What is agent readiness?
Advanced is about agent readiness: the emerging well-known files and records an AI agent uses to find and act on your services, from MCP server cards to OAuth discovery and Web Bot Auth. It matters to a machine because an agent doing something for a person, such as calling an API, signing in or buying, needs a documented way in, and these files are where it looks. Below are the 11 checks in this course, what each one looks for, and what good looks like. Most sites need none of these yet, and we can't tell from outside whether yours should, so each check says when it applies.
These run on every scan and show in your results as their own Advanced sub-score, kept out of your headline score.
The checks in this course
11 checksMCP Server Card
Can an AI agent find the MCP server I run?Advertises an MCP server so agents can discover and use your tools. Only relevant if you expose agent-facing infrastructure.
What good looks like A valid MCP Server Card. The current proposal (SEP-2127, still a draft) puts it at /.well-known/mcp-server-card; sites in the wild also serve /.well-known/mcp.json and /.well-known/mcp/server-card.json, and any of the three counts.
Read more about MCP server cardsAI catalog
Is there one place an AI agent can see everything I offer it?A single index of the AI-facing things you publish — MCP servers, agent cards, skills, datasets — so an agent finds them in one hop instead of guessing at paths. Adoption is early and the specification is still a draft, so not having one is normal today rather than a defect.
What good looks like A valid /.well-known/ai-catalog.json that actually lists something. An index with nothing in it is discoverable but tells an agent no more than having none.
Read more about AI catalogsAgent Skills index
Can I give AI agents instructions for using my product?A discoverable manifest of skills an agent can use on your site.
What good looks like A valid Agent Skills index at /.well-known/agent-skills/index.json.
Read more about Agent Skills indexesAPI catalog
Can a machine find the APIs my company publishes?A machine-readable index of your APIs (RFC 9727) lets agents find and use them.
What good looks like A valid /.well-known/api-catalog.
Read more about API catalogsOAuth authorization-server metadata
Can an AI agent work out how to sign in to my service?Discovery metadata lets agents learn how to authenticate against protected resources.
What good looks like Valid OAuth authorization-server metadata at the well-known path.
Read more about OAuth sign-in discoveryOAuth protected-resource metadata
Does my API tell an AI agent where to get permission?RFC 9728 protected-resource metadata is how an MCP server tells an agent which authorization server guards it — the entry point of the MCP auth handshake.
What good looks like A valid /.well-known/oauth-protected-resource pointing at your authorization server.
Read more about API permission discoveryOpenID Connect discovery
Can other software discover how my site handles sign-in?OIDC discovery metadata lets agents and clients learn your token, authorization and JWKS endpoints without hard-coding them.
What good looks like Valid OpenID Connect discovery metadata at /.well-known/openid-configuration.
Read more about OpenID Connect provider metadataWeb Bot Auth (operates a signed bot)
How does a bot prove to websites that it is who it says it is?Web Bot Auth (IETF draft) lets a BOT OPERATOR cryptographically prove its traffic: the operator publishes signing keys on its own domain, and websites verify them. This one only applies if this domain operates a bot or agent — a normal publisher site has nothing to publish here, and that's expected.
What good looks like Only if you operate a bot/agent: a JWKS at /.well-known/http-message-signatures-directory on the domain your bot signs as (e.g. chatgpt.com publishes one).
Read more about Web Bot AuthUniversal Commerce Protocol manifest
Can an AI shopping agent buy from my store?UCP (Google) is how an AI shopping agent finds out what you sell without a human browsing your site. The agent appends /.well-known/ucp to your domain and reads a JSON manifest of your services, capabilities, payment handlers and API endpoints. Only relevant if you sell something — we don't check it otherwise.
What good looks like A JSON manifest at /.well-known/ucp declaring what you sell, how to transact, and which transports you support.
Read more about the Universal Commerce ProtocolAuth.md agent registration
How does an AI agent sign up to my service for a customer?OAuth tells an agent how to authenticate. auth.md tells it how to register in the first place — the step before that. Without one, an AI agent acting for a customer has no documented way to get credentials for your service.
What good looks like A /auth.md describing your registration flows, scopes and endpoints, alongside your OAuth protected-resource metadata.
Read more about auth.mdAI discovery via DNS
Can AI agents find my services through DNS?DNS-based AI-discovery records help agents find your endpoints without fetching the page.
What good looks like AI-discovery DNS records are published.
Read more about agent discovery records in DNSWords you'll meet here
- Agent Skills index
- AI catalog
- AI discovery via DNS
- API
- API catalog
- auth.md
- DNS / DNS-over-HTTPS
- HTTP message signatures
- MCP
- MCP server
- MCP Server Card
- OAuth
- OAuth authorization-server metadata
- OAuth protected-resource metadata
- OpenID Connect discovery
- Signatures directory / JWKS
- Signed bot / signed request
- UCP
- Web Bot Auth
How does your page read to a machine?
A free scan checks these 11 and everything else in about 20 seconds — no signup.
Rather have it handled? No pitch, just a plain-English chat.
Book a call