HonestClaw
What is Agent Readiness?

Agent Readiness Score

bfl.ai

46 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well bfl.ai's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability11.8/24
Content Accessibility13.8/24
Bot Access Control0/12
Protocol & Capability Discovery19.9/41
Authentication & Credentials10/19
Documentation Quality6.8/10
Structured Data I/O5.6/13
Observable State & Reliability3.7/15
Agent Safety & Trust5.5/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.bfl.ai, docs.bfl.ai).Useful
robots.txtrobots-txtrobots.txt at https://bfl.ai/robots.txt declares a sitemap. Declared sitemap https://bfl.ai/sitemap.xml resolves as valid XML.Cross-verified
Canonical domaincanonical-domainThe origin https://bfl.ai/ is reachable, but root/www do not converge on one host.Detected
sitemap.xmlsitemap-xmlhttps://bfl.ai/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
API existenceapi-existenceA real API surface is declared at https://api.bfl.ai/openapi.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog. Blocked by robots.txt for a generic compliant agent (Disallow: /api).Not detected
API versioningapi-versioningThe API version is declared in the spec (info.version) at https://api.bfl.ai/openapi.json. (source: spec)Parseable

Content Accessibility

Markdown twinmarkdown-twinA markdown twin is published at https://docs.bfl.ai/quick_start/introduction.md alongside the docs HTML surface (https://docs.bfl.ai/).Parseable
Freshness signalsfreshness-signalsFreshness signals present: ETag header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredA manageable sitemap (65 page URLs) helps agents estimate crawl cost.Useful
Raw content extractabilityraw-content-extractabilityModerate-to-strong main content (79% of visible text) is extractable from raw HTML on the homepage.Useful
llms.txtllms-txtA curated llms.txt index is published at https://bfl.ai/llms.txt: 58 links across 4 sections.Cross-verified
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredAn MCP server is described at https://docs.bfl.ai/.well-known/mcp.json, but the description doesn't include a web address for the server.Parseable
MCP supportmcp-supportFirst-party documentation at https://docs.bfl.ai/api_integration/mcp_integration identifies the MCP endpoint https://mcp.bfl.ai/ and explains both its capabilities and how clients connect or authenticate.Cross-verified
MCP Server Cardmcp-server-cardA file exists at https://docs.bfl.ai/.well-known/mcp/server-card.json, but it doesn't contain the fields that describe an MCP Server Card.Detected
A2A Agent Carda2a-agent-cardAn A2A Agent Card is described at https://docs.bfl.ai/.well-known/agent-card.json, but it is missing required fields (name, description, version, supportedInterfaces, or skills).Parseable
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.bfl.ai.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued). Blocked by robots.txt for a generic compliant agent (Disallow: /api).Not detected
SDK availabilitysdk-availabilityGetting-started page at https://www.mintlify.com/library/best-api-docs-and-sdk-generation-tools: 1 GitHub repo, 0 registry links, 0 install commands (1 pointer).Useful
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
Link headerslink-headersNo RFC 8288 Link headers found on any probed response. Blocked by robots.txt for a generic compliant agent (Disallow: /api).Not detected
OpenAPI specificationopenapi-specValid OpenAPI 3.1.0 spec at https://api.bfl.ai/openapi.json: 28 operations, 34 schemas, 100% response coverage, servers declared.Cross-verified
Rate limit documentationrate-limit-docsNo rate limit documentation found at the standard docs locations an agent would check.Not detected
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://www.mintlify.com/docs/deploy/authentication-setup, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Auth documentationauth-documentationAuthentication is fully documented at https://www.mintlify.com/docs/deploy/authentication-setup, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified

Documentation Quality

API reference depthapi-reference-depthAn API reference page exists at https://www.mintlify.com/docs/organize/settings-reference, but it doesn't show parameters with example requests and responses.Parseable
Changelog presencechangelog-presenceA changelog is published at https://www.mintlify.com/docs/changelog with multiple recent dated entries, indicating it is actively maintained.Cross-verified

Structured Data I/O

Structured data I/Ostructured-data-ioThe spec at https://api.bfl.ai/openapi.json declares typed response schemas as a rule (100% of operations) — no documented pagination pattern. (source: spec)Useful
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify). Blocked by robots.txt for a generic compliant agent (Disallow: /api).Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.bfl.ml/ (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /api).Not detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationNo webhook or event documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationErrors are documented at https://docs.bfl.ai/api_integration/errors with specific codes or a documented response shape. To reach the top level, it would need recovery guidance and a machine-readable error format, or corroboration against the API spec.Useful

Agent Safety & Trust

security.txtsecurity-txtNo security.txt found at /.well-known/security.txt or /security.txt.Not detected
Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful