HTTP message signatures.
medium
Complex
Capability
π
OAuth2 preferred over static API keys
Your API uses OAuth2 security schemes instead of static API keys.
high
Moderate
Capability
π
Credentials via headers not query params
API keys and tokens are passed in headers, not query parameters.
high
Quick fix
Capability
π
OAuth scopes defined
Your OAuth metadata declares scopes_supported.
medium
Quick fix
Capability
π
Token revocation endpoint available
Your OAuth metadata publishes a revocation_endpoint.
medium
Moderate
Capability
π
Token introspection supported
Your OAuth metadata publishes an introspection_endpoint (optional).
low
Moderate
Capability
π
Private key JWT authentication
Your token endpoint supports private_key_jwt auth method (optional).
low
Complex
Capability
π
Token Exchange (RFC 8693) supported
Your OAuth metadata supports token-exchange grant type (optional).
medium
Complex
Capability
π
AAuth metadata endpoint available
Your API publishes /.well-known/aauth.json with agent authorization metadata.
medium
Moderate
Capability
π
Agent Authorization Grant supported
Your OAuth metadata includes the agent_authorization grant type.
medium
Complex
Capability
π
AAuth scope descriptions published
Your aauth.json publishes scope_descriptions (optional).
low
Quick fix
Capability
π
DPoP token binding supported
Your OAuth metadata supports DPoP (RFC 9449) for token binding (optional).
medium
Complex
Capability
π
mTLS-bound access tokens
Your OAuth metadata supports mTLS certificate-bound tokens (optional).
medium
Complex
Capability
π
Short-lived access tokens
Your token endpoint returns expires_in with access tokens.
medium
Quick fix
Capability
π
Refresh token rotation supported
Your OAuth metadata includes refresh_token in grant_types_supported (optional).
medium
Moderate
Capability
π
Token revocation endpoint reachable
Your credential security analysis confirms revocation endpoint is supported.
medium
Moderate
Capability
π
No static API keys in OpenAPI security
Your OpenAPI spec does not use apiKey security schemes.
high
Moderate
Capability
π
Authentication clarity
Security schemes are declared in the OpenAPI spec.
critical
Moderate
Capability
πͺͺ
Identity
Can agents verify your on-chain identity?
3 rules
Identity
Can agents verify your on-chain identity?
πͺͺ
WebFinger Identity Lookup
Your site can answer 'who is this?' queries from AI agents.
low
Moderate
Capability
π
DID Document
Your site provides a Decentralized Identifier document for on-chain identity verification.
low
Complex
Capability
key
OAuth Authorization Server metadata (RFC 9728)
OAuth Authorization Server Metadata published at /.well-known/oauth-authorization-server.
medium
Moderate
Capability
π°
Payments
Can agents pay for your services programmatically?
11 rules
Payments
Can agents pay for your services programmatically?
π°
Paid Endpoint Response
When an agent tries to access a paid feature, your site responds with a clear payment request.
high
Complex
Capability
π
Payment Challenge Decodable
The payment request your site sends is properly formatted and can be decoded by agents.
high
Complex
Capability
π
Payment Required Header
Your payment responses include a header that tells agents payment is needed.
high
Moderate
Capability
π€
Payment Recipient
Your payment requests specify who should receive the payment.
high
Moderate
Capability
π΅
Payment Amount
Your payment requests specify how much the agent needs to pay.
medium
Moderate
Capability
π
Payment Discovery File
Your site publishes a file that describes all payment options in one place.
medium
Moderate
Capability
π¦
Payment Facilitator
Your payment requests specify a facilitator that can process the payment.
medium
Complex
Capability
β‘
Lightning Payment Support
Your site supports Lightning Network payments for instant, low-cost transactions.
high
Complex
Capability
π«
Lightning Payment Details
Your Lightning payment responses include all required details for agents to pay.
high
Complex
Capability
π³
MPP (Machine Payments Protocol) Support
Checks for /.well-known/mpp.json declaring Machine Payments Protocol support.
medium
Quick fix
Capability
π³
SPT (Stripe Payment Terms) Support
Checks for /.well-known/spt.json declaring Stripe Payment Terms support.
low
Quick fix
Capability
πͺ
Bazaar
Is your agent listed in the decentralized marketplace?
3 rules
Bazaar
Is your agent listed in the decentralized marketplace?
πͺ
Bazaar Discoverable
Your agent marketplace listings can be discovered by other agents.
medium
Moderate
Capability
π·οΈ
Bazaar Service Declared
Your site declares what services it offers in the Bazaar marketplace.
low
Moderate
Capability
π
Bazaar in Lightning Payments
Your Lightning payment responses include Bazaar marketplace information.
medium
Complex
Capability
π«
Error Semantics
Are 4xx error responses declared with schemas and descriptions in the spec?
1 rule
Error Semantics
Are 4xx error responses declared with schemas and descriptions in the spec?
π
Retry Semantics
Are idempotency and retry guidance (Retry-After) declared for agents?
1 rule
Retry Semantics
Are idempotency and retry guidance (Retry-After) declared for agents?
π§ͺ
Sandbox
Is a test/sandbox environment advertised for agent experimentation?
1 rule
Sandbox
Is a test/sandbox environment advertised for agent experimentation?
π
Versioning
Is the API version declared with a deprecation/sunset policy?
1 rule
Versioning
Is the API version declared with a deprecation/sunset policy?
Verifiability
Can an agent verify what it observed?
Weight: 25
β
Verification
Can agents verify you are who you say you are?
2 rules
Verification
Can agents verify you are who you say you are?
ποΈ
Infrastructure
Are your caching, errors, and rate limits agent-ready?
6 rules
Infrastructure
Are your caching, errors, and rate limits agent-ready?
β‘
Cache Headers
Your site sends cache headers so agents and CDNs know how to cache your content.
medium
Quick fix
Semantic
π«
Structured 404 Errors
Your site returns structured JSON for 404 errors instead of plain HTML.
medium
Quick fix
Semantic
β±οΈ
Rate Limit Headers
Your site sends rate limit headers so agents know how many requests they can make.
low
Quick fix
Semantic
π
HTTPS Redirect Enforced
Your site automatically redirects HTTP requests to HTTPS so agents always use a secure connection.
high
Quick fix
Semantic
π
Content-Security-Policy header
Your homepage returns a Content-Security-Policy header.
high
Moderate
Semantic
π
Referrer-Policy header
Your homepage returns a Referrer-Policy header.
low
Quick fix
Semantic
π
Agent Policy
Is there a machine-readable usage policy for automated clients?
1 rule
Agent Policy
Is there a machine-readable usage policy for automated clients?
How does AgentBadge compare?
Wondering if you need AgentBadge alongside your existing tools?
Want to check your site against all 147 rules?
Scan Your SiteExplore More
-
FAQ
Common questions about agent readiness rules
-
Agent Guide
Step-by-step guide to becoming agent-ready
-
Blog
Deep dives into agent readiness concepts