HonestClaw
What is Agent Readiness?

Agent Readiness Score

netlify.com

50 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well netlify.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability12/24
Content Accessibility15.1/24
Bot Access Control7/12
Protocol & Capability Discovery22.6/41
Authentication & Credentials8.5/19
Documentation Quality3.5/10
Structured Data I/O5.6/13
Observable State & Reliability4.2/15
Agent Safety & Trust5.3/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepAn agent-relevant subdomain is live and serves its expected content kind (docs.netlify.com).Parseable
Canonical domaincanonical-domainRoot and www converge on www.netlify.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://netlify.com/robots.txt declares a sitemap. Declared sitemap https://www.netlify.com/sitemap-index.xml resolves as valid XML.Cross-verified
API catalogapi-catalogAPI Catalog found at https://netlify.com/.well-known/api-catalog (application/linkset+json).Detected
sitemap.xmlsitemap-xmlhttps://www.netlify.com/sitemap-index.xml is a valid sitemap with lastmod and real (non-homepage) URLs.Useful
API existenceapi-existenceA real API surface is declared at https://netlify.com/openapi.json: the spec lists servers and paths. (source: spec)Parseable
API versioningapi-versioningA versioning-related page exists at https://docs.netlify.com/manage/visual-editor/version-control/, but it doesn't describe a versioning scheme or deprecation policy. (source: docs)Parseable

Content Accessibility

Freshness signalsfreshness-signalsA single freshness signal is present (ETag header).Parseable
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredNo crawl-cost signals found (no sitemap URL inventory or Crawl-delay directive).Not detected
Raw content extractabilityraw-content-extractabilityReadable content is extractable without JavaScript on 2 probed surface(s) with a strong main-content ratio (77% on the homepage).Cross-verified
llms.txtllms-txtA curated llms.txt index is published at https://netlify.com/llms.txt: 27 links across 5 sections.Cross-verified
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Markdown twinmarkdown-twinA markdown twin is published at https://www.netlify.com/index.md alongside the docs HTML surface (https://www.netlify.com/).Parseable

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt declares explicit rules for 7 AI bot(s): gptbot, oai-searchbot, chatgpt-user, claude-web, claudebot, google-extended, perplexitybot.Cross-verified
Content signalscontent-signalsrobots.txt declares 3 recognized Content Signal(s) with a valid value: search, ai-input, ai-train.Cross-verified
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP supportmcp-supportFirst-party documentation at https://docs.netlify.com/build/build-with-ai/agent-setup-guides/agent-setup-overview/ explicitly states that the company operates MCP servers and explains both their capabilities and how clients connect or authenticate.Cross-verified
MCP descriptormcp-descriptorInformational — not scoredA file exists at https://docs.netlify.com/.well-known/mcp.json, but it doesn't contain the fields that describe an MCP server.Detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardA file exists at https://netlify.com/.well-known/mcp/server-card.json, but it doesn't contain the fields that describe an MCP Server Card.Detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.netlify.com.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
SDK availabilitysdk-availabilitySDK libraries page at https://developers.netlify.com/sdk/: 0 GitHub repos, 0 registry links, 0 install commands (0 pointers).Parseable
OpenAPI specificationopenapi-specValid OpenAPI 3.0.0 spec at https://netlify.com/openapi.json: 167 operations, 103 schemas, 100% response coverage, servers declared.Cross-verified
Link headerslink-headersAn agent-relevant Link rel (api-catalog) resolves to a live resource at https://netlify.com/.well-known/api-catalog.Cross-verified
Rate limit documentationrate-limit-docsRate limits are documented at https://docs.netlify.com/manage/security/secure-access-to-sites/rate-limiting/ with a concrete limit and rate-limit response headers. To reach the top level, it would need 429 handling, Retry-After guidance, and tier/plan differences.Useful
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is documented at https://developers.netlify.com/guides/generating-personal-access-tokens-with-netlify-oauth/, naming a non-interactive grant and a token endpoint. To reach the top level, it would need scopes and token expiry/refresh documented.Useful
Auth documentationauth-documentationAuthentication is fully documented at https://developers.netlify.com/guides/generating-personal-access-tokens-with-netlify-oauth/, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected

Documentation Quality

API reference depthapi-reference-depthAn API reference page exists at https://docs.netlify.com/resources/troubleshooting/error-reference/, but it doesn't show parameters with example requests and responses.Parseable
Changelog presencechangelog-presenceA changelog page exists at https://developers.netlify.com/guides/whats-new-with-angular-19-on-netlify/, but it doesn't list dated entries describing actual changes.Parseable

Structured Data I/O

Structured data I/Ostructured-data-ioThe spec at https://netlify.com/openapi.json declares typed response schemas as a rule (75% of operations) — no documented pagination pattern. (source: spec)Useful
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://www.netlifystatus.com/ (HTTP 200).Detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationWebhooks are mentioned at https://docs.netlify.com/deploy/deploy-notifications/, but not on a page dedicated to documenting them.Detected
Error documentationerror-documentationErrors are documented at https://docs.netlify.com/manage/monitoring/observability/reference/status-codes/ with specific codes or a documented response shape. To reach the top level, it would need recovery guidance and a machine-readable error format, or corroboration against the API spec.Useful
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify

Agent Safety & Trust

security.txtsecurity-txtNo security.txt found at /.well-known/security.txt or /security.txt.Not detected
Org identity signalsorg-identityHomepage exposes three org-identity signal types (legal_name, address, social).Useful
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesAt least one legal policy page is discoverable.Detected