UNIVERSITY · LESSON 1 · BASICS · 3 MIN READ
The five layers of agent readiness
One question per layer, and the files or protocols that answer it.
Agent Readiness Compare editors · Spec status checked September 2026
Answer
Agent readiness splits into five layers: discover, read, act, pay and trust. Each layer asks one question and is addressed by different files or protocols. A site can be strong on one layer and absent on another, so check them separately.
On this page
1.What are the five layers?
This reference groups agent readiness into five layers, each a question that an agent's task depends on.
- Discover: can an agent find you, and is it allowed in? robots.txt (RFC 9309), sitemaps, llms.txt and A2A Agent Cards live here.
- Read: can it read and understand what you offer? Server-rendered HTML, llms.txt, markdown negotiation (
Accept: text/markdown) and JSON-LD address this layer. - Act: can it complete a task on your site or API? MCP, WebMCP, agents.json and OpenAPI describe actions an agent can call.
- Pay: can it pay you? x402 uses HTTP 402 so a client can pay per request and retry. ACP, UCP and MPP are other agentic commerce protocols.
- Trust: can you tell which agent it is, and on whose behalf it acts? Web Bot Auth and OAuth 2.0 address identity and delegated access.
2.Why keep the layers separate?
Because each layer can fail on its own. A site can allow every AI crawler in robots.txt and still render its pricing only in JavaScript, which fails the read layer. A site can publish a complete llms.txt and still offer no way for an agent to submit a demo request, which fails the act layer. A single score that averages everything can hide a layer that is missing entirely.
3.Which layers are files and which are protocols?
Discover and read are mostly files you publish and pages you render: robots.txt, sitemap.xml, llms.txt, JSON-LD. Act, pay and trust are protocols you implement, usually on an API or at the CDN: an MCP server, WebMCP tools, an x402 payment flow, Web Bot Auth verification. The first two are usually content and front-end work; the last three usually need engineering time.
4.How can you check each layer quickly?
- Discover: fetch /robots.txt and search for
Disallow: /underUser-agent: *(checklist L1.2). - Read: fetch your pricing page with JavaScript disabled and look for the prices (L2.1).
- Act: write down the three to five tasks an agent should complete (L3.1).
- Pay: decide whether anything on your site should be bought per request, and record the answer (L4.4).
- Trust: check whether your CDN verifies signed bots or trusts user agent strings alone (L5.1).
Five checks will not make a site ready, but they show which layer to work on first.
5.Where should you go next?
The readiness stack figure maps each layer to its standards and to the tools that document support. The checklist turns the five layers into 24 checks. Next: how AI agents read a web page.
Source: RFC 9309 · llmstxt.org · MCP specification · WebMCP repository · x402.org · Cloudflare Web Bot Auth docs · Reviewed Sep 2026