AgentsReady
Verified deep dive · Commerce

Spotify

Run the agent liveReport a change
10 minTime to key
NoNo-human path
4Human gates
6/10Onboarding score
CAPTCHACard before first callEmail verificationManual review

Fastest path to a key

  1. Email verification
    Create Spotify account (email verification) and hold an ACTIVE Premium subscription (required for app owners of Development Mode apps since Feb 2026).
  2. Log in at developer.spotify.com/dashboard -> accept Developer Terms.
  3. Create app: name, description, redirect URI, tick 'Web API' -> Save -> copy Client ID / Client Secret (limit 1 client ID per developer for new apps).
  4. client_credentials token (public catalog) or Authorization Code + PKCE (user data) -> first call. Dev mode: max 5 users, many endpoints removed, search capped at 10 results.
  5. Consumer agent path: add Spotify connector https://mcp-gateway-external-pilot.spotify.net/mcp in Claude/ChatGPT -> OAuth via accounts.spotify.com.
  6. Working API key

Biggest gap

Feb 2026 dev-mode restrictions (Premium required, 5 users, 1 client ID) and no DCR, so custom agents cannot use the MCP gateway.

Worth copying

robots.txt explicitly allows the OpenAPI spec while blocking other YAMLs; a dedicated 'Building with AI' guide.

Sources (10) · checked 2026-10-11
35Readiness score / 100
L1 Agent-readableBeats 46% of 1,846 companies
Access16/20
Context11/20
Interfaces8/32
Onboarding0/19
Trust0/9
llms.txt · docs

Biggest gains

  1. +12 Remote MCP server for the product. Host a remote MCP server (e.g. mcp.<domain>/mcp, Streamable HTTP) for your core actions.
  2. +8 Machine-readable API spec. Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
  3. +6 Docs available as markdown. Serve every docs page as .md, or honour Accept: text/markdown.
All 20 checks
  • PASSAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • FAILContent is server-rendered4
  • PASSllms.txt exists8
  • FAILllms-full.txt exists3
  • FAILDocs available as markdown6
  • PASSSitemap2
  • PASSStructured metadata1
  • PASSPublic developer docs4
  • FAILMachine-readable API spec8
  • FAILRemote MCP server for the product12
  • FAILDocs MCP or searchable docs4
  • PASSSDKs and a CLI4
  • FAILOAuth discovery metadata5
  • FAILAgents can self-register OAuth clients6
  • FAILSelf-serve API keys5
  • FAILFree tier or test mode3
  • FAILAgent manifests4
  • FAILsecurity.txt2
  • FAILPublic status page3

Your fix pack: 14 changes, up to +65 points

Each change is ready to paste, filled in for spotify.com, with a command to check it worked. Or hand the whole list to your coding agent.

A remote MCP server lets Claude, ChatGPT and Cursor act on your product in one click, with no glue code.

Where: https://mcp.spotify.com/mcp (Streamable HTTP)
// npm i @modelcontextprotocol/sdk zod  — minimal remote MCP server (Streamable HTTP, stateless)
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StreamableHTTPServerTransport } from "@modelcontextprotocol/sdk/server/streamableHttp.js";
import express from "express";
import { z } from "zod";

const app = express();
app.use(express.json());

app.post("/mcp", async (req, res) => {
  const server = new McpServer({ name: "spotify.com", version: "1.0.0" });
  // One tool per core job. Clear verbs, typed inputs, small outputs.
  server.tool("create_<thing>", "Create a <thing> for the signed-in user.", { name: z.string() },
    async ({ name }) => {
      const key = req.headers.authorization?.replace("Bearer ", ""); // scoped API key or OAuth token
      const r = await fetch("https://spotify.com/v1/<things>", { method: "POST", headers: { Authorization: `Bearer ${key}` }, body: JSON.stringify({ name }) });
      return { content: [{ type: "text", text: await r.text() }] };
    });
  const transport = new StreamableHTTPServerTransport({ sessionIdGenerator: undefined });
  res.on("close", () => transport.close());
  await server.connect(transport);
  await transport.handleRequest(req, res, req.body);
});
app.listen(3000);
Check it worked:curl -s -X POST https://mcp.spotify.com/mcp -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"t","version":"1"}}}' -i | head -15

Add the badge to your README

AgentsReady badge for spotify.com
[![AgentsReady](https://agentsready.dev/badge/spotify.com)](https://agentsready.dev/c/spotify.com)