HonestClaw
What is Agent Readiness?

Agent Readiness Score

hubspot.com

41 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well hubspot.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability14.9/24
Content Accessibility13.8/24
Bot Access Control0/12
Protocol & Capability Discovery10.3/41
Authentication & Credentials12.2/19
Documentation Quality2.3/10
Structured Data I/O0/13
Observable State & Reliability5.8/15
Agent Safety & Trust9.5/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.hubspot.com, developer.hubspot.com).Useful
Canonical domaincanonical-domainRoot and www converge on www.hubspot.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://hubspot.com/robots.txt is a valid robots file (no Sitemap: declared).Parseable
sitemap.xmlsitemap-xmlhttps://www.hubspot.com/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
API existenceapi-existenceA real API surface at https://api.hubapi.com/crm/v3/schemas answered HTTP 401 with non-HTML JSON. (source: live)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningThe API version lifecycle is documented at https://developers.hubspot.com/blog/a-developers-guide-to-hubspots-date-based-api-versioning, including deprecation/sunset. (source: docs)Cross-verified

Content Accessibility

Markdown twinmarkdown-twinA markdown twin is published at https://developers.hubspot.com/docs/index.md alongside the docs HTML surface (https://developers.hubspot.com/docs).Parseable
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap declares 3025 page URLs — moderate crawl cost; agents should budget accordingly.Parseable
Raw content extractabilityraw-content-extractabilitySubstantial visible text (15,055 chars) is readable without JavaScript on at least one probed page.Useful
llms.txtllms-txtA curated llms.txt index is published at https://www.hubspot.com/llms.txt: 201 links across 27 sections.Cross-verified
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
Link headerslink-headersNo RFC 8288 Link headers found on any probed response.Not detected
OpenAPI specificationopenapi-specNo OpenAPI/Swagger specification found.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.hubspot.com.Not detected
SDK availabilitysdk-availabilitySDK libraries page at https://developers.hubspot.com/blog/introducing-hubspot-go-a-community-go-sdk-for-hubspot-developers: 3 GitHub repos, 0 registry links, 1 install command (4 pointers).Cross-verified
MCP supportmcp-supportA first-party MCP support page exists at https://developers.hubspot.com/ai-tools/mcp, but it does not identify a concrete HTTPS MCP endpoint or fully establish a company-operated service.Parseable
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Auth discoveryauth-discoveryNo standardized authentication-discovery surface found. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Rate limit documentationrate-limit-docsRate limits are documented at https://developers.hubspot.com/changelog/additional-rate-limit-protection-being-added-to-form-submissions-api with a concrete limit and rate-limit response headers. To reach the top level, it would need 429 handling, Retry-After guidance, and tier/plan differences.Useful
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://developers.hubspot.com/blog/enhancing-user-insights-in-public-apps-using-oauth-tokens, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Credential managementcredential-managementCredential management is mentioned at https://developers.hubspot.com/blog/hubspot-service-keys-the-right-api-credential-for-data-integrations, but not on a page dedicated to documenting it.Detected
Sandbox environmentsandbox-environmentA sandbox/testing page exists at https://developers.hubspot.com/blog/your-sandbox-should-look-like-production, but it doesn't show how to obtain test credentials or a test base URL.Parseable
Auth documentationauth-documentationAuthentication is fully documented at https://developers.hubspot.com/blog/oauth-token-management-hubspot-integrations, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified

Documentation Quality

API reference depthapi-reference-depthAn API reference page exists at https://developers.hubspot.com/blog/hello-world-creating-your-first-react-graphql-custom-card-for-hubspots-crm, but it doesn't show parameters with example requests and responses.Parseable
Changelog presencechangelog-presenceA changelog is mentioned at https://developers.hubspot.com/docs, but not on a page dedicated to publishing release history.Detected

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas).Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.hubspot.com/ (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developers.hubspot.com/blog/how-to-process-webhooks-in-hubspot-workflows-using-aws-lambda, but it doesn't list specific event types with their payload shape.Parseable
Retry & idempotencyretry-and-idempotencyRetry/idempotency is documented at https://developers.hubspot.com/changelog/2018-12-10-updated-webhook-retry-logic with an idempotency-key mechanism or a concrete retry strategy. To reach the top level, it would need an idempotency key and backoff/retry guidance together.Useful
Error documentationerror-documentationAn error documentation page exists at https://developers.hubspot.com/changelog/2018-11-12-reminder-the-fix-for-certain-http-requests-that-are-incorrectly-returning-http-200-status-codes-is-going-live-tomorrow, but it doesn't enumerate specific error codes or a documented error response shape.Parseable

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://hubspot.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes three org-identity signal types (legal_name, address, social).Useful
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful