HonestClaw
What is Agent Readiness?

Agent Readiness Score

okta.com

37 — Limited. Agents will struggle to discover or use this site without human help.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well okta.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability15.6/24
Content Accessibility12.7/24
Bot Access Control0/12
Protocol & Capability Discovery8.7/41
Authentication & Credentials4.6/19
Documentation Quality8.5/10
Structured Data I/O0/13
Observable State & Reliability2/15
Agent Safety & Trust10.4/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.okta.com, developer.okta.com).Useful
Canonical domaincanonical-domainRoot and www converge on www.okta.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://okta.com/robots.txt declares a sitemap. Declared sitemap https://www.okta.com/sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://www.okta.com/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
API existenceapi-existenceA conventional API path at https://www.okta.com/graphql returned an auth challenge (HTTP 401). (source: live)Detected
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningThe API version lifecycle is documented at https://developer.okta.com/blog/2019/12/16/semantic-versioning, including deprecation/sunset. (source: docs)Cross-verified

Content Accessibility

llms.txtllms-txtA curated llms.txt index is published at https://www.okta.com/llms.txt: 1448 links across 11 sections.Cross-verified
Raw content extractabilityraw-content-extractabilitySubstantial visible text (11,826 chars) is readable without JavaScript on at least one probed page.Useful
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredA manageable sitemap (1148 page URLs) helps agents estimate crawl cost.Useful
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Markdown twinmarkdown-twinNo markdown twin found alongside probed docs HTML surfaces.Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

SDK availabilitysdk-availabilitySDK libraries page at https://developer.okta.com/blog/2019/01/16/which-java-sdk: 2 GitHub repos, 0 registry links, 0 install commands (2 pointers).Cross-verified
MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexA non-owned /.well-known/ descriptor is present and parses.Parseable
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP supportmcp-supportA first-party MCP support page exists at https://developer.okta.com/blog/2025/09/22/okta-mcp-server, but it does not identify a concrete HTTPS MCP endpoint or fully establish a company-operated service.Parseable
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.okta.com.Not detected
GraphQL surfacegraphql-surfaceCould not conclusively check for GraphQL (endpoints unreachable, rate-limited, or behind auth). Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Auth discoveryauth-discoveryAn auth-discovery artifact is present but did not validate.Detected
Rate limit documentationrate-limit-docsNo rate limit documentation found at the standard docs locations an agent would check.Not detected
Link headerslink-headersLink header(s) present with recognized rel values.Parseable
OpenAPI specificationopenapi-specNo OpenAPI/Swagger specification found.Not detected
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Programmatic auth flowprogrammatic-auth-flowNo programmatic authentication documentation found at the standard docs locations an agent would check.Not detected
Credential managementcredential-managementCredential management is documented at https://developer.okta.com/blog/2026/06/29/verifiable-digital-credentials, covering how to rotate or revoke credentials. To reach the top level, it would need rotation, revocation, and scoping/expiry all documented.Useful
Auth documentationauth-documentationAn authentication documentation page exists at https://developer.okta.com/blog/2015/12/02/tls-client-authentication-for-services, but it doesn't name a specific method or show how a request is authenticated.Parseable
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected

Documentation Quality

API reference depthapi-reference-depthThe API reference at https://developer.okta.com/blog/2017/08/09/jax-rs-vs-spring-rest-endpoints documents parameters with example requests and responses. To reach the top level, it would need request and response bodies, authentication, pagination, and error codes.Useful
Changelog presencechangelog-presenceA changelog is published at https://developer.okta.com/blog/2019/12/04/whats-new-nodejs-2020 with multiple recent dated entries, indicating it is actively maintained.Cross-verified

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas).Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.okta.com/ (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developer.okta.com/blog/2017/10/11/why-are-webhooks-better-than-serverless-extensibility, but it doesn't list specific event types with their payload shape.Parseable
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationNo error documentation found at the standard docs locations an agent would check.Not detected

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://okta.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes legal name, address, support contact, and social profile links.Cross-verified
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful