hashicorp.com
agent readiness score · scanned Aug 18, 2026 · 5s
#868 of 979 · #48 in category
Agents can't use you yet — the good news: the first 20 points are cheap.
Discovery 7.3/20
Access 11.3/30
Usability 7.2/40
Payments 0/10
Top fixes
- +10
Pricing discoverable
Expose a crawlable /pricing page with literal plan prices and link it from your homepage nav.
- +7.5
llms.txt
Add /llms.txt: an H1 with your name, a one-line blockquote summary, and H2 sections of curated links to docs, pricing, and API.
- +7.3
Brand search discoverability
Your domain doesn't surface when agents search "Vercel Security Checkpoint". Strengthen brand pages, structured data, and third-party citations (docs portals, GitHub, directories).
- +5.9
MCP server discovery
Publish /.well-known/mcp/server-card.json describing your MCP endpoint so agents can autodiscover it. Evidence found: none.
- +5.9
OpenAPI spec discoverable
Publish your OpenAPI spec at /openapi.json and link it from docs — it's the single highest-leverage artifact for agent integration.
- +5.6
Markdown content negotiation
Serve text/markdown when clients send `Accept: text/markdown` (or expose .md twins of key pages) — agents get far more signal per token.
1.Can an agent discover and trust you?
4/8
1.Can an agent discover and trust you?
Whether agents can crawl you, find you in the registries and searches they check, and trust what they find.
✓Sitemap present & fresh4/4
Sitemap at https://hashicorp.com/sitemap.xml: 701 entries, freshest <lastmod> 2026-08-13 (4 days ago)
Resolved the sitemap from robots.txt or /sitemap.xml, validated XML, and checked lastmod freshness
spec ↗✗Brand search discoverability0/4
Neither search ("Vercel Security Checkpoint", "Vercel Security Checkpoint security") cited hashicorp.com. Cited instead: https://github.com/vercel/vercel/issues/16227, https://vercel.com/docs/vercel-firewall/firewall-concepts, https://github.com/vercel/vercel/issues/13147, https://community.vercel.com/t/server-error-were-verifying-your-browser-security-checkpoint/5997, https://github.com/vercel/next.js/discussions/59436
fix → Your domain doesn't surface when agents search "Vercel Security Checkpoint". Strengthen brand pages, structured data, and third-party citations (docs portals, GitHub, directories).
Ran clean brand-name web searches and checked whether your domain is cited in the results
—MCP registry listingsna
No MCP server detected for this product
Queried the official MCP registry, Smithery, Glama, and PulseMCP for servers matching your domain
spec ↗
2.Do you welcome agents?
5/12
2.Do you welcome agents?
Whether your robots policy, bot protection, and agent guidance actively admit AI agents instead of blocking them.
✗robots.txt present & parseable0/2
GET /robots.txt returned HTTP 429
fix → Serve a valid /robots.txt; without one, agent crawlers guess your policy.
Fetched /robots.txt and validated it parses as a robots policy
spec ↗✓AI crawler policy5/5
No robots.txt (HTTP 429) — none of the 12 AI crawler user-agents are blocked. Note: without a robots.txt, crawlers guess your policy.
Evaluated robots.txt groups for the major AI agent user-agents (GPTBot, ClaudeBot, PerplexityBot, …)
✗Content Signals directives0/2
No robots.txt (HTTP 429), so no Content-Signal lines are declared
fix → Declare Content Signals in robots.txt (e.g. `Content-Signal: search=yes, ai-train=no`) to express AI usage preferences machine-readably.
Looked for Content-Signal lines in robots.txt
spec ↗!Agent user-agent parityerror
Browser UA received HTTP 429 — cannot evaluate parity (the site may be blocking our scanner)
Compared responses served to browser and AI-agent user-agents (informational while in beta)
✗agents.md0/3
No agents.md: https://hashicorp.com/agents.md → HTTP 429, https://hashicorp.com/AGENTS.md → HTTP 429
fix → Add /agents.md: what agents may do on your site, key URLs, auth, rate limits, and who to contact.
Fetched /agents.md and checked for substantive agent guidance
spec ↗
3.Does an agent understand who you are and what you do?
0/9
3.Does an agent understand who you are and what you do?
Whether your pages carry machine-readable identity: structured data, llms.txt, clear copy an agent can quote.
!Homepage states what you areerror
Homepage returned HTTP 429 — no content to evaluate
An LLM read your homepage as an agent would and rated how confidently it could say what you do
!OpenGraph / social metadataerror
Homepage returned HTTP 429 (text/html) — could not parse HTML meta tags
Parsed homepage og:title / og:description / og:image and twitter:card meta tags
spec ↗✗llms.txt0/4
GET /llms.txt returned HTTP 429
fix → Add /llms.txt: an H1 with your name, a one-line blockquote summary, and H2 sections of curated links to docs, pricing, and API.
Fetched /llms.txt and validated it against the llmstxt.org shape (H1, summary, curated links)
spec ↗✗llms-full.txt0/2
GET /llms-full.txt returned HTTP 429
fix → Add /llms-full.txt with expanded inline docs content so agents can load everything in one fetch.
Fetched /llms-full.txt and checked for substantial inline markdown content
spec ↗!JSON-LD structured dataerror
Homepage returned HTTP 429 (content-type text/html) — no HTML to inspect
Extracted and validated application/ld+json blocks on the homepage and pricing page
spec ↗✗Markdown content negotiation0/3
GET / with `Accept: text/markdown` returned HTTP 429 text/html; no .md twins found (2 probed)
fix → Serve text/markdown when clients send `Accept: text/markdown` (or expose .md twins of key pages) — agents get far more signal per token.
Requested key pages with Accept: text/markdown and probed .md twin URLs
4.Can an agent integrate with you?
watch →4/21
4.Can an agent integrate with you?
Whether the artifacts an agent needs to build on you — docs, API specs, SDKs, MCP servers — exist and are findable.
✗Developer resource discoverability0/3
Search "Vercel Security Checkpoint API documentation" cited nothing from hashicorp.com and nothing mentioning "Vercel Security Checkpoint". Cited: https://solverify.net/docs/vercel-botid, https://github.com/dorukardahan/twitterapi-io-mcp/blob/main/scrape-docs.cjs, https://github.com/reggiechan74/JobOps/issues/5, https://raw.githubusercontent.com/api-evangelist/blue-origin/refs/heads/main/apis.yml, https://vercel.com/security/web-application-firewall
fix → Create a crawlable /docs or developers.hashicorp.com hub and link it from your homepage footer so search-grounded agents find your API.
Searched for your brand with developer-keyword suffixes and checked which official resources are cited
✗OpenAPI spec discoverable0/5
No OpenAPI spec found: checked docs-page links and /openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /docs/openapi.json, and api-subdomain locations
fix → Publish your OpenAPI spec at /openapi.json and link it from docs — it's the single highest-leverage artifact for agent integration.
Probed standard OpenAPI locations and docs links for a fetchable, parseable spec
spec ↗✓Docs discoverable4/4
Docs found at https://developer.hashicorp.com/sentinel (via path probe, 2242 chars of readable text)
Followed homepage nav/footer links and probed /docs, /developers, docs.{domain}
✗MCP server discovery0/5
No MCP evidence found: probed /.well-known/mcp/server-card.json, /.well-known/mcp.json, /mcp.json and scanned llms.txt, agents.md, and docs for endpoints or install commands
fix → Publish /.well-known/mcp/server-card.json describing your MCP endpoint so agents can autodiscover it. Evidence found: none.
Probed /.well-known/mcp/server-card.json, mcp.json, and docs mentions for an MCP endpoint
spec ↗✗npm SDK0/2
No official npm SDK found: probed 6 candidate(s) (@vercelsecuritycheckpoint/sdk, @vercelsecuritycheckpoint/vercelsecuritycheckpoint, vercelsecuritycheckpoint, vercelsecuritycheckpoint-sdk, vercelsecuritycheckpoint-api, vercelsecuritycheckpoint-js)
fix → Publish an official npm SDK (suggest @vercelsecuritycheckpoint/sdk) with your domain in package.json homepage so agents can verify it's official.
Searched the npm registry for an official, domain-verified SDK package
✗PyPI SDK0/2
No official PyPI SDK found: probed 4 candidate(s) (vercelsecuritycheckpoint, vercelsecuritycheckpoint-sdk, vercelsecuritycheckpointapi, vercelsecuritycheckpoint-python)
fix → Publish an official Python SDK (suggest "vercelsecuritycheckpoint") with your domain in the project URLs so agents can verify it's official.
Searched PyPI for an official, domain-verified SDK package
5.Is your integration well-built?
watch →2.1/5
5.Is your integration well-built?
Whether your specs, docs, and tools are complete and descriptive enough for an agent to use them without guessing.
—OpenAPI validity & qualityna
No OpenAPI spec found — nothing to lint
Linted the spec: descriptions, operationIds, securitySchemes, servers
◐Docs quality2.1/3
Docs at https://developer.hashicorp.com/sentinel scored clarity 4/5, completeness 3/5, runnable examples 4/5, agent-friendliness 3/5 (mean 3.5/5)
fix → Docs scored 3/5 on completeness. The documentation provides a high-level overview and links to tutorials, but lacks a clear, consolidated guide for an AI agent to understand and implement Sentinel's core functionalities programmatically without human interpretation of external links.
An LLM rated your docs for clarity, completeness, runnable examples, and agent-friendliness
✗Quickstart / getting started0/2
Quickstart link https://docs.hashicorp.com/sentinel/tutorials/get-started on https://developer.hashicorp.com/sentinel returned HTTP 404
fix → Fix the quickstart link so it resolves to a 200 page with a runnable code example.
Looked for a quickstart/getting-started guide containing code blocks
—MCP tool qualityna
No MCP endpoint known — tool lint requires a tools/list
Linted listed tools for descriptions, typed input schemas, and naming
6.Can an agent use you reliably in production?
watch →1/3
6.Can an agent use you reliably in production?
Response hygiene, TLS and redirect discipline, and security contact channels agents depend on at runtime.
◐TLS & redirect hygiene1/2
http://hashicorp.com/ reaches https but ends in HTTP 429: http://hashicorp.com/ → https://hashicorp.com/
fix → Redirect http→https in one hop and keep redirect chains ≤2; each hop costs agent latency and some clients give up.
Checked http→https redirect behavior, chain length, and TLS health
!Response speed & weighterror
Homepage returned HTTP 429 — cannot assess response hygiene
Measured homepage TTFB, payload size, and compression
✗security.txt0/1
https://hashicorp.com/.well-known/security.txt returned HTTP 429
fix → Publish RFC 9116 /.well-known/security.txt with a Contact and a future Expires.
Fetched /.well-known/security.txt and validated Contact + Expires
spec ↗
7.Can an agent authenticate to you?
watch →0/7
7.Can an agent authenticate to you?
Whether agents can discover your auth model machine-readably (OAuth metadata) and follow documented steps to credentials.
✗OAuth authorization server metadata0/3
Neither /.well-known/oauth-authorization-server nor /.well-known/openid-configuration resolved (HTTP 429 / HTTP 429)
fix → Serve RFC 8414 metadata at /.well-known/oauth-authorization-server with PKCE (S256) and a registration_endpoint so agents can self-onboard.
Fetched /.well-known/oauth-authorization-server (and openid-configuration fallback)
spec ↗✗OAuth protected resource metadata0/2
No RFC 9728 metadata: https://hashicorp.com/.well-known/oauth-protected-resource → HTTP 429
fix → Serve RFC 9728 metadata at /.well-known/oauth-protected-resource naming your authorization servers so agents can discover how to authenticate.
Fetched /.well-known/oauth-protected-resource
spec ↗✗Auth documentation0/2
No auth/API-key link found among 54 links on docs page https://developer.hashicorp.com/sentinel, and /auth.md is absent
fix → Document auth end-to-end (key creation → header format → example call), or ship /auth.md.
Looked for /auth.md or an authentication docs page with code examples
8.Can an agent transact with you?
watch →0/10
8.Can an agent transact with you?
Whether pricing is discoverable and machine-readable, and whether you support agent payment protocols.
✗Pricing discoverable0/5
No pricing page found: no homepage link matching pricing/plans/billing, and probes of /pricing and /plans returned no HTML page.
fix → Expose a crawlable /pricing page with literal plan prices and link it from your homepage nav.
Followed nav/footer links and probed /pricing for a page with legible price signals
—Machine-readable pricingna
No pricing page found to evaluate
Looked for Offer JSON-LD, then had an LLM attempt structured extraction of your plans
spec ↗✗x402 payment support0/2
/.well-known/x402 returned HTTP 429. No x402 support detected (bonus check — absence costs nothing).
fix → Support x402: serve payment requirements at /.well-known/x402, or answer unauthenticated API calls with HTTP 402 plus an x402 payment-requirements payload (x402Version, accepts[]).
Probed /.well-known/x402 and API endpoints for HTTP 402 payment-required envelopes
spec ↗✗AP2 readiness0/1
No AP2 hints found — scanned docs page (https://developer.hashicorp.com/sentinel); /.well-known/ap2 returned HTTP 429.
fix → Adopt AP2 to accept delegated agent payments — see https://ap2-protocol.org.
Scanned fetched artifacts and well-known paths for AP2 hints
spec ↗✗Agentic Commerce Protocol0/1
No Agentic Commerce Protocol hints found — scanned docs page (https://developer.hashicorp.com/sentinel); /.well-known/acp returned HTTP 429.
fix → Adopt the Agentic Commerce Protocol so agent checkouts can complete against your store — see https://developers.openai.com/commerce.
Scanned docs and specs for agentic checkout endpoints
spec ↗✗Other agent payment protocols0/1
No UCP/MPP hints found — scanned docs page (https://developer.hashicorp.com/sentinel).
fix → Track emerging agent payment protocols (UCP, MPP) and adopt the ones your buyers' agents use.
Scanned fetched artifacts for UCP/MPP protocol hints
9.Can a user act through an agent?
—
9.Can a user act through an agent?
Whether an end user's agent can operate on their behalf: working MCP tools, published skills, agent configs.
—Agent skill publishedna
Requires the analysis phase — not yet evaluated
Checked /skill.md, /.well-known/skills/, and skills.sh for published agent skills
—MCP handshake & tools listna
No MCP endpoint known — nothing to handshake with
Performed a streamable-HTTP initialize + tools/list against the MCP endpoint
spec ↗—Agent configs in public repona
Requires the analysis phase — not yet evaluated
Checked your public GitHub org's main repos for AGENTS.md / .claude / .cursor configs
10.Can an agent operate your website directly?
0/2
10.Can an agent operate your website directly?
Whether the site itself is legible to non-rendering and browser agents: semantic HTML, no JS walls, accessibility.
✗NLWeb endpoint0/1
No NLWeb endpoint detected: /.well-known/nlweb.json returned HTTP 429 (text/html); GET /ask?query=hello returned HTTP 429 (text/html)
fix → Consider exposing an NLWeb /ask endpoint (and /.well-known/nlweb.json) for conversational access to your content.
Probed /.well-known/nlweb.json and the /ask endpoint
spec ↗!Semantic HTML structureerror
Homepage returned HTTP 429 (content-type text/html) — no HTML to inspect
Scored landmark elements, heading hierarchy, and text-to-markup ratio on the homepage
!Content readable without JavaScripterror
Homepage returned HTTP 429 (content-type text/html) — no HTML to inspect
Measured visible text in the raw, unrendered homepage HTML
!Accessibility basicserror
Homepage did not parse as HTML (HTTP 429, content-type "text/html")
Static checks: lang attribute, title, alt coverage, labeled inputs, landmarks
✗WebMCP0/1
No WebMCP evidence on homepage: no application/webmcp script and no navigator.modelContext reference
fix → Consider WebMCP to expose page actions as tools to browser agents.
Looked for WebMCP script declarations on the homepage
spec ↗