HonestClaw
What is Agent Readiness?

Agent Readiness Score

platform.sh

50 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well platform.sh's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability14.9/24
Content Accessibility14.7/24
Bot Access Control0/12
Protocol & Capability Discovery16.7/41
Authentication & Credentials8.5/19
Documentation Quality8.5/10
Structured Data I/O5.6/13
Observable State & Reliability7/15
Agent Safety & Trust8.5/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.platform.sh, docs.platform.sh).Useful
robots.txtrobots-txtrobots.txt at https://platform.sh/robots.txt declares a sitemap. Declared sitemap https://platform.sh/sitemap/sitemap-index.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://platform.sh/sitemap/sitemap-index.xml is a valid sitemap (1 location(s)), but without lastmod or non-homepage URLs.Parseable
Canonical domaincanonical-domainRoot and www converge on upsun.com, with a matching canonical tag.Cross-verified
API existenceapi-existenceA real API surface is declared at https://petstore3.swagger.io/api/v3/openapi.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningThe API version lifecycle is documented at https://developer.upsun.com/posts/how-tos/meta-version-updater-introduction, including deprecation/sunset. (source: docs)Cross-verified

Content Accessibility

Markdown twinmarkdown-twinA markdown twin is published at https://developer.upsun.com/index.md alongside the docs HTML surface (https://developer.upsun.com/).Parseable
llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://fixed.docs.upsun.com/llms.txt: 370 links across 2 sections. Its credit is capped at useful because it is not published on the main domain.Useful
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, ETag header.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredNo crawl-cost signals found (no sitemap URL inventory or Crawl-delay directive).Not detected
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
Raw content extractabilityraw-content-extractabilityReadable content is extractable without JavaScript on 2 probed surface(s) with substantial visible text.Cross-verified
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP supportmcp-supportA first-party MCP support page exists at https://developer.upsun.com/posts/ai/upsun-mcp-announcement, but it does not identify a concrete HTTPS MCP endpoint or fully establish a company-operated service.Parseable
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.platform.sh.Not detected
SDK availabilitysdk-availabilitySDK libraries page at https://developer.upsun.com/posts/releases/upsun-node-sdk-announcement: 2 GitHub repos, 1 registry link, 0 install commands (3 pointers).Cross-verified
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Auth discoveryauth-discoveryNo standardized authentication-discovery surface found. Blocked by robots.txt for a generic compliant agent (Disallow: /).Not detected
Rate limit documentationrate-limit-docsRate limits are documented at https://developer.upsun.com/posts/hands-on/varnish-102-protecting-your-application-with-rate-limiting-on-upsun with a concrete limit and rate-limit response headers. To reach the top level, it would need 429 handling, Retry-After guidance, and tier/plan differences.Useful
Link headerslink-headersAn agent-relevant Link rel (api-catalog) points at /.well-known/api-catalog.Useful
OpenAPI specificationopenapi-specValid OpenAPI 3.0.4 spec at https://petstore3.swagger.io/api/v3/openapi.json: 19 operations, 6 schemas, 100% response coverage, servers declared.Cross-verified
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is documented at https://developer.upsun.com/api/rest/authentication, naming a non-interactive grant and a token endpoint. To reach the top level, it would need scopes and token expiry/refresh documented.Useful
Auth documentationauth-documentationAuthentication is fully documented at https://developer.upsun.com/api/rest/authentication, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified
Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected

Documentation Quality

API reference depthapi-reference-depthThe API reference at https://developer.upsun.com/api/rest/endpoints documents parameters with example requests and responses. To reach the top level, it would need request and response bodies, authentication, pagination, and error codes.Useful
Changelog presencechangelog-presenceA changelog is published at https://www.mintlify.com/docs/changelog with multiple recent dated entries, indicating it is actively maintained.Cross-verified

Structured Data I/O

Structured data I/Ostructured-data-ioThe spec at https://petstore3.swagger.io/api/v3/openapi.json declares typed response schemas as a rule (63% of operations) — no documented pagination pattern, no structured error envelope. (source: spec)Useful
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.upsun.com/ (HTTP 200).Detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developer.upsun.com/docs/integrations/activity/webhooks, but it doesn't list specific event types with their payload shape.Parseable
Error documentationerror-documentationErrors are fully documented at https://developer.upsun.com/api/rest/errors, enumerating codes with a machine-readable format and recovery guidance.Cross-verified
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://platform.sh/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful
Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified