HonestClaw
What is Agent Readiness?

Agent Readiness Score

onelogin.com

17 — Limited. Agents will struggle to discover or use this site without human help.

44 of 45 checks conclusive · Confidence High · Evidence coverage 98%

HonestClaw measured how well onelogin.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability3.9/24
Content Accessibility0/24
Bot Access Control0/12
Protocol & Capability Discovery8.5/36
Authentication & Credentials13.1/19
Documentation Quality0.5/10
Structured Data I/O0/13
Observable State & Reliability1.8/15
Agent Safety & Trust0/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.onelogin.com, docs.onelogin.com).Useful
Canonical domaincanonical-domainRoot and www converge on a single canonical host (www.onelogin.com).Parseable
robots.txtrobots-txtNo robots.txt found (or the path returned an HTML page).Not detected
sitemap.xmlsitemap-xmlhttps://www.onelogin.com/sitemap.xml is a valid sitemap (5 location(s)), but without lastmod or non-homepage URLs.Parseable
API existenceapi-existenceNo API endpoint found at common paths (only HTML pages or 404s).Not detected
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningNo versioning signal found (no spec info.version, version header, /vN API surface, or versioning docs).Not detected

Content Accessibility

llms.txtllms-txtNo llms.txt file found (HTML pages at .txt paths do not qualify).Not detected
Freshness signalsfreshness-signalsNo freshness signals found (no Last-Modified, ETag, or sitemap lastmod).Not detected
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap index declares 5 child sitemap(s) — crawl cost is not directly observable from the index alone.Parseable
Raw content extractabilityraw-content-extractabilityThe homepage is a JS-rendered shell with no meaningful content in the initial HTML — content is behind JavaScript.Not detected
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Markdown twinmarkdown-twinNo markdown twin found alongside probed docs HTML surfaces.Not detected

Bot Access Control

AI bot rulesai-bot-rulesNo robots.txt was found (missing, or not servable as plain text), so no AI-bot rules are declared.Not detected
Content signalscontent-signalsNo robots.txt was found (missing, or not servable as plain text), so no Content Signals are declared.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
SDK availabilitysdk-availabilitySDK libraries page at https://developers.onelogin.com/blog/go-beyond-the-login-with-onelogins-new-developer-sdks: 4 GitHub repos, 0 registry links, 0 install commands (4 pointers).Cross-verified
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.onelogin.com.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Link headerslink-headersNo RFC 8288 Link headers found on any probed response.Not detected
OpenAPI specificationopenapi-specNo OpenAPI/Swagger specification found.Not detected
Auth discoveryauth-discoveryNo standardized authentication-discovery surface found. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Rate limit documentationrate-limit-docsRate limits are documented at https://developers.onelogin.com/api-docs/1/oauth20-tokens/get-rate-limit with a concrete limit and rate-limit response headers. To reach the top level, it would need 429 handling, Retry-After guidance, and tier/plan differences.Useful
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify
MCP supportmcp-supportCould not conclusively discover or check first-party MCP support documentation and likely endpoints.Couldn't verify

Authentication & Credentials

Sandbox environmentsandbox-environmentA sandbox/testing page exists at https://developers.onelogin.com/blog/enterprise-sandbox, but it doesn't show how to obtain test credentials or a test base URL.Parseable
Credential managementcredential-managementCredential management is documented at https://developers.onelogin.com/api-docs/1/getting-started/working-with-api-credentials, covering how to rotate or revoke credentials. To reach the top level, it would need rotation, revocation, and scoping/expiry all documented.Useful
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://developers.onelogin.com/api-authorization/authorizing-aws-api-gateway-requests-with-onelogin-oauth-access-tokens, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Auth documentationauth-documentationAuthentication is documented at https://developers.onelogin.com/api-authorization/authorizing-aws-api-gateway-requests-with-onelogin-oauth-access-tokens with the specific detail an agent needs — the credential and how it is sent. To reach the top level, it would need to corroborate against another surface or document more than one complete method.Useful

Documentation Quality

API reference depthapi-reference-depthAPI reference content is mentioned at https://developers.onelogin.com/api-docs/2/getting-started/dev-overview, but not on a dedicated reference page.Detected
Changelog presencechangelog-presenceNo changelog or release notes found at the standard docs locations an agent would check.Not detected

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas).Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthNo health or status endpoint found.Not detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developers.onelogin.com/blog/how-to-send-event-notifications-slack-serverless-webhooks, but it doesn't list specific event types with their payload shape.Parseable
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationNo error documentation found at the standard docs locations an agent would check.Not detected

Agent Safety & Trust

Org identity signalsorg-identityNo org-identity signals detected on the homepage.Not detected
Metadata consistencymetadata-consistencyInsufficient homepage metadata to assess consistency.Not detected
security.txtsecurity-txtNo security.txt found at /.well-known/security.txt or /security.txt.Not detected
Legal policy pageslegal-pagesNo terms, privacy, or data-use policy pages found at conventional paths.Not detected