§3 · CHECKLIST · 24 CHECKS · LAST REVIEWED SEPTEMBER 2026

Agent readiness checklist: 24 checks for your website

Work down the five layers. Each check names the standard behind it and a way to verify it by hand.


Agent Readiness Compare editors · Spec status checked September 2026

Answer

Start with discovery (5 checks) and reading (5 checks); most sites fail there first. Then decide which tasks agents should complete and work through acting (5), paying (4) and trust (5). Every check can be verified by hand; a scanner speeds it up, and a task run with a real agent confirms it.

L1.Discover: can an agent find you, and is it allowed in?

Table 3.1. Discover checks
IDCheckWhy it mattersHow to verifyStandard
robots.txt returns HTTP 200 at /robots.txt and parses.A missing or broken file leaves crawler behaviour to defaults.Fetch the URL; confirm 200 and plain text.robots.txt (RFC 9309)
The AI crawlers and agents you want are not blocked by User-agent: * or by name.A blanket Disallow also turns away agents acting for prospective customers.Read each group; search for Disallow: /.robots.txt (RFC 9309)
CDN and firewall bot rules match your robots.txt policy.An edge rule can block what robots.txt allows.Review bot rules and logs for AI user agents.robots.txt, Web Bot Auth
An XML sitemap is listed in robots.txt and includes pricing, product and docs pages.Agents and crawlers find the pages you most want read.Open the sitemap; search for those URLs.Sitemaps
If you run an agent, it publishes an A2A Agent Card at the well-known URI.Other agents can discover what your agent does.Request the Agent Card; validate it against the A2A specification.A2A

L2.Read: can it read and understand what you offer?

Table 3.2. Read checks
IDCheckWhy it mattersHow to verifyStandard
Pricing, plans, product and docs pages are server-rendered.Many agents do not execute JavaScript; client-only pages look empty.Fetch with curl and search the HTML for the price and plan names.Server rendering
/llms.txt exists with an H1, a summary and links to key pages.Gives models a short, accurate map of the site.Fetch the file; open every link.llms.txt
Key pages are available as markdown (.md URLs or Accept: text/markdown).Markdown is cheaper and cleaner for models to read than full HTML.Request a page with Accept: text/markdown; check the response type.Markdown negotiation, llms.txt
JSON-LD describes the organization, products and offers.Structured data states facts an agent can quote accurately.View source; validate the JSON-LD.JSON-LD (Schema.org)
Prices, plan limits and requirements are in text, not only in images, sliders or toggles.An agent cannot compare plans it cannot read.Disable JavaScript and images; confirm the numbers remain.Server rendering

L3.Act: can it complete a task on your site or API?

Table 3.3. Act checks
IDCheckWhy it mattersHow to verifyStandard
You have listed the three to five tasks an agent should be able to complete (for example: explain pricing, recommend a plan, find a feature in docs, request a demo, start a trial).Readiness is judged task by task, not page by page.Write the list; assign an owner to each task.None (practice)
Forms have labels and accessible names, and submit without custom gestures.Agents operate forms through their labels and structure.Inspect the form's accessibility tree.HTML forms, WebMCP declarative
Your API is described with OpenAPI, with agents.json flows if tasks span several calls.Agents can choose calls by outcome instead of guessing.Validate the OpenAPI file; request /.well-known/agents.json.OpenAPI, agents.json
API-backed tasks are available through an MCP server with authorization.MCP is how most agents call external tools.Connect a client; call tools/list and one tool.MCP, OAuth 2.0
In-page tasks are exposed as WebMCP tools (optional, experimental).In-browser agents can call a tool instead of clicking through the UI.Inspect the page with a WebMCP inspector.WebMCP

L4.Pay: can it pay you?

Table 3.4. Pay checks
IDCheckWhy it mattersHow to verifyStandard
Prices are machine-readable (JSON-LD Offer or a pricing API).An agent quoting a price should read it from you, not from a third-party page.Validate the Offer markup or call the API.JSON-LD (Schema.org)
The purchase or demo-request path can be completed by a verified agent without a challenge it cannot pass.A CAPTCHA at the last step ends the journey.Walk the path with a verified agent or a scanner that runs agents.Web Bot Auth
Pay-per-request resources answer unpaid requests with HTTP 402 and payment requirements.Lets an agent buy access without an account.Request without payment; confirm 402.x402
You have a written policy on whether AI crawlers may pay for or are denied content.Crawling and paid access are commercial decisions, not defaults.Record the policy; confirm edge settings match.Pay per crawl (Cloudflare), robots.txt

L5.Trust: can you tell which agent it is, and on whose behalf it acts?

Table 3.5. Trust checks
IDCheckWhy it mattersHow to verifyStandard
Your edge verifies signed bots instead of trusting user agent strings alone.Anyone can claim to be a known crawler.Check CDN settings for Web Bot Auth or verified bot handling.Web Bot Auth
If you operate a bot or agent, it signs requests and hosts a key directory at /.well-known/http-message-signatures-directory.Sites can verify your agent and let it through.Request the directory; confirm keys are served over HTTPS.Web Bot Auth, RFC 9421
Delegated access to user accounts uses OAuth, never shared passwords.Agents act for a person with scoped, revocable access.Review MCP and API authorization.OAuth 2.0
Trust pages (terms, privacy, security contact, company details) are linked from every page.Agents look for these before recommending or transacting.Check the footer on key pages.None (practice)
Key agent tasks are re-tested after releases that touch pricing, sign-in, bot rules or checkout.A journey that worked last month can break after the next release.Keep a dated log of task runs.None (practice)

How do tools help with this checklist?

Readiness scanners automate most of L1, L2 and parts of L3 to L5 by checking public signals. ora.ai Scan and Cloudflare Is It Agent Ready both scan a public URL; ora.ai Journey records an agent attempting a chosen task, which is the closest automated check for L3.1 and L4.2. See tools by job.

Note

A passing checklist means the signals are present. It does not measure how often agents visit or whether they convert; measure that with your own analytics.

Frequently asked questions

What is the most common agent readiness failure?

Content that only appears after JavaScript runs, especially pricing tables and plan toggles. Agents that do not execute JavaScript see an empty page. Check L2.1 and L2.5 first.

How long does the checklist take?

L1 and L2 can be checked by hand in an hour for a small site. L3 to L5 depend on whether you have an API, a checkout, or an agent of your own.

Do I need every item?

No. L1, L2 and L5.4 apply to almost every site. The act, pay and trust items apply when agents should complete tasks, buy, or be identified.

Source: RFC 9309 · llmstxt.org · Cloudflare Markdown for Agents · MCP specification · WebMCP proposal · agents.json · A2A specification · x402.org · Cloudflare Web Bot Auth docs · Reviewed Sep 2026