HonestClaw
What is Agent Readiness?

Agent Readiness Score

figma.com

44 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well figma.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability12.7/24
Content Accessibility11.2/24
Bot Access Control5/12
Protocol & Capability Discovery15/41
Authentication & Credentials10/19
Documentation Quality8.5/10
Structured Data I/O0/13
Observable State & Reliability5.5/15
Agent Safety & Trust7.3/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.figma.com, developers.figma.com).Useful
Canonical domaincanonical-domainRoot and www converge on www.figma.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://figma.com/robots.txt declares a sitemap. Declared sitemap https://www.figma.com/sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://www.figma.com/sitemap.xml is a valid sitemap with lastmod and real (non-homepage) URLs.Useful
API existenceapi-existenceNo API endpoint found at common paths (only HTML pages or 404s). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
API versioningapi-versioningAPI versioning is documented at https://developers.figma.com/docs/plugins/updates/2019/08/21/version-1-update-1/ (the versioning scheme). To reach the top level, it would need a documented deprecation/sunset lifecycle. (source: docs)Useful

Content Accessibility

llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://developers.figma.com/llms.txt: 119 links across 10 sections. Its credit is capped at useful because it is not published on the main domain.Useful
Freshness signalsfreshness-signalsFreshness signals present: ETag header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap index declares 14 child sitemap(s) — crawl cost is not directly observable from the index alone.Parseable
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Raw content extractabilityraw-content-extractabilitySubstantial visible text (3,936 chars) is readable without JavaScript on at least one probed page.Useful
Markdown twinmarkdown-twinNo markdown twin found alongside probed docs HTML surfaces.Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt declares explicit rules for 10 AI bot(s): gptbot, cohere-ai, claudebot, ccbot, google-extended, omgilibot, omgili, chatgpt-user, oai-searchbot, perplexitybot.Cross-verified
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
MCP supportmcp-supportFirst-party documentation at https://developers.figma.com/docs/figma-mcp-server/ identifies the MCP endpoint https://www.figma.com/mcp-catalog/ and explains both its capabilities and how clients connect or authenticate.Cross-verified
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
Link headerslink-headersNo RFC 8288 Link headers found on any probed response. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
OpenAPI specificationopenapi-specNo OpenAPI/Swagger specification found. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.figma.com.Not detected
SDK availabilitysdk-availabilityNo SDK or client library documentation found.Not detected
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Rate limit documentationrate-limit-docsRate limits are fully documented at https://developers.figma.com/docs/rest-api/rate-limits/, with concrete limits, response headers, 429 handling, Retry-After, and tier/plan differences.Cross-verified
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://developers.figma.com/docs/rest-api/oauth-apps/, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Auth documentationauth-documentationAuthentication is fully documented at https://developers.figma.com/docs/rest-api/oauth-apps/, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified

Documentation Quality

API reference depthapi-reference-depthThe API reference at https://developers.figma.com/docs/rest-api/activity-logs-endpoints/ documents parameters with example requests and responses. To reach the top level, it would need request and response bodies, authentication, pagination, and error codes.Useful
Changelog presencechangelog-presenceA changelog is published at https://developers.figma.com/docs/rest-api/changelog/ with multiple recent dated entries, indicating it is actively maintained.Cross-verified

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.figma.com/ (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developers.figma.com/docs/rest-api/webhooks-events/, but it doesn't list specific event types with their payload shape.Parseable
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationErrors are documented at https://developers.figma.com/docs/rest-api/errors/ with specific codes or a documented response shape. To reach the top level, it would need recovery guidance and a machine-readable error format, or corroboration against the API spec.Useful

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://figma.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesAt least one legal policy page is discoverable.Detected