DISPATCH · 22 SEP 2026

How to choose an agent readiness scanner: eight questions to ask

A buyer's guide for web and growth leads comparing tools that score a site for AI agents.


Agent Readiness Compare editors · Spec status checked September 2026

Agent Readiness Compare editors · · 6 min read

Answer

Ask what the scanner checks, whether it runs an agent through a real task, whether its scoring rules are published, and whether you can run it from a CLI or a CI job. Then check the limits: scanners generally read public URLs only, and none measures revenue. Use the answers to match a scanner to your job rather than to find one winner.

On this page
  1. 1. Why does the choice of scanner matter?
  2. 2. Which standards does it check?
  3. 3. Does it run an agent, or only check files?
  4. 4. Is the scoring method published?
  5. 5. Can you run it from code?
  6. 6. Can you fix what it finds on the same platform?
  7. 7. Can you use it today?
  8. 8. What can it not see?
  9. 9. Does it keep up with the standards?
  10. 10. How should you compare the answers?
  11. 11. Sources

1.Why does the choice of scanner matter?

Readiness scanners look alike from the outside: enter a URL, get a score. Underneath, they differ in what they check, how they weight it and what they can reach. Two scanners can give the same site different grades for defensible reasons. Knowing those differences before you pick one, or before you report a score to leadership, saves an argument about a number nobody can explain.

The eight questions below follow the criteria we use to compare scanners on our method page. They apply to any tool in the category.

2.Which standards does it check?

List the standards that matter for your site and compare them with the scanner's published list. A useful set spans all five layers: robots.txt and sitemaps (discover), llms.txt, markdown negotiation and JSON-LD (read), MCP, WebMCP and OpenAPI (act), x402 and other commerce protocols (pay), and Web Bot Auth and OAuth (trust).

Cloudflare's Is It Agent Ready lists its checks in five categories on its public page. ora.ai publishes its list as AgentReady, an MIT-licensed specification at agentready.org that reached v1.0.0 on 24 April 2026. If a vendor does not publish its list, ask for it in writing.

3.Does it run an agent, or only check files?

A file check confirms that /llms.txt exists or that a header comes back. A task run sends an agent to do something, such as find a price, and records where it stopped. Both are useful, and they answer different questions.

ora.ai Journey records an agent attempting a chosen task and shows where it stalled, and ora.ai says Deep Scan v2, released on 7 July 2026, derives its checklist from agents run on real tasks. Cloudflare's public scanner page describes checks against published standards and does not describe running an agent through a task.

4.Is the scoring method published?

A grade is only as useful as its rules. Look for the layers, the points per layer, the number of checks and the grade bands. ora.ai's methodology page publishes four layers worth 20, 30, 40 and 10 points, with 16, 41, 56 and 6 checks, and grade bands from A+ to F. Cloudflare's page lists five categories and the standards checked but does not publish score bands.

Whichever tool you use, record the date of each scan. Scoring rules change, and a dated record lets you tell a change in your site from a change in the method.

5.Can you run it from code?

Readiness regresses when pages change, so a check that runs in CI can catch a problem before an agent meets it. ora.ai documents a CLI (npx ax audit), a REST API and an MCP server that can rescan after each fix. We did not find a documented CLI or API for Cloudflare's scanner on its public page. If your team ships every week, give this question more weight.

6.Can you fix what it finds on the same platform?

Some findings are content fixes; others need infrastructure. Cloudflare's scanner sits next to Cloudflare features that address several findings directly: Markdown for Agents, AI Crawl Control, Pay per crawl (private beta) and Web Bot Auth verification. ora.ai ranks fixes by impact and can rescan, but the implementation happens on your own stack. If you already run on a CDN that offers the fixes, the path from finding to fix is shorter.

7.Can you use it today?

Check sign-up steps, waitlists and limits before you plan around a tool. Cloudflare's scanner is a public page: enter a URL and scan. ora.ai's free tier needs no API key or sign-up, and its home page asks new users to join a waitlist. is-agentic.com, built by Vercel with scans run by ora.ai, is another public entry point.

8.What can it not see?

Scanners of this kind read public URLs. ora.ai states that it cannot evaluate login-gated content, so a checkout or account area behind sign-in needs a separate test. No scanner measures whether readiness work changes sign-ups or revenue; that question belongs to your own analytics.

9.Does it keep up with the standards?

The standards moved several times in 2026. A2A reached v1.0.0 on 12 March, MCP published a stateless specification on 28 July, and llms.txt was revised to v2 in August. Ask how quickly the scanner updates its checks after a specification changes, and whether it tells you when a score moved because the rules changed rather than your site. Our news page tracks these releases.

10.How should you compare the answers?

Decide which of the eight questions matter most to your team, weight them, and score each candidate from its public documentation, as we do on our method page. Then run each shortlisted scanner on the same three pages and one task, and compare the findings rather than the grades. For the two like-for-like scanners we cover, see ora.ai and Cloudflare; for tools that do other jobs, see tools by job.

11.Sources

Reviewed Sep 2026