terraform.io
agent readiness score · scanned Aug 18, 2026 · 6s · Infrastructure & DevOps
#538 of 979 · #42 in category
Terraform is an infrastructure as code tool that allows developers to build, change, and version infrastructure safely and efficiently across various cloud providers and on-premise environments.
Discovery 7.5/20
Access 17.3/30
Usability 13.8/40
Payments 5/10
Top fixes
- +6.9
OpenAPI spec discoverable
Publish your OpenAPI spec at /openapi.json and link it from docs — it's the single highest-leverage artifact for agent integration.
- +5
Brand search discoverability
Your domain doesn't surface when agents search "Terraform". Strengthen brand pages, structured data, and third-party citations (docs portals, GitHub, directories).
- +5
Sitemap present & fresh
Publish /sitemap.xml, reference it from robots.txt, and include <lastmod> dates so agents can tell what's current. Freshest lastmod seen: none.
- +4.6
llms.txt
Serve /llms.txt as plain markdown — an HTML page there is a routing catch-all, not an llms.txt.
- +4.1
agents.md
Add /agents.md: what agents may do on your site, key URLs, auth, rate limits, and who to contact.
- +4.1
OAuth authorization server metadata
Serve RFC 8414 metadata at /.well-known/oauth-authorization-server with PKCE (S256) and a registration_endpoint so agents can self-onboard.
1.Can an agent discover and trust you?
0/8
1.Can an agent discover and trust you?
Whether agents can crawl you, find you in the registries and searches they check, and trust what they find.
✗Sitemap present & fresh0/4
No valid sitemap found: robots.txt listed 0 Sitemap URL(s), and GET /sitemap.xml returned HTTP 200
fix → Publish /sitemap.xml, reference it from robots.txt, and include <lastmod> dates so agents can tell what's current. Freshest lastmod seen: none.
Resolved the sitemap from robots.txt or /sitemap.xml, validated XML, and checked lastmod freshness
spec ↗✗Brand search discoverability0/4
Neither search ("Terraform", "Terraform infrastructure devops") cited terraform.io. Cited instead: https://developer.hashicorp.com/terraform/cli/commands/plan, https://github.com/BlackMesaLTD/tfreport, https://github.com/mohsendehbashi/terraform-report, https://developer.hashicorp.com/terraform/cli/commands/show, https://developer.hashicorp.com/terraform/internals/machine-readable-ui
fix → Your domain doesn't surface when agents search "Terraform". Strengthen brand pages, structured data, and third-party citations (docs portals, GitHub, directories).
Ran clean brand-name web searches and checked whether your domain is cited in the results
—MCP registry listingsna
No MCP server detected for this product
Queried the official MCP registry, Smithery, Glama, and PulseMCP for servers matching your domain
spec ↗
2.Do you welcome agents?
6/12
2.Do you welcome agents?
Whether your robots policy, bot protection, and agent guidance actively admit AI agents instead of blocking them.
◐robots.txt present & parseable1/2
/robots.txt returned HTTP 200 but looks like an HTML page (content-type text/html), not a robots policy
fix → Serve /robots.txt as plain text with User-agent groups; an HTML error page there is unparseable to crawlers.
Fetched /robots.txt and validated it parses as a robots policy
spec ↗✓AI crawler policy5/5
/robots.txt is unparseable (looks like HTML) — crawlers treat this as no restrictions, so none of the 12 AI crawler user-agents are blocked
Evaluated robots.txt groups for the major AI agent user-agents (GPTBot, ClaudeBot, PerplexityBot, …)
✗Content Signals directives0/2
/robots.txt is unparseable, so no Content-Signal lines could be read
fix → Declare Content Signals in robots.txt (e.g. `Content-Signal: search=yes, ai-train=no`) to express AI usage preferences machine-readably.
Looked for Content-Signal lines in robots.txt
spec ↗!Agent user-agent parityerror
Browser-UA homepage fetch failed (Request budget exhausted) — cannot compare UA treatment
Compared responses served to browser and AI-agent user-agents (informational while in beta)
✗agents.md0/3
No agents.md: https://terraform.io/agents.md → HTTP 200, https://terraform.io/AGENTS.md → HTTP 200
fix → Add /agents.md: what agents may do on your site, key URLs, auth, rate limits, and who to contact.
Fetched /agents.md and checked for substantive agent guidance
spec ↗
3.Does an agent understand who you are and what you do?
7/18
3.Does an agent understand who you are and what you do?
Whether your pages carry machine-readable identity: structured data, llms.txt, clear copy an agent can quote.
✓Homepage states what you are3/3
Homepage clarity rated 5/5 — an agent can confidently say what this company does (model's one-sentence read: "Terraform is an infrastructure as code tool that allows developers to build, change, and version infrastructure safely and efficiently across various cloud providers and on-premise environments.")
An LLM read your homepage as an agent would and rated how confidently it could say what you do
✓OpenGraph / social metadata2/2
Homepage has og:title, og:description, and og:image (twitter:card="summary_large_image" present)
Parsed homepage og:title / og:description / og:image and twitter:card meta tags
spec ↗✗llms.txt0/4
/llms.txt returned HTML (content-type text/html), not markdown
fix → Serve /llms.txt as plain markdown — an HTML page there is a routing catch-all, not an llms.txt.
Fetched /llms.txt and validated it against the llmstxt.org shape (H1, summary, curated links)
spec ↗✗llms-full.txt0/2
/llms-full.txt returned HTML (content-type text/html), not markdown
fix → Serve /llms-full.txt as plain markdown, not an HTML page.
Fetched /llms-full.txt and checked for substantial inline markdown content
spec ↗◐JSON-LD structured data2/4
2 JSON-LD block(s) on homepage and pricing page (types: BreadcrumbList) but none is a substantive type, or Organization/WebSite lacks name+url
fix → Embed Organization + WebSite JSON-LD with name and url on your homepage (plus logo, sameAs) and Product/Offer JSON-LD on pricing.
Extracted and validated application/ld+json blocks on the homepage and pricing page
spec ↗✗Markdown content negotiation0/3
GET / with `Accept: text/markdown` returned HTTP 200 text/html; no .md twins found (2 probed)
fix → Serve text/markdown when clients send `Accept: text/markdown` (or expose .md twins of key pages) — agents get far more signal per token.
Requested key pages with Accept: text/markdown and probed .md twin URLs
4.Can an agent integrate with you?
watch →7.5/17
4.Can an agent integrate with you?
Whether the artifacts an agent needs to build on you — docs, API specs, SDKs, MCP servers — exist and are findable.
◐Developer resource discoverability1/3
Search "Terraform API documentation" cited no terraform.io URL — only third-party content describes your API: https://developer.hashicorp.com/terraform/cloud-docs/api-docs, https://developer.hashicorp.com/terraform/registry/api-docs, https://developer.hashicorp.com/terraform/cloud-docs/api-docs/plans, https://developer.hashicorp.com/terraform/cloud-docs/api-docs/applies, https://developer.hashicorp.com/terraform/cloud-docs/api-docs/state-versions
fix → Create a crawlable /docs or developers.terraform.io hub and link it from your homepage footer so search-grounded agents find your official API docs.
Searched for your brand with developer-keyword suffixes and checked which official resources are cited
✗OpenAPI spec discoverable0/5
No OpenAPI spec found: checked docs-page links and /openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /docs/openapi.json, and api-subdomain locations
fix → Publish your OpenAPI spec at /openapi.json and link it from docs — it's the single highest-leverage artifact for agent integration.
Probed standard OpenAPI locations and docs links for a fetchable, parseable spec
spec ↗✓Docs discoverable4/4
Docs found at https://developer.hashicorp.com/terraform (via homepage link, 4382 chars of readable text)
Followed homepage nav/footer links and probed /docs, /developers, docs.{domain}
◐MCP server discovery2.5/5
MCP evidence found only as a mention in docs page (https://developer.hashicorp.com/terraform): "mcp-server" — no well-known server card
fix → Publish /.well-known/mcp/server-card.json describing your MCP endpoint so agents can autodiscover it. Evidence found: docs page (https://developer.hashicorp.com/terraform).
Probed /.well-known/mcp/server-card.json, mcp.json, and docs mentions for an MCP endpoint
spec ↗!npm SDKerror
All 6 npm registry requests failed: @terraform/sdk (Request budget exhausted), @terraform/terraform (Request budget exhausted), terraform (Request budget exhausted), terraform-sdk (Request budget exhausted), terraform-api (Request budget exhausted), terraform-js (Request budget exhausted)
Searched the npm registry for an official, domain-verified SDK package
!PyPI SDKerror
All 4 PyPI registry requests failed: terraform (Request budget exhausted), terraform-sdk (Request budget exhausted), terraformapi (Request budget exhausted), terraform-python (Request budget exhausted)
Searched PyPI for an official, domain-verified SDK package
5.Is your integration well-built?
watch →1.5/5
5.Is your integration well-built?
Whether your specs, docs, and tools are complete and descriptive enough for an agent to use them without guessing.
—OpenAPI validity & qualityna
No OpenAPI spec found — nothing to lint
Linted the spec: descriptions, operationIds, securitySchemes, servers
◐Docs quality1.5/3
Docs at https://developer.hashicorp.com/terraform scored clarity 3/5, completeness 2/5, runnable examples 3/5, agent-friendliness 2/5 (mean 2.5/5)
fix → Docs scored 2/5 on completeness. The documentation provides a high-level overview and navigation, but lacks direct, actionable API specifications or detailed integration guides for an AI agent.
An LLM rated your docs for clarity, completeness, runnable examples, and agent-friendliness
✗Quickstart / getting started0/2
No quickstart/getting-started link or heading found on docs page https://developer.hashicorp.com/terraform (searched 98 links)
fix → Add a copy-pasteable quickstart (auth → first API call) — agents follow it literally.
Looked for a quickstart/getting-started guide containing code blocks
—MCP tool qualityna
No MCP endpoint known — tool lint requires a tools/list
Linted listed tools for descriptions, typed input schemas, and naming
6.Can an agent use you reliably in production?
watch →2/3
6.Can an agent use you reliably in production?
Response hygiene, TLS and redirect discipline, and security contact channels agents depend on at runtime.
◐TLS & redirect hygiene1/2
http://terraform.io/ is unreachable (Request budget exhausted); HTTPS works but there is no http→https redirect
fix → Listen on port 80 and 301-redirect all http requests to https — some clients still try http first.
Checked http→https redirect behavior, chain length, and TLS health
✓Response speed & weight1/1
Homepage TTFB 88ms, payload 130KB, Content-Encoding: br
Measured homepage TTFB, payload size, and compression
!security.txterror
Fetch of https://terraform.io/.well-known/security.txt failed at the network layer (Request budget exhausted)
Fetched /.well-known/security.txt and validated Contact + Expires
spec ↗
7.Can an agent authenticate to you?
watch →0/5
7.Can an agent authenticate to you?
Whether agents can discover your auth model machine-readably (OAuth metadata) and follow documented steps to credentials.
✗OAuth authorization server metadata0/3
Neither /.well-known/oauth-authorization-server nor /.well-known/openid-configuration resolved (HTTP 200 / HTTP 200)
fix → Serve RFC 8414 metadata at /.well-known/oauth-authorization-server with PKCE (S256) and a registration_endpoint so agents can self-onboard.
Fetched /.well-known/oauth-authorization-server (and openid-configuration fallback)
spec ↗✗OAuth protected resource metadata0/2
No RFC 9728 metadata: https://terraform.io/.well-known/oauth-protected-resource → HTTP 200
fix → Serve RFC 9728 metadata at /.well-known/oauth-protected-resource naming your authorization servers so agents can discover how to authenticate.
Fetched /.well-known/oauth-protected-resource
spec ↗!Auth documentationerror
Fetch of https://terraform.io/auth.md failed at the network layer (Request budget exhausted)
Looked for /auth.md or an authentication docs page with code examples
8.Can an agent transact with you?
watch →5/11
8.Can an agent transact with you?
Whether pricing is discoverable and machine-readable, and whether you support agent payment protocols.
◐Pricing discoverable2.5/5
Pricing page found at https://developer.hashicorp.com/terraform (via path probe) but no legible price signals in 4382 chars of page text — no currency amounts, "per month"/"/mo", or "free plan" terms (reads as contact-sales only).
fix → Add literal plan prices to https://developer.hashicorp.com/terraform; 'Contact sales'-only pricing means agents can't complete a purchase evaluation.
Followed nav/footer links and probed /pricing for a page with legible price signals
◐Machine-readable pricing2.5/5
Pricing at https://developer.hashicorp.com/terraform is extractable only via inference and stays ambiguous — only contact-sales/unpriced plans came back (confidence 0.50): HCP Terraform (no listed price). No Offer JSON-LD on the page.
fix → Add Offer JSON-LD per plan (name, price, priceCurrency, billing period) to https://developer.hashicorp.com/terraform so pricing parses without inference.
Looked for Offer JSON-LD, then had an LLM attempt structured extraction of your plans
spec ↗!x402 payment supporterror
Could not fetch /.well-known/x402 (Request budget exhausted).
Probed /.well-known/x402 and API endpoints for HTTP 402 payment-required envelopes
spec ↗!AP2 readinesserror
Could not probe /.well-known/ap2: Request budget exhausted; no AP2 hints in fetched artifacts.
Scanned fetched artifacts and well-known paths for AP2 hints
spec ↗!Agentic Commerce Protocolerror
Could not probe /.well-known/acp: Request budget exhausted; no Agentic Commerce Protocol hints in fetched artifacts.
Scanned docs and specs for agentic checkout endpoints
spec ↗✗Other agent payment protocols0/1
No UCP/MPP hints found — scanned llms.txt, agents.md, docs page (https://developer.hashicorp.com/terraform).
fix → Track emerging agent payment protocols (UCP, MPP) and adopt the ones your buyers' agents use.
Scanned fetched artifacts for UCP/MPP protocol hints
9.Can a user act through an agent?
—
9.Can a user act through an agent?
Whether an end user's agent can operate on their behalf: working MCP tools, published skills, agent configs.
—Agent skill publishedna
Requires the analysis phase — not yet evaluated
Checked /skill.md, /.well-known/skills/, and skills.sh for published agent skills
—MCP handshake & tools listna
No MCP endpoint known — nothing to handshake with
Performed a streamable-HTTP initialize + tools/list against the MCP endpoint
spec ↗—Agent configs in public repona
Requires the analysis phase — not yet evaluated
Checked your public GitHub org's main repos for AGENTS.md / .claude / .cursor configs
10.Can an agent operate your website directly?
7/9
10.Can an agent operate your website directly?
Whether the site itself is legible to non-rendering and browser agents: semantic HTML, no JS walls, accessibility.
✗NLWeb endpoint0/1
No NLWeb endpoint detected: /.well-known/nlweb.json returned HTTP 200 (text/html); GET /ask?query=hello returned HTTP 200 (text/html)
fix → Consider exposing an NLWeb /ask endpoint (and /.well-known/nlweb.json) for conversational access to your content.
Probed /.well-known/nlweb.json and the /ask endpoint
spec ↗✓Semantic HTML structure3/3
5/6 semantic signals present on the homepage (missing: text-to-markup ratio ≥ 0.10)
Scored landmark elements, heading hierarchy, and text-to-markup ratio on the homepage
✓Content readable without JavaScript2/2
Homepage raw HTML contains 4382 chars of visible text without JavaScript
Measured visible text in the raw, unrendered homepage HTML
✓Accessibility basics2/2
Homepage accessibility: 5/5 checks passed
Static checks: lang attribute, title, alt coverage, labeled inputs, landmarks
✗WebMCP0/1
No WebMCP evidence on homepage: no application/webmcp script and no navigator.modelContext reference
fix → Consider WebMCP to expose page actions as tools to browser agents.
Looked for WebMCP script declarations on the homepage
spec ↗