Agent Readiness Score
onesignal.com
48 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.
HonestClaw measured how well onesignal.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.
Dimensions
Discoverability10.9/24
Content Accessibility12.6/24
Bot Access Control0/12
Protocol & Capability Discovery23.5/41
Authentication & Credentials6.8/19
Documentation Quality6.8/10
Structured Data I/O8/13
Observable State & Reliability5/15
Agent Safety & Trust7.6/11
Checks
Discoverability
Subdomain sweepsubdomain-sweepAn agent-relevant subdomain is live (developer.onesignal.com).Detected
robots.txtrobots-txtrobots.txt at https://onesignal.com/robots.txt declares a sitemap. Declared sitemap https://onesignal.com/sitemaps-1-sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://onesignal.com/sitemaps-1-sitemap.xml is a valid sitemap with lastmod and real (non-homepage) URLs.Useful
Canonical domaincanonical-domainRoot and www converge on onesignal.com, with a matching canonical tag.Cross-verified
API existenceapi-existenceA real API surface is declared at https://documentation.onesignal.com/openapi.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
API versioningapi-versioningA versioning-related page exists at https://documentation.onesignal.com/docs/en/app-version-update, but it doesn't describe a versioning scheme or deprecation policy. (source: docs)Parseable
Content Accessibility
Markdown twinmarkdown-twinA markdown twin is published at https://documentation.onesignal.com/docs/en/home.md alongside the docs HTML surface (https://documentation.onesignal.com/).Parseable
llms.txtllms-txtA valid llms.txt header exists at https://onesignal.com/llms.txt, but it lists few or no link sections (1 links, 9 sections).Parseable
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap index declares 46 child sitemaps — high crawl cost; page URL inventory is not directly observable from the index.Detected
Raw content extractabilityraw-content-extractabilityModerate-to-strong main content (80% of visible text) is extractable from raw HTML on the homepage.Useful
llms-full.txtllms-full-txtAn llms-full.txt with substantial inline content is published at https://onesignal.com/llms-full.txt (17,425 chars). To reach the top level, it would need more comprehensive inline coverage.Useful
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Bot Access Control
AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected
Protocol & Capability Discovery
MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
MCP supportmcp-supportFirst-party documentation at https://documentation.onesignal.com/docs/en/model-context-protocol identifies the MCP endpoint https://api.onesignal.com/mcp/oauth and explains both its capabilities and how clients connect or authenticate.Cross-verified
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.onesignal.com.Not detected
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
SDK availabilitysdk-availabilitySDK libraries page at https://documentation.onesignal.com/docs/en/android-sdk-setup: 1 GitHub repo, 0 registry links, 0 install commands (1 pointer).Useful
Link headerslink-headersNo RFC 8288 Link headers found on any probed response. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
OpenAPI specificationopenapi-specValid OpenAPI 3.1.0 spec at https://documentation.onesignal.com/openapi.json: 62 operations, 25 schemas, 100% response coverage, servers declared.Cross-verified
Rate limit documentationrate-limit-docsRate limits are fully documented at https://documentation.onesignal.com/reference/rate-limits, with concrete limits, response headers, 429 handling, Retry-After, and tier/plan differences.Cross-verified
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify
Authentication & Credentials
Programmatic auth flowprogrammatic-auth-flowProgrammatic authentication is mentioned at https://documentation.onesignal.com/reference/create-api-key, but not on a page dedicated to documenting it.Detected
Credential managementcredential-managementCredential management is documented at https://documentation.onesignal.com/reference/create-api-key, covering how to rotate or revoke credentials. To reach the top level, it would need rotation, revocation, and scoping/expiry all documented.Useful
Auth documentationauth-documentationAuthentication is documented at https://documentation.onesignal.com/reference/create-api-key with the specific detail an agent needs — the credential and how it is sent. To reach the top level, it would need to corroborate against another surface or document more than one complete method.Useful
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Documentation Quality
Changelog presencechangelog-presenceA changelog is published at https://documentation.onesignal.com/release-notes/changelog with multiple recent dated entries, indicating it is actively maintained.Cross-verified
API reference depthapi-reference-depthAn API reference page exists at https://documentation.onesignal.com/docs/en/server-sdk-reference, but it doesn't show parameters with example requests and responses.Parseable
Structured Data I/O
Structured data I/Ostructured-data-ioThe spec at https://documentation.onesignal.com/openapi.json declares typed, consistent response schemas (100% of operations) with a pagination pattern and a structured error envelope. (source: spec)Cross-verified
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify). Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected
Observable State & Reliability
Status & health endpointsstatus-and-healthHealth/status endpoint found at https://status.onesignal.com/api/v2/status.json (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Retry & idempotencyretry-and-idempotencyRetry and idempotency are fully documented at https://documentation.onesignal.com/reference/idempotent-notification-requests, with an idempotency-key mechanism and backoff/retry guidance.Cross-verified
Error documentationerror-documentationNo error documentation found at the standard docs locations an agent would check. Blocked by robots.txt for a generic compliant agent (Disallow: /api/*).Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://documentation.onesignal.com/docs/cn/journeys-webhook, but it doesn't list specific event types with their payload shape.Parseable
Agent Safety & Trust
security.txtsecurity-txtsecurity.txt at https://onesignal.com/.well-known/security.txt publishes Contact and a future Expires date.Useful
Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful