Agent Readiness Score
hellosign.com
41 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.
HonestClaw measured how well hellosign.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.
Dimensions
Discoverability12.7/24
Content Accessibility11.2/24
Bot Access Control0/12
Protocol & Capability Discovery11.2/41
Authentication & Credentials10/19
Documentation Quality5.5/10
Structured Data I/O8/13
Observable State & Reliability5.2/15
Agent Safety & Trust5.5/11
Checks
Discoverability
Subdomain sweepsubdomain-sweepAn agent-relevant subdomain is live and serves its expected content kind (developers.hellosign.com).Parseable
Canonical domaincanonical-domainRoot and www converge on sign.dropbox.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://hellosign.com/robots.txt declares a sitemap. Declared sitemap https://sign.dropbox.com/sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://sign.dropbox.com/sitemap.xml is a valid sitemap (10667 location(s)), but without lastmod or non-homepage URLs.Parseable
API existenceapi-existenceA real API surface is declared at https://developers.hellosign.com/openapi/api-reference.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogAPI Catalog found at https://developers.hellosign.com/.well-known/api-catalog (application/linkset+json).Detected
API versioningapi-versioningAPI versioning is documented at https://developers.hellosign.com/docs/sdks/versioning-policy (the versioning scheme). To reach the top level, it would need a documented deprecation/sunset lifecycle. (source: docs)Useful
Content Accessibility
Markdown twinmarkdown-twinA markdown twin is published at https://developers.hellosign.com/index.md alongside the docs HTML surface (https://developers.hellosign.com/).Parseable
Freshness signalsfreshness-signalsA single freshness signal is present (Last-Modified header).Parseable
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredLarge sitemap (10,667 page URLs) signals high crawl cost with limited guidance.Detected
Raw content extractabilityraw-content-extractabilityModerate-to-strong main content (64% of visible text) is extractable from raw HTML on the homepage.Useful
llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://developers.hellosign.com/llms.txt: 170 links across 6 sections. Its credit is capped at useful because it is not published on the main domain.Useful
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Bot Access Control
AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected
Protocol & Capability Discovery
MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.hellosign.com.Not detected
MCP supportmcp-supportNo first-party MCP support documentation or MCP-specific endpoint response was found.Not detected
Auth discoveryauth-discoveryNo standardized authentication-discovery surface found. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
SDK availabilitysdk-availabilityGetting-started page at https://sign.dropbox.com/blog/dropbox-sign-ruby-sdk-in-rails: 6 GitHub repos, 0 registry links, 1 install command (7 pointers).Cross-verified
Rate limit documentationrate-limit-docsRate limiting is mentioned at https://sign.dropbox.com/blog/rate-limits-and-best-practices-to-avoiding-them, but not on a page dedicated to documenting it.Detected
Link headerslink-headersLink header(s) present with recognized rel values.Parseable
OpenAPI specificationopenapi-specValid OpenAPI 3.1.0 spec at https://developers.hellosign.com/openapi/api-reference.json: 70 operations, 244 schemas, 100% response coverage, servers declared.Cross-verified
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify
Authentication & Credentials
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://developers.hellosign.com/api/api-reference-authentication, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Auth documentationauth-documentationAuthentication is fully documented at https://developers.hellosign.com/api/api-reference-authentication, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified
Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Documentation Quality
API reference depthapi-reference-depthAPI reference content is mentioned at https://developers.hellosign.com/api/api-reference-authentication, but not on a dedicated reference page.Detected
Changelog presencechangelog-presenceA changelog is published at https://developers.hellosign.com/changelog with multiple recent dated entries, indicating it is actively maintained.Cross-verified
Structured Data I/O
Structured data I/Ostructured-data-ioThe spec at https://developers.hellosign.com/openapi/api-reference.json declares typed, consistent response schemas (100% of operations) with a pagination pattern and a structured error envelope. (source: spec)Cross-verified
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected
Observable State & Reliability
Status & health endpointsstatus-and-healthStatus page found at https://status.dropbox.com/ (HTTP 200).Detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationNo webhook or event documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationErrors are fully documented at https://developers.hellosign.com/api/manual-reference-pages/warnings-and-errors, enumerating codes with a machine-readable format and recovery guidance.Cross-verified
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify
Agent Safety & Trust
security.txtsecurity-txtNo security.txt found at /.well-known/security.txt or /security.txt.Not detected
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful
Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified