AgentsReady
ARS v1 · Oct 2026

The standard

Eight rules, ordered by how much they shorten an agent's path to a working key. Rules one to three are what separates the fastest platforms in our benchmark from the rest.

  1. Let agents get a key before a human pays or waits

    Test keys, free credits and claimable sandboxes first. Move KYC, cards and business checks to go-live.

  2. Use auth agents can finish

    OAuth with discovery metadata and client self-registration, CLI device login, scoped keys an agent can mint.

  3. Publish an agent playbook

    An /auth.md that tells an agent which commands to run, and where it must stop for a human.

  4. Run a remote MCP server

    Core actions as tools at a predictable URL like mcp.<domain>/mcp, plus docs search.

  5. Publish a machine-readable contract

    OpenAPI at a stable URL, linked from llms.txt.

  6. Be cheap to understand

    llms.txt, llms-full.txt, and every docs page as markdown.

  7. Don't wall out real users' agents

    Treat Claude-User and ChatGPT-User like browsers; decide training crawlers separately.

  8. Write errors for machines

    Stable codes, a fix in the message, a docs link, Retry-After and request IDs.

The readiness score

100 points from a passive scan. Onboarding gates that a scan can't see are graded separately by the agent run (A to F) and by hand in the benchmark.

PillarCheckPointsHow to pass
AccessAgents get the real page, not a bot wall10Serve the homepage to AI user-agents (Claude-User, ChatGPT-User) without a challenge or 403.
robots.txt lets user-triggered agents in6Don't Disallow ChatGPT-User, Claude-User or Perplexity-User. Block training crawlers separately if you must.
Content is server-rendered4Ship at least 1,000 characters of real text in the HTML, without needing JavaScript.
Contextllms.txt exists8Publish /llms.txt: a markdown index of your docs at the root or docs host.
llms-full.txt exists3Publish /llms-full.txt with the whole docs corpus in one file.
Docs available as markdown6Serve every docs page as .md, or honour Accept: text/markdown.
Sitemap2Publish sitemap.xml and reference it from robots.txt.
Structured metadata1Add JSON-LD and a meta description.
InterfacesPublic developer docs4Link docs from the homepage; host them at docs.<domain>.
Machine-readable API spec8Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
Remote MCP server for the product12Host a remote MCP server (e.g. mcp.<domain>/mcp, Streamable HTTP) for your core actions.
Docs MCP or searchable docs4Expose a docs-search MCP. Mintlify, Fern and GitBook include one.
SDKs and a CLI4Ship official SDKs and a CLI agents can install and script.
OnboardingOAuth discovery metadata5Publish RFC 8414 authorization-server and RFC 9728 protected-resource metadata.
Agents can self-register OAuth clients6Support dynamic client registration (RFC 7591) or client ID metadata documents so MCP clients connect in one click.
Self-serve API keys5Show how to create a key on the first docs page. No sales call.
Free tier or test mode3Offer free credits or a sandbox so an agent can verify an integration before payment.
TrustAgent manifests4Publish an MCP server card (/.well-known/mcp.json) or A2A agent card.
security.txt2Publish /.well-known/security.txt with a contact.
Public status page3Link a status page so agents can tell outages from bugs.
L4 Agent-native · 80+L3 Agent-operable · 60+L2 Agent-documented · 40+L1 Agent-readable · 20+L0 Agent-invisible · 0+

The prompt

Paste it into Claude Code, Cursor or any coding agent with access to your site, docs and API repos.

You are making our platform agent-ready: an AI agent acting for a user must be able to
READ our site, UNDERSTAND our product, GET CREDENTIALS and ACT through our API with as
few human steps as possible. Work through the phases below in order. For each phase:
look at what exists, make the smallest change that passes, then verify it with the
check given. Open one PR per phase. Never weaken security or remove an existing
protection without asking me first.

Company: <name>  |  Domain: <example.com>  |  Docs live in: <repo/path or docs platform>
Core product actions an agent should be able to do: <e.g. create a voice agent, send a message>

## Phase 0: baseline
- Run https://agentsready.dev/?check=<domain> and save the grade, time to key and gates.
- List every repo/service that owns: marketing site, docs, API, auth, dashboard.

## Phase 1: Access (don't wall out agents)
- robots.txt: allow user-triggered agents (ChatGPT-User, Claude-User, Perplexity-User,
  OAI-SearchBot, Claude-SearchBot). Decide training crawlers (GPTBot, ClaudeBot,
  Google-Extended, CCBot) as a separate, explicit policy. Reference the sitemap.
- WAF/bot rules: AI user-agents must get the real page (200, real content), not a challenge.
- Server-render the homepage, pricing and docs.
  Check: curl -sA "Claude-User/1.0" https://<domain>/ | sed 's/<[^>]*>//g' | wc -c   (> 1000)

## Phase 2: Context (be cheap to understand)
- /llms.txt at the root and docs host: name, one-paragraph summary, then markdown links:
  Quickstart, Auth & API keys, API reference, OpenAPI spec, MCP server, SDKs, Pricing &
  limits, Errors, Changelog. Keep it under ~20 KB.
- /llms-full.txt: the full docs as one markdown file, regenerated on every docs deploy.
- Every docs page as markdown: <page>.md and Accept: text/markdown.
  Check: curl -s https://<domain>/llms.txt | head -5   (starts with "# ")

## Phase 3: Interfaces (let agents act)
- OpenAPI 3.1 spec at a stable URL (/openapi.json), generated from code, linked in llms.txt.
- A REMOTE MCP server at https://mcp.<domain>/mcp (Streamable HTTP) exposing core actions
  as well-described tools, plus docs search. Publish /.well-known/mcp.json (server card).
- One-click install links for Cursor, VS Code and Claude on a /docs/ai page.
- SDKs (TypeScript + Python) and a CLI with --json output on every command.

## Phase 4: Onboarding (credentials without a babysitter)
- OAuth 2.1 for the MCP server and API: PKCE, RFC 8414 + RFC 9728 metadata, and client
  ID metadata documents or dynamic client registration so any MCP client connects in one click.
- Accept a scoped API key as a Bearer header on the MCP server for headless agents.
- CLI login via browser or device flow that writes a scoped key; let login double as signup.
- Claimable sandbox: an agent creates a temporary test project/key with NO account
  (rate-limited, short TTL, proof-of-work instead of CAPTCHA); a human claims it later.
- Publish /auth.md: the exact commands an agent runs, and where it must pause for a human.
- Keys: self-serve from the first docs page, scoped, expiring, revocable, with a key API.
- First call before friction: test mode or free credits with no card. Move KYC, card and
  business verification to go-live. No CAPTCHA or phone OTP on the API-key page.

## Phase 5: Errors (agents debug themselves)
- Every error: stable code, a message that says how to fix it, docs URL, request id.
  401 says where to get a key; 402/429 state the limit and Retry-After.

## Phase 6: Verify and report
- Re-run https://agentsready.dev/?check=<domain>: report before -> after grade, time to key, gates.
- Act as a brand-new agent: from only "<domain>", find docs, get a test key (stop at any
  human gate and log it), connect the MCP server, make one call. Log every step and minute.
- Output: what changed, the PRs, remaining human gates, the next three fixes by impact.