STANDARD · §2.3 · ACT · LAST REVIEWED SEPTEMBER 2026
What is agents.json?
An OpenAPI extension that tells agents which API calls to chain, and in what order.
Agent Readiness Compare editors · Spec status checked September 2026
Answer
agents.json is an open specification, maintained by Wildcard AI under the MIT license, that describes contracts for API and agent interactions on top of OpenAPI. It adds "flows" (sequences of API calls toward an outcome) and "links" (how one call's output feeds the next), and proposes publishing the file at /.well-known/agents.json. It is at version 0.1.0, so treat it as early.
- Maintainer:
- Wildcard AI
- Status:
- open specification, version 0.1.0
1.What problem does agents.json address?
OpenAPI describes individual endpoints well, but it was written for human developers. An agent reading an OpenAPI file sees hundreds of operations and has to guess which ones to call, in which order, to reach an outcome such as 'create an invoice and email it'. agents.json keeps OpenAPI as the base and adds a layer that states those sequences explicitly.
2.What are flows and links?
- Flow: a named sequence of one or more API calls that reaches a specific outcome.
- Link: a connection between actions, describing how data from one call is passed to the next.
Because flows are declared by the API owner, an agent can pick a flow by its outcome instead of planning the call sequence itself.
3.Where does the file go?
The specification proposes /.well-known/agents.json so agents can find it at a predictable path.
GET /.well-known/agents.json HTTP/1.1
Host: api.example.com
Accept: application/jsonFor the file's schema, use the specification repository; it is changing and we do not reproduce it here.
4.What does agents.json not do?
- It does not replace OpenAPI; it references it.
- It does not run anything. An agent still needs a client that executes the calls, with authentication.
- It is not the same as A2A's Agent Card, which describes an agent, not an API. See A2A.
5.How do you check it?
- Request /.well-known/agents.json and confirm it returns JSON.
- Confirm each flow references operations that exist in your current OpenAPI file.
- Walk one flow by hand with real credentials to confirm the sequence still works after API changes.
6.Where does it sit in the readiness stack?
Layer 3, Act: it is for sites whose tasks run through an API.
The readiness stack: five layers (Discover, Read, Act, Pay, Trust), the standards that address each, and the tools that document support.
Can an agent find you, and is it allowed in?
Can it read and understand what you offer?
Can it complete a task on your site or API?
Can it pay you?
Can you tell which agent it is, and on whose behalf it acts?
L1 DISCOVER
Can an agent find you, and is it allowed in?
Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it)
L2 READ
Can it read and understand what you offer?
Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it)
L3 ACT
Can it complete a task on your site or API?
Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it)
L4 PAY
Can it pay you?
Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it)
L5 TRUST
Can you tell which agent it is, and on whose behalf it acts?
Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities)
| Layer | Question | Standards | Tools that document support |
|---|---|---|---|
| L1 DISCOVER | Can an agent find you, and is it allowed in? | robots.txt (RFC 9309); Sitemaps; llms.txt; A2A Agent Card | Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it) |
| L2 READ | Can it read and understand what you offer? | llms.txt; Markdown negotiation (Accept: text/markdown); JSON-LD | Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it) |
| L3 ACT | Can it complete a task on your site or API? | MCP; WebMCP; agents.json; OpenAPI | Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it) |
| L4 PAY | Can it pay you? | x402; ACP; UCP; MPP | Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it) |
| L5 TRUST | Can you tell which agent it is, and on whose behalf it acts? | Web Bot Auth; OAuth 2.0 | Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities) |
Text version of the diagram
| Layer | Question | Standards | Tools that document support |
|---|---|---|---|
| L1 DISCOVER | Can an agent find you, and is it allowed in? | robots.txt (RFC 9309); Sitemaps; llms.txt; A2A Agent Card | Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it) |
| L2 READ | Can it read and understand what you offer? | llms.txt; Markdown negotiation (Accept: text/markdown); JSON-LD | Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it) |
| L3 ACT | Can it complete a task on your site or API? | MCP; WebMCP; agents.json; OpenAPI | Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it) |
| L4 PAY | Can it pay you? | x402; ACP; UCP; MPP | Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it) |
| L5 TRUST | Can you tell which agent it is, and on whose behalf it acts? | Web Bot Auth; OAuth 2.0 | Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities) |
Frequently asked questions
Is agents.json an official standard?
No. It is an open specification maintained by Wildcard AI on GitHub, at version 0.1.0, under the MIT license.
Do I need agents.json if I already have an MCP server?
Not necessarily. An MCP server exposes tools directly to agents. agents.json describes flows over an existing REST API. Some teams will publish one, some both.
Source: github.com/wild-card-ai/agents-json · Reviewed Sep 2026